Government and defence face the post-quantum transition earlier and harder than any other sector, for two reasons: the classification periods are long, and the mandates are real.
Classification outlives the cryptography
Material classified for 25 years and transmitted today under classical key exchange must remain secret well past any credible estimate for capable quantum hardware.
Harvest now, decrypt later is not a theoretical concern in this context. Nation-state adversaries have both the capacity to store traffic at scale and the patience to wait, and the assumption that they already do so is the prudent planning position.
CNSA 2.0 is a requirement, not guidance
CNSA 2.0 sets algorithms and deadlines for US National Security Systems, with transitions targeted between 2030 and 2033. Web browsers, servers, and cloud services were expected to support and prefer the suite by 2025 — a marker that has already passed — and to move to exclusive use by 2033.
The detail that catches people: CNSA 2.0 requires ML-KEM-1024, whereas the web has converged on ML-KEM-768 inside the hybrid group X25519MLKEM768. Inheriting what browsers negotiate by default does not make a system CNSA 2.0 compliant. The parameter size matters.
Contractors and suppliers are in scope too
The requirements propagate down the supply chain. Suppliers to national security programmes are increasingly asked to evidence their own cryptographic posture, often before they have any inventory to evidence it with.
An external assessment is the fastest way to answer that question honestly, because it requires no access to the systems being assessed.
What assessment finds
Long-lived estates accumulate long-lived problems: TLS 1.2-only appliances, services standing since before TLS 1.3 was deployable, and public-facing infrastructure inherited across programme boundaries with no clear owner.
None of it can negotiate post-quantum key exchange, because hybrid groups require TLS 1.3. For those hosts the protocol upgrade is the prerequisite, not the cryptography.
Where to start
With an inventory — every mandate assumes one exists, and most estates do not have one. Start externally, since it needs no credentials or change control, then work inward. See how to inventory your cryptography.