technology
SLH-DSA (FIPS 205)
Also known as FIPS 205, SPHINCS+, Stateless Hash-Based Digital Signature Algorithm
SLH-DSA is the stateless hash-based digital signature algorithm NIST standardized as FIPS 205 in August 2024, derived from SPHINCS+, as a backup in case lattice-based ML-DSA proves vulnerable.[1][2][3] It relies only on hash functions but produces signatures of 7,856 to 49,856 bytes, several times larger than ML-DSA's.[4][5]
Key facts
What it is
SLH-DSA (Stateless Hash-Based Digital Signature Algorithm) is one of the three post-quantum standards NIST published on 13 August 2024, as FIPS 205.[1] It is based on SPHINCS+, an entry in NIST’s competition.[2] Like ml-dsa, it signs data so recipients can detect tampering and confirm who signed it. Its role is different, though. NIST describes it as a backup in case ML-DSA proves vulnerable.[3]
Why hash-based matters
Most post-quantum standards rely on structured lattices. SLH-DSA relies only on the security of hash functions.[6][2] Quantum computers only weaken hash functions modestly, through Grover’s algorithm, and larger outputs compensate.[7] That independence from lattices is why NIST keeps it as a backup.[3] Attacks on candidates do happen. The isogeny-based SIKE scheme was broken in 2022 after reaching NIST’s fourth round.[8]
The trade-off
Security comes at a price in size. FIPS 205 approves 12 parameter sets, each tuned for relatively small signatures (“s”) or relatively fast signing (“f”).[4] Public keys are tiny, 32 to 64 bytes. Signatures range from 7,856 to 49,856 bytes, several times larger than ML-DSA’s 2,420 to 4,627 bytes.[4][5] Each key pair can sign up to 2^64 messages.[9]
In April 2026 NIST released a draft, SP 800-230, adding SLH-DSA parameter sets for cases where only a limited number of signatures is needed.[10]
Where it fits
SLH-DSA is supported in mainstream libraries; OpenSSL 3.5 added it alongside ML-KEM and ML-DSA in April 2025.[11] Signature size matters most where many signatures travel with each connection, as in the Web PKI, which the UK NCSC expects to be one of the hardest systems to migrate.[12] For the wider picture of how signatures are being migrated, see how post-quantum cryptography works and the migration timeline debate.
How it is built
FIPS 205 says SLH-DSA’s security relies on the presumed difficulty of finding preimages for hash functions, along with related properties of the same hash functions.[13] The scheme is assembled from hash-based building blocks: the WOTS+ one-time signature, the XMSS Merkle-tree scheme and the FORS few-time scheme, arranged in a “hypertree”. Each key pair contains billions of FORS keys, all generated pseudorandomly from a single seed.[14] Because so many keys are available, the signer does not have to keep track of which ones have been used. That is what “stateless” means.[14][9]
Stateless versus stateful
NIST already approves older, stateful hash-based signatures in SP 800-208. With those, the signer must keep a record of how often each key has been used.[15] NSA chose the SP 800-208 schemes for signing software and firmware under CNSA 2.0, a setting where keeping track of key use is practical.[15][16] SLH-DSA removes the need to track state, at the cost of the larger signatures described above.[4] For comparison, NSA expects software and firmware signing in US national security systems to use CNSA 2.0 algorithms, which for that purpose means the stateful SP 800-208 schemes, exclusively by 2030.[17][15]
Questions readers ask
Why have a second signature standard?
NIST intends SLH-DSA as a backup in case ML-DSA proves vulnerable. It is based on hash functions rather than lattices.[3][2]
What does "stateless" mean here?
FIPS 205 defines SLH-DSA as a stateless hash-based scheme, and its parameter sets are designed so that one key pair can sign up to 2^64 messages.[2][9]
What is SP 800-230?
A draft NIST publication, released in April 2026, that adds SLH-DSA parameter sets for limited-signature use cases.[10]
Sources
Each numbered claim is a statement we checked against the sources listed with it. Status shows how well established it is.
