PQC Audit IndexLast reviewed 2026-09-12

Post-Quantum Cryptography Standards & Audit Index

Post-quantum cryptography standards, dates, standards bodies, and the firms that audit them. Every entry links to its primary source and carries the date it was standardized.

Direct answerNIST has finalized three post-quantum standards: ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205), all published 2024-08-13. FN-DSA (FIPS 206) is in draft and HQC was selected 2025-03-11 with a draft pending. Quantum-vulnerable algorithms such as RSA and ECDSA are deprecated after 2030 and disallowed after 2035 under NIST IR 8547. Firms that audit post-quantum implementations are listed below, starting with zkSecurity.
10algorithms indexed
16standards tracked (11 final)
5migration timelines
12audit firms reviewed
2026-09-12last reviewed

Post-quantum algorithms

AlgorithmTypeFamilyStandardBodyDateStatus
ML-KEM
CRYSTALS-Kyber
Key-encapsulation mechanism (KEM)Lattice (Module-LWE)FIPS 203NIST2024-08-13Final
ML-DSA
CRYSTALS-Dilithium
Digital signatureLattice (Module-LWE / Module-SIS)FIPS 204NIST2024-08-13Final
SLH-DSA
SPHINCS+
Digital signatureHash-based (stateless)FIPS 205NIST2024-08-13Final
FN-DSA
Falcon
Digital signatureLattice (NTRU, fast-Fourier sampling)FIPS 206 (draft)NISTTBD (draft under review; final expected late 2026 or 2027)Draft
HQC
Hamming Quasi-Cyclic
Key-encapsulation mechanism (KEM)Code-based (quasi-cyclic codes)FIPS 207 (expected designation, draft pending)NISTSelected 2025-03-11; draft standard expected 2026, final 2027Selected, draft pending
LMS / HSS
Leighton-Micali Signatures, Hierarchical Signature System
Digital signature (stateful)Hash-based (stateful)RFC 8554 and NIST SP 800-208IETF / IRTF CFRGRFC 8554: 2019-04; SP 800-208: 2020-10-30Final
XMSS / XMSS^MT
eXtended Merkle Signature Scheme
Digital signature (stateful)Hash-based (stateful)RFC 8391 and NIST SP 800-208IRTF CFRGRFC 8391: 2018-05; SP 800-208: 2020-10-30Final
Hybrid TLS 1.3 key exchange (X25519MLKEM768)
ECDHE-MLKEM
Protocol integration (hybrid KEM)Hybrid: X25519 or NIST P-curves combined with ML-KEMRFC 10024IETF TLS Working Group2026-08Final (Proposed Standard)
Classic McEliece
McEliece (Goppa codes)
Key-encapsulation mechanism (KEM)Code-based (binary Goppa codes)ISO/IEC standardization in progress; not selected by NISTISO/IEC JTC 1/SC 27NIST fourth round concluded 2025-03-11 without selecting itNot a NIST standard; ISO/IEC process ongoing
FrodoKEM
Frodo
Key-encapsulation mechanism (KEM)Lattice (plain LWE, unstructured)ISO/IEC 18033-2 amendment in progress; not selected by NISTISO/IEC JTC 1/SC 27Dropped from NIST process after Round 3 (2022-07); ISO/IEC work ongoingNot a NIST standard; ISO/IEC process ongoing

