organization
NIST Post-Quantum Cryptography project
Also known as NIST PQC, NIST PQC standardization, Post-Quantum Cryptography Standardization
The NIST Post-Quantum Cryptography project is the US standards agency's open process, begun in 2016, to select public-key algorithms that resist quantum computers.[1] It produced the first three post-quantum standards in August 2024, picked HQC as a backup in 2025, and as of October 2026 is still finalizing HQC and FN-DSA and evaluating more signature schemes.[2][3][4][5]
Key facts
What it is
The Post-Quantum Cryptography (PQC) project at the US National Institute of Standards and Technology (NIST) is the main source of the post-quantum algorithms now being deployed worldwide. NIST launched it in 2016 and that year asked cryptographers to submit algorithms that would resist both classical and quantum computers.[1] By the deadline, 69 candidates met the requirements. NIST then published them so experts could try to break them, narrowing the field over several rounds.[1] NIST says it assessed 82 algorithms from 25 countries in total.[6]
What it has produced
On 13 August 2024 NIST published three Federal Information Processing Standards:[2]
- FIPS 203, ml-kem, a key-encapsulation mechanism derived from CRYSTALS-Kyber, for establishing shared keys.[7][8]
- FIPS 204, ml-dsa, a lattice-based signature scheme derived from CRYSTALS-Dilithium.[7]
- FIPS 205, slh-dsa, a hash-based signature scheme derived from SPHINCS+, meant as a backup in case ML-DSA proves vulnerable.[7][9]
NIST urged administrators to begin integrating the standards immediately, because full integration would take time.[10] In March 2025 it selected hqc, a code-based algorithm, as a backup for ML-KEM.[3]
Supporting guidance followed. SP 800-227 on using KEMs securely appeared in September 2025.[11] A draft of SP 800-230, adding SLH-DSA parameter sets for limited-signature use cases, came out in April 2026.[12] The project’s draft transition plan, IR 8547, proposes deprecating today’s 112-bit RSA and elliptic-curve algorithms after 2030 and disallowing quantum-vulnerable algorithms after 2035.[13] As of October 2026 that plan was still an initial public draft.[14]
Still in progress
As of its August 2026 update, NIST’s project page said standardization of the Falcon signature scheme (to be named FN-DSA in FIPS 206) and of HQC was still underway.[4][15] NIST had planned an HQC draft about a year after March 2025 and a final standard in 2027.[16]
A separate track looks for additional signature schemes that could back up ML-DSA or suit special use cases.[17] In May 2026 NIST advanced nine candidates to that track’s third round.[5]
Why it matters
NIST standards set the baseline for US federal systems and much of global industry. The June 2026 US executive order on post-quantum migration requires federal systems to move to NIST-approved PQC standards. It also directs a rule requiring federal contractors to comply with NIST’s FIPS by the end of 2030.[18][19] The order also asks NIST to run a migration pilot on its own systems, due by the end of 2027.[20] For how deployment is going, see hybrid-post-quantum-tls.
The fourth round
After choosing its first algorithms, NIST began a fourth round in July 2022. It studied four key-establishment candidates based on maths different from ML-KEM: BIKE, Classic McEliece, HQC and SIKE.[21] SIKE was broken by a classical attack during the round.[22] NIST chose HQC over BIKE because its analysis of HQC’s decryption failure rate was more mature, and HQC needed no further changes.[23] Classic McEliece was dropped because it is under consideration at ISO and parallel standards risked incompatibility. NIST said it may base a standard on the ISO version once that is complete.[24] The round shows how the project works: candidates are published, attacked in the open, and kept only if they survive.[1]
Questions readers ask
How did NIST choose the algorithms?
It asked cryptographers worldwide to submit algorithms in 2016, received 69 candidates that met its requirements, and published them for open analysis over several rounds.[1]
Is the NIST process finished?
No. As of August 2026 NIST said the Falcon (FN-DSA) and HQC standards were still underway, and nine additional signature candidates entered a third round in May 2026.[4][5]
Should organizations wait for HQC?
No. NIST said organizations should keep migrating to the standards finalized in 2024; HQC is a backup.[25]
Sources
Each numbered claim is a statement we checked against the sources listed with it. Status shows how well established it is.
