NIST PQC standardization activities
NIST started the standardization activities to specify PQC algorithms in 2016, followed by a series of evaluation rounds. In 2022, after 3 rounds of evaluation, NIST published IR 8413 (2022-07)1, which specified 1 key encapsulation mechanism (KEM) and 3 digital signature algorithms. The former is to confidentially transmit a secret key by encapsulating (encrypting) it, and the latter is the signature algorithms that are expected to replace RSA and the elliptic curve digital signature algorithm (ECDSA).
Selected algorithms (IR 8413)
KEM
| Original name | Official standard name | Algorithm type |
| CRYSTALS-Kyber | ML-KEM2 (FIPS 203) | Lattice-based |
Signature algorithms
| Original name | Official standard name | Algorithm type |
| CRYSTALS-Dilithium | ML-DSA3 (FIPS 204)4 | Lattice-based |
| Falcon | FN-DSA5 (FIPS 206)6 | Lattice-based |
| SPHINCS+ | SLH-DSA7 (FIPS 205)8 | Hash-based |
Additional signature algorithms
After the publication of IR 8413 (i.e., at the end of the round 3 evaluation), no other signature candidate remained. To expand the signature algorithm portfolio, NIST announced a call for additional signature algorithms.9 A part of the motivation for this call was to diversify the algorithm types beyond lattice-based (except for SPHINCS+ which is hash-based). Furthermore, this call specifically mentioned algorithms that have “short signatures and fast verification.” At the time of writing, IR 8610 (2026-05) 10 announced 9 candidates, advancing to the next round of evaluation.
| Algorithm name | Algorithm type |
| FAEST | MPC-in-the-Head |
| MQOM11 | MPC-in-the-Head |
| SDitH12 | MPC-in-the-Head |
| HAWK | Lattice-based |
| MAYO | Multivariate |
| UOV13 | Multivariate-based |
| QR-UOV14 | Multivariate |
| SNOVA15 | Multivariate |
| SQIsign | Isogeny-based |
Next step of additional signature algorithms
With the publication of IR 8610, the evaluation process proceeds to the 3rd round. NIST plans to hold a conference in the first half of 2027, when the update status of the above 9 candidate algorithms are discussed toward the conclusion of the 3rd round evaluation. As the standardization selection was announced after the 3rd round in the original cycle (IR 8413), it is possible that the current 3rd round may conclude with an announcement for standardization selection of one or more additional signature algorithm(s).
Quantum-resistant math problems
As mentioned in the preceding tables, several mathematical problems are considered to be quantum computer-resistant. and resulting signature algorithms named after these mathematical problems: (1) lattice-based, (2) code-based, (3) multivariate, (4) hash-based, (5) MPC-in-the-head, and (6) isogeny-based. Each of these algorithms is distinct in its mathematical nature. We will discuss each of these mathematical problems in our future blog.
In our next blog,,,
In our next blog, we are going to talk about the characteristics of the standardized signature algorithms and some of the algorithms currently in evaluation.
- NIST, “Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process” (https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8413-upd1.pdf)
- ML-KEM: Module-Lattice-Based Key-Encapsulation Mechanism
- ML-DSA: Module-Lattice-Based Digital Signature Algorithm
- https://csrc.nist.gov/pubs/fips/204/final
- FN-DSA: FFT-over NTRU-Lattice-Based Digital Signature Algorithm
- https://csrc.nist.gov/pubs/fips/205/final
- SLH-DSA: Stateless Hash-Based Digital Signature Algorithm
- https://csrc.nist.gov/pubs/fips/205/final
- https://csrc.nist.gov/projects/pqc-dig-sig
- NIST Internal Report NIST IR 8610, Status Report on the Second Round of the Additional Digital Signature Schemes for the NIST Post-Quantum Cryptography Standardization Process, https://nvlpubs.nist.gov/nistpubs/ir/2026/NIST.IR.8610.pdf
- MQOM: MQ on my Mind
- SDitH: Syndrome Decoding in the Head
- UOV: Unbalanced Oil and Vinegar
- QR-UOV: Quotient Ring UOV
- SNOVA: Simple NOVA
Leave a Reply