NIST Post-Quantum Standards Status: FIPS 203, 204, 205, FN-DSA and HQC
The short version
If you only remember one thing: three post-quantum standards are final and ready to deploy, and two more are on the way. That is excellent progress for a process that began with a public call for algorithms in 2016. For the story of how the winners were picked, read the NIST process guide.
The final three
| Standard | Algorithm | Job | Deep dive |
|---|---|---|---|
| FIPS 203 | ML-KEM (from CRYSTALS-Kyber) | Key establishment | ML-KEM |
| FIPS 204 | ML-DSA (from CRYSTALS-Dilithium) | Digital signatures, general purpose | ML-DSA |
| FIPS 205 | SLH-DSA (from SPHINCS+) | Digital signatures, hash based backup | SLH-DSA |
NIST's project page says these were released in August 2024 and that they "can and should be put into use now." ML-KEM and ML-DSA are built on lattice math. SLH-DSA is built only on hash functions, which is a deliberately different foundation, so one mathematical surprise cannot sink everything. That diversity is a feature, see hash functions and quantum computers.
FN-DSA: a compact signature, still pending
FN-DSA is based on Falcon and is expected to become FIPS 206. NIST's project page says only that Falcon was selected for ongoing standardization and the process is underway. A third-party guide reported that NIST submitted the draft for approval on August 28, 2025 and that the final is widely expected in late 2026 or early 2027, but I did not find a NIST page confirming a public draft or final date, so treat timing as unconfirmed. The reported reason for the wait is implementation difficulty: Falcon signing uses floating point Gaussian sampling that is hard to implement safely. Its payoff is smaller signatures than ML-DSA, which is attractive where bandwidth matters, such as certificates (see the PKI guide).
HQC: a second key encapsulation method
On March 11, 2025, NIST selected HQC as a backup key encapsulation mechanism. It is based on error correcting codes, a different mathematical family from ML-KEM's lattices. The idea is insurance: if lattices ever turn out weaker than hoped, a second family is standing by. NIST said it would release a draft standard for public comment and then finalize roughly two years after selection, which is where the 2027 expectation comes from. NIST's own conference listing shows a talk titled FIPS 207: HQC-KEM in September 2025. I found no confirmation that the draft has been published as of October 2026, so check the NIST site. HQC is a backup, not a replacement, and ML-KEM remains the recommended choice today.
Timelines for retiring old algorithms
NIST's project page says it will deprecate and ultimately remove quantum-vulnerable algorithms from its standards by 2035, with high-risk systems moving much earlier. The detailed draft is NIST IR 8547 (initial public draft, November 12, 2024). Related US agency dates are summarized in the government deadlines guide. Keep in mind drafts can change.
What this means for decisions
- Deploy ML-KEM now for key exchange, ideally in a hybrid with a classical method, as browsers do (hybrid TLS).
- Choose ML-DSA for new general signature designs, with SLH-DSA for cases that want a hash only fallback.
- Do not wait for FN-DSA or HQC to begin inventory and planning. Build in crypto agility so you can add them later (crypto agility).
- Avoid home-made or pre-standard algorithms for anything serious.
Why to feel optimistic
Standards are the unglamorous backbone of a safe transition, and the community delivered the first set years before experts expect a quantum computer capable of breaking today's cryptography. For comparison, see how long the quantum hardware side may take in the timeline. Because the replacement toolbox exists, quantum computing can keep advancing toward medicine, materials and climate science without privacy being the casualty.
Standards news is sometimes used as hype for crypto tokens. It is not a reason to buy anything, and the QNT memecoin is independent of Quantinuum Ltd and of NIST. This is education, not financial advice.
Sources and further reading
- NIST: post-quantum cryptography project page
- NIST IR 8547 initial public draft: Transition to Post-Quantum Cryptography Standards
- The Quantum Insider: NIST selects HQC (March 11, 2025)
- NIST: FIPS 207 HQC-KEM presentation listing
- Encryption Consulting: FN-DSA (FIPS 206) guide (third-party, timing unconfirmed)
Reported as of 2026-10-09. Standards and rollout numbers change often, so check the primary documents before relying on any figure. This is education, not financial advice. The QNT memecoin is independent of Quantinuum Ltd, the real company, and of any lab or government.
Frequently asked questions
Which post-quantum standards are final?
FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA), released in August 2024.
What is FN-DSA?
A compact signature scheme based on Falcon, expected as FIPS 206. In the sources I found it was not yet final, with a final widely expected around late 2026 or early 2027 (unconfirmed).
What is HQC?
A code based key encapsulation method NIST selected on March 11, 2025 as a backup to ML-KEM. A draft was planned for 2026 and a final for 2027, and I could not confirm the draft has been published.
Should I wait for FN-DSA or HQC before migrating?
No. NIST says the first three standards can and should be used now. Plan for agility so you can add others later.
Is this a signal about QNT?
No. The token is an independent memecoin. Nothing here is financial advice.
Keep reading
- The NIST Post-Quantum Process Explained
How NIST ran its multi-year post-quantum cryptography competition, from public call to the first standards in 2024, and what work is still continuing. - ML-KEM Explained: The Post-Quantum Key Exchange Standard
ML-KEM (FIPS 203) is NIST's standard for post-quantum key encapsulation. Learn what a KEM is, how lattices fit in, and where it is used, in plain English. - ML-DSA Explained: The Post-Quantum Signature Standard
ML-DSA (FIPS 204) is NIST's main post-quantum digital signature standard. Learn how lattice signatures work, how they compare to ECDSA, and the trade-offs. - SLH-DSA Explained: Hash-Based Stateless Signatures
SLH-DSA (FIPS 205) is NIST's hash-based, stateless post-quantum signature standard. Learn how it works, why it is cautious, and its size and speed trade-offs.
All Quantum policy and governments guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary