Back to News
quantum-computing

NIST taps PQShield to map global rules for quantum-safe algorithms

Ivy Delaney
Loading...
5 min read
0 likes
⚡ Quantum Brief
NIST has selected PQShield to help map global regulatory frameworks for quantum-safe cryptographic algorithms, as national authorities race to meet 2030 deadlines for critical systems and 2035 for standard ones. The effort highlights deep divisions in post-quantum cryptography adoption, with the US NSA banning hybrid systems while European bodies like Germany’s BSI and France’s ANSSI mandate or recommend them for backward compatibility. South Korea and China are advancing their own certification programs, incorporating algorithms like ML-KEM, ML-DSA, and domestically developed options. The fragmented landscape forces product owners to navigate conflicting regional requirements, complicating worldwide compliance.
Why it matters

This initiative underscores the urgent need for harmonized quantum-safe standards, as divergent national policies risk creating technical and compliance barriers that could delay global adoption of post-quantum cryptography.

AI Audio Summary
0:00 / 0:00
Click to play
quantum computing images (2).jpg
Quantum News · Media Library

The timeline for securing digital systems against quantum threats is surprisingly short, with national authorities now targeting 2030 for critical products and 2035 for standard ones. Once an academic exercise, post-quantum cryptography is rapidly becoming a practical necessity, yet implementation is proving complex. The landscape has dramatically shifted, creating regulatory differences as the US National Security Agency forbids hybrid cryptographic systems, directly contradicting the approach of European bodies like ANSSI in France and BSI in Germany, who mandate or strongly recommend them for backward compatibility. Regional Adoption of ML-KEM and ML-DSA Post-NIST Standardization National authorities are establishing distinct criteria for post-quantum cryptography (PQC) algorithm adoption, categorizing them as either globally or regionally specific to protocol system standards, creating challenges for product owners aiming for worldwide compliance. South Korea’s KCMVP certification program has not yet been updated with PQC algorithms, but anticipates the inclusion of ML-KEM and ML-DSA, alongside domestically selected KEMs NTRU+ and SMAUG-T, and signature algorithms AIMER and HAETAE, following a parallel development effort completed in January 2025. Germany’s Bundesamt für Sicherheit in der Informationstechnik (BSI) recommends utilizing traditional cryptographic algorithms in conjunction with all algorithms, including hash-based options, in hybrid post-quantum/traditional (PQ/T) configurations, a stance sharply contrasted by the US National Security Agency (NSA). The BSI TR-02102-1 document details recommended parameter sets for ML-KEM, ML-KEM-768 or ML-KEM-1024, and ML-DSA, ML-DSA-65 or ML-DSA-87, alongside specifications for other algorithms like Classic McEliece and FrodoKEM. While the BSI embraces a broad approach to PQC implementation, the NSA has no plans to incorporate SLH-DSA, FN-DSA, or HQC into its approved cryptographic suite, limiting LMS and XMSS to software and firmware signing applications only, European Cybersecurity Certification Group says. This divergence in regulatory approaches is further highlighted by France’s Agence Nationale de la Sécurité des Systèmes d’Information (ANSSI), which mandates or strongly recommends hybrid implementations featuring ML-KEM and ML-DSA, alongside FrodoKEM, for backward compatibility, a direct contradiction of the NSA’s position.

The European Cybersecurity Certification Group (ECCG) acknowledges ML-DSA and SLH-DSA, alongside other PQC options, but does not mandate a specific hybrid approach.

The United Kingdom’s National Cyber Security Centre (NCSC) permits ML-DSA as an interim measure, but does not currently approve ML-KEM, demonstrating a fragmented landscape where national preferences significantly shape PQC adoption strategies. China and South Korea’s National PQC Algorithm Certification China and South Korea are actively establishing national certification programs for post-quantum cryptography algorithms, diverging from approaches seen elsewhere as deadlines for quantum-resistant systems approach. While the United States National Security Agency forbids hybrid post-quantum/traditional cryptographic systems for national security applications, China permits certified products integrating both foreign and standard algorithms, though these requirements do not apply to everyday consumer goods. This difference highlights a regional approach to implementation, creating complexities for product owners seeking global compliance. These selections demonstrate a proactive stance toward establishing a domestically supported post-quantum infrastructure, even as international standards solidify. The nation anticipates a 2030 deadline for critical products and a 2035 deadline for standard products to achieve quantum-resilience, mirroring the timeframe established by other national authorities. The Chinese approach, governed by its Cryptography Law, allows for the sale of cryptography products certified under its State Cryptography Administration, even if originating from foreign entities, while simultaneously updating its own cryptographic standards through national competitions, according to European Cybersecurity Certification Group. This dual pathway suggests a strategy of both embracing international collaboration and fostering domestic innovation in the field.

The European Cybersecurity Certification Group’s Agreed Cryptographic Mechanisms provides recommendations for high-assurance cybersecurity certifications, but national implementation varies significantly, as evidenced by the NSA’s restrictive stance on hybrid systems. A recent report from the UK’s National Cyber Security Centre states, “PQC should be viewed as the end goal,” emphasizing the long-term vision despite immediate implementation challenges. EU Cyber Resilience Act and Algorithm Recommendations for 2026-2027 The European Cybersecurity Certification Group’s most recent recommendations, updated in May 2025 and again in April 2026, specify ML-KEM with either a 768 or 1024 parameter set for key encapsulation mechanisms, alongside ML-DSA-65 or ML-DSA-87 for digital signatures, aligning with a push for cryptography by 2026-2027 as mandated by the EU Cyber Resilience Act. Germany’s BSI TR-02102-1 document echoes these preferences, also listing Classic McEliece and FrodoKEM as viable options, while indicating intent to add HQC once standardized, demonstrating a convergence on a core set of algorithms despite regional nuances. These algorithm selections are not static; documentation regarding KpqC algorithms indicates ongoing standardization processes and the expectation of further changes, requiring continuous adaptation from implementers. The BSI specifically recommends utilizing all algorithms, including hash-based ones, in a hybrid PQ/T form, while the NSA permits traditional algorithms like AES-256 and SHA-384/512 for specific applications, but restricts asymmetric traditional algorithms entirely. This difference in approach highlights the complexities facing product owners navigating a fragmented regulatory landscape, as they seek global compliance with varying regional requirements. NCSC guidance further specifies that only ML-DSA should be used as a general-purpose signature, with LMS and XMSS reserved for case-by-case application, and expects users to select parameter sets based on system constraints. “NCSC recommends migrating to PQ/T hybrid cryptography ‘where reasonable’ as an interim step,” reflecting a pragmatic approach to adoption. China categorizes ‘commercial cryptography’ as publicly available for use if certified by the State Cryptography Administration (SCA), with these commercial requirements not applying to everyday consumer goods. Source: https://pqshield.com/regional-regulations-for-cryptography-algorithm-selection/ More like thisQuantum CryptographySEALSQ’s QS7001 Validated for ANSSI’s Post-Quantum MandateQuantum Computing Business NewsTQ42 Cryptography Validated for Post-Quantum SecurityQuantum CryptographyANSSI leads G7 push for quantum-resistant encryptionCybersecurityNIST Proposes Dual-Stack PIV Model for Quantum-Safe CredentialsStay currentSee today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals. Tags:

Read Original

Tags

post-quantum-cryptography
quantum-standards
quantum-algorithms
quantum-cryptography

Source Information

Source: Quantum Zeitgeist

Discussion

0 professional contributions

Sign in to join this professional discussion.

Be the first to add a constructive contribution.