PQC Library

The standards, drafts and guidance that define post-quantum cryptography.

What this means for you

Executive / Business Leader
Pick the "Plan migration" door for guidance and report picks rather than raw specifications; sort by Urgency, and each document's panel shows a Migration urgency value and an "Open document" link to the original.
GRC / Risk & Compliance
The "Cert-relevant" quick view is the FIPS 203–205, SP 800-208 and CMVP set; open any document for its Trust score, Vetting body, Peer reviewed and last-verified date, and "Authoritative sources only" under Advanced drops the rest.
Developer / Engineer
Search "ML-KEM", "FIPS 203" or "hybrid TLS", or open Advanced and filter by Algorithm family; the "Reference" door keeps standards, specs and policy, and "Builds on" in a document's panel lists what it depends on.
Security Architect
The "Reference" door holds standards, specs and policy; a document's panel lists what it "Builds on", its "Previous revisions" and the "CSWP-39 requirements" it satisfies, each linking to the matching Command Center zone.
Researcher / Academic
Sort by Publication date or Most cited; every document panel shows its type, region, last-verified date, Trust score, Peer reviewed status and "Previous revisions", with "Open document" going to the original source.
Certification & Validation Engineer
The "Cert-relevant" quick view is the FIPS 203–205, SP 800-208 and CMVP set; your categories lead with Compliance & Certification, NIST Standards and Algorithm Specifications.
IT Ops / DevOps
"Start here — picked for" your role sits above the doors; the "Cert-relevant" quick view is FIPS 203–205, SP 800-208 and the CMVP manual, and Lifecycle status filters to Published so you are not configuring against a draft.
Curious Explorer
Pick the "Learn" door for research, analysis and explainers; "Recently changed" at the top shows what was just added or updated, and the search box takes plain words like "hybrid TLS".
Recently changed1012 docs
1275 documents
openfhe-v1.6.0New

C++ library for BGV, BFV, CKKS, CGGI/FHEW, threshold FHE and proxy re-encryption.

Web page · 216 KB · a long read

MiscIndustry & Research
OpenFHE (NJIT, Duality Technologies and contributors)Sep 28, 2026
Trust 36Needs review
tfhe-rs-v1.8.1New

Pure-Rust TFHE (CGGI) library from Zama with seeded client-key generation and compressed server keys; WASM bindings.

Web page · 209 KB · a long read

MiscIndustry & Research
ZamaSep 17, 2026
Trust 36Needs review
PCI-SSC-Blog-KMO-v1-0-PublishedNew

PCI Perspectives blog post of 14 September 2026 announcing publication of the PCI Key Management and Operations (KMO) Standard v1.0.

Web page · 83 KB · a short read

MiscCompliance & CertificationReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
PCI Security Standards Council (PCI Perspectives blog)Sep 14, 2026
Trust 34Needs review
draft-ietf-jose-pq-composite-sigsNew

JOSE and COSE serializations for PQ/T hybrid composite signatures that combine ML-DSA with ECDSA or EdDSA (six algorithms, e.g. ML-DSA-65-ES256, ML-DSA-65-Ed25519). Revision -04 signs the message representative M' directly, uses uncompressed EC public keys and DER-encoded ECDSA components, and publishes JOSE and COSE examples in Appendix A.

Web page · 359 KB · a long read

ReleasedDigital Signature1 rev
IETFSep 11, 2026
Trust 85Authoritative
draft-ietf-lamps-pq-composite-kem-21Updated

Composite ML-KEM public keys and algorithms for X.509 (also used by CMS/S-MIME, EST and CMP): an ML-KEM key and a classical KEM key (X25519, ECDH, RSA-OAEP) under one OID in the id-pkix 1.3.6.1.5.5.7.6.55-.66 range, ML-KEM component first; .58 = id-MLKEM768-X25519-SHA3-256. Revision -21; in IESG Evaluation.

Web page · 475 KB · a long read

DraftProtocolsPKI Certificate Management8 revsReviewed (LLM) · eramusa · Oct 2026 · via manual data edit (library)
IETF LAMPS WGSep 1, 2026
Trust 41Needs review
NIAP-CCEVS-POLICY-33Updated

NIAP policy requiring CNSA 2.0 for every cryptographic function in NIAP/CCRA-certified products used in US National Security Systems: effective 2027-01-01; non-CNSA 2.0 products not accepted into NIAP evaluation from 2028-01-01 and not posted to the NIAP PCL from 2029-01-01 (CNSA 1.0 cut-offs 2027-01-01 / 2027-07-01).

PDF · 193 KB · a short read

ReleasedCompliance & CertificationCriticalReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (LM-068 regional remediation)
NIAPAug 31, 2026
Trust 62Needs review
Post-Quantum-Composite-Signatures-in-SSHUpdated

Specifies composite post-quantum signatures — PQC plus classical under one identifier — in the SSH protocol.

Web page · 84 KB · a short read

DraftDigital SignatureProtocolsHigh
Damien Miller (OpenSSH)Aug 21, 2026
Trust 81Authoritative
TCG-TPM-2.0-Library-v1.85-Errata

Errata to TCG TPM 2.0 Library v1.85. Corrections to ML-DSA, ML-KEM, Labeled KEM command definitions.

PDF · 248 KB · a short read

ReleasedPKI Certificate Management
Trusted Computing Group (TCG)Aug 11, 2026
Trust 89Authoritative
Module-Lattice-Digital-Signature-Algorithm-for-DNSSEC

Defines DNSSEC DS/DNSKEY/RRSIG use of the ML-DSA-44 parameter set from FIPS 204, assigning DNSSEC algorithm number 18 (mnemonic MLDSA44); basis for Cloudflare's 2026-09-10 1.1.1.1 resolver pilot.

Web page · 60 KB · a short read

DraftProtocols
B. Westerbaan (Cloudflare); S. Schmieg (Google)Aug 11, 2026
Trust 54Needs review
arXiv-2602-21524-Quantum-Attacks-NuclearUpdated

Research paper (arXiv:2602.21524v2, Baseri and Waller) analysing the quantum threat to nuclear power plant I&C. States that Shor’s algorithm renders RSA and ECC "the cryptographic bedrock of industrial authentication, firmware signing, and secure communications" and models complete breaks of RSA-2048 and ECC-256/384. Cited as research, not as a specification: IEC 62645 is paywalled and IAEA NSS 33-T names no cryptographic algorithm at all.

PDF · 1.3 MB · a long read

Research PaperIndustry & ResearchHigh
Yaser Baseri, Edward Waller (arXiv:2602.21524)Jul 30, 2026
Trust 53Needs review
2026-Minimum-Elements-for-a-Software-Bill-of-Materials-SBOMUpdated

Finalized v2.1 update to the SBOM Minimum Elements, co-authored by CISA, NSA, FBI and 15 international partner cyber agencies (Australia's ACSC, Canadian Centre for Cyber Security, Czech NUKIB, French ANSSI, German BSI, Indian CERT-In, Italian ACN, Japan's METI/NCO, NIS/NCSC, South Korea's KISA, Dutch NCSC-NL, New Zealand's NCSC-NZ, Polish NASK, Ukrainian NBU). Preserves the 2021 NTIA baseline's core principles while adding 10 new required SBOM elements (SBOM Author Signature, SBOM/Data-Format Version and Name, Component Hash Value/Algorithm, SBOM Generation Context, SBOM Tool Name/Version, Component License) plus clarified scope on 8 existing fields. Version 2.0 (Aug 2025) was a public-comment draft; this 2.1 release (July 29, 2026) is the final successor NTIA-SBOM-Minimum-Elements-2021 anticipated but had not yet seen.

PDF · 1.3 MB · a long read

ReleasedGovernment & Policy1 rev
CISA (lead); NSA; FBI; and 15 international partner cyber agencies (ASD's ACSC, Canadian Centre for Cyber Security, NUKIB, ANSSI, BSI, CERT-In, ACN, METI/NCO, NIS/NCSC, KISA, NCSC-NL, NCSC-NZ, NASK, NBU)Jul 29, 2026
Trust 63Needs review
NIST-CMVP-Cert-5450Updated

Web page · 121 KB · a short read

MiscMigration Guidance
NIST CMVPJul 29, 2026
Trust 26Needs review
draft-ietf-tls-mlkem-07Updated

Defines ML-KEM-512 ML-KEM-768 and ML-KEM-1024 as NamedGroups for pure PQ key agreement in TLS 1.3. WGLC issues identified requiring revision. Expires Aug 2026.

Web page · 65 KB · a short read

DraftProtocolsHigh2 revs
IETF TLS WGJul 28, 2026
Trust 78Authoritative
SLH-DSA-for-JOSE-and-COSEUpdated

Defines how SLH-DSA signatures are represented in JOSE and COSE — the token and object-signing formats.

Web page · 115 KB · a short read

DraftAlgorithm SpecificationsHigh
IETF COSE WG (Michael Prorock, mesur.io; Orie Steele, Tradeverifyd; Hannes Tschofenig, UniBw M.)Jul 28, 2026
Trust 81Authoritative
draft-ietf-lamps-pq-composite-sigs-19Updated

Composite signature OIDs binding ML-DSA-44/65/87 with classical ECDSA, RSA, Ed25519, EdDSA.

Web page · 764 KB · a long read

ReleasedDigital SignaturePKI Certificate Management4 revs
M. Ounsworth; J. Gray; M. Pala; J. Klaußner; S. Fluhrer (IETF LAMPS WG)Jul 27, 2026
Trust 75Authoritative
cosmos-sdk-CHANGELOG-ML-DSA-65-FIPS-204-validator-account-keUpdated

cosmos-sdk's own CHANGELOG.md, v0.55.0 (2026-07-27) Features section: 'Add ML-DSA-65 (FIPS 204) post-quantum validator consensus key type, with SDK key wrappers, Amino + interface-registry registration, multisig support, and a hd.MlDsa65Type constant' (PR #26436) and 'Add ML-DSA-65 (FIPS 204) support for user account keys: mnemonic-based keyring creation/recovery (--algo ml_dsa_65), transaction signing/verification' (PR #26472). Real, shipped, PR-linked code — not a roadmap or proposal.

Web page · 109 KB · a short read

MiscIndustry & Research
Cosmos SDK contributorsJul 27, 2026
Trust 46Needs review
draft-ietf-ipsecme-ikev2-pqc-auth-08Updated

Defines ML-DSA-44/65/87 and SLH-DSA-128s/192s/256s as IKEv2 authentication methods.

Web page · 93 KB · a short read

ReleasedDigital SignatureProtocols2 revs
T. Reddy (Nokia); V. Smyslov (ELVIS-PLUS); S. Fluhrer (Cisco)Jul 24, 2026
Trust 71Authoritative
Composite-ML-DSA-Signatures-for-SSHUpdated

Defines how composite ML-DSA signatures — one PQC and one classical algorithm under a single identifier — are carried in SSH.

Web page · 66 KB · a short read

DraftProtocols
Sun Shuzhou; Lucas Prabel (Huawei)Jul 24, 2026
Trust 70Authoritative
draft-ietf-ipsecme-hybrid-kem-ikev2-frodo-00Updated

WG-adopted from wang-ipsecme-hybrid-kem-ikev2-frodo. Defines FrodoKEM-as-additional-KE in IKEv2.

Web page · 81 KB · a short read

DraftKEMProtocols1 rev
C. Wang et al. (IETF IPSECME WG)Jul 23, 2026
Trust 65Needs review
draft-ietf-sshm-mlkem-hybrid-kex-10Updated

Defines mlkem768x25519-sha256 and similar hybrid SSH KEX methods.

Web page · 87 KB · a short read

DraftProtocols3 revs
P. Kampanakis; D. Stebila; T. Hansen (IETF SSHM WG)Jul 22, 2026
Trust 71Authoritative
draft-becker-cnsa2-ssh-profile-03Updated

Maps NSA CNSA 2.0 mandate (ML-KEM-1024, ML-DSA-87) to OpenSSH config from 2027.

Web page · 74 KB · a short read

DraftProtocols1 rev
A. Becker; M. Jenkins; C. Wynn (NSA)Jul 22, 2026
Trust 71Authoritative
draft-ietf-mls-pq-ciphersuites-06Updated

Registers post-quantum cipher suites combining ML-KEM with AEAD/hash/signature for MLS.

Web page · 71 KB · a short read

DraftProtocols1 rev
R. Mahy; R. Barnes (Cisco)Jul 21, 2026
Trust 71Authoritative
Merkle-Tree-Agent-Certificates-MTAC-Batch-Issued-Post-QuantuUpdated

Proposes batch-issued post-quantum identity credentials built on Merkle trees, to amortise certificate size across many identities.

Web page · 102 KB · a short read

DraftPKI Certificate Management
Reuben Burls (Aelethion OU)Jul 21, 2026
Trust 71Authoritative
draft-ietf-ipsecme-ikev2-mlkem-05Updated

Specifies ML-KEM-512/768/1024 as standalone IKEv2 KE transforms and as additional KE within RFC 9370.

Web page · 81 KB · a short read

DraftKEMProtocols2 revs
P. Kampanakis (IETF IPSECME WG)Jul 20, 2026
Trust 72Authoritative
EAP-WSIM-SIM-Based-EAP-Authentication-for-Enterprise-Wi-Fi-UUpdated

Proposes SIM-based EAP authentication for enterprise Wi-Fi using MILENAGE, with post-quantum considerations.

Web page · 125 KB · a short read

DraftProtocols
Praveen Gupta (MobileStack, Inc.)Jul 20, 2026
Trust 71Authoritative
GSS-API-Key-Exchange-with-hybrid-ML-KEM

Defines GSS-API key exchange methods using hybrid PQ/T cryptography for SSH, updating RFC 4462 and reusing schemes from I-D.ietf-sshm-mlkem-hybrid-kex for GSS-API authentication.

Web page · 60 KB · a short read

DraftProtocols
Individual submission (IETF-hosted)Jul 18, 2026
Trust 71Authoritative
Post-quantum-Key-Encapsulation-with-ML-KEM-in-Public-Key-CryUpdated

Specifies ML-KEM key encapsulation for the initial public-key exchange in the protocol it profiles.

Web page · 93 KB · a short read

DraftProtocols
Individual submission (IETF-hosted)Jul 18, 2026
Trust 72Authoritative
draft-ietf-pquip-hbs-state

Guidance on managing stateful HBS (LMS/XMSS) state to prevent catastrophic key reuse. Covers state persistence and distributed signing strategies.

Web page · 112 KB · a short read

DraftDigital Signature
IETF PQUIP WGJul 17, 2026
Trust 75Authoritative
draft-ietf-tls-hybrid-design-16

Framework for hybrid key exchange combining traditional and PQ algorithms in TLS 1.3.

Web page · 80 KB · a short read

DraftProtocolsHigh
IETF TLS WGJul 15, 2026
Trust 77Authoritative
draft-ietf-lamps-cms-composite-kem

LAMPS WG-adopted draft specifying composite ML-KEM (ML-KEM + RSA-OAEP / ECDH / X25519 / X448) within CMS KEMRecipientInfo per RFC 9629. Profiles the X.509 composite-KEM construction into CMS for S/MIME-encrypted email and CMS-based protocols. Latest revision -01, Proposed Standard.

Web page · 91 KB · a short read

DraftProtocols
IETF LAMPS WGJul 15, 2026
Trust 81Authoritative
OASIS-Approves-Two-Public-Key-Cryptography-Standards-to-AdvaUpdated

OASIS announcement approving two public-key cryptography standards advancing post-quantum adoption — a dated marker for procurement references.

Web page · 146 KB · a short read

MiscProtocolsHigh
OASIS OpenJul 15, 2026
Trust 54Needs review
CA/Browser Forum Ballot SC-PQC

CA/Browser Forum requirements for ML-DSA certificates in Web PKI.

Web page · 7 KB · a quick skim

ReleasedPKI Certificate ManagementHigh
CA/Browser ForumJul 14, 2026
Trust 56Needs review
draft-ietf-tls-mldsa-03Updated

Specifies use of ML-DSA-44/65/87 signature schemes in TLS 1.3 server authentication.

Web page · 59 KB · a short read

DraftDigital SignatureProtocols3 revs
T. Hollebeek; S. Schmieg; B. Westerbaan (IETF TLS WG)Jul 8, 2026
Trust 70Authoritative
draft-ietf-hpke-pqUpdated

Extends HPKE (RFC 9180) with post-quantum and hybrid PQ/T key encapsulation mechanisms including ML-KEM and hybrid combinations with X25519 and P-256. Enables quantum-safe HPKE for email encryption, messaging, and ECH.

Web page · 208 KB · a long read

DraftProtocols
IETF HPKE WGJul 6, 2026
Trust 67Needs review
draft-ietf-mls-extensions-09

Generic MLS extensions framework supporting PQ ciphersuites and other extensions.

Web page · 123 KB · a short read

DraftProtocols
R. Robert (Phoenix R&D)Jul 6, 2026
Trust 63Needs review
draft-ietf-jose-hpke-encrypt

Defines how JWE uses HPKE in two modes: Integrated Encryption (HPKE encrypts the payload; the header carries only "alg", the JWE Encrypted Key is the encapsulated secret, IV and tag are empty) and Key Encryption (HPKE wraps the CEK; the encapsulated secret goes in "ek"). Registers the classical DHKEM suites HPKE-0 to HPKE-7; the post-quantum and PQ/T suites are registered separately in draft-ietf-jose-hpke-pq-pqt.

Web page · 224 KB · a long read

DraftKEM
IETF JOSE WGJul 6, 2026
Trust 77Authoritative
Hybrid-Post-Quantum-Password-Authenticated-Key-Exchange

Hybrid aPAKE combining classical CPace with post-quantum OQUAKE+ (ML-KEM-based); addresses Harvest-Now-Decrypt-Later exposure of classical PAKEs like OPAQUE-3DH/SPAKE2+.

Web page · 150 KB · a short read

DraftProtocols
Individual submission (IETF-hosted)Jul 6, 2026
Trust 71Authoritative
Multi-Authentication-in-IKEv2-with-Post-quantum-Security

Lets IKEv2 peers negotiate two or more authentication methods via a new IKEv2 Authentication Method registry value (17) and SUPPORTED_AUTH_METHODS notify, for PQC transition defense-in-depth.

Web page · 74 KB · a short read

DraftProtocols
Individual submission (IETF-hosted)Jul 6, 2026
Trust 71Authoritative
Post-Quantum-Key-Encapsulation-Mechanisms-PQ-KEMs-for-COSE

WG-track draft specifying ML-KEM-512/768/1024 for COSE Direct Key Agreement and Key Agreement with Key Wrap modes; hybrid PQ KEMs explicitly out of scope for this document.

Web page · 78 KB · a short read

DraftProtocols
IETF cose WGJul 6, 2026
Trust 81Authoritative
Module-Lattice-Based-Signatures-with-Merkle-Tree-Ladders-MLUpdated

Applies Merkle tree ladders to ML-DSA for DNSSEC, addressing the response-size problem post-quantum signatures create for DNS.

Web page · 89 KB · a short read

DraftProtocols
A. Kaizer; J. Harvey; B. Kaliski; S. Sheth (Verisign Labs)Jul 6, 2026
Trust 71Authoritative
N-PAMP-Native-Post-Quantum-Agent-Messaging-ProtocolUpdated

Proposes a messaging protocol for software agents built post-quantum from the start rather than retrofitted.

Web page · 117 KB · a short read

DraftProtocols
Shawn Edward Sammartano (BubbleFish Technologies, Inc.)Jul 6, 2026
Trust 71Authoritative
draft-ietf-jose-hpke-pq-pqt-01

Registers the post-quantum and PQ/T hybrid HPKE algorithms for JOSE: HPKE-12/13 (ML-KEM-768/1024) and HPKE-8/9/10 (ML-KEM-768+P-256, ML-KEM-768+X25519 i.e. X-Wing, ML-KEM-1024+P-384), all with SHAKE256 and AES-256-GCM, for Integrated Encryption and Key Encryption (-KE) per draft-ietf-jose-hpke-encrypt. Keys use the AKP key type of RFC 9964. Appendix A publishes test vectors for every algorithm.

Web page · 192 KB · a long read

DraftKEM
IETF JOSE Working GroupJul 6, 2026
Trust 62Needs review
Preventing-Key-Reuse-and-Cross-Key-Forgeries-in-Composite-MLUpdated

Addresses a real attack class in composite ML-DSA: reusing a component key across contexts, and forging across the pair.

Web page · 55 KB · a short read

DraftProtocols
Individual submission (IETF-hosted)Jul 5, 2026
Trust 71Authoritative
draft-ietf-ipsecme-ikev2-mlkem-09

ML-KEM key exchange for IKEv2 (IPsec), pure and hybrid. Section 2.1 allows ML-KEM-512 alone in IKE_SA_INIT over UDP; ML-KEM-768/1024 SHOULD NOT be used there without a guaranteed path MTU or reliable transport.

Web page · 82 KB · a short read

DraftProtocols
IETF IPSECME WGJul 5, 2026
Trust 45Needs review
Post-Quantum-Cryptography-Recommendations-for-TLS-based-Appl

WG-adopted best-practice recommendations for quantum-ready TLS/DTLS 1.3 application profiles: hybrid key exchange preferred, composite certificates for transition, External PSK as CRQC mitigation.

Web page · 103 KB · a short read

DraftProtocols
IETF uta WGJul 4, 2026
Trust 81Authoritative
draft-yusef-tls-pqt-dual-certs

This document defines a TLS 1.3 extension for dual-certificate hybrid authentication using separate traditional and post-quantum signature algorithms.

Web page · 85 KB · a short read

DraftProtocolsHigh
Rifaat Shekh-Yusef; Hannes Tschofenig; Mike Ounsworth; Tirumaleswar Reddy.K; Yaroslav RosomakhoJul 3, 2026
Trust 65Needs review
KEM-based-Authentication-for-IKEv2-with-Post-quantum-Securit

Proposes ML-KEM-based authentication for IKEv2 (more efficient than ML-DSA signatures) using an Encrypted Certificate payload; accommodates ideas from the PQuAKE protocol.

Web page · 96 KB · a short read

DraftProtocols
Individual submission (IETF-hosted)Jul 3, 2026
Trust 71Authoritative
Post-Quantum-Signature-Algorithm-Profile-and-Migration-ConsiUpdated

Profiles which post-quantum signature algorithms apply to its target protocol, and what migrating to them involves.

Web page · 109 KB · a short read

DraftProtocols
Individual submission (IETF-hosted)Jul 3, 2026
Trust 71Authoritative
Singapore IMDA Cyber Security GuideUpdated

Singapore guidance for organizations preparing for PQC transition.

PDF · 1.7 MB · a reference document — dip in, don’t read it through

ReleasedMigration Guidance
IMDA SingaporeJul 2026
Trust 51Needs review
draft-ietf-lake-edhoc-pskUpdated

This document specifies a Pre-Shared Key (PSK) authentication method for the Ephemeral Diffie-Hellman Over COSE (EDHOC) key exchange protocol. The PSK method enhances computational efficiency while providing mutual authentication, ephemeral key exchange, identity protection, and quantum resistance. It is particularly suited for systems where nodes share a PSK provided out-of-band

Web page · 116 KB · a short read

DraftProtocols
IETFJul 1, 2026
Trust 78Authoritative
RFC-9846-The-Transport-Layer-Security-TLS-Protocol-Version-1Updated

Obsoletes RFC 8446; consolidates TLS 1.3 errata/clarifications (does not itself define PQC key exchange -- catalogued as the current base TLS 1.3 spec that PQC hybrid-KEM drafts like draft-ietf-tls-hybrid-design extend).

Web page · 611 KB · a long read

ReleasedProtocols3 revs
IETF TLS WGJul 2026
Trust 82Authoritative
X-509v3-ML-DSA-Certificates-for-the-Secure-Shell-SSH-ProtocoUpdated

Defines X.509v3 certificates carrying ML-DSA keys for use with SSH.

Web page · 54 KB · a short read

DraftPKI Certificate ManagementProtocols
Roumen PetrovJul 1, 2026
Trust 81Authoritative
CCN-TEC-009-BP-37-Spain-Recomendaciones-para-una-transicion

Spain’s CCN recommendations for a post-quantum transition, including its phased approach.

PDF · 3.1 MB · a reference document — dip in, don’t read it through

ReleasedGovernment & Policy
CCN (Centro Criptológico Nacional)Jul 2026
Trust 77Authoritative
draft-ietf-lamps-one-signature-certs-02

Defines certificates for single-use signing keys bound to one signed document through a signedDocumentBinding extension, so the key needs no revocation or long validity. X.509 work relevant to large PQC signatures, but not a hybrid certificate mechanism.

Web page · 95 KB · a short read

DraftProtocolsReviewed (LLM) · eramusa · Oct 2026 · via manual data edit (library)
IETF LAMPS WGJul 1, 2026
Trust 34Needs review
NIST-ESV-Cert-E335Updated

Web page · 41 KB · a short read

MiscMigration Guidance
NIST CMVP (ESV)Jul 1, 2026
Trust 26Needs review
Microsoft-QSP-Roadmap-2025Updated

Microsoft publishes comprehensive QSP roadmap detailing transition to quantum-safe cryptography across all products through 2033. Covers Windows platform, Azure, signing services, and core infrastructure.

Web page · 283 KB · a long read

MiscMigration GuidanceHigh
MicrosoftJun 30, 2026
Trust 61Needs review
draft-ietf-opsawg-rfc5706bisUpdated

New Protocols and Protocol Extensions are best designed with due consideration of the functionality needed to operate and manage them. Retrofitting operations and management considerations is suboptimal. The purpose of this document is to provide guidance to authors and reviewers on what operational and management aspects should be addressed when writing documents in the IETF Stream

Web page · 186 KB · a long read

DraftProtocols
IETFJun 29, 2026
Trust 74Authoritative
Post-Quantum-Traditional-PQ-T-Hybrid-PKI-Authentication-in-t

Hybrid PKI authentication for IKEv2: component keys/algorithms must not be reused across the hybrid scheme, and hybrid IKEv2 key exchange must independently be CRQC-resilient.

Web page · 73 KB · a short read

DraftProtocols
Individual submission (IETF-hosted)Jun 26, 2026
Trust 71Authoritative
A-Post-Quantum-Hybrid-Commitment-Certificate-Extension-PQCHCUpdated

Proposes an X.509 extension that commits to a post-quantum key alongside a classical one, so a certificate can carry both without a new format.

Web page · 64 KB · a short read

DraftProtocols
Brian Vicente (Sanctum SecOps LLC)Jun 26, 2026
Trust 72Authoritative
OMB-M-26-15Updated

OMB memorandum implementing Executive Order 14412, directing federal agencies to execute prioritized PQC migration by December 31 2030 and submit PQC Migration Plans to OMB and ONCD within 120 days. Establishes a 5-phase migration schedule (Discovery 2026-27, Pilots 2027-28, Key-Establishment Migration 2028-30, Signature Migration 2031, Full Migration by 2035) and does not apply to national security systems.

PDF · 283 KB · a short read

ReleasedGovernment & PolicyCritical
OMB; White HouseJun 24, 2026
Trust 58Needs review
EPC-342-08-v16-0-1-Guidelines-on-Cryptographic-Algorithms-UsUpdated

The European Payments Council’s guidance on cryptographic algorithms and key management — the reference European payment schemes size their migrations against.

PDF · 1.4 MB · a long read

ReleasedProtocolsHigh1 rev
European Payments Council (PSSG)Jun 24, 2026
Trust 59Needs review
EO-2026-06-22-Securing-the-NationUpdated

U.S. Executive Order signed June 22 2026 mandating federal post-quantum migration: agencies name a PQC migration lead within 30 days; OMB issues guidance to inventory High Value Assets and submit migration plans within 90 days; a NIST migration pilot completes by 2027; HVAs and high-impact systems transition to PQC for key establishment (FIPS 203) by Dec 31 2030 and digital signatures (FIPS 204) by Dec 31 2031; covered contractors comply by 2030; CISA and NIST publish CBOM minimum elements and accelerate FIPS 140-3 validation.

Web page · 289 KB · a long read

ReleasedGovernment & PolicyHigh1 revReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (LM-068 regional remediation)
The White House (Executive Office of the President); OMB; NIST; CISA; NSAJun 22, 2026
Trust 62Needs review
EO-14413

Companion order to EO 14412, signed the same day. Establishes the Quantum Computer for Application Development and Discovery Science (QC-ADDS) initiative, targeting delivery of a scientifically useful quantum computer to a Department of Energy facility by 2028, and directs a National Quantum Strategy update within 180 days. Does not itself impose cryptography compliance obligations.

Web page · 296 KB · a long read

ReleasedGovernment & Policy
White HouseJun 22, 2026
Trust 55Needs review
Analysis-of-Hybrid-Key-Establishment-and-Standalone-ML-KEM-iUpdated

Compares hybrid key establishment against standalone ML-KEM in TLS 1.3, and what each choice costs.

Web page · 86 KB · a short read

DraftProtocols
Muhammad Usama Sardar (TU Dresden, Germany)Jun 21, 2026
Trust 80Authoritative
Post-Quantum-Key-Encapsulation-Mechanisms-PQ-KEMs-in-EAP-AKA

WG-adopted draft integrating ML-KEM into EAP-AKA' FS for quantum-resistant perfect forward secrecy; defines AT_PUB_KEM/AT_KEM_CT attributes, ML-KEM-512/768/1024 parameter sets.

Web page · 91 KB · a short read

DraftProtocols
IETF emu WGJun 19, 2026
Trust 81Authoritative
Enhancing-Security-in-EAP-AKA-prime-with-Hybrid-Post-Quantum

WG-adopted draft using HPKE-wrapped hybrid ML-KEM to protect EAP-AKA' Forward Secrecy against CRQC; requires ML-KEM key pairs be used in only one EAP session.

Web page · 74 KB · a short read

DraftProtocols
IETF emu WGJun 19, 2026
Trust 81Authoritative
draft-ietf-tls-mldsa-04

Defines ML-DSA (FIPS 204) signature algorithms for TLS 1.3 authentication. Submitted to the IESG; on the 2026-07-02 telechat.

Web page · 57 KB · a short read

DraftProtocols
IETF TLS WGJun 18, 2026
Trust 58Needs review
New-Pure-Post-Quantum-Protocol-Specification-2Updated

Specifies a protocol using post-quantum algorithms alone, with no classical component to fall back on.

Web page · 76 KB · a short read

DraftProtocols1 rev
Individual submission (IETF-hosted)Jun 18, 2026
Trust 71Authoritative
draft-ietf-ipsecme-ikev2-mlkem-06

ML-KEM key exchange for IKEv2 (IPsec). Submitted to the IESG; on the 2026-07-02 telechat.

Web page · 81 KB · a short read

DraftProtocols
IETF IPSECME WGJun 17, 2026
Trust 59Needs review
Matter-1-6-Core-SpecificationUpdated

The Matter smart-home core specification, including the device attestation and commissioning cryptography embedded in shipped hardware.

PDF · 15.7 MB · a reference document — dip in, don’t read it through

ReleasedProtocols
Connectivity Standards Alliance (CSA)Jun 16, 2026
Trust 85Authoritative
New-Hybrid-Post-Quantum-Protocol-SpecificationUpdated

Specifies a hybrid post-quantum protocol combining classical and PQC key establishment.

