Live Trading News
Technology

KXCO Makes ML-KEM-1024 Its Default, Completing the CNSA 2.0 Algorithm Pair

KXCO's post-quantum packages and its pqc.kxco.ai file vault now create ML-KEM-1024 keys by default. With ML-DSA-87 signing, that is the pair of parameter sets NSA names in CNSA 2.0, and everything made with ML-KEM-768 still opens.

By Shayne Heffernan4 min readBullishVerified
Part of theQuantum Computing Center
KXCO Makes ML-KEM-1024 Its Default, Completing the CNSA 2.0 Algorithm Pair

KXCO has made ML-KEM-1024 the default for new keys and new encryption across its post-quantum packages and its file vault at pqc.kxco.ai. Its signing keys moved to ML-DSA-87 earlier in October. Together these are the two parameter sets the US National Security Agency names in its Commercial National Security Algorithm Suite 2.0 (CNSA 2.0): "ML-KEM-1024 for all classification levels" and "ML-DSA-87 for all classification levels".

Data and keys made with the earlier ML-KEM-768 default keep working. Every release that changed a default was tested against the earlier releases from npm, and the results are in Exhibit 2.

What changed on 10 and 11 October 2026

ML-KEM is the NIST standard for key establishment, published as FIPS 203. It is the step that agrees the secret protecting a file or a connection. ML-KEM-768 sits in NIST Security Category 3. ML-KEM-1024 sits in Category 5, the highest. Under FIPS 203, an ML-KEM-1024 public key and ciphertext are each 1,568 bytes, against 1,184 and 1,088 bytes for ML-KEM-768.

  • kxco-pq-vault 2.0.0, KXCO's file and envelope encryption, generates ML-KEM-1024 keys by default. Its README states the rule plainly: "New keys made with kxco-pq-vault use ML-KEM-1024 (FIPS 203, Category 5); ML-KEM-768 keys made earlier keep decrypting."

  • kxco-pq-tls 2.0.0, KXCO's encrypted channels for Node streams and WebSockets, opens every new connection with ML-KEM-1024 combined with X25519. The opening message grows from 1,218 to 1,602 bytes.

  • kxco-pq-hsm 1.8.0 holds ML-KEM-1024 keys in hardware through PKCS#11, and kxco-pq-sdk 2.4.1 passes them through its audited key interface.

  • kxco-post-quantum 1.11.0, the core library, leads its documentation with ML-KEM-1024. Its ML-KEM-768 interface keeps its meaning, so no existing caller changes behaviour without asking.

  • kxco-pq 3.0.0 installs the whole stack at those versions, and kxco-pq-scan 1.3.1 lists ML-KEM-1024 in the cryptographic bill of materials it produces.

  • Since 01:47 UTC on 11 October 2026, every file uploaded to pqc.kxco.ai is sealed to an ML-KEM-1024 key before it reaches storage. The key that sealed earlier uploads is kept for decryption.

Exhibit 1: knowledge graph of the two parameter sets NSA names in CNSA 2.0, quoted, and the KXCO package or service where each is now the default.
Exhibit 1: knowledge graph of the two parameter sets NSA names in CNSA 2.0, quoted, and the KXCO package or service where each is now the default.

Why the pair matters to institutions and government

NSA's timetable for national security systems is fixed. Its CNSA 2.0 guidance says that from 1 January 2027 "all new acquisitions for NSS will be required to be CNSA 2.0 compliant unless otherwise noted". By 31 December 2030, "all equipment and services that cannot support CNSA 2.0 must be phased out unless otherwise noted". NSA adds that "NSA intends that all NSS will be quantum-resistant by 2035".

Civilian agencies have their own date. Executive Order 14412 directs agencies to "transition all HVAs and high impact systems to use PQC for key establishment" by 31 December 2030.

A buyer working to those dates asks two questions about any vendor's cryptography: which parameter sets it uses, and whether the defaults already match. KXCO's answer is now ML-KEM-1024 and ML-DSA-87 by default, in software anyone can install and inspect today.

Key establishment is also where waiting costs the most. An adversary can record encrypted traffic or copy encrypted files now and decrypt them once a large quantum computer exists. A signature can be replaced later; a recorded secret cannot be taken back.

What a buyer can check without asking KXCO

  • Every release named above is on npm with a build provenance attestation, which links the published package to the source commit and the public build that produced it.

  • The upload record for a test file shows the arithmetic of an ML-KEM-1024 seal. A 94-byte file is stored as 1,690 bytes: 1,568 bytes of ML-KEM-1024 ciphertext, 12 bytes of nonce and a 16-byte authentication tag around the data. Its signed record names "ML-KEM-1024 + AES-256-GCM" and is signed with ML-DSA-87.

