up:: The Mandates MOC
The Coalition Interoperability Gap
The coalition interoperability gap is the distance between what allied militaries are each required to build and what they need to have in common. Every major ally has published post-quantum requirements, and those requirements specify different parameter sets, different positions on hybrid deployment, and different completion dates. NATO’s own quantum strategy lists a quantum-safe alliance as an objective rather than a dated commitment, so nothing above the national level currently reconciles them.
The systems still talk today because protocol negotiation absorbs the difference. The question is what happens to a joint operation when negotiation runs out of common ground.
The short version:
- NATO has a quantum strategy and no post-quantum deadline. The published summary lists “NATO has transitioned its cryptographic systems to quantum-safe cryptography” as a desired future outcome, with no date attached.
- Allied national deadlines differ by years. The US national-security suite mandates by the end of 2031, the UK completes by 2035, and Australia exits classical public-key by the end of 2030.
- Parameter choices differ too. CNSA 2.0 requires the strongest parameter set at every classification level, while the UK recommends a middle set for general use, and systems built to each do not automatically negotiate a common configuration.
- The hybrid question splits the alliance three ways, covered in ANSSI vs BSI vs NCSC vs NSA on Hybrid.
- Procurement carries the divergence into equipment. A national mandate becomes a vendor requirement, and the vendor ships what its largest buyer specified, so the difference ends up baked into radios and gateways rather than resolved in policy.
Imagine an alliance agreeing to replace every lock in a shared building, with each member responsible for its own floor. They agree on the brand of lock, which is the genuinely hard part and already settled. Then one member fits the heaviest grade on every door, another fits the standard grade, a third insists the old lock stays mounted alongside the new one, and a fourth has until 2035 to finish. The building still works, because everyone carries a keyring and tries keys until one turns. It works right up until two people need the same door open at the same time and the only key they share is the old one.
What does coalition interoperability actually require?
Systems built by different countries have to complete a cryptographic operation together, which means they need an algorithm, a parameter set, and a protocol version in common, and each side has to consider that combination acceptable under its own national rules.
That last clause is what makes coalition interoperability harder than ordinary interoperability. A commercial client and server negotiate down to whatever they share. A military system frequently cannot, because its national policy sets a floor below which the connection is prohibited rather than merely weaker. When two national floors do not overlap, there is no negotiated outcome at all.
The mechanics of how negotiation succeeds and fails are in Cryptographic Interoperability. This note is about the policy layer sitting above those mechanics, and about what happens when 32 sets of national rules are applied to one shared network.
What has NATO actually committed to?
Less than most people assume, and the wording repays close reading.
NATO published a summary of its Quantum Technologies Strategy on 16 January 2024. It states as current fact that “post-quantum cryptography is an important approach to secure communications against quantum-enabled attacks,” and it recognizes that “a functional quantum computer would also have the ability to break current cryptographic protocols.”
The transition itself appears in a different register. Among the strategy’s desired future outcomes: “NATO has transitioned its cryptographic systems to quantum-safe cryptography.” Alongside it: “NATO has developed, adopted and implemented frameworks, policies and standards for both software and hardware to enhance interoperability.”
Both are written as end states the alliance intends to reach, and neither carries a date. The implementation language is similarly permissive: “through NATO committees and bodies Allies can support each other, and the NATO Enterprise, in the development and implementation of post-quantum cryptography and quantum key distribution.”
Source: NATO, “Summary of NATO’s Quantum Technologies Strategy,” 16 January 2024, nato.int.
So the alliance has an articulated direction and no clock. Every one of its members has a clock. That inversion is the structural problem: the binding dates exist at the national level, where they differ, and the coordinating body has published nothing to converge them.
Where do allied requirements actually diverge?
