CNSA 2.0
Commercial National Security Algorithm Suite 2.0
The NSA's post-quantum algorithm suite and transition timeline for US national-security systems, built around ML-KEM and ML-DSA. Its dates are widely used as a pacing signal even by organisations it does not bind.
In practice
Software and firmware signing is expected to move first, with broad adoption by 2030 and completion by 2035.
Related terms
NIST's report on transitioning to post-quantum standards, which proposes deprecating RSA-2048 and ECDSA-P256 by 2030 and disallowing them by 2035. It is the clearest published deadline for retiring classical public-key cryptography.
A structured record of every algorithm, key, certificate, protocol, library and vendor dependency in an organisation. It is the mandatory first step of a post-quantum migration, because you cannot replace what you cannot enumerate.
The NIST-standardised post-quantum key encapsulation mechanism, used to establish a shared secret over an untrusted network. It is the replacement for RSA key transport and elliptic-curve Diffie-Hellman.
The NIST-standardised lattice-based digital signature algorithm, intended as the general-purpose post-quantum replacement for RSA-PSS and ECDSA. Signatures are larger than ECDSA but performance is practical for most uses.