Maintained technical resource

Post-Quantum Cryptography Standards Tracker

The production-ready NIST post-quantum standards are FIPS 203 for ML-KEM, FIPS 204 for ML-DSA, and FIPS 205 for SLH-DSA. FN-DSA and HQC remain under standardization, while IETF, NSA, ETSI, and BSI guidance defines how these primitives should move into protocols and enterprise migration programs.

Last verified: August 10, 2026Primary sources onlyVendor-neutral status
3finalized NIST PQC standards
2NIST algorithms in development
4standards bodies and agencies tracked
2026current verification year

NIST algorithm and transition status

“Final” means an approved NIST publication available for implementation. “In development” means selection or drafting is underway and the result must not be represented as a finalized standard.

PublicationPrimitiveStatusEnterprise interpretationPrimary source
FIPS 203ML-KEM key encapsulationFinal · Aug 2024Primary NIST-standardized mechanism for post-quantum key establishment.NIST FIPS 203
FIPS 204ML-DSA digital signaturesFinal · Aug 2024General-purpose lattice-based signature standard for authentication and integrity.NIST FIPS 204
FIPS 205SLH-DSA digital signaturesFinal · Aug 2024Stateless hash-based signature alternative with different security assumptions.NIST FIPS 205
FIPS 206FN-DSA, derived from FALCONIn developmentDo not treat FN-DSA as a finalized FIPS until NIST publishes the final standard.NIST selected algorithms
HQCCode-based backup KEMSelected · Mar 2025NIST selected HQC to diversify the KEM portfolio; ML-KEM remains the recommended general-encryption choice.NIST HQC announcement
NIST IR 8547Transition planningInitial public draftUseful for planning, but identify it as draft guidance when setting policy or deadlines.NIST IR 8547 IPD

Protocol and migration ecosystem

Algorithm publication is only the first layer. Secure adoption also depends on protocol specifications, validated implementations, procurement requirements, inventory, interoperability, and controlled migration.

BodyTracked workCurrent statusWhat teams should doPrimary source
IETFML-KEM key agreement for TLS 1.3Internet-Draft -09
IESG Last Call ending August 13, 2026
Track the Datatracker rather than freezing an implementation to an obsolete draft revision.IETF Datatracker
NSACNSA 2.0 and NSS transition resourcesPolicy guidanceUse CNSA requirements for applicable National Security Systems; do not generalize them into universal commercial mandates.NSA PQC resources
ETSIRepeatable framework for quantum-safe migrationsPublished · Oct 2024Use the framework to organize discovery, risk assessment, planning, execution, and validation.ETSI TR 104 016
BSIMigration to post-quantum cryptographyPublished guidanceEvaluate BSI’s hybrid-migration recommendations in the context of system assurance and applicable jurisdiction.BSI migration guidance

What security teams should do now

01 · Discover

Inventory cryptographic dependencies

Map algorithms, libraries, protocols, certificates, keys, owners, data lifetimes, and external dependencies before selecting replacements.

02 · Prioritize

Separate standards status from migration risk

Prioritize long-lived sensitive data and exposed key-establishment paths while tracking whether each target primitive and protocol is final or still changing.

03 · Validate

Test implementations and interoperability

Measure performance, side-channel resistance, certificate and message-size effects, rollback behavior, observability, and operational recovery before broad rollout.

Method and update policy

This tracker uses primary publications and official standards-body status pages. Drafts are labelled as drafts, and selected algorithms are not labelled as finalized standards. QuantumGenie reviews the source status before changing this page. The tracker is educational and does not replace standards text, regulator guidance, procurement requirements, or system-specific cryptographic engineering.