technology
ML-DSA (FIPS 204)
Also known as FIPS 204, CRYSTALS-Dilithium, Dilithium, Module-Lattice-Based Digital Signature Algorithm
ML-DSA is the lattice-based digital signature algorithm NIST standardized as FIPS 204 in August 2024, derived from CRYSTALS-Dilithium, to replace RSA and elliptic-curve signatures.[1][2] Its signatures run to several kilobytes, which makes it harder to deploy than ML-KEM. In 2026 Google and Cloudflare made post-quantum authentication their priority.[3][4][5]
Key facts
What it does
ML-DSA (Module-Lattice-Based Digital Signature Algorithm) produces digital signatures. A signature shows that data has not been altered and identifies who signed it.[6] Signatures secure software updates, website certificates and logins. Today these mostly use RSA or elliptic-curve algorithms, which a large quantum computer could forge.[7]
How it works
Like ml-kem, ML-DSA is built on the Module Learning With Errors problem. NIST says it is believed secure, and strongly unforgeable, even against an attacker with a large-scale fault-tolerant quantum computer.[6] FIPS 204 defines three parameter sets. Public keys are 1,312, 1,952 and 2,592 bytes, and signatures 2,420, 3,309 and 4,627 bytes.[3] Certificates carry several signatures and keys, which is why the UK NCSC treats the Web PKI as one of the hardest parts of the migration.[8]
Deployment
Signatures face no “harvest now, decrypt later” risk. An attacker can only forge a signature once a quantum computer exists.[9] Early post-quantum deployments such as Chrome’s focused on key exchange.[10] In 2026 priorities shifted. Google said it had adjusted its threat model to prioritize authentication and digital signatures, and that Android 17 is integrating ML-DSA.[4][11] Cloudflare set 2029 as its target for full post-quantum security including authentication.[5] OpenSSL has shipped ML-DSA since version 3.5.[12]
The Web PKI is the system of certificate authorities and transparency logs behind every HTTPS certificate. The NCSC expects it to need more than a simple algorithm swap.[8] The June 2026 US executive order gives high-value federal systems until 31 December 2031 to adopt post-quantum signatures, a year after its deadline for key establishment.[13]
Backups and alternatives
NIST standardized slh-dsa as a hash-based backup in case ML-DSA proves vulnerable.[14] A FALCON-based standard, FN-DSA, is still in progress.[15] A separate competition is evaluating more schemes that could back up ML-DSA or serve special uses.[16][17]
Signing modes and security
FIPS 204 says ML-DSA is designed to be strongly existentially unforgeable under chosen-message attack. Its security rests on the MLWE problem and on a variant of the Module Short Integer Solution problem called SelfTargetMSIS.[18] ML-DSA-44 is claimed to meet security category 2. That drops to category 1 if the random bit generator used provides less than 192 bits of security.[19]
By default, signing is “hedged”: it mixes fresh randomness into each signature. The standard also allows a fully deterministic variant for signers that have no source of randomness. NIST warns that the deterministic variant makes side-channel attacks, especially fault attacks, harder to defend against.[20]
National-security use
NSA’s CNSA 2.0 suite lists CRYSTALS-Dilithium, the basis of ML-DSA, at its highest (Level V) parameters for all classification levels, which corresponds to ML-DSA-87. For software and firmware signing, CNSA 2.0 instead uses the stateful hash-based schemes of NIST SP 800-208.[21] NSA’s advisory expects operating systems to support and prefer CNSA 2.0 algorithms by 2027 and to use them exclusively by 2033.[22]
Questions readers ask
What is ML-DSA used for?
Digital signatures, which detect unauthorized changes to data and authenticate who signed it. It is meant to replace RSA and elliptic-curve signatures.[6][7]
How big are ML-DSA signatures?
Between 2,420 bytes (ML-DSA-44) and 4,627 bytes (ML-DSA-87), with public keys from 1,312 to 2,592 bytes.[3]
Sources
Each numbered claim is a statement we checked against the sources listed with it. Status shows how well established it is.