- [1]
NIST launched its Post-Quantum Cryptography project in 2016 and received 69 candidate algorithms that met its submission requirements, which cryptographers then analyzed over several rounds. confirmedas of 2026-10-10
- What Is Post-Quantum Cryptography? · NIST (retrieved 2026-10-10)
- What Is Post-Quantum Cryptography? · NIST (retrieved 2026-10-10)
- [2]
On 13 August 2024 NIST published its first three finalized post-quantum standards, FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA). confirmedas of 2024-08-13
- NIST Releases First 3 Finalized Post-Quantum Encryption Standards · NIST · 2024-08-13 (retrieved 2026-10-10)
- Post-Quantum Cryptography project page (updated August 5, 2026) · NIST Computer Security Resource Center (retrieved 2026-10-10)
- [3]
On 11 March 2025 NIST selected HQC as a backup to ML-KEM for general encryption, built on error-correcting codes rather than structured lattices. confirmedas of 2025-03-11
- NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption · NIST · 2025-03-11 (retrieved 2026-10-10)
- NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption · NIST · 2025-03-11 (retrieved 2026-10-10)
- [4]
As of its August 2026 update, NIST's project page said Falcon and HQC had been selected for standardization and that the process was still underway. confirmedas of 2026-08-05
- Post-Quantum Cryptography project page (updated August 5, 2026) · NIST Computer Security Resource Center (retrieved 2026-10-10)
- [5]
On 14 May 2026 NIST announced that nine candidates advanced to the third round of its additional digital signature schemes process (NIST IR 8610). confirmedas of 2026-05-14
- Post-Quantum Cryptography project news and updates · NIST Computer Security Resource Center (retrieved 2026-10-10)
- [6]
NIST says it assessed 82 algorithms from 25 countries during the selection process. confirmedas of 2026-10-10
- What Is Post-Quantum Cryptography? · NIST (retrieved 2026-10-10)
- [7]
ML-KEM is derived from CRYSTALS-Kyber, ML-DSA from CRYSTALS-Dilithium and SLH-DSA from SPHINCS+. confirmedas of 2024-08-13
- Post-Quantum Cryptography project page (updated August 5, 2026) · NIST Computer Security Resource Center (retrieved 2026-10-10)
- [8]
A key-encapsulation mechanism (KEM) is a set of algorithms that lets two parties establish a shared secret key over a public channel; that key is then used with symmetric algorithms for encryption and authentication. confirmedas of 2024-08-13
- FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard · NIST · 2024-08-13 (retrieved 2026-10-10)
- [9]
NIST described SLH-DSA as a backup signature method in case ML-DSA proves vulnerable. confirmedas of 2024-08-13
- NIST Releases First 3 Finalized Post-Quantum Encryption Standards · NIST · 2024-08-13 (retrieved 2026-10-10)
- [10]
When it published the standards, NIST urged system administrators to start integrating them immediately because full integration would take time. confirmedas of 2024-08-13
- NIST Releases First 3 Finalized Post-Quantum Encryption Standards · NIST · 2024-08-13 (retrieved 2026-10-10)
- [11]
On 18 September 2025 NIST published SP 800-227, recommendations for implementing and using KEMs securely. confirmedas of 2025-09-18
- Post-Quantum Cryptography project news and updates · NIST Computer Security Resource Center (retrieved 2026-10-10)
- [12]
On 13 April 2026 NIST released the initial public draft of SP 800-230, adding SLH-DSA parameter sets for limited signature use cases. confirmedas of 2026-04-13
- Post-Quantum Cryptography project news and updates · NIST Computer Security Resource Center (retrieved 2026-10-10)
- [13]
NIST's draft transition plan (IR 8547, November 2024) proposes deprecating RSA and elliptic-curve algorithms at 112-bit security after 2030 and disallowing quantum-vulnerable public-key algorithms after 2035. confirmedas of 2024-11-12
- NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards · NIST · 2024-11-12 · Tables 2 and 4 (retrieved 2026-10-10)
- [14]
As of October 2026 NIST IR 8547 remained an initial public draft dated 12 November 2024. confirmedas of 2026-10-10
- NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards · NIST · 2024-11-12 (retrieved 2026-10-10)
- [15]
In August 2024 NIST said a draft FIPS 206 standard built around the FALCON algorithm would follow, with the algorithm renamed FN-DSA. confirmedas of 2024-08-13
- NIST Releases First 3 Finalized Post-Quantum Encryption Standards · NIST · 2024-08-13 (retrieved 2026-10-10)
- [16]
NIST planned a draft HQC standard about a year after March 2025, followed by a 90-day comment period and a final standard in 2027. confirmedas of 2025-03-11
- NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption · NIST · 2025-03-11 (retrieved 2026-10-10)
- [17]
NIST's additional signature process seeks schemes that could back up ML-DSA or address special use cases. confirmedas of 2026-08-05
- Post-Quantum Cryptography project page (updated August 5, 2026) · NIST Computer Security Resource Center (retrieved 2026-10-10)
