ISO/IEC & ITU-T
The international standards system gives PQC global reach. ISO/IEC JTC 1/SC 27 is the international home for cryptographic standards and typically adopts and aligns with NIST output, while ITU-T SG17 carries quantum-safe security into the telecom world. For many buyers, an ISO/IEC reference is what makes an algorithm procurable.
Why the international layer matters
A FIPS is a US federal standard. Many governments and enterprises outside the US prefer — or are required — to cite an international standard. ISO/IEC and ITU-T provide that layer: they take cryptography that has been analyzed and selected elsewhere and place it inside globally recognized standards families, smoothing cross-border procurement, certification, and compliance.
ISO/IEC JTC 1/SC 27
SC 27 (with cryptographic work centered in WG 2) is the international home for cryptographic mechanisms. Its established families are now incorporating PQC:
- ISO/IEC 18033-2 is the standards family for asymmetric encryption mechanisms; international adoption of PQC KEMs will typically proceed within this series or related revisions, and the specific project stage should be confirmed against the current ISO/IEC JTC 1/SC 27 work items.
- ISO/IEC 14888-3:2018 — discrete-logarithm-based signatures with appendix, which already includes
SM2andSM9. - ISO/IEC 14888-4:2024 — stateful hash-based signatures (XMSS/LMS family), published in 2024.
- ISO/IEC AWI 14888-5 — lattice-based signatures (ML-DSA/FN-DSA family), in development.
- ISO/IEC WD 14888-6 — stateless hash-based signatures (SLH-DSA family), in development.
- ISO/IEC 11770-3:2021 — key management using asymmetric techniques, key establishment.
SC 27 is also working to standardize the NIST lattice schemes internationally (see 14888-5 above). In practice, ISO often adopts or aligns with NIST output rather than designing competing algorithms, which keeps the global ecosystem coherent. For the stateful hash-based context, compare with SP 800-208.
ITU-T SG17 — telecom security
ITU-T Study Group 17 is the telecommunication standardization sector's security group. Its quantum-related work spans two strands:
- Quantum-safe guidance for telecom security mechanisms — X.1811 (Apr 2021), "Security guidelines for applying quantum-safe algorithms in IMT-2020 systems", carries algorithmic PQC into 5G.
- QKD networking — the X.1710-series addresses the architecture and security of quantum key distribution networks: X.1710 (2020) security framework for QKD networks, X.1713 (2024) protection of QKD nodes, and X.1714 (2020) key combination for QKDN. Note this is a different technology track from the algorithmic PQC that NIST standardizes. Do not treat QKD networking standards as PQC algorithm standards.
Relationship to NIST
| Question | NIST | ISO/IEC & ITU-T |
|---|---|---|
| Designs/selects algorithms? | Yes — runs the competition | Typically adopts & aligns |
| Scope | US federal standards (FIPS) | International standards |
| Procurement reach | Strong in US & allied govt | Broad global recognition |
| Telecom & QKD networks | Out of scope | ITU-T SG17 (X.1710-series) |
What this means for planning
If your obligations are framed in ISO/IEC terms, watch SC 27 for the international adoption of ML-KEM and ML-DSA and for the 14888-4 stateful hash-based work. Because ISO aligns with NIST, the underlying algorithms and parameters will match — the difference is the citation and certification path, not the cryptography. See the broader picture in Standards Overview.
