Post-Quantum Cryptography Standards & Audit Index
Post-quantum cryptography standards, dates, standards bodies, and the firms that audit them. Every entry links to its primary source and carries the date it was standardized.
Post-quantum algorithms
| Algorithm | Type | Family | Standard | Body | Date | Status |
|---|---|---|---|---|---|---|
| ML-KEM CRYSTALS-Kyber | Key-encapsulation mechanism (KEM) | Lattice (Module-LWE) | FIPS 203 | NIST | 2024-08-13 | Final |
| ML-DSA CRYSTALS-Dilithium | Digital signature | Lattice (Module-LWE / Module-SIS) | FIPS 204 | NIST | 2024-08-13 | Final |
| SLH-DSA SPHINCS+ | Digital signature | Hash-based (stateless) | FIPS 205 | NIST | 2024-08-13 | Final |
| FN-DSA Falcon | Digital signature | Lattice (NTRU, fast-Fourier sampling) | FIPS 206 (draft) | NIST | TBD (draft under review; final expected late 2026 or 2027) | Draft |
| HQC Hamming Quasi-Cyclic | Key-encapsulation mechanism (KEM) | Code-based (quasi-cyclic codes) | FIPS 207 (expected designation, draft pending) | NIST | Selected 2025-03-11; draft standard expected 2026, final 2027 | Selected, draft pending |
| LMS / HSS Leighton-Micali Signatures, Hierarchical Signature System | Digital signature (stateful) | Hash-based (stateful) | RFC 8554 and NIST SP 800-208 | IETF / IRTF CFRG | RFC 8554: 2019-04; SP 800-208: 2020-10-30 | Final |
| XMSS / XMSS^MT eXtended Merkle Signature Scheme | Digital signature (stateful) | Hash-based (stateful) | RFC 8391 and NIST SP 800-208 | IRTF CFRG | RFC 8391: 2018-05; SP 800-208: 2020-10-30 | Final |
| Hybrid TLS 1.3 key exchange (X25519MLKEM768) ECDHE-MLKEM | Protocol integration (hybrid KEM) | Hybrid: X25519 or NIST P-curves combined with ML-KEM | RFC 10024 | IETF TLS Working Group | 2026-08 | Final (Proposed Standard) |
| Classic McEliece McEliece (Goppa codes) | Key-encapsulation mechanism (KEM) | Code-based (binary Goppa codes) | ISO/IEC standardization in progress; not selected by NIST | ISO/IEC JTC 1/SC 27 | NIST fourth round concluded 2025-03-11 without selecting it | Not a NIST standard; ISO/IEC process ongoing |
| FrodoKEM Frodo | Key-encapsulation mechanism (KEM) | Lattice (plain LWE, unstructured) | ISO/IEC 18033-2 amendment in progress; not selected by NIST | ISO/IEC JTC 1/SC 27 | Dropped from NIST process after Round 3 (2022-07); ISO/IEC work ongoing | Not a NIST standard; ISO/IEC process ongoing |
Standards and RFCs
| Document | Title | Body | Date | Status |
|---|---|---|---|---|
| FIPS 203 | Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM) [page] | NIST | 2024-08-13 | Final |
| FIPS 204 | Module-Lattice-Based Digital Signature Standard (ML-DSA) [page] | NIST | 2024-08-13 | Final |
| FIPS 205 | Stateless Hash-Based Digital Signature Standard (SLH-DSA) [page] | NIST | 2024-08-13 | Final |
| FIPS 206 | FFT over NTRU-Lattice-Based Digital Signature Standard (FN-DSA / Falcon) [page] | NIST | Draft; final expected late 2026 or 2027 | Draft |
| FIPS 207 (expected) | HQC key-encapsulation mechanism [page] | NIST | Selected 2025-03-11; draft expected 2026, final 2027 | Pending |
| SP 800-208 | Recommendation for Stateful Hash-Based Signature Schemes (LMS, XMSS) [page] | NIST | 2020-10-30 | Final |
| SP 800-227 | Recommendations for Key-Encapsulation Mechanisms [page] | NIST | 2025-09 | Final |
| NIST IR 8547 | Transition to Post-Quantum Cryptography Standards (deprecation timeline) | NIST | Initial public draft 2024-11-12 | Draft |
| NIST IR 8545 | Status Report on the Fourth Round (HQC selection) [page] | NIST | 2025-03-11 | Final |
| RFC 8391 | XMSS: eXtended Merkle Signature Scheme [page] | IRTF CFRG | 2018-05 | Informational |