- [1]
On 13 August 2024 NIST published its first three finalized post-quantum standards, FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA). confirmedas of 2024-08-13
- NIST Releases First 3 Finalized Post-Quantum Encryption Standards · NIST · 2024-08-13 (retrieved 2026-10-10)
- Post-Quantum Cryptography project page (updated August 5, 2026) · NIST Computer Security Resource Center (retrieved 2026-10-10)
- [2]
ML-KEM is derived from CRYSTALS-Kyber, ML-DSA from CRYSTALS-Dilithium and SLH-DSA from SPHINCS+. confirmedas of 2024-08-13
- Post-Quantum Cryptography project page (updated August 5, 2026) · NIST Computer Security Resource Center (retrieved 2026-10-10)
- [3]
ML-DSA's three parameter sets, ML-DSA-44, ML-DSA-65 and ML-DSA-87, have public keys of 1,312, 1,952 and 2,592 bytes and signatures of 2,420, 3,309 and 4,627 bytes. confirmedas of 2024-08-13
- FIPS 204: Module-Lattice-Based Digital Signature Standard · NIST · 2024-08-13 · Table 2 (retrieved 2026-10-10)
- [4]
Google said it had adjusted its threat model to prioritize post-quantum migration of authentication services and digital signatures, and recommended other engineering teams do the same. confirmedas of 2026-03-25
- Quantum frontiers may be closer than they appear · Google · 2026-03-25 (retrieved 2026-10-10)
- [5]
On 7 April 2026 Cloudflare said it was targeting full post-quantum security, including authentication, across its entire product suite by 2029. confirmedas of 2026-04-07
- Cloudflare targets 2029 for full post-quantum security · Cloudflare · 2026-04-07 (retrieved 2026-10-10)
- [6]
ML-DSA is based on the Module Learning With Errors problem and is believed to be secure, and strongly unforgeable, even against an adversary with a large-scale fault-tolerant quantum computer. confirmedas of 2024-08-13
- FIPS 204: Module-Lattice-Based Digital Signature Standard · NIST · 2024-08-13 (retrieved 2026-10-10)
- [7]
A large-scale quantum computer would make insecure the public-key systems based on integer factorization, such as RSA, and those based on the discrete logarithm problem, which includes elliptic-curve cryptography. confirmedas of 2026-10-10
- NIST IR 8105: Report on Post-Quantum Cryptography · NIST · 2016-04-01 (retrieved 2026-10-10)
- NIST IR 8105: Report on Post-Quantum Cryptography · NIST · 2016-04-01 (retrieved 2026-10-10)
- [8]
The NCSC singles out the Web PKI, the system of certificate authorities and transparency logs, as an area where post-quantum migration will be harder than a simple algorithm swap. confirmedas of 2025-03-20
- Timelines for migration to post-quantum cryptography · UK National Cyber Security Centre · 2025-03-20 (retrieved 2026-10-10)
- [9]
Unlike encryption, authentication is not exposed to harvest-now-decrypt-later attacks; it stays secure as long as the algorithms and keys are secure at the moment authentication is performed. confirmedas of 2026-10-10
- NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards · NIST · 2024-11-12 (retrieved 2026-10-10)
- [10]
Google announced that Chrome 131 would switch from Kyber to ML-KEM, changing the TLS codepoint for hybrid post-quantum key exchange from 0x6399 (Kyber768+X25519) to 0x11EC (ML-KEM768+X25519), because minor changes in the final ML-KEM standard made it incompatible with the Kyber version deployed earlier. confirmedas of 2024-09-13
- A new path for Kyber on the web · Google Security Blog · 2024-09-13 (retrieved 2026-10-10)
- A new path for Kyber on the web · Google Security Blog · 2024-09-13 (retrieved 2026-10-10)
- [11]
Google said Android 17 is integrating post-quantum digital signature protection using ML-DSA. confirmedas of 2026-03-25
- Quantum frontiers may be closer than they appear · Google · 2026-03-25 (retrieved 2026-10-10)
- [12]
OpenSSL 3.5, released on 8 April 2025, added support for ML-KEM, ML-DSA and SLH-DSA. confirmedas of 2025-04-08
- OpenSSL 3.5 Final Release - Live · OpenSSL Library · 2025-04-08 (retrieved 2026-10-10)
- [13]
The order requires agencies to move all high value assets and high-impact systems to PQC for key establishment by 31 December 2030 and for digital signatures by 31 December 2031. confirmedas of 2026-06-25
- Executive Order 14412: Securing the Nation Against Advanced Cryptographic Attacks (Federal Register 2026-12909) · Federal Register (Executive Office of the President) · 2026-06-25 (retrieved 2026-10-10)
- Executive Order 14412: Securing the Nation Against Advanced Cryptographic Attacks (Federal Register 2026-12909) · Federal Register (Executive Office of the President) · 2026-06-25 (retrieved 2026-10-10)
- [14]
NIST described SLH-DSA as a backup signature method in case ML-DSA proves vulnerable. confirmedas of 2024-08-13
- NIST Releases First 3 Finalized Post-Quantum Encryption Standards · NIST · 2024-08-13 (retrieved 2026-10-10)
- [15]
As of its August 2026 update, NIST's project page said Falcon and HQC had been selected for standardization and that the process was still underway. confirmedas of 2026-08-05
- Post-Quantum Cryptography project page (updated August 5, 2026) · NIST Computer Security Resource Center (retrieved 2026-10-10)
- [16]
NIST's additional signature process seeks schemes that could back up ML-DSA or address special use cases. confirmedas of 2026-08-05
- Post-Quantum Cryptography project page (updated August 5, 2026) · NIST Computer Security Resource Center (retrieved 2026-10-10)
