A readiness evidence record separates cryptographic observations from configuration declarations, supplier capability statements and human planning decisions. It supports assessment; it is not a compliance certificate.
Who should review the 2027 and 2030 milestones?
NSA's PQC Resource Hub describes support requirements for new commercial National Security Systems by 2027 and the phase-out of legacy systems by 2030. These dates must not be presented as a universal deadline for every commercial website or every defense supplier system.
Before selecting a migration target, have the responsible security or procurement team establish system applicability, controlling policy, required profile and contractual obligations. Record that decision separately from scanner evidence.
Capability, configuration and negotiation are different evidence
A single handshake records one result for one client and network vantage. It does not enumerate all supported profiles or establish configured preference. Missing evidence should remain unknown or not tested, with an accountable next action.
| Question | Evidence to request |
|---|---|
| Can the product support the required profile? | Version-specific supplier documentation and compatibility tests |
| What is configured? | Authorized configuration evidence with date and scope |
| What was negotiated? | An observed handshake, client profile, endpoint and timestamp |
| How was the peer authenticated? | Certificate, chain and handshake-authentication evidence separately |
| What remains unknown? | Untested profiles, internal systems and missing supplier evidence |
Turn the inventory into an actionable review
Cipher Discovery's current public scan provides bounded external observations. Its workspace connects retained evidence to manual planning and ownership. A dedicated CNSA 2.0 Evidence Snapshot is planned, not available as a certification or automatic compliance report.
- Define scope
List systems, selected discovery sources and exclusions before collecting evidence.
- Assign accountability
Connect each asset to an application, owner, supplier and documented migration decision.
- Record prerequisites
Identify library, standards and partner support needed before rollout. Treat these as reviewed planning assertions.
- Verify after deployment
Compare the approved expectation against newer evidence, preserving mismatches and remaining unknowns.
Frequently asked questions
Does a public scan certify CNSA 2.0 compliance?
No. It cannot establish system applicability, complete coverage, supplier capability or every required configuration and authentication property.
Does ML-KEM support alone establish readiness?
No. The applicable profile, parameter set, implementation, authentication and operational evidence require separate review.
Can I generate a dedicated CNSA snapshot today?
No. That report is planned. Existing scan and inventory evidence can support a human-led review with explicit gaps.