- [1]
On 13 August 2024 NIST published its first three finalized post-quantum standards, FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA). confirmedas of 2024-08-13
- NIST Releases First 3 Finalized Post-Quantum Encryption Standards · NIST · 2024-08-13 (retrieved 2026-10-10)
- Post-Quantum Cryptography project page (updated August 5, 2026) · NIST Computer Security Resource Center (retrieved 2026-10-10)
- [2]
SLH-DSA is a stateless hash-based digital signature algorithm based on SPHINCS+. confirmedas of 2024-08-13
- FIPS 205: Stateless Hash-Based Digital Signature Standard · NIST · 2024-08-13 (retrieved 2026-10-10)
- [3]
NIST described SLH-DSA as a backup signature method in case ML-DSA proves vulnerable. confirmedas of 2024-08-13
- NIST Releases First 3 Finalized Post-Quantum Encryption Standards · NIST · 2024-08-13 (retrieved 2026-10-10)
- [4]
FIPS 205 approves 12 SLH-DSA parameter sets, tuned for either small signatures ("s") or fast signing ("f"), with public keys of 32 to 64 bytes and signatures from 7,856 to 49,856 bytes. confirmedas of 2024-08-13
- FIPS 205: Stateless Hash-Based Digital Signature Standard · NIST · 2024-08-13 (retrieved 2026-10-10)
- FIPS 205: Stateless Hash-Based Digital Signature Standard · NIST · 2024-08-13 · Section 11, Table 2 (retrieved 2026-10-10)
- [5]
ML-DSA's three parameter sets, ML-DSA-44, ML-DSA-65 and ML-DSA-87, have public keys of 1,312, 1,952 and 2,592 bytes and signatures of 2,420, 3,309 and 4,627 bytes. confirmedas of 2024-08-13
- FIPS 204: Module-Lattice-Based Digital Signature Standard · NIST · 2024-08-13 · Table 2 (retrieved 2026-10-10)
- [6]
Of the four algorithms NIST first selected, three are based on structured lattices and one on hash functions, math problems experts believe are hard for both classical and quantum computers. confirmedas of 2026-10-10
- What Is Post-Quantum Cryptography? · NIST (retrieved 2026-10-10)
- [7]
Grover's algorithm gives only a quadratic speed-up against symmetric-key systems, and NIST judged that doubling the key size would be enough to preserve their security. confirmedas of 2026-10-10
- NIST IR 8105: Report on Post-Quantum Cryptography · NIST · 2016-04-01 (retrieved 2026-10-10)
- [8]
In 2022 researchers at KU Leuven published a classical attack that broke SIKEp434, an instance of the isogeny-based SIKE scheme then in NIST's fourth round, in about ten minutes on a single core. confirmedas of 2022-07-30
- An efficient key recovery attack on SIDH · IACR Cryptology ePrint Archive (EUROCRYPT 2023) · 2022-07-30 (retrieved 2026-10-10)
- [9]
The SLH-DSA parameter sets in FIPS 205 were designed for key pairs that sign up to 2^64 messages. confirmedas of 2024-08-13
- FIPS 205: Stateless Hash-Based Digital Signature Standard · NIST · 2024-08-13 · Section 11 (2^64 rendered as 264 in text extraction) (retrieved 2026-10-10)
- [10]
On 13 April 2026 NIST released the initial public draft of SP 800-230, adding SLH-DSA parameter sets for limited signature use cases. confirmedas of 2026-04-13
- Post-Quantum Cryptography project news and updates · NIST Computer Security Resource Center (retrieved 2026-10-10)
- [11]
OpenSSL 3.5, released on 8 April 2025, added support for ML-KEM, ML-DSA and SLH-DSA. confirmedas of 2025-04-08
- OpenSSL 3.5 Final Release - Live · OpenSSL Library · 2025-04-08 (retrieved 2026-10-10)
- [12]
The NCSC singles out the Web PKI, the system of certificate authorities and transparency logs, as an area where post-quantum migration will be harder than a simple algorithm swap. confirmedas of 2025-03-20
- Timelines for migration to post-quantum cryptography · UK National Cyber Security Centre · 2025-03-20 (retrieved 2026-10-10)
- [13]
FIPS 205 says SLH-DSA's security relies on the presumed difficulty of finding preimages for hash functions and related properties of those hash functions. confirmedas of 2024-08-13
- FIPS 205: Stateless Hash-Based Digital Signature Standard · NIST · 2024-08-13 (retrieved 2026-10-10)
- [14]
SLH-DSA is built from hash-based components - the WOTS+ one-time signature, the XMSS Merkle-tree scheme and the FORS few-time scheme - arranged in a hypertree, and each key pair holds billions of FORS keys generated pseudorandomly from a single seed. confirmedas of 2024-08-13