Web page · 24 KB · a quick skim

DraftProtocols
A. Muhammad (Independent)Jun 15, 2026
Trust 71Authoritative
IETF-Token-Status-ListUpdated

IETF specification for a compact bit-array status list to check validity states of credentials (valid revoked suspended). Provides privacy-preserving revocation: the verifier cannot determine which specific credential is being checked from the status list position alone. Used in EUDI Wallet ecosystem for credential revocation checking without revealing holder identity to the issuer.

Web page · 217 KB · a long read

DraftProtocols
IETF OAuth Working GroupJun 12, 2026
Trust 78Authoritative
draft-ietf-jose-pqc-kemUpdated

Revision -05 (cited here) defined ML-KEM for JOSE/JWE direct key agreement (alg ML-KEM-512/768/1024, KMAC256 key derivation) and for COSE. Revision -06 (2026-07-06) was retitled 'Post-Quantum Key Encapsulation Mechanisms (PQ KEMs) for COSE' and no longer covers JOSE; post-quantum JWE now goes through HPKE (draft-ietf-jose-hpke-encrypt with draft-ietf-jose-hpke-pq-pqt).

Web page · 42 KB · a short read

DraftProtocols1 rev
IETF JOSE WGJun 12, 2026
Trust 84Authoritative
SP-800-73-6-Part-1-PIV-Card-Application-Namespace-Data-Model

Proposed PQC updates to PIV card interfaces: dual-stack model preserving classical keys while adding ML-DSA/ML-KEM key references and certificate containers for backward-compatible, incremental deployment.

Web page · 40 KB · a short read

DraftProtocols
NISTJun 12, 2026
Trust 91Authoritative
SP-800-73-6-Part-2-PIV-Card-Application-Card-Command-Interfa

Proposed PQC updates to PIV card interfaces: dual-stack model preserving classical keys while adding ML-DSA/ML-KEM key references and certificate containers for backward-compatible, incremental deployment.

Web page · 40 KB · a short read

DraftProtocols
NISTJun 12, 2026
Trust 91Authoritative
SP-800-78-6-Cryptographic-Algorithms-and-Key-Sizes-for-PIV

Companion PQC algorithm/key-size update to SP 800-73-6: specifies ML-DSA and ML-KEM parameter sets approved for use within the dual-stack PIV credential model.

Web page · 40 KB · a short read

DraftProtocols
NISTJun 12, 2026
Trust 90Authoritative
AFiR-Post-Quantum-Signed-Inference-Receipts-as-a-TEE-Free-PrUpdated

Proposes post-quantum signed receipts for AI inference, as an alternative to trusted-execution-environment attestation.

Web page · 71 KB · a short read

DraftProtocols
Steve Rotzin (Hive / AFiR)Jun 12, 2026
Trust 71Authoritative
An-Assessment-Framework-for-Application-Level-CryptographicUpdated

Proposes a way to measure how cryptographically agile an application actually is, rather than treating agility as a yes/no property.

Web page · 43 KB · a short read

Research PaperIndustry & Research
Navaneeth Rameshan; Gregoire MessmerJun 11, 2026
Trust 51Needs review
draft-sheffer-tls-pqc-continuity

Proposes a TLS-layer mechanism for servers to make a cached commitment that they support PQC key exchange. Clients that have cached the commitment refuse future connections that omit PQC, providing protection against active MITM downgrade attacks that suppress ML-KEM negotiation during the quantum transition. Introduces the concept of a downgrade limit (cached duration) analogous to HSTS for HTTP.

Web page · 70 KB · a short read

DraftProtocolsHigh
Yaron Sheffer; Bas Westerbaan (Cloudflare); Nimrod AviramJun 9, 2026
Trust 71Authoritative
ASD-Australia-Information-Security-Manual-Guidelines-for-Cry

Australia’s ISM cryptography guidelines — the approved-algorithm list Australian government systems are held to, including its PQC dates.

PDF · 983 KB · a long read

ReleasedGovernment & Policy
ASD (Australian Signals Directorate)Jun 9, 2026
Trust 82Authoritative
Gaps-in-Operational-Visibility-for-Post-Quantum-CryptographiUpdated

Identifies what network operators cannot currently see about their own post-quantum readiness, and what telemetry would be needed.

Web page · 60 KB · a short read

DraftProtocols
Brian Vicente (Sanctum SecOps LLC)Jun 8, 2026
Trust 71Authoritative
Requirements-and-Gaps-for-Post-Quantum-Certificate-RotationUpdated

Sets out what multi-tenant public infrastructure needs for post-quantum certificate rotation, and which of those needs nothing currently meets.

Web page · 58 KB · a short read

DraftMigration GuidanceHigh
Brian Vicente (Sanctum SecOps LLC)Jun 8, 2026
Trust 81Authoritative
Post-Quantum-Guidance-for-current-deployments-of-IETF-protoc

General guidance for deploying IETF-protocol applications with post-quantum algorithm support across current (non-PQC-native) deployments.

Web page · 63 KB · a short read

ExpiredProtocols
Individual submission (IETF-hosted)Jun 4, 2026
Trust 66Needs review
PKCS11-V32-OS-OASISUpdated

PKCS#11 v3.2 finalized as an OASIS Standard (3 June 2026), technically identical in content to the prior Committee Specification Draft 01 / Committee Specification 01 — no substantive changes after Working Draft 13 (16 April 2025) per the spec's own Appendix C Revision History. Adds post-quantum mechanisms: ML-KEM (CKM_ML_KEM 0x00000017, CKM_ML_KEM_KEY_PAIR_GEN 0x0000000f), ML-DSA (CKM_ML_DSA 0x0000001d, CKM_ML_DSA_KEY_PAIR_GEN 0x0000001c, CKM_HASH_ML_DSA_*), and SLH-DSA (CKM_SLH_DSA, CKM_SLH_DSA_KEY_PAIR_GEN). Introduces C_EncapsulateKey() and C_DecapsulateKey() for KEM operations, and C_WrapKeyAuthenticated()/C_UnwrapKeyAuthenticated(). New key types: CKK_ML_KEM (0x49), CKK_ML_DSA (0x4a), CKK_SLH_DSA (0x4b). New attributes: CKA_PARAMETER_SET, CKA_ENCAPSULATE, CKA_DECAPSULATE, CKA_SEED.

Web page · 5.5 MB · a long read

ReleasedProtocolsHigh3 revsReviewed (LLM) · maintainer (automated) · Jul 2026 · via automated, user-directed ("add the final release to our library — older release should show as previous revision"); PKCS#11 v3.2 OS status re-verified against docs.oasis-open.org 2026-07-10; local commits 4c7525b4/7c400a1c on test/all-changes-0710, not yet merged/pushed
OASIS PKCS11 Technical CommitteeJun 3, 2026
Trust 73Authoritative
PKCS-11-Cryptographic-Token-Interface-Profiles-Version-3-2-OUpdated

Defines the conformance profiles that PKCS#11 v3.2 conformance is measured against. Section 7 of the base specification states that an implementation is a conforming Provider only if it meets one or more provider profiles specified here, so the base spec mandates no mechanism on its own. Specifies Baseline Provider, Complete Provider, Extended Provider, Authentication Token, Public Certificates Token and HKDF TLS Token, plus Baseline and Extended Consumer. Baseline Provider requires a CKO_PROFILE object with CKP_BASELINE_PROVIDER and explicitly requires no mechanisms. Edited by Tim Hudson (Cryptsoft); supersedes Profiles v3.1.

PDF · 530 KB · a long read

ReleasedProtocols
OASIS PKCS11 Technical CommitteeJun 3, 2026
Trust 74Authoritative
draft-miller-sshm-mldsa44-ed25519-composite-sigs-00Updated

Individual draft defining ML-DSA-44 + Ed25519 composite signatures for SSH. Replaces the earlier ML-DSA-65 composite draft.

Web page · 61 KB · a short read

DraftProtocolsHigh1 rev
D. Miller (individual)Jun 2, 2026
Trust 72Authoritative
ML-DSA-44-Ed255192-Composite-Signatures-in-SSHUpdated

Specifies the ML-DSA-44 with Ed25519 composite signature pairing for SSH.

Web page · 14 KB · a quick skim

DraftProtocolsHigh
D. Miller (OpenSSH)Jun 2, 2026
Trust 71Authoritative
AQ-PQC-Migration-Framework-v2.1-2026Updated

Major v2.1 (June 2026) of Marin Ivezic's (Applied Quantum) enterprise PQC migration methodology. Phase-by-phase guide across 8 phases (0-7) plus cross-cutting Skills, SOC, and GRC layers and sector packs. v2.0/v2.1 add a two-track approach, right-sizing profiles, AI-assisted migration guidance (5.7), a data-at-rest strategy (5.6), and new appendices: framework crosswalk (G) and protocol coverage matrix (H). Informed by NIST FIPS 203/204/205, IR 8547, CNSA 2.0, ETSI, and GSMA standards. Licensed CC BY 4.0.

PDF · 1.5 MB · a long read

ReleasedMigration GuidanceHigh1 rev
Marin Ivezic; Applied QuantumJun 2026
Trust 55Needs review
Spherity-PQC-Identity-Corridors-2026

Three-author governance and systems-architecture analysis of organizational identity in the PQC transition. Distinguishes harvest-now-decrypt-later confidentiality risk from the integrity / non-repudiation risk created by future forgery of legacy digital signatures. Introduces the "PQC Corridor" — a bounded governance + technical migration domain coordinating scope, legal assurance, data horizons, trust boundaries, cryptographic profiles, and audit. Treats business wallets (incl. proposed European Business Wallet), qualified Verifiable Data Registries (qVDRs), and Verifiable LEIs (vLEIs) as organizational interfaces for cross-jurisdiction trust. Targets B2B, B2G, G2G, M2M, and agent-to-agent ecosystems.

Web page · 421 KB · a long read

DraftIndustry & ResearchHigh
Brian Couzens (SITG Consulting); Dr. Carsten Stöcker (Spherity GmbH); Prof. Dr. Ingrid Vasiliu-Feltes (University of Miami Herbert Business School)Jun 1, 2026
Trust 42Needs review
CSA-Crypto-News-June-2026

Cloud Security Alliance monthly cryptography newsletter compiled by Dr. Dhananjoy Dey (IIIT Lucknow, CSA Quantum-Safe Security Working Group). June 2026 issue covers cryptographic maturity as a precursor to PQC, the new DST (Distributed Service Trust) Task Force report on quantum-safe thinking, and ongoing PQC migration coverage across standards bodies and industry. Published under the CSA Quantum-Safe Security Working Group.

Web page · 116 KB · a short read

ReleasedIndustry & Research
Cloud Security Alliance; Quantum-Safe Security Working Group; Dr. Dhananjoy Dey (IIIT Lucknow)Jun 1, 2026
Trust 61Needs review
Bernstein-MLDSA-Bugs-2026Updated

Cryptanalysis paper by Daniel J. Bernstein demonstrating exploitability of ML-DSA software vulnerabilities. Reproduces two distinct bug patterns (Dilithium 1.0 implementation flaw + PlayStation 3 ECDSA-style randomness reuse) as ML-DSA software variants, each forging signatures in ~1 second on a laptop core. Provides open-source attack demos that recover equivalent secret keys from public keys + a small number of signatures. Estimates breakable-key rates over time for ML-DSA solo vs. Ed25519+ML-DSA hybrid, arguing quantitatively for hybrid signature deployment.

PDF · 546 KB · a long read

ReleasedAlgorithm SpecificationsHigh
Daniel J. Bernstein (UIC; Academia Sinica Taiwan)Jun 1, 2026
Trust 48Needs review
ENISA-SBOM-Adoption-2026

ENISA survey-based analysis of Software Bill of Materials (SBOM) adoption across the EU (June 2026). Reports survey results on adoption readiness, formats (SPDX/CycloneDX), tooling and SDLC lifecycle integration, barriers and supplier requirements; finds the EU Cyber Resilience Act (CRA) is the primary accelerator, with 79% of organisations expecting to reach SBOM maturity before the CRA becomes fully applicable. Foundational to crypto-asset inventory and CBOM for PQC migration.

PDF · 2.9 MB · a reference document — dip in, don’t read it through

ReleasedGovernment & Policy
ENISA; European Union Agency for CybersecurityJun 2026
Trust 56Needs review
EU-NIS-CG-Security-Measures-2026

NIS Cooperation Group reference document (v1.0, June 2026) detailing technical and methodological security measures for essential and important entities under the NIS2 Directive (EU) 2022/2555, aligned with Commission Implementing Regulation (EU) 2024/2690. Covers cybersecurity governance, risk management, supply-chain security, effectiveness assessment and a dedicated cryptography section (2.10 Cryptography); replaces the previous Cooperation Group reference document.

Web page · 50 KB · a short read

ReleasedInternational Frameworks
EU NIS Cooperation Group; European Commission; ENISAJun 1, 2026
Trust 56Needs review
RFC 9980Updated

Published RFC form of draft-ietf-openpgp-pqc: defines post-quantum and hybrid public-key algorithms for OpenPGP — ML-KEM key encapsulation with ML-DSA / SLH-DSA / Ed25519 signatures.

Web page · 825 KB · a long read

ReleasedProtocols3 revs
IETF OpenPGP WGJun 2026
Trust 85Authoritative
RFC-9958Updated

IETF guidance relevant to the post-quantum transition; see the document for its normative scope.

Web page · 161 KB · a long read

ReleasedMigration GuidanceHigh1 rev
IETF PQUIPJun 2026
Trust 83Authoritative
https-arxiv-org-pdf-2606-04669Updated

PDF · 2.5 MB · a reference document — dip in, don’t read it through

Research PaperIndustry & ResearchHigh
R.D.N. Shakya; C.P. Wijesiriwardana; S.M. Vidanagamachchi; Nalin A.G. ArachchilageJun 2026
Trust 51Needs review
ETSI-TS-119-312-V2-1-1-Electronic-Signatures-and-Trust-InfraUpdated

ETSI cryptographic suites for electronic signatures and trust services — which algorithms and key sizes are approved for qualified signatures in the EU.

PDF · 303 KB · a short read

ReleasedInternational Frameworks1 rev
ETSI ESIJun 2026
Trust 90Authoritative
Circle-PQC-Roadmap-2026

Three-phase PQC migration roadmap for Circle (USDC issuer) and the Arc blockchain. Catalogs seven quantum attack vectors on the full blockchain stack (at-rest forgery via EVM ecrecover; retroactive privacy loss; consensus disruption; history rewrite; P2P session compromise via libp2p/Noise; RPC interception; on-spend). Readiness phase: SLH-DSA-SHA2-128s on-chain precompile for smart-account signature verification; X-Wing hybrid KEM (ML-KEM-768 + X25519) for TLS 1.3 and encrypted memos; TEE-based private execution environment (AWS Nitro/SGX/TDX). Transition phase: dual-mode USDC smart contracts; post-quantum ecrecover override; multi-sig cold storage; encrypted mempool. Switch phase: full PQ validator signatures; account recovery (dual-key BIP-39 derivation; TEE-attested ZK proof; off-chain). Policy section covers quantum flag day regulatory implications for stranded USDC assets. Co-authored with Dan Boneh (Stanford).

PDF · 607 KB · a long read

ReleasedMigration GuidanceHigh
Circle; Stanford University (Dan Boneh)May 30, 2026
Trust 61Needs review
draft-ietf-ipsecme-ikev2-downgrade-preventionUpdated

Specifies a mechanism to prevent algorithm downgrade attacks in IKEv2, ensuring that PQC-capable peers cannot be forced to negotiate weaker classical algorithms. Companion to draft-ietf-ipsecme-ikev2-mlkem.

Web page · 28 KB · a quick skim

DraftProtocolsHigh
IETF IPSECME WGMay 29, 2026
Trust 65Needs review
NIST IR 8320E

NIST IR 8320 Series Volume E. Defines a TEE plus remote-attestation plus key-release workflow for protecting AI/ML data in use within cloud workloads. Frames confidential computing as the third pillar (alongside data-at-rest and data-in-transit encryption) and ties hardware-anchored attestation into cloud KMS key release.

PDF · 907 KB · a long read

DraftNIST Standards
NIST; Michael Bartock; Murugiah Souppaya; Timothy Knoll (Intel)May 29, 2026
Trust 77Authoritative
x402-Cryptographic-Receipts-Format-Post-Quantum-Discipline-aUpdated

Defines the x402 cryptographic receipt format and its post-quantum requirements, anchored to Starknet.

Web page · 137 KB · a short read

DraftBlockchain Standards
F. Serafini, Ed. (Vauban Research)May 29, 2026
Trust 71Authoritative
MVPS-Proof-Envelope-Tamper-Evident-Binding-of-Theorem-CataloUpdated

Proposes a tamper-evident envelope binding theorem catalogues to their validators and proofs.

Web page · 61 KB · a short read

DraftProtocols
Leonardo Melegassi Costa (Catellix)May 28, 2026
Trust 71Authoritative
draft-harrison-sshm-mlkem

This document defines pure post-quantum key exchange methods based on Module-lattice post-quantum key encapsulation schemes for use in the SSH Transport Layer Protocol.

Web page · 53 KB · a short read

DraftProtocolsHigh
Alexander Harrison; Andrew Benhase; Panos KampanakisMay 27, 2026
Trust 65Needs review
draft-ietf-tls-ecdhe-mlkem-05Updated

Hybrid X25519MLKEM768 / SecP256r1MLKEM768 key agreement for TLS 1.3. IESG-approved; in the RFC Editor queue.

Web page · 84 KB · a short read

DraftProtocols3 revs
IETF TLS WGMay 26, 2026
Trust 65Needs review
RFC-10024

Specifies X25519MLKEM768, SecP256r1MLKEM768, and SecP384r1MLKEM1024 hybrid groups for TLS 1.3. Normative hybrid framework: draft-ietf-tls-hybrid-design (also in RFC Ed Queue). Both drafts in final pre-publication stage as of Feb 2026.

Web page · 75 KB · a short read

DraftProtocolsHigh
IETF TLS Working GroupMay 26, 2026
Trust 66Needs review
Post-Quantum-Cryptographic-Discipline-for-x402-STARK-ReceiptUpdated

Sets out post-quantum requirements for x402 STARK-based payment receipts.

Web page · 83 KB · a short read

DraftProtocols
Individual submission (IETF-hosted)May 25, 2026
Trust 72Authoritative
draft-ietf-plants-merkle-tree-certsUpdated

This document describes Merkle Tree certificates, a new form of X.509 certificate that integrates public logging with certificate issuance to reduce overhead for post-quantum signatures.

Web page · 194 KB · a long read

ReleasedMigration Guidance4 revs
IETFMay 24, 2026
Trust 82Authoritative
draft-ietf-lamps-cms-composite-sigs

LAMPS WG-adopted draft specifying composite ML-DSA (ML-DSA + RSA-PSS / RSA-PKCS1 / ECDSA / Ed25519 / Ed448) SignerInfo for CMS per RFC 5652. Provides CMS-specific guidance for 18 composite signature algorithm combinations operating in pre-hash mode with algorithm-specific digests (SHA-256 / SHA-512 / SHAKE256). Latest revision -04, IESG state AD Followup (DISCUSS pending), Proposed Standard.

Web page · 49 KB · a short read

DraftProtocols
IETF LAMPS WGMay 22, 2026
Trust 82Authoritative
draft-ietf-lamps-certdiscovery-03

Lets a primary certificate advertise where a related secondary certificate (for example one with a PQC key) can be fetched, using a new subjectInfoAccess access method (id-ad-certDiscovery) and a relatedCertificateDescriptor otherName. Supports migration where a relying party needs a certificate in another algorithm. Replaces draft-lamps-okubo-certdiscovery. OIDs are still TBD.

Web page · 85 KB · a short read

DraftProtocolsPKI Certificate ManagementReviewed (LLM) · eramusa · Oct 2026 · via manual data edit (library)
IETF LAMPS WGMay 21, 2026
Trust 34Needs review
draft-turner-lamps-cms-fn-dsa-00Updated

Defines FN-DSA (FALCON/FIPS 206) signature usage in CMS. Expires May 2026.

Web page · 30 KB · a quick skim

DraftProtocols
IETF LAMPSMay 20, 2026
Trust 76Authoritative
draft-ietf-lamps-fn-dsa-certificates-00

Defines how FN-DSA (the Falcon-based signature planned as FIPS 206) public keys and signatures appear in X.509 certificates and CRLs. Its OIDs under the NIST sigAlgs arc are still TBD and FIPS 206 is not final, so no deployable FN-DSA certificate exists yet. Watchlist item.

Web page · 94 KB · a short read

DraftProtocolsPKI Certificate ManagementReviewed (LLM) · eramusa · Oct 2026 · via manual data edit (library)
IETF LAMPS WGMay 20, 2026
Trust 35Needs review
draft-yang-tls-hybrid-sm2-mlkem-03Updated

Defines curveSM2MLKEM768 hybrid for TLS 1.3 combining Chinese SM2 curve with ML-KEM.

Web page · 15 KB · a quick skim

DraftProtocols1 rev
IETF Individual SubmissionMay 19, 2026
Trust 76Authoritative
draft-reddy-tls-composite-mldsaUpdated

Defines the use of Composite ML-DSA hybrid signatures in TLS 1.3, combining ML-DSA with classical algorithms (ECDSA, RSA) for backward-compatible migration. Extends draft-ietf-lamps-pq-composite-sigs into the TLS layer.

Web page · 33 KB · a quick skim

DraftProtocols
T. Reddy; IETF TLS WGMay 14, 2026
Trust 66Needs review
Algorand-Post-Quantum-LedgerUpdated

Algorand's three-phase quantum-resistance roadmap: (1) blockchain history protected via State Proofs with Falcon (deployed 2022), (2) lazy migration for current account security — single-sig, multisig, LSig, and App accounts each given specific Falcon rekeying paths, (3) native PQC accounts (stateless or stateful Falcon) with consensus PQC planned. First MainNet Falcon transaction via LSig account abstraction deployed November 2025.

Web page · 210 KB · a long read

MiscIndustry & ResearchHigh
Algorand; Cosimo BassiMay 14, 2026
Trust 43Needs review
NIST IR 8610Updated

Status report on the second round of the NIST additional post-quantum digital signature candidates beyond the lattice-based standards.

PDF · 389 KB · a short read

ReleasedIndustry & Research
NISTMay 14, 2026
Trust 80Authoritative
Post-Quantum-Enhancements-to-TLS-Based-EAP-Methods-WG-draftUpdated

WG-adopted successor to draft-reddy-emu-pqc-eap-tls: hybrid key exchange recommended for TLS-based EAP methods; addresses large-certificate round-trip/fragmentation risk and inner-auth exposure if the outer tunnel breaks.

Web page · 64 KB · a short read

ReleasedProtocols2 revs
IETF emu WGMay 13, 2026
Trust 81Authoritative
ML-KEM-Security-Considerations

Implementation-guidance draft (co-authored by Scott Fluhrer et al.) on ML-KEM pitfalls: validate public keys via Encapsulation Key Check, guard entropy quality, retain public key alongside secret key, watch PAKE-context timing side-channels.

Web page · 74 KB · a short read

DraftProtocols
Individual submission (IETF-hosted)May 13, 2026
Trust 72Authoritative
Key-Management-Interoperability-Protocol-Specification-VersiUpdated

Web page · 19.3 MB · a long read

DraftMigration Guidance
OASIS KMIP TCMay 7, 2026
Trust 26Needs review
draft-josefsson-ssh-sphincs

Specification of SLH-DSA/Sphincs+ digital signatures for SSH, including standalone and hybrid modes with Ed25519/Ed448.

Web page · 107 KB · a short read

DraftProtocolsHigh
Simon JosefssonMay 6, 2026
Trust 65Needs review
ProjectEleven-Quantum-Threat-Blockchains-2026Updated

110-page comprehensive analysis of quantum threats to blockchain systems by Project Eleven. Projects Q-Day likely by 2030–2033. Covers secp256k1/ECDSA vulnerability, Bitcoin and Ethereum exposure, BIP-32 HD wallet risk, stablecoin quantification, and urgent PQC migration recommendations for blockchain operators and digital asset custodians.

Web page · 195 KB · a long read

MiscIndustry & ResearchHigh
Project Eleven (Alex Pruden; Conor Deegan)May 5, 2026
Trust 55Needs review
draft-wiggers-tls-authkem-pskUpdated

Extends TLS AuthKEM with pre-shared key authentication modes; provides a fully quantum-resistant TLS 1.3 handshake without relying on any classical asymmetric primitives.

Web page · 40 KB · a short read

DraftProtocols
IETFMay 4, 2026
Trust 75Authoritative
draft-celi-wiggers-tls-authkem-07Updated

Replaces classical signature-based TLS 1.3 authentication with a KEM-based handshake.

Web page · 99 KB · a short read

ReleasedKEMProtocols2 revs
T. Wiggers; S. Celi; P. Schwabe; D. Stebila; N. SullivanMay 4, 2026
Trust 71Authoritative
Sammo-PQC-NPP-MonteCarlo-2026

Monte Carlo simulation (lognormal latency, M/M/c queueing, GEV tails) showing ML-DSA and Falcon meet payment SLAs, plus a four-phase bottom-up migration cost model and a harvest-now-decrypt-later exposure estimate. Illustrates the probabilistic and activity-based cost-model families for PQC migration.

PDF · 2.2 MB · a reference document — dip in, don’t read it through

DraftIndustry & ResearchHigh
Nazmus Salehin SammoMay 4, 2026
Trust 54Needs review
RFC-9964Updated

This document specifies JSON Object Signing and Encryption (JOSE) and CBOR Object Signing and Encryption (COSE) serializations for Module-Lattice-Based Digital Signature Standard (ML-DSA) defined in NIST FIPS 204. Registers ML-DSA-44/65/87 with the new Algorithm Key Pair (AKP) key type (kty=AKP, COSE kty=7) and JOSE alg names matching the COSE registrations (-48/-49/-50). HashML-DSA is explicitly out of scope (§7.2); private key is the 32-byte seed only.

Web page · 260 KB · a long read

ReleasedAlgorithm SpecificationsHigh2 revs
IETF COSE WGMay 2026
Trust 88Authoritative
W3C WebAuthn

Web Authentication Level 3 specification for browser-based public-key authentication. Targeted by ML-DSA WebAuthn drafts that add PQ COSE algorithm identifiers for passkeys.

Web page · 2.7 MB · a long read

ReleasedProtocols
W3C Web Authentication Working GroupMay 2026
Trust 84Authoritative
G7-CB-QT-Financial-2026

G7 Central Bank Quantum Technologies Working Group analytical report co-chaired by Banque de France and Bank of Canada. Covers harvest-now-decrypt-later risks, PQC migration planning for financial infrastructures, and quantum computing applications in finance (optimisation, simulation, payment systems). Provides governance and interoperability considerations for central banks and financial institutions transitioning to quantum-resilient security.

Web page · 295 KB · a long read

ReleasedInternational FrameworksHigh
G7 Central Bank Quantum Technologies Working Group; Banque de France; Bank of CanadaMay 1, 2026
Trust 73Authoritative
Cisco-Quantum-Safe-Architecture-2026Updated

Cisco blog outlining its internal quantum-safe architecture strategy: embedding PQC into firmware, hardware, and supply chain. Covers ML-KEM, ML-DSA adoption roadmap, crypto-agility framework, and lessons from large-scale enterprise migration planning.

Web page · 80 KB · a short read

MiscImplementationsHigh
CiscoApr 30, 2026
Trust 60Needs review
PQShield-4-Quantum-Threats-Enterprises-2026Updated

PQShield identifies four immediate quantum threats enterprises must address: harvest-now-decrypt-later attacks, vulnerable key exchange in TLS, insecure firmware signing, and inadequate crypto-agility. Recommends prioritized PQC migration starting with key establishment.

Web page · 162 KB · a long read

MiscIndustry & ResearchHigh
PQShield (via Quantum Zeitgeist)Apr 30, 2026
Trust 60Needs review
ENISA-Hybridization-Standardisation-StatusUpdated

ENISA/ECCG cross-protocol survey of IETF, ETSI, NIST, and ITU-T hybrid PQ/T standardisation status across 14 protocols (TLS, IKEv2, CMS/S-MIME, SSH, OpenPGP, COSE, JOSE, MLS, EAP-AKA', PKIX/X.509, HPKE, CFRG, MLKEM/FrodoKEM combiners). Maps hybrid key agreement (CatKDF/CasKDF, NIST SP 800-227) and hybrid signature status against ECCG Agreed Cryptographic Mechanisms v2.0; explicitly not an ENISA recommendation.

PDF · 1.1 MB · a long read

ReleasedInternational Frameworks
ENISA; ECCG subgroup on cryptographyApr 30, 2026
Trust 75Authoritative
A-Survey-on-Security-Reductions-in-Post-Quantum-CryptographyUpdated

Surveys the security reductions underpinning post-quantum schemes: what each construction actually proves, and against which assumption.

PDF · 686 KB · a long read

Research PaperIndustry & Research
TNO (Netherlands Organisation for Applied Scientific Research); Centrum Wiskunde & Informatica (CWI); Leiden University; Max Planck Institute for Security and PrivacyApr 30, 2026
Trust 45Needs review
GopherSecurity-PQC-Agility-MCP-2026Updated

Technical analysis of PQC agility requirements in MCP (Model Context Protocol) transport layer used by AI agents. Examines how LLM tool-calling infrastructure inherits TLS vulnerabilities and proposes hybrid PQC key exchange as a mitigation for AI-to-AI and AI-to-tool communication channels.

Web page · 152 KB · a long read

MiscIndustry & Research
Gopher SecurityApr 29, 2026
Trust 61Needs review
QuantumInsider-Why-2026-Matters-QSUpdated

The Quantum Insider analysis of why 2026 is a pivotal year for quantum security: NIST standards finalized, government migration deadlines approaching, enterprise procurement cycles beginning, and hardware progress accelerating. Frames 2026 as the year quantum security moves from planning to execution.

Web page · 229 KB · a long read

MiscIndustry & ResearchHigh
The Quantum InsiderApr 28, 2026
Trust 55Needs review
ITPro-Monetizing-Quantum-Shift-PQC-2026Updated

ITPro/CSA analysis of 11 business channel opportunities emerging from the PQC migration wave. Covers managed PQC services, crypto-agility tooling, compliance consulting, hardware security modules, and post-quantum VPN products as revenue streams for technology vendors and MSSPs.

Web page · 1.0 MB · a long read

MiscIndustry & Research
ITPro / Cloud Security AllianceApr 28, 2026
Trust 61Needs review
QuantumInsider-QS-Threats-Solutions-2026Updated

Quantum Insider overview of the quantum security landscape: threat timeline, key cryptographic vulnerabilities (RSA, ECDSA, DH), PQC solution categories (KEM, signatures, agility), and the competitive race among enterprises, governments, and vendors to deploy quantum-safe infrastructure.

Web page · 244 KB · a long read

MiscIndustry & ResearchHigh
The Quantum InsiderApr 27, 2026
Trust 55Needs review
QCReport-QDay-Accelerated-Timeline-2026Updated

Quantum Computing Report executive summary on the accelerating Q-Day timeline. Synthesizes hardware progress (Google Willow, neutral-atom systems), algorithmic improvements reducing qubit requirements, and expanded attack surface beyond RSA to ECDSA and lattice-adjacent schemes. Projects credible Q-Day risk by 2029–2030.

