China's Own Post-Quantum Standards: The NGCC Program Versus NIST
The short story
The US National Institute of Standards and Technology (NIST) finished its first post-quantum standards in 2024: ML-KEM, ML-DSA and SLH-DSA. The process is described in NIST's post-quantum process. China decided to run its own parallel contest. Why that matters: the world may end up with more than one set of standards, which is exactly the problem crypto agility is meant to handle.
Timeline
- February 2025: the Institute of Commercial Cryptography Standards (ICCS), under China's cryptography standardization system, announced a global call for quantum-resistant algorithms covering public-key cryptography, hash functions and block ciphers, open to international researchers, per The Quantum Insider.
- October 9, 2025: formal calls for public-key and hash proposals, with a June 30, 2026 submission deadline, per PostQuantum. A block cipher track runs separately.
- March 2026: a leading expert said China will likely develop national post-quantum standards within about three years, per The Quantum Insider.
- September 20, 2026: ICCS reportedly published 119 round one candidates: 34 signature schemes, 41 key encapsulation mechanisms, 9 key exchange protocols and 35 hash functions.
Why not just use NIST?
Experts quoted by New Scientist, via The Quantum Insider, suggested the effort reflects distrust of US-led standards (including worries about backdoors) and a push for technological self-reliance. That is commentators' interpretation, not an official ICCS statement. NIST mathematician Dustin Moody was quoted as saying China had previously chosen algorithms similar to NIST's, that its process is less transparent, and that NIST would monitor China's work and might adopt strong Chinese algorithms if they offered enough improvement. That is a refreshingly open-minded stance.
The rules
PostQuantum reports that public-key submissions must meet three classical security strengths (128, 256 and 512 bits) with quantum-resistant strengths of at least 80, 128 and 256 bits, and that algorithms already standardized or completed by international bodies, countries or regions are excluded, which rules out the NIST standards. Submitters supplied English specifications, C reference code and test vectors. The standards would cover commercial cryptography, such as that used by banks and telecom operators. Reuters-sourced coverage cited by The Quantum Insider says finance and energy are expected early adopters.
Public cryptanalysis: the system working
Within days of publication, researchers began attacking candidates. According to PostQuantum, the site ngcc.dev run by cryptographer Markku-Juhani Saarinen listed 104 findings against 65 of the 119 candidates by September 23, 2026: 61 implementation flaws and 43 design flaws. Examples reported include a signature verifier that returned success regardless of the result, key generation that ignored the supplied random generator, and outright breaks of the Tins and Facto-DSA signature schemes and the MoFang and Neulaser hash functions.
This is not a scandal. It is the point of an open competition. NIST's own process saw candidates fall to attacks, including a famous break of a finalist-level scheme in 2022. Early rounds are supposed to be messy. The same report notes that no NGCC candidate is standardized or deployed, so no production system is affected. I am relying on a single outlet and a crowd-sourced site for round one details, so verify against ICCS publications.
What it means for you
- Nothing to do today. The algorithms protecting banks, phones and wallets are not changing because of NGCC.
- For crypto, the quantum-safe path discussed in post-quantum cryptography and crypto and whether quantum breaks Bitcoin and Solana still centers on the known, heavily studied options.
- Fragmented standards raise costs for global companies, so expect talk of interoperability.
The optimistic read
More eyes on post-quantum math is good for everyone. A global crowd stress-testing candidates in real time makes the winners stronger. The quantum threat is a shared problem, and healthy competition on defenses is a good way to meet it. Not financial advice.
Sources and further reading
- PostQuantum: NGCC round one candidate flaws
- The Quantum Insider: China launches its own quantum-resistant standards (Feb 2025)
- The Quantum Insider: China expects PQC standards within three years (Mar 2026)
Reported as of 2026-10-09. Press and company claims change, so check the primary documents before relying on any figure. Nothing here is financial advice, and the QUANTUM (QNT) memecoin is independent and has no link to any lab, company or government mentioned.
Frequently asked questions
Is China using NIST's post-quantum algorithms?
Its program excludes algorithms already standardized elsewhere, so the NIST standards are not eligible for the NGCC contest. What China will deploy is not settled.
Were the Chinese candidates broken?
Reported public review found many flaws, including outright breaks of a few schemes, within days. No candidate is standardized or deployed.
Do I need to change my crypto wallet because of this?
No. This is a standards contest, not an attack. Not financial advice.
Keep reading
- The NIST Post-Quantum Process Explained
How NIST ran its multi-year post-quantum cryptography competition, from public call to the first standards in 2024, and what work is still continuing. - ML-KEM Explained: The Post-Quantum Key Exchange Standard
ML-KEM (FIPS 203) is NIST's standard for post-quantum key encapsulation. Learn what a KEM is, how lattices fit in, and where it is used, in plain English. - Crypto Agility Explained: Preparing for Algorithm Change
Crypto agility is the ability to swap cryptographic algorithms without rebuilding a system. Learn why it matters for the post-quantum shift and for blockchains. - China's Quantum Strategy: The 15th Five-Year Plan, Zuchongzhi and Origin Wukong
What China's 2026 to 2030 plan says about quantum, how much money is really involved, and how to read claims about Zuchongzhi and Origin Wukong.
All Quantum policy and governments guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary