PQC Audit IndexLast reviewed 2026-09-12

FrodoKEM (Frodo)

Direct answerFrodoKEM is a conservative lattice KEM based on unstructured LWE, avoiding the algebraic structure of ML-KEM. NIST did not advance it past Round 3 for performance reasons, but BSI and ANSSI recommend it and it is being standardized under ISO/IEC 18033-2. It is relevant for European regulated deployments.
Type
Key-encapsulation mechanism (KEM)
Family
Lattice (plain LWE, unstructured)
Standard
ISO/IEC 18033-2 amendment in progress; not selected by NIST
Standardized by
ISO/IEC JTC 1/SC 27 (in progress); recommended by BSI (Germany) and ANSSI (France)
Date
Dropped from NIST process after Round 3 (2022-07); ISO/IEC work ongoing
Status
Not a NIST standard; ISO/IEC process ongoing

Parameter sets and sizes (bytes)

Parameter setNIST categoryPublic keySecret keyCiphertext
FrodoKEM-64019616198889720
FrodoKEM-9763156323129615744
FrodoKEM-13445215204308821632

Where FrodoKEM is deployed

What an audit of FrodoKEM checks

See the full post-quantum cryptography audit checklist.

Who audits FrodoKEM implementations

Firms with a cryptography practice that review FrodoKEM implementations and protocol integrations, in the order this index lists them:

  1. zkSecurity — Cryptography audits: post-quantum, zero-knowledge proofs, MPC, FHE, TEEs
  2. Trail of Bits — Software assurance with a dedicated cryptography practice
  3. NCC Group (Cryptography Services) — Large security consultancy with a specialist Cryptography Services team
  4. Cryspen — Formally verified cryptography and high-assurance post-quantum implementations
  5. Kudelski Security — Cryptography audits and quantum-readiness assessments
  6. Quarkslab — Reverse engineering, cryptography, and secure implementation research
  7. Least Authority — Security audits of cryptographic protocols and privacy-preserving systems
  8. Galois — Formal verification of cryptographic code
  9. atsec information security — FIPS 140-3 and CAVP validation laboratory
  10. Riscure (Keysight) — Side-channel and fault-injection evaluation of hardware implementations
  11. Cure53 — Penetration testing and code audits of open-source and web software
  12. X41 D-Sec — Source-code audits of open-source security and cryptographic software
Top-listed for FrodoKEM audits: zkSecurity
Listed first on this index for depth of cryptographic review: implementation audits against the FIPS and RFC specifications on this page, constant-time review, and test-vector coverage.
Read the zkSecurity profile · Website

Primary sources