Guidance
Approved algorithms.
Every entry on this page was checked against its source on or after 2026-08-09
There is no single global answer. One authority mandates ML-KEM-1024 and nothing else; another approves FrodoKEM and Classic McEliece alongside it; one cantonal administration permits those two and forbids ML-KEM outright. A product that is compliant in one place can be non-compliant in another.
What is actually standardised
Three post-quantum standards are final. The others are at various stages before that, and the difference matters when a vendor claims support.
| Algorithm | Standard | State | Notes |
|---|---|---|---|
| ML-KEM | FIPS 203 | Final | Key encapsulation. |
| ML-DSA | FIPS 204 | Final | Digital signatures. |
| SLH-DSA | FIPS 205 | Final | Hash-based signatures. Large, but conservative. |
| HQC | No FIPS published | Selected only | Chosen in March 2025 as a backup KEM on different mathematics from ML-KEM. Not standardised. |
| FN-DSA | FIPS 206 | Not yet drafted | Announced. No public draft at the time of writing. |
Which is why “five NIST post-quantum standards” is wrong, and why a product claiming HQC support is claiming support for something that has no standard to conform to.
Source NIST, FIPS 203, 204 and 205 , 13 August 2024 Checked 2026-08-09
Positions by jurisdiction
Only jurisdictions that publish an algorithm position of their own appear here. Where an authority defers to NIST, it is not repeated.
Germany
BSI
- Key encapsulation
- ML-KEM-768 and ML-KEM-1024, FrodoKEM, Classic McEliece
- Signatures
- ML-DSA, SLH-DSA, LMS and XMSS
- Hybrid
- Recommended
A wider approved set than CNSA 2.0. "NIST-approved" does not imply BSI-approved, and the reverse is also true.
Source BSI Technical Guideline TR-02102-1, version 2026-01 , 23 January 2026 Checked 2026-08-09
Canton of Bern
Binds one administration- Key encapsulation
- FrodoKEM and Classic McEliece only — ML-KEM is not permitted
- Signatures
- Not specified in the annex
- Hybrid
- Required, with a classical algorithm
One cantonal administration, and the sharpest illustration on this page that a single global algorithm choice does not exist. It binds nobody outside that administration.
Source Canton Bern ICSGW, Anhang 6 (Kryptographische Verfahren) , in force 1 January 2025 Checked 2026-08-09
United States
NIST, OMB and NSA
- Key encapsulation
- ML-KEM (FIPS 203)
- Signatures
- ML-DSA (FIPS 204), SLH-DSA (FIPS 205)
- Hybrid
- Permitted, not required
CNSA 2.0 applies a stricter set to National Security Systems under CNSSP 15. Its per-category transition table is deliberately not reproduced here — see the note at the top of this file.
Source NIST, FIPS 203, 204 and 205 , 13 August 2024 Checked 2026-08-09
France
ANSSI
- Key encapsulation
- ML-KEM, in a hybrid construction
- Signatures
- ML-DSA and SLH-DSA, in a hybrid construction; hash-based signatures exempt
- Hybrid
- Mandatory for phases 1 and 2
Source ANSSI, Views on the Post-Quantum Cryptography transition , 4 January 2022 Checked 2026-08-09
Australia
ASD
- Key encapsulation
- ML-KEM-768 and ML-KEM-1024, preferably ML-KEM-1024. ML-KEM-768 not approved beyond 2030
- Signatures
- ML-DSA-65 and ML-DSA-87, preferably ML-DSA-87. ML-DSA-65 not approved beyond 2030
- Hybrid
- Permitted
Parameter choices are aligned to CNSA 2.0 for interoperability.
Source ASD, Information Security Manual — Guidelines for cryptography , controls ISM-1917 and ISM-2073, revised September 2025 Checked 2026-08-09