How NIST Chose The Post-Quantum Algorithms
NIST spent eight years narrowing 82 submissions to a handful of standards. Here is how the competition worked, which algorithms broke along the way and what that says about trusting the winners.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
The post-quantum algorithms now arriving in browsers and operating systems were not designed by NIST. They were submitted by research teams around the world and then attacked, measured and argued over in public for years. NIST ran the process and wrote the final standards.
Knowing how that process worked helps with a fair concern, which is whether to trust algorithms that are only a few years old. This article walks through the rounds, the two well-known algorithms that were broken during the contest, and what came after the first standards.
An Open Call In 2016
In December 2016 NIST published a notice in the US Federal Register asking for nominations of public-key algorithms that could resist quantum attack, with a deadline of 30 November 2017.1 It asked for two kinds of algorithm: key establishment schemes (later framed as key encapsulation mechanisms, or KEMs) and digital signatures.
NIST received 82 submissions. In December 2017 it accepted 69 of them as complete and proper first-round candidates.2 Anyone could then analyse them, and many did. Research groups published attacks, benchmarks and implementation studies, and NIST used that public work to decide who moved forward.
How Candidates Were Judged
NIST’s call set out three broad tests, and it applied them in every round.3 Security came first. Each scheme had to resist known classical and quantum attacks, and its designers had to claim one of five strength levels pegged to familiar targets such as finding an AES key. Cost and performance came next: how big the keys, ciphertexts and signatures are, and how much computing time each operation takes. The third test covered algorithm and implementation characteristics, which NIST described as flexibility, simplicity and the absence of anything likely to hold back adoption.3
These tests pull against each other. A scheme can be very well understood but have public keys hundreds of kilobytes long, or be tiny and fast but rest on a newer problem that has had less scrutiny. NIST also said it valued diversity, so that the final set would not depend on a single kind of mathematics.3 Much of the later shortlisting is the story of NIST trading these goals off against each other.
Narrowing The Field
Each round cut the list further. On 30 January 2019 NIST announced 26 second-round candidates: 17 for key establishment and 9 for signatures.2 In July 2020 it named 7 finalists and 8 alternates for a third round. The finalists were Classic McEliece, CRYSTALS-Kyber, NTRU and SABER for key establishment, and CRYSTALS-Dilithium, Falcon and Rainbow for signatures.4
On 5 July 2022 NIST announced its selections. CRYSTALS-Kyber was chosen for key establishment. CRYSTALS-Dilithium, Falcon and SPHINCS+ were chosen for signatures, with Dilithium as the main recommendation. Four key establishment candidates, BIKE, Classic McEliece, HQC and SIKE, went on to a fourth round.3
The Algorithms That Broke
Two well-known candidates failed under public scrutiny, and both failures were found with ordinary computers rather than quantum ones.
Rainbow was a third-round signature finalist based on multivariate equations. In February 2022 Ward Beullens of IBM Research published a key recovery attack on the lowest security level parameters from Rainbow’s second-round submission. On average it recovered the secret key in about 53 hours on a standard laptop, roughly a weekend of computing.5
SIKE was an isogeny-based key establishment scheme with very small keys, and it had advanced to the fourth round. In July 2022 Wouter Castryck and Thomas Decru of KU Leuven published an attack on the underlying SIDH protocol. Their paper reports recovering a key for the lowest SIKE parameter set in about ten minutes on a single processor core.6
From Selection To Standards
Selection was only the start. NIST released draft standards for Kyber, Dilithium and SPHINCS+ in August 2023 and published the final versions on 13 August 2024 as FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA).7 The standards carry new names, and they also differ in some details from the versions submitted to the competition, so code written for the submissions is not automatically compliant.
The fourth round ended on 11 March 2025, when NIST selected HQC as a second key establishment algorithm. NIST said it wanted a backup to ML-KEM built on different mathematics, and that it planned a draft standard in about a year and a final one in 2027.8 Falcon, the other 2022 signature pick, is being written up as FIPS 206 under the name FN-DSA. Neither FIPS 206 nor FIPS 207, the HQC standard, had been released even as a public draft by 7 October 2026.9
NIST also opened a separate call in September 2022 for additional signature schemes, to diversify beyond lattices. That process is still running. In May 2026 NIST advanced nine candidates to a third round.10
- Call For Proposals
Federal Register notice; submissions due 30 November 2017.
- 69 First-Round Candidates
From 82 submissions.
- 26 Second-Round Candidates
- 7 Finalists And 8 Alternates
- Rainbow Broken
Lowest parameters broken in about a weekend on a laptop.
- First Selections
Kyber, Dilithium, Falcon and SPHINCS+ chosen; SIKE broken weeks later.
- FIPS 203, 204 And 205 Published
- HQC Selected
Second key establishment algorithm, based on error-correcting codes.
- Additional Signatures, Round Three
Nine candidates advanced.
- FIPS 206 (FN-DSA) And FIPS 207 (HQC)Upcoming
No public drafts as of 7 October 2026.
Footnotes
-
NIST, “Announcing Request for Nominations for Public-Key Post-Quantum Cryptographic Algorithms”, Federal Register, 20 December 2016. federalregister.gov ↩
-
NIST, IR 8240, “Status Report on the First Round of the NIST Post-Quantum Cryptography Standardization Process”, January 2019. csrc.nist.gov ↩ ↩2
-
NIST, IR 8413, “Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process”, July 2022, updated September 2022. csrc.nist.gov ↩ ↩2 ↩3 ↩4
-
NIST, IR 8309, “Status Report on the Second Round of the NIST Post-Quantum Cryptography Standardization Process”, July 2020. csrc.nist.gov ↩
-
W. Beullens, “Breaking Rainbow Takes a Weekend on a Laptop”, IACR ePrint 2022/214, February 2022. eprint.iacr.org ↩
-
W. Castryck and T. Decru, “An efficient key recovery attack on SIDH”, IACR ePrint 2022/975, July 2022. eprint.iacr.org ↩
-
NIST, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards”, 13 August 2024. nist.gov ↩
-
NIST, “NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption”, 11 March 2025. nist.gov ↩
-
NIST Computer Security Resource Center, FIPS publications list, checked 7 October 2026. csrc.nist.gov ↩
-
NIST Computer Security Resource Center, “Post-Quantum Cryptography: Additional Digital Signature Schemes”, updated 28 September 2026. csrc.nist.gov ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.