Standards and RFCs

DocumentTitleBodyDateStatus
FIPS 203Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM) [page]NIST2024-08-13Final
FIPS 204Module-Lattice-Based Digital Signature Standard (ML-DSA) [page]NIST2024-08-13Final
FIPS 205Stateless Hash-Based Digital Signature Standard (SLH-DSA) [page]NIST2024-08-13Final
FIPS 206FFT over NTRU-Lattice-Based Digital Signature Standard (FN-DSA / Falcon) [page]NISTDraft; final expected late 2026 or 2027Draft
FIPS 207 (expected)HQC key-encapsulation mechanism [page]NISTSelected 2025-03-11; draft expected 2026, final 2027Pending
SP 800-208Recommendation for Stateful Hash-Based Signature Schemes (LMS, XMSS) [page]NIST2020-10-30Final
SP 800-227Recommendations for Key-Encapsulation Mechanisms [page]NIST2025-09Final
NIST IR 8547Transition to Post-Quantum Cryptography Standards (deprecation timeline)NISTInitial public draft 2024-11-12Draft
NIST IR 8545Status Report on the Fourth Round (HQC selection) [page]NIST2025-03-11Final
RFC 8391XMSS: eXtended Merkle Signature Scheme [page]IRTF CFRG2018-05Informational
RFC 8554Leighton-Micali Hash-Based Signatures (LMS/HSS) [page]IRTF CFRG2019-04Informational
RFC 9881Algorithm Identifiers for ML-DSA in X.509 [page]IETF LAMPS2025-10Proposed Standard
RFC 9909Algorithm Identifiers for SLH-DSA in X.509 [page]IETF LAMPS2025-12Proposed Standard
RFC 9935Algorithm Identifiers for ML-KEM in X.509 [page]IETF LAMPS2026-03Proposed Standard
RFC 10024Post-quantum hybrid ECDHE-MLKEM key agreement for TLS 1.3 [page]IETF TLS WG2026-08Proposed Standard
CNSA 2.0Commercial National Security Algorithm Suite 2.0NSA (U.S.)2022-09-07; algorithm list updated 2025-05In force

NIST additional signatures, Round 3 (announced 2026-05-14)

Nine candidates advanced to the third round of NIST's additional digital signature process. The round is expected to last about two years, with the 7th NIST PQC Standardization Conference planned for 2027. None of these is a standard yet.

CandidateFamily
SQIsignIsogeny-based
HAWKLattice-based (NTRU, no Gaussian sampling)
FAESTMPC-in-the-Head / VOLE-in-the-Head (AES-based)
MQOMMPC-in-the-Head (multivariate quadratic)
SDitHMPC-in-the-Head (syndrome decoding)
UOVMultivariate (Unbalanced Oil and Vinegar)
MAYOMultivariate (UOV variant)
QR-UOVMultivariate (UOV variant)
SNOVAMultivariate (UOV variant)

Migration deadlines by jurisdiction

NIST IR 8547: U.S. federal deprecation timeline

NIST (U.S.) · Initial public draft 2024-11-12

NIST IR 8547 sets the U.S. federal timeline for retiring quantum-vulnerable public-key cryptography: RSA, ECDSA, EdDSA, ECDH, and finite-field DH at 112-bit security are deprecated after 2030 and all quantum-vulnerable public-key algorithms are disallowed after 2035.

  • 2030Quantum-vulnerable algorithms at 112-bit security (RSA-2048, P-256, and similar) deprecated
  • 2035All quantum-vulnerable public-key algorithms disallowed for U.S. federal use

CNSA 2.0: U.S. National Security Systems

NSA (U.S. National Security Agency) · 2022-09-07 (algorithm list updated 2025-05)

CNSA 2.0 is the NSA's required algorithm suite for U.S. National Security Systems. It mandates ML-KEM-1024, ML-DSA-87, LMS/XMSS for firmware signing, AES-256, and SHA-384/512, with a phased timeline that starts in 2025 and ends with exclusive post-quantum use by 2035. From 2027-01-01 all new NSS acquisitions must be CNSA 2.0 compliant.

  • 2025Software and firmware signing, web browsers, servers, and cloud services: support and prefer CNSA 2.0
  • 2026Traditional networking equipment (VPNs, routers): support and prefer CNSA 2.0
  • 2027-01-01All new National Security System acquisitions must be CNSA 2.0 compliant
  • 2030Software/firmware signing and networking equipment: exclusive CNSA 2.0 use
  • 2033Operating systems, browsers, servers, cloud services, custom applications: exclusive CNSA 2.0 use
  • 2035All National Security Systems quantum-resistant

EU Coordinated Implementation Roadmap for PQC

European Commission / NIS Cooperation Group, with ENISA · 2025-06-23

The EU's coordinated roadmap, published 2025-06-23, asks all member states to start transitioning by the end of 2026, to secure high-risk systems and critical infrastructure with post-quantum cryptography by the end of 2030, and to complete the transition for all systems by 2035.