Three dimensions, and a coalition system inherits all three at once.
| Ally | Parameter requirement | Hybrid posture | Completion date |
|---|---|---|---|
| United States (national-security systems) | ML-KEM-1024 and ML-DSA-87, level 5 at every classification level | Permitted for interoperability, moves no deadline | Mandated end of 2031, new acquisitions from 1 January 2027 |
| United Kingdom | ML-KEM-768 and ML-DSA-65 for general use | Interim measure only, PQC-only is the destination | Complete by 2035, discovery by 2028 |
| France | No closed list; prefers NIST level 5, else level 3 | Required for certified products, hash-based signatures excepted | Standalone PQC “probably not earlier than 2030” |
| Germany | ML-KEM and ML-DSA, plus conservative alternatives retained | Recommended for long-term confidentiality | Annual guideline revisions, no single date |
| Australia | Classical public-key ceases use | Not framed as a hybrid requirement | End of 2030 |
Source: NSA, “CNSA 2.0 FAQ,” PP-24-4014, December 2024 update, PDF; NCSC, “Timelines for migration to post-quantum cryptography,” 20 March 2025, ncsc.gov.uk; ANSSI, “(2023 follow up),” 21 December 2023, PDF; BSI, TR-02102-1 Version 2026-01, PDF; Australian Signals Directorate, “Guidelines for cryptography,” Information Security Manual, cyber.gov.au.
The full four-way comparison of the hybrid question is in ANSSI vs BSI vs NCSC vs NSA on Hybrid.
Why does a parameter mismatch matter if both sides use ML-KEM?
Because agreeing on the algorithm is not the same as agreeing on the configuration, and the connection is established by the configuration.
ML-KEM-768 and ML-KEM-1024 are different parameter sets of the same algorithm, negotiated as distinct options, and a system that offers only one will not complete a handshake with a system that accepts only the other. In commercial deployments this resolves itself, because implementations support several sets and negotiate whatever is mutually available.
In a national-security context the flexibility is deliberately removed. CNSA 2.0 requires level 5 at every classification level, which is a step above the general-purpose recommendation NIST publishes and above what the UK recommends for OFFICIAL-tier information. A US system built strictly to that requirement and a UK system built strictly to its own national guidance can both be fully compliant, fully migrated, and unable to agree on a shared configuration.
This is the point most often missed about the transition. The algorithm choice was the coordination problem everyone expected, and it was solved by an open international process that produced a shared answer. The parameter and policy layer underneath was left to national discretion, and that’s where the divergence actually sits.
How does a national mandate turn into coalition equipment?
Through procurement, which is slower to reverse than policy.
A national requirement becomes a condition of sale, and a vendor that wants to keep selling into that market builds to it. The CNSA 2.0 acquisition gate on 1 January 2027 is the clearest instance: from that date, new national-security-system products have to support CNSA 2.0, so any supplier serving that market ships level-5 parameters well before then, and its own suppliers inherit the same clock.
Radios, gateways, and satellite terminals bought under one nation’s requirement then arrive in coalition service configured to that nation’s rules. Firmware and certification cycles for defense equipment run years, so a configuration decision made to satisfy a 2027 procurement gate is still in the field long after the policy conversation has moved on. Divergence written into hardware outlives divergence written into guidance.
Which date does a coalition capability actually have to meet?
The earliest one that binds any participant, which is a different question from the one most national programs are answering.
A joint capability involving US national-security systems inherits the 2027 acquisition gate and the 2031 mandate. The same capability involving UK systems has a 2035 completion horizon and a 2031 milestone for highest-priority work. An Australian participant exits classical public-key at the end of 2030. Nothing reconciles those, so in practice the coalition capability is governed by whichever participant’s rule bites first, while its overall security is governed by whichever participant migrates last.
Those two facts pull in opposite directions and neither is anyone’s stated plan. The strictest national rule sets the procurement floor, and the slowest national migration sets the effective security of any shared link, because a connection is only as protected as the endpoint that has not moved yet.
What actually holds it together today?
Negotiation and hybrid deployment, both of which are working and neither of which is a policy.
