Standards tracker

What is standardized, what is still in draft, and how much of the ecosystem has actually moved.

NIST algorithm portfolio

ML-KEM

CRYSTALS-Kyber

Standardized
Family
Module-Lattice
Purpose
Key encapsulation
Standard
FIPS 203
Parameter sets
512 / 768 / 1024
Ecosystem readiness
5/5

The default PQC key exchange. Deployed in hybrid X25519MLKEM768 across Chrome, Firefox, Cloudflare, AWS and OpenSSH.

Full profile

ML-DSA

CRYSTALS-Dilithium

Standardized
Family
Module-Lattice
Purpose
Digital signature
Standard
FIPS 204
Parameter sets
44 / 65 / 87
Ecosystem readiness
4/5

Primary general-purpose PQC signature. Certificate ecosystem support is still maturing.

Full profile

SLH-DSA

SPHINCS+

Standardized
Family
Hash-based
Purpose
Digital signature
Standard
FIPS 205
Parameter sets
128 / 192 / 256 (s and f)
Ecosystem readiness
4/5

Conservative hash-based backup signature. Large signatures limit use to firmware and root-of-trust signing.

Full profile

FN-DSA

FALCON

Draft standard
Family
NTRU Lattice
Purpose
Digital signature
Standard
FIPS 206 (draft)
Parameter sets
512 / 1024
Ecosystem readiness
3/5

Compact signatures attractive for certificates; floating-point implementation raises side-channel concerns.

Full profile

HQC

Hamming Quasi-Cyclic

Selected for standardization
Family
Code-based
Purpose
Key encapsulation
Standard
FIPS (in development)
Parameter sets
128 / 192 / 256
Ecosystem readiness
2/5

Selected March 2025 as a code-based backup to ML-KEM in case of a lattice break. Draft expected 2026.

Full profile

XMSS / LMS

Standardized
Family
Stateful hash-based
Purpose
Digital signature
Standard
SP 800-208
Parameter sets
Parameterized
Ecosystem readiness
4/5

Approved for firmware signing only. State management makes general-purpose use hazardous.

Full profile

Classic McEliece

Under consideration
Family
Code-based
Purpose
Key encapsulation
Standard
ISO track
Parameter sets
128 / 192 / 256
Ecosystem readiness
2/5

Very large public keys, very small ciphertexts. Favored in some European long-term confidentiality guidance.

Full profile

Standards and mandate timeline

Dated decisions from standards bodies and the deadlines regulators have committed to.

  1. NIST

    PQC standardization process launched

    NIST opens the public competition to standardize quantum-resistant public-key algorithms.

    Source
  2. NSA

    CNSA 2.0 suite announced

    NSA publishes Commercial National Security Algorithm Suite 2.0, setting PQC transition timelines for national security systems.

    Source
  3. White House

    NSM-10 and Quantum Computing Cybersecurity Preparedness Act

    US federal agencies directed to inventory cryptographic systems and plan migration.

  4. NIST

    FIPS 203, 204, 205 published

    ML-KEM, ML-DSA and SLH-DSA become final US federal standards.

    Source
  5. NIST

    IR 8547 transition guidance

    Draft guidance deprecating RSA and ECC by 2030 and disallowing them after 2035.

  6. NIST

    HQC selected as backup KEM

    A code-based alternative is chosen to hedge against a structural break in lattice assumptions.

  7. CNSA 2.0

    Software and firmware signing must be PQC

    NSA requirement milestone for national security systems.

  8. EU
    Projected

    Coordinated PQC roadmap

    EU Member States commit to starting migration of critical infrastructure.

  9. NIST
    Projected

    FIPS 206 (FN-DSA) finalization

    Falcon-based signature standard expected to be finalized.

  10. NIST
    Projected

    RSA and ECC deprecated

    112-bit classical public-key cryptography deprecated for federal use.

  11. NSA
    Projected

    CNSA 2.0 full compliance

    All national security systems expected to be exclusively quantum-resistant.

  12. NIST
    Projected

    RSA and ECC disallowed

    Classical public-key cryptography no longer permitted for federal use.