Skip to main content
Skip to content
Home/Knowledge Center/NIST Post-Quantum Cryptography Standards
Standards10 min read

NIST Post-Quantum Cryptography Standards

NIST finalized three post-quantum cryptography standards in August 2024 and selected two more for forthcoming standardization. This is what organizations need to know.

Overview

NIST's post-quantum cryptography standardization program was launched in 2016 in response to the anticipated threat that large-scale quantum computers would pose to widely deployed public-key cryptography. After three rounds of public competition and evaluation, NIST finalized its first three post-quantum cryptography standards on August 13, 2024, and subsequently selected two additional algorithms for forthcoming standardization.

The finalized standards are: FIPS 203 (ML-KEM) for key encapsulation, FIPS 204 (ML-DSA) for digital signatures, and FIPS 205 (SLH-DSA) as a hash-based backup signature scheme. FN-DSA (FIPS 206, derived from FALCON) has been selected for standardization but is not yet finalized. HQC has been selected as a backup key encapsulation mechanism for algorithm diversity but is also not yet finalized.

These standards define the algorithms that organizations should plan to adopt. NIST IR 8547 provides additional guidance on migration timelines and planned deprecation of classical algorithms.

The Three Finalized Standards

NIST finalized three standards in August 2024, covering both key establishment and digital signatures.

FIPS 203: ML-KEM

The primary standard for key encapsulation. Replaces RSA and ECDH for key establishment in TLS, VPNs, SSH, and other protocols. Based on Module Learning With Errors (M-LWE). Three parameter sets: ML-KEM-512, ML-KEM-768, ML-KEM-1024.

FIPS 204: ML-DSA

The primary standard for digital signatures. Replaces ECDSA and RSA for code signing, TLS certificates, document signing, and authentication. Based on M-LWE and M-SIS. Three parameter sets: ML-DSA-44, ML-DSA-65, ML-DSA-87.

FIPS 205: SLH-DSA

A hash-based backup signature standard. Security rests only on hash function security, providing algorithm diversity independent of lattice assumptions. Larger signatures than ML-DSA. Best suited for root certificates, firmware signing, and high-assurance contexts.

Selected Algorithms Pending Finalization

Two additional algorithms have been selected for standardization but have not yet been finalized as FIPS documents.

FN-DSA (FIPS 206, based on FALCON)

A lattice-based signature scheme based on NTRU lattices and the Fast Fourier Transform. Produces smaller signatures than ML-DSA at equivalent security levels but has more complex implementation requirements. Selected for standardization as FIPS 206, which is not yet finalized.

HQC (Hamming Quasi-Cyclic)

A code-based key encapsulation mechanism selected as a backup to ML-KEM. Its security rests on the hardness of decoding random linear codes, providing algorithm diversity independent of lattice-based security assumptions. Not yet finalized.

Why Multiple Algorithms?

NIST selected algorithms from multiple mathematical families deliberately. If a weakness were discovered in one family of problems, algorithms from other families would remain secure. ML-KEM and ML-DSA are both based on lattice problems. SLH-DSA is based only on hash functions. HQC is based on error-correcting codes. FN-DSA uses NTRU lattices, distinct from the module lattices in ML-KEM and ML-DSA.

Organizations are not expected to implement all of these. NIST's guidance is to use ML-KEM for key establishment and ML-DSA for most signature applications, with SLH-DSA for high-assurance contexts. FN-DSA and HQC will be relevant once finalized, particularly for contexts where their size or performance characteristics are advantageous.

How NIST Selected These Algorithms

NIST evaluated candidate algorithms across several dimensions: security, performance, key and signature sizes, implementation properties, and deployment feasibility. The competition ran three rounds of public evaluation from 2016 to 2022, with NIST announcing the selected algorithms in July 2022 before drafting the final standards.

Security evaluation included analysis by NIST staff and the global cryptographic research community. Candidates were analyzed for security against both classical and quantum algorithms, for implementation side-channel risks, and for resistance to fault attacks. Algorithms that showed vulnerabilities during the process were eliminated.

Performance across a range of platforms, including embedded systems, smartphones, servers, and hardware accelerators, was evaluated. Algorithms that were impractical for constrained environments or required excessive computation on common hardware were deprioritized.

Compliance and Migration Implications

NSA CNSA 2.0 (September 2022) identifies ML-KEM, ML-DSA, SLH-DSA, and FN-DSA as the approved post-quantum algorithms for National Security Systems and sets a 2033 deadline for full migration. Organizations operating National Security Systems should reference CNSA 2.0 for specific requirements by algorithm and system type.

OMB M-23-02 (December 2022) directs all federal agencies to produce a cryptographic inventory and develop a migration plan to post-quantum cryptography, with initial inventory requirements due in 2023. Civilian federal agencies should reference both OMB M-23-02 and the CISA guidance for implementation requirements.

Commercial organizations are not yet subject to a universal regulatory requirement for PQC migration, but pressure from regulators, auditors, and customers is increasing. NIST's finalization of the standards removes the primary barrier to migration planning: organizations can now build against stable, production-ready specifications.

References

Frequently Asked Questions

Are the NIST PQC standards production-ready?

Yes. FIPS 203, 204, and 205 are finalized standards published in August 2024. Organizations can implement against these specifications with confidence that they will not change. FN-DSA (FIPS 206) and HQC are still in the standardization process and should not be deployed as primary algorithms until finalized.

Do I need to implement all NIST PQC algorithms?

No. For most organizations, ML-KEM for key establishment and ML-DSA for digital signatures cover the primary migration needs. SLH-DSA is added for high-assurance signing contexts. FN-DSA and HQC are additional options that become relevant once finalized.

Apply This to Your Organization

Schedule a Consultation

A post-quantum readiness specialist will walk through how these concepts apply to your specific systems, data, and timeline.