NSA sets 2027 and 2030 deadlines for post-quantum cryptography in national security systems

Started by RealChristopher10, Today at 03:50 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: NSA sets 2027 and 2030 deadlines for post-quantum cryptography in national security systems   Views(Read 45 times)
Active members in this topic:
RealChristopher10(1) Hidden Sookie(1)

RealChristopher10

The US National Security Agency has announced new measures to move national security systems over to quantum resistant cryptography. It is a government announcement about defence systems, so please keep the thread focused on the technology and security side. The key dates are clear. From 2027, all new commercial products used in national security systems must support quantum resistant algorithms, and by 2030 legacy systems that cannot support them must be phased out

The measures apply to national security systems, the Department of War and the wider defence industrial base. They build on Executive Order 14412, titled Securing the Nation Against Advanced Cryptographic Attacks, and a national security systems policy known as CNSS Policy 15. Alongside the post-quantum guidance, the NSA is offering services to defence contractors including attack surface management, protective DNS and threat intelligence, plus zero trust implementation guidelines. That is a broad package, not just a quantum announcement

Morgan Stern, who leads the NSA's quantum resistance work, said the agency is at the forefront of the transition. He described the quantum threat as an existential threat to the digital ecosystem, but added that we have the tools today to combat it. The announcement specifically mentions adversaries using harvest now, decrypt later and trust now, exploit later strategies. Those phrases are becoming standard in security circles

This ties directly into our recent thread on post-quantum cryptography. The NIST standards are already finalised, so the technical building blocks exist, and the UK's National Cyber Security Centre has its own timeline running to 2035. The NSA's 2030 deadline for legacy systems is considerably tighter, which shows how seriously it takes the threat to secrets that need to stay protected for decades

Government deadlines like this tend to ripple out to the wider industry, as vendors build compliant products and then sell them to everyone. Do you think 2030 is achievable for legacy systems? And will this speed up post-quantum migration in the private sector?

Coffee first. Questions later.

Hidden Sookie

The 2027 rule for new products is the realistic one. It is much easier to require new kit to support new algorithms than to replace everything already deployed

Every new purchase from now on moves things forward. Procurement rules are a powerful lever