Web page · 135 KB · a short read

MiscIndustry & ResearchHigh
Quantum Computing ReportApr 25, 2026
Trust 53Needs review
draft-ietf-mls-combiner-02

Specifies combining a traditional MLS session with a PQ MLS session for amortized hybrid security.

Web page · 45 KB · a short read

ExpiredProtocols
X. Tian; B. Hale; M. Mularczyk; J. AlwenApr 25, 2026
Trust 71Authoritative
ArsTechnica-Ransomware-Quantum-Safe-2026Updated

Ars Technica reporting on the first confirmed ransomware family deploying post-quantum cryptography. The ransomware uses ML-KEM for key encapsulation, making traditional decryption-key recovery impossible even with law enforcement access to command-and-control infrastructure. Marks a new threat tier for incident response.

Web page · 147 KB · a short read

MiscIndustry & ResearchHigh
Ars TechnicaApr 23, 2026
Trust 53Needs review
draft-bonnell-lamps-chameleon-certs-07Updated

Defines an X.509v3 extension encoding differences between two paired certificates. Allows a relying party to reconstruct both traditional and PQC certificates from a single cert. Alternative to composite and related-certificate (RFC 9763) hybrid approaches. Backed by DigiCert and Entrust.

Web page · 191 KB · a long read

ExpiredPKI Certificate ManagementHigh
IETF LAMPS; Corey Bonnell (DigiCert); John Gray (Entrust); D. Hook (KeyFactor); Tomofumi Okubo (DigiCert); Mike Ounsworth (Entrust)Apr 21, 2026
Trust 76Authoritative
QuantumInsider-AES128-Safe-Quantum-2026Updated

Quantum Insider coverage of new cryptanalysis research concluding AES-128 remains secure against quantum attack under revised Grover algorithm resource estimates. Higher parallelization requirements and error correction overhead mean AES-128 provides adequate quantum security margin, contrary to earlier conservative estimates.

Web page · 222 KB · a long read

MiscIndustry & Research
The Quantum InsiderApr 21, 2026
Trust 53Needs review
Federal-PKI-Common-Policy-X-509-Certificate-and-CRL-Profile

The draft post-quantum profile for US Federal PKI certificates and CRLs — what a federal PQC certificate is allowed to contain.

PDF · 700 KB · a long read

DraftPKI Certificate ManagementHigh
Federal PKI Policy AuthorityApr 21, 2026
Trust 62Needs review
Output-Schema-Based-on-Cryptographic-Bill-of-Materials-CBoM

Proposes an organizational-level Cryptographic Asset Inventory schema extending CycloneDX CBoM (component-level) to hardware/software/services, with quantum-readiness compliance indicators and criticality scoring.

Web page · 68 KB · a short read

DraftProtocols
Individual submission (IETF-hosted)Apr 20, 2026
Trust 66Needs review
IPv4-5-A-Locator-Identifier-Separated-Extension-to-IPv4-with

Single-author proposal for a 96-bit locator/identifier-separated IPv4 extension with hybrid ML-KEM-768+X25519 session security over UDP/4242; addresses IPv4 exhaustion, not adopted by any WG.

Web page · 108 KB · a short read

DraftProtocols
Individual submission (IETF-hosted)Apr 19, 2026
Trust 72Authoritative
NIST-SP-800-133r3-ipdUpdated

NIST draft recommendation specifying methods for generating cryptographic keys. Rev. 3 adds ML-KEM-based symmetric key establishment, PQC signature algorithm support (ML-DSA), seed-expansion via SHAKE and DRBGs, and aligns randomness guidance with SP 800-90C. Public comment period closes June 16, 2026.

Web page · 46 KB · a short read

DraftNIST StandardsHigh
NIST; Quynh Dang; Dustin Moody; Andrew Regenscheid; Hamilton SilbergApr 17, 2026
Trust 84Authoritative
draft-sheth-pqc-dnssec-strategy-01

Strategy document recommending SLH-DSA-MTL, Falcon, XMSS, LMS plus "drop-in" NIST onramp algos for DNSSEC.

Web page · 57 KB · a short read

DraftProtocols
S. Sheth (Verisign Labs); T. Chung (Virginia Tech); B. Overeinder (NLnet Labs)Apr 17, 2026
Trust 66Needs review
GhostLock-A-Hybrid-Post-Quantum-Encryption-Protocol

File-level hybrid encryption protocol (X25519/Ed25519 + Kyber768, ChaCha20-Poly1305 AEAD) defining a .glock container format; individual submission, not a protocol used by any deployed system in this catalog.

Web page · 39 KB · a quick skim

ExpiredProtocols
Individual submission (IETF-hosted)Apr 17, 2026
Trust 64Needs review
Microsoft-Crypto-Inventory-CPM-2026Updated

Microsoft Security Blog on establishing a cryptographic inventory as the foundation of a CPM program; four-phase approach from discovery to continuous monitoring.

Web page · 307 KB · a long read

MiscMigration Guidance
Microsoft SecurityApr 16, 2026
Trust 60Needs review
Meta-PQC-Migration-2026Updated

Meta Engineering case study on a large-scale PQC migration with explicit inventory, policy, and rollout framework.

Web page · 125 KB · a short read

MiscMigration Guidance
Meta EngineeringApr 16, 2026
Trust 59Needs review
NIST-SP-800-230-ipdUpdated

NIST SP 800-230 extends FIPS 205 with six new SLH-DSA parameter sets (SHA2 and SHAKE at levels 1/3/5) optimised for firmware signing, software distribution, and certificate signing. Signatures are roughly half the size of FIPS 205 variants but carry a strict 2^24 signatures-per-key limit. Not for general-purpose use.

Web page · 49 KB · a short read

DraftAlgorithm Specifications1 rev
NISTApr 13, 2026
Trust 75Authoritative
Hybrid-Post-Quantum-and-Traditional-Authentication-for-IKEv2

Defines composite-certificate hybrid authentication for IKEv2 (traditional + PQC signatures in one cert) without changing base protocol messages; requires IKEv2 Fragmentation support for larger messages.

Web page · 58 KB · a short read

DraftProtocols
Individual submission (IETF-hosted)Apr 13, 2026
Trust 71Authoritative
QuantumZeitgeist-CryptoNext-NIST-Cert-2026Updated

CryptoNext Security becomes the first EU company to achieve full NIST quantum-safe certification across ML-KEM, ML-DSA, and SLH-DSA. Coverage of their C-Pqc library FIPS compliance milestone and implications for European organizations seeking certified PQC implementations.

Web page · 152 KB · a long read

MiscCompliance & Certification
Quantum Zeitgeist / CryptoNext SecurityApr 10, 2026
Trust 53Needs review
EFF-Encryption-Y2K-Moment-2026Updated

EFF policy analysis drawing parallel between Y2K remediation urgency and the PQC migration challenge. Argues the quantum cryptography deadline is arriving faster than expected with less organizational readiness. Calls for immediate government action, vendor support timelines, and user-facing communication.

Web page · 65 KB · a short read

MiscGovernment & PolicyHigh
Electronic Frontier Foundation (EFF)Apr 9, 2026
Trust 55Needs review
ACS-Google-Cloudflare-PQC-2029Updated

Australian Computer Society coverage of Google and Cloudflare jointly pushing for industry-wide PQC deployment by 2029. Both companies cite accelerating quantum hardware progress and HNDL risks as justification for a 2029 deadline — three years earlier than previously communicated targets.

Web page · 33 KB · a quick skim

MiscIndustry & ResearchHigh
ACS (Australian Computer Society)Apr 8, 2026
Trust 59Needs review
QuantumInsider-QuantumXChange-PhioTX-2026Updated

Quantum XChange announces Phio TX Management Console for centralized PQC key management and crypto-agility across enterprise networks. Enables policy-based PQC algorithm selection, inventory tracking, and rollout orchestration for hybrid classical/PQC environments.

Web page · 218 KB · a long read

MiscImplementations
Quantum XChange (via The Quantum Insider)Apr 8, 2026
Trust 55Needs review
draft-sfluhrer-ssh-mldsaUpdated

This document describes the use of ML-DSA digital signatures for authentication within the Secure Shell (SSH) protocol.

Web page · 61 KB · a short read

DraftProtocols
IETFApr 7, 2026
Trust 82Authoritative
CoT-Decrypting-Future-PQC-Timelines-2026

Charter of Trust PQC Working Group report comparing global PQC transition timelines across US, EU, UK, Japan, Singapore, and Australia. Covers sectoral prioritization, quantum threat landscape, attack scenarios, and a practitioner playbook for PQC migration. Contributors include Siemens, IBM, Microsoft, Infineon, Atos, and Bosch.

Web page · 100 KB · a short read

ReleasedMigration GuidanceHigh
Charter of Trust – PQC Working GroupApr 7, 2026
Trust 65Needs review
Cloudflare-PostQuantum-Roadmap-2026Updated

Cloudflare's official post-quantum roadmap blog. Details phased deployment: X25519MLKEM768 hybrid in TLS already deployed to all customers, plans for ML-DSA certificate signing, 2029 target for full quantum-safe infrastructure, and migration guidance for customers.

Web page · 504 KB · a long read

MiscImplementationsHigh
CloudflareApr 7, 2026
Trust 60Needs review
QCReport-QSE-Enterprise-PQC-Platform-2026Updated

QSE launches QPA v2, an enterprise post-quantum migration platform providing automated cryptographic inventory discovery, risk scoring, and migration orchestration. Integrates with existing PKI and key management systems to enable phased PQC rollout without infrastructure replacement.

Web page · 137 KB · a short read

MiscImplementationsHigh
QSE (via Quantum Computing Report)Apr 7, 2026
Trust 53Needs review
draft-ietf-cose-hpke

Adds HPKE (RFC 9180 base mode plus PQ/T hybrid KEM algorithms) to COSE, enabling pure and hybrid post-quantum key encapsulation for COSE_Encrypt structures. Revision -25 submitted to IESG for publication; in AD evaluation as of 2026-04-07.

Web page · 269 KB · a long read

DraftKEM
IETF COSE WGApr 7, 2026
Trust 75Authoritative
draft-ietf-pquip-pqc-hsm-constrained-03Updated

Guidance for integrating PQC into resource-constrained devices including IoT nodes and lightweight HSMs; covers seed-based key generation, ephemeral key handling, cryptographic task offloading, and post-quantum firmware authentication.

Web page · 65 KB · a short read

ExpiredMigration GuidanceHigh
IETF PQUIP WGApr 1, 2026
Trust 76Authoritative
RFC 9941Updated

Specifies sntrup761x25519-sha512 hybrid key exchange for SSH; supersedes draft-ietf-sshm-ntruprime-ssh.

Web page · 89 KB · a short read

ReleasedProtocols2 revs
M. Friedl; J. Mojzis; S. JosefssonApr 2026
Trust 89Authoritative
Content-Credentials-C2PA-Technical-Specification-Version-2-4Updated

C2PA's normative specification for Content Credentials — cryptographically signed provenance manifests (claims, assertions, hard/soft bindings) embedded in media assets, with an X.509/COSE trust and validation model. Cited by the ai-security-pqc module for content provenance; the specification is not about post-quantum cryptography, and its allowed signature algorithms are ECDSA, RSASSA-PSS and Ed25519 only.

Web page · 1.1 MB · a long read

ReleasedCompliance & Certification
Coalition for Content Provenance and Authenticity (C2PA), a Joint Development Foundation projectApr 2026
Trust 54Needs review
NIST-SP-1800-40B-IPDUpdated

Initial public draft of NIST SP 1800-40B (April 2026), the NCCoE practice guide volume on automating the Cryptographic Module Validation Program.

PDF · 2.5 MB · a reference document — dip in, don’t read it through

DraftCompliance & CertificationReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
NIST NCCoEApr 2026
Trust 34Needs review
NIST-IR-8259r1Updated

NIST report describing recommended cybersecurity activities manufacturers should consider before their IoT products are sold, so customers get the product cybersecurity capabilities and information they need; supersedes NIST IR 8259 (2020). Recommends considering quantum-safe approaches and updatable hardware to allow a later move to post-quantum cryptography (pp. 31-32), without setting a deadline.

PDF · 2.6 MB · a reference document — dip in, don’t read it through

ReleasedCompliance & CertificationReviewed (LLM) · eramusa · Oct 2026 · via manual data edit (library)
NIST (Fagan M; Megas K; Cuthill B; Marron J; Hoehn B)Apr 2026
Trust 54Needs review
NIST-CMVP-Cert-5223Updated

Web page · 83 KB · a short read

MiscMigration Guidance
NIST CMVPApr 1, 2026
Trust 26Needs review
EJBCA-Beyond-CBOMUpdated

Argues a CBOM is necessary but insufficient; posture management adds lifecycle, policy, observability, and assurance layers.

Web page · 84 KB · a short read

MiscMigration Guidance
Keyfactor / EJBCAMar 31, 2026
Trust 54Needs review
arXiv-2603-28728Updated

Cisco Research survey examining PQC migration status across nine widely deployed protocols: TLS, IPsec, BGP, DNSSEC, SSH, QUIC, OpenID Connect, OpenVPN, and Signal Protocol. Analyses cryptographic foundations, quantum risks, and current state of PQC migration per protocol. Finds TLS and Signal lead with hybrid PQC key exchange deployed at scale; DNSSEC and BGP face structural barriers due to signature size constraints.

PDF · 603 KB · a long read

Research PaperIndustry & ResearchHigh
Tushin Mallick; Ashish Kundu; Ramana Kompella (Cisco Research)Mar 30, 2026
Trust 53Needs review
Google-QuantumAI-EC-Crypto-Quantum-2026Updated

Google Quantum AI and Ethereum Foundation whitepaper providing new resource estimates for breaking secp256k1 (256-bit ECDLP) with Shor's algorithm — under 1,200 logical qubits and 90 million Toffoli gates. Introduces fast-clock vs slow-clock CRQC distinction and "on-spend" attack concept. Surveys cryptocurrency vulnerabilities including mempool exposure, reused addresses, and P2PK outputs. Recommends migration to PQC signatures for blockchain systems.

PDF · 1.7 MB · a reference document — dip in, don’t read it through

Research PaperIndustry & ResearchCritical
Ryan Babbush; Adam Zalcman; Craig Gidney; Michael Broughton; Tanuj Khattar; Hartmut Neven; Thiago Bergamaschi (Google Quantum AI); Justin Drake (Ethereum Foundation); Dan Boneh (Stanford)Mar 30, 2026
Trust 66Needs review
arXiv-2603-28627Updated

Demonstrates that Shor's algorithm for breaking RSA and ECC can be executed with as few as ~10,000 reconfigurable neutral atom qubits — an order of magnitude fewer than prior estimates. Substantially narrows the timeline for practical quantum attacks on current public-key infrastructure.

Web page · 44 KB · a short read

Research PaperIndustry & ResearchHigh
arXiv (neutral atom quantum computing researchers)Mar 30, 2026
Trust 65Needs review
draft-fregly-dnsop-slh-dsa-mtl-dnssec-06

Specifies SLH-DSA in Merkle Tree Ladder mode for DNSSEC to mitigate the signature-size problem.

Web page · 68 KB · a short read

DraftProtocols
A. Fregly; J. Harvey; B. Kaliski; D. Wessels (Verisign Labs)Mar 30, 2026
Trust 71Authoritative
EJBCA-Understanding-CPMUpdated

EJBCA/Keyfactor primer framing CPM as continuous visibility + automated policy enforcement across certs, keys, and libraries.

Web page · 85 KB · a short read

MiscMigration Guidance
Keyfactor / EJBCAMar 25, 2026
Trust 54Needs review
QuantumInsider-25-Companies-PQC-2026Updated

Quantum Insider survey of 25 companies shaping the quantum cryptography and communications market in 2026. Covers PQC software vendors, QKD hardware providers, crypto-agility platform companies, and quantum networking startups. Useful vendor landscape reference for procurement and market analysis.

Web page · 236 KB · a long read

MiscIndustry & Research
The Quantum InsiderMar 25, 2026
Trust 54Needs review
draft-vitap-ml-dsa-webauthnUpdated

Defines ML-DSA (FIPS 204) as a new algorithm for WebAuthn/FIDO2 authentication. Specifies COSE algorithm identifiers for ML-DSA variants for use in W3C Web Authentication credentials.

Web page · 44 KB · a short read

ExpiredProtocols
IETF / Individual (vitap)Mar 23, 2026
Trust 82Authoritative
draft-ietf-tls-key-share-predictionUpdated

Mechanism for TLS 1.3 servers to predict which key share a client will offer, enabling zero-RTT PQC key exchange by avoiding HelloRetryRequest. Critical for ML-KEM deployment performance given large key sizes.

Web page · 15 KB · a quick skim

ExpiredProtocols
IETF TLS WGMar 19, 2026
Trust 81Authoritative
NIST-CSWP-37AUpdated

NIST CSWP 37A, published 16 March 2026: the September 2024 status report of the NCCoE project on automating the Cryptographic Module Validation Program.

PDF · 834 KB · a long read

ReleasedCompliance & CertificationReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
NIST (Celi; Calis; Souppaya; Barker; Kent) with MITRE, atsec, Cisco, AWSMar 16, 2026
Trust 34Needs review
draft-ietf-cose-falcon-04Updated

Defines FN-DSA (FALCON) algorithm identifiers and serialization for JSON Object Signing and Encryption (JOSE) and CBOR Object Signing and Encryption (COSE).

Web page · 93 KB · a short read

DraftProtocols1 rev
IETF COSE WGMar 15, 2026
Trust 76Authoritative
TCG-TPM-V185-Part0

Overview and change summary for the TCG TPM 2.0 Library V1.85 RC4 specification. Introduces PQC algorithm IDs (TPM_ALG_MLKEM=0x00A0; TPM_ALG_MLDSA=0x00A1) and explains the rationale for enlarging TPM_BUFFER_MAX from 4096 to 8192 bytes to accommodate ML-DSA-87 signatures.

PDF · 300 KB · a short read

ReleasedAlgorithm SpecificationsHigh
Trusted Computing GroupMar 12, 2026
Trust 82Authoritative
TCG-TPM-V185-Part1Updated

Defines the TPM 2.0 architecture including the four-hierarchy model (Platform/Endorsement/Storage/Owner) and their handle values (TPM_RH_ENDORSEMENT=0x4000000B; TPM_RH_OWNER=0x40000001; TPM_RH_PLATFORM=0x4000000C). Specifies PQC key roles (EK; SRK; AIK; IDevID) and the impact of ML-KEM-768 and ML-DSA-65 adoption on attestation flows and TPM_BUFFER_MAX.

PDF · 3.3 MB · a reference document — dip in, don’t read it through

ReleasedImplementationsHigh1 rev
Trusted Computing GroupMar 12, 2026
Trust 83Authoritative
TCG-TPM-V185-Part2

Normative structure definitions for TPM 2.0 V1.85. Assigns TPM_ALG_MLKEM=0x00A0 and TPM_ALG_MLDSA=0x00A1. Defines TPMT_ASYM_SCHEME for ML-KEM encapsulation and ML-DSA signing. Specifies key-size constants: ML-KEM-768 pk=1184B/ct=1088B; ML-DSA-65 pk=1952B/sig=3309B. Sets TPM_BUFFER_MAX=8192 and TPM2B_MAX_BUFFER size.

PDF · 875 KB · a long read

ReleasedAlgorithm SpecificationsHigh
Trusted Computing GroupMar 12, 2026
Trust 83Authoritative
TCG-TPM-2.0-Library-v1.85-Part3-PublishedUpdated

PUBLISHED TPM 2.0 Library v1.85 Part 3: Commands. Supersedes the December 2025 RC4. Defines ML-DSA, ML-KEM, Labeled KEM, EdDSA TPM commands.

ReleasedMigration Guidance1 rev
Trusted Computing Group (TCG)Mar 12, 2026
Trust 60Needs review
NIST-ESV-Cert-E321Updated

Web page · 41 KB · a short read

MiscMigration Guidance
NIST CMVP (ESV)Mar 11, 2026
Trust 26Needs review
GRI-Quantum-Threat-Timeline-2025Updated

Annual expert survey of 26 global quantum computing experts on CRQC probability and timeline. Published March 2026. 2025 survey shows significant acceleration: 28-49% probability within 10 years (up from 19-34% in 2024), 51-70% within 15 years. Majority now consider a CRQC likely by 2035. Authored by Dr. Michele Mosca and Dr. Marco Piani (evolutionQ Inc.), published by the Global Risk Institute.

PDF · 9.1 MB · a reference document — dip in, don’t read it through

ReleasedIndustry & ResearchHigh1 rev
Global Risk InstituteMar 9, 2026
Trust 69Needs review
RFC-9935Updated

Defines algorithm identifiers (OIDs) for ML-KEM-512, ML-KEM-768, and ML-KEM-1024 for use in X.509 certificates and CRLs. Direct complement to RFC 9881 (ML-DSA identifiers). Required for post-quantum PKI certificate issuance.

Web page · 694 KB · a long read

ReleasedPKI Certificate ManagementHigh2 revs
IETF LAMPS WG; Sean Turner; Panos Kampanakis (AWS); Jake Massimo (AWS); Bas Westerbaan (Cloudflare)Mar 6, 2026
Trust 76Authoritative
RFC-9936Updated

Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) is a quantum-resistant Key Encapsulation Mechanism (KEM). Three parameter sets for the ML-KEM algorithm are specified by the US National Institute of Standards and Technology (NIST) in FIPS 203. In order of increasing security strength (and decreasing performance), these parameter sets are ML-KEM-512, ML-KEM-768, and ML-KEM-1024. This do

Web page · 405 KB · a long read

ReleasedProtocols1 rev
IETFMar 6, 2026
Trust 83Authoritative
draft-wang-ipsecme-kem-auth-ikev2-03Updated

Specifies KEM-based authentication for IKEv2 as more efficient alternative to ML-DSA.

Web page · 97 KB · a short read

DraftProtocols1 rev
IETF Individual SubmissionMar 2, 2026
Trust 76Authoritative
draft-connolly-cfrg-xwing-kem-10

Specifies X-Wing, a general-purpose hybrid KEM combining X25519 with ML-KEM-768. Unlike the TLS named groups it is not bound to a single protocol, which is why it appears in file/secrets encryption (age, SOPS) as well as on the wire. Fixes encapsulation key at 1216 bytes, ciphertext at 1120 and shared secret at 32.

Web page · 145 KB · a short read

DraftProtocols
D. Connolly, P. Schwabe, B. E. Westerbaan (IRTF CFRG)Mar 2, 2026
Trust 82Authoritative
NIST-CSWP-36AUpdated

NIST Cybersecurity White Paper (Initial Public Draft) covering the 5G Subscription Concealed Identifier (SUCI) mechanism per 3GPP TS 33.501. Describes how SUCI protects permanent subscriber identifiers (SUPIs/IMSIs) using public-key encryption (X25519 Profile A, P-256 Profile B) to prevent IMSI-catching attacks. Authored by NIST ITL, Scarfone Cybersecurity, and The MITRE Corporation.

PDF · 2.3 MB · a reference document — dip in, don’t read it through

ReleasedNIST Standards
Michael Bartock; Jeffrey Cichonski; Murugiah Souppaya (NIST); Karen Scarfone (Scarfone Cybersecurity); Parisa Grayeli; Sanjeev Sharma; Charles Teague (MITRE)Mar 2026
Trust 56Needs review
arXiv-2603-01091-HNDL-RekeyingUpdated

Empirical analysis of HNDL attack economics across TLS 1.2, TLS 1.3, QUIC, and SSH. Quantifies adversarial storage cost feasibility; proposes aggressive rekeying and hybrid PQC as defences. References production deployments by Cloudflare, Apple PQ3, AWS, and Google Chrome. Companion paper to the open-source hndl-dev simulator.

Web page · 322 KB · a long read

Research PaperIndustry & ResearchHigh
perlab-uc3m; Universidad Carlos III de MadridMar 2026
Trust 59Needs review
AU-ACSC-Quantum-Tech-Primer-Communications-2026

Australian Cyber Security Centre primer on quantum technology for the communications sector. Covers quantum threats, PQC migration priorities, and guidance for Australian telecom operators.

Web page · 320 KB · a long read

ReleasedMigration GuidanceHigh
Australian Cyber Security Centre (ACSC)Mar 1, 2026
Trust 74Authoritative
draft-hu-ipsecme-pqt-hybrid-authUpdated

Proposes using both a classical (ECDSA) and PQC (ML-DSA) signature in IKEv2 AUTH payload for defense-in-depth during the transition period.

Web page · 29 KB · a quick skim

ExpiredProtocolsHigh
IETF IPSECMEFeb 27, 2026
Trust 75Authoritative
WebPKI PQC TimelineUpdated

Google/Chrome Root Program statement of the Web PKI post-quantum plan. Chrome has NO immediate plan to add PQC X.509 certificates to its root store; instead it is pursuing Merkle Tree Certificates in three phases — Phase 1 feasibility study with Cloudflare (underway), Phase 2 CT-log bootstrapping (Q1 2027), Phase 3 the Chrome Quantum-resistant Root Store alongside the existing one (Q3 2027).

Web page · 259 KB · a long read

MiscPKI Certificate ManagementHigh
Chrome Root Program, GoogleFeb 27, 2026
Trust 49Needs review
draft-reddy-lamps-x509-pq-commit

Defines X.509 certificate extensions that allow a certificate authority or subscriber to embed a PQC Continuity commitment directly in a certificate. A relying party that encounters this extension knows the server is committed to PQC and can refuse future classical-only connections, extending the TLS-layer draft-sheffer-tls-pqc-continuity concept into the PKI certificate layer.

Web page · 66 KB · a short read

DraftProtocolsPKI Certificate ManagementHigh
T. Reddy.K; M. BouchetFeb 25, 2026
Trust 65Needs review
draft-ietf-uta-pqc-app-01Updated

Best practices for implementing quantum-ready usage profiles in TLS-based applications.

Web page · 97 KB · a short read

DraftProtocolsHigh1 rev
IETF UTAFeb 24, 2026
Trust 82Authoritative
Reducing-the-Number-of-Qubits-in-Quantum-Discrete-LogarithmsUpdated

Applies the same Residue Number System compression to the elliptic-curve discrete logarithm problem, reaching 3.12n + o(n) qubits — the most space-efficient polynomial-time ECDLP algorithm published. Estimates 1,193 logical qubits for a 256-bit curve at 2^38.98 Toffoli gates across 22 runs, against 2,043 for RSA-3072 at comparable classical security.

PDF · 503 KB · a long read

Research PaperIndustry & ResearchHigh
Clémence Chevignard; Pierre-Alain Fouque; André Schrottenloher (Univ Rennes, Inria, CNRS, IRISA)Feb 17, 2026
Trust 63Needs review
draft-reddy-cose-jose-pqc-hybrid-hpke

Specification of Post-Quantum and Hybrid KEMs for HPKE within JOSE and COSE, including algorithm identifiers and key formats.

Web page · 155 KB · a long read

DraftProtocolsHigh
T. Reddy (individual)Feb 15, 2026
Trust 73Authoritative
India-DST-NQM-RoadmapUpdated

India DST Task Force under National Quantum Mission publishes phased roadmap for PQC migration. CII foundations by 2027, high-priority systems by 2028, full CII by 2029, nationwide by 2033.

PDF · 2.0 MB · a reference document — dip in, don’t read it through

ReleasedGovernment & PolicyHigh1 rev
DST India; National Quantum Mission; CERT-InFeb 4, 2026
Trust 67Needs review
HKMA-Fintech-Blueprint-2026

HKMA Fintech Promotion Blueprint launched February 2026. Includes Quantum Preparedness Index as flagship initiative for Hong Kong banking sector PQC readiness assessment and migration planning.

Web page · 82 KB · a short read

ReleasedGovernment & PolicyHigh
HKMA; Hong Kong Monetary AuthorityFeb 3, 2026
Trust 64Needs review
HKMA-FINTECH-BLUEPRINT-2026Updated

Hong Kong Monetary Authority Fintech 2030 blueprint — commits to PQC transition for the HK banking sector, launches Quantum Preparedness Index.

PDF · 4.5 MB · a reference document — dip in, don’t read it through

MiscCompliance & Certification
HKMAFeb 3, 2026
Trust 80Authoritative
ANSSI-PQC-SSH-Transition-v2

ANSSI technical fact sheet (ANSSI-FT-116, 16 pp) on the post-quantum transition of SSHv2. Recommends hybrid key exchange combining a classical scheme (X25519 / sntrup761) with ML-KEM to protect SSH sessions against Harvest-Now-Decrypt-Later, with concrete OpenSSH configuration guidance for developers, administrators, and CISOs. Translated from French.

PDF · 1.4 MB · a long read

ReleasedProtocolsHigh
ANSSIFeb 2, 2026
Trust 83Authoritative
ANSSI-PQC-TLS13-Transition

ANSSI technical fact sheet (ANSSI-FT-115, 16 pp) on the post-quantum transition of TLS 1.3. Recommends hybrid key exchange (classical + ML-KEM) and addresses ML-DSA-based authentication, giving practical migration and configuration guidance for TLS 1.3 deployments. Translated from French.

PDF · 1.9 MB · a reference document — dip in, don’t read it through

ReleasedProtocolsHigh
ANSSIFeb 2, 2026
Trust 83Authoritative
ANSSI-PQC-IPsec-Transition

ANSSI technical fact sheet (ANSSI-FT-117, 22 pp) on the post-quantum transition of IPsec. Recommends hybrid key exchange (classical + ML-KEM) within IKEv2 to protect VPN tunnels against the quantum threat, with configuration guidance for administrators. Translated from French.

PDF · 1.5 MB · a long read

ReleasedProtocolsHigh
ANSSIFeb 2, 2026
Trust 83Authoritative
lattigo-v6.2.0Updated

Go library for BGV/BFV and CKKS with multiparty protocols: t-of-N threshold, refresh and key switching.

Web page · 213 KB · a long read

MiscIndustry & Research
Tune Insight SA; EPFL Laboratory for Data SecurityFeb 2, 2026
Trust 36Needs review
ref-webster-pinnacleUpdated

Introduction of the Pinnacle Architecture using quantum LDPC codes to reduce the physical qubit overhead for fault-tolerant quantum computation, demonstrating RSA-2048 factoring with fewer than 100,000 physical qubits.

PDF · 1.2 MB · a long read

Research PaperIndustry & Research
Paul Webster; Lucas Berent; Omprakash Chandra; Evan T. Hockings; Nouedyn Baspin; Felix Thomsen; Samuel C. Smith; Lawrence Z. CohenFeb 2026
Trust 52Needs review
3GPP TS 33.501 Rel-19Updated

5G security architecture updates incorporating PQC algorithms.

PDF · 4.3 MB · a reference document — dip in, don’t read it through

ReleasedProtocolsHigh1 rev
3GPPFeb 2026
Trust 55Needs review
ETSI TS 103 744 v1.3.1Updated

Updated framework incorporating NIST finalized ML-KEM standards and additional hybrid patterns.

