๐Ÿ” CNSA 2.0 & NIST PQC Compliance

Measure Your
Post-Quantum Readiness
Before It's Mandated

Quantum computers threaten every asymmetric key in your stack today. Bulwark gives security teams a structured 39-control assessment against CNSA 2.0 or the NIST PQC standards (FIPS 203/204/205) โ€” with live scoring, gap tracking, and board-ready PDF reports.

Free to start ยท Work email required ยท No credit card needed

Framework coverage

CNSA 2.0
NIST PQC
FIPS 203 / ML-KEM
FIPS 204 / ML-DSA
FIPS 205 / SLH-DSA
SP 800-208
NIST IR 8547

Harvest Now,
Decrypt Later

Adversaries are collecting encrypted traffic today to decrypt once a cryptographically-relevant quantum computer exists. Long-lived secrets โ€” financial records, health data, classified communications โ€” are already at risk.

The NSA's CNSA 2.0 suite and NIST's PQC standards (FIPS 203/204/205) both mandate migration to post-quantum algorithms. Financial institutions and government contractors must demonstrate readiness โ€” but most have no structured way to measure where they stand.

2030
CNSA 2.0 migration milestone โ€” and NIST IR 8547 deprecation date for legacy public-key algorithms
39
Controls across transit, at-rest, and governance domains
5
Maturity levels from Initial to Optimized
3
Security domains: Transit ยท At Rest ยท Governance

39 Controls Across Three Domains

Every control maps to a specific CNSA 2.0 or NIST PQC requirement โ€” with clear evidence criteria, remediation guidance, and maturity targets.

๐Ÿ”’

Data in Transit

13 controls
  • TLS 1.3 with ML-KEM key exchange
  • Post-quantum certificate chain validation
  • VPN and encrypted tunnel migration
  • API gateway and service mesh controls
  • Certificate lifecycle and rotation
๐Ÿ—„๏ธ

Data at Rest

13 controls
  • AES-256-GCM storage encryption
  • ML-KEM key encapsulation for KEK
  • HSM validation (FIPS 140-3 Level 3)
  • Key rotation and expiration policies
  • Backup and archive encryption
๐Ÿ“‹

Governance

13 controls
  • Cryptographic inventory and asset register
  • PQC migration roadmap and ownership
  • Vendor and supply chain attestations
  • PQC standards training and awareness
  • Board-level reporting cadence

Everything You Need to Prove Readiness

From initial gap discovery to board-level reporting, Bulwark handles the full assessment lifecycle.

๐Ÿ“Š

Live Readiness Dashboard

Scores update in real-time as assessors complete controls. See overall readiness band, per-domain averages, open gaps by priority, and completion percentage at a glance.

Real-time
โœ๏ธ

Structured Control Editor

Each control shows the framework target (CNSA 2.0 or NIST PQC), evidence requirements, and editable fields for maturity score, notes, gap description, remediation plan, owner, and target date. Auto-saves on every change.

Autosave
๐Ÿ“„

PDF Report Export

Generate a branded, regulator-ready report with your org name, readiness band, domain breakdown, and full gaps & remediation register sorted by priority. Suitable for board and auditor review.

Board-ready
๐ŸŽฏ

Maturity Scoring (0โ€“5)

Score each control from Initial (0) to Optimized (5). Domain and overall scores roll up automatically. Readiness bands give clear program status: Initial โ†’ Aware โ†’ Developing โ†’ Managed โ†’ Optimized.

Maturity scale
๐Ÿ‘ฅ

Role-Based Collaboration

Admin, Assessor, and Viewer roles. Admins manage members and advance assessment status. Assessors fill out controls. Viewers and executives get read-only access to the dashboard and reports.

Multi-user
๐Ÿข

Multi-Assessment Tracking

Run multiple assessment cycles to track progress over time. Each assessment captures a point-in-time snapshot so you can demonstrate improvement to regulators and leadership.

Progress tracking

From Sign-Up to Readiness Report in Hours

No professional services required. Your security team can complete a full CNSA 2.0 or NIST PQC assessment in a single working day.

1

Create Your Organization

Sign up with your work email, verify your identity, and create your organization. Invite assessors and reviewers โ€” each with the right access level.

2

Pick a Framework & Score 39 Controls

Choose CNSA 2.0 or NIST PQC, then work through controls across Transit, At Rest, and Governance. Score each control, add notes, document gaps, assign remediation owners, and set target dates.

3

Export Your Readiness Report

Generate a PDF with your overall readiness band, domain scores, and full gap register. Share with your board, auditors, or regulators in one click.

Built for Security-Conscious Organizations

Purpose-built for teams that need to demonstrate CNSA 2.0 or NIST PQC compliance โ€” not a generic security checklist tool.

๐Ÿฆ

Financial Institutions

Banks, credit unions, and payment processors preparing for post-quantum mandates. Demonstrate readiness to regulators and internal risk committees with structured evidence.

๐Ÿ›๏ธ

Government Contractors

Defense contractors and federal system integrators building or operating national security systems subject to CNSA 2.0 transition requirements.

๐Ÿ”

CISOs & Security Leaders

Get a clear, quantified picture of your organization's cryptographic exposure. Prioritize remediation, allocate resources, and report program progress to leadership.

๐Ÿ“

Crypto Architects & Engineers

Work through detailed technical controls with evidence requirements, current-state notes, and remediation planning in a structured collaborative environment.

Know Where You Stand on Post-Quantum Readiness

Start your free assessment with your organization email. No credit card, no professional services โ€” just your security team and 39 controls.

Work email required ยท Personal email providers not accepted