NIST taps PQShield to map global rules for quantum-safe algorithms

The timeline for securing digital systems against quantum threats is surprisingly short, with national authorities now targeting 2030 for critical products and 2035 for standard ones. Once an academic exercise, post-quantum cryptography is rapidly becoming a practical necessity, yet implementation is proving complex. The landscape has dramatically shifted, creating regulatory differences as the US National Security Agency forbids hybrid cryptographic systems, directly contradicting the approach of European bodies like ANSSI in France and BSI in Germany, who mandate or strongly recommend them for backward compatibility.

Regional Adoption of ML-KEM and ML-DSA Post-NIST Standardization

National authorities are establishing distinct criteria for post-quantum cryptography (PQC) algorithm adoption, categorizing them as either globally or regionally specific to protocol system standards, creating challenges for product owners aiming for worldwide compliance. South Korea’s KCMVP certification program has not yet been updated with PQC algorithms, but anticipates the inclusion of ML-KEM and ML-DSA, alongside domestically selected KEMs NTRU+ and SMAUG-T, and signature algorithms AIMER and HAETAE, following a parallel development effort completed in January 2025.

Germany’s Bundesamt für Sicherheit in der Informationstechnik (BSI) recommends utilizing traditional cryptographic algorithms in conjunction with all algorithms, including hash-based options, in hybrid post-quantum/traditional (PQ/T) configurations, a stance sharply contrasted by the US National Security Agency (NSA). The BSI TR-02102-1 document details recommended parameter sets for ML-KEM, ML-KEM-768 or ML-KEM-1024, and ML-DSA, ML-DSA-65 or ML-DSA-87, alongside specifications for other algorithms like Classic McEliece and FrodoKEM.

While the BSI embraces a broad approach to PQC implementation, the NSA has no plans to incorporate SLH-DSA, FN-DSA, or HQC into its approved cryptographic suite, limiting LMS and XMSS to software and firmware signing applications only, European Cybersecurity Certification Group says. This divergence in regulatory approaches is further highlighted by France’s Agence Nationale de la Sécurité des Systèmes d’Information (ANSSI), which mandates or strongly recommends hybrid implementations featuring ML-KEM and ML-DSA, alongside FrodoKEM, for backward compatibility, a direct contradiction of the NSA’s position.

The European Cybersecurity Certification Group (ECCG) acknowledges ML-DSA and SLH-DSA, alongside other PQC options, but does not mandate a specific hybrid approach. The United Kingdom’s National Cyber Security Centre (NCSC) permits ML-DSA as an interim measure, but does not currently approve ML-KEM, demonstrating a fragmented landscape where national preferences significantly shape PQC adoption strategies.

China and South Korea’s National PQC Algorithm Certification

China and South Korea are actively establishing national certification programs for post-quantum cryptography algorithms, diverging from approaches seen elsewhere as deadlines for quantum-resistant systems approach. While the United States National Security Agency forbids hybrid post-quantum/traditional cryptographic systems for national security applications, China permits certified products integrating both foreign and standard algorithms, though these requirements do not apply to everyday consumer goods. This difference highlights a regional approach to implementation, creating complexities for product owners seeking global compliance.

These selections demonstrate a proactive stance toward establishing a domestically supported post-quantum infrastructure, even as international standards solidify. The nation anticipates a 2030 deadline for critical products and a 2035 deadline for standard products to achieve quantum-resilience, mirroring the timeframe established by other national authorities.

The Chinese approach, governed by its Cryptography Law, allows for the sale of cryptography products certified under its State Cryptography Administration, even if originating from foreign entities, while simultaneously updating its own cryptographic standards through national competitions, according to European Cybersecurity Certification Group. This dual pathway suggests a strategy of both embracing international collaboration and fostering domestic innovation in the field.

The European Cybersecurity Certification Group’s Agreed Cryptographic Mechanisms provides recommendations for high-assurance cybersecurity certifications, but national implementation varies significantly, as evidenced by the NSA’s restrictive stance on hybrid systems. A recent report from the UK’s National Cyber Security Centre states, “PQC should be viewed as the end goal,” emphasizing the long-term vision despite immediate implementation challenges.

EU Cyber Resilience Act and Algorithm Recommendations for 2026-2027

The European Cybersecurity Certification Group’s most recent recommendations, updated in May 2025 and again in April 2026, specify ML-KEM with either a 768 or 1024 parameter set for key encapsulation mechanisms, alongside ML-DSA-65 or ML-DSA-87 for digital signatures, aligning with a push for cryptography by 2026-2027 as mandated by the EU Cyber Resilience Act. Germany’s BSI TR-02102-1 document echoes these preferences, also listing Classic McEliece and FrodoKEM as viable options, while indicating intent to add HQC once standardized, demonstrating a convergence on a core set of algorithms despite regional nuances.

These algorithm selections are not static; documentation regarding KpqC algorithms indicates ongoing standardization processes and the expectation of further changes, requiring continuous adaptation from implementers. The BSI specifically recommends utilizing all algorithms, including hash-based ones, in a hybrid PQ/T form, while the NSA permits traditional algorithms like AES-256 and SHA-384/512 for specific applications, but restricts asymmetric traditional algorithms entirely.

This difference in approach highlights the complexities facing product owners navigating a fragmented regulatory landscape, as they seek global compliance with varying regional requirements. NCSC guidance further specifies that only ML-DSA should be used as a general-purpose signature, with LMS and XMSS reserved for case-by-case application, and expects users to select parameter sets based on system constraints.

“NCSC recommends migrating to PQ/T hybrid cryptography ‘where reasonable’ as an interim step,” reflecting a pragmatic approach to adoption. China categorizes ‘commercial cryptography’ as publicly available for use if certified by the State Cryptography Administration (SCA), with these commercial requirements not applying to everyday consumer goods.

Stay current

See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.

Avatar of Ivy Delaney

Ivy Delaney

Ivy Delaney has been working with neural networks and machine learning since the mid-nineties, back when a couple of hidden layers and a long afternoon of training counted as ambitious. She has watched the field go from academic curiosity to the thing quietly running underneath everything, and she brings that long view to quantum computing. For Quantum Zeitgeist she covers the ground where the two fields meet. That means quantum machine learning and the variational algorithms it leans on, and it also means the less glamorous but more interesting story of classical machine learning already doing real work inside quantum machines, decoding error-correcting codes, calibrating noisy hardware and learning the error models that simulators depend on. She writes about the hardware those algorithms have to run on too, and about the post-quantum cryptography scramble that the same hardware has set off. Her stories typically start with the paper, whether that is peer-reviewed work, conference proceedings or an arXiv preprint, with the source linked so you can hold a claim up against the research it came from. She is unimpressed by benchmarks that will not say what they beat, and by demonstrations that only work in the press release.

Latest Posts by Ivy Delaney: