Roadmap & standards currency
Is the vendor keeping pace with a standards landscape that is still moving?
Requirements, evidence source, and references
This page is the citable form of this dimension — a finding elsewhere can link straight to the bar it was judged against.
Roadmap & standards currency
5 requirementsIs the vendor keeping pace with a standards landscape that is still moving?
A stated timeline for algorithms still being standardised, rather than silence.
- NIST post-quantum programme — additional algorithms (HQC, FN-DSA)search-corroboratedHQC was selected as an additional KEM and FN-DSA (FALCON) remains pending a final standard. Draft/final status changes; verify against the programme page before scoring a roadmap claim.
Evidence the vendor tracks standards revisions, and ships against final rather than draft text.
A stated policy for deprecating an algorithm, including notice periods for customers.
Alignment with the published regulatory timelines the vendor's market is actually held to.
- NSA Commercial National Security Algorithm Suite 2.0 (CNSA 2.0)search-corroborated2026-08-12Direct PDF read was blocked (HTTP 403) when last attempted; contents corroborated across secondary sources only. Do not upgrade without reading the primary.
- EU Cyber Resilience Act — Regulation (EU) 2024/2847search-corroboratedCited for the software-bill-of-materials and update-path obligations that make crypto-agility a procurement question rather than an engineering preference. Primary text not read here.
Roadmap items are distinguishable from shipped features in the vendor's own material.
- NIST post-quantum programme — additional algorithms (HQC, FN-DSA)search-corroboratedHQC was selected as an additional KEM and FN-DSA (FALCON) remains pending a final standard. Draft/final status changes; verify against the programme page before scoring a roadmap claim.
- NSA Commercial National Security Algorithm Suite 2.0 (CNSA 2.0)search-corroborated2026-08-12Direct PDF read was blocked (HTTP 403) when last attempted; contents corroborated across secondary sources only. Do not upgrade without reading the primary.
- EU Cyber Resilience Act — Regulation (EU) 2024/2847search-corroboratedCited for the software-bill-of-materials and update-path obligations that make crypto-agility a procurement question rather than an engineering preference. Primary text not read here.