PDF · 199 KB · a short read

ReleasedProtocolsHigh1 revReviewed (LLM) · maintainer (automated) · Jul 2026 · via automated, plan-driven remediation (pqctoday-hub-remediation-plans-07082026/library.md, all items P1-P3); facts re-verified against rfc-editor.org, csrc.nist.gov, etsi.org, and live HTTP checks on 2026-07-09; local commit db9d8b2e on fix/hub-remediation-wave2-0708 (branch wave2-library-0708), not yet merged/pushed
ETSI QSCFeb 2026
Trust 59Needs review
DoD-OT-Control-Systems-SRGUpdated

DoD Security Requirements Guide for control systems and operational technology (OT), DISA-published.

PDF · 3.0 MB · a reference document — dip in, don’t read it through

ReleasedAlgorithm Specifications
US DoD; DISAFeb 2026
Trust 61Needs review
SIMD-0461-Falcon-FN-DSA-Signature-Verification-Precompile

Solana Improvement Document PR proposing a Falcon-512 (FN-DSA) signature verification syscall — verification only, does not replace Ed25519, framed by its own author as exploratory ('gauging interest before committing to a PQC strategy'). Retitled mid-review from a precompile to a syscall design. The author closed the PR on 2026-06-17 ('we are going to pause this effort ... closed for now, will reopen when there is more demand'), citing a separate SBF-native Falcon implementation (PR #563) as the more promising path. As of 2026-08-16 the PR remains closed/unmerged.

Web page · 585 KB · a long read

ReleasedIndustry & Research
zz-sol (community contributor); Solana Foundation (SIMD repository)Feb 1, 2026
Trust 47Needs review
RFC-9925

Defines id-alg-unsigned (1.3.6.1.5.5.7.6.36) for X.509 certificates that carry no signature: a zero-length signature BIT STRING and a placeholder issuer name (id-rdna-unsigned). Updates RFC 5280. Validators must never accept id-alg-unsigned as a signature in a certification path; the format serves trust anchors and keys that need no issuer signature. Published from draft-ietf-lamps-x509-alg-none.

Web page · 70 KB · a short read

ReleasedPKI Certificate ManagementReviewed (LLM) · eramusa · Oct 2026 · via manual data edit (library)
IETF LAMPS WG; David BenjaminFeb 1, 2026
Trust 60Needs review
BSI TR-02102-2Updated

TLS-specific PQC recommendations including hybrid key exchange. Version 2026-01.

PDF · 759 KB · a long read

ReleasedProtocolsHigh
BSI GermanyJan 27, 2026
Trust 82Authoritative
BSI TR-02102-3Updated

IPsec/IKEv2-specific PQC recommendations. Version 2026-01.

PDF · 724 KB · a long read

ReleasedProtocolsHigh
BSI GermanyJan 27, 2026
Trust 83Authoritative
BSI TR-02102-4Updated

SSH-specific PQC recommendations for secure remote access. Version 2026-01.

PDF · 639 KB · a long read

ReleasedProtocolsHigh
BSI GermanyJan 27, 2026
Trust 83Authoritative
BSI TR-02102-1Updated

German federal recommendations including ML-KEM ML-DSA SLH-DSA XMSS LMS FrodoKEM Classic McEliece. Version 2026-01. Expanded PQC KEM and signature recommendations.

PDF · 568 KB · a long read

ReleasedInternational FrameworksHigh3 revs
BSI GermanyJan 23, 2026
Trust 79Authoritative
draft-kwiatkowski-pquip-pqc-migration-00Updated

Migration guidance covering challenges, anti-patterns, and best practices for PQC transition.

Web page · 70 KB · a short read

ExpiredMigration GuidanceHigh
IETF Individual SubmissionJan 21, 2026
Trust 81Authoritative
G7-Financial-PQC-Roadmap-2026Updated

G7 Cyber Expert Group publishes roadmap for financial sector PQC migration covering inventory, risk prioritization, algorithm selection (ML-KEM, ML-DSA), testing, and transition milestones for G7 financial institutions.

PDF · 385 KB · a short read

ReleasedGovernment & PolicyHigh1 rev
G7 Cyber Expert Group; US Treasury; G7 Finance MinistersJan 17, 2026
Trust 72Authoritative
3GPP-PQC-Study-2025Updated

3GPP Technical Report 33.938 v19.2.0 (2026-01), the cryptographic inventory of 3GPP specifications: enumerates where RSA, ECDSA, ECDH and ECIES are used across the 3GPP protocol suite as the basis for transition planning. Note it names neither SUCI nor ML-KEM — the ML-KEM SUCI "Profile C" is one research paper's own proposal, not a 3GPP profile (3GPP defines Profiles A and B only).

PDF · 153 KB · a short read

ReleasedProtocolsHighReviewed (LLM) · maintainer (automated) · Jul 2026 · via automated, plan-driven backfill (pqctoday-hub-remediation-plans-07082026/revisions.md item 2, WS-C); source PR #408 already human-merged (eramusa) 2026-07-08
3GPP SA3Jan 16, 2026
Trust 60Needs review
draft-ietf-openpgp-nist-bp-comp-03Updated

Adds NIST P-384/P-521 and Brainpool384/512 hybrid combinations to the OpenPGP-PQC scheme.

Web page · 348 KB · a long read

DraftProtocols1 rev
Q. Dang (NIST); S. Ehlen; S. Kousidis (BSI); J. Roth; F. Strenzke (MTG AG)Jan 8, 2026
Trust 71Authoritative
Samsung-Thales-ML-KEM-eSE-2026Updated

Samsung System LSI and Thales bring ML-KEM quantum-resistant capabilities to embedded Secure Element (eSE). Two dedicated PQC hardware accelerators 18x faster than software. CES Best Cybersecurity Innovation Award winner. EAL6+ certification target. Crypto-agile architecture.

Web page · 418 KB · a long read

MiscIndustry & ResearchHigh
Samsung System LSI; ThalesJan 6, 2026
Trust 37Needs review
InfoSec-Global-Hype-Cycles

InfoSec Global positioning of CPM/crypto-agility as Gartner-recognized categories; useful market-landscape reference.

Web page · 94 KB · a short read

ReleasedMigration Guidance
InfoSec GlobalJan 5, 2026
Trust 56Needs review
Europol-FS-ISAC-PQC-Financial-2026Updated

Europol, FS-ISAC, and QSFF joint guidance for financial institutions on prioritising PQC migration. Introduces a Quantum Risk Score framework covering shelf life of data, exposure, and severity. Provides migration complexity assessment and cryptographic antipattern identification for financial sector risk management.

Web page · 428 KB · a long read

MiscIndustry & ResearchHigh
Europol; FS-ISAC; Quantum Safe Financial Forum2026
Trust 59Needs review
ETSI-GR-QKD-007

Establishes the vocabulary and terminology for QKD standards ensuring consistency across all ETSI QKD specifications. Defines over 100 terms related to quantum key distribution systems.

PDF · 174 KB · a short read

ReleasedIndustry & Research
ETSI ISG QKDJan 2026
Trust 82Authoritative
VIAVI-PQC-Migration-WP-2026Updated

Real-world scale performance benchmarking of PQC migration using VIAVI TeraVM Security Test on Dell R6625 hardware. Tests ML-KEM-768 hybrid (X25519Kyber768) against classical X25519 on HAProxy TLS and Strongswan IKEv2 VPN. Finds 32% throughput drop, 3500%+ latency increase (web pages 48x slower), and 75% reduction in VPN tunnel setup rate. Covers NGFWs enterprise impact and mitigation via hardware acceleration and TLS session resumption.

Web page · 66 KB · a short read

MiscIndustry & ResearchHigh
VIAVI Solutions2026
Trust 62Needs review
FS-ISAC-PQC-Timeline-2026

FS-ISAC PQC Working Group, QSFF, and CFDIR QRWG position paper on financial sector PQC migration timelines. Introduces Augmented Mosca's Theorem risk framework, 4-phase transition model, and cross-jurisdictional comparison of Australia, Canada, EU, US, UK NCSC, Bank of Israel, and MAS Singapore timelines.

Web page · 20 KB · a quick skim

ReleasedGovernment & Policy
FS-ISAC; QSFF; CFDIR QRWG; Jaime Gómez García (Banco Santander)2026
Trust 65Needs review
ref-kim-ecdlpUpdated

Presents optimized quantum circuits for Shor’s algorithm to break prime elliptic curve cryptography, estimating the physical resources and time required for such attacks.

PDF · 1.3 MB · a long read

Research PaperIndustry & Research
Hyunji Kim; Kyungbae Jang; Siyi Wang; Vikas Srivastava; Anubhab Baksi; Gyeongju Song; Hwajeong Seo; Anupam Chattopadhyay2026
Trust 53Needs review
ref-stutz-reuse-pubkeysUpdated

Analysis of cross-chain public key reuse between UTXO and account-based cryptocurrencies to improve entity clustering and privacy assessment.

PDF · 905 KB · a long read

Research PaperIndustry & Research
Rainer Stütz; Nicholas Stifter; Melitta Dragaschnig; Bernhard Haslhofer; Aljosha JudmayerJan 2026
Trust 51Needs review
Microchip-TS1800-PQC-RootOfTrust-2026Updated

Microchip Technology announces TS1800 and TS50x post-quantum-ready root-of-trust controller family. Hardware-embedded PQC at silicon level for IoT, automotive, and embedded systems. Supports ML-KEM and ML-DSA, enabling true crypto-agility in constrained devices.

Web page · 34 KB · a quick skim

MiscImplementations
Microchip Technology Incorporated2026
Trust 59Needs review
Citi-GPS-Quantum-Threat-2026

Citi GPS research report quantifying the financial system quantum threat. Estimates 19-34% probability of cryptographically relevant quantum computer by 2034 (60-82% by 2044) and $2-3.3T GDP-at-risk from a single-day quantum attack on a top-5 US bank. Covers harvest-now/decrypt-later attacks, blockchain/Bitcoin quantum exposure (~25% of bitcoin), PQC migration urgency, regulatory landscape, and recommended migration sequencing for financial institutions.

Web page · 1.6 MB · a long read

ReleasedIndustry & ResearchHigh
Citi GPS; Citigroup2026
Trust 65Needs review
ETSI-TS-103-765-1-Rail-Telecommunications-RT-FRMCS-Transport

The FRMCS transport stratum specification.

PDF · 657 KB · a long read

ReleasedProtocols
ETSIJan 2026
Trust 56Needs review
ETSI-TS-103-765-2-Rail-Telecommunications-RT-FRMCS-Service-S

The FRMCS service stratum specification.

PDF · 419 KB · a long read

ReleasedProtocols
ETSIJan 2026
Trust 56Needs review
ETSI-TS-103-765-4-Rail-Telecommunications-RT-FRMCS-On-Networ

The FRMCS on-network interworking specification.

PDF · 203 KB · a short read

ReleasedProtocols
ETSIJan 2026
Trust 55Needs review
A-Gentle-Introduction-to-Lattice-Based-Cryptography

PDF · 5.7 MB · a reference document — dip in, don’t read it through

ReleasedMigration Guidance
Unknown2026
Trust 38Needs review
Quantum-computers-are-speeding-towards-cryptographic-relevanUpdated

Web page · 168 KB · a long read

MiscMigration Guidance
Unknown2026
Trust 26Needs review
Why-Mythos-Finding-a-Flaw-in-HAWK-is-Good-for-PQC-EntrustUpdated

Web page · 104 KB · a short read

MiscMigration Guidance
Unknown2026
Trust 26Needs review
Efficient-Threshold-ML-DSA-Brave

Web page · 60 KB · a short read

ReleasedMigration Guidance
Brave2026
Trust 26Needs review
Root-Causes-626-TLS-1-3-Roadblock-Sectigo-OfficialUpdated

Web page · 562 KB · a long read

MiscProtocols
Sectigo® Official2026
Trust 26Needs review
The-Era-of-Mathematical-Zero-Days-Why-Post-Quantum-SecurityUpdated

Web page · 262 KB · a long read

MiscMigration Guidance
Qrypt2026
Trust 26Needs review
2025-in-NumbersUpdated

PDF · 2.7 MB · a reference document — dip in, don’t read it through

MiscMigration Guidance
Unknown2026
Trust 26Needs review
Frame-TransactionUpdated

Web page · 231 KB · a long read

DraftMigration Guidance
Ethereum Improvement Proposals2026
Trust 26Needs review
Trends-in-PKI-Security-A-Global-Study-of-Trends-Challenges-BUpdated

Web page · 43 KB · a short read

MiscMigration Guidance
Unknown2026
Trust 26Needs review
F5-BIG-IP-v21-1-is-now-generally-available-bringing-PQC-andUpdated

Web page · 424 KB · a long read

MiscMigration Guidance
F5, Inc.2026
Trust 26Needs review
The-Applied-Quantum-PQC-Migration-Framework-Universal-VersioUpdated

PDF · 1.9 MB · a reference document — dip in, don’t read it through

MiscMigration Guidance
Unknown2026
Trust 26Needs review
ETSI-TR-104-239-1-V1-2-1

PDF · 252 KB · a short read

ReleasedMigration Guidance
Unknown2026
Trust 37Needs review
TSA-SD-PIPELINE-2021-02GUpdated

TSA Security Directive Pipeline-2021-02G (effective May 3, 2026 to May 2, 2027) renews, without substantive change, mandatory cybersecurity measures for TSA-designated critical hazardous liquid, natural gas and LNG pipeline owner/operators: an approved Cybersecurity Implementation Plan, incident response plan, assessment program, network segmentation, access control/MFA and encryption of data in transit. Not PQC-specific; relevant to PQC migration as a binding US OT encryption and authentication mandate whose cryptography will need quantum-safe replacement.

PDF · 372 KB · a short read

ReleasedCompliance & Certification1 rev
US TSA2026
Trust 36Needs review
Campbell-Enterprise-PQC-Timelines-2026

Peer-reviewed analysis estimating enterprise PQC migration timelines by organization size - 5-7 years (small), 8-12 (medium), 12-15+ (large) - against a fault-tolerant quantum window of 2028-2033. Frames the cost and effort drivers: cryptographic inventory discovery, HSM and hardware refresh, hybrid-crypto operations, personnel scarcity, and inter-enterprise synchronization.

PDF · 435 KB · a long read

ReleasedIndustry & ResearchHigh
Robert CampbellDec 24, 2025
Trust 69Needs review
NIST CSWP 39Updated

Strategies and practices for cryptographic agility — the ability to replace and adapt cryptographic algorithms in protocols, applications, and infrastructure without disruption. Essential companion to the PQC transition.

PDF · 1.1 MB · a long read

ReleasedNIST StandardsHigh1 revReviewed (LLM) · eramusa · May 2026 · via local commit
NISTDec 19, 2025
Trust 82Authoritative
X-509-Certificate-Policy-for-the-U-S-Federal-PKI-Common-Poli

The certificate policy governing the US Federal PKI Common Policy Framework — the rules every federal CA operates under.

PDF · 958 KB · a long read

ReleasedPKI Certificate Management
Federal PKI Policy AuthorityDec 16, 2025
Trust 62Needs review
BSI-CC-PP-0084-V2-2026Updated

Security IC Platform Protection Profile including Functional Packages, Version 2.0 (16 December 2025), certified by BSI as BSI-CC-PP-0084-V2-2026.

PDF · 1.7 MB · a reference document — dip in, don’t read it through

ReleasedCompliance & Certification
Infineon Technologies AG; NXP Semiconductors (certified by BSI)Dec 16, 2025
Trust 34Needs review
CIR-EU-2025-2462-EUCC-AmendmentUpdated

Commission Implementing Regulation (EU) 2025/2462 of 8 December 2025, amending the EUCC scheme regulation (EU) 2024/482 on definitions, ICT product series certification, assurance continuity and state-of-the-art documents.

Web page · 259 KB · a long read

ReleasedCompliance & Certification
European CommissionDec 8, 2025
Trust 34Needs review
NIST-SP-800-57-Pt1-R6Updated

Major revision of NIST key management guidelines. Adds PQC security categories and quantum-resistant algorithms (FIPS 203/204/205), Ascon (SP 800-232), separates key establishment and key storage discussion, and replaces time-based algorithm approval status. Comment period closed Feb 2026.

PDF · 2.6 MB · a reference document — dip in, don’t read it through

DraftNIST StandardsHigh
NISTDec 5, 2025
Trust 83Authoritative
CISA-PQC-CATEGORY-LIST-2026Updated

Updated product category list per Executive Order 14306. Identifies cloud services web software networking hardware endpoint security as PQC-ready categories. Developed with NSA. Products must support PQC for key establishment and digital signatures.

Web page · 73 KB · a short read

ReleasedGovernment & PolicyHigh1 rev
CISA/NSADec 1, 2025
Trust 77Authoritative
RFC-9909Updated

Defines X.509 algorithm identifiers and parameter conventions for all 12 SLH-DSA parameter sets (FIPS 205 / SPHINCS+). Specifies absent-parameters rule and self-signed certificate requirements for hash-based PQC PKI. Companion to RFC 9881 (ML-DSA in X.509).

Web page · 156 KB · a long read

ReleasedPKI Certificate ManagementHigh
IETF LAMPS; Kaveh Bashiri (BSI); Scott Fluhrer (Cisco Systems); Stefan-Lukas Gazdag (genua GmbH); Daniel Van Geest (CryptoNext Security); Stavros Kousidis (BSI)Dec 2025
Trust 83Authoritative
RFC 9847Updated

Adds a Discouraged designation to TLS/DTLS IANA registries to flag weak or deprecated cryptographic mechanisms while maintaining backward compatibility.

Web page · 100 KB · a short read

ReleasedProtocols1 rev
Joseph A. Salowey; Sean TurnerDec 2025
Trust 69Needs review
UK-DSIT-CNI-PQC-Perspectives-2025Updated

UK DSIT publishes perspectives report from critical national infrastructure (CNI) sector leads on PQC transition planning. Identifies sector-specific challenges across energy, transport, finance, and telecoms.

PDF · 2.3 MB · a reference document — dip in, don’t read it through

MiscGovernment & PolicyHigh
DSIT; UK Department for Science Innovation and TechnologyNov 27, 2025
Trust 57Needs review
Cambridge-JBS-Quantum-Blockchain-2025Updated

Cambridge Judge Business School / CCAF analysis by Philippa Coney on quantum computing threats to blockchain. Covers quantum-resilient cryptography for distributed ledgers, blockchain upgrade pathways, digital asset security, and the role of regulators in the quantum transition.

Web page · 211 KB · a long read

MiscIndustry & ResearchHigh
Philippa Coney; Cambridge Centre for Alternative Finance (CCAF)Nov 26, 2025
Trust 64Needs review
fhe-rs-v0.1.1Updated

Experimental Rust library for Ring-LWE-based homomorphic encryption, implementing an RNS variant of the BFV scheme.

Web page · 34 KB · a quick skim

MiscIndustry & ResearchReviewed (LLM) · eramusa · Oct 2026 · via manual data edit (library)
Tancrède LepointNov 23, 2025
Trust 37Needs review
DoD-CIO-PQC-Memo-2025Updated

DoD CIO directive requiring all Pentagon components to inventory cryptography across all information systems. Establishes two-gate PQC approval process (intake + deployment). Sets Dec 2030 deadline for PSK replacement. Bans QKD on DoD networks.

PDF · 823 KB · a long read

MiscGovernment & PolicyHigh
DoD CIO (Katie Arrington)Nov 20, 2025
Trust 59Needs review
RFC-9901-SD-JWT-VCUpdated

IETF RFC defining SD-JWT (Selective Disclosure for JWTs) — the base selective-disclosure mechanism for JWTs using salted hashes. SD-JWT VC (verifiable credentials) is a SEPARATE IETF draft (draft-ietf-oauth-sd-jwt-vc) built on this spec and adopted by the EUDI Wallet ARF for online attestations. Text-based JSON encoding optimised for remote online services.

Web page · 2.0 MB · a long read

ReleasedMigration GuidanceHigh
IETF OAuth Working GroupNov 19, 2025
Trust 88Authoritative
liboqs-v0.15.0Updated

Latest liboqs release with updated PQC algorithm implementations including NIST-standardized ML-KEM ML-DSA and SLH-DSA. Part of Linux Foundation PQCA.

Web page · 21 KB · a quick skim

MiscMigration GuidanceHigh
Open Quantum Safe; Linux Foundation PQCANov 14, 2025
Trust 54Needs review
CSA-PQC-Guide-2025Updated

Practical roadmap for organizations to assess plan and mitigate quantum computing risks. Covers NIST FIPS 203/204/205 standards and hybrid key exchange protocols.

Web page · 98 KB · a short read

ReleasedMigration GuidanceHigh1 rev
Cloud Security AllianceNov 10, 2025
Trust 52Needs review
ref-quantinuum-heliosUpdated

Report on the Helios 98-qubit trapped-ion quantum computer architecture, performance metrics, and operational advances by Quantinuum.

PDF · 4.0 MB · a reference document — dip in, don’t read it through

Research PaperIndustry & Research
QuantinuumNov 7, 2025
Trust 40Needs review
PKI-Consortium-PQC-2025

World's largest PQC conference (2500+ delegates, 30+ countries) concluded in Kuala Lumpur. Issued urgent call for global migration. Includes Malaysia national PQC plan announcement.

Web page · 80 KB · a short read

ReleasedMigration GuidanceHigh
PKI ConsortiumNov 4, 2025
Trust 66Needs review
Malaysia-NACSA-PQC-2025Updated

NACSA's action plan operationalising Malaysia's National Cryptography Policy (MyKriptografi) into an implementation roadmap. Built on four core pillars comprising 12 strategies, 32 programmes and 80 activities across Government, National Critical Information Infrastructure (NCII), industry, academia and the wider digital economy, and named as preparing Malaysia for "the quantum computing era". The page does not publish algorithm-level requirements or a dated PQC migration timetable.

Web page · 10 KB · a quick skim

MiscGovernment & PolicyHigh
NACSA Malaysia; Malaysia Ministry of DigitalNov 1, 2025
Trust 74Authoritative
eprint-2025-2059Updated

Introduces Silithium — a fused hybrid signature combining EC-Schnorr (secp256k1) and ML-DSA-65 via an adapted Fiat-Shamir transform. Achieves Strong Non-Separability (SNS) with smaller signatures than concatenation. Defines Hybrid EU-CMA security notion covering separability, recombination, and cross-protocol attacks.

Web page · 16 KB · a quick skim

Research PaperIndustry & Research
Julien Devevey; Morgane Guerreau; Maxime RoméasNov 1, 2025
Trust 68Needs review
NZISM-V3-9Updated

New Zealand GCSB NZISM v3.9 mandatory and recommended security controls for NZ government information systems. Cryptography chapter specifies approved algorithms, key management, PKI, and TLS requirements with PQC transition guidance.

PDF · 5.8 MB · a reference document — dip in, don’t read it through

ReleasedGovernment & Policy
GCSB; New Zealand Government Communications Security BureauNov 1, 2025
Trust 64Needs review
RFC 9867

Extends RFC 8784 PSK mixing into IKE_INTERMEDIATE and CREATE_CHILD_SA so rekeying preserves PQ protection.

Web page · 108 KB · a short read

ReleasedProtocols
V. Smyslov (ELVIS-PLUS)Nov 2025
Trust 82Authoritative
Cabinet-Secretariat-Japan-PQC-Migration-Interim-Report-for-GUpdated

Japan’s interim government position on PQC migration for public institutions.

PDF · 231 KB · a short read

MiscGovernment & Policy
Inter-Ministerial Liaison Conference on the Use of Post-Quantum Cryptography (PQC) in Government Institutions, etc. (Japan)Nov 2025
Trust 80Authoritative
ETSI-TS-103-764-Rail-Telecommunications-RT-FRMCS-System-Arch

The FRMCS system architecture replacing GSM-R for European rail — new infrastructure whose cryptography is being chosen now.

PDF · 766 KB · a long read

ReleasedProtocols
ETSINov 2025
Trust 55Needs review
AppViewX-47Day-CertsUpdated

Operational guide to ACME/EST/CMP automation under the CA/B Forum 47-day cadence landing March 2029.

Web page · 120 KB · a short read

MiscMigration GuidanceHigh
AppViewXOct 30, 2025
Trust 50Needs review
RFC 9882Updated

Defines ML-DSA (Dilithium) usage in CMS for document and message signing.

Web page · 121 KB · a short read

ReleasedProtocolsHigh
IETF LAMPSOct 29, 2025
Trust 82Authoritative
Cloudflare-MTC-BlogUpdated

Cloudflare blog post explaining the Merkle Tree Certificate proposal, its motivation (PQC certificate bloat), architecture (MTCA, transparency service, subscribers), and experimental deployment results. Includes size comparison data.

Web page · 538 KB · a long read

MiscMigration Guidance
Cloudflare ResearchOct 28, 2025
Trust 48Needs review
Cloudflare-PQ-Internet-2025Updated

Cloudflare's annual review of PQC adoption across the Internet, covering ML-KEM deployment in TLS 1.3, browser support (Chrome, Firefox), certificate transparency challenges, and the MTC proposal as a solution to PQ certificate bloat.

Web page · 604 KB · a long read

MiscMigration GuidanceHigh
Cloudflare ResearchOct 28, 2025
Trust 47Needs review
Springer-MathFoundations-PQC-2026Updated

Open-access Springer volume (Mathematics for Industry 40) from the Crypto-Math CREST project. Covers mathematical foundations underlying NIST PQC standards: lattice theory (LWE, MLWE, NTRU, Module-LWE), code-based cryptography, hash-based signatures, isogeny-based cryptography, and multivariate schemes. Edited by leading Japanese cryptographers (Takagi, Wakayama, Kunihiro, Tanaka, Kimoto, Kudo). ISBN eBook 978-981-96-1218-5. CC BY 4.0.

Web page · 312 KB · a long read

Research PaperAlgorithm Specifications
Tsuyoshi Takagi; Masato Wakayama; Noboru Kunihiro; Keisuke Tanaka; Kazufumi Kimoto; Momonari Kudo (Eds.) — University of Tokyo; NTT Inc.; University of Tsukuba; Institute of Science Tokyo; University of the Ryukyus; Fukuoka Institute of TechnologyOct 28, 2025
Trust 78Authoritative
CycloneDX-Cryptography-Registry

Standalone, machine-readable naming registry introduced in CycloneDX v1.7: 96 cryptographic algorithm families (RSA, ECDSA, EdDSA, AES, ChaCha20, SHA-2/3, HKDF, ML-KEM, ML-DSA, SLH-DSA, XMSS, LMS, and more) across 14 primitive types, plus 246 elliptic curves across 15 standardization categories (NIST, Brainpool, SECG, BLS, GOST, etc). Published as versioned JSON + JSON Schema, usable independently of CycloneDX/CBOM tooling for any framework needing consistent crypto-mechanism naming.

Web page · 202 KB · a long read

ReleasedMigration Guidance
OWASP CycloneDXOct 21, 2025
Trust 74Authoritative
CycloneDX-Spec-OverviewUpdated

OWASP CycloneDX general Bill of Materials specification, standardized as ECMA-424 — covers SBOM, SaaSBOM, HBOM, ML-BOM, VDR/VEX and CBOM as sibling BOM types sharing one object model. This is the general-BOM spec entry point; the crypto-specific CBOM capability guide is tracked separately (see OWASP-CycloneDX-CBOM-Guide).

Web page · 37 KB · a quick skim

ReleasedAlgorithm Specifications
OWASP CycloneDX / Ecma International TC54Oct 21, 2025
Trust 82Authoritative
2510-10436-Post-Quantum-Cryptography-and-Quantum-Safe-SecuriUpdated

A survey paper covering post-quantum cryptography and quantum-safe security as a combined field.

Web page · 43 KB · a short read

ReleasedIndustry & Research1 rev
Gaurab Chhetri; Shriyank Somvanshi; Pavan Hebli; Shamyo Brotee; Subasish DasOct 12, 2025
Trust 75Authoritative
CA-TBS-SPIN-PQC-2025Updated

Treasury Board of Canada Secretariat (TBS) Security Policy Implementation Notice (SPIN 2025-01) directing all federal departments to begin PQC migration planning. Establishes inventory requirements and migration timelines for Government of Canada IT systems.

Web page · 37 KB · a quick skim

ReleasedGovernment & PolicyHighReviewed (LLM) · eramusa · May 2026 · via local commit
Treasury Board of Canada Secretariat; Government of CanadaOct 9, 2025
Trust 56Needs review
IBM-IBV-Secure-PostQuantum-2025

IBM Institute for Business Value report on enterprise quantum-safe readiness; organizational maturity model and investment sequencing.

Web page · 582 KB · a long read

ReleasedMigration Guidance
Ray Harishankar et al. (IBM IBV)Oct 3, 2025
Trust 52Needs review
RFC 9858Updated

Adds SHA-256/192, SHAKE256/256, and SHAKE256/192 parameter sets for LMS/HSS, reducing signature sizes by 35-40% compared to the original RFC 8554 SHA-256 parameter sets.

Web page · 117 KB · a short read

ReleasedDigital Signature
IETF CFRGOct 2025
Trust 76Authoritative
RFC 9881Updated

Defines X.509 OIDs and certificate structures for ML-DSA (Dilithium) signatures. Supersedes draft-ietf-lamps-dilithium-certificates.

Web page · 296 KB · a long read

ReleasedPKI Certificate ManagementHigh2 revs
IETF LAMPSOct 2025
Trust 78Authoritative
ANSSI-PQC-FAQ-2025Updated

ANSSI frequently asked questions on post-quantum cryptography covering algorithm selection, hybrid approaches, migration timelines, and practical guidance for French organizations. Updated October 2025.

Web page · 63 KB · a short read

MiscGovernment & PolicyHigh
ANSSIOct 1, 2025
Trust 76Authoritative
ENISA-Threat-Landscape-2025Updated

Annual ENISA threat landscape report analyzing 4,875 incidents from July 2024 to June 2025; identifies quantum computing as a strategic long-term threat requiring proactive PQC transition planning.

PDF · 4.5 MB · a reference document — dip in, don’t read it through

MiscInternational FrameworksHigh
ENISAOct 2025
Trust 57Needs review
FrodoKEM-SCA-Countermeasures-2024Updated

Implementation study on FrodoKEM side-channel countermeasures. Analyzes power-analysis and template attacks on the discrete Gaussian sampler; proposes isochronous sampling and masking. Includes fault-injection countermeasures with sampling calibration.

PDF · 1.5 MB · a reference document — dip in, don’t read it through

Research PaperIndustry & Research
Research Square (preprint)Oct 1, 2025
Trust 50Needs review
Labour-Tech-Defend-or-Depend-Policy-2025

UK Labour Tech policy report on defence sovereignty covering quantum commercialisation, PQC adoption pathways, quantum sensing/PNT, and the strategic case for UK sovereign quantum capability. Includes Steven Vaile chapter on quantum cybersecurity procurement reform (pp.22-23).

