Resources
A curated, verified register of the primary post-quantum cryptography standards and documents — grouped by standards body. Every link points to an official source. Status and dates are current as of June 2026; always confirm against the live document before implementing.
NIST — algorithms & transition guidance
NIST is the source of the core PQC algorithm standards and the US transition guidance.
| Document | What it is | Status | Link |
|---|---|---|---|
| FIPS 203 | ML-KEM — Module-Lattice key encapsulation | Final, Aug 2024 | csrc.nist.gov |
| FIPS 204 | ML-DSA — Module-Lattice signatures | Final, Aug 2024 | csrc.nist.gov |
| FIPS 205 | SLH-DSA — stateless hash-based signatures | Final, Aug 2024 | csrc.nist.gov |
| FIPS 206 | FN-DSA (Falcon) — compact lattice signatures | In development / clearance; public IPD not yet released; not a final FIPS standard | PQC project |
| SP 800-208 | Stateful hash-based signatures (LMS/XMSS) | Final, Oct 2020 | csrc.nist.gov |
| SP 800-227 | Recommendations for Key-Encapsulation Mechanisms | Final, 2025-09-18 | csrc.nist.gov |
| NIST IR 8547 | Transition to PQC Standards; proposes a time frame for gradually deprecating/disallowing quantum-vulnerable public-key algorithms. | Initial Public Draft, Nov 2024 | csrc.nist.gov |
| NIST IR 8545 | Status report on the Fourth Round (HQC selection) | Final, Mar 2025 | csrc.nist.gov |
| NIST IR 8528 | Additional-signature on-ramp: Round 1 status report is NIST IR 8528; Round 2 had 14 candidates; on 2026-05-14, 9 candidates advanced to Round 3. | Final, 2024 | csrc.nist.gov |
| SP 1800-38 | NCCoE practice guide — Migration to PQC | Preliminary drafts | nccoe.nist.gov |
Process pages: the NIST PQC project, the additional-signatures on-ramp (Round 2, 14 candidates), and the HQC selection announcement (Mar 2025).
IETF — protocol integration (RFCs & drafts)
The IETF defines how PQC enters real protocols. Several 2025 RFCs are now published; key exchange in TLS/SSH is still on drafts.
| Document | What it is | Type | Link |
|---|---|---|---|
| RFC 9794 | Terminology for PQ/Traditional hybrid schemes | RFC (Informational) | rfc-editor |
| RFC 9881 | ML-DSA algorithm identifiers for X.509 | RFC, 2025 | rfc-editor |
| RFC 9909 | SLH-DSA algorithm identifiers for X.509 | RFC, 2025 | rfc-editor |
| RFC 9935 | ML-KEM algorithm identifiers for X.509 | RFC, 2025 | rfc-editor |
| RFC 9882 / 9814 / 9936 | ML-DSA / SLH-DSA / ML-KEM in CMS | RFCs, 2025 | 9882 · 9814 · 9936 |
| RFC 9370 / 8784 | Multiple key exchanges in IKEv2 / PQ preshared keys | RFCs | 9370 · 8784 |
| RFC 8391 / 8554 | XMSS / LMS-HSS hash-based signatures | RFCs (Informational) | 8391 · 8554 |
| RFC 9708 / 9802 | HSS-LMS in CMS / HSS-XMSS in X.509 | RFCs | 9708 · 9802 |
| RFC 9941 | SSH hybrid KEX sntrup761x25519-sha512 | RFC (Informational), 2026-04 | rfc-editor |
| draft-ietf-tls-ecdhe-mlkem | TLS 1.3 hybrid X25519MLKEM768 (codepoint 4588) | Internet-Draft | datatracker |
| draft-ietf-tls-mldsa | ML-DSA authentication in TLS 1.3 | Internet-Draft | datatracker |
| lamps-pq-composite-sigs / -kem | Composite ML-DSA / ML-KEM for X.509 | Internet-Drafts | sigs · kem |
| sshm-mlkem-hybrid-kex | ML-KEM hybrid KEX in SSH (mlkem768x25519) | Internet-Draft | datatracker |
| connolly-cfrg-xwing-kem | X-Wing general-purpose hybrid KEM | Internet-Draft (CFRG) | datatracker |
ISO/IEC & ITU-T — international standards
| Document | What it is | Status | Link |
|---|---|---|---|
