STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 12 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to General Application (GAPP) Security Requirements Guide

V-288246

CAT I (High)

The application must use Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) cryptographic algorithms.

Rule ID

SV-288246r1252946_rule

STIG

General Application (GAPP) Security Requirements Guide

Version

V1R0.1

CCIs

CCI-002450

Discussion

Use of improperly configured or lower-assurance equipment and solutions could compromise high-value information. CNSA 2.0 is the NSA's next-generation cybersecurity standard designed to protect National Security Systems (NSS) from the impending threat of quantum computing. It phases out vulnerable legacy algorithms (like RSA and ECC) in favor of quantum-resistant post-quantum cryptography (PQC) selected from NIST standards. This requirement pertains to Zero Trust.

Check Content

Review the application documentation and deployed configuration to determine whether the application's cryptography mechanism uses CNSA 2.0 cryptographic algorithms.

If the application's cryptography mechanism does not use CNSA 2.0 cryptographic algorithms, this is a finding.

Fix Text

Navigate to the cryptography configuration within the application.

Configure the application's cryptography mechanism to use CNSA 2.0 cryptographic algorithms.