Home / Standards / NIST PQC Standards
STANDARDS

The three algorithms behind the NIST post-quantum cryptography standards

The NIST post-quantum cryptography standards became official in August 2024, marking the shift from research to implementation. FIPS 203, 204, and 205 cover key exchange and digital signatures using algorithms designed to resist attacks from future quantum computers. Not every mandate requires all three; CNSA 2.0, for example, specifies only two of them.

Check a domain →
203 ML-KEM
204 ML-DSA
205 SLH-DSA
NIST released three post-quantum cryptography standards in August 2024, after an eight-year public evaluation process: FIPS 203, FIPS 204, and FIPS 205. FIPS 203 (ML-KEM) covers key exchange, FIPS 204 (ML-DSA) covers digital signatures, and FIPS 205 (SLH-DSA) is a structurally distinct backup signature scheme.

What are the three NIST PQC algorithms?

FIPS 203 · ML-KEM
Module-Lattice-Based Key-Encapsulation Mechanism
The primary standard for general encryption, letting two parties securely establish a shared key.
FIPS 204 · ML-DSA
Module-Lattice-Based Digital Signature Algorithm
The main standard for protecting digital signatures.
FIPS 205 · SLH-DSA
Stateless Hash-Based Digital Signature Algorithm
A hash-based backup if ML-DSA is ever found vulnerable.
In practice, FIPS 203 protects confidentiality. This includes harvest-now-decrypt-later attacks, where an adversary records encrypted traffic today and decrypts it later once a powerful enough quantum computer exists. FIPS 204 and 205 support authenticity and integrity.

Does every mandate require all three algorithms?

No. It’s easy to assume all three NIST algorithms are universally required, but they aren’t. CNSA 2.0 specifies ML-KEM and ML-DSA, and does not currently approve SLH-DSA. Always check the specific mandate that applies to your organization rather than assuming blanket coverage.
Standard
Algorithm
Function
Required by CNSA 2.0?
FIPS 203
ML-KEM
Key exchange
Yes
FIPS 204
ML-DSA
Digital signatures
Yes
FIPS 205
SLH-DSA
Digital signatures (backup)
No

Why does NIST have a backup signature algorithm?

SLH-DSA (FIPS 205) is built on hash functions rather than lattice mathematics, the foundation shared by ML-KEM and ML-DSA. If a future cryptanalytic advance weakened lattice-based schemes, SLH-DSA would still stand on unrelated math. NIST standardized it specifically as that structural hedge, not because ML-DSA is currently considered weak.
Want to know which algorithms your services actually run?

How were the NIST post-quantum cryptography standards selected?

NIST ran a public, multi-round competition starting in 2016, evaluating dozens of candidate algorithms submitted by cryptographers worldwide for resistance to quantum attacks. CRYSTALS-Kyber became ML-KEM (FIPS 203) for key exchange, and CRYSTALS-Dilithium became ML-DSA (FIPS 204) for digital signatures, the two primary lattice-based algorithms to survive the process. SPHINCS+ became SLH-DSA (FIPS 205), a hash-based signature kept as a structurally distinct backup in case future cryptanalysis weakens the lattice-based approach.

 

Written by the team behind Anvil Secure.