| ISO/IEC 14888-4:2024 | Stateful hash-based signatures (XMSS/LMS-type) | Published 2024 | iso.org |
| ISO/IEC 14888-5 / -6 | Lattice-based / stateless hash-based signatures | In development | -5 · -6 |
| ISO/IEC 18033-2 + FDAmd 2 | Asymmetric ciphers + PQC KEM amendment | Amendment in progress | iso.org |
| ISO/IEC 11770-3:2021 | Key management — asymmetric techniques | Published 2021 | iso.org |
| ITU-T X.1710 / X.1713 / X.1714 | QKD-network security framework / node protection / key combination | In force | itu.int |
| ITU-T X.1811 | Quantum-safe algorithms in IMT-2020 (5G) systems | In force, Apr 2021 | itu.int |
ETSI — migration & hybrid guidance
| Document | What it is | Link |
|---|---|---|
| ETSI TR 103 619 | Migration strategies and recommendations to quantum-safe schemes (2020-07) | etsi.org |
| ETSI TS 103 744 | Quantum-safe Hybrid Key Exchanges | etsi.org |
| ETSI TR 103 949 / TR 103 966 | QSC migration (C-ITS, 2023) / hybrid deployment considerations (2024) | etsi.org |
| ETSI/IQC QSC Conference | Annual quantum-safe cryptography conference (2026: Ottawa) | etsi.org |
National & regional guidance
| Authority | Document / stance | Link |
|---|---|---|
| NSA (US) | CNSA 2.0 — ML-KEM-1024, ML-DSA-87, LMS/XMSS; milestones to 2030–2033 (advisory updated May 2025) | media.defense.gov |
| White House / OMB (US) | NSM-10 (May 2022); OMB M-23-02 migration memo (Nov 2022) | M-23-02 |
| CISA/NSA/NIST (US) | Quantum-Readiness: Migration to PQC factsheet (Aug 2023) | media.defense.gov |
| BSI (Germany) | TR-02102-1 — recommends ML-KEM + FrodoKEM + Classic McEliece; hybrid-first (v2026-01) | bsi.bund.de |
| ANSSI (France) | PQC position (Jan 2022) + follow-up (11 October 2023) — phased, hybrid-first | cyber.gouv.fr |
| NCSC (UK) | Timelines for migration to PQC — 2028 / 2031 / 2035 (Mar 2025) | ncsc.gov.uk |
| EU / ENISA | Recommendation (EU) 2024/1101 coordinated roadmap; ENISA PQC studies | eur-lex |
Telecom — 3GPP & GSMA
| Document | What it is | Link |
|---|---|---|
| 3GPP TR 33.841 | Study on 256-bit algorithms for 5G (symmetric, Rel-16) | 3gpp.org |
| 3GPP TR 33.938 | Cryptographic inventory of 3GPP security protocols (Rel-19) — basis for PQC migration | 3gpp.org |
| 3GPP TS 33.501 | 5G security architecture — SUCI/ECIES (the Shor-vulnerable target) | 3gpp.org |
| GSMA PQ.01 / PQ.02 / PQ.03 | PQTN Impact Assessment / Quantum Risk Management / PQC Guidelines for Telecom (v2.0) | gsma.com |
China — commercial cryptography (商用密码)
| Item | What it is | Link |
|---|---|---|
| GM/T 0003 / 0004 / 0002 / 0044 / 0001 | SM2 / SM3 / SM4 / SM9 / ZUC national standards | GM-Standards |
| ISO/IEC adoptions | SM2/SM9 in 14888-3, SM3 in 10118-3, SM4 in 18033-3, ZUC in 18033-4 | iso.org |
| ICCS / SCA | Next-generation commercial cryptographic algorithms call (Feb 2025) — classical + quantum resistance | oscca.gov.cn |
Implementations & tools
- Open Quantum Safe (OQS) — liboqs C library, language wrappers, and the OpenSSL provider.
- PQClean — clean, portable reference C implementations.
- oqs-provider — PQC for OpenSSL 3; OpenSSL 3.5+ natively supports ML-KEM, ML-DSA, and SLH-DSA; default TLS negotiation behavior depends on the specific OpenSSL minor version and distribution configuration.
- NIST CAVP / ACVP — validation and test vectors.
Explore this site
Standards →
FIPS 203/204/205, SP 800-208/227, IR 8547.
Global & Industry →
IETF, ISO/IEC, ETSI, regional, telecom.
Comparison →
Algorithm sizes and trade-offs at a glance.
Migration →
Crypto-agility, hybrid, discovery, playbook.