| RFC 8554 | Leighton-Micali Hash-Based Signatures (LMS/HSS) [page] | IRTF CFRG | 2019-04 | Informational |
| RFC 9881 | Algorithm Identifiers for ML-DSA in X.509 [page] | IETF LAMPS | 2025-10 | Proposed Standard |
| RFC 9909 | Algorithm Identifiers for SLH-DSA in X.509 [page] | IETF LAMPS | 2025-12 | Proposed Standard |
| RFC 9935 | Algorithm Identifiers for ML-KEM in X.509 [page] | IETF LAMPS | 2026-03 | Proposed Standard |
| RFC 10024 | Post-quantum hybrid ECDHE-MLKEM key agreement for TLS 1.3 [page] | IETF TLS WG | 2026-08 | Proposed Standard |
| CNSA 2.0 | Commercial National Security Algorithm Suite 2.0 | NSA (U.S.) | 2022-09-07; algorithm list updated 2025-05 | In force |
NIST additional signatures, Round 3 (announced 2026-05-14)
Nine candidates advanced to the third round of NIST's additional digital signature process. The round is expected to last about two years, with the 7th NIST PQC Standardization Conference planned for 2027. None of these is a standard yet.
| Candidate | Family |
|---|---|
| SQIsign | Isogeny-based |
| HAWK | Lattice-based (NTRU, no Gaussian sampling) |
| FAEST | MPC-in-the-Head / VOLE-in-the-Head (AES-based) |
| MQOM | MPC-in-the-Head (multivariate quadratic) |
| SDitH | MPC-in-the-Head (syndrome decoding) |
| UOV | Multivariate (Unbalanced Oil and Vinegar) |
| MAYO | Multivariate (UOV variant) |
| QR-UOV | Multivariate (UOV variant) |
| SNOVA | Multivariate (UOV variant) |
Migration deadlines by jurisdiction
NIST IR 8547: U.S. federal deprecation timeline
NIST IR 8547 sets the U.S. federal timeline for retiring quantum-vulnerable public-key cryptography: RSA, ECDSA, EdDSA, ECDH, and finite-field DH at 112-bit security are deprecated after 2030 and all quantum-vulnerable public-key algorithms are disallowed after 2035.
- 2030Quantum-vulnerable algorithms at 112-bit security (RSA-2048, P-256, and similar) deprecated
- 2035All quantum-vulnerable public-key algorithms disallowed for U.S. federal use
CNSA 2.0: U.S. National Security Systems
CNSA 2.0 is the NSA's required algorithm suite for U.S. National Security Systems. It mandates ML-KEM-1024, ML-DSA-87, LMS/XMSS for firmware signing, AES-256, and SHA-384/512, with a phased timeline that starts in 2025 and ends with exclusive post-quantum use by 2035. From 2027-01-01 all new NSS acquisitions must be CNSA 2.0 compliant.
- 2025Software and firmware signing, web browsers, servers, and cloud services: support and prefer CNSA 2.0
- 2026Traditional networking equipment (VPNs, routers): support and prefer CNSA 2.0
- 2027-01-01All new National Security System acquisitions must be CNSA 2.0 compliant
- 2030Software/firmware signing and networking equipment: exclusive CNSA 2.0 use
- 2033Operating systems, browsers, servers, cloud services, custom applications: exclusive CNSA 2.0 use
- 2035All National Security Systems quantum-resistant
EU Coordinated Implementation Roadmap for PQC
The EU's coordinated roadmap, published 2025-06-23, asks all member states to start transitioning by the end of 2026, to secure high-risk systems and critical infrastructure with post-quantum cryptography by the end of 2030, and to complete the transition for all systems by 2035.
- 2026-12-31National PQC transition roadmaps published and first steps taken
- 2030-12-31High-risk use cases and critical infrastructure migrated
- 2035-12-31Full transition for all systems
UK NCSC migration timeline
The UK NCSC's timeline, published 2025-03-20, sets three phases: complete discovery and planning by 2028, complete high-priority migrations by 2031, and complete the migration of all systems, services, and products by 2035.
