NIST PQC standards: FIPS 203, 204, 205 and HQC
Three post-quantum standards have been final since August 2024, with more in the pipeline. This is what each one does, and what your QBOM should record about it.
- NIST published FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) on 13 August 2024.
- ML-KEM is for key establishment; ML-DSA and SLH-DSA are for digital signatures, with SLH-DSA based on different mathematics as a backup.
- A fourth standard based on FALCON, to be called FN-DSA (FIPS 206), was announced as forthcoming.
- NIST selected HQC in March 2025 as a backup key-encapsulation mechanism, with a final standard expected in 2027.
- Record the algorithm and the parameter set in the QBOM; the parameter set determines the security category.
The three final standards
On 13 August 2024 NIST released its first three finalised post-quantum cryptography standards and encouraged system administrators to start integrating them immediately. NIST's Dustin Moody said: "There is no need to wait for future standards. Go ahead and start using these three" [1].
| Standard | Algorithm (original name) | Purpose | Parameter sets |
|---|---|---|---|
| FIPS 203 [2] | ML-KEM (CRYSTALS-Kyber) | Key encapsulation, to establish a shared secret key over a public channel | ML-KEM-512, ML-KEM-768, ML-KEM-1024, in increasing security strength and decreasing performance |
| FIPS 204 [3] | ML-DSA (CRYSTALS-Dilithium) | Digital signatures | ML-DSA-44, ML-DSA-65, ML-DSA-87 |
| FIPS 205 [4] | SLH-DSA (SPHINCS+) | Stateless hash-based digital signatures | Multiple parameter sets based on SHA-2 or SHAKE, in small-signature and fast variants |
NIST describes ML-KEM as the primary standard for general encryption, ML-DSA as the primary standard for digital signatures, and SLH-DSA as a backup signature method that uses different mathematics from ML-DSA [1]. ML-KEM's security rests on the Module Learning with Errors problem [2].
What comes next
- FN-DSA (FIPS 206). A fourth standard based on FALCON, to be renamed FN-DSA, was announced alongside the first three and in March 2025 NIST said it would be released "shortly" as FIPS 206 [5]. Check NIST's post-quantum news page for its current status before relying on it [6].
- HQC. On 11 March 2025 NIST selected HQC as an additional key-encapsulation algorithm. It is based on error-correcting codes rather than lattices, giving a backup to ML-KEM built on different mathematics. NIST said it planned to issue a draft standard in about a year and to finalise it in 2027 [5].
- More signatures. In May 2026 NIST advanced nine candidates to the third round of its additional digital signatures process [6].
- Implementation guidance. NIST published SP 800-227, recommendations for key-encapsulation mechanisms, in September 2025, and in April 2026 released a draft SP 800-230 with additional SLH-DSA parameter sets for limited signature use cases [6].
Where they are used
| Use | Typical choice |
|---|---|
| TLS, VPN and SSH key exchange | ML-KEM, often in a hybrid with a classical algorithm during transition |
| Certificates and document signing | ML-DSA as ecosystem support matures |
| Long-lived roots of trust where hash-based security is preferred | SLH-DSA, or stateful hash-based schemes such as LMS and XMSS |
For U.S. national security systems, CNSA 2.0 selects the highest parameter sets, ML-KEM-1024 and ML-DSA-87, and LMS or XMSS for software and firmware signing [7]. See CNSA 2.0 algorithms and timeline.
What to record in the QBOM
"We use ML-KEM" is not enough. Record the algorithm, the parameter set, the implementation (library and version) and whether it is used alone or in a hybrid. CycloneDX 1.6 has fields for each: parameterSetIdentifier, primitive (for example kem or signature), nistQuantumSecurityLevel for the NIST security strength category, and implementationPlatform and certificationLevel for implementation details [8]. This lets you answer policy questions such as "which services use ML-KEM-768 where our policy requires ML-KEM-1024?"
Also track which standards are final and which are draft. HQC and FN-DSA should be recorded as "planned" in policy until their standards are published.
Related reading
For deprecation dates of the algorithms these standards replace, see NIST IR 8547 transition timeline. For deployment, see Preparing for post-quantum cryptography.
How IntelliXBOM helps
IntelliXBOM ingests CycloneDX cryptographic properties, including algorithm, parameter set and quantum security level, and can validate them against required-field policies. It correlates each algorithm with the libraries, services and hardware that use it, keeping version history as services move to the new standards.
Frequently asked questions
What are FIPS 203, 204 and 205?
They are NIST's first three post-quantum cryptography standards, published on 13 August 2024. FIPS 203 specifies ML-KEM for key encapsulation, FIPS 204 specifies ML-DSA for digital signatures and FIPS 205 specifies SLH-DSA, a hash-based signature scheme.
Why did NIST select HQC?
NIST wanted a backup to ML-KEM based on different mathematics. HQC uses error-correcting codes rather than structured lattices, so a future weakness in one approach would not necessarily affect the other.
Which ML-KEM parameter set should I use?
FIPS 203 defines ML-KEM-512, ML-KEM-768 and ML-KEM-1024 with increasing security strength and decreasing performance. The choice depends on your policy; CNSA 2.0, for example, requires ML-KEM-1024 for U.S. national security systems.
Sources
- NIST Releases First 3 Finalized Post-Quantum Encryption Standards (13 August 2024)NISTwww.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards
- FIPS 203, Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM)NISTcsrc.nist.gov/pubs/fips/203/final
- FIPS 204, Module-Lattice-Based Digital Signature Standard (ML-DSA)NISTcsrc.nist.gov/pubs/fips/204/final
- FIPS 205, Stateless Hash-Based Digital Signature Standard (SLH-DSA)NISTcsrc.nist.gov/pubs/fips/205/final
- NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption (March 2025)NISTwww.nist.gov/news-events/news/2025/03/nist-selects-hqc-fifth-algorithm-post-quantum-encryption
- Post-Quantum Cryptography project newsNIST Computer Security Resource Centercsrc.nist.gov/Projects/post-quantum-cryptography/news
- CNSA 2.0: Complete Guide to NSA's PQC RequirementsPostQuantum.compostquantum.com/cnsa-2-0/complete-guide/
- CycloneDX 1.6 JSON schema (cryptoProperties)OWASP CycloneDX on GitHubgithub.com/CycloneDX/specification/blob/1.6/schema/bom-1.6.schema.json
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.