
Defense Data Has the Longest Confidentiality Lifetime on Earth
A classified communications link in 2026 can reasonably be expected to carry material that must remain secret for 50 years or more. Diplomatic cables, weapons system design, intelligence sources, and operational plans all have confidentiality lifetimes measured in decades. That is exactly the scenario Mosca's X + Y > Z theorem warns about. Harvest-now-decrypt-later adversaries are presumed to be archiving every encrypted packet that crosses borders, and the defense community has no option but to assume a large quantum computer exists within the archival window.
This guide summarizes the state of Quantum Resistant Cryptography for aerospace and defense as of April 2026. It covers the NSA CNSA 2.0 suite, NIAP protection profile work, Data at Rest capability packages, and the migration pressures on defense contractors, primes, and suppliers.
NSA CNSA 2.0: The Operative Directive
The NSA Commercial National Security Algorithm Suite 2.0 was announced on September 7, 2022. It replaces CNSA 1.0 and sets the algorithm baseline for US National Security Systems. The required algorithms are:
- ML-KEM-1024 (FIPS 203) for key establishment at NIST category 5.
- ML-DSA-87 (FIPS 204) for digital signatures at NIST category 5.
- LMS and XMSS stateful hash-based signatures (NIST SP 800-208) for software and firmware signing near-term.
- AES-256 for symmetric encryption.
- SHA-384 or SHA-512 for hashing.
CNSA 2.0 sets a full migration target of 2035 for NSS. New NSS deployments should be quantum-resistant by January 2027. Application-level migration is expected by 2030. The full infrastructure deadline is 2035. This is operative. The FAQ is on media.defense.gov and is not a draft.
NIAP and Protection Profiles
The National Information Assurance Partnership (NIAP) develops Common Criteria protection profiles for US government procurement. As CNSA 2.0 becomes operative, NIAP is developing new and revised protection profiles aligned to the CNSA 2.0 algorithm suite. Vendors selling to NSS or Department of Defense procurement will need Common Criteria evaluations that reference PQC primitives. Today most NIAP PPs still cite CNSA 1.0 primitives. Expect 2026 through 2028 to bring a wave of revised protection profiles.
The Current Data at Rest Picture
The CSfC Data at Rest (DAR) Capability Package v5.0 currently references CNSA 1.0 algorithms. The CSfC program uses a two-layer approach (software full disk encryption plus file encryption, or hardware full disk encryption plus software file encryption) to enable commercial products to protect classified data. Vendors participating in CSfC should expect a v6.0 that aligns DAR with CNSA 2.0. The classical layers will not be ripped out. Instead the composition will gain a PQC layer.
Mission Systems and the Long Tail
Defense mission systems have long procurement and sustainment cycles. Aircraft like the B-52 will fly past 2050. Radar and communication systems deployed in 2026 can be expected to operate into the 2040s. Crypto primitives built into the platforms at design time become very difficult to change. Crypto-agility at the system architecture level is the only sustainable answer. That means software-defined crypto modules, HSM firmware upgradability, and certificate profiles that can accommodate ML-DSA signatures in addition to ECDSA.
Suite B to CNSA 1.0 to CNSA 2.0
The evolution from Suite B to CNSA 1.0 to CNSA 2.0 shows a pattern: the NSA publishes an algorithm suite, procurement catches up over years, and legacy systems eventually age out. The same will happen with CNSA 2.0. Contractors that start the migration planning early (now) will have working PQC implementations before the 2035 deadline. Contractors that wait will face schedule risk and possibly contract penalties.
Satellites, UAVs, and Space Systems
Space Development Agency tranches, GPS III, and other space assets have multi-decade operational lives once launched. Link-16, Mode 5 IFF, and tactical data links all use classical cryptography that Shor's algorithm would defeat. Cross-link traffic between satellites is especially exposed to long-term archival capture. Program offices are quietly updating crypto roadmaps to reflect CNSA 2.0 and NSM-10 guidance.
Allied and Coalition Considerations
Five Eyes partners (UK, Canada, Australia, New Zealand) are pursuing aligned PQC timelines. The UK NCSC published timeline guidance in 2024 with a 2035 target. Canada, Australia, and New Zealand have similar windows. NATO interoperability requirements mean defense systems have to speak CNSA 2.0 with Five Eyes and a set of aligned NATO PQC profiles with other allies.
Supply Chain and Contractor Obligations
CMMC and DFARS clauses already push defense contractors toward cybersecurity maturity. Expect contract vehicles to start requiring:
- Cryptographic inventories of contractor IT and engineering environments.
- CNSA 2.0 readiness plans for defense information systems.
- PQC-compliant data at rest for Controlled Unclassified Information (CUI).
- Supplier certifications cascading down Tier 2 and Tier 3.
QNSQY and the Defense Use Case
QNSQY implements the CNSA 2.0 algorithm set: ML-KEM-1024 for key establishment, ML-DSA-87 for signatures, SLH-DSA and LMS for stateful or hash-based signing, AES-256-GCM for bulk encryption. Defense contractors use QNSQY to protect engineering data, design repositories, contract deliverables, and long-lived IP in ways that meet CNSA 2.0 expectations without waiting for a hardware refresh.
For defense security leads. CNSA 2.0 is operative. 2027 is the near-term NSS deadline, 2035 is the full-migration deadline. An HNDL adversary is not waiting. Contractors should assume their classified-adjacent engineering data is already being archived by hostile services.
Frequently Asked Questions
What algorithms does CNSA 2.0 require?
CNSA 2.0 requires ML-KEM-1024 for key establishment, ML-DSA-87 for digital signatures, LMS or XMSS for near-term firmware signing, AES-256 for symmetric encryption, and SHA-384 or SHA-512 for hashing.
What is the CNSA 2.0 full migration deadline?
The full-migration target for US National Security Systems is 2035, with new NSS deployments expected to be quantum-resistant by January 2027 and application migration by 2030.
Does the current CSfC Data at Rest Capability Package cover PQC?
Not as of v5.0. It still references CNSA 1.0. A revised version aligning with CNSA 2.0 is expected.
Is NIAP requiring PQC in protection profiles today?
NIAP is developing new and revised protection profiles aligned to CNSA 2.0. Most current PPs still reference CNSA 1.0, so expect a rolling update over 2026 to 2028.
Do coalition allies have matching PQC timelines?
Yes. UK NCSC 2024 guidance has a 2035 target. Canada, Australia, and New Zealand align similarly, and NATO interoperability will require both CNSA 2.0 fluency and allied PQC profiles.
Sources
- NSA CNSA 2.0 FAQ
- White House NSM-10
- NIST FIPS 203 (ML-KEM)
- NIST FIPS 204 (ML-DSA)
- NIST SP 800-208 (LMS/HSS)
- UK NCSC PQC Migration Timelines
Related Articles
- PQC for Government and Defense
- Harvest Now, Decrypt Later Threat
- LMS Stateful Signatures
- ML-DSA vs SLH-DSA Comparison
- NIST FIPS 203/204/205 Guide
Protect Your Data Before Q-Day Arrives
QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.
Try QNSQYOriginally published at quantumsequrity.com/blog/pqc-aerospace-defense-systems.