PDF · 1.5 MB · a reference document — dip in, don’t read it through

ReleasedGovernment & PolicyHigh
Labour Tech; Steven Vaile; Jack Shaw (ed.); Dr. Joe Spencer; Naushabah Khan MP; Calvin Bailey MBE MPOct 1, 2025
Trust 49Needs review
Westerbaan-PQCrypto2025-SlidesUpdated

Invited talk slides by Bas Westerbaan (Cloudflare Research) at PQCrypto 2025. Covers the state of PQC deployment on the internet: ML-KEM adoption in TLS, maximum compatibility mode and its limits, quantum downgrade attacks (active MITM suppressing PQC negotiation), PQ Lock/PQC HSTS, PQC Continuity (draft-sheffer-tls-pqc-continuity), and Merkle Tree Certificates as a downgrade detection layer via public issuance logs.

PDF · 2.0 MB · a reference document — dip in, don’t read it through

MiscIndustry & ResearchHigh
Bas Westerbaan (Cloudflare Research)Oct 1, 2025
Trust 60Needs review
GFMA-Quantum-Migration-Mapping-the-Emerging-Landscape-Octobe

The Global Financial Markets Association’s survey of the quantum migration landscape for financial institutions.

PDF · 1.7 MB · a reference document — dip in, don’t read it through

ReleasedMigration GuidanceHigh
GFMA (Global Financial Markets Association)Oct 1, 2025
Trust 52Needs review
RFC-9864Updated

IETF Standards Track RFC that defines fully-specified JOSE and COSE algorithm identifiers (fixing curve, KDF and hash) and deprecates the polymorphic identifiers in RFCs 8037 and 9053, e.g. replacing EdDSA with Ed25519/Ed448. The document itself does not mention PQC; it matters for PQC migration because it sets the rule that new JOSE/COSE algorithm registrations name one fully-specified algorithm.

Web page · 124 KB · a short read

ReleasedProtocols
IETF; M.B. Jones (Self-Issued Consulting); O. Steele (Tradeverifyd)Oct 2025
Trust 58Needs review
FRB-FEDS-2025093-Blockchain-PQCUpdated

Federal Reserve FEDS Working Paper (2025-093) analysing HNFL risks for blockchain networks. Examines how quantum computers could retroactively compromise immutable on-chain transaction data across Bitcoin, Ethereum, and distributed ledger systems.

PDF · 398 KB · a short read

Research PaperIndustry & ResearchHigh
Federal Reserve BoardSep 30, 2025
Trust 55Needs review
SG-MAS-QKD-Sandbox-Report-2025

MAS and industry partners (DBS, HSBC, OCBC, UOB) technical report on QKD proof-of-concept sandbox (Sept 2024-March 2025). Reports 6.75M AES-256 keys/day per bank, demonstrating feasibility of quantum-safe key distribution in financial settlement systems.

Web page · 254 KB · a long read

ReleasedGovernment & Policy
MAS; DBS; HSBC; OCBC; UOB; Singtel; SPTelSep 29, 2025
Trust 62Needs review
NIST-SP-800-90CUpdated

NIST standard specifying constructions for Random Bit Generators (RBGs) that combine entropy sources with DRBGs. Defines RBG1, RBG2, RBG3, and RBGC classes for defense-in-depth randomness.

PDF · 10.1 MB · a reference document — dip in, don’t read it through

ReleasedNIST StandardsHigh
NISTSep 25, 2025
Trust 89Authoritative
MQOM-Round2-Spec

MPC-in-the-Head signature whose security rests on solving random multivariate quadratic (MQ) systems over finite fields. Best combined public-key-plus-signature sizes across all three NIST levels among MPCitH candidates, with competitive signing and verification speeds. NIST IR 8528 explicitly flagged that ROM and QROM security proofs still need further maturation.

PDF · 708 KB · a long read

ReleasedNIST Standards
MQOM submission team (Feneuil, Joux, Rivain, et al.)Sep 22, 2025
Trust 74Authoritative
NIST SP 800-227Updated

Guidance for implementing KEMs securely including hybrid KEMs and FIPS 140 validation requirements.

PDF · 903 KB · a long read

ReleasedKEMHigh
NISTSep 18, 2025
Trust 86Authoritative
NIST CSWP 48Updated

Maps NCCoE PQC Migration project capabilities to NIST Cybersecurity Framework 2.0 (CSF 2.0) and SP 800-53 security controls, helping organizations align PQC migration efforts with established risk management frameworks and identify controls needed for successful PQC migration.

PDF · 593 KB · a long read

DraftNIST StandardsHigh
NIST NCCoESep 18, 2025
Trust 80Authoritative
OpenID4VCI-SpecUpdated

OpenID Foundation specification defining how credential issuers expose APIs for digital credential issuance. Specifies credential offer flow pre-authorisation code flow authorisation code flow and credential endpoint. Defines proof of possession using key binding JWTs. Mandatory protocol for all EUDI Wallet credential issuers (PID providers attestation issuers).

Web page · 504 KB · a long read

ReleasedProtocolsHigh
OpenID FoundationSep 16, 2025
Trust 54Needs review
ArXiv-2025-SLH-DSA-RowhammerUpdated

Demonstrates Rowhammer-based universal signature forgery on SLH-DSA. Induces DRAM bit flips during signature generation to produce valid signatures without knowledge of the private key. Emphasizes Rowhammer as a persistent remotely triggerable threat.

Web page · 44 KB · a short read

Research PaperIndustry & ResearchHigh
arXivSep 16, 2025
Trust 52Needs review
NIST SP 800-88Updated

Guidelines for establishing a media sanitization program to ensure the confidentiality of information on storage media through clear, purge, and destroy methods.

PDF · 984 KB · a long read

ReleasedGovernment & Policy
NISTSep 2025
Trust 87Authoritative
NetDiligence Cyber Claims Study 2025

Analysis of 10,402 real cyber-insurance claims from incidents in 2020-2024, split into SMEs (under $2B revenue) and large companies. Figures 9 and 10 give the five-year average total incident cost per tier ($264K and $10.3M), the source of the organization-size cost anchors in roiBaselines.ts.

PDF · 9.5 MB · a reference document — dip in, don’t read it through

ReleasedIndustry & ResearchReviewed · claude-opus-5 (session review, 2026-08-11) · Aug 2026 · via primary-document retrieval + manual data edit
NetDiligenceSep 2025
Trust 44Needs review
PCI-SSC-Blog-Authentication-Cryptography-GuidanceUpdated

PCI Perspectives blog post of 26 August 2025 announcing new PCI SSC guidance on authentication and cryptography.

Web page · 87 KB · a short read

MiscCompliance & CertificationReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
PCI Security Standards Council (PCI Perspectives blog)Aug 26, 2025
Trust 34Needs review
HQC SpecificationUpdated

Code-based KEM selected March 2025 as backup to ML-KEM. Draft FIPS expected 2026, final 2027.

PDF · 876 KB · a long read

DraftKEM
NIST/HQC TeamAug 22, 2025
Trust 77Authoritative
Sectigo-State-Crypto-Agility-2025Updated

Sectigo annual benchmark of crypto-agility and CLM automation maturity across 500+ enterprises.

Web page · 588 KB · a long read

MiscMigration Guidance
SectigoAug 18, 2025
Trust 57Needs review
NIST-SP-800-232Updated

NIST lightweight cryptography standard based on the Ascon algorithm family. Specifies Ascon-AEAD128 (authenticated encryption), Ascon-Hash256 (hash), and Ascon-XOF128/CXOF128 (extendable output functions) for constrained IoT and embedded devices.

PDF · 1.2 MB · a long read

ReleasedNIST Standards
NISTAug 13, 2025
Trust 83Authoritative
CISA-OT-Asset-Inventory-Guidance

CISA/NSA joint guidance on building an OT asset inventory and taxonomy for critical infrastructure operators.

PDF · 1.0 MB · a long read

ReleasedGovernment & Policy
CISA; NSAAug 13, 2025
Trust 65Needs review
ASC-X9-PQC-Readiness-2025Updated

ASC X9 report providing guidance on safely and cost-effectively migrating the financial services industry to post-quantum cryptography. Covers readiness needs assessment, migration priorities, risk frameworks, and practical implementation recommendations for financial institutions transitioning to NIST PQC standards.

PDF · 119 KB · a short read

MiscIndustry & ResearchHigh
ASC X9Aug 5, 2025
Trust 57Needs review
Keyfactor-Introducing-CBOM

Keyfactor framing of CBOM as a foundation for modern cryptographic management.

Web page · 140 KB · a short read

ReleasedMigration Guidance
KeyfactorAug 5, 2025
Trust 55Needs review
Common-Policy-X-509-Certificate-and-CRL-Profile

The current (pre-PQC) profile for US Federal PKI certificates and CRLs.

PDF · 573 KB · a long read

ReleasedPKI Certificate Management
Federal PKI Policy AuthorityAug 4, 2025
Trust 61Needs review
arXiv-2508-01694Updated

Empirical performance benchmarks comparing CRYSTALS-Kyber (ML-KEM) against RSA and ECC for key generation, encapsulation, and storage. Provides quantitative evidence that Kyber achieves faster operations and smaller key sizes than RSA while being quantum-resistant.

Web page · 43 KB · a short read

Research PaperIndustry & Research
Cornell UniversityAug 3, 2025
Trust 65Needs review
CIR-EU-2025-1567-Remote-QSCD-ManagementUpdated

Commission Implementing Regulation (EU) 2025/1567 of 29 July 2025, under eIDAS (Regulation (EU) No 910/2014), on managing remote qualified signature and seal creation devices as qualified trust services.

Web page · 31 KB · a quick skim

ReleasedCompliance & Certification
European CommissionJul 29, 2025
Trust 34Needs review
CIR-EU-2025-1570-QSCD-Certification-NotificationUpdated

Commission Implementing Regulation (EU) 2025/1570 of 29 July 2025, under eIDAS, on notifying information about certified qualified signature and seal creation devices.

Web page · 29 KB · a quick skim

ReleasedCompliance & Certification
European CommissionJul 29, 2025
Trust 34Needs review
draft-sfluhrer-ipsecme-ikev2-mldsaUpdated

This document describes how to use the ML-DSA post-quantum signature algorithm for authentication within IKEv2 as a replacement for traditional algorithms.

Web page · 61 KB · a short read

DraftProtocols2 revs
IETFJul 28, 2025
Trust 82Authoritative
RFC 9814Updated

Defines SPHINCS+ (SLH-DSA), the stateless hash-based signature standard, usage in Cryptographic Message Syntax. Included for comparison with stateful LMS/XMSS schemes.

Web page · 85 KB · a short read

ReleasedProtocols
IETF LAMPSJul 19, 2025
Trust 81Authoritative
PQ-SUCI-MLKEM-Profile-C-2025Updated

Peer-reviewed proposal for a post-quantum SUCI protection scheme. Defines a "Profile C" (identifier 0x3) using ML-KEM/Kyber-512 alongside the 3GPP-defined Profiles A and B. RESEARCH PROPOSAL, not a 3GPP-standardised profile — the authors state Profiles A and B are defined by 3GPP and that Profile C is their own scheme.

PDF · 447 KB · a long read

Research PaperIndustry & Research
Information (MDPI), vol. 16 no. 7, art. 617Jul 18, 2025
Trust 69Needs review
OpenID4VP-SpecUpdated

OpenID Foundation specification defining how holders present verifiable credentials to relying parties. Specifies the authorization request presentation definition (DIF PE) and presentation submission. Enables selective disclosure presentations where holders reveal only the credential attributes required by the relying party. Mandatory for EUDI Wallet credential presentation flows.

Web page · 515 KB · a long read

ReleasedProtocolsHigh
OpenID FoundationJul 9, 2025
Trust 54Needs review
CA-B-Forum-Ballot-SMC013Updated

Enables ML-DSA post-quantum digital signatures in S/MIME certificates. IPR Exclusion period completed with no notices filed. Adopted August 22 2025.

Web page · 24 KB · a quick skim

ReleasedPKI Certificate ManagementHigh
CA/Browser ForumJul 2, 2025
Trust 55Needs review
RFC 9810Updated

Adds KEM key transport to CMP. Obsoletes RFC 4210.

Web page · 583 KB · a long read

ReleasedPKI Certificate Management3 revs
IETF LAMPSJul 2025
Trust 80Authoritative
NIST-SP-800-63-3Updated

NIST framework for digital identity management. SP 800-63A covers identity proofing and enrollment (Identity Assurance Levels IAL1/2/3). SP 800-63B covers authentication (Authenticator Assurance Levels AAL1/2/3). SP 800-63C covers federation (Federation Assurance Levels FAL1/2/3). Referenced in EUDI Wallet implementations for IAL/AAL equivalency mapping with European LoA (Low Substantial High).

PDF · 858 KB · a long read

ReleasedNIST Standards
NISTJul 2025
Trust 87Authoritative
BIS-Paper-158Updated

Bank for International Settlements paper outlining quantum-readiness roadmap for global financial systems. Covers cryptographic inventory, migration timelines, and cross-border interoperability for central banks.

PDF · 2.2 MB · a reference document — dip in, don’t read it through

Research PaperIndustry & ResearchHigh
BIS; Bank for International SettlementsJul 2025
Trust 72Authoritative
RFC 9811Updated

CMP profile for HSM-based certificate lifecycle management; enables PQC key generation and ML-DSA certificate enrollment directly from PKCS#11-compliant HSMs.

Web page · 78 KB · a short read

ReleasedPKI Certificate ManagementHigh
IETFJul 2025
Trust 82Authoritative
HK-CI-Ordinance-2025Updated

Hong Kong Legislative Council enacts critical infrastructure cybersecurity legislation requiring operators to protect computer systems including cryptographic controls relevant to PQC migration.

Web page · 13 KB · a quick skim

MiscGovernment & PolicyHigh
Hong Kong LegCo; HKMAJun 27, 2025
Trust 53Needs review
NIST-ESV-Cert-E266Updated

Web page · 42 KB · a short read

MiscMigration Guidance
NIST CMVP (ESV)Jun 27, 2025
Trust 26Needs review
draft-ietf-pquip-hybrid-signature-spectrumsUpdated

Defines a taxonomy for hybrid digital signature schemes combining classical and PQC algorithms; informs IETF composite signature standards.

Web page · 75 KB · a short read

DraftProtocolsHigh2 revs
IETF PQUIPJun 20, 2025
Trust 74Authoritative
ASC-X9-Financial-PKIUpdated

ASC X9 Financial PKI launched June 2025 (key ceremony June 13). Industry-specific PKI infrastructure for financial services built with DigiCert as managed provider. Supports both legacy algorithms for backward compatibility and post-quantum cryptography (ML-KEM, ML-DSA) for next-generation algorithm transition. Purpose-built for payment terminal interoperability, cross-enterprise authentication, and secure device communication.

Web page · 119 KB · a short read

MiscIndustry & ResearchHigh
ASC X9; DigiCertJun 13, 2025
Trust 58Needs review
APRA-CPS-234Updated

APRA Prudential Standard CPS 234 mandates that all APRA-regulated entities (banks, insurers, superannuation funds) maintain information security capabilities commensurate with threats. Requires board accountability, policy frameworks, and cryptographic controls for sensitive data. PQC transition is in scope as a material vulnerability in long-lived cryptographic infrastructure.

Web page · 1.0 MB · a long read

ReleasedGovernment & PolicyHigh
APRA; Australian Prudential Regulation AuthorityJun 10, 2025
Trust 85Authoritative
EO-14306

Trump administration EO directing DHS/CISA to publish PQC product categories. Requires TLS 1.3 adoption by 2030. Amends EO 13694 and EO 14144. Retains PQC migration provisions from Biden era.

Web page · 321 KB · a long read

ReleasedGovernment & PolicyHigh
White HouseJun 6, 2025
Trust 62Needs review
HSBC-InfoSecGlobal-Thales-CryptographicInventory-2025Updated

Joint industry whitepaper from HSBC, InfoSec Global (Keyfactor), and Thales covering Ten Strategic Principles for cryptographic inventory. Presents the business case for proactive cryptographic discovery, CBOM generation methodology, crypto agility frameworks, and enterprise case studies for PQC migration readiness planning.

PDF · 15.4 MB · a reference document — dip in, don’t read it through

MiscMigration GuidanceHigh
HSBC; InfoSec Global (Keyfactor); Thales; Blair Canavan (Thales); Dr. Vladimir Soukharev (InfoSec Global)Jun 2, 2025
Trust 69Needs review
RFC 9794Updated

Defines terminology for PQ/T hybrid schemes including composite KEMs and signatures.

Web page · 98 KB · a short read

ReleasedMigration GuidanceHigh1 rev
IETF PQUIPJun 2025
Trust 83Authoritative
RFC 9802Updated

Defines OIDs and certificate structures for stateful hash-based signatures in X.509.

Web page · 148 KB · a short read

ReleasedPKI Certificate Management
IETF LAMPSJun 2025
Trust 76Authoritative
RFC-9763Updated

Defines a CSR attribute (relatedCertRequest) and X.509 extension (RelatedCertificate) that bind two certificates to the same end entity. Enables non-composite hybrid authentication using separate traditional and PQC certificates (the catalyst approach). Published as RFC 9763.

Web page · 80 KB · a short read

ReleasedPKI Certificate ManagementHigh1 rev
IETF LAMPS; Alison Becker (NSA); Rebecca Guthrie (NSA); Michael Jenkins (NSA)Jun 2025
Trust 77Authoritative
GSA-PQC-Buyers-Guide-2025Updated

GSA Federal Acquisition Service guide for federal agencies procuring PQC-capable products. Covers PQC planning and implementation use cases, Quantum Security-as-a-Service (QSaaS), Quantum SD-WAN, and PQC + Zero Trust Architecture integration.

PDF · 5.4 MB · a reference document — dip in, don’t read it through

ReleasedGovernment & PolicyHigh
GSA Federal Acquisition ServiceJun 2025
Trust 73Authoritative
NSA CNSA 2.0Updated

US government adoption requirements for ML-KEM-1024, ML-DSA-87, SLH-DSA, LMS/XMSS. Level 5 recommended.

PDF · 587 KB · a long read

ReleasedGovernment & PolicyHigh1 revReviewed (LLM) · eramusa · May 2026 · via local commit
NSAMay 30, 2025
Trust 79Authoritative
W3C-Verifiable-Credentials-Data-Model-v2-0Updated

The W3C data model for verifiable credentials. Its signature suites are where post-quantum algorithms have to land for digital identity.

Web page · 1.0 MB · a long read

ReleasedProtocols
W3C Verifiable Credentials Working GroupMay 15, 2025
Trust 81Authoritative
UAE-DESC-PQC-GuidelineUpdated

Dubai Electronic Security Center (DESC) launches PQC guideline at GISEC Global 2025 to prepare Dubai digital infrastructure for quantum threats. Migration framework for Dubai government and private sector.

Web page · 235 KB · a long read

MiscGovernment & PolicyHigh
DESC; Dubai Electronic Security CenterMay 6, 2025
Trust 59Needs review
ONC-Health-IT-Certification-Criterion-170-315-d-7-End-User-DUpdated

The US health-IT certification criterion for end-user device encryption.

Web page · 409 KB · a long read

MiscCompliance & Certification
Office of the National Coordinator for Health IT (ONC), U.S. HHSMay 4, 2025
Trust 85Authoritative
ONC-Health-IT-Certification-Criterion-170-315-d-8-IntegrityUpdated

The US health-IT certification criterion for data integrity, which is where signature algorithms are pinned.

Web page · 393 KB · a long read

MiscCompliance & Certification
Office of the National Coordinator for Health IT (ONC), U.S. HHSMay 4, 2025
Trust 85Authoritative
ONC-Health-IT-Certification-Criterion-170-315-d-9-Trusted-CoUpdated

The US health-IT certification criterion for trusted connections — the TLS requirements certified health software must meet.

Web page · 396 KB · a long read

MiscCompliance & Certification
Office of the National Coordinator for Health IT (ONC), U.S. HHSMay 4, 2025
Trust 85Authoritative
EUCC v2.0 ACMUpdated

Includes PQC algorithms in Agreed Cryptographic Mechanisms for EUCC certification.

PDF · 407 KB · a long read

ReleasedInternational FrameworksHigh1 rev
ECCG/ENISAMay 2025
Trust 70Authoritative
PQCC-Migration-Roadmap-2025Updated

PQCC publishes PQC Migration Roadmap with four-category framework: Preparation, Prioritization, Migration, and Sustainment. Practical guidance for organizations at any stage of PQC transition.

PDF · 750 KB · a long read

MiscInternational FrameworksHigh
PQCC; Post-Quantum Cryptography CoalitionMay 2025
Trust 65Needs review
ref-gidney-factor-rsaUpdated

Estimation of the physical qubit and time costs required to factor 2048-bit RSA integers using noisy quantum computers.

PDF · 4.2 MB · a reference document — dip in, don’t read it through

Research PaperIndustry & Research
C. GidneyMay 2025
Trust 44Needs review
https-arxiv-org-pdf-2505-08791Updated

PDF · 187 KB · a short read

Research PaperAlgorithm Specifications
Alexander MeyerMay 2025
Trust 50Needs review
OpenSSL-3.5.0-ReleaseUpdated

OpenSSL 3.5.0 (April 29, 2025) is the first version to include ML-KEM (FIPS 203), ML-DSA (FIPS 204), SLH-DSA (FIPS 205), and X25519MLKEM768 hybrid TLS natively, without the OQS provider. This is the foundational library release enabling mainstream PQC adoption across TLS stacks, VPNs, and cryptographic applications worldwide.

Web page · 49 KB · a short read

MiscImplementationsHigh
OpenSSL ProjectApr 29, 2025
Trust 82Authoritative
PKCS-11-Cryptographic-Token-Interface-Usage-Guide-Version-3Updated

Companion guidance to PKCS#11 v3.2 and a normative reference of it. v3.2 moved the session-state model, the user/login model and the object-access matrix out of the base specification and into this document — the spec says only that CK_STATE holds the session state 'as described in [PKCS11-UG]'. Auditing session, login or private-object access behaviour against the base specification alone will therefore find no governing text. Note the process asymmetry: this is a non-standards-track Committee Note that the Standard nevertheless cites normatively. Edited by Dieter Bong (Utimaco); supersedes the v2.40 Usage Guide.

PDF · 468 KB · a long read

MiscProtocols
OASIS PKCS11 Technical CommitteeApr 15, 2025
Trust 63Needs review
CAB-Forum-SC-081v3Updated

CA/Browser Forum Ballot SC-081v3 establishing requirements for post-quantum key exchange in TLS certificates issued by publicly trusted CAs. Affects all Web PKI certificate issuers.

Web page · 35 KB · a quick skim

ReleasedPKI Certificate ManagementHigh
CA/Browser ForumApr 11, 2025
Trust 82Authoritative
PQCC-Inventory-Workbook-2025Updated

PQCC publishes structured workbook to assist organizations in creating centralized cryptographic inventories for PQC migration planning. Covers asset identification, risk prioritization, and migration scheduling.

Web page · 88 KB · a short read

MiscInternational FrameworksHigh
PQCC; Post-Quantum Cryptography CoalitionApr 9, 2025
Trust 63Needs review
ETSI-EN-319-411Updated

ETSI standard defining policy and security requirements for Qualified Trust Service Providers (QTSPs) issuing qualified certificates under eIDAS. Forms the basis for European CA auditing under WebTrust/ETSI audit schemes and the EUDI Trust Framework for credential issuer accreditation. Part 1 covers general requirements; Part 2 covers NCP/NCP+/QCP/eIDAS policies.

PDF · 362 KB · a short read

ReleasedInternational FrameworksHigh
ETSIApr 2025
Trust 88Authoritative
UK-CMORG-PQC-Guidance-2025Updated

UK Cross Market Operational Resilience Group (CMORG) publishes PQC guidance for UK financial sector. Covers threat landscape, algorithm selection, migration planning, and prioritization for UK banks and financial market infrastructures.

PDF · 277 KB · a short read

MiscGovernment & PolicyHigh
CMORG; Bank of England; UK Financial AuthoritiesApr 2025
Trust 65Needs review
ETSI-launches-new-standard-for-Quantum-Safe-Hybrid-Key-ExchaUpdated

ETSI announcement of its quantum-safe hybrid key-exchange standard — useful as a dated marker of when the specification became citable.

Web page · 137 KB · a short read

MiscIndustry & ResearchHigh
ETSIMar 25, 2025
Trust 67Needs review
SecBoulevard-Carielli-CryptoAgility-2025Updated

Forrester Principal Analyst Sandy Carielli on why crypto-agility and posture management investments are justified on operational merit alone.

Web page · 654 KB · a long read

MiscMigration Guidance
Sandy Carielli (Forrester) / Security BoulevardMar 24, 2025
Trust 53Needs review
UK-NCSC-Migration-Timelines-2025Updated

UK NCSC three-phase PQC migration timeline guidance. Phase 1 (by 2028): discovery and planning; Phase 2 (2028-2031): active migration of priority systems; Phase 3 (by 2035): complete PQC migration. Includes sector-specific guidance for UK government and CNI.

PDF · 202 KB · a short read

MiscGovernment & PolicyHigh
NCSC UK; UK National Cyber Security CentreMar 20, 2025
Trust 77Authoritative
draft-ietf-tls-cert-abridge

Proposed TLS Certificate Compression scheme using a shared dictionary of root and intermediate WebPKI certificates. Streamlines transition toward post-quantum cryptography by removing root and intermediate certificates from the TLS certificate chain while preserving trust verification. Reportedly provides superior compression vs competing approaches. Cited by PQCC April 2026 transport-issues panel as mitigation for TCP Initial Congestion Window and QUIC amplification protection.

Web page · 50 KB · a short read

ExpiredProtocols
IETF TLS WGMar 20, 2025
Trust 73Authoritative
NIST-ESV-Cert-E232Updated

Web page · 41 KB · a short read

MiscMigration Guidance
NIST CMVP (ESV)Mar 14, 2025
Trust 26Needs review
NIST-ESV-Cert-E233Updated

Web page · 41 KB · a short read

MiscMigration Guidance
NIST CMVP (ESV)Mar 14, 2025
Trust 26Needs review
NIST IR 8545Updated

Documents HQC selection as fourth PQC standard providing code-based cryptographic diversity.

Web page · 50 KB · a short read

ReleasedKEM
NISTMar 11, 2025
Trust 80Authoritative
GSMA-PQC-Country-Survey-2025Updated

GSMA survey of post-quantum cryptography government initiatives across countries and regions as of March 2025. Covers national PQC programs, regulatory developments, and migration timelines for 30+ countries.

PDF · 207 KB · a short read

MiscGovernment & Policy
GSMAMar 2, 2025
Trust 62Needs review
ETSI TS 103 744Updated

Framework for hybrid ECDH + ML-KEM with standard key combiners (concatenation, HKDF).

PDF · 252 KB · a short read

ReleasedProtocolsHigh
ETSI QSCMar 2025
Trust 92Authoritative
Japan CRYPTREC Report 2024Updated

Japanese government evaluation of PQC algorithms covering ML-KEM/DSA/SLH-DSA/FN-DSA/HQC with security analysis and migration guidance based on Mosca's inequality framework.

PDF · 1.3 MB · a long read

MiscGovernment & PolicyHigh
CRYPTREC JapanMar 2025
Trust 73Authoritative
SDitH-Round2-Spec

MPC-in-the-Head signature built on the syndrome decoding problem for random linear codes over finite fields — one of the most-studied hard problems in code-based cryptography, dating to McEliece (1978). Among the MPCitH candidates, only FAEST (AES-based) shares a comparably well-analysed security foundation. Tradeoff: typically slower than its MPCitH peers, though sizes are competitive when tuned.

PDF · 576 KB · a long read

ReleasedNIST Standards
SDitH submission team (Aguilar Melchor, Gama, Howe, Hülsing, Joseph, Yue, et al.)Feb 5, 2025
Trust 74Authoritative
UOV-Round2-Spec

Original UOV construction by Kipnis-Patarin-Goubin (1999). Public key is a system of multivariate quadratic polynomials with the secret oil/vinegar partition hidden inside. Tiny 96 B signatures at NIST L1; large public key (~66 KB raw, ~1.2 KB compressed) and private key (~237 KB). 2025 Ran wedge attack pushed three of four parameter sets (uov-Ip, uov-III, uov-V) below their security targets; reparameterisation in odd-characteristic fields restores security.

PDF · 742 KB · a long read

ReleasedNIST Standards
UOV submission team (Beullens, Chen, Ding, Kuo, Petzoldt, Wang, et al.)Feb 5, 2025
Trust 75Authoritative
HAWK-Round2-Spec

Lattice signature that eliminates FN-DSA's floating-point Gaussian-sampling pain — pure integer arithmetic on a rank-2 module lattice with a Gram matrix as the public key. Compact 555 B signatures at NIST L1 — smaller than both ML-DSA and FN-DSA — and dramatically easier to implement in constant time on constrained hardware. Security rests on newer assumptions: the Search Module Lattice Isomorphism Problem (smLIP) and the One-More-Shortest-Vector Problem (omSVP). NIST flagged these for further community analysis; Round 2 included a refined omSVP definition addressing a discrepancy found during evaluation.

PDF · 1.1 MB · a long read

ReleasedNIST Standards
HAWK submission team (Bernard, Espitau, Fouque, Kirchner, Pulles, Pornin, Postlethwaite, Prest, et al.)Feb 5, 2025
Trust 74Authoritative
EUDI-Wallet-ARF

Technical architecture and reference framework for the European Digital Identity Wallet. Defines credential formats (mso_mdoc per ISO 18013-5 and SD-JWT VC (draft-ietf-oauth-sd-jwt-vc)) trust framework protocol requirements (OpenID4VCI OpenID4VP) and cryptographic security requirements. Specifies no PQC migration roadmap — the Dec 2026/2030/2035 transition dates come from the NIS Cooperation Group Coordinated Implementation Roadmap (June 2025), not from the ARF.

Web page · 417 KB · a long read

ReleasedInternational FrameworksHigh
European Commission; eIDAS Expert GroupFeb 4, 2025
Trust 59Needs review
ETSI-TS-104-015Updated

Defines KEMAC (Key Encapsulation Mechanism with Access Control) scheme called Covercrypt. Provides pre- and post-quantum security through hybridization with precise data access control. Encapsulation and decapsulation in hundreds of microseconds.

PDF · 258 KB · a short read

ReleasedProtocols
ETSIFeb 2025
Trust 85Authoritative
RFC 9690Updated

Defines RSA-KEM usage in CMS EnvelopedData using KEMRecipientInfo. Obsoletes RFC 5990. Supports hybrid RSA+ML-KEM migration scenarios for S/MIME.

Web page · 143 KB · a short read

ReleasedProtocols1 rev
IETF LAMPSFeb 2025
Trust 86Authoritative
CZ-NUKIB-Crypto-Requirements-2023Updated

Czech NUKIB publishes minimum requirements for cryptographic algorithms including PQC readiness guidance. Sets 2027 deadline for key establishment migration and recommends hybrid PQC approaches for Czech government systems.

PDF · 382 KB · a short read

ReleasedGovernment & PolicyHigh1 rev
NUKIB; Czech National Cyber and Information Security AgencyFeb 1, 2025
Trust 58Needs review
5G-Americas-PQCS-2025Updated

Industry white paper examining post-quantum cryptography impacts on 5G and telecommunications network security. Covers PQC algorithm readiness, protocol migration for 5G NR and core network, and vendor ecosystem status.

