Observatory · Standards

Standards observatory

'NIST standardized PQC' does not mean every protocol and product is quantum-safe. Each artefact below carries its real status, because a draft transition document is not a regulation.

Dataset as of 2026-09-06
The migration stack
  1. 01Mathematical primitives — ML-KEM · ML-DSA · SLH-DSA
  2. 02Algorithm standards — FIPS 203 · 204 · 205
  3. 03Protocol standards — TLS · X.509 · CMS · JOSE · IKE/IPsec · SSH
  4. 04Crypto implementations — OpenSSL · OS crypto APIs · HSM firmware
  5. 05Trust infrastructure — PKI · CAs · KMS · IAM · code signing
  6. 06Platforms — cloud · network equipment · devices · applications
  7. 07Industry workflows — payments · telecom · healthcare · IoT · automotive · defense
  8. 08Organization migration — inventory · prioritize · procure · test · deploy · retire
FIPS 203finalA1NIST · 2024-08-13

ML-KEM — Module-Lattice Key Encapsulation

The core post-quantum key-establishment primitive.

FIPS 204finalA1NIST · 2024-08-13

ML-DSA — Module-Lattice Digital Signature Algorithm

The general-purpose post-quantum signature standard.

FIPS 205finalA1NIST · 2024-08-13

SLH-DSA — Stateless Hash-Based Signatures

Conservative hash-based signature alternative.

SP 800-227finalA1NIST · 2025-09-18

Recommendations for Key Encapsulation Mechanisms

Translates KEM primitives into secure usage.

NIST IR 8547draftA2NIST · 2024-11-12

Transition to Post-Quantum Cryptography Standards

The most quoted — and most misquoted — transition timeline.

CSWP 39finalA2NIST · 2026-06-29

Considerations for Achieving Crypto Agility

Connects PQ migration to routine algorithm replacement.

RFC 10024proposedA1IETF · 2026-08

Hybrid ML-KEM / ECDHE key exchange for TLS 1.3

Puts post-quantum TLS on the standards track.

RFC 9881finalA1IETF · 2025-10

ML-DSA in X.509 certificates

The bridge between post-quantum signatures and PKI.

RFC 9882finalA1IETF · 2025-10

ML-DSA in CMS

Signed content, enterprise messaging, document and code signing.

RFC 9964finalA1IETF · 2026-02

ML-DSA for JOSE and COSE

Application identity and token ecosystems.

RFC 9958finalA2IETF · 2026-01

Post-Quantum Cryptography for Engineers

The educational bridge from algorithms to engineering implications.

EU RoadmapadoptedA2EU · 2025-06

Coordinated Implementation Roadmap for PQC

The main EU-wide policy timeline.

ENISA studyfinalA2ENISA · 2025-01

Post-Quantum Cryptography Integration Study

System integration reference.

NCSC timelinesguidanceA2NCSC · 2025-03

UK PQC migration timelines

The clearest whole-economy migration planning framework.

GC roadmapguidanceA2CSE · 2025-06

Government of Canada PQC roadmap

Strong model for inventory, dependencies and migration governance.

ASD guidanceguidanceA2ASD · 2026-01

ASD post-quantum transition guidance

A comparatively aggressive 2030 completion target.

CNSA 2.0effectiveA1NSA · 2022-09

Commercial National Security Algorithm Suite 2.0

Defense and NSS procurement and product-design dependency.

CRYPTREC listfinalA1CRYPTREC · 2026-03-30

Japan e-Government recommended ciphers list

Japan's public-sector crypto procurement baseline as PQC enters it.

CSA QRIguidanceA2CSA · 2026-07

Quantum-Safe Migration Handbook and Quantum Readiness Index

Converts quantum risk into organisational self-assessment.

BIS reportfinalA2BIS · 2025-07

Quantum readiness for the financial system

Cross-border financial-sector roadmap.