Post-quantum compliance, on the federal clock
CNSA 2.0 establishes a staged transition for National Security Systems, with milestones that vary by programme and technology. CipherMap gives compliance teams the inventory, detection profiles, and enforcement workflows to plan against the policy that controls their system — entirely on their own machines. DevSecOps Enterprise Tier B includes every Tier A audit artifact and adds provider integrations and fleet operations. Proposal preview remains Free; source-changing publication is planned and unavailable.
Current CSfC planning milestones
A planning aid, not a universal legal deadline; programme owners should verify the controlling CNSS, NSA, agency, and contract requirements.
- Now — 2026Discovery
Inventory & baseline
Generate a CycloneDX 1.6 CBOM across every repository. Establish a quantum-readiness baseline and prioritize national-security-adjacent systems.
- 2027Availability
CNSA 2.0 components enter programs
NSA's current CSfC planning expects components supporting CNSA 2.0 algorithms to begin appearing on approved lists. Exact acquisition requirements remain programme-specific.
- 2028CSfC plan
Capability-package enforcement
Current CSfC planning targets capability-package updates that require CNSA 2.0 for encryption and software or firmware signing. Confirm the controlling policy for each system.
- 2030CSfC target
Registered-solution transition target
The published CSfC planning target is for registered solutions to have CNSA 2.0 algorithms or other post-quantum mitigations across cryptographic layers; NSA notes that this schedule may change.
Built for compliance teams
CycloneDX 1.6 CBOM
Export a machine-readable Cryptographic Bill of Materials — with real cryptoProperties — for every scan. SPDX 2.3 and OpenVEX export feed directly into your SBOM pipeline and audit tooling.
Compliance detection profiles
Additive --target profiles for CNSA 2.0, FIPS 140-3, and NIST SP 800-56B. Profile output includes mapped citations where available; not every scanner rule has a verbatim publication citation.
Enterprise PR automation
The plain scan --fail-on gate and remediation proposal preview are free. Tier B adds provider-aware PR reviews for GitHub, GitLab, Azure DevOps and Bitbucket Cloud. Source publication is not enabled in this release.
Request a Federal Integration Brief
Tell us about your environment and we'll prepare a tailored brief covering deployment architecture, compliance detection profiles, and the CBOM & attestation artifact chain.
The current invitation-only source Preview does not collect inquiry form data on this public site. Email the CipherMap team directly to request source-preview access or an enterprise integration brief.
Email the CipherMap teamSales & Licensing
For enterprise quotes, custom licence agreements, or questions about invoicing:
sales@ciphermap.ioTechnical Support
For assistance with CLI issues, bug reports, or technical questions:
support@ciphermap.io