
The NSA has long been moving toward mandatory compliance with the Commercial National Security Algorithm Suite (CNSA 1.0 and CNSA 2.0), and we have arrived at the terminus for non-compliant products: With the publication of NIAP Policy Letter 33, NIAP has established specific transition timelines for when CNSA 1.0 compliance will be enforced and when CNSA 2.0 compliance becomes mandatory.
The key takeaway of the Policy Letter is that CNSA 1.0 compliance will be mandatory starting January 1st, 2027, and CNSA 2.0 compliance will be mandatory starting January 1st, 2028. Before we dive into the specifics of the Policy Letter, let’s review why this is happening.
Why Now?
Some might remember that mandatory CNSA 2.0 compliance was expected by 2030—we even highlighted this in our post discussing the release of CNSA 2.0. So why is NIAP requiring it two years early?
One of the largest motivating factors is Executive Order 14412, which mandates that Federal information systems comply with NIST-approved Post-Quantum Cryptography (PQC) algorithms, and the CNSA is how compliance with PQC algorithms extends to Common Criteria evaluations under NIAP.
In the Executive Order, it is stated that transitioning high value assets and high impact systems to use PQC must be completed by the end of 2030 (for key establishment) and the end of 2031 (for digital signatures). Previous transition dates for the technology used ranged from 2030 to 2033, so multiple transition dates have been brought forward. To support that transition timeline, new products approved for use by the U.S. government need to be compliant ahead of those dates.
Adding to the urgency is the fact that advancements in quantum computing and artificial intelligence (AI) have changed the cybersecurity landscape drastically over just the last year. “Harvest now, decrypt later” has always been a threat, and the “later” seems to keep getting closer faster than we expect; Anthropic’s Claude, meanwhile, has proven a deft hand at finding cryptographic weaknesses, going so far as to weaken the HAWK PQC digital signature scheme.
And, let’s not forget, NIAP had already been pushing the certification community in this direction when they published Addendum 2 of NIAP Policy Letter 5, which made CNSA 1.0 compliance mandatory for CC:2022 evaluations, as we discussed back in March. With Protection Profiles and collaborative Protection Profiles being consistently updated to align with CC:2022, CNSA 1.0 compliance was already on the horizon.
The 2027 Deadline
The January 1st, 2027, deadline for CNSA 1.0 compliance has several facets to cover.
Before discussing the deadlines themselves, it’s important to note that validation resources will be prioritized for CNSA 2.0 compliant products. Fully compliant products are given the highest priority, followed by partially compliant products, and fully non-compliant products will receive the lowest priority for validation resources.
First, the January 1st date is when NIAP will stop accepting products into evaluation that are not at least CNSA 1.0 compliant. Furthermore, said products will not be posted to the NIAP Product Compliant List (PCL) starting July 1st, 2027, meaning if you started an evaluation for a non-compliant product before the turn of the year, it could wind up not getting posted after the evaluation.
Products already posted to the NIAP PCL that are non-compliant will also be archived at a date still to be determined, and will not be eligible for extending certificate length via Assurance Maintenance. Adding on to this, non-compliant products cannot have a certificate length over two years, regardless of the length outlined in NIAP Policy Letter 29 and its Addendum 1.
The 2028 and 2029 Deadlines
In 2028, CNSA 2.0 compliance will become mandatory, with a similar set of requirements as CNSA 1.0 compliance saw above.
On January 1st, 2028, NIAP will not accept evaluations for products that are not compliant with CNSA 2.0 requirements for every cryptographic function.
Products not compliant with CNSA 2.0 that started their evaluations before 2028 will have until January 1st, 2029, to be posted, as NIAP will stop posting non-compliant products on January 1st of 2029.
And, similar to previous CNSA 1.0 compliance, products that are not compliant with CNSA 2.0 that are on the NIAP PCL will be archived at a future date that will be determined later.
The jump from CNSA 1.0 to CNSA 2.0 is substantial, with many algorithms being restricted and replaced with new, quantum-resistant algorithms. The table below shows the changes between the two versions, with removals highlighted in red and additions highlighted in green.

Taking Action and Final Thoughts
We realize that, for many vendors, the above restrictions are going to be challenging.
But, between the way resources will be prioritized for CNSA 2.0 compliant products and the restrictions on new evaluations, we strongly encourage vendors to start exploring CNSA 2.0 compliance as soon as possible.
CNSA 1.0 compliant products will make it through evaluation in the near future, but they will be deprioritized for validation resources and at risk of removal from the NIAP PCL starting in 2028.
Products with no CNSA compliance face significantly greater hurdles, as they will be deprioritized for validation resources and have only half a year to get posted while still facing the same archival risk.
To get a head start, you can learn more about transitioning to PQC algorithms at the upcoming FIPS ‘n’ Chips conference on October 26th—an expert panel will be discussing the PQC countdown. The FIPS ‘n’ Chips Conference will see presentations, panels and discussions on many important issues like this one. We invite you to join us in Austin – register today!
For anyone concerned about these new timelines, we’re happy to answer any questions or provide clarity as best as we are able. Don’t hesitate to get in touch with us at info@atsec.com!



