Post-quantum readiness for government and defence

Government systems face binding CNSA 2.0 deadlines and classification periods long enough that harvest-now-decrypt-later is already live.

Government and defence face the post-quantum transition earlier and harder than any other sector, for two reasons: the classification periods are long, and the mandates are real.

Classification outlives the cryptography

Material classified for 25 years and transmitted today under classical key exchange must remain secret well past any credible estimate for capable quantum hardware.

Harvest now, decrypt later is not a theoretical concern in this context. Nation-state adversaries have both the capacity to store traffic at scale and the patience to wait, and the assumption that they already do so is the prudent planning position.

CNSA 2.0 is a requirement, not guidance

CNSA 2.0 sets algorithms and deadlines for US National Security Systems, with transitions targeted between 2030 and 2033. Web browsers, servers, and cloud services were expected to support and prefer the suite by 2025 — a marker that has already passed — and to move to exclusive use by 2033.

The detail that catches people: CNSA 2.0 requires ML-KEM-1024, whereas the web has converged on ML-KEM-768 inside the hybrid group X25519MLKEM768. Inheriting what browsers negotiate by default does not make a system CNSA 2.0 compliant. The parameter size matters.

Contractors and suppliers are in scope too

The requirements propagate down the supply chain. Suppliers to national security programmes are increasingly asked to evidence their own cryptographic posture, often before they have any inventory to evidence it with.

An external assessment is the fastest way to answer that question honestly, because it requires no access to the systems being assessed.

What assessment finds

Long-lived estates accumulate long-lived problems: TLS 1.2-only appliances, services standing since before TLS 1.3 was deployable, and public-facing infrastructure inherited across programme boundaries with no clear owner.

None of it can negotiate post-quantum key exchange, because hybrid groups require TLS 1.3. For those hosts the protocol upgrade is the prerequisite, not the cryptography.

Where to start

With an inventory — every mandate assumes one exists, and most estates do not have one. Start externally, since it needs no credentials or change control, then work inward. See how to inventory your cryptography.

Related

FrameworkCNSA 2.0The NSA's Commercial National Security Algorithm Suite 2.0: which algorithms are required, which deadlines apply to which system classes, and who is in scope.GuideHarvest now, decrypt laterAttackers record encrypted traffic today and decrypt it once quantum computers mature. Why classical key exchange is a present-tense risk.GuideInventory your cryptographyA practical order of operations for discovering what cryptography an organisation actually uses, starting with internet-facing services.

Last reviewed 2026-07-21.