NIAP has published Policy Letter #33, setting certification deadlines for the transition to post-quantum cryptography (PQC). The policy affects products entering NIAP evaluation, products seeking placement on the Product Compliant List (PCL), and products already certified by NIAP or a CCRA partner.
For vendors, the practical effect is clear: PQC adoption is now on the critical path, and timelines are tightening. NIAP is introducing certification and market-access gates ahead of some of NSA’s broader operational transition dates. These gates apply not only to products entering NIAP evaluation, but also to internationally certified CCRA products seeking placement on the NIAP PCL. Existing listings are also affected. NIAP intends to archive noncompliant products on a date yet to be determined, regardless of how much time remains on their certifications. At the same time, Protection Profiles and supporting requirements still need to be updated to provide a viable path to demonstrating CNSA 2.0 compliance through NIAP evaluation.
The rest of this post looks at what Policy Letter 33 changes, how its deadlines compare with NSA’s broader CNSA 2.0 transition schedule, and the implementation gaps vendors still need to navigate.
Read More