Protocol negotiation lets 2 systems find common ground at connection time, which is why divergent national migrations have not yet produced visible failures. Hybrid constructions help too, in a way that cuts against how they are usually discussed: a system running a classical algorithm alongside a post-quantum one retains a fallback that a fully migrated peer can still meet. The UK’s own guidance names interoperability during phased migration as 1 of the 3 circumstances warranting hybrid.
The property that makes any of this survivable over a decade is crypto-agility, the ability to change algorithms and parameters without re-architecting, which every one of these authorities asks for. It’s the only requirement they genuinely share, and it is doing the work that a common standard would otherwise do.
Common misconceptions
- “NATO has set a post-quantum deadline.” The published strategy summary lists the transition as a desired outcome with no date. The dates all live at the national level.
- “Everyone picked the NIST algorithms, so interoperability is solved.” The algorithm layer converged. The parameter, hybrid, and timeline layers stayed national, and connections are established at that layer.
- “A mismatch just falls back to something weaker.” In commercial systems, often. Under national-security policy a floor is a prohibition, so the outcome can be no connection rather than a weaker one.
- “This resolves itself when everyone finishes migrating.” Completion dates span 2030 to 2035, and equipment procured to satisfy an earlier gate stays in service across that whole window.
- “It’s a technical problem.” The technical layer has answers, in negotiation and crypto-agility. What’s missing is an alliance-level requirement that would make those answers unnecessary.
Questions people ask
Does NATO require its members to use specific post-quantum algorithms? Not in anything published. The Quantum Technologies Strategy summary of 16 January 2024 frames both the cryptographic transition and the interoperability standards as desired outcomes, and the implementation language is about allies supporting each other through NATO committees rather than about a binding requirement.
Will a US and a UK military system be able to talk after both migrate? They will if their configurations overlap. CNSA 2.0 requires ML-KEM-1024 and ML-DSA-87 at every level while UK guidance recommends ML-KEM-768 and ML-DSA-65 for general use, so two strictly compliant systems can fail to find a shared configuration even though both are fully migrated.
Isn’t this just the normal interoperability problem? The mechanics are the same and the constraint is different. Commercial systems negotiate down to whatever they share; national-security systems have a floor below which connecting is prohibited, so the usual escape route is closed.
Which country’s deadline governs a joint program? In procurement terms, the earliest binding one, which today is the US acquisition gate of 1 January 2027. In security terms, the last participant to migrate, because a shared link is only as protected as its weakest endpoint.
Does hybrid deployment help or hurt coalition interoperability? It helps during the transition, by keeping a classical fallback available that partially migrated peers can meet, and the UK names interoperability as one of the three circumstances warranting it. It stops helping once a quantum computer exists, at which point the classical half protects nothing.
Why did the alliance coordinate on algorithms but not on parameters? The algorithms came from an open international standardization process that produced a single published answer. Parameter selection, hybrid policy, and timelines were left to national authorities, each of which answered according to its own risk posture, which is the divergence documented in ANSSI vs BSI vs NCSC vs NSA on Hybrid.
Are non-NATO alignments a factor? Yes, and they widen the problem. The US and its allies have largely converged on the NIST algorithms, while some other states are pursuing national algorithm sets, so cross-bloc communications face a divergence at the algorithm layer rather than only at the parameter layer.
What would actually close the gap? An alliance-level configuration profile for shared systems, which is a narrower thing than harmonized national policy. Countries can keep different domestic requirements and still agree a common profile for joint networks, and that separation is what makes the problem tractable without anyone abandoning their national position.
The map is free and I keep it that way. When these divergent requirements have to be reconciled inside a specific program with specific partners and specific equipment already in the field, that’s the work I do at LaMarr Labs.
Go deeper
- ANSSI vs BSI vs NCSC vs NSA on Hybrid for the four national positions compared line by line
- Cryptographic Interoperability for the technical failure modes underneath this
- NSA CNSA 2.0 for the US national-security requirement and its dates
- Crypto-Agility for the one property all these authorities agree on
- The Mandates MOC for the full regulatory picture
Last verified 2026-08-02 · Maintained by Addie LaMarr, LaMarr Labs.