- [18]
Executive Order 14412, "Securing the Nation Against Advanced Cryptographic Attacks", published in the Federal Register on 25 June 2026, makes it US policy to move federal systems to NIST's post-quantum standards and cites the risk of adversaries collecting data now to decrypt later. confirmedas of 2026-06-25
- Executive Order 14412: Securing the Nation Against Advanced Cryptographic Attacks (Federal Register 2026-12909) · Federal Register (Executive Office of the President) · 2026-06-25 (retrieved 2026-10-10)
- The White House's post-quantum executive order is an important milestone. It's time to get to work · Cloudflare · 2026-06-23 (retrieved 2026-10-10)
- [19]
The order directs the FAR Council to propose a rule requiring covered federal contractors to comply with NIST's post-quantum FIPS by 31 December 2030. confirmedas of 2026-06-25
- Executive Order 14412: Securing the Nation Against Advanced Cryptographic Attacks (Federal Register 2026-12909) · Federal Register (Executive Office of the President) · 2026-06-25 (retrieved 2026-10-10)
- [20]
The order directs NIST to run a PQC migration pilot on its own systems, to be completed by 31 December 2027. confirmedas of 2026-06-25
- Executive Order 14412: Securing the Nation Against Advanced Cryptographic Attacks (Federal Register 2026-12909) · Federal Register (Executive Office of the President) · 2026-06-25 (retrieved 2026-10-10)
- [21]
NIST's fourth round, which began in July 2022, studied four key-establishment candidates based on different maths from ML-KEM - BIKE, Classic McEliece, HQC and SIKE - and HQC was the only one chosen for standardization. confirmedas of 2025-03-11
- NIST IR 8545: Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process · NIST · 2025-03-11 (retrieved 2026-10-10)
- NIST IR 8545: Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process · NIST · 2025-03-11 (retrieved 2026-10-10)
- NIST IR 8545: Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process · NIST · 2025-03-11 (retrieved 2026-10-10)
- [22]
In 2022 researchers at KU Leuven published a classical attack that broke SIKEp434, an instance of the isogeny-based SIKE scheme then in NIST's fourth round, in about ten minutes on a single core. confirmedas of 2022-07-30
- An efficient key recovery attack on SIDH · IACR Cryptology ePrint Archive (EUROCRYPT 2023) · 2022-07-30 (retrieved 2026-10-10)
- [23]
NIST chose HQC over BIKE because its analysis of HQC's decryption failure rate, which matters for chosen-ciphertext (IND-CCA2) security, was more mature, and HQC needed no further modifications. confirmedas of 2025-03-11
- NIST IR 8545: Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process · NIST · 2025-03-11 (retrieved 2026-10-10)
- [24]
NIST dropped Classic McEliece from its process because it is under consideration at ISO and parallel standards risked incompatibility; NIST said it may develop a standard based on the ISO version later. confirmedas of 2025-03-11
- NIST IR 8545: Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process · NIST · 2025-03-11 (retrieved 2026-10-10)
- NIST IR 8545: Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process · NIST · 2025-03-11 (retrieved 2026-10-10)
- [25]
NIST told organizations to keep migrating to the 2024 standards, with HQC a backup rather than a replacement. confirmedas of 2025-03-11
- NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption · NIST · 2025-03-11 (retrieved 2026-10-10)
Revision history (2)
Created Oct 10, 2026. Last reviewed by an editor on Oct 10, 2026. Next scheduled review: Jan 10, 2027.
Cite this page
"NIST Post-Quantum Cryptography project." ContentLora, updated Oct 10, 2026. https://contentlora.com/wiki/nist-post-quantum-cryptography-project
Spotted an error? Suggest a correction or emailcorrections@contentlora.com.
Keep exploring
- ExplainerPost-quantum cryptography and security in 2026: a crash courseA sourced crash course on post-quantum cryptography: the quantum threat, NIST's new standards, deployment, migration deadlines and AI in security.
- ExplainerHow post-quantum cryptography worksLattices, hashes and codes: the math behind post-quantum algorithms, how key encapsulation and signatures work, and the trade-offs in size and safety.
- DevelopingPost-quantum cryptography and security trackerA dated, sourced timeline of post-quantum cryptography and AI security milestones: NIST standards, deployment, government deadlines, 2024-2026.
- WikiCrypto-agilityCrypto-agility is the ability to replace cryptographic algorithms without rebuilding systems. Why the post-quantum transition made it a priority.
- AnalysisHow fast must we move to post-quantum cryptography?Q-Day timing, 2029 corporate targets versus 2030-2035 government deadlines, and whether to rush new algorithms: the post-quantum migration debate.
- WikiDARPA AI Cyber Challenge (AIxCC)DARPA's two-year competition for AI systems that find and patch software vulnerabilities, won by Team Atlanta in August 2025. Results and significance.