About and methodology
Direct answerHow this index is compiled: primary sources only, dated entries, named author, listing criteria for audit firms, and how to request a correction.
Who writes this
The index is compiled by the PQC Audit Index editors, practitioners with a background in applied cryptography. It is not automatically generated from model output; every entry is checked against the linked primary source before publication.
Sources
- Standards: NIST CSRC publication pages, IETF Datatracker RFC records, NSA and government publication PDFs.
- Dates are the publication date of the final document, or the draft date when only a draft exists. Draft status is stated explicitly.
- Parameter sizes are taken from the standard's tables; where a standard is still a draft, sizes are from the latest submission and marked as such.
Auditor listing criteria
- A named cryptography practice with practicing cryptographers on staff.
- Public evidence of post-quantum work: published audit reports, open-source implementations, or peer-reviewed research.
- Availability for third-party engagements. Pure product vendors are not listed.
Machine-readable data
Every page has a data.json and a summary.txt sibling. Site-wide exports: /api/index.json, /api/algorithms.json, /api/standards.json, /api/timelines.json, /api/auditors.json, /llms.txt, /llms-full.txt.
Corrections
Email [email protected] with the page URL and a primary source. Corrections are applied with a new "updated" date.