The NIST Post-Quantum Standards Explained: ML-KEM, ML-DSA, SLH-DSA And What Comes Next
A plain guide to FIPS 203, 204 and 205, the FN-DSA and HQC standards still in preparation, and the search for more signature schemes, with status as of October 2026.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
When people talk about “the NIST post-quantum standards”, they usually mean three documents published in August 2024. Two more are on the way, a guidance document on key encapsulation was finalised in 2025, and a separate competition for extra signature schemes is still running. Keeping track of which is final and which is still a plan matters, because procurement teams and auditors will ask.
This article explains what each standard does, where it came from, and its status as of 7 October 2026.
The Three Final Standards
NIST published three Federal Information Processing Standards on 13 August 2024.1
FIPS 203, ML-KEM. The Module-Lattice-Based Key-Encapsulation Mechanism, derived from CRYSTALS-Kyber. A key encapsulation mechanism (KEM) lets two parties establish a shared secret over a public network, which then keys a symmetric cipher such as AES. NIST calls ML-KEM its primary standard for general encryption.1 It comes in three parameter sets, ML-KEM-512, ML-KEM-768 and ML-KEM-1024, and NIST recommends ML-KEM-768 as the default.2
FIPS 204, ML-DSA. The Module-Lattice-Based Digital Signature Algorithm, derived from CRYSTALS-Dilithium. It is NIST’s primary standard for digital signatures, with parameter sets ML-DSA-44, ML-DSA-65 and ML-DSA-87.1
FIPS 205, SLH-DSA. The Stateless Hash-Based Digital Signature Algorithm, derived from SPHINCS+. Its security rests only on hash functions, a different foundation from the lattice problems behind ML-KEM and ML-DSA. NIST positions it as a backup in case ML-DSA turns out to be weaker than expected.1 Its signatures are many times larger than ML-DSA’s, which is the price of that conservative design.
Standards Still In Preparation
FIPS 206, FN-DSA. This will standardise Falcon, the compact lattice signature scheme NIST selected in 2022. NIST has described FN-DSA as producing much smaller signatures than ML-DSA but being harder to implement, because Falcon as submitted uses floating-point arithmetic in key generation and signing.3 In a public mailing list post on 28 August 2025, NIST’s Dustin Moody said the draft was essentially complete and had been sent up the chain for approval.4 The plan then changed. On 28 September 2026 NIST’s FIPS 206 team proposed that the draft should instead specify fixed-point arithmetic for both key generation and signing, with a single signing procedure that implementations must match exactly in testing, and asked the community for feedback.5 As of 7 October 2026, no public draft of FIPS 206 appears on NIST’s publications site.6
FIPS 207, HQC. NIST selected HQC in March 2025 as a second KEM, based on error-correcting codes rather than lattices, so that a weakness in ML-KEM would not leave organisations without an option. At the time NIST said it planned a draft in about a year and a final standard in 2027.7 NIST presented the planned contents of FIPS 207 at its September 2025 standardisation conference.8 In August 2026 it told its public mailing list that it was preparing to release the initial public draft soon.9 As of 7 October 2026, that draft has not appeared.6
Guidance Around The Standards
SP 800-227. Published in final form in September 2025, this NIST Special Publication explains how key encapsulation mechanisms work, the security properties they offer, and how to implement and use them safely.10 It is the practical companion to FIPS 203 and to the coming HQC standard.
SP 800-208. Published in October 2020, before the main competition ended, it approves two stateful hash-based signature schemes, LMS and XMSS, for specialised uses such as firmware signing.11 A later article in this section explains why they are treated differently.
NIST IR 8547. An initial public draft from November 2024 that proposes timelines for retiring quantum-vulnerable algorithms. As of October 2026 it remains a draft.12
More Signatures On The Way
Both ML-DSA and FN-DSA rest on lattice problems. To avoid depending on one family for most signatures, NIST issued a separate call for additional signature schemes in September 2022.13 Fourteen candidates reached the second round in October 2024.14 On 14 May 2026 NIST advanced nine to a third round: FAEST, HAWK, MAYO, MQOM, QR-UOV, SDitH, SNOVA, SQIsign and UOV.15
NIST’s round three page, updated on 28 September 2026, reports that the HAWK team has withdrawn its submission, leaving eight active candidates and no lattice schemes among them.16 The page gives no date or reason for the withdrawal. Any standard from this process is still several years away.
