Skip to content

PQC standards & compliance

CNSA 2.0 in plain English, and what 2027 means for Indian enterprises

The US timeline sets the pace even for Indian buyers, because your customers and your supply chain answer to it.

Asha Ramesh· Standards analyst· 10 Jun 2026· 7 min read

Why an American mandate matters in Mumbai

CNSA 2.0 is a US National Security Agency requirement. It doesn't bind an Indian bank directly. It binds the vendors that Indian bank buys from, the OEMs whose questionnaires it must answer, and the timelines the whole industry now plans against. 2027 is when software and firmware signing must be quantum-safe under CNSA 2.0.

If your product ships into a supply chain that touches US government or defence, the deadline is effectively yours.

The practical read

Treat CNSA 2.0's 2027 as the date your signing must be PQ-ready and its later dates as your general migration horizon. Signing is where hash-based signatures (LMS/XMSS) matter, see Dhiti Sign.

Get started

See how Comply maps your framework.