technology
HQC (Hamming Quasi-Cyclic)
Also known as Hamming Quasi-Cyclic
HQC is a post-quantum key-encapsulation algorithm based on error-correcting codes, which NIST selected on 11 March 2025 as a backup to the lattice-based ML-KEM.[1] NIST planned a draft standard about a year later and a final standard in 2027; as of NIST's August 2026 update the process was still underway.[2][3]
Key facts
What it is
HQC (Hamming Quasi-Cyclic) is a post-quantum key-encapsulation mechanism, the same kind of algorithm as ml-kem. It is used to set up shared secret keys over a public network.[1][4] NIST selected it on 11 March 2025 as the fifth algorithm in its post-quantum programme. Its role is to back up ML-KEM for general encryption.[1]
Why NIST wanted a backup
ML-KEM rests on structured lattices. HQC rests on error-correcting codes, which NIST notes have been used in information security for decades.[1] Different math is the point. If a weakness were ever found in ML-KEM, HQC would offer a second line of defence that does not share the flaw.[1] That caution has precedent. SIKE, an isogeny-based candidate, was broken by a classical attack in 2022 after reaching NIST’s fourth round.[5] In 2024 a claimed quantum attack on Learning With Errors, the problem underneath ML-KEM, was retracted within days.[6]
Trade-offs
NIST said HQC is a lengthier algorithm than ML-KEM and demands more computing resources. Reviewers chose it for its clean and secure operation.[7] Because of that cost, NIST told organizations to keep migrating to the standards finalized in 2024. HQC complements ML-KEM rather than replacing it.[8]
Standards status
When it selected HQC, NIST said it would release a draft standard for public comment in about a year. A final standard would follow in 2027, after a 90-day comment period.[2] As of the August 2026 update to NIST’s project page, HQC and the Falcon signature scheme were both still in standardization.[3] The release of an HQC draft is one of the milestones followed in the post-quantum and security tracker. For how HQC fits among the other algorithms, see how post-quantum cryptography works and the nist-post-quantum-cryptography-project.
How HQC was chosen
NIST’s fourth round began in July 2022. It studied four key-establishment candidates, all based on different maths from ML-KEM: BIKE, Classic McEliece, HQC and SIKE. HQC was the only one chosen for standardization.[9] SIKE was broken during the round.[5] Between the two remaining code-based general-purpose candidates, NIST preferred HQC to BIKE. It judged the analysis of HQC’s decryption failure rate, which matters for security against chosen-ciphertext attacks, to be more mature, and HQC needed no further changes.[10] Classic McEliece was dropped from the NIST process because it is under consideration at ISO, and parallel standards risked incompatibility. NIST said it may later base a standard on the ISO version.[11]
Sizes and performance
HQC’s encapsulation keys are 2,249, 4,522 and 7,245 bytes, and its ciphertexts 4,497, 9,042 and 14,485 bytes, at security levels I, III and V. These are several times larger than ML-KEM’s.[12] NIST’s report noted that HQC gives faster TLS handshakes on good networks, but BIKE does better on poor ones. It added that BIKE would likely be more attractive than HQC for TLS over the web.[13] HQC’s job is insurance, not replacing ML-KEM on the web.
Questions readers ask
Does HQC replace ML-KEM?
No. NIST said organizations should keep migrating to the standards finalized in 2024; HQC is a backup in case a weakness is found in ML-KEM.[8][1]
Why pick a code-based algorithm?
Because it uses different math. ML-KEM is built on structured lattices, while HQC is built on error-correcting codes, so one break would not take out both.[1]
Sources
Each numbered claim is a statement we checked against the sources listed with it. Status shows how well established it is.