PDF · 6.8 MB · a reference document — dip in, don’t read it through

MiscIndustry & ResearchHigh
5G AmericasFeb 1, 2025
Trust 75Authoritative
https-nukib-gov-cz-download-publications-en-Annex-20to-20theUpdated

PDF · 844 KB · a long read

MiscGovernment & Policy
NUKIB; Czech National Cyber and Information Security AgencyFeb 1, 2025
Trust 51Needs review
ATIS-Preparing-5G-for-the-Quantum-Era-An-Analysis-of-3GPP-ArUpdated

ATIS analysis of where post-quantum algorithms have to land in 3GPP 5G architecture, and what each insertion point costs.

PDF · 3.8 MB · a reference document — dip in, don’t read it through

MiscIndustry & ResearchHigh
Alliance for Telecommunications Industry Solutions (ATIS)Feb 2025
Trust 77Authoritative
KpqC-SMAUG-TUpdated

SMAUG-T is a post-quantum KEM selected as a South Korean national PQC standard by KpqC in January 2025. Based on Module-LWE and Module-LWR assumptions. The “T” (Twisted) refers to a key derivation tweak improving security margins. Developed by CryptoLab Inc.

PDF · 584 KB · a long read

Research PaperAlgorithm SpecificationsHigh
CryptoLab Inc.; KISA; NIS KoreaJan 31, 2025
Trust 76Authoritative
KpqC-AIMerUpdated

AIMer is a post-quantum signature scheme selected as a South Korean national PQC standard by KpqC in January 2025. Based on the MPC-in-the-head (MPCitH) paradigm using the AIM one-way function. Offers competitive signature sizes without lattice assumptions, providing security diversity.

PDF · 737 KB · a long read

Research PaperAlgorithm SpecificationsHigh
KISA; NIS KoreaJan 31, 2025
Trust 74Authoritative
KpqC-HAETAEUpdated

HAETAE is a lattice-based digital signature scheme selected as a South Korean national PQC standard by KpqC in January 2025. Developed by CryptoLab Inc. Uses a Fiat-Shamir with Aborts variant over module lattices, offering efficient signatures competitive with ML-DSA.

Web page · 169 KB · a long read

MiscAlgorithm SpecificationsHigh
CryptoLab Inc.; KISA; NIS KoreaJan 31, 2025
Trust 74Authoritative
Radboud-MTC-Thesis-2025Updated

Master's thesis from Radboud University providing a practical implementation and performance analysis of Merkle Tree Certificates in TLS 1.3. Evaluates tree construction, proof generation, and handshake overhead with ML-DSA.

PDF · 962 KB · a long read

Research PaperProtocols
M. Pohl (Radboud University)Jan 30, 2025
Trust 48Needs review
IETF RFC 9701Updated

This specification defines a JSON Web Token (JWT) response format for OAuth 2.0 Token Introspection to provide stronger assurance and cryptographic security for token state verification.

Web page · 384 KB · a long read

ReleasedMigration GuidanceReviewed (LLM) · maintainer (automated) · Jul 2026 · via automated, plan-driven remediation (pqctoday-hub-remediation-plans-07082026/library.md, all items P1-P3); facts re-verified against rfc-editor.org, csrc.nist.gov, etsi.org, and live HTTP checks on 2026-07-09; local commit db9d8b2e on fix/hub-remediation-wave2-0708 (branch wave2-library-0708), not yet merged/pushed
IETFJan 30, 2025
Trust 88Authoritative
SNOVA-Round2-Spec

Most aggressive size optimisation in the multivariate family: combines a MAYO-like whipping structure with a noncommutative block-ring structure. SNOVA l=4 at NIST L1: pk=1,016 B, sk=48 B, sig=248 B. Hit hardest by the 2025 wedge attack — most original parameter sets broken, sometimes by a wide margin. Odd-characteristic reparameterisation proposed; resulting Category-1 sizes are smaller than FN-DSA. NIST IR 8528 notes SNOVA has 'not reached a stable form'.

PDF · 506 KB · a long read

ReleasedNIST Standards
SNOVA submission team (Wang, Cheng, et al.)Jan 25, 2025
Trust 75Authoritative
CMMC-Alignment-NIST-StandardsUpdated

DoD crosswalk mapping CMMC practices to their source NIST SP 800-171 / 800-172 requirements.

PDF · 429 KB · a long read

MiscCompliance & Certification
US DoD; DoD CIOJan 21, 2025
Trust 64Needs review
CMMC-SPRS-GuidanceUpdated

DoD guidance on Supplier Performance Risk System (SPRS) scoring in relation to CMMC assessment levels.

PDF · 521 KB · a long read

MiscCompliance & Certification
US DoD; DoD CIOJan 21, 2025
Trust 67Needs review
EO-14144

Biden administration executive order on cybersecurity including PQC provisions. Mandates PQC-ready systems for federal agencies and sets security standards for critical infrastructure.

Web page · 146 KB · a short read

ReleasedGovernment & PolicyCritical
White HouseJan 17, 2025
Trust 57Needs review
CISA-Bad-Practices-PQC-2025Updated

Updated voluntary CISA/FBI guidance for software manufacturers. Bad Practice #7 (Cryptographic Weaknesses) explicitly recommends manufacturers begin supporting standardized PQC algorithms consistent with NIST guidance and avoid deprecated algorithms.

Web page · 89 KB · a short read

MiscGovernment & Policy
CISA; FBIJan 17, 2025
Trust 79Authoritative
KpqC-Competition-ResultsUpdated

Korea selects HAETAE and AIMer (signatures) plus SMAUG-T and NTRU+ (KEMs) as national PQC standards. Target standardization by 2029 migration by 2035.

Web page · 13 KB · a quick skim

MiscAlgorithm SpecificationsHighReviewed (LLM) · maintainer (automated) · Jul 2026 · via automated, plan-driven backfill (pqctoday-hub-remediation-plans-07082026/revisions.md item 2, WS-C); source PR #408 already human-merged (eramusa) 2026-07-08
KISA; Ministry of Science and ICT; NIS KoreaJan 16, 2025
Trust 76Authoritative
RFC 9708Updated

Updated HSS/LMS usage in CMS. Obsoletes RFC 8708.

Web page · 86 KB · a short read

ReleasedProtocols
IETF LAMPSJan 2025
Trust 81Authoritative
EU-NIS-CG-Roadmap-v1.1Updated

EU NIS Cooperation Group coordinated roadmap v1.1 for PQC transition across EU member states. Provides harmonized timelines, priority sectors, and cross-border coordination mechanisms.

PDF · 553 KB · a long read

ReleasedInternational FrameworksHigh1 rev
EU NIS Cooperation Group; European Commission; ENISA2025
Trust 51Needs review
IN-CERTIN-QBOM-Guidelines-2025

India CERT-In v2.0 guidelines on software, quantum, cryptographic, AI, and hardware bills of materials. Includes CBOM and QBOM specifications for cryptographic inventory and quantum-readiness assessment of Indian organizations.

PDF · 1.7 MB · a reference document — dip in, don’t read it through

ReleasedGovernment & PolicyHigh
CERT-In; Indian Computer Emergency Response Team2025
Trust 64Needs review
Europol-QSFF-Call-to-Action-2025Updated

Europol Quantum Safe Financial Forum call to action for European financial institutions to begin immediate PQC migration planning. Addresses harvest-now-decrypt-later threats to financial data and recommends coordinated sector response.

Web page · 98 KB · a short read

MiscGovernment & PolicyHigh
Europol; Quantum Safe Financial Forum2025
Trust 69Needs review
IN-TEC-PQC-Migration-Report-2025Updated

Telecommunications Engineering Centre (TEC) India technical report on migrating to post-quantum cryptography. Covers algorithm selection (ML-KEM, ML-DSA, SLH-DSA), hybrid approaches, protocol migration for Indian telecom, and implementation guidance for operators.

PDF · 1.8 MB · a reference document — dip in, don’t read it through

ReleasedGovernment & PolicyHigh1 rev
TEC India; Telecommunications Engineering Centre; Department of TelecommunicationsJan 2025
Trust 68Needs review
ETSI-TR-103-967

Updated analysis of quantum computing impact specifically on symmetric cryptography including block ciphers, stream ciphers, hash functions, and MACs. Successor to GR QSC 006.

PDF · 350 KB · a short read

ReleasedInternational FrameworksHigh
ETSI TC CYBER WG QSCJan 2025
Trust 83Authoritative
JPMorgan-RWPQC-2025Updated

JPMorgan Chase presentation at Real World PQC 2025 conference on financial sector PQC migration challenges and strategies.

PDF · 2.3 MB · a reference document — dip in, don’t read it through

MiscIndustry & ResearchCritical
JPMorgan Chase2025
Trust 64Needs review
NTNU-PQC-Challenges-SildeUpdated

Presentation by Tjerand Silde (NTNU / PONE Biometrics) on quantum-safe cryptography challenges including FIDO, secure authentication, and SNDL threats.

PDF · 6.0 MB · a reference document — dip in, don’t read it through

MiscIndustry & Research
Tjerand Silde (NTNU; PONE Biometrics)2025
Trust 49Needs review
PROACT-2025-SCA-Lattice-PQCUpdated

PROACT 2025 slides on side-channel and fault-injection attacks on ML-KEM and ML-DSA lattice implementations. Demonstrates single-trace key recovery on unmasked implementations and effectiveness against masked and shuffled countermeasures.

PDF · 5.6 MB · a reference document — dip in, don’t read it through

MiscIndustry & ResearchHigh
PROACT School; Radboud University2025
Trust 46Needs review
EmergentMind-Nonce-Reuse-CryptoUpdated

Overview of nonce reuse vulnerabilities in cryptographic protocols. Weak PRNGs and protocol misconfigurations cause repeated nonces enabling key recovery and forgery attacks across PQC and classical schemes.

Web page · 224 KB · a long read

MiscMigration GuidanceHigh
EmergentMind2025
Trust 51Needs review
Invicti-OWASP-CryptoFailures-2025Updated

Analysis of cryptographic failures in the OWASP Top 10. Real-world vulnerabilities from misconfigurations, weak key management, and insecure protocol usage rather than algorithmic weaknesses.

Web page · 139 KB · a short read

MiscIndustry & ResearchHigh
Invicti Security2025
Trust 63Needs review
ref-fukuda-grand-challengeUpdated

Analysis of technical and economic challenges in migrating modern blockchains to Post-Quantum Cryptography.

PDF · 395 KB · a short read

Research PaperIndustry & Research
Kigen Fukuda; Shin'ichiro Matsuo; Yuji Suga; Tadahiko Ito2025
Trust 52Needs review
ref-habovstiak-hashed-keysUpdated

Argues that pay-to-pubkey-hash outputs can remain quantum secure despite mempool exposure, provided spending after reveal is restricted to a quantum-resistant signature scheme.

Web page · 8 KB · a quick skim

MiscIndustry & Research
M. Habov stiak2025
Trust 52Needs review
ref-drake-hash-multisigUpdated

Introduction of hash-based non-interactive multi-signature schemes based on XMSS variants for Ethereum’s proof-of-stake consensus.

Web page · 18 KB · a quick skim

Research PaperIndustry & Research
J. Drake et al.2025
Trust 54Needs review
US-TREASURY-FSRMP-2025Updated

US Treasury sector risk management plan for financial services covering quantum computing as an emerging technology risk. Identifies PQC migration as a priority resilience initiative and outlines coordinated government-industry response.

PDF · 3.1 MB · a reference document — dip in, don’t read it through

MiscGovernment & PolicyHigh
US Department of the Treasury2025
Trust 61Needs review
Swift-Customer-Security-Controls-Framework-CSCF-v2026Updated

The mandatory security controls every Swift-connected institution attests to annually, including its cryptographic requirements.

PDF · 4.6 MB · a reference document — dip in, don’t read it through

ReleasedCompliance & CertificationHigh1 rev
SWIFT2025
Trust 58Needs review
Brilliant-at-the-Basics-ITUpdated

DoD CIO streamlined top-10 IT cybersecurity practices campaign for small/mid-sized Defense Industrial Base partners, companion to the CMMC/DFARS compliance track.

PDF · 1.6 MB · a reference document — dip in, don’t read it through

MiscMigration Guidance
US DoD; DoD CIO2025
Trust 64Needs review
Cyentia IRIS 2025

Longitudinal study of cyber-incident frequency, likelihood and loss. Figure 6 gives the annual probability that a typical firm suffers a significant incident (2.5% in 2008 rising to 9.3% in 2024); Figure 7 splits that by revenue tier. Source of the organization-size breach-probability defaults in the Breach Scenario Simulator, ROI Calculator and Cost of Inaction Analyzer.

PDF · 2.6 MB · a reference document — dip in, don’t read it through

ReleasedIndustry & ResearchReviewed · claude-opus-5 (session review, 2026-08-11) · Aug 2026 · via primary-document retrieval + manual data edit
Cyentia Institute2025
Trust 44Needs review
QuSecure-Launches-QuProtect-R3-Simplifying-Encryption-ModernUpdated

Web page · 88 KB · a short read

MiscMigration Guidance
Unknown2025
Trust 26Needs review
IEEE-Standard-for-Wireless-Access-in-Vehicular-Environments

ReleasedMigration Guidance
IEEE Standards Association2025
Trust 9Needs review
Purchase required
Secondary-Signature-AlgorithmsUpdated

Web page · 42 KB · a short read

DraftMigration Guidance
Ethereum Improvement Proposals2025
Trust 26Needs review
November-11-2025-KB5068861-OS-Build-26100-7171Updated

Web page · 163 KB · a long read

MiscMigration Guidance
Unknown2025
Trust 26Needs review
Amazon-CloudFront-launches-TLS-security-policy-with-post-quaUpdated

Web page · 323 KB · a long read

MiscProtocols
Amazon Web Services, Inc.2025
Trust 26Needs review
AWS-KMS-adds-support-for-post-quantum-ML-DSA-digital-signatuUpdated

Web page · 323 KB · a long read

MiscMigration Guidance
Amazon Web Services, Inc.2025
Trust 26Needs review
Announcing-NET-10Updated

Web page · 337 KB · a long read

MiscMigration Guidance
.NET Blog2025
Trust 26Needs review
2025-Cost-of-a-Data-Breach-Report-Navigating-the-AI-rush-witUpdated

Web page · 172 KB · a long read

MiscMigration Guidance
Unknown2025
Trust 26Needs review
Commission-Implementing-Regulation-EU-2025-2162-of-27-OctobeUpdated

PDF · 665 KB · a long read

ReleasedMigration Guidance
Unknown2025
Trust 26Needs review
What-is-Azure-Dedicated-HSMUpdated

Web page · 56 KB · a short read

MiscMigration Guidance
MicrosoftLearn2025
Trust 26Needs review
CID-EU-2025-138-EN-18031Updated

Commission Implementing Decision that publishes EN 18031-1, -2 and -3:2024 in the Official Journal as harmonised standards under the Radio Equipment Directive, with notices that withhold presumption of conformity in specific cases (e.g. where the user may opt not to set a password). Not PQC-specific; it determines which cybersecurity standard EU IoT radio products are assessed against, including its cryptography clauses.

Web page · 279 KB · a long read

ReleasedCompliance & Certification
European Commission2025
Trust 36Needs review
NIST-SP-1800-36BUpdated

NIST NCCoE practice guide volume (SP 1800-36B, Nov 2025, final) describing the approach, architecture and security characteristics of example builds for trusted network-layer onboarding and lifecycle management of IP-based IoT devices (Wi-Fi Easy Connect/DPP, BRSKI per RFC 8995, Thread, EST). Documents IEEE 802.1AR-2018 device identity in onboarding: for BRSKI the birth credential is an 802.1AR certificate installed as the device's IDevID (carrying the MASA location and voucher trust anchors), with an LDevID issued during network-layer onboarding.

PDF · 3.6 MB · a reference document — dip in, don’t read it through

ReleasedNIST Standards
NIST NCCoE (with MITRE, CableLabs, Cisco, Aruba/HPE, NXP, SEALSQ, Silicon Labs, Kudelski IoT, Foundries.io, NquiringMinds, Sandelman Software Works)2025
Trust 50Needs review
IACR-ePrint-2025-075Updated

Web page · 18 KB · a quick skim

Research PaperMigration Guidance
IACR Cryptology ePrint Archive2025
Trust 26Needs review
RFC-9679Updated

This specification defines a method for computing a hash value over a CBOR Object Signing and Encryption (COSE) Key. It specifies which fields within the COSE Key structure are included in the cryptographic hash computation, the process for creating a canonical representation of these fields, and how to hash the resulting byte sequence. The resulting hash value, referred to as a "thumbprint", ca

Web page · 332 KB · a long read

ReleasedProtocols
IETFDec 20, 2024
Trust 77Authoritative
Ethereum-PQC-Tasklist-Ethresearch

Ethereum Foundation research post outlining the full roadmap to post-quantum Ethereum. Covers STARK-based and lattice-based signature replacement for ECDSA and BLS12-381, and describes the emergency quantum fork path for an unplanned Q-Day.

Web page · 467 KB · a long read

DraftProtocolsHigh
Ethereum Foundation PQC Research TeamDec 19, 2024
Trust 48Needs review
Bitcoin-BIP360-P2QRHUpdated

Proposes a new Bitcoin output type (SegWit v3, bc1r...) using post-quantum signatures via a soft fork. Removes the quantum-vulnerable key-spend path from Taproot. Exact PQC algorithms to be standardized in a companion BIP; ML-DSA and FALCON-512 are leading candidates under community discussion. Authored by Hunter Beast to address the HNFL risk to Bitcoin public keys.

Web page · 476 KB · a long read

DraftProtocolsHigh
Hunter Beast; Bitcoin Core CommunityDec 18, 2024
Trust 62Needs review
CIR-EU-2024-3144-EUCC-AmendmentUpdated

Commission Implementing Regulation (EU) 2024/3144 of 18 December 2024, amending the EUCC scheme regulation (EU) 2024/482 on applicable international standards and correcting it.

Web page · 74 KB · a short read

ReleasedCompliance & Certification
European CommissionDec 18, 2024
Trust 34Needs review
Deloitte-TechTrends-2025-QuantumUpdated

Deloitte analyst brief arguing CPM investment is defensible on operational and regulatory grounds independent of quantum-arrival timing.

Web page · 332 KB · a long read

MiscMigration Guidance
Deloitte InsightsDec 11, 2024
Trust 48Needs review
ENISA-State-of-Cybersecurity-2024Updated

First biennial NIS2-mandated cybersecurity report for the EU; identifies PQC as a top emerging technology topic and warns most European stakeholders remain underprepared for the quantum transition.

PDF · 10.6 MB · a reference document — dip in, don’t read it through

MiscGovernment & Policy
ENISADec 3, 2024
Trust 57Needs review
AU-ASD-ISM-Crypto-2024

Australian Signals Directorate (ASD) ISM cryptography guidelines update (December 2024). Mandates transition to NIST-standardized PQC algorithms for Australian government systems, sets migration timelines, and provides algorithm selection guidance.

PDF · 1.2 MB · a long read

ReleasedGovernment & PolicyHighReviewed (LLM) · eramusa · May 2026 · via local commit
ASD; Australian Signals Directorate; ACSCDec 2024
Trust 66Needs review
NL-PQC-Migration-Handbook-2024Updated

The PQC Migration Handbook (2nd ed., December 2024) by AIVD, CWI and TNO — Diagnosis/Planning/Execution migration guidance, 'no-regret moves', crypto-agility, a detailed PQC-method overview, and international legislation. Named in the Applied Quantum framework's Appendix G crosswalk. 117 pages.

PDF · 2.3 MB · a reference document — dip in, don’t read it through

MiscMigration GuidanceHigh
AIVD; CWI; TNODec 2024
Trust 55Needs review
UEFI-SPEC-2.10-SecureBootUpdated

Defines UEFI Secure Boot: authenticating firmware images via EFI_CERT_X509 entries in the Secure Boot database (db). Specifies key enrollment, dbx revocation, and signature verification using PKCS#7 SignedData at boot time. Relevant to PQC migration as RSA/ECDSA signing keys must be replaced with ML-DSA or SLH-DSA.

PDF · 16.7 MB · a reference document — dip in, don’t read it through

ReleasedImplementationsHigh
UEFI ForumNov 21, 2024
Trust 64Needs review
FCC-24-123-ET-Docket-19-138Updated

Web page · 269 KB · a long read

ReleasedMigration Guidance
Federal Communications CommissionNov 20, 2024
Trust 26Needs review
NIST IR 8547Updated

Roadmap for transitioning from classical to post-quantum cryptography. The only published draft is the Initial Public Draft of 2024-11-12 (comment period closed 2025-01-10; final version pending). It retains the 2030 deprecation and 2035 disallowment targets.

PDF · 722 KB · a long read

DraftNIST StandardsHigh1 rev
NISTNov 12, 2024
Trust 79Authoritative
IACR-2024-1828-McEliece-SCA-FaultUpdated

IACR ePrint paper summarizing side-channel and fault-injection attacks targeting Classic McEliece including additive FFT and Gaussian elimination. Proposes a hardened FPGA/ASIC hardware design mitigating both attack classes.

PDF · 938 KB · a long read

Research PaperIndustry & Research
IACR ePrintNov 7, 2024
Trust 63Needs review
EU-BSI-PQC-Joint-Statement-2024Updated

Joint statement by 21 European nation cybersecurity agencies (including BSI, ANSSI, NCSC-NL) urging coordinated EU PQC migration. Endorses NIST-standardized algorithms and sets common migration principles for European organizations.

PDF · 822 KB · a long read

MiscGovernment & PolicyHighReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (LM-068 regional remediation)
BSI; ANSSI; NCSC Netherlands; 21 EU cybersecurity agenciesNov 1, 2024
Trust 75Authoritative
BSI-BSZ-METHODUpdated

BSI Beschleunigte Sicherheitszertifizierung — German accelerated security-certification scheme, implementing EN 17640 Fixed-time Cybersecurity Evaluation Methodology (FiT CEM).

PDF · 533 KB · a long read

ReleasedCompliance & Certification
BSINov 1, 2024
Trust 86Authoritative
CCN-STIC-221-Spain-Guia-de-Mecanismos-Criptograficos-autoriz

Spain’s CCN list of cryptographic mechanisms authorised for classified and public-sector systems.

PDF · 2.2 MB · a reference document — dip in, don’t read it through

ReleasedInternational Frameworks
CCN (Centro Criptológico Nacional)Nov 2024
Trust 81Authoritative
NIST-IR-8528Updated

Documents evaluation criteria and selection of 14 second-round candidates (CROSS, FAEST, HAWK, LESS, MAYO, Mirath, MQOM, PERK, QR-UOV, RYDE, SDitH, SNOVA, SQIsign, UOV) from 40 first-round submissions in NIST's additional PQC digital signature call.

Web page · 50 KB · a short read

ReleasedDigital Signature
NISTOct 24, 2024
Trust 80Authoritative
FAEST-Round2-Spec

AES-based MPC-in-the-Head signature using the VOLE-in-the-Head paradigm. Security reduces directly to AES — the most-studied symmetric cipher in existence — making FAEST the most conservative foundation among the MPCitH candidates. Smallest public and private keys in the contest (32 B each); signatures are kilobytes (FAEST-128f: 6,336 B). NIST selected it explicitly for the strength of its symmetric-primitive trust argument.

PDF · 1.2 MB · a long read

ReleasedNIST Standards
FAEST submission team (Baum, Beck, Becker, Ciampi, Faller, Lipmaa, Orsini, Roy, et al.)Oct 24, 2024
Trust 74Authoritative
MAYO-Round2-Spec

UOV variant that uses a 'whipping' algorithm to expand a small seed key into a full UOV instance — drastically reducing the public-key bloat that plagues raw UOV. MAYO-1 at NIST L1: pk=1,168 B, sk=24 B, sig=321 B. MAYO-2 lost ~30 bits to the 2025 wedge attack at Category 1; reparameterisation in progress and expected to recover.

PDF · 626 KB · a long read

ReleasedNIST Standards
MAYO submission team (Beullens, et al.)Oct 24, 2024
Trust 75Authoritative
QR-UOV-Round2-Spec

UOV variant in odd-characteristic fields using quotient-ring mathematics to reduce the public-key representation size. The only multivariate candidate that emerged from the 2025 Ran wedge attack unscathed — its use of odd-characteristic fields makes it immune to the original exterior-product exploit, and subsequent extensions to odd characteristics did not reduce security below existing attack complexities.

PDF · 622 KB · a long read

ReleasedNIST Standards
QR-UOV submission team (Furue, Ikematsu, Hashimoto, Sakurai, Takagi, et al.)Oct 24, 2024
Trust 75Authoritative
SQIsign-Round2-Spec

Isogeny-based signature scheme — the only post-quantum candidate built on supersingular elliptic-curve isogenies. Smallest combined public-key+signature of any PQC candidate by a wide margin: SQIsign-I (NIST L1) is pk=64 B, sig=177 B (up from 148 B in Round 1, traded for a 20× signing speedup). Round 2 redesign switched to higher-dimensional isogenies, simplifying the security analysis and dramatically improving performance. SQIsign avoids the auxiliary-torsion structure that enabled the 2022 SIKE break.

PDF · 1.2 MB · a long read

ReleasedNIST Standards
SQIsign submission team (De Feo, Kohel, Leroux, Petit, Wesolowski, Basso, et al.)Oct 24, 2024
Trust 75Authoritative
EU-CRA-REG-2024-2847Updated

EU regulation imposing mandatory cybersecurity requirements on hardware and software products with digital elements. Annex I requires cryptographic best practices; PQC migration relevant for product lifecycle compliance.

PDF · 1.8 MB · a reference document — dip in, don’t read it through

ReleasedCompliance & CertificationHigh
European Parliament; Council of the EUOct 23, 2024
Trust 65Needs review
GSMA PQ.03 PQC GuidelinesUpdated

Guidance for integrating PQC into TLS, IKE, and 5G infrastructure.

PDF · 3.3 MB · a reference document — dip in, don’t read it through

ReleasedProtocolsHigh2 revs
GSMAOct 2024
Trust 68Needs review
NIST-SP-800-131A-Rev3Updated

Algorithm deprecation roadmap: SHA-1 and RSA/ECC <128-bit disallowed after 2030. Establishes federal algorithm retirement calendar aligned with PQC transition. References FIPS 203/204/205 as post-2030 replacements.

PDF · 928 KB · a long read

DraftNIST StandardsHigh
NISTOct 2024
Trust 92Authoritative
US-CISA-PQC-OT-2024Updated

CISA guidance on PQC considerations specific to operational technology (OT) environments. Addresses unique migration challenges in ICS/SCADA systems including constrained devices, legacy protocols, and long operational lifetimes.

PDF · 1.4 MB · a long read

MiscGovernment & PolicyHigh
CISA; Cybersecurity and Infrastructure Security AgencyOct 2024
Trust 76Authoritative
ETSI-TR-103-965

Examines how quantum computing affects the validity of existing cryptographic security proofs. Analyzes whether classical reduction-based proofs remain meaningful in a post-quantum setting.

PDF · 255 KB · a short read

ReleasedInternational FrameworksHigh
ETSI TC CYBER WG QSCOct 2024
Trust 82Authoritative
ETSI-TR-103-966

Provides practical guidance on deploying hybrid classical-plus-PQC schemes. Addresses implementation considerations, key combiner design, protocol integration, and performance tradeoffs.

PDF · 233 KB · a short read

ReleasedInternational FrameworksHigh
ETSI TC CYBER WG QSCOct 2024
Trust 83Authoritative
ETSI-TR-104-016

Provides a structured, repeatable framework for organizations planning quantum-safe cryptographic migrations. Covers discovery, assessment, planning, execution, and validation phases.

PDF · 506 KB · a long read

ReleasedInternational FrameworksHigh
ETSI TC CYBER WG QSCOct 2024
Trust 88Authoritative
ref-pont-downtimeUpdated

Analysis of the cumulative downtime required to upgrade the Bitcoin network from ECDSA to post-quantum cryptosystems to prevent quantum attacks.

Web page · 41 KB · a short read

Research PaperIndustry & Research
Jamie J. Pont; Joseph J. Kearney; Jack Moyler; Carlos A. Perez-DelgadoOct 2024
Trust 55Needs review
DigiCert-PQC-Maturity-ModelUpdated

DigiCert 5-level PQC maturity model mapped to organizational readiness; companion to CPM maturity frameworks.

PDF · 1.7 MB · a reference document — dip in, don’t read it through

MiscMigration Guidance
DigiCertOct 1, 2024
Trust 52Needs review
DIB-CSaaS-SlicksheetUpdated

DC3/DCISE overview of the free Defense Industrial Base Cybersecurity as a Service program for DIB partners.

PDF · 226 KB · a short read

MiscMigration Guidance
US DoD; DC3/DCISESep 27, 2024
Trust 60Needs review
BSI-AIS-20-31Updated

BSI (Germany) standard defining functionality classes DRG.1–DRG.4 for deterministic RNGs and PTG.1–PTG.3 for physical/true RNGs. AIS 31 compliance is required for Common Criteria RNG evaluations and is cited by QRNG hardware certifications including ID Quantique Quantis.

PDF · 6.1 MB · a reference document — dip in, don’t read it through

ReleasedAlgorithm Specifications
BSISep 10, 2024
Trust 77Authoritative
ETSI-EN-303645Updated

European baseline security requirements for consumer-IoT devices — crypto, default passwords, update integrity.

PDF · 976 KB · a long read

ReleasedCompliance & Certification
ETSISep 2024
Trust 88Authoritative
CMMC-2.0-MODEL

DoD CMMC v2.13 three-level maturity framework (Foundational/Advanced/Expert) based on NIST SP 800-171 and 800-172. Required for defense contractors handling CUI. Cryptographic controls span key management, PKI, and access control.

PDF · 977 KB · a long read

ReleasedCompliance & CertificationHigh
US DoD; DoD CIOSep 2024
Trust 66Needs review
CMMC-L1-Scoping-Guide

DoD CMMC Level 1 (Foundational) scoping guidance defining assessment boundary for FCI-handling systems.

PDF · 589 KB · a long read

ReleasedCompliance & CertificationHigh
US DoD; DoD CIOSep 2024
Trust 64Needs review
CMMC-L1-Assessment-Guide

DoD CMMC Level 1 self-assessment methodology and 15 basic safeguarding requirements (FAR 52.204-21 aligned).

PDF · 820 KB · a long read

ReleasedCompliance & CertificationHigh
US DoD; DoD CIOSep 2024
Trust 64Needs review
CMMC-L2-Scoping-Guide

DoD CMMC Level 2 (Advanced) scoping guidance defining assessment boundary for CUI-handling systems, NIST SP 800-171 aligned.

PDF · 700 KB · a long read

ReleasedCompliance & CertificationHigh
US DoD; DoD CIOSep 2024
Trust 64Needs review
CMMC-L2-Assessment-Guide

DoD CMMC Level 2 assessment methodology against the 110 NIST SP 800-171 security requirements.

PDF · 2.3 MB · a reference document — dip in, don’t read it through

ReleasedCompliance & CertificationHigh
US DoD; DoD CIOSep 2024
Trust 65Needs review
ref-google-willow-below-thresholdUpdated

Demonstration of below-threshold quantum error correction performance using surface codes on superconducting processors.