- FIPS 205: Stateless Hash-Based Digital Signature Standard · NIST · 2024-08-13 (retrieved 2026-10-10)
- FIPS 205: Stateless Hash-Based Digital Signature Standard · NIST · 2024-08-13 · Footnote 3 (exponents 2^63 to 2^68 lost in text extraction) (retrieved 2026-10-10)
- [15]
Separately from FIPS 205, NIST SP 800-208 approves stateful hash-based signature schemes, which require the signer to track key use; NSA's CNSA 2.0 picked the SP 800-208 schemes for software and firmware signing. confirmedas of 2024-08-13
- FIPS 205: Stateless Hash-Based Digital Signature Standard · NIST · 2024-08-13 (retrieved 2026-10-10)
- Announcing the Commercial National Security Algorithm Suite 2.0 (Cybersecurity Advisory PP-22-1338) · National Security Agency · 2022-09-07 (retrieved 2026-10-10)
- [16]
CNSA 2.0 lists CRYSTALS-Kyber (standardised as ML-KEM) for key establishment and CRYSTALS-Dilithium (ML-DSA) for signatures, at their highest (Level V) parameters for all classification levels, and NIST SP 800-208 hash-based signatures for software and firmware signing. confirmedas of 2022-09-07
- Announcing the Commercial National Security Algorithm Suite 2.0 (Cybersecurity Advisory PP-22-1338) · National Security Agency · 2022-09-07 · Table II, rows for CRYSTALS-Kyber and CRYSTALS-Dilithium (retrieved 2026-10-10)
- Announcing the Commercial National Security Algorithm Suite 2.0 (Cybersecurity Advisory PP-22-1338) · National Security Agency · 2022-09-07 (retrieved 2026-10-10)
- [17]
NSA's CNSA 2.0 advisory expects US national security systems to complete the move to quantum-resistant algorithms by 2035, in line with NSM-10, and sets earlier dates for using CNSA 2.0 algorithms exclusively, such as 2030 for software and firmware signing and networking equipment and 2033 for operating systems. confirmedas of 2022-09-07
- Announcing the Commercial National Security Algorithm Suite 2.0 (Cybersecurity Advisory PP-22-1338) · National Security Agency · 2022-09-07 · Timing section (archived copy) (retrieved 2026-10-10)
- Announcing the Commercial National Security Algorithm Suite 2.0 (Cybersecurity Advisory PP-22-1338) · National Security Agency · 2022-09-07 · Other requirements for NSS (archived copy) (retrieved 2026-10-10)
- Announcing the Commercial National Security Algorithm Suite 2.0 (Cybersecurity Advisory PP-22-1338) · National Security Agency · 2022-09-07 (retrieved 2026-10-10)
- Announcing the Commercial National Security Algorithm Suite 2.0 (Cybersecurity Advisory PP-22-1338) · National Security Agency · 2022-09-07 (retrieved 2026-10-10)
Revision history (2)
- Page created.
- Added how SLH-DSA is built, its security assumption and its relation to stateful hash-based signatures.
Created Oct 10, 2026. Last reviewed by an editor on Oct 10, 2026. Next scheduled review: Jan 10, 2027.
Cite this page
"SLH-DSA (FIPS 205)." ContentLora, updated Oct 10, 2026. https://contentlora.com/wiki/slh-dsa
Spotted an error? Suggest a correction or emailcorrections@contentlora.com.
Keep exploring
- ExplainerHow post-quantum cryptography worksLattices, hashes and codes: the math behind post-quantum algorithms, how key encapsulation and signatures work, and the trade-offs in size and safety.
- ExplainerPost-quantum cryptography and security in 2026: a crash courseA sourced crash course on post-quantum cryptography: the quantum threat, NIST's new standards, deployment, migration deadlines and AI in security.
- WikiCrypto-agilityCrypto-agility is the ability to replace cryptographic algorithms without rebuilding systems. Why the post-quantum transition made it a priority.
- WikiHQC (Hamming Quasi-Cyclic)HQC is the code-based encryption algorithm NIST picked in 2025 as a backup to ML-KEM. Why it was chosen, its trade-offs and its standards status.
- WikiHybrid post-quantum TLS (X25519MLKEM768)How browsers and servers combine X25519 with ML-KEM to protect web traffic from future quantum decryption, and how far deployment had got by 2026.
- WikiML-DSA (FIPS 204)ML-DSA, formerly CRYSTALS-Dilithium, is NIST's main post-quantum digital signature standard. How it works, its sizes and where it is deployed.