- [1]
On 11 March 2025 NIST selected HQC as a backup to ML-KEM for general encryption, built on error-correcting codes rather than structured lattices. confirmedas of 2025-03-11
- NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption · NIST · 2025-03-11 (retrieved 2026-10-10)
- NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption · NIST · 2025-03-11 (retrieved 2026-10-10)
- [2]
NIST planned a draft HQC standard about a year after March 2025, followed by a 90-day comment period and a final standard in 2027. confirmedas of 2025-03-11
- NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption · NIST · 2025-03-11 (retrieved 2026-10-10)
- [3]
As of its August 2026 update, NIST's project page said Falcon and HQC had been selected for standardization and that the process was still underway. confirmedas of 2026-08-05
- Post-Quantum Cryptography project page (updated August 5, 2026) · NIST Computer Security Resource Center (retrieved 2026-10-10)
- [4]
A key-encapsulation mechanism (KEM) is a set of algorithms that lets two parties establish a shared secret key over a public channel; that key is then used with symmetric algorithms for encryption and authentication. confirmedas of 2024-08-13
- FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard · NIST · 2024-08-13 (retrieved 2026-10-10)
- [5]
In 2022 researchers at KU Leuven published a classical attack that broke SIKEp434, an instance of the isogeny-based SIKE scheme then in NIST's fourth round, in about ten minutes on a single core. confirmedas of 2022-07-30
- An efficient key recovery attack on SIDH · IACR Cryptology ePrint Archive (EUROCRYPT 2023) · 2022-07-30 (retrieved 2026-10-10)
- [6]
An April 2024 preprint claimed a polynomial-time quantum algorithm for the Learning With Errors problem, but within days its author reported a bug he could not fix and said the claim no longer held. confirmedas of 2024-04-19
- Quantum Algorithms for Lattice Problems · IACR Cryptology ePrint Archive · 2024-04-10 (retrieved 2026-10-10)
- Quantum Algorithms for Lattice Problems · IACR Cryptology ePrint Archive · 2024-04-10 (retrieved 2026-10-10)
- [7]
NIST said HQC is a lengthier algorithm than ML-KEM and demands more computing resources, but that its clean and secure operation convinced reviewers it would make a worthy backup. confirmedas of 2025-03-11
- NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption · NIST · 2025-03-11 (retrieved 2026-10-10)
- NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption · NIST · 2025-03-11 (retrieved 2026-10-10)
- [8]
NIST told organizations to keep migrating to the 2024 standards, with HQC a backup rather than a replacement. confirmedas of 2025-03-11
- NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption · NIST · 2025-03-11 (retrieved 2026-10-10)
- [9]
NIST's fourth round, which began in July 2022, studied four key-establishment candidates based on different maths from ML-KEM - BIKE, Classic McEliece, HQC and SIKE - and HQC was the only one chosen for standardization. confirmedas of 2025-03-11
- NIST IR 8545: Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process · NIST · 2025-03-11 (retrieved 2026-10-10)
- NIST IR 8545: Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process · NIST · 2025-03-11 (retrieved 2026-10-10)
- NIST IR 8545: Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process · NIST · 2025-03-11 (retrieved 2026-10-10)
- [10]
NIST chose HQC over BIKE because its analysis of HQC's decryption failure rate, which matters for chosen-ciphertext (IND-CCA2) security, was more mature, and HQC needed no further modifications. confirmedas of 2025-03-11
- NIST IR 8545: Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process · NIST · 2025-03-11 (retrieved 2026-10-10)
- [11]
NIST dropped Classic McEliece from its process because it is under consideration at ISO and parallel standards risked incompatibility; NIST said it may develop a standard based on the ISO version later. confirmedas of 2025-03-11
- NIST IR 8545: Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process · NIST · 2025-03-11 (retrieved 2026-10-10)
- NIST IR 8545: Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process · NIST · 2025-03-11 (retrieved 2026-10-10)
- [12]
In NIST's fourth-round report, HQC's encapsulation keys are 2,249, 4,522 and 7,245 bytes and its ciphertexts 4,497, 9,042 and 14,485 bytes for security levels I, III and V, several times larger than ML-KEM's. confirmedas of 2025-03-11
- NIST IR 8545: Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process · NIST · 2025-03-11 · Table 7 (HQC keys and ciphertext sizes in bytes) (retrieved 2026-10-10)
- FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard · NIST · 2024-08-13 · Table 3 (retrieved 2026-10-10)
- [13]
NIST noted that HQC gives faster TLS handshakes when network conditions are good but BIKE does better on poor networks, and that BIKE would likely be more attractive than HQC for TLS over the web. confirmedas of 2025-03-11
- NIST IR 8545: Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process · NIST · 2025-03-11 (retrieved 2026-10-10)
- NIST IR 8545: Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process · NIST · 2025-03-11 (retrieved 2026-10-10)
Revision history (2)
- Page created.
- Added how HQC was chosen over BIKE and Classic McEliece, its key and ciphertext sizes, and performance trade-offs.
Created Oct 10, 2026. Last reviewed by an editor on Oct 10, 2026. Next scheduled review: Jan 10, 2027.
Cite this page
"HQC (Hamming Quasi-Cyclic)." ContentLora, updated Oct 10, 2026. https://contentlora.com/wiki/hqc
Spotted an error? Suggest a correction or emailcorrections@contentlora.com.
Keep exploring
- ExplainerHow post-quantum cryptography worksLattices, hashes and codes: the math behind post-quantum algorithms, how key encapsulation and signatures work, and the trade-offs in size and safety.
- DevelopingPost-quantum cryptography and security trackerA dated, sourced timeline of post-quantum cryptography and AI security milestones: NIST standards, deployment, government deadlines, 2024-2026.
- WikiCrypto-agilityCrypto-agility is the ability to replace cryptographic algorithms without rebuilding systems. Why the post-quantum transition made it a priority.
- WikiHybrid post-quantum TLS (X25519MLKEM768)How browsers and servers combine X25519 with ML-KEM to protect web traffic from future quantum decryption, and how far deployment had got by 2026.
- WikiML-DSA (FIPS 204)ML-DSA, formerly CRYSTALS-Dilithium, is NIST's main post-quantum digital signature standard. How it works, its sizes and where it is deployed.
- WikiML-KEM (FIPS 203)ML-KEM, formerly CRYSTALS-Kyber, is NIST's main post-quantum key-establishment standard and the algorithm behind hybrid post-quantum TLS.