PDF · 3.8 MB · a reference document — dip in, don’t read it through

Research PaperIndustry & Research
Google Quantum AIAug 24, 2024
Trust 44Needs review
US-CISA-ACDI-Strategy-2024Updated

CISA strategy outlining approach for US organizations to adopt automated tools for PQC cryptographic discovery and inventory. Provides methodology for identifying all classical cryptography in use and building migration roadmaps.

PDF · 538 KB · a long read

MiscGovernment & PolicyHigh
CISA; Cybersecurity and Infrastructure Security AgencyAug 15, 2024
Trust 79Authoritative
UK-NCSC-PQC-Whitepaper-2024Updated

UK NCSC white paper providing updated guidance on PQC migration preparation. Covers algorithm selection, hybrid PQC, migration prioritization framework, and UK-specific timelines. Updates 2023 guidance and aligns with NIST finalized standards.

PDF · 134 KB · a short read

MiscGovernment & PolicyHigh
NCSC UK; UK National Cyber Security CentreAug 14, 2024
Trust 78Authoritative
FIPS 203Updated

Specifies ML-KEM (Kyber) with three parameter sets (512, 768, 1024) for quantum-resistant key establishment. Errata Oct 2024.

PDF · 1.3 MB · a long read

ReleasedKEMHighReviewed (LLM) · eramusa · May 2026 · via local commit
NISTAug 13, 2024
Trust 87Authoritative
FIPS 204Updated

Specifies ML-DSA (Dilithium) signature algorithms with three parameter sets (44, 65, 87). Errata Oct 2024.

PDF · 3.3 MB · a reference document — dip in, don’t read it through

ReleasedDigital SignatureHighReviewed (LLM) · eramusa · May 2026 · via local commit
NISTAug 13, 2024
Trust 87Authoritative
FIPS 205Updated

Specifies SLH-DSA (SPHINCS+) stateless hash-based signatures with 12 parameter sets. The stateless alternative to LMS/XMSS — no state management required, but larger signatures.

PDF · 1.1 MB · a long read

ReleasedDigital SignatureReviewed (LLM) · eramusa · May 2026 · via local commit
NISTAug 13, 2024
Trust 87Authoritative
IBM-Quantum-Safe-ResearchUpdated

IBM Research contributions to NIST PQC standards including co-invention of CRYSTALS-Kyber (ML-KEM) and CRYSTALS-Dilithium (ML-DSA).

Web page · 87 KB · a short read

MiscIndustry & ResearchHigh
IBM ResearchAug 13, 2024
Trust 80Authoritative
ref-aardal-falcon-labradorUpdated

A rigorous proof and adaptation of the LaBRADOR proof system to aggregate Falcon signatures, introducing predicate special soundness for knowledge soundness analysis.

PDF · 1.3 MB · a long read

Research PaperIndustry & Research
Marius A. Aardal; Diego F. Aranha; Katharina Boudgoust; Sebastian Kolby; Akira TakahashiAug 9, 2024
Trust 51Needs review
RFC 9629Updated

Defines CMS KEMRecipientInfo structure for PQ KEMs including ML-KEM.

Web page · 87 KB · a short read

ReleasedProtocolsHigh
IETF LAMPSAug 2024
Trust 81Authoritative
ENISA-Crypto-Market-Analysis-2024Updated

ENISA market analysis of EU cryptographic products and services, highlighting PQC readiness gaps across European stakeholders and Cryptography-as-a-Service market trends.

PDF · 3.6 MB · a reference document — dip in, don’t read it through

MiscInternational Frameworks
ENISAAug 2024
Trust 57Needs review
USENIX-2024-HQC-Division-TimingUpdated

USENIX Security 2024 paper demonstrating timing side-channel attacks on HQC. Compiler-emitted variable-time division instructions leak secret data; constructs a Plaintext-Checking oracle to recover HQC secret keys.

PDF · 672 KB · a long read

Research PaperIndustry & Research
Robin Leander Schröder; Stefan Gast; Qian Guo; USENIX SecurityAug 1, 2024
Trust 80Authoritative
RFC 9581

Adds persistent symmetric (KDF / KEK-style) key packets to OpenPGP for hybrid encryption modes.

Web page · 23 KB · a quick skim

ReleasedProtocols
IETF OPENPGP WGAug 2024
Trust 81Authoritative
WH-PQC-Report-2024

White House report estimating $7.1B government-wide PQC migration cost. Provides status of agency inventories, migration planning, and budget projections through 2035.

PDF · 1.2 MB · a long read

ReleasedGovernment & PolicyCritical
White House; ONCDJul 2024
Trust 66Needs review
RFC 9580Updated

Specifies OpenPGP message formats for encryption, digital signatures, compression, and key management with modern cryptographic practices; prepares ecosystem for PQC signature integration.

Web page · 878 KB · a long read

ReleasedProtocolsHigh1 rev
Paul Wouters; Daniel Huigens; Justus Winter; Niibe YutakaJul 2024
Trust 63Needs review
RFC 9593Updated

Introduces a mechanism for IKEv2 peers to announce supported authentication methods, enabling negotiation of PQC signature algorithms for hybrid key exchange.

Web page · 82 KB · a short read

ReleasedProtocols
Valery SmyslovJul 2024
Trust 64Needs review
UIC-FRMCS-T-v1-0-Future-Railway-Mobile-Communication-System

The UIC technical specification for the Future Railway Mobile Communication System.

PDF · 700 KB · a long read

ReleasedProtocols
UIC (International Union of Railways)Jul 2024
Trust 56Needs review
NIST-SP-800-78-5-Cryptographic-Algorithms-and-Key-Sizes-for

Specifies the algorithms and key sizes permitted for US federal PIV credentials — the gate any PQC identity credential has to pass.

PDF · 694 KB · a long read

ReleasedProtocols
NISTJul 2024
Trust 62Needs review
ISO/IEC 14888-4:2024

Standardizes XMSS and LMS stateful hash-based signatures at ISO level.

Web page · 88 KB · a short read

ReleasedDigital Signature
ISO/IEC JTC 1/SC 27Jun 2024
Trust 81Authoritative
Singapore-CSA-Quantum-Safe-HandbookUpdated

Singapore guidance for organizations preparing for PQC transition.

PDF · 1.7 MB · a reference document — dip in, don’t read it through

ReleasedGovernment & Policy1 rev
CSA SingaporeJun 1, 2024
Trust 74Authoritative
NATO-Quantum-Strategy-2024

NATO's first Quantum Technologies Strategy establishing quantum-safe cryptography as a priority for Alliance cybersecurity. Commits NATO and member nations to post-quantum migration of classified communications and critical military systems.

Web page · 314 KB · a long read

ReleasedGovernment & PolicyCritical
NATO; North Atlantic Treaty OrganizationJun 1, 2024
Trust 62Needs review
eIDAS-2-RegulationUpdated

EU regulation establishing the European Digital Identity framework mandating EUDI Wallets for all member states by late 2026. Requires private sector acceptance by late 2027. Introduces Qualified Electronic Attestations of Attributes (QEAA) and specifies the trust framework for digital identity across EU. Supersedes eIDAS 1.0.

Web page · 836 KB · a long read

ReleasedInternational FrameworksHigh
European Parliament; Council of the European UnionMay 30, 2024
Trust 59Needs review
Ethereum-EIP7702Updated

Allows EOAs to set executable code via signed authorisation tuples (Pectra hard fork). Provides a bridge for PQC migration: a delegated smart contract can verify ML-DSA or FALCON signatures on behalf of the EOA, enabling quantum-safe signing without full account migration. Note: EIP-7702 authorisation tuples are themselves signed with secp256k1; quantum resistance is provided by the delegated contract's verification logic.

Web page · 58 KB · a short read

ReleasedIndustry & ResearchHigh
Vitalik Buterin; Sam Wilson; Ansgar Dietrichs; Ethereum FoundationMay 7, 2024
Trust 46Needs review
NIST-SP-800-171-Rev-3-Protecting-Controlled-Unclassified-Inf

The controls US contractors must apply to controlled unclassified information, including its cryptographic requirements.

PDF · 1.6 MB · a reference document — dip in, don’t read it through

ReleasedProtocols
NISTMay 2024
Trust 61Needs review
NIST-SP-800-171Ar3Updated

NIST assessment procedures for the security requirements in NIST SP 800-171 Rev. 3, used to verify CMMC Level 2 compliance.

PDF · 1.2 MB · a long read

ReleasedNIST StandardsHigh
NISTMay 2024
Trust 67Needs review
Sigstore-Algorithm-RegistryUpdated

Normative registry of signing algorithms Sigstore clients and services must support. Names the ECDSA (ecdsa-sha2-256-nistp256, P-384, P-521), RSA-PKCS1/PSS and Ed25519 variants, and the ML-DSA-44/65/87 pure variants being integrated. Cited as the proof that Sigstore-based software supply-chain signing uses ECDSA today and ML-DSA as its post-quantum replacement.

Web page · 5 KB · a quick skim

MiscIndustry & ResearchHigh
Sigstore project (OpenSSF)May 1, 2024
Trust 51Needs review
EU PQC Recommendation

EU-wide coordination framework for member state PQC transitions. Target 2030 for critical systems.

PDF · 110 KB · a short read

ReleasedMigration GuidanceHigh
European CommissionApr 2024
Trust 64Needs review
EC-Recommendation-2024-1101Updated

European Commission formal Recommendation calling on EU member states to implement PQC migration roadmaps and coordinated timelines by 2030. Sets interoperability and procurement requirements for EU digital infrastructure.

PDF · 483 KB · a long read

ReleasedGovernment & PolicyHigh1 rev
European CommissionApr 2024
Trust 57Needs review
BSI-ANSSI-QKD-Position-2024Updated

Joint position paper from BSI, ANSSI, NLNCSA, and SNCSA on quantum key distribution (QKD). Concludes QKD alone is insufficient for government communications and recommends PQC as primary quantum-safe approach, with QKD as complementary where justified.

PDF · 476 KB · a long read

MiscGovernment & Policy
BSI; ANSSI; NLNCSA Netherlands; SNCSA SwedenApr 1, 2024
Trust 76Authoritative
RFC 9528Updated

Lightweight authenticated key-establishment protocol for constrained IoT devices. Provides mutual authentication and forward secrecy in 3 messages over COSE; intended as the security handshake under OSCORE.

Web page · 1.8 MB · a long read

ReleasedProtocols
IETF LAKE WG (Selander, Mattsson, Palombini)Mar 20, 2024
Trust 89Authoritative
arXiv-2403-11741Updated

Academic survey on PQC covering lattice-based, code-based, multivariate, and hash-based schemes with analysis of quantum threats to classical cryptography.

PDF · 955 KB · a long read

Research PaperIndustry & Research
Dr. G S Mamatha; Rasha Sinha (R.V. College of Engineering)Mar 18, 2024
Trust 70Authoritative
China GB/T 43692-2024Updated

Chinese national recommended standard (GB/T) defining quantum-communication terms and definitions, including QKD. In force 2024-10-01. It is a terminology standard for quantum communication, not a post-quantum cryptography standard.

Web page · 24 KB · a quick skim

ReleasedIndustry & ResearchHighReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (LM-068 regional remediation)
SAMR / Standardization Administration of China (GB/T national standard)Mar 15, 2024
Trust 61Needs review
US-FCC-24-26-Cyber-Trust-MarkUpdated

FCC Report and Order establishing the voluntary U.S. Cyber Trust Mark labeling program for consumer wireless IoT products, with accredited-lab testing, Cybersecurity Label Administrators, a QR-code registry and NISTIR 8425 baseline criteria. Not PQC-specific; it is the US conformity scheme through which future IoT cryptographic expectations (including PQC) could be applied to consumer devices.

PDF · 647 KB · a long read

ReleasedCompliance & Certification
Federal Communications Commission (FCC)Mar 15, 2024
Trust 38Needs review
CCDB-014-Assurance-Continuity-v3-1Updated

CCRA requirements for assurance continuity (maintaining or re-evaluating certificates after product changes), version 3.1, issued 29 February 2024.

PDF · 325 KB · a short read

ReleasedCompliance & Certification
CCRA Development Board (CCDB)Feb 29, 2024
Trust 34Needs review
NIST-CSF-2.0Updated

NIST Cybersecurity Framework 2.0 (CSWP 29) — the six functions (Govern, Identify, Protect, Detect, Respond, Recover) and their subcategories. The anchor framework for the Applied Quantum PQC Migration Framework's Appendix G crosswalk (phase ↔ CSF function/subcategory). Foundational cyber risk-management framework.

PDF · 1.5 MB · a reference document — dip in, don’t read it through

ReleasedGovernment & Policy
NISTFeb 26, 2024
Trust 87Authoritative
NIST IR 8477Updated

NIST IR 8477 defines the NIST methodology for creating typed concept mappings (subset_of, superset_of, equivalent, intersects_with) between any cybersecurity or privacy documentary standards, submitted via the NIST OLIR process and hosted in CPRT. SP 800-218 (SSDF) is the primary worked example in §3. No PQC content.

PDF · 912 KB · a long read

ReleasedNIST Standards
NISTFeb 23, 2024
Trust 77Authoritative
Apple-PQ3-Security-BlogUpdated

Apple's technical whitepaper describing PQ3, the post-quantum protocol upgrade for iMessage. Achieves Level 3 PQC security by combining ML-KEM with periodic key rotation to protect both initial key establishment and ongoing message exchange. Independently verified by ETH Zurich and University of Waterloo.

Web page · 106 KB · a short read

MiscIndustry & ResearchHigh
Apple Security Engineering & ArchitectureFeb 21, 2024
Trust 47Needs review
SG-MAS-Quantum-Advisory-2024Updated

Monetary Authority of Singapore (MAS) advisory requiring Singapore financial institutions to develop quantum risk management programs. Establishes timeline for financial sector PQC planning and mandates cryptographic inventory assessments.

PDF · 139 KB · a short read

MiscGovernment & PolicyHigh
MAS; Monetary Authority of SingaporeFeb 20, 2024
Trust 57Needs review
Reducing-the-Number-of-Qubits-in-Quantum-FactoringUpdated

Cuts the logical-qubit cost of Shor's factoring algorithm by computing approximate modular exponentiations with a Residue Number System, removing the assumption that n-bit arithmetic needs an n-qubit register. Estimates 1,730 logical qubits and 2^36 Toffoli gates for RSA-2048 — the source of the revised figure, and the basis Gidney 2025 builds on to reach fewer than 1M noisy physical qubits.

PDF · 581 KB · a long read

Research PaperIndustry & ResearchHigh
Clémence Chevignard; Pierre-Alain Fouque; André Schrottenloher (Univ Rennes, Inria, CNRS, IRISA)Feb 13, 2024
Trust 63Needs review
NIST SP 800-66Updated

Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule

PDF · 1.6 MB · a reference document — dip in, don’t read it through

ReleasedGovernment & Policy
NISTFeb 2024
Trust 86Authoritative
ITU-T X.1819Updated

ITU guidance on implementing quantum-safe cryptography in telecommunications.

PDF · 527 KB · a long read

ReleasedMigration Guidance1 rev
ITU-T SG17Feb 1, 2024
Trust 51Needs review
IACR-2024-046-Aviation-Quantum-SecureUpdated

Research paper (IACR ePrint 2024/046, Dowling and Wimalasiri, University of Sheffield) on securing Controller-Pilot Data Link Communications (CPDLC) between air traffic control and aircraft. States that ECDSA "has been proposed as a suitable scheme for securing ACARS messages by the ACARS message security standard" (ARINC 823P1), analyses ECDH over P-384 as the classical key exchange, and proposes Kyber/ML-KEM with Dilithium for the post-quantum variant. Cited as research: ARINC 811 and 823 are sold through SAE and cannot be cited.

PDF · 817 KB · a long read

Research PaperIndustry & ResearchHigh
Benjamin Dowling, Bhagya Wimalasiri (University of Sheffield)Jan 11, 2024
Trust 54Needs review
Saudi-NCA-ECC2-2024Updated

Saudi Arabia NCA releases updated Essential Cybersecurity Controls 2024 with expanded cryptography domain covering PQC awareness. Applicable to all Saudi government entities and critical infrastructure.

PDF · 1.2 MB · a long read

ReleasedGovernment & Policy
Saudi NCA; National Cybersecurity Authority Saudi Arabia2024
Trust 52Needs review
ITU-T-X1811Updated

ITU-T recommendation providing security guidelines for the application of quantum-safe cryptographic mechanisms in telecommunications.

PDF · 1.6 MB · a reference document — dip in, don’t read it through

ReleasedProtocols
ITU-T2024
Trust 78Authoritative
NIST-PQC-Seminar-FaultInjection-LatticeUpdated

NIST seminar on practical fault injection attacks targeting Kyber and Dilithium on ARM Cortex-M4. Covers clock/voltage glitching, laser and electromagnetic fault injection exploiting polynomial multiplication and decryption routines.

PDF · 11.3 MB · a reference document — dip in, don’t read it through

MiscNIST StandardsHigh
NIST2024
Trust 73Authoritative
NSA CSfC PQC Guidance AddendumUpdated

NSA CSfC program addendum incorporating post-quantum cryptography requirements under CNSA 2.0. Governs classified systems transitioning to PQC algorithms.

PDF · 1.5 MB · a long read

DraftNIST StandardsHigh
NSA2024
Trust 82Authoritative
ETSI-GS-QKD-016-V2Updated

Updated Common Criteria Protection Profile for Prepare-and-Measure QKD modules aligned with CC:2022 Revision 1. World's first QKD Protection Profile, certified by BSI as BSI-CC-PP-0120-2024.

PDF · 891 KB · a long read

ReleasedIndustry & ResearchHigh1 rev
ETSI ISG QKDJan 2024
Trust 82Authoritative
EMVCo-Quantum-Position-StatementUpdated

EMVCo's position on the quantum threat to EMV chip cryptography, covering the RSA-based offline data authentication in Book 2 and EMVCo’s intended migration approach.

PDF · 302 KB · a short read

MiscIndustry & ResearchHigh
EMVCo Security Working GroupJan 1, 2024
Trust 61Needs review
RFC-9563-SM2-Digital-Signature-Algorithm-for-DNSSECUpdated

IETF RFC 9563 specifies SM2 for DNSSEC (algorithm number 17): 64-octet uncompressed public key (x||y), 64-octet signature (32-octet r || 32-octet s each). Used as the primary source for SM2's ALGORITHM_REGISTRY byte sizes.

Web page · 16 KB · a quick skim

ReleasedInternational Frameworks
IETFJan 1, 2024
Trust 69Needs review
PQShield-Leadership-Lounge-NIST-standards-the-PQC-turning-poUpdated

Web page · 81 KB · a short read

MiscMigration Guidance
PQShield2024
Trust 26Needs review
Advancing-Our-Amazing-Bet-on-Asymmetric-CryptographyUpdated

Web page · 284 KB · a long read

MiscMigration Guidance
Google2024
Trust 26Needs review
ISO-11898-1-2024-Road-vehicles-Controller-area-network-CAN-P

ReleasedMigration Guidance
ISO/IEC2024
Trust 9Needs review
Purchase required
Electronic-Signatures-and-Infrastructures-ESI-JAdES-digitalUpdated

PDF · 395 KB · a short read

ReleasedMigration Guidance
Unknown2024
Trust 26Needs review
Download-Bouncy-Castle-JavaUpdated

Web page · 1.5 MB · a long read

MiscMigration Guidance
Bouncycastle2024
Trust 26Needs review
PCI-SSC-P2PE-Program-PageUpdated

PCI SSC program page for the Point-to-Point Encryption (P2PE) standard.

Web page · 727 KB · a long read

MiscCompliance & CertificationReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
PCI Security Standards Council2024
Trust 34Needs review
EN-18031-1-2024Updated

CEN/CENELEC harmonised standard specifying common security requirements and assessment criteria (access control, authentication, secure update, secure communication, confidential cryptographic keys, best-practice cryptography) for internet-connected radio equipment under the RED delegated act. Not PQC-specific; its best-practice cryptography requirement is where post-quantum algorithm expectations for EU IoT radio products would land.

Web page · 296 KB · a long read

ReleasedCompliance & CertificationReviewed (LLM) · eramusa · Oct 2026 · via manual data edit (library)
CEN/CENELEC JTC 132024
Trust 62Needs review
EN-18031-3-2024Updated

CEN/CENELEC JTC 13 harmonised European Standard (EN 18031-3, August 2024) specifying common security requirements and assessment criteria for internet-connected radio equipment that lets the holder or user transfer money, monetary value or virtual currency, supporting the RED Delegated Regulation (EU) 2022/30 (Annex ZA). Requirement families cover access control, authentication, secure update, secure storage, secure communication, logging, confidential cryptographic keys, general equipment capabilities and best-practice cryptography ([CRY-1]), with mappings to EN IEC 62443-4-2:2019, ETSI EN 303 645 and SESIP.

PDF · 1.3 MB · a long read

ReleasedCompliance & CertificationReviewed (LLM) · eramusa · Oct 2026 · via manual data edit (library)
CEN/CENELEC JTC 132024
Trust 62Needs review
PSA-Certified-Level-2-PP-SESIP-v2-0Updated

SESIP Profile (JSADEN012 v2.0) defining the Target of Evaluation, assets, security objectives and SESIP security functional requirements for a PSA Certified Level 2 laboratory evaluation of an IoT chip's Root of Trust. Not PQC-specific, but it ties key strength to NIST SP 800-57 Part 1 and states RSA-2048 is accepted only for products certified before the end of 2026, making it a lever for future quantum-safe algorithm requirements in IoT certification.

PDF · 705 KB · a long read

ReleasedCompliance & CertificationReviewed (LLM) · eramusa · Oct 2026 · via manual data edit (library)
PSA JSA Members (Applus+ Laboratories; Arm Limited; CAICT; DEKRA; ECSEC; ProvenRun; Riscure; Serma; SGS Brightsight; TrustCB; UL TS)2024
Trust 44Needs review
Torres-ICREPQ-2024-341Updated

UPV/EHU conference paper (ICREPQ'24) simulating a Docker-virtualised IEC 61850 substation protection system and showing that adding virtual IEDs raises the tripping communication delay (37 ms baseline, about +3 ms with 1 extra IED and +44 ms with 7). Documents the IEC 61850-5 transfer-time classes TT0-TT6 (TT0 >1000 ms, TT1 1000 ms, TT2 500 ms, TT3 100 ms, TT4 20 ms, TT5 10 ms, TT6 3 ms for trips and blockings).

PDF · 550 KB · a long read

Research PaperIndustry & Research
E. Torres, N. Escobar, P. Eguia, O. Abarrategi, D.M. Larruskain, V. Valverde, G. Buigues (University of the Basque Country UPV/EHU)2024
Trust 50Needs review
RFC-9496Updated

This memo specifies two prime-order groups, ristretto255 and decaf448, suitable for safely implementing higher-level and complex cryptographic protocols. The ristretto255 group can be implemented using Curve25519, allowing existing Curve25519 implementations to be reused and extended to provide a prime-order group. Likewise, the decaf448 group can be implemented using edwards448. This document i

Web page · 128 KB · a short read

ReleasedProtocols
IETFDec 22, 2023
Trust 78Authoritative
ANSSI PQC Position PaperUpdated

ANSSI publishes France's position on PQC transition, advocating hybrid post-quantum/classical schemes as the primary migration path. Provides phased approach guidance for French government and regulated entities.

PDF · 186 KB · a short read

MiscInternational Frameworks
ANSSI; French National Cybersecurity AgencyDec 21, 2023
Trust 76Authoritative
ANSSI PQC Follow-up PaperUpdated

Updated guidance on hybridization requirements and timeline phases through 2030+.

PDF · 172 KB · a short read

MiscInternational FrameworksHigh
ANSSI FranceDec 21, 2023
Trust 78Authoritative
NERC-CIP-012-2Updated

NERC Reliability Standard CIP-012-2 requires Control Center owners/operators to implement documented plans that protect the confidentiality, integrity and availability of Real-time Assessment and Real-time monitoring data transmitted between Control Centers (adds availability and link recovery to CIP-012-1). Not PQC-specific; relevant to PQC migration because encryption of inter-Control-Center links is a listed mitigation and will need quantum-safe replacement in North American grid OT.

PDF · 231 KB · a short read

ReleasedCompliance & Certification1 rev
NERCDec 12, 2023
Trust 62Needs review
NIST NCCoE SP 1800-38CUpdated

Practical guidance for enterprise PQC migration with use cases and reference architectures.

PDF · 1.6 MB · a reference document — dip in, don’t read it through

DraftNIST StandardsHigh
NIST NCCoEDec 2023
Trust 83Authoritative
BIS-OTHP107Updated

BIS Innovation Hub Project Leap Phase 2 tests CRYSTALS-Dilithium post-quantum digital signatures in the Eurosystem T2 payment system. Demonstrates functional feasibility, performance benchmarks (PQC ~7.4× slower than RSA), interoperability across central bank configurations, and identifies challenges for hybrid cryptography migration.

PDF · 1.4 MB · a long read

MiscIndustry & ResearchHigh
BIS Innovation Hub; Bank of Italy; Bank of France; Deutsche Bundesbank; Nexi-Colt; SwiftDec 2023
Trust 67Needs review
NIST NCCoE SP 1800-38BUpdated

Volume B — Tools and techniques for cryptographic discovery. Guides organizations in identifying quantum-vulnerable cryptography across their environments as the first step in PQC migration.

PDF · 1.7 MB · a reference document — dip in, don’t read it through

ReleasedNIST StandardsHigh1 rev
NIST NCCoEDec 1, 2023
Trust 80Authoritative
AUTOSAR-CP-SWS-CryptoDriver-R23-11Updated

AUTOSAR Classic Platform software specification for the Crypto Driver, the in-vehicle ECU cryptographic abstraction. Enumerates the algorithm families an ECU stack must expose, including CRYPTO_ALGOFAM_ECDSA and CRYPTO_ALGOFAM_ECDH alongside RSA, ED25519 and BRAINPOOL. Cited as the proof that in-vehicle networks use ECDH and ECDSA; note MACsec (802.1AE) itself is AES-GCM and names neither.

PDF · 846 KB · a long read

ReleasedAlgorithm SpecificationsHigh
AUTOSAR Release ManagementNov 23, 2023
Trust 51Needs review
NIST-SP-800-140BUpdated

Specifies minimum documentation requirements for FIPS 140-3 Security Policy documents; part of the NIST SP 800-140 series that defines the CMVP submission and validation framework.

PDF · 589 KB · a long read

ReleasedNIST StandardsReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
NIST CMVPNov 2023
Trust 89Authoritative
NY-DFS-23-NYCRR-500-A2Updated

New York Department of Financial Services cybersecurity regulation for covered entities (banks, insurers, money transmitters).

PDF · 696 KB · a long read

ReleasedCompliance & Certification
NY DFSNov 1, 2023
Trust 81Authoritative
Signal-PQXDH-Spec

Signal's specification for PQXDH, extending the X3DH key agreement protocol with post-quantum security using ML-KEM. Deployed in Signal Messenger since September 2023. Provides forward secrecy and post-quantum confidentiality for initial key establishment in Signal's end-to-end encryption.

Web page · 64 KB · a short read

ReleasedProtocolsHigh
Signal MessengerSep 19, 2023
Trust 48Needs review
Canada CSE PQC Guidance

Canadian Centre for Cyber Security guidance on PQC adoption.

PDF · 649 KB · a long read

ReleasedGovernment & Policy
CCCS CanadaSep 1, 2023
Trust 71Authoritative
RFC 9449Updated

Defines DPoP for binding OAuth 2.0 tokens to a client public key using signed proof-of-possession JWTs. DPoP proof JWTs use ECDSA signatures that are quantum-vulnerable. Migration to ML-DSA-signed DPoP proofs requires JOSE PQC standardization and results in significantly larger proof headers per request.

Web page · 220 KB · a long read

ReleasedProtocols
IETFSep 2023
Trust 85Authoritative
NIST SP 800-82 Rev. 3Updated

NIST guidance for securing industrial control systems (ICS), SCADA, DCS, and OT networks. Covers the Purdue model, network architecture, and security controls for critical infrastructure.

PDF · 8.6 MB · a reference document — dip in, don’t read it through

ReleasedGovernment & PolicyHigh
NISTSep 2023
Trust 87Authoritative
GSMA-PQ02Updated

GSMA guidelines for performing Quantum Cryptanalytic Risk Assessment (QCRA) in telecom. Adapts NIST RMF and ISO/IEC 27000 for quantum risk. Introduces the Crypto Agility Risk Assessment Framework (CARAF).

PDF · 1.2 MB · a long read

ReleasedCompliance & CertificationHigh1 rev
GSMASep 2023
Trust 87Authoritative
CISA-Quantum-Readiness-Roadmap

Joint CISA/NSA/NIST guidance on preparing organizations for post-quantum cryptography migration. Outlines a four-step quantum-readiness roadmap: establish governance; inventory vulnerable cryptography; assess priorities; engage vendors and plan transitions. Foundational regulatory baseline for federal and critical-infrastructure organizations and the most-cited US migration-readiness document.

PDF · 558 KB · a long read

ReleasedGovernment & PolicyHigh
CISA; NSA; NISTAug 21, 2023
Trust 92Authoritative
ref-ibm-qldpc-gross-codeUpdated

Presentation of an end-to-end fault-tolerant quantum memory protocol using high-rate LDPC codes with low overhead and high error thresholds.

PDF · 858 KB · a long read

Research PaperIndustry & Research
S. Bravyi; A. Cross; J. Gambetta; et al. (IBM)Aug 15, 2023
Trust 45Needs review
RFC-9380Updated

This document specifies a number of algorithms for encoding or hashing an arbitrary string to a point on an elliptic curve. This document is a product of the Crypto Forum Research Group (CFRG) in the IRTF.

Web page · 2.2 MB · a long read

ReleasedProtocols
IETFAug 11, 2023
Trust 78Authoritative
China GB/T 42829-2023Updated

Chinese national recommended standard (GB/T) setting basic requirements for applying quantum secure communication (QKD-based). In force 2024-03-01. It is a quantum-communication standard, not a post-quantum cryptography standard.

Web page · 24 KB · a quick skim

ReleasedProtocolsHighReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (LM-068 regional remediation)
SAMR / Standardization Administration of China (GB/T national standard)Aug 6, 2023
Trust 61Needs review
ref-obrien-chrome-hybridUpdated

Announcement of the implementation of Hybrid Kyber KEM to protect Chrome traffic.

Web page · 179 KB · a long read

MiscIndustry & Research
D. O'BrienAug 2023
Trust 50Needs review
ref-bravyi-quantum-memoryUpdated

Presentation of a high-threshold, low-overhead fault-tolerant quantum memory protocol using bivariate bicycle LDPC codes.

PDF · 2.8 MB · a reference document — dip in, don’t read it through

Research PaperIndustry & Research
S. Bravyi et al.Aug 2023
Trust 45Needs review
SCA-2023-Masked-Kyber-DLUpdated

Profiled deep-learning power analysis recovers secret and shared keys from first-, second-, and third-order masked Kyber-768 implementations on ARM Cortex-M4 — demonstrating that AI/ML side-channel analysis defeats standard masking countermeasures today, with no quantum computer or classical mathematical break of the underlying lattice problem required.

