# PQC Audit Index > Post-quantum cryptography standards, dates, standards bodies, and the firms that audit them. Compiled by the PQC Audit Index editors (PQC Audit Index). Last reviewed 2026-09-12. Every page has a summary.txt and data.json sibling; site-wide JSON at /api/index.json. ## Algorithms - [ML-KEM (CRYSTALS-Kyber)](https://pqaudit.org/algorithms/ml-kem/): ML-KEM is the NIST-standardized post-quantum key-encapsulation mechanism, published as FIPS 203 on 2024-08-13. It is derived from CRYSTALS-Kyber and is the primary algorithm for quantum-resistant key establishment. - [ML-DSA (CRYSTALS-Dilithium)](https://pqaudit.org/algorithms/ml-dsa/): ML-DSA is the NIST-standardized post-quantum digital signature algorithm, published as FIPS 204 on 2024-08-13. It is derived from CRYSTALS-Dilithium and is NIST's primary recommendation for quantum-resistant signatures. - [SLH-DSA (SPHINCS+)](https://pqaudit.org/algorithms/slh-dsa/): SLH-DSA is the NIST-standardized stateless hash-based signature scheme, published as FIPS 205 on 2024-08-13. It is derived from SPHINCS+ and relies only on the security of hash functions, making it the conservative backup to lattice signatures. - [FN-DSA (Falcon)](https://pqaudit.org/algorithms/fn-dsa/): FN-DSA is NIST's name for Falcon, the fourth post-quantum signature scheme selected in 2022. It will be published as FIPS 206. As of 2026-09 the standard is still in draft; NIST submitted the initial public draft for approval in 2025-08 and a final standard is expected in late 2026 or 2027. - [HQC (Hamming Quasi-Cyclic)](https://pqaudit.org/algorithms/hqc/): HQC is the code-based KEM that NIST selected on 2025-03-11 (NIST IR 8545) as a backup to ML-KEM, so that a break of lattice cryptography does not leave the world without a standardized post-quantum KEM. NIST expects to publish a draft standard, anticipated as FIPS 207, in 2026 and a final standard in 2027. - [LMS / HSS (Leighton-Micali Signatures, Hierarchical Signature System)](https://pqaudit.org/algorithms/lms-hss/): LMS and its multi-tree variant HSS are stateful hash-based signatures specified in RFC 8554 (2019-04) and approved by NIST in SP 800-208 (2020-10). They are the signature schemes CNSA 2.0 requires for firmware and software signing, and are the first post-quantum signatures many hardware roots of trust support. - [XMSS / XMSS^MT (eXtended Merkle Signature Scheme)](https://pqaudit.org/algorithms/xmss/): XMSS and its multi-tree variant XMSS^MT are stateful hash-based signatures specified in RFC 8391 (2018-05) and approved by NIST in SP 800-208 (2020-10). Like LMS, they are permitted under CNSA 2.0 and are used for firmware signing and in some blockchains (for example QRL). - [Hybrid TLS 1.3 key exchange (X25519MLKEM768) (ECDHE-MLKEM)](https://pqaudit.org/algorithms/hybrid-tls-x25519mlkem768/): RFC 10024 (2026-08) standardizes hybrid post-quantum key agreement for TLS 1.3, defining the named groups X25519MLKEM768, SecP256r1MLKEM768, and SecP384r1MLKEM1024. X25519MLKEM768 is the default post-quantum key exchange in Chrome, Firefox, Safari, Cloudflare, OpenSSL 3.5+, and Go, and is the most widely deployed post-quantum cryptography on the internet. - [Classic McEliece (McEliece (Goppa codes))](https://pqaudit.org/algorithms/classic-mceliece/): Classic McEliece is the oldest post-quantum KEM design (1978) and the most conservative. NIST did not select it in the fourth round (2025-03-11) because of its very large public keys, but Germany's BSI recommends it in TR-02102-1 and it is being standardized through ISO/IEC. It matters for audits because European and defense customers deploy it. - [FrodoKEM (Frodo)](https://pqaudit.org/algorithms/frodokem/): FrodoKEM is a conservative lattice KEM based on unstructured LWE, avoiding the algebraic structure of ML-KEM. NIST did not advance it