What This Means For Buyers
For procurement and architecture decisions in 2026, the three final standards are the ones to ask for by name. A supplier claiming post-quantum support should be able to say which of ML-KEM, ML-DSA and SLH-DSA it implements, which parameter sets it uses, and whether the implementation follows the final FIPS text rather than an earlier competition version such as Kyber or Dilithium. The NSA, for example, states that implementations which do not follow FIPS 203 or 204 do not count as compliant with its CNSA 2.0 suite, even if they carry the older names.17
For FN-DSA and HQC, the sensible position is to design for them without depending on them. Leave room in protocols and key stores for another algorithm, and revisit once NIST publishes drafts.
| Item | Origin | Job | Maths Family | Status |
|---|---|---|---|---|
| FIPS 203 ML-KEM | CRYSTALS-Kyber | Key establishment | Lattice | Final, 13 August 2024 |
| FIPS 204 ML-DSA | CRYSTALS-Dilithium | Signature | Lattice | Final, 13 August 2024 |
| FIPS 205 SLH-DSA | SPHINCS+ | Signature | Hash-based | Final, 13 August 2024 |
| FIPS 206 FN-DSA | Falcon | Signature | Lattice | Draft being revised (fixed-point plan, September 2026); not public |
| FIPS 207 HQC | HQC | Key establishment | Code-based | Draft announced as coming soon (August 2026); not public |
| SP 800-208 | LMS and XMSS | Signature (stateful) | Hash-based | Final, October 2020 |
| SP 800-227 | Guidance | KEM recommendations | Not applicable | Final, September 2025 |
| Additional signatures | Open call, 2022 | Signature | Several | Round three, 8 active candidates |
Footnotes
-
NIST, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards”, 13 August 2024. nist.gov ↩ ↩2 ↩3 ↩4
-
NIST, FIPS 203, “Module-Lattice-Based Key-Encapsulation Mechanism Standard”, August 2024. csrc.nist.gov ↩
-
R. Perlner (NIST), “FIPS 206 Status Update”, presentation, 2025. csrc.nist.gov ↩
-
D. Moody (NIST), post to the NIST pqc-forum mailing list on the status of FIPS 206, 28 August 2025. groups.google.com ↩
-
R. Perlner, on behalf of the NIST FIPS 206 team, “New plan for FN-DSA”, NIST pqc-forum mailing list, 28 September 2026. groups.google.com ↩
-
NIST Computer Security Resource Center, FIPS publications list, checked 7 October 2026. csrc.nist.gov ↩ ↩2
-
NIST, “NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption”, 11 March 2025. nist.gov ↩
-
A. Robinson (NIST), “FIPS 207: HQC-KEM”, Sixth PQC Standardization Conference, 25 September 2025. csrc.nist.gov ↩
-
A. Robinson (NIST), “Upcoming FIPS 207 - Key format”, NIST pqc-forum mailing list, August 2026. groups.google.com ↩
-
NIST, SP 800-227, “Recommendations for Key-Encapsulation Mechanisms”, September 2025. csrc.nist.gov ↩
-
NIST, SP 800-208, “Recommendation for Stateful Hash-Based Signature Schemes”, October 2020. csrc.nist.gov ↩
-
NIST, IR 8547 (initial public draft), “Transition to Post-Quantum Cryptography Standards”, November 2024. csrc.nist.gov ↩
-
NIST Computer Security Resource Center, “Post-Quantum Cryptography: Additional Digital Signature Schemes”, updated 28 September 2026. csrc.nist.gov ↩
-
NIST, IR 8528, “Status Report on the First Round of the Additional Digital Signature Schemes for the NIST Post-Quantum Cryptography Standardization Process”, October 2024. csrc.nist.gov ↩
-
NIST, IR 8610, “Status Report on the Second Round of the Additional Digital Signature Schemes for the NIST Post-Quantum Cryptography Standardization Process”, May 2026. csrc.nist.gov ↩
-
NIST Computer Security Resource Center, “Round 3 Additional Signatures”, updated 28 September 2026. csrc.nist.gov ↩
-
NSA, “The Commercial National Security Algorithm Suite 2.0 and Quantum Computing FAQ”, version 2.1, December 2024. media.defense.gov ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.