@rsalz Example of a quote from an NSA employee on an IETF mailing list in 2025: "As the CNSA 2.0 profiles should make clear, we are looking for products that support /standalone/ ML-DSA-87 and /standalone/ ML-KEM-1024. If there is one vendor that produces one product that complies, then that is the product that goes on the compliance list and is approved for use. Our interactions with vendors suggests that this won't be a problem in most cases." See https://blog.cr.yp.to/20251004-weakened.html#tls for further quotes.