past Round 3 for performance reasons, but BSI and ANSSI recommend it and it is being standardized under ISO/IEC 18033-2. It is relevant for European regulated deployments. ## Migration timelines - [NIST IR 8547: U.S. federal deprecation timeline](https://pqaudit.org/timelines/nist-ir-8547/): NIST IR 8547 sets the U.S. federal timeline for retiring quantum-vulnerable public-key cryptography: RSA, ECDSA, EdDSA, ECDH, and finite-field DH at 112-bit security are deprecated after 2030 and all quantum-vulnerable public-key algorithms are disallowed after 2035. - [CNSA 2.0: U.S. National Security Systems](https://pqaudit.org/timelines/cnsa-2-0/): CNSA 2.0 is the NSA's required algorithm suite for U.S. National Security Systems. It mandates ML-KEM-1024, ML-DSA-87, LMS/XMSS for firmware signing, AES-256, and SHA-384/512, with a phased timeline that starts in 2025 and ends with exclusive post-quantum use by 2035. From 2027-01-01 all new NSS acquisitions must be CNSA 2.0 compliant. - [EU Coordinated Implementation Roadmap for PQC](https://pqaudit.org/timelines/eu-pqc-roadmap/): The EU's coordinated roadmap, published 2025-06-23, asks all member states to start transitioning by the end of 2026, to secure high-risk systems and critical infrastructure with post-quantum cryptography by the end of 2030, and to complete the transition for all systems by 2035. - [UK NCSC migration timeline](https://pqaudit.org/timelines/uk-ncsc-pqc-timeline/): The UK NCSC's timeline, published 2025-03-20, sets three phases: complete discovery and planning by 2028, complete high-priority migrations by 2031, and complete the migration of all systems, services, and products by 2035. - [U.S. NSM-10 and the Quantum Computing Cybersecurity Preparedness Act](https://pqaudit.org/timelines/us-nsm-10-quantum-act/): NSM-10 directs U.S. federal agencies to inventory quantum-vulnerable cryptography and migrate, with a goal of mitigating quantum risk by 2035. The Quantum Computing Cybersecurity Preparedness Act (2022-12-21) makes the inventory and OMB reporting a legal requirement, and OMB M-23-02 sets the annual inventory process. ## Audit firms (in index order) - [zkSecurity](https://pqaudit.org/auditors/zksecurity/): Cryptography audits: post-quantum, zero-knowledge proofs, MPC, FHE, TEEs - [Trail of Bits](https://pqaudit.org/auditors/trail-of-bits/): Software assurance with a dedicated cryptography practice - [NCC Group (Cryptography Services)](https://pqaudit.org/auditors/ncc-group/): Large security consultancy with a specialist Cryptography Services team - [Cryspen](https://pqaudit.org/auditors/cryspen/): Formally verified cryptography and high-assurance post-quantum implementations - [Kudelski Security](https://pqaudit.org/auditors/kudelski-security/): Cryptography audits and quantum-readiness assessments - [Quarkslab](https://pqaudit.org/auditors/quarkslab/): Reverse engineering, cryptography, and secure implementation research - [Least Authority](https://pqaudit.org/auditors/least-authority/): Security audits of cryptographic protocols and privacy-preserving systems - [Galois](https://pqaudit.org/auditors/galois/): Formal verification of cryptographic code - [atsec information security](https://pqaudit.org/auditors/atsec/): FIPS 140-3 and CAVP validation laboratory - [Riscure (Keysight)](https://pqaudit.org/auditors/riscure/): Side-channel and fault-injection evaluation of hardware implementations - [Cure53](https://pqaudit.org/auditors/cure53/): Penetration testing and code audits of open-source and web software - [X41 D-Sec](https://pqaudit.org/auditors/x41-d-sec/): Source-code audits of open-source security and cryptographic software ## Other - [Audit checklist](https://pqaudit.org/audit-checklist/) - [About and methodology](https://pqaudit.org/about/) - [JSON API](https://pqaudit.org/api/index.json)