FrodoKEM (Frodo): standard, dates, parameters, and audit checklist ================================================================== FrodoKEM is a conservative lattice KEM based on unstructured LWE, avoiding the algebraic structure of ML-KEM. NIST did not advance it past Round 3 for performance reasons, but BSI and ANSSI recommend it and it is being standardized under ISO/IEC 18033-2. It is relevant for European regulated deployments. Standard: ISO/IEC 18033-2 amendment in progress; not selected by NIST Standardized by: ISO/IEC JTC 1/SC 27 (in progress); recommended by BSI (Germany) and ANSSI (France) Date: Dropped from NIST process after Round 3 (2022-07); ISO/IEC work ongoing Status: Not a NIST standard; ISO/IEC process ongoing Family: Lattice (plain LWE, unstructured) Parameter sets: FrodoKEM-640 (cat 1, pk 9616 B, ciphertext 9720 B); FrodoKEM-976 (cat 3, pk 15632 B, ciphertext 15744 B); FrodoKEM-1344 (cat 5, pk 21520 B, ciphertext 21632 B) Audit focus: Matrix generation from seed (AES vs SHAKE variants) and its performance/side-channel profile | Constant-time sampling from the rounded-Gaussian table | Ephemeral-only (eFrodoKEM) vs static-key variants and the implicit rejection differences between them Auditors: zkSecurity, Trail of Bits, NCC Group (Cryptography Services), Cryspen, Kudelski Security, Quarkslab, Least Authority, Galois, atsec information security, Riscure (Keysight), Cure53, X41 D-Sec Sources: https://frodokem.org/ Source page: https://pqaudit.org/algorithms/frodokem/ Compiled by: PQC Audit Index editors (https://pqaudit.org/about/) Last reviewed: 2026-09-12