The NIST Post-Quantum Process Explained
Why NIST ran a competition
NIST, the United States National Institute of Standards and Technology, publishes cryptographic standards used far beyond its own borders. Because Shor's algorithm threatens today's public key systems, NIST opened a public process to find replacements. The approach copies how earlier standards such as AES were chosen: invite everyone to submit, then invite everyone to attack.
The stages
- Call for proposals: NIST published requirements and evaluation criteria, covering security, performance and practical fit.
- Submissions: Teams of researchers from many countries sent in dozens of candidate schemes for key establishment and for signatures.
- Rounds of analysis: Candidates were examined in public over several rounds. Some were eliminated, including some that were broken by new attacks. Others were merged or narrowed down.
- Selection: NIST announced the algorithms it intended to standardize.
- Drafts and comment: Draft standards were released for public feedback before finalization.
- Publication: The first three standards were published in 2024.
What was standardized
| Standard | Name | Purpose | Basis |
|---|---|---|---|
| FIPS 203 | ML-KEM | Key establishment | Lattices |
| FIPS 204 | ML-DSA | Signatures | Lattices |
| FIPS 205 | SLH-DSA | Signatures | Hash functions |
Read more in ML-KEM Explained, ML-DSA Explained and SLH-DSA Explained.
Why public attack matters
A scheme cannot be trusted just because its authors say so. Public scrutiny found real weaknesses in some candidates during the process, which is exactly the point. It also explains why newer algorithms are treated cautiously compared with ones that have faced decades of analysis.
Work that continues
The process did not end with the first publication. NIST has said it continues to evaluate additional candidates, with the aim of having alternatives that rely on different mathematical ideas, and further signature options are under consideration. Guidance on migration timelines has also been published by various government bodies. Specific schedules and candidates change, so check NIST directly for current status.
What it means for readers
Having standards makes it practical for software, browsers, hardware and eventually blockchains to plan upgrades. It does not mean the threat has arrived. For the crypto angle, see Post-Quantum Cryptography and Crypto and Crypto Agility Explained.
It is worth noticing what the process did not claim. NIST did not announce that a quantum computer capable of breaking current cryptography exists. It chose to standardize early because replacing cryptography across the internet takes many years, and data with a long secrecy lifetime may already be at risk from recording. The reasoning is explained in harvest now, decrypt later.
The process also shows a healthy pattern for security work: open specifications, competing teams, public cryptanalysis and slow, documented decisions. Anyone can read the submissions and the reports, which is a good way to judge how seriously a claim of being quantum safe should be taken. Be skeptical of products that use the label without naming a standard or an algorithm.
Frequently asked questions
When were the first NIST post-quantum standards published?
In 2024, NIST published FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA).
Did every submitted algorithm survive?
No. Many were eliminated, and a few were broken by published attacks during the open evaluation. That is how the process is designed to work.
Is the process finished?
Not entirely. NIST has indicated that additional evaluation continues, so more algorithms may be standardized later. Check NIST for the latest status.
Does NIST decide what blockchains use?
No. Networks make their own choices. NIST standards are influential references, though, because they are vetted and widely implemented.
Why include both lattice and hash-based schemes?
Diversity reduces risk. If a flaw is found in one family of math, another standard built on different assumptions can still be relied upon.
Is NIST the only body working on this?
No. Other national agencies and standards groups also publish guidance, and many of them reference NIST selected algorithms.
Keep reading
- ML-KEM Explained: The Post-Quantum Key Exchange Standard
ML-KEM (FIPS 203) is NIST's standard for post-quantum key encapsulation. Learn what a KEM is, how lattices fit in, and where it is used, in plain English. - ML-DSA Explained: The Post-Quantum Signature Standard
ML-DSA (FIPS 204) is NIST's main post-quantum digital signature standard. Learn how lattice signatures work, how they compare to ECDSA, and the trade-offs. - SLH-DSA Explained: Hash-Based Stateless Signatures
SLH-DSA (FIPS 205) is NIST's hash-based, stateless post-quantum signature standard. Learn how it works, why it is cautious, and its size and speed trade-offs. - Post-Quantum Cryptography and Crypto: What It Means
Why large quantum computers could threaten blockchain signatures, and what post-quantum cryptography is doing about it.
All Quantum computing guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary