April 30, 2024
•
3
min read
Getting Ready for the Future: A Look at The Commercial National Security Algorithm Suite 2.0 (CNSA 2.0)
The transition to post-quantum cryptography is continuing to accelerate. Last week, the National Security Agency (NSA) released its latest update to the Commercial National Security Algorithm Suite 2.0 (CNSA 2.0), the set of cryptography requirements for securing National Security Systems (NSS) against the potential threat of quantum computers.
What is CNSA 2.0?
CNSA 2.0 sets the standards and timelines for organizations owning, operating, or supporting National Security Systems to transition to quantum-resistant (QR) algorithms. These algorithms are designed to be secure even when faced with the immense processing power of quantum computers. Traditional public-key cryptography, used throughout security systems today, will be vulnerable to attacks from sufficiently powerful quantum computers. CNSA 2.0 aims to mitigate this risk mandating the transition to new, post-quantum cryptography.
Why is CNSA 2.0 important?
Experts expect that quantum computers able to break current encryption methods could be available as soon as 2030 and data that is encrypted today is at risk from Harvest Now/Decrypt Later attacks. CNSA 2.0 prepares NSS by setting the timeframes to transition to QR algorithms resistant to such attacks. Even organizations that do not support National Security Systems should carefully review the guidance. Clearly the stakes are the highest for national intelligence and defense, but critical infrastructure, financial services, healthcare, technology, and any other sectors that handle sensitive data are also at risk.
What's the timeline for CNSA 2.0?
The NSA is urging NSS owners and operators to be aware of the requirements, start the transition now where possible, and closely monitor the availability of additional QR standards. Most importantly, NIST has announced that it will be releasing new cryptographic standards for key exchange and digital signature in FIPS 203, 204, and 205 by the summer of 2024.
The following table details the CNSA 2.0 timeline requirements for different system types:
What are the implications of CNSA 2.0?
The NSA and other cybersecurity experts clearly recognize the complexity of transitioning cryptographic algorithms and systems. For years they have advised organizations to begin the transition planning process, including inventorying cryptographic usage, completing risk assessments, and beginning the transition to quantum-safe algorithms as soon as possible. CNSA 2.0 lays out specific requirements for NSS, and it provides a guide to organizations of all types on the timelines that they should work towards in this transition. Vendors, developers, and implementers need to start this shift today if they haven’t already.