Standards & references
- ISO/IEC 18033-2:2006 — Encryption algorithms, Part 2: Asymmetric ciphers (FDAmd 2 in progress)
- ISO/IEC 14888-3:2018 — Digital signatures with appendix, Part 3: Discrete logarithm based mechanisms
- ISO/IEC 14888-4:2024 — Digital signatures with appendix, Part 4: Stateful hash-based mechanisms
- ISO/IEC AWI 14888-5 — Part 5: Lattice-based mechanisms (in development)
- ISO/IEC WD 14888-6 — Part 6: Stateless hash-based mechanisms (in development)
- ISO/IEC 11770-3:2021 — Key management, Part 3: Mechanisms using asymmetric techniques
- ITU-T X.1710 (2020) — Security framework for QKD networks
- ITU-T X.1811 (2021) — Security guidelines for quantum-safe algorithms in IMT-2020 systems
ISO/IEC 与 ITU-T
国际标准体系赋予 PQC 全球适用性。ISO/IEC JTC 1/SC 27 是国际密码标准的归口,通常采纳并对齐 NIST 成果;ITU-T SG17 则把量子安全带入电信领域。对许多采购方而言,一份 ISO/IEC 引用才让某算法具备可采购性。
国际层面为何重要
FIPS 是美国联邦标准。美国之外的许多政府与企业更倾向于、甚至被要求引用国际标准。ISO/IEC 与 ITU-T 提供了这一层:它们把在别处完成分析与遴选的密码算法纳入全球公认的标准族,从而顺畅跨境采购、认证与合规。
ISO/IEC JTC 1/SC 27
SC 27(密码工作集中于 WG 2)是国际密码机制的归口。其既有标准族正在纳入 PQC:
- ISO/IEC 18033-2 是非对称加密机制所在标准族,PQC KEM 的国际采纳通常会在该系列或相关修订中推进;具体项目阶段应以 ISO/IEC JTC 1/SC 27 当前工作项为准。
- ISO/IEC 14888-3:2018,基于离散对数的带附录数字签名,已纳入
SM2与SM9。 - ISO/IEC 14888-4:2024,有状态哈希签名(XMSS/LMS 族),已于 2024 年发布。
- ISO/IEC AWI 14888-5,格基签名(ML-DSA/FN-DSA 族),制定中。
- ISO/IEC WD 14888-6,无状态哈希签名(SLH-DSA 族),制定中。
- ISO/IEC 11770-3:2021,基于非对称技术的密钥管理与密钥建立。
SC 27 也在推动将 NIST 格基算法国际标准化(见上述 14888-5)。实践中 ISO 往往采纳或对齐 NIST 成果,而非另起炉灶设计竞争算法,以保持全球生态的一致性。有状态哈希签名的语境可对照 SP 800-208。
ITU-T SG17 电信安全
ITU-T 第 17 研究组是电信标准化部门的安全工作组。其量子相关工作分为两条线索:
- 面向电信安全机制的量子安全指南,X.1811(2021 年 4 月)《在 IMT-2020 系统中应用量子安全算法的安全指南》将算法型 PQC 引入 5G。
- QKD 组网,X.1710 系列规定量子密钥分发网络的架构与安全:X.1710(2020) QKD 网络安全框架、X.1713(2024) QKD 节点防护、X.1714(2020) QKDN 密钥组合。需注意这与 NIST 标准化的算法型 PQC 属于不同的技术路线。不要把 QKD 网络标准当作 PQC 算法标准。
与 NIST 的关系
| 问题 | NIST | ISO/IEC 与 ITU-T |
|---|---|---|
| 是否设计/遴选算法 | 是,主持征集 | 通常采纳并对齐 |
| 范围 | 美国联邦标准(FIPS) | 国际标准 |
| 采购适用面 | 美国及盟国政府强 | 广泛的全球认可 |
| 电信与 QKD 网络 | 不在范围内 | ITU-T SG17(X.1710 系列) |
对规划的意义
若你的义务以 ISO/IEC 表述,请关注 SC 27 对 ML-KEM 与 ML-DSA 的国际采纳,以及 14888-4 的有状态哈希签名工作。由于 ISO 对齐 NIST,底层算法与参数将保持一致,差别在于引用与认证路径,而非密码本身。更全面的图景见 标准总览。
标准与参考
- ISO/IEC 18033-2:2006 加密算法 第 2 部分 非对称密码(FDAmd 2 制定中)
- ISO/IEC 14888-3:2018 带附录数字签名 第 3 部分 基于离散对数的机制
- ISO/IEC 14888-4:2024 带附录数字签名 第 4 部分 有状态哈希机制
- ISO/IEC AWI 14888-5 第 5 部分 格基机制(制定中)
- ISO/IEC WD 14888-6 第 6 部分 无状态哈希机制(制定中)
- ISO/IEC 11770-3:2021 密钥管理 第 3 部分 基于非对称技术的机制
- ITU-T X.1710(2020)QKD 网络安全框架
- ITU-T X.1811(2021)IMT-2020 系统量子安全算法安全指南