Skip to content
ContentLora

    Tip: press / anywhere to search.

    technology

    HQC (Hamming Quasi-Cyclic)

    Also known as Hamming Quasi-Cyclic

    HQC is a post-quantum key-encapsulation algorithm based on error-correcting codes, which NIST selected on 11 March 2025 as a backup to the lattice-based ML-KEM.[1] NIST planned a draft standard about a year later and a final standard in 2027; as of NIST's August 2026 update the process was still underway.[2][3]

    Editor reviewedUpdated Post-quantum cryptography and securityComputing
    Key facts

    What it is

    HQC (Hamming Quasi-Cyclic) is a post-quantum key-encapsulation mechanism, the same kind of algorithm as ml-kem. It is used to set up shared secret keys over a public network.[1][4] NIST selected it on 11 March 2025 as the fifth algorithm in its post-quantum programme. Its role is to back up ML-KEM for general encryption.[1]

    Why NIST wanted a backup

    ML-KEM rests on structured lattices. HQC rests on error-correcting codes, which NIST notes have been used in information security for decades.[1] Different math is the point. If a weakness were ever found in ML-KEM, HQC would offer a second line of defence that does not share the flaw.[1] That caution has precedent. SIKE, an isogeny-based candidate, was broken by a classical attack in 2022 after reaching NIST’s fourth round.[5] In 2024 a claimed quantum attack on Learning With Errors, the problem underneath ML-KEM, was retracted within days.[6]

    Trade-offs

    NIST said HQC is a lengthier algorithm than ML-KEM and demands more computing resources. Reviewers chose it for its clean and secure operation.[7] Because of that cost, NIST told organizations to keep migrating to the standards finalized in 2024. HQC complements ML-KEM rather than replacing it.[8]

    Standards status

    When it selected HQC, NIST said it would release a draft standard for public comment in about a year. A final standard would follow in 2027, after a 90-day comment period.[2] As of the August 2026 update to NIST’s project page, HQC and the Falcon signature scheme were both still in standardization.[3] The release of an HQC draft is one of the milestones followed in the post-quantum and security tracker. For how HQC fits among the other algorithms, see how post-quantum cryptography works and the nist-post-quantum-cryptography-project.

    How HQC was chosen

    NIST’s fourth round began in July 2022. It studied four key-establishment candidates, all based on different maths from ML-KEM: BIKE, Classic McEliece, HQC and SIKE. HQC was the only one chosen for standardization.[9] SIKE was broken during the round.[5] Between the two remaining code-based general-purpose candidates, NIST preferred HQC to BIKE. It judged the analysis of HQC’s decryption failure rate, which matters for security against chosen-ciphertext attacks, to be more mature, and HQC needed no further changes.[10] Classic McEliece was dropped from the NIST process because it is under consideration at ISO, and parallel standards risked incompatibility. NIST said it may later base a standard on the ISO version.[11]

    Sizes and performance

    HQC’s encapsulation keys are 2,249, 4,522 and 7,245 bytes, and its ciphertexts 4,497, 9,042 and 14,485 bytes, at security levels I, III and V. These are several times larger than ML-KEM’s.[12] NIST’s report noted that HQC gives faster TLS handshakes on good networks, but BIKE does better on poor ones. It added that BIKE would likely be more attractive than HQC for TLS over the web.[13] HQC’s job is insurance, not replacing ML-KEM on the web.

    Questions readers ask

    Does HQC replace ML-KEM?

    No. NIST said organizations should keep migrating to the standards finalized in 2024; HQC is a backup in case a weakness is found in ML-KEM.[8][1]

    Why pick a code-based algorithm?

    Because it uses different math. ML-KEM is built on structured lattices, while HQC is built on error-correcting codes, so one break would not take out both.[1]

    When will the HQC standard be final?

    NIST planned a final standard in 2027. As of its August 2026 update, the standardization process was still underway.[2][3]

    Sources

    Each numbered claim is a statement we checked against the sources listed with it. Status shows how well established it is.

    1. [1]

      On 11 March 2025 NIST selected HQC as a backup to ML-KEM for general encryption, built on error-correcting codes rather than structured lattices. confirmedas of 2025-03-11

    2. [2]

      NIST planned a draft HQC standard about a year after March 2025, followed by a 90-day comment period and a final standard in 2027. confirmedas of 2025-03-11

    3. [3]

      As of its August 2026 update, NIST's project page said Falcon and HQC had been selected for standardization and that the process was still underway. confirmedas of 2026-08-05

    4. [4]

      A key-encapsulation mechanism (KEM) is a set of algorithms that lets two parties establish a shared secret key over a public channel; that key is then used with symmetric algorithms for encryption and authentication. confirmedas of 2024-08-13

    5. [5]

      In 2022 researchers at KU Leuven published a classical attack that broke SIKEp434, an instance of the isogeny-based SIKE scheme then in NIST's fourth round, in about ten minutes on a single core. confirmedas of 2022-07-30

    6. [6]

      An April 2024 preprint claimed a polynomial-time quantum algorithm for the Learning With Errors problem, but within days its author reported a bug he could not fix and said the claim no longer held. confirmedas of 2024-04-19

    7. [7]

      NIST said HQC is a lengthier algorithm than ML-KEM and demands more computing resources, but that its clean and secure operation convinced reviewers it would make a worthy backup. confirmedas of 2025-03-11

    8. [8]

      NIST told organizations to keep migrating to the 2024 standards, with HQC a backup rather than a replacement. confirmedas of 2025-03-11

    9. [9]

      NIST's fourth round, which began in July 2022, studied four key-establishment candidates based on different maths from ML-KEM - BIKE, Classic McEliece, HQC and SIKE - and HQC was the only one chosen for standardization. confirmedas of 2025-03-11

    10. [10]

      NIST chose HQC over BIKE because its analysis of HQC's decryption failure rate, which matters for chosen-ciphertext (IND-CCA2) security, was more mature, and HQC needed no further modifications. confirmedas of 2025-03-11

    11. [11]

      NIST dropped Classic McEliece from its process because it is under consideration at ISO and parallel standards risked incompatibility; NIST said it may develop a standard based on the ISO version later. confirmedas of 2025-03-11

    12. [12]

      In NIST's fourth-round report, HQC's encapsulation keys are 2,249, 4,522 and 7,245 bytes and its ciphertexts 4,497, 9,042 and 14,485 bytes for security levels I, III and V, several times larger than ML-KEM's. confirmedas of 2025-03-11

    13. [13]

      NIST noted that HQC gives faster TLS handshakes when network conditions are good but BIKE does better on poor networks, and that BIKE would likely be more attractive than HQC for TLS over the web. confirmedas of 2025-03-11

    Revision history (2)
    1. Page created.
    2. Added how HQC was chosen over BIKE and Classic McEliece, its key and ciphertext sizes, and performance trade-offs.

    Created Oct 10, 2026. Last reviewed by an editor on Oct 10, 2026. Next scheduled review: Jan 10, 2027.

    Cite this page

    "HQC (Hamming Quasi-Cyclic)." ContentLora, updated Oct 10, 2026. https://contentlora.com/wiki/hqc

    Spotted an error? Suggest a correction or emailcorrections@contentlora.com.