Post-Quantum Cryptography migration readiness and CNSA 2.0 compliance
Readiness Tier
Migration underway but incomplete. Continue replacing vulnerable algorithms.
PQC Readiness Score
72/100
Based on 3 assessments (2 completed)
Cryptographic Inventory
15 algorithms
Track your PQC migration across the five key phases
NSA Commercial National Security Algorithm Suite 2.0 requirement checklist
ML-KEM (FIPS 203) for key encapsulation
ML-KEM-768 deployed for internal key exchange.
ML-DSA (FIPS 204) for digital signatures
ML-DSA-65 used for code signing pipeline.
SLH-DSA (FIPS 205) for stateless hash-based signatures
SLH-DSA-SHA2-128s configured for firmware signing.
AES-256 for symmetric encryption
Some legacy services still use AES-128.
SHA-384+ for hashing
SHA-256 in use; SHA-384 migration pending.
XMSS/LMS for stateful hash-based signatures
Not yet evaluated for deployment.
Hybrid key exchange for TLS 1.3
TLS endpoints not yet configured for hybrid mode.