资源链接
一份经核实的后量子密码核心标准与文档清单,按标准组织分组。每个链接都指向官方来源。状态与日期 截至 2026 年 6 月;实现前请以在线原文为准。
NIST 算法与迁移指南
NIST 是 PQC 核心算法标准与美国迁移指南的来源。
| 文档 | 内容 | 状态 | 链接 |
|---|---|---|---|
| FIPS 203 | ML-KEM——模格密钥封装 | 正式版 2024-08 | csrc.nist.gov |
| FIPS 204 | ML-DSA——模格签名 | 正式版 2024-08 | csrc.nist.gov |
| FIPS 205 | SLH-DSA——无状态哈希签名 | 正式版 2024-08 | csrc.nist.gov |
| FIPS 206 | FN-DSA(Falcon)——紧凑格签名 | 拟定中 / 审批中;公开 IPD 尚未发布;未成为最终 FIPS 标准。 | PQC 项目 |
| SP 800-208 | 有状态哈希签名(LMS/XMSS) | 正式版 2020-10 | csrc.nist.gov |
| SP 800-227 | 密钥封装机制使用建议 | 正式版 2025-09-18 | csrc.nist.gov |
| NIST IR 8547 | 向 PQC 标准迁移;提出逐步弃用/禁用量子脆弱公钥算法的时间框架。 | 公开征求意见草案 2024-11 | csrc.nist.gov |
| NIST IR 8545 | 第四轮状态报告(HQC 入选) | 正式版 2025-03 | csrc.nist.gov |
| NIST IR 8528 | 新增签名征集:第一轮状态报告 NIST IR 8528;第二轮 14 个候选;2026-05-14 已推进 9 个候选进入第三轮。 | 正式版 2024 | csrc.nist.gov |
| SP 1800-38 | NCCoE 实践指南——迁移到 PQC | 初步草案 | nccoe.nist.gov |
过程页面:NIST PQC 项目、 新增签名征集第二轮(14 个候选), 以及 HQC 入选公告(2025-03)。
IETF 协议集成 RFC 与草案
IETF 定义 PQC 如何进入真实协议。多份 2025 年 RFC 已正式发布;TLS/SSH 的密钥交换仍处于草案阶段。
| 文档 | 内容 | 类型 | 链接 |
|---|---|---|---|
| RFC 9794 | 后量子与传统混合方案术语 | RFC(信息类) | rfc-editor |
| RFC 9881 | X.509 中 ML-DSA 算法标识 | RFC 2025 | rfc-editor |
| RFC 9909 | X.509 中 SLH-DSA 算法标识 | RFC 2025 | rfc-editor |
| RFC 9935 | X.509 中 ML-KEM 算法标识 | RFC 2025 | rfc-editor |
| RFC 9882 / 9814 / 9936 | CMS 中的 ML-DSA / SLH-DSA / ML-KEM | RFC 2025 | 9882 · 9814 · 9936 |
| RFC 9370 / 8784 | IKEv2 多重密钥交换 / 后量子预共享密钥 | RFC | 9370 · 8784 |
| RFC 8391 / 8554 | XMSS / LMS-HSS 哈希签名 | RFC(信息类) | 8391 · 8554 |
| RFC 9708 / 9802 | CMS 中 HSS-LMS / X.509 中 HSS-XMSS | RFC | 9708 · 9802 |
| RFC 9941 | SSH 混合密钥交换 sntrup761x25519-sha512 | RFC(信息类),2026-04 | rfc-editor |
| draft-ietf-tls-ecdhe-mlkem | TLS 1.3 混合 X25519MLKEM768(码点 4588) | Internet-Draft | datatracker |
| draft-ietf-tls-mldsa | TLS 1.3 中 ML-DSA 认证 | Internet-Draft | datatracker |
| lamps-pq-composite-sigs / -kem | X.509 复合 ML-DSA / ML-KEM | Internet-Draft | sigs · kem |
| sshm-mlkem-hybrid-kex | SSH 中 ML-KEM 混合密钥交换(mlkem768x25519) | Internet-Draft | datatracker |
| connolly-cfrg-xwing-kem | X-Wing 通用混合 KEM | Internet-Draft(CFRG) | datatracker |
ISO/IEC 与 ITU-T 国际标准
| 文档 | 内容 | 状态 | 链接 |
|---|---|---|---|
