China's Own Post-Quantum Standards: The NGCC Program Versus NIST

Updated | 3 min read | QUANTUM (QNT) community

The short story

The US National Institute of Standards and Technology (NIST) finished its first post-quantum standards in 2024: ML-KEM, ML-DSA and SLH-DSA. The process is described in NIST's post-quantum process. China decided to run its own parallel contest. Why that matters: the world may end up with more than one set of standards, which is exactly the problem crypto agility is meant to handle.

Timeline

Why not just use NIST?

Experts quoted by New Scientist, via The Quantum Insider, suggested the effort reflects distrust of US-led standards (including worries about backdoors) and a push for technological self-reliance. That is commentators' interpretation, not an official ICCS statement. NIST mathematician Dustin Moody was quoted as saying China had previously chosen algorithms similar to NIST's, that its process is less transparent, and that NIST would monitor China's work and might adopt strong Chinese algorithms if they offered enough improvement. That is a refreshingly open-minded stance.

The rules

PostQuantum reports that public-key submissions must meet three classical security strengths (128, 256 and 512 bits) with quantum-resistant strengths of at least 80, 128 and 256 bits, and that algorithms already standardized or completed by international bodies, countries or regions are excluded, which rules out the NIST standards. Submitters supplied English specifications, C reference code and test vectors. The standards would cover commercial cryptography, such as that used by banks and telecom operators. Reuters-sourced coverage cited by The Quantum Insider says finance and energy are expected early adopters.

Public cryptanalysis: the system working

Within days of publication, researchers began attacking candidates. According to PostQuantum, the site ngcc.dev run by cryptographer Markku-Juhani Saarinen listed 104 findings against 65 of the 119 candidates by September 23, 2026: 61 implementation flaws and 43 design flaws. Examples reported include a signature verifier that returned success regardless of the result, key generation that ignored the supplied random generator, and outright breaks of the Tins and Facto-DSA signature schemes and the MoFang and Neulaser hash functions.

This is not a scandal. It is the point of an open competition. NIST's own process saw candidates fall to attacks, including a famous break of a finalist-level scheme in 2022. Early rounds are supposed to be messy. The same report notes that no NGCC candidate is standardized or deployed, so no production system is affected. I am relying on a single outlet and a crowd-sourced site for round one details, so verify against ICCS publications.

What it means for you

The optimistic read

More eyes on post-quantum math is good for everyone. A global crowd stress-testing candidates in real time makes the winners stronger. The quantum threat is a shared problem, and healthy competition on defenses is a good way to meet it. Not financial advice.

Sources and further reading

Reported as of 2026-10-09. Press and company claims change, so check the primary documents before relying on any figure. Nothing here is financial advice, and the QUANTUM (QNT) memecoin is independent and has no link to any lab, company or government mentioned.

Frequently asked questions

Is China using NIST's post-quantum algorithms?

Its program excludes algorithms already standardized elsewhere, so the NIST standards are not eligible for the NGCC contest. What China will deploy is not settled.

Were the Chinese candidates broken?

Reported public review found many flaws, including outright breaks of a few schemes, within days. No candidate is standardized or deployed.

Do I need to change my crypto wallet because of this?

No. This is a standards contest, not an attack. Not financial advice.

Share on X

Keep reading

All Quantum policy and governments guides | Back to top | Search the site

Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary

QUANTUM (QNT) is the quantum sector memecoin on Solana. See the live chart, buys and burnt supply or read the token facts. Questions? Join the Telegram.