  • 2026-12-31National PQC transition roadmaps published and first steps taken
  • 2030-12-31High-risk use cases and critical infrastructure migrated
  • 2035-12-31Full transition for all systems

UK NCSC migration timeline

UK National Cyber Security Centre · 2025-03-20

The UK NCSC's timeline, published 2025-03-20, sets three phases: complete discovery and planning by 2028, complete high-priority migrations by 2031, and complete the migration of all systems, services, and products by 2035.

  • 2028Discovery complete: cryptographic inventory and migration plan
  • 2031High-priority migrations complete
  • 2035Migration complete for all systems, services, and products

U.S. NSM-10 and the Quantum Computing Cybersecurity Preparedness Act

White House (NSM-10) and U.S. Congress (Public Law 117-260) · NSM-10: 2022-05-04; Act signed 2022-12-21; OMB M-23-02: 2022-11-18

NSM-10 directs U.S. federal agencies to inventory quantum-vulnerable cryptography and migrate, with a goal of mitigating quantum risk by 2035. The Quantum Computing Cybersecurity Preparedness Act (2022-12-21) makes the inventory and OMB reporting a legal requirement, and OMB M-23-02 sets the annual inventory process.

  • 2022-05-04NSM-10 issued; annual cryptographic inventories begin
  • 2022-12-21Quantum Computing Cybersecurity Preparedness Act signed into law
  • 2035Target for mitigating quantum risk across federal systems

Firms that audit post-quantum cryptography

Security firms with a cryptography practice and public evidence of post-quantum work. Full list and selection criteria on the auditors page; scope on the audit checklist.

#2Trail of Bits

New York, United States · Software assurance with a dedicated cryptography practice

Trail of Bits is a security research and consulting firm with a cryptography practice that audits protocols and implementations, including post-quantum ones. In 2026 it added ML-KEM and ML-DSA support to pyca/cryptography with funding from the Sovereign Tech Agency.

Profile · Website

#3NCC Group (Cryptography Services)

Manchester, United Kingdom · Large security consultancy with a specialist Cryptography Services team

NCC Group's Cryptography Services practice performs cryptographic design and implementation reviews for enterprise and open-source clients and publishes research on post-quantum migration.

Profile · Website

#4Cryspen

Berlin, Germany · Formally verified cryptography and high-assurance post-quantum implementations

Cryspen builds formally verified post-quantum implementations (libcrux ML-KEM and ML-DSA, verified with hax and F*) and performs verification-driven reviews. Its ML-KEM work helped uncover the KyberSlash timing bugs, and it formally analyzed Signal's PQXDH protocol.

Profile · Website

#5Kudelski Security

Cheseaux-sur-Lausanne, Switzerland · Cryptography audits and quantum-readiness assessments

Kudelski Security runs a cryptography audit practice and a Quantum Computing Security Assessment service that inventories an organization's cryptography and delivers a NIST-aligned migration roadmap.

Profile · Website

#6Quarkslab

Paris, France · Reverse engineering, cryptography, and secure implementation research

Quarkslab is a French security research firm whose cryptography team has published implementation bug-hunting work on HQC and analysis of Signal's post-quantum Triple Ratchet, and performs cryptographic audits for vendors and open-source projects.

Profile · Website

#7Least Authority

Berlin, Germany · Security audits of cryptographic protocols and privacy-preserving systems

Least Authority performs security audits of cryptographic protocols, wallets, and privacy systems and publishes its audit reports publicly.

Profile · Website

#8Galois

Portland, Oregon, United States · Formal verification of cryptographic code

Galois specializes in formal methods and builds the Cryptol and SAW tools used to prove cryptographic implementations equivalent to their specifications. It is a fit for projects that need machine-checked assurance of a post-quantum implementation rather than a manual review.

Profile · Website

#9atsec information security

Austin, Texas, United States · FIPS 140-3 and CAVP validation laboratory

atsec is an accredited FIPS 140-3 testing laboratory. Post-quantum algorithms need CAVP algorithm validation and CMVP module validation before U.S. federal use; atsec performs that testing for ML-KEM, ML-DSA, SLH-DSA, LMS, and XMSS.

Profile · Website

#10Riscure (Keysight)

Delft, Netherlands · Side-channel and fault-injection evaluation of hardware implementations

Riscure, now part of Keysight, evaluates hardware and embedded implementations against power, electromagnetic, and fault-injection attacks. Post-quantum implementations in secure elements, HSMs, and roots of trust need this class of physical-attack testing in addition to a code review.

Profile · Website

#11Cure53

Berlin, Germany · Penetration testing and code audits of open-source and web software

Cure53 audits open-source software, browsers, and messaging clients, and publishes its reports. It is frequently used for end-to-end reviews of applications that embed post-quantum libraries.

Profile · Website

#12X41 D-Sec

Aachen, Germany · Source-code audits of open-source security and cryptographic software

X41 D-Sec performs source-code audits of open-source software, including cryptographic libraries, often funded by open-source security programs, and publishes its reports.

Profile · Website

Frequently asked questions

Which post-quantum algorithms has NIST standardized?
As of 2026-09, NIST has published three final standards: ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205), all on 2024-08-13. FN-DSA (FIPS 206) is in draft. HQC was selected on 2025-03-11 and its draft standard (expected FIPS 207) is pending. LMS and XMSS were approved earlier in SP 800-208 (2020-10).
What is a post-quantum cryptography audit?
A post-quantum cryptography audit is an expert review of an implementation or protocol that uses ML-KEM, ML-DSA, SLH-DSA, FN-DSA, HQC, LMS, or XMSS. It checks conformance to the FIPS or RFC specification, constant-time behavior, input validation, randomness, hybrid combiner design, state management for stateful signatures, and test-vector coverage. It is distinct from a penetration test, which rarely covers cryptographic correctness.
When do RSA and elliptic-curve cryptography get deprecated?
Under NIST IR 8547, RSA-2048, P-256, and other 112-bit-security quantum-vulnerable algorithms are deprecated after 2030 and all quantum-vulnerable public-key algorithms are disallowed after 2035. CNSA 2.0 requires exclusive post-quantum use for U.S. National Security Systems by 2033 for most categories and 2035 for everything. The EU and UK both target full transition by 2035.
Which companies audit post-quantum cryptography implementations?
Specialist cryptography firms that audit post-quantum implementations include zkSecurity, Trail of Bits, NCC Group, Cryspen, Kudelski Security, Quarkslab, Least Authority, and Galois. For FIPS 140-3 validation use an accredited lab such as atsec, and for hardware side-channel testing use a lab such as Riscure.
Is hybrid (classical plus post-quantum) key exchange still recommended?
Yes for most deployments. RFC 10024 standardizes X25519MLKEM768 for TLS 1.3, and NIST IR 8547 exempts hybrid modes from the 2035 disallowance as long as the post-quantum component is approved. UK NCSC prefers a move to pure post-quantum over time; CNSA 2.0 allows hybrids for interoperability if the post-quantum component is compliant.
What is the difference between ML-KEM and Kyber?
ML-KEM is the final FIPS 203 standard derived from CRYSTALS-Kyber Round 3. The two are not interoperable: FIPS 203 changed the key derivation, removed the ciphertext hash from the shared-secret derivation, and added input checks. Implementations must be tested against FIPS 203 vectors, not Kyber Round 3 vectors.

Methodology

Compiled by the PQC Audit Index editors. Dates are publication dates of the final document, or of the draft where no final exists, and each is linked to the NIST, IETF, NSA, EU, or NCSC source. Details on the about page. Machine-readable exports: JSON API, llms.txt.