- [17]
On 14 May 2026 NIST announced that nine candidates advanced to the third round of its additional digital signature schemes process (NIST IR 8610). confirmedas of 2026-05-14
- Post-Quantum Cryptography project news and updates · NIST Computer Security Resource Center (retrieved 2026-10-10)
- [18]
FIPS 204 says ML-DSA is designed to be strongly existentially unforgeable under chosen-message attack, with security based on the MLWE problem and a variant of the Module Short Integer Solution problem called SelfTargetMSIS. confirmedas of 2024-08-13
- FIPS 204: Module-Lattice-Based Digital Signature Standard · NIST · 2024-08-13 (retrieved 2026-10-10)
- FIPS 204: Module-Lattice-Based Digital Signature Standard · NIST · 2024-08-13 (retrieved 2026-10-10)
- [19]
FIPS 204 claims security category 2 for ML-DSA-44, but says this falls to category 1 if the random bit generator used provides less than 192 bits of security. confirmedas of 2024-08-13
- FIPS 204: Module-Lattice-Based Digital Signature Standard · NIST · 2024-08-13 (retrieved 2026-10-10)
- [20]
FIPS 204's default ML-DSA signing is "hedged", mixing in fresh randomness, while a fully deterministic variant is allowed for signers without a source of randomness; NIST warns the deterministic variant makes side-channel and fault attacks harder to mitigate. confirmedas of 2024-08-13
- FIPS 204: Module-Lattice-Based Digital Signature Standard · NIST · 2024-08-13 (retrieved 2026-10-10)
- FIPS 204: Module-Lattice-Based Digital Signature Standard · NIST · 2024-08-13 (retrieved 2026-10-10)
- [21]
CNSA 2.0 lists CRYSTALS-Kyber (standardised as ML-KEM) for key establishment and CRYSTALS-Dilithium (ML-DSA) for signatures, at their highest (Level V) parameters for all classification levels, and NIST SP 800-208 hash-based signatures for software and firmware signing. confirmedas of 2022-09-07
- Announcing the Commercial National Security Algorithm Suite 2.0 (Cybersecurity Advisory PP-22-1338) · National Security Agency · 2022-09-07 · Table II, rows for CRYSTALS-Kyber and CRYSTALS-Dilithium (retrieved 2026-10-10)
- Announcing the Commercial National Security Algorithm Suite 2.0 (Cybersecurity Advisory PP-22-1338) · National Security Agency · 2022-09-07 (retrieved 2026-10-10)
- [22]
NSA's CNSA 2.0 advisory expects US national security systems to complete the move to quantum-resistant algorithms by 2035, in line with NSM-10, and sets earlier dates for using CNSA 2.0 algorithms exclusively, such as 2030 for software and firmware signing and networking equipment and 2033 for operating systems. confirmedas of 2022-09-07
- Announcing the Commercial National Security Algorithm Suite 2.0 (Cybersecurity Advisory PP-22-1338) · National Security Agency · 2022-09-07 · Timing section (archived copy) (retrieved 2026-10-10)
- Announcing the Commercial National Security Algorithm Suite 2.0 (Cybersecurity Advisory PP-22-1338) · National Security Agency · 2022-09-07 · Other requirements for NSS (archived copy) (retrieved 2026-10-10)
- Announcing the Commercial National Security Algorithm Suite 2.0 (Cybersecurity Advisory PP-22-1338) · National Security Agency · 2022-09-07 (retrieved 2026-10-10)
- Announcing the Commercial National Security Algorithm Suite 2.0 (Cybersecurity Advisory PP-22-1338) · National Security Agency · 2022-09-07 (retrieved 2026-10-10)
- [23]
ML-KEM's security rests on the difficulty of solving certain systems of noisy linear equations, the Module Learning With Errors (MLWE) problem, and it is believed to be secure even against quantum adversaries. confirmedas of 2024-08-13
- FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard · NIST · 2024-08-13 (retrieved 2026-10-10)
Revision history (2)
- Page created.
- Added signing modes, security basis, security categories and national-security requirements.
Created Oct 10, 2026. Last reviewed by an editor on Oct 10, 2026. Next scheduled review: Jan 10, 2027.
Cite this page
"ML-DSA (FIPS 204)." ContentLora, updated Oct 10, 2026. https://contentlora.com/wiki/ml-dsa
Spotted an error? Suggest a correction or emailcorrections@contentlora.com.
Keep exploring
- ExplainerHow post-quantum cryptography worksLattices, hashes and codes: the math behind post-quantum algorithms, how key encapsulation and signatures work, and the trade-offs in size and safety.
- ExplainerPost-quantum cryptography and security in 2026: a crash courseA sourced crash course on post-quantum cryptography: the quantum threat, NIST's new standards, deployment, migration deadlines and AI in security.
- AnalysisHow fast must we move to post-quantum cryptography?Q-Day timing, 2029 corporate targets versus 2030-2035 government deadlines, and whether to rush new algorithms: the post-quantum migration debate.
- WikiCrypto-agilityCrypto-agility is the ability to replace cryptographic algorithms without rebuilding systems. Why the post-quantum transition made it a priority.
- WikiHQC (Hamming Quasi-Cyclic)HQC is the code-based encryption algorithm NIST picked in 2025 as a backup to ML-KEM. Why it was chosen, its trade-offs and its standards status.
- WikiHybrid post-quantum TLS (X25519MLKEM768)How browsers and servers combine X25519 with ML-KEM to protect web traffic from future quantum decryption, and how far deployment had got by 2026.