| ISO/IEC 14888-4:2024 | 有状态哈希签名(XMSS/LMS 类) | 已发布 2024 | iso.org |
| ISO/IEC 14888-5 / -6 | 格类 / 无状态哈希类签名 | 制定中 | -5 · -6 |
| ISO/IEC 18033-2 + FDAmd 2 | 非对称加密 + PQC KEM 修订 | 修订进行中 | iso.org |
| ISO/IEC 11770-3:2021 | 密钥管理——非对称技术 | 已发布 2021 | iso.org |
| ITU-T X.1710 / X.1713 / X.1714 | QKD 网络安全框架 / 节点保护 / 密钥组合 | 现行 | itu.int |
| ITU-T X.1811 | IMT-2020(5G)系统中量子安全算法指南 | 现行 2021-04 | itu.int |
ETSI 迁移与混合指南
| 文档 | 内容 | 链接 |
|---|---|---|
| ETSI TR 103 619 | 向量子安全方案迁移的策略与建议(2020-07) | etsi.org |
| ETSI TS 103 744 | 量子安全混合密钥交换 | etsi.org |
| ETSI TR 103 949 / TR 103 966 | QSC 迁移(C-ITS 2023)/ 混合方案部署考量(2024) | etsi.org |
| ETSI/IQC QSC 大会 | 年度量子安全密码大会(2026 渥太华) | etsi.org |
各国与地区监管
| 机构 | 文档与立场 | 链接 |
|---|---|---|
| NSA 美国 | CNSA 2.0——ML-KEM-1024、ML-DSA-87、LMS/XMSS;里程碑至 2030–2033(2025-05 更新) | media.defense.gov |
| 白宫 / OMB 美国 | NSM-10(2022-05);OMB M-23-02 迁移备忘录(2022-11) | M-23-02 |
| CISA/NSA/NIST 美国 | 量子就绪——迁移到 PQC 简报(2023-08) | media.defense.gov |
| BSI 德国 | TR-02102-1——推荐 ML-KEM + FrodoKEM + Classic McEliece;优先混合(v2026-01) | bsi.bund.de |
| ANSSI 法国 | PQC 立场(2022-01)与后续(2023 年 10 月 11 日)——分阶段优先混合 | cyber.gouv.fr |
| NCSC 英国 | PQC 迁移时间表——2028 / 2031 / 2035(2025-03) | ncsc.gov.uk |
| EU / ENISA | 建议 (EU) 2024/1101 协调路线图;ENISA PQC 研究 | eur-lex |
电信 3GPP 与 GSMA
| 文档 | 内容 | 链接 |
|---|---|---|
| 3GPP TR 33.841 | 5G 256 位算法研究(对称,Rel-16) | 3gpp.org |
| 3GPP TR 33.938 | 3GPP 安全协议密码资产清查(Rel-19)——PQC 迁移基础 | 3gpp.org |
| 3GPP TS 33.501 | 5G 安全架构——SUCI/ECIES(Shor 可攻破目标) | 3gpp.org |
| GSMA PQ.01 / PQ.02 / PQ.03 | PQTN 影响评估 / 量子风险管理 / 电信 PQC 指南(v2.0) | gsma.com |
中国商用密码
| 条目 | 内容 | 链接 |
|---|---|---|
| GM/T 0003 / 0004 / 0002 / 0044 / 0001 | SM2 / SM3 / SM4 / SM9 / ZUC 国家标准 | GM-Standards |
| ISO/IEC 采纳 | SM2/SM9 入 14888-3,SM3 入 10118-3,SM4 入 18033-3,ZUC 入 18033-4 | iso.org |
| ICCS / 国家密码管理局 | 新一代商用密码算法征集(2025-02)——要求抗经典与量子攻击 | oscca.gov.cn |
实现与工具
- Open Quantum Safe(OQS)——liboqs C 库、各语言封装与 OpenSSL 提供者。
- PQClean——干净可移植的参考 C 实现。
- oqs-provider——OpenSSL 3 的 PQC 提供者;OpenSSL 3.5+:原生支持 ML-KEM、ML-DSA、SLH-DSA;TLS 默认协商行为需以具体 OpenSSL 小版本与发行版配置为准。
- NIST CAVP / ACVP——验证与测试向量。
浏览本站
标准规范 →
FIPS 203/204/205、SP 800-208/227、IR 8547。
国际与行业 →
IETF、ISO/IEC、ETSI、各国监管、电信。
算法对比 →
各方案尺寸与取舍一览。
迁移 →
密码敏捷性、混合、资产发现、实战手册。