Delatr presents Lineage at The NATO Maritime Interdiction Operational Training Centre (NMIOTC)

CNSA 2.0 and the Quantum Deadline Facing Drone Manufacturers

The transition to post-quantum security is no longer something defence manufacturers can leave for the future.

News

The NSA’s Commercial National Security Algorithm Suite 2.0, or CNSA 2.0, sets the direction for how US National Security Systems will transition away from cryptography that could eventually be broken by quantum computers. NIST has also finalised its first post-quantum cryptography standards, while the UK’s NCSC has set a national migration pathway running through 2028, 2031 and 2035.

For drone manufacturers, this matters because the aircraft being designed and sold today may remain operational well into that transition.

A drone is also a communications system

Modern unmanned platforms depend on cryptography throughout their architecture. Command and control, telemetry, software updates, firmware signing, ground control stations, payload communications and device authentication can all depend on cryptographic systems.

If those systems rely on quantum-vulnerable public-key algorithms, manufacturers may eventually have to replace or redesign parts of the platform.

For an enterprise IT system, that might mean a software upgrade. For an aircraft that has already been qualified, manufactured and deployed across thousands of units, it can mean new hardware, new integration work, testing, certification and potentially an expensive fleet-wide retrofit.

That makes post-quantum readiness a product design issue, not simply a cybersecurity issue.

The procurement impact will arrive before 2035

The important date is not simply the point at which existing cryptography is finally retired.

NSA programmes are already introducing CNSA 2.0 requirements into classified commercial solutions, with post-quantum capable components expected to become increasingly available from 2027 onwards and requirements tightening through the end of the decade.

At the same time, the UK NCSC expects organisations to understand their cryptographic estates and have migration plans in place by 2028, move their highest priority systems by 2031 and work toward completing migration by 2035.

This means defence OEMs could begin seeing post-quantum requirements appear in tenders, prime contractor requirements and customer security questionnaires years before the final deadlines.

What drone OEMs should be doing now

The immediate challenge is not replacing every cryptographic component overnight. It is understanding where the risk exists.

Manufacturers should know which algorithms protect their command links, where cryptographic keys are generated and stored, how firmware is authenticated, what security sits inside their radios and whether those components can be upgraded without redesigning the aircraft.

Crypto-agility is likely to become increasingly valuable. Platforms designed so that their security layer can evolve independently of the radio, flight controller and wider avionics stack will be much easier to transition than systems where cryptography is deeply embedded into proprietary hardware.

For drone manufacturers, the quantum transition is therefore becoming another lifecycle engineering requirement.

The platforms being designed today need to remain secure, supportable and procurable in the security environment of the 2030s.

Reference sources used

This version is based on official guidance rather than the PostQuantum.com article: NSA's CNSA 2.0 and post-quantum resources, including its current CSfC transition guidance; NIST's final post-quantum standards and migration programme; and the UK NCSC's official PQC migration timeline.

Secure The Fleet.

Encryption that will outlast the platforms it protects.

Secure The Fleet.

Encryption that will outlast the platforms it protects.

Secure The Fleet.

Encryption that will outlast the platforms it protects.