ML-KEM
CRYSTALS-Kyber
- Family
- Module-Lattice
- Purpose
- Key encapsulation
- Standard
- FIPS 203
- Parameter sets
- 512 / 768 / 1024
The default PQC key exchange. Deployed in hybrid X25519MLKEM768 across Chrome, Firefox, Cloudflare, AWS and OpenSSH.
Full profileWhat is standardized, what is still in draft, and how much of the ecosystem has actually moved.
CRYSTALS-Kyber
The default PQC key exchange. Deployed in hybrid X25519MLKEM768 across Chrome, Firefox, Cloudflare, AWS and OpenSSH.
Full profileCRYSTALS-Dilithium
Primary general-purpose PQC signature. Certificate ecosystem support is still maturing.
Full profileSPHINCS+
Conservative hash-based backup signature. Large signatures limit use to firmware and root-of-trust signing.
Full profileFALCON
Compact signatures attractive for certificates; floating-point implementation raises side-channel concerns.
Full profileHamming Quasi-Cyclic
Selected March 2025 as a code-based backup to ML-KEM in case of a lattice break. Draft expected 2026.
Full profileApproved for firmware signing only. State management makes general-purpose use hazardous.
Full profileVery large public keys, very small ciphertexts. Favored in some European long-term confidentiality guidance.
Full profileDated decisions from standards bodies and the deadlines regulators have committed to.
NIST opens the public competition to standardize quantum-resistant public-key algorithms.
SourceNSA publishes Commercial National Security Algorithm Suite 2.0, setting PQC transition timelines for national security systems.
SourceUS federal agencies directed to inventory cryptographic systems and plan migration.
ML-KEM, ML-DSA and SLH-DSA become final US federal standards.
SourceDraft guidance deprecating RSA and ECC by 2030 and disallowing them after 2035.
A code-based alternative is chosen to hedge against a structural break in lattice assumptions.
NSA requirement milestone for national security systems.
EU Member States commit to starting migration of critical infrastructure.
Falcon-based signature standard expected to be finalized.
112-bit classical public-key cryptography deprecated for federal use.
All national security systems expected to be exclusively quantum-resistant.
Classical public-key cryptography no longer permitted for federal use.