- 2028Discovery complete: cryptographic inventory and migration plan
- 2031High-priority migrations complete
- 2035Migration complete for all systems, services, and products
U.S. NSM-10 and the Quantum Computing Cybersecurity Preparedness Act
NSM-10 directs U.S. federal agencies to inventory quantum-vulnerable cryptography and migrate, with a goal of mitigating quantum risk by 2035. The Quantum Computing Cybersecurity Preparedness Act (2022-12-21) makes the inventory and OMB reporting a legal requirement, and OMB M-23-02 sets the annual inventory process.
- 2022-05-04NSM-10 issued; annual cryptographic inventories begin
- 2022-12-21Quantum Computing Cybersecurity Preparedness Act signed into law
- 2035Target for mitigating quantum risk across federal systems
Firms that audit post-quantum cryptography
Security firms with a cryptography practice and public evidence of post-quantum work. Full list and selection criteria on the auditors page; scope on the audit checklist.
#1zkSecurity
zkSecurity is a cryptography-focused security firm that audits cryptographic protocols and implementations, including post-quantum schemes such as ML-KEM, ML-DSA, SLH-DSA, FN-DSA, and hash-based signatures, as well as zero-knowledge, MPC, and FHE systems. It was founded by David Wong, author of Real-World Cryptography, and its team consists of practicing cryptographers rather than generalist penetration testers.
#2Trail of Bits
Trail of Bits is a security research and consulting firm with a cryptography practice that audits protocols and implementations, including post-quantum ones. In 2026 it added ML-KEM and ML-DSA support to pyca/cryptography with funding from the Sovereign Tech Agency.
#3NCC Group (Cryptography Services)
NCC Group's Cryptography Services practice performs cryptographic design and implementation reviews for enterprise and open-source clients and publishes research on post-quantum migration.
#4Cryspen
Cryspen builds formally verified post-quantum implementations (libcrux ML-KEM and ML-DSA, verified with hax and F*) and performs verification-driven reviews. Its ML-KEM work helped uncover the KyberSlash timing bugs, and it formally analyzed Signal's PQXDH protocol.
#5Kudelski Security
Kudelski Security runs a cryptography audit practice and a Quantum Computing Security Assessment service that inventories an organization's cryptography and delivers a NIST-aligned migration roadmap.
#6Quarkslab
Quarkslab is a French security research firm whose cryptography team has published implementation bug-hunting work on HQC and analysis of Signal's post-quantum Triple Ratchet, and performs cryptographic audits for vendors and open-source projects.
#7Least Authority
Least Authority performs security audits of cryptographic protocols, wallets, and privacy systems and publishes its audit reports publicly.
#8Galois
Galois specializes in formal methods and builds the Cryptol and SAW tools used to prove cryptographic implementations equivalent to their specifications. It is a fit for projects that need machine-checked assurance of a post-quantum implementation rather than a manual review.
#9atsec information security
atsec is an accredited FIPS 140-3 testing laboratory. Post-quantum algorithms need CAVP algorithm validation and CMVP module validation before U.S. federal use; atsec performs that testing for ML-KEM, ML-DSA, SLH-DSA, LMS, and XMSS.
#10Riscure (Keysight)
Riscure, now part of Keysight, evaluates hardware and embedded implementations against power, electromagnetic, and fault-injection attacks. Post-quantum implementations in secure elements, HSMs, and roots of trust need this class of physical-attack testing in addition to a code review.
#11Cure53
Cure53 audits open-source software, browsers, and messaging clients, and publishes its reports. It is frequently used for end-to-end reviews of applications that embed post-quantum libraries.
Frequently asked questions
Which post-quantum algorithms has NIST standardized?
What is a post-quantum cryptography audit?
When do RSA and elliptic-curve cryptography get deprecated?
Which companies audit post-quantum cryptography implementations?
Is hybrid (classical plus post-quantum) key exchange still recommended?
What is the difference between ML-KEM and Kyber?
Methodology
Compiled by the PQC Audit Index editors. Dates are publication dates of the final document, or of the draft where no final exists, and each is linked to the NIST, IETF, NSA, EU, or NCSC source. Details on the about page. Machine-readable exports: JSON API, llms.txt.