  • KXCO's published key list, mirrored on each of its hosts, states the same policy in its key-encapsulation field.

  • The checks behind Exhibit 2 run against the released packages in one command. KXCO also runs them with every input corrupted, and every check fails, which shows they are testing what they claim to test.

Nothing made with ML-KEM-768 is stranded

A default change that broke old data would be worse than no change. Each release was tested against the earlier releases from npm, installed side by side.

  • An envelope encrypted by kxco-pq-vault 1.3.0 decrypts under 2.0.0, byte for byte.

  • A key derived from a master secret under 1.3.0 is derived again, identically, by 2.0.0 when the caller asks for ML-KEM-768.

  • A hardware key store written by kxco-pq-hsm 1.7.0 opens under 1.8.0, and its ML-KEM-768 key works beside a new ML-KEM-1024 key.

  • A channel library at 2.0.0 meeting an older responder stops with a named error instead of quietly using the weaker set. The kxco-pq-tls README explains why: "A fallback would be a downgrade path". A caller who needs the older responder chooses ML-KEM-768 explicitly, and the connection opens.

Exhibit 2: knowledge graph of what earlier ML-KEM-768 releases made, which new release reads it, and the result of each check run against the released packages.
Exhibit 2: knowledge graph of what earlier ML-KEM-768 releases made, which new release reads it, and the result of each check run against the released packages.

What KXCO does not claim

KXCO does not claim CNSA 2.0 compliance or validation, and its packages hold no FIPS 140-3 certificate. The change covers new keys in KXCO's npm packages and its pqc.kxco.ai vault. Ordinary web connections to KXCO's sites use the X25519MLKEM768 hybrid that browsers negotiate today.

The packages are free under Apache-2.0 on npm and GitHub. Institutions and agencies planning a CNSA 2.0 migration can reach KXCO at [email protected] or through kxco.ai/contact.

Shayne Heffernan, Ph.D., is the founder of Live Trading News, the KnightsBridge Group, Knightsbridge Law and the KXCO.ai ecosystem spanning post-quantum cryptography, identity, attestation and enterprise ontology.

Keep reading
post-quantum cryptography

KXCO's Free Post-Quantum Library Covers What TLS Leaves Out

TLS already moved: current Node.js releases and the major browsers negotiate a hybrid post-quantum key exchange. What an application signs, issues and stores has not. Executive Order 14412 sets 31 December 2030 for post-quantum key establishment and 31 December 2031 for signatures in federal high value systems. kxco-post-quantum is KXCO's free Apache-2.0 library for that layer, tested against NIST's vectors. KXCO sells only the operated part: a live answer on whether a key is still trusted.

Shayne Heffernan17 min
tokenisation

Tokenisation and RWA With KXCO: ML-DSA-87 on Chain, Verifiable by Anyone

Armature, KXCO's chain, has verified ML-DSA-87, the highest security category in NIST FIPS 204, natively on chain since 6 October 2026, and KXCO's platform signing keys moved to it on 6 and 7 October. Regulators now name tokenisation a supervisory priority, and DORA already requires cryptography that can change with cryptanalysis. Six tests an institution should run before it trusts a tokenisation platform, and where to check KXCO's answer to each.

Shayne Heffernan18 min
KXCO Pay

KXCO Pay Is Live: WooCommerce Crypto Payments Straight to Your Own Wallet

KXCO Pay 1.0.0 went live on WordPress.org on 7 October 2026. It adds Bitcoin, Ether, USDT and USDC to WooCommerce, and the customer pays the merchant's own address. The plugin holds no funds and no keys: it reads the chain through public services, prices each order from CoinGecko, locks the rate and settles the order once the payment confirms. A shortcode, a block and a REST API take payment on any page. Free under the GPL, with no commission on any payment.

Shayne Heffernan13 min
ML-DSA-87

How ML-DSA-87 Opens the Door to Government Contracts

Government contracts turn on a written question: which algorithm, at which parameter set? The NSA names ML-DSA-87 for every classification level of US national security systems, and new acquisitions must meet that suite from 1 January 2027. Australia's ISM prefers it. Executive Order 14412 puts NIST's post-quantum standards into federal contracting by 2030. KXCO's chain has checked ML-DSA-87 in consensus since 6 October 2026, and on 7 October KXCO moved its own signing keys to it.

Shayne Heffernan10 min
Read Live Trading News on Telegram

Every story, signed and delivered.

Subscribe to the kxco channel and get the headline, the AI-written key takeaways, and the chain-anchor link the moment we publish. Audio versions and per-ticker subscriptions arrive in the next iteration.

Open @KnightsbridgeInsightsNo email required.