aws AWS What's New ·

AWS Load Balancers Support RFC 9151 CNSA Security Policies

securitygovernanceawsgovernment
feature announcement

AWS Application and Network Load Balancers now support RFC 9151 compliant security policies for CNSA 1.0 TLS requirements. This enables customers to meet NSA cryptographic standards for secure communications using TLS 1.2 and 1.3. The feature is available in all AWS regions, including GovCloud and China, and supports transitional interoperability policies to minimize disruption. Customers can enable these policies by updating existing listeners or selecting them for new listeners.

  • RFC 9151 Security Policies for CNSA 1.0
  • Broader Interoperability and Gradual Transition
  • Global Availability and Cost
  • Configuration Instructions
Features (1)
  • RFC 9151 Security Policies for CNSA 1.0

    Application Load Balancers (ALB) and Network Load Balancers (NLB) now support new TLS security policies that comply with RFC 9151 and the US National Security Agency's CNSA 1.0 requirements. These policies enforce cryptographic standards for TLS 1.2 and TLS 1.3 protocols.

Enhancements (1)
  • Broader Interoperability and Gradual Transition

    Broader interoperability policies are available, allowing for a default CNSA implementation while maintaining compatibility with non-CNSA clients during their transition. This minimizes service disruption for customers migrating to RFC 9151 compliance.

Notes (2)
  • Global Availability and Cost

    This feature is available at no additional cost for ALB and NLB in all AWS Commercial Regions, the AWS GovCloud (US) Regions, and the China region.

  • Configuration Instructions

    Customers can enable these RFC 9151 compliant security policies by updating existing ALB HTTPS listeners or NLB TLS listeners, or by selecting a compliant policy when creating new listeners via the AWS Management Console, CLI, API, or SDK.

Read the original announcement →

https://aws.amazon.com/about-aws/whats-new/2026/08/aws-application-network/

Related releases