Guidance

Approved algorithms.

Every entry on this page was checked against its source on or after 2026-08-09

There is no single global answer. One authority mandates ML-KEM-1024 and nothing else; another approves FrodoKEM and Classic McEliece alongside it; one cantonal administration permits those two and forbids ML-KEM outright. A product that is compliant in one place can be non-compliant in another.

What is actually standardised

Three post-quantum standards are final. The others are at various stages before that, and the difference matters when a vendor claims support.

Algorithm Standard State Notes
ML-KEM FIPS 203 Final Key encapsulation.
ML-DSA FIPS 204 Final Digital signatures.
SLH-DSA FIPS 205 Final Hash-based signatures. Large, but conservative.
HQC No FIPS published Selected only Chosen in March 2025 as a backup KEM on different mathematics from ML-KEM. Not standardised.
FN-DSA FIPS 206 Not yet drafted Announced. No public draft at the time of writing.

Which is why “five NIST post-quantum standards” is wrong, and why a product claiming HQC support is claiming support for something that has no standard to conform to.

Source NIST, FIPS 203, 204 and 205 , 13 August 2024 Checked 2026-08-09

Positions by jurisdiction

Only jurisdictions that publish an algorithm position of their own appear here. Where an authority defers to NIST, it is not repeated.

Germany

BSI

Key encapsulation
ML-KEM-768 and ML-KEM-1024, FrodoKEM, Classic McEliece
Signatures
ML-DSA, SLH-DSA, LMS and XMSS
Hybrid
Recommended

A wider approved set than CNSA 2.0. "NIST-approved" does not imply BSI-approved, and the reverse is also true.

Source BSI Technical Guideline TR-02102-1, version 2026-01 , 23 January 2026 Checked 2026-08-09

Canton of Bern

Binds one administration
Key encapsulation
FrodoKEM and Classic McEliece only — ML-KEM is not permitted
Signatures
Not specified in the annex
Hybrid
Required, with a classical algorithm

One cantonal administration, and the sharpest illustration on this page that a single global algorithm choice does not exist. It binds nobody outside that administration.

Source Canton Bern ICSGW, Anhang 6 (Kryptographische Verfahren) , in force 1 January 2025 Checked 2026-08-09

United States

NIST, OMB and NSA

Key encapsulation
ML-KEM (FIPS 203)
Signatures
ML-DSA (FIPS 204), SLH-DSA (FIPS 205)
Hybrid
Permitted, not required

CNSA 2.0 applies a stricter set to National Security Systems under CNSSP 15. Its per-category transition table is deliberately not reproduced here — see the note at the top of this file.

Source NIST, FIPS 203, 204 and 205 , 13 August 2024 Checked 2026-08-09

France

ANSSI

Key encapsulation
ML-KEM, in a hybrid construction
Signatures
ML-DSA and SLH-DSA, in a hybrid construction; hash-based signatures exempt
Hybrid
Mandatory for phases 1 and 2

Source ANSSI, Views on the Post-Quantum Cryptography transition , 4 January 2022 Checked 2026-08-09

Australia

ASD

Key encapsulation
ML-KEM-768 and ML-KEM-1024, preferably ML-KEM-1024. ML-KEM-768 not approved beyond 2030
Signatures
ML-DSA-65 and ML-DSA-87, preferably ML-DSA-87. ML-DSA-65 not approved beyond 2030
Hybrid
Permitted

Parameter choices are aligned to CNSA 2.0 for interoperability.

Source ASD, Information Security Manual — Guidelines for cryptography , controls ISM-1917 and ISM-2073, revised September 2025 Checked 2026-08-09

← Back to guidance