PDF · 3.9 MB · a reference document — dip in, don’t read it through

Research PaperIndustry & ResearchHigh
CHES/TCHES research communityJul 4, 2023
Trust 71Authoritative
RFC 9420Updated

Key establishment protocol for efficient asynchronous group key establishment with forward secrecy and post-compromise security for groups of two to thousands. Uses HPKE tree-based key encapsulation (TreeKEM). Foundation for PQC group messaging via draft-ietf-mls-pq-ciphersuites (ML-KEM + hybrid KEMs).

Web page · 638 KB · a long read

ReleasedProtocols
IETF MLSJul 2023
Trust 84Authoritative
NIST-SP-800-140CUpdated

List of approved security functions (algorithms) that FIPS 140-3 modules may implement under CMVP.

PDF · 720 KB · a long read

ReleasedCompliance & Certification1 revReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
NISTJul 2023
Trust 88Authoritative
NIST-SP-800-140DUpdated

Approved methods for sensitive security parameter (SSP) generation and establishment under FIPS 140-3.

PDF · 730 KB · a long read

ReleasedCompliance & Certification1 revReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
NISTJul 2023
Trust 88Authoritative
RFC-9345Updated

The organizational separation between operators of TLS and DTLS endpoints and the certification authority can create limitations. For example, the lifetime of certificates, how they may be used, and the algorithms they support are ultimately determined by the Certification Authority (CA). This document describes a mechanism to overcome some of these limitations by enabling operators to delegate

Web page · 74 KB · a short read

ReleasedProtocols1 rev
IETFJul 2023
Trust 79Authoritative
CA-CFDIR-Quantum-Readiness-2023Updated

Canadian Forum for Digital Infrastructure Resilience (CFDIR) publishes quantum-readiness best practices for Canadian organizations covering PQC algorithm selection, hybrid approaches, and migration planning.

PDF · 2.9 MB · a reference document — dip in, don’t read it through

ReleasedGovernment & PolicyHigh
CFDIR; Innovation Science and Economic Development CanadaJun 12, 2023
Trust 67Needs review
Singapore-NQSN-Plus

Singapore IMDA, CSA, and GovTech launch National Quantum-Safe Network Plus (NQSN+) to pilot quantum-safe networking solutions. Connects government, financial sector, and critical infrastructure operators.

Web page · 140 KB · a short read

ReleasedGovernment & PolicyHigh
IMDA Singapore; CSA Singapore; GovTech SingaporeJun 1, 2023
Trust 68Needs review
ref-litinski-toffoliUpdated

Resource estimates for breaking 256-bit elliptic curve private keys using Shor’s algorithm on fault-tolerant quantum computers with active-volume architectures.

PDF · 3.3 MB · a reference document — dip in, don’t read it through

Research PaperIndustry & Research
D. LitinskiJun 2023
Trust 53Needs review
OWASP-CycloneDX-CBOM-Guide

OWASP CycloneDX specification for the Cryptographic Bill of Materials (CBOM). Defines the schema, asset classes (algorithms, certificates, protocols, related cryptographic material), and discovery/enumeration guidance. The canonical format reference for CBOM tooling interoperability.

Web page · 38 KB · a quick skim

ReleasedMigration Guidance
OWASP CycloneDXJun 1, 2023
Trust 71Authoritative
NIST-SP-1800-40A-PDUpdated

Preliminary draft (June 2023) of NIST SP 1800-40A, the executive-summary volume of the NCCoE project on automating the Cryptographic Module Validation Program.

PDF · 293 KB · a short read

DraftCompliance & CertificationReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
NIST NCCoE (Apostol Vassilev; Murugiah Souppaya; William Barker)Jun 2023
Trust 34Needs review
MICA-REG-2023-1114Updated

EU crypto-asset regulation establishing prudential and operational requirements for crypto-asset service providers and issuers. Article 30 requires ICT security and cryptographic controls aligned with DORA.

PDF · 1.6 MB · a reference document — dip in, don’t read it through

ReleasedCompliance & CertificationHigh
European Parliament; Council of the EUMay 31, 2023
Trust 64Needs review
FIPS-197Updated

In 2000, NIST announced the selection of the Rijndael block cipher family as the winner of the Advanced Encryption Standard (AES) competition. Block ciphers are the foundation for many cryptographic services, especially those that provide assurance of the confidentiality of data. Three members of the Rijndael family are specified in this Standard: AES-128, AES-192, and AES-256. Each of them trans

Web page · 44 KB · a short read

ReleasedAlgorithm Specifications
NISTMay 9, 2023
Trust 81Authoritative
ETSI-TR-103-949

Reviews deployment of cryptographic security mechanisms in Intelligent Transport Systems (ITS) and Cooperative ITS. Assesses quantum computing vulnerability of V2X communications and trust roots.

PDF · 693 KB · a long read

ReleasedInternational FrameworksHigh
ETSI TC CYBER WG QSCMay 2023
Trust 83Authoritative
RFC 9370Updated

Enables multiple key exchanges in single IKEv2 SA for hybrid PQ+classical.

Web page · 153 KB · a long read

ReleasedProtocolsHigh
IETF IPSECMEMay 2023
Trust 61Needs review
AU-National-Quantum-Strategy-2023

Australia's whole-of-government quantum strategy establishing five themes: R&D and investment in quantum technologies; access to quantum infrastructure and materials; a skilled and growing quantum workforce; standards and frameworks supporting national interests; and a trusted, ethical, and inclusive quantum ecosystem. Sets the national vision for Australia to be a top-10 global quantum nation by 2045.

PDF · 17.6 MB · a reference document — dip in, don’t read it through

ReleasedGovernment & Policy
Australian Government Department of Industry, Science and ResourcesMay 1, 2023
Trust 64Needs review
CCMC-2023-04-001-CC2022-Transition-PolicyUpdated

CCRA Management Committee policy CCMC-2023-04-001 (20 April 2023) on the transition from CC v3.1 to CC:2022 and CEM:2022.

PDF · 157 KB · a short read

ReleasedCompliance & Certification
CCRA Management Committee (CCMC)Apr 20, 2023
Trust 34Needs review
SLSA-Specification-v1.1

A framework of graduated levels (Build L1-L3) for supply-chain integrity, defining provenance requirements for how an artifact was produced. Cited by the sandbox supply-chain-signing scenario, which demonstrates SLSA-style provenance signed with ML-DSA rather than ECDSA. A governance and process specification, not a cryptographic algorithm spec.

Web page · 20 KB · a quick skim

ReleasedProtocols
OpenSSF (Open Source Security Foundation)Apr 19, 2023
Trust 85Authoritative
NIST NCCoE SP 1800-38A

Volume A — Executive summary and business case for enterprise PQC migration. Frames the challenge of transitioning to quantum-resistant cryptography and outlines the NCCoE migration project scope.

Web page · 41 KB · a short read

DraftNIST StandardsHigh
NIST NCCoEApr 2023
Trust 84Authoritative
CRYPTREC-LS-0001-2022R2-List-of-Ciphers-to-be-Referred-to-foUpdated

Japan’s CRYPTREC list of ciphers approved for government procurement — the reference a Japanese public-sector migration is measured against.

PDF · 240 KB · a short read

ReleasedGovernment & PolicyHigh
Digital Agency (Japan); Ministry of Internal Affairs and Communications (Japan); Ministry of Economy, Trade and Industry (Japan)Mar 30, 2023
Trust 80Authoritative
ISO-IEC-23837-1

Security requirements for QKD modules. Defines protection profiles and security targets analogous to Common Criteria for QKD hardware.

Web page · 88 KB · a short read

ReleasedKEM
ISO/IEC JTC 1/SC 27Mar 1, 2023
Trust 79Authoritative
ISO-IEC-23837-2

Testing methodology and evaluation criteria for QKD modules. Provides test vectors and conformance assessment procedures.

Web page · 88 KB · a short read

ReleasedKEM
ISO/IEC JTC 1/SC 27Mar 1, 2023
Trust 77Authoritative
EPA-Guidance-on-Improving-Cybersecurity-at-Drinking-Water-an

US EPA cybersecurity guidance for water and wastewater systems — operational technology with very long replacement cycles.

PDF · 458 KB · a long read

ReleasedMigration Guidance
US EPA Office of WaterMar 2023
Trust 56Needs review
FIPS 186-5Updated

Specifies RSA, ECDSA, EdDSA. Removes DSA. Errata May 2025. Transition to PQC planned.

PDF · 1.8 MB · a reference document — dip in, don’t read it through

ReleasedDigital Signature
NISTFeb 3, 2023
Trust 86Authoritative
NIST-SP-800-186Updated

Specifies the elliptic curves and domain parameters NIST approves for discrete-logarithm cryptography — the classical curves a PQC migration is replacing.

Web page · 45 KB · a short read

ReleasedNIST Standards
Lily Chen; Dustin Moody; Andrew Regenscheid; Angela Robinson (NIST); Karen Randall (Randall Consulting)Feb 3, 2023
Trust 89Authoritative
Rosenpass-Protocol

Defines the Rosenpass protocol for adding PQC to WireGuard. Runs a separate ML-KEM-768 + Classic McEliece handshake and injects the combined shared secret as a WireGuard pre-shared key (PSK). Formally verified with ProVerif.

PDF · 347 KB · a short read

ReleasedProtocolsHigh
Rosenpass e.V.Feb 1, 2023
Trust 53Needs review
RFC 9364

IETF BCP for DNSSEC; consolidates operational guidance and references PQ work as future work.

Web page · 98 KB · a short read

ReleasedProtocols
P. HoffmanFeb 2023
Trust 82Authoritative
GSMA-PQ01Updated

Foundational GSMA whitepaper analysing quantum-computing impact on telecom. Covers PQC technology dependencies, transition timelines, and market drivers across 2G/3G/4G/5G domains. Excludes QKD.

PDF · 1.2 MB · a long read

MiscCompliance & CertificationHigh
GSMA Post Quantum Telco Network Task ForceFeb 2023
Trust 88Authoritative
ref-bindel-hybrid-sigsUpdated

Analysis of design goals and security properties for hybrid digital signature schemes combining classical and post-quantum algorithms.

PDF · 1.0 MB · a long read

Research PaperIndustry & Research
N. Bindel and B. Hale2023
Trust 52Needs review
NIST-AI-100-1-Artificial-Intelligence-Risk-Management-FramewUpdated

NIST's voluntary framework for managing risks in the design, development, deployment and use of AI systems, organised around the Govern/Map/Measure/Manage core. Cited by the ai-security-pqc module as the AI-risk governance anchor; the document itself contains no mention of cryptography, encryption or quantum computing and does not address post-quantum migration.

PDF · 1.9 MB · a reference document — dip in, don’t read it through

ReleasedGovernment & Policy
National Institute of Standards and Technology (NIST), U.S. Department of CommerceJan 2023
Trust 55Needs review
DigiCert-Unveils-CEO-Predictions-for-Digital-Trust-in-2024-DUpdated

Web page · 121 KB · a short read

MiscMigration Guidance
Unknown2023
Trust 26Needs review
NIST-Selects-HQC-as-Fifth-Algorithm-for-Post-Quantum-EncryptUpdated

Web page · 95 KB · a short read

MiscMigration Guidance
NIST2023
Trust 26Needs review
Electronic-Signatures-and-Infrastructures-ESI-Certificate-PrUpdated

PDF · 126 KB · a short read

DraftMigration Guidance
Unknown2023
Trust 26Needs review
OpenSSL-1-1-1-End-Of-Life-ApproachingUpdated

Web page · 25 KB · a quick skim

MiscMigration Guidance
OpenSSL Corporation2023
Trust 26Needs review
ISO-8583-2023-Financial-transaction-card-originated-messages

ReleasedMigration Guidance
ISO/IEC2023
Trust 9Needs review
Purchase required
IEC-62056-5-3-2023-Electricity-metering-data-exchange-The-DL

ReleasedMigration Guidance
IEC2023
Trust 9Needs review
Purchase required
Mitigation-Guide-Healthcare-and-Public-Health-HPH-SectorUpdated

PDF · 1.2 MB · a long read

MiscMigration GuidanceReviewed (LLM) · eramusa · Sep 2026 · via lineage/apply_secondary.py
Unknown2023
Trust 26Needs review
UK-PSTI-Regs-2023-1007Updated

UK statutory instrument under the PSTI Act 2022 setting mandatory security requirements for consumer connectable products: no universal default passwords, a vulnerability-reporting policy, and a published minimum security-update support period, with deemed compliance via ETSI EN 303 645 or ISO/IEC 29147 provisions. Not PQC-specific; its defined support period matters for PQC planning because devices sold now must be supported into the quantum-risk window.

PDF · 251 KB · a short read

ReleasedCompliance & Certification
UK Department for Science, Innovation and Technology (Secretary of State)2023
Trust 38Needs review
EN-17927-2023Updated

CEN/CENELEC European Standard (EN 17927:2023) defining SESIP, a methodology for security evaluation of IoT platforms and platform parts with reusable security functional and assurance requirements and SESIP assurance levels; drafted from the reseller listing and free sample only. Not PQC-specific; relevant to PQC migration as the evaluation basis IoT certification schemes (e.g. PSA Certified) reuse, where future quantum-safe cryptographic requirements would be assessed.

Web page · 305 KB · a long read

ReleasedCompliance & CertificationReviewed (LLM) · eramusa · Oct 2026 · via manual data edit (library)
CEN/CENELEC JTC 132023
Trust 60Needs review
ODVA-PUB00319-CIP-SecurityUpdated

ODVA technology overview of CIP Security, the EtherNet/IP security extension: five security profiles (EtherNet/IP Confidentiality, CIP User Authentication, Resource-Constrained, Pull Model, Device-Based Firewall) built on X.509v3 certificates or PSKs, TLS/DTLS, HMAC, AES and OAuth 2.0/OpenID Connect tokens. Not PQC-specific; relevant to PQC migration because device identity and secure transport in EtherNet/IP rest on classical certificates and TLS/DTLS key exchange.

PDF · 497 KB · a long read

MiscProtocolsReviewed (LLM) · eramusa · Oct 2026 · via manual data edit (library)
ODVA2023
Trust 36Needs review
QCCPA-2022Updated

US legislation requiring OMB to prioritize PQC migration across federal agencies. Established annual reporting requirements and directed NIST to maintain updated PQC guidance.

Web page · 362 KB · a long read

MiscGovernment & PolicyCritical
US CongressDec 21, 2022
Trust 58Needs review
US-QCCPA-2022Updated

US federal law requiring federal agencies to inventory and migrate cryptographic systems to quantum-resistant standards. Directs NIST and OMB to develop migration guidelines and establishes annual reporting requirements for PQC migration progress.

PDF · 208 KB · a short read

ReleasedGovernment & PolicyCritical
US Congress; Office of Management and BudgetDec 21, 2022
Trust 58Needs review
NIS2-DIRECTIVE-2022-2555Updated

EU cybersecurity directive mandating risk-management measures and incident reporting for essential and important entities. Requires cryptographic controls and supply-chain security. Implemented by member states by Oct 2024.

PDF · 1.3 MB · a long read

ReleasedCompliance & CertificationHigh
European Parliament; Council of the EUDec 14, 2022
Trust 65Needs review
DORA-REG-2022-2554Updated

EU regulation requiring financial entities to manage ICT risk including cryptographic controls, incident reporting, and digital operational resilience testing. Applicable from Jan 2025.

Web page · 1.0 MB · a long read

ReleasedCompliance & CertificationHigh
European Parliament; Council of the EUDec 14, 2022
Trust 66Needs review
FRA-Information-Guide-on-Positive-Train-Control-in-49-CFR-Pa

US Federal Railroad Administration guidance on Positive Train Control, including the message authentication it depends on.

PDF · 277 KB · a short read

ReleasedMigration Guidance
US Federal Railroad AdministrationDec 12, 2022
Trust 55Needs review
IBM-CBOM-Harishankar

IBM Research introduction to CBOM as the data artifact underpinning quantum-safe enterprise transformation.

Web page · 68 KB · a short read

ReleasedMigration Guidance
Ray Harishankar et al. (IBM)Dec 8, 2022
Trust 55Needs review
KLEPTO-2022-Kyber-BackdoorUpdated

Practical kleptographic (SETUP) backdoor demonstrated in Kyber/ML-KEM key generation — the generated public key covertly leaks the secret key to whoever holds the backdoor key. Validated end-to-end on TLS 1.3. A deliberately-subverted implementation, not a math or quantum-computer break: proof that a correctly-specified PQC algorithm can still be broken today via a compromised implementation or supply chain.

PDF · 355 KB · a short read

Research PaperIndustry & ResearchHigh
Prasanna Ravi; Shivam Bhasin; Anupam Chattopadhyay; Aikata Aikata; Sujoy Sinha RoyDec 2, 2022
Trust 74Authoritative
RFC-9329Updated

Transports IKE and IPsec packets over a TCP connection so they can cross networks that block UDP. Obsoletes RFC 8229. draft-ietf-ipsecme-ikev2-mlkem-09 names it as a reliable transport that permits ML-KEM-768/1024 in IKE_SA_INIT.

Web page · 628 KB · a long read

ReleasedProtocols1 rev
IETFNov 30, 2022
Trust 63Needs review
ASC-X9-IR-F01-2022Updated

ASC X9 informative report assessing quantum computing risks to the financial services industry. Covers cryptographic threats, harvest-now-decrypt-later attacks, timeline projections, and migration priorities for financial institutions. Produced by the X9F Quantum Computing Risk Study Group.

PDF · 1.9 MB · a reference document — dip in, don’t read it through

ReleasedIndustry & ResearchHigh
ASC X9; X9F Quantum Computing Risk Study GroupNov 29, 2022
Trust 57Needs review
KpqC-NTRU-PlusUpdated

NTRU+ is a post-quantum KEM selected as a South Korean national PQC standard by KpqC in January 2025. Based on NTRU lattice assumptions with improved key sizes over classic NTRU. Targets NIST-equivalent security levels L1, L3, and L5. National standard target year: 2029, migration by 2035.

PDF · 479 KB · a long read

Research PaperAlgorithm SpecificationsHigh
KISA; Ministry of Science and ICT; NIS KoreaNov 21, 2022
Trust 74Authoritative
OMB-M-23-02Updated

OMB memo requiring federal agencies to submit cryptographic system inventories per NSM-10. Sets deadlines for PQC migration planning across US government systems.

PDF · 255 KB · a short read

ReleasedGovernment & PolicyCritical
OMB; White HouseNov 18, 2022
Trust 65Needs review
OASIS-CSAF-2.0-VEXUpdated

OASIS Standard defining CSAF 2.0, whose Profile 5 is the Vulnerability Exploitability eXchange (VEX) — a machine-readable statement of whether a product is actually affected by a given vulnerability. VEX complements an SBOM: the SBOM says what components are present, VEX says which of their known vulnerabilities are exploitable in this product.

PDF · 736 KB · a long read

ReleasedAlgorithm Specifications
OASIS CSAF Technical CommitteeNov 18, 2022
Trust 85Authoritative
CC-2022-PART2Updated

CC:2022 Part 2 — catalog of security functional requirements (SFRs) used to construct protection profiles and security targets.

PDF · 3.2 MB · a reference document — dip in, don’t read it through

ReleasedCompliance & Certification
Common Criteria Recognition Arrangement (CCRA)Nov 2022
Trust 83Authoritative
CC-2022-PART3Updated

CC:2022 Part 3 — assurance classes and families (ADV, AGD, ALC, ATE, AVA, etc.) used to define Evaluation Assurance Levels (EALs).

PDF · 2.9 MB · a reference document — dip in, don’t read it through

ReleasedCompliance & Certification
Common Criteria Recognition Arrangement (CCRA)Nov 2022
Trust 83Authoritative
CC-2022-CEMUpdated

Companion to CC:2022 parts 1–3 — methodology evaluators apply when assessing conformance to protection profiles and security targets.

PDF · 3.6 MB · a reference document — dip in, don’t read it through

ReleasedCompliance & Certification
Common Criteria Recognition Arrangement (CCRA)Nov 2022
Trust 83Authoritative
COMMON-CRITERIAUpdated

Common Criteria (ISO/IEC 15408) provides a framework for computer security certification. Relevant to PQC module evaluation.

PDF · 4.5 MB · a reference document — dip in, don’t read it through

ReleasedCompliance & Certification1 rev
Common Criteria Recognition Arrangement (CCRA)Nov 2022
Trust 85Authoritative
RFC 9325Updated

IETF BCP for secure TLS/DTLS configuration. Notes PQC is work-in-progress; will be updated when PQ specs published.

Web page · 247 KB · a long read

ReleasedProtocols1 rev
P. Sheffer; R. Holz; P. Saint-Andre; T. FossatiNov 2022
Trust 82Authoritative
CC-2022-PART4Updated

CC:2022 Revision 1 Part 4 (CCMB-2022-11-004): the framework for specifying evaluation methods and activities.

PDF · 596 KB · a long read

ReleasedCompliance & Certification
Common Criteria Recognition Arrangement (CCRA)Nov 2022
Trust 34Needs review
CC-2022-PART5Updated

CC:2022 Revision 1 Part 5 (CCMB-2022-11-005): the pre-defined packages of security requirements.

PDF · 586 KB · a long read

ReleasedCompliance & Certification
Common Criteria Recognition Arrangement (CCRA)Nov 2022
Trust 34Needs review
ISO-IEC-27001-2022Updated

International standard specifying requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS). Serves as the governance anchor for accepting residual risk and operating the standing security capabilities handed to business-as-usual after a PQC migration.

Web page · 136 KB · a short read

ReleasedMigration Guidance1 rev
ISO/IECOct 25, 2022
Trust 46Needs review
Classic-McEliece-Spec

NIST PQC Round 4 finalist specification for Classic McEliece, a code-based KEM with 50+ years of cryptanalytic scrutiny. Uses binary Goppa codes. Largest key sizes of all NIST finalists but conservative security assumptions and established mathematical foundations.

PDF · 249 KB · a short read

DraftAlgorithm Specifications
TU Eindhoven; UC Berkeley; CWI AmsterdamOct 23, 2022
Trust 47Needs review
BIKE-Round4-Spec-2022Updated

Specification of BIKE (Bit Flipping Key Encapsulation), a code-based KEM advanced to NIST Round 4 alongside Classic McEliece and HQC. Defines parameter sets BIKE-1, BIKE-3, BIKE-5 (NIST Levels 1/3/5).

PDF · 811 KB · a long read

DraftAlgorithm Specifications
BIKE Team (Aragon, Barreto, Bettaieb, Bidoux, Blazy, Deneuville, Gaborit, Gueron, Guneysu, Misoczki, Persichetti, Sendrier, Tillich, Vasseur, Zemor)Oct 10, 2022
Trust 75Authoritative
NSA CNSA 2.0 FAQ

FAQ document with implementation timelines: 2025-2030 prefer, 2030-2033 exclusive, 2035 complete.

PDF · 442 KB · a long read

ReleasedGovernment & PolicyHigh
NSASep 7, 2022
Trust 83Authoritative
NIST-SP-800-108-R1Updated

NIST SP 800-108 Rev.1 specifies key derivation functions (KDFs) based on pseudorandom functions including counter mode feedback mode and double-pipeline mode using HMAC or CMAC. Directly implemented in PKCS#11 v3.0 as CKM_SP800_108_COUNTER_KDF and used in HSM-based QKD key derivation pipelines.

PDF · 745 KB · a long read

ReleasedNIST StandardsHigh1 rev
NISTAug 2022
Trust 84Authoritative
RFC 9052Updated

Defines COSE protocol for signatures, MACs, and encryption using CBOR serialization; critical path for PQC adoption in IoT and constrained device environments.

Web page · 313 KB · a long read

ReleasedProtocols1 rev
Jim Schaad (August Cellars)Aug 2022
Trust 66Needs review
RFC 9053Updated

Defines initial cryptographic algorithm identifiers for COSE (used in CBOR-based protocols like IoT, CWTLS, JOSE); ML-KEM and ML-DSA COSE algorithm IDs are being registered.

Web page · 252 KB · a long read

ReleasedProtocols
IETFAug 2022
Trust 84Authoritative
RFC-0793Updated

Transmission Control Protocol (TCP) — foundational IETF transport standard (1981), obsoleted by RFC 9293 (2022). Provides reliable, ordered, byte-stream delivery over IP. Underpins TLS, HTTPS, and virtually every PQC protocol deployment; referenced as a dependency in protocol migration analysis.

Web page · 264 KB · a long read

ReleasedProtocols
IETFAug 2022
Trust 79Authoritative
IACR-2022-952-FrodoKEM-RowhammerUpdated

Demonstrates end-to-end key recovery on FrodoKEM using Rowhammer DRAM bit flips. Forces key generation to produce high-error public keys, enabling decryption-failure attacks for full secret key recovery.

PDF · 850 KB · a long read

Research PaperIndustry & Research
IACR ePrintJul 23, 2022
Trust 63Needs review
NIST IR 8413Updated

Documents selection of CRYSTALS-Kyber (ML-KEM), CRYSTALS-Dilithium (ML-DSA), FALCON (FN-DSA), and SPHINCS+ (SLH-DSA) for standardization. Advances HQC, BIKE, Classic McEliece, and SIKE to Round 4.

PDF · 885 KB · a long read

ReleasedNIST Standards
NISTJul 5, 2022
Trust 77Authoritative
RFC-9258Updated

RFC 9258 defines an external PSK importer interface for TLS 1.3 (RFC 8446). It allows QKD-derived keys delivered via ETSI GS QKD 014 to be bound to a specific KDF and hash algorithm and imported as a TLS 1.3 pre-shared key — enabling QKD integration without any TLS protocol modifications.

Web page · 100 KB · a short read

ReleasedProtocolsHigh
IETF TLS Working GroupJul 2022
Trust 79Authoritative
ENISA-PQC-Integration-Study-2022Updated

ENISA study on integrating post-quantum cryptography into existing security protocols and systems. Analyzes PQC integration challenges for TLS, PKI, and code signing; provides recommendations for European organizations on algorithm selection and migration priorities.

PDF · 1.3 MB · a long read

MiscGovernment & Policy
ENISA; European Union Agency for CybersecurityJul 1, 2022
Trust 55Needs review
SALSA-2022-Lattice-TransformerUpdated

First published use of transformer models (the same architecture family behind modern LLMs) to attack LWE-based lattice cryptography — recovers sparse binary secrets for small-to-mid LWE dimensions (up to n=128). Does not threaten standardized ML-KEM/ML-DSA parameter sets, but establishes AI-assisted cryptanalysis as an active, real research direction against lattice-based PQC, not a hypothetical one.

Web page · 9 KB · a quick skim

Research PaperIndustry & Research
Emily Wenger; et al. (Meta AI / academic collaborators)Jul 2022
Trust 79Authoritative
SPHINCS-Plus-Spec-v31Updated

Official specification for SPHINCS+ (standardized as SLH-DSA in FIPS 205). A stateless hash-based signature scheme providing security based solely on hash function security. Covers SPHINCS+-SHA2 and SPHINCS+-SHAKE parameter sets at security levels 1, 3, and 5.

PDF · 1.0 MB · a long read

DraftAlgorithm SpecificationsHigh
TU Eindhoven; Ruhr University Bochum; UC BerkeleyJun 10, 2022
Trust 47Needs review
IMO-MSC-FAL-1-Circ-3-Rev-2-Guidelines-on-Maritime-Cyber-Risk

IMO guidelines on maritime cyber risk management — the baseline a vessel’s cryptographic posture is assessed against.

PDF · 425 KB · a long read

ReleasedInternational Frameworks
International Maritime Organization (IMO)Jun 7, 2022
Trust 84Authoritative
RFC-9110Updated

The Hypertext Transfer Protocol (HTTP) is a stateless application-level protocol for distributed, collaborative, hypertext information systems. This document describes the overall architecture of HTTP, establishes common terminology, and defines aspects of the protocol that are shared by all versions. In this definition are core protocol elements, extensibility mechanisms, and the "http" and "http

Web page · 4.7 MB · a long read

ReleasedProtocols
IETFJun 6, 2022
Trust 79Authoritative
CCCS-ITSAP40018

CCCS practical guidance on cryptographic agility — the ability to swap cryptographic algorithms via configuration without major software/hardware changes. Covers inventory, vendor selection (CMVP/CC certification), protocol negotiation, and phased quantum transition strategy. Companion to ITSAP.00.017 (quantum threat) and ITSM.40.001 (PQC migration roadmap).

Web page · 66 KB · a short read

ReleasedGovernment & PolicyHigh
Canadian Centre for Cyber Security (CCCS / CSE)May 17, 2022
Trust 64Needs review
NSM-10Updated

US National Security Memorandum directing federal agencies to inventory cryptographic systems and transition to PQC. Established key milestones for quantum-resistant standards adoption.

Web page · 164 KB · a long read

ReleasedGovernment & PolicyCritical
White HouseMay 4, 2022
Trust 65Needs review
McKinsey-PQC-PreparationUpdated

McKinsey Digital piece on sequencing PQC preparation, with inventory and governance as the first no-regret investments.

Web page · 183 KB · a long read

MiscMigration Guidance
McKinsey & CompanyMay 4, 2022
Trust 53Needs review
RFC-9242Updated

Defines intermediate exchange for IKEv2 enabling PQC key exchange payloads that exceed single-packet size limits.

Web page · 70 KB · a short read

ReleasedProtocolsHigh
IETFMay 2022
Trust 83Authoritative
ETSI-GS-QKD-015Updated

Defines the control interface between QKD network layer and SDN controllers for programmable quantum networks.

PDF · 519 KB · a long read

ReleasedProtocols
ETSI ISG QKDApr 2022
Trust 84Authoritative
ETSI-GS-QKD-018Updated

Orchestration interface for managing QKD resources in SDN environments. Defines YANG data models for interoperability between QKD network layer, SDN controllers, and orchestrators. Enables multi-domain key routing and programmable quantum networks.

PDF · 363 KB · a short read

ReleasedProtocols
ETSI ISG QKDApr 2022
Trust 84Authoritative
RFC 9147Updated

Specifies DTLS 1.3 — the UDP-based variant of TLS 1.3 used for CoAP and constrained IoT communications. Key reference for PQC handshake overhead analysis on constrained devices.

Web page · 265 KB · a long read

ReleasedProtocolsHigh1 rev
IETF TLSApr 2022
Trust 80Authoritative
RFC 9151Updated

NSA CNSA Suite profile for TLS and DTLS 1.2/1.3 — the cipher-suite, certificate and extension requirements a CNSA-compliant TLS deployment must meet. Superseded in direction by CNSA 2.0, which mandates ML-KEM and ML-DSA.

Web page · 96 KB · a short read

ReleasedProtocols
D. Cooley (NSA) — IETF Independent SubmissionApr 2022
Trust 62Needs review
RFC-9148Updated

Defines EST-coaps, carrying Enrollment over Secure Transport (EST, RFC 7030) certificate-provisioning payloads over CoAP secured with DTLS so constrained devices can enroll certificates. Not PQC-specific; it is a likely path for re-provisioning constrained devices with post-quantum certificates, where larger PQ payloads stress CoAP block transfer.

Web page · 193 KB · a long read

ReleasedPKI Certificate Management
IETF ACE WG; P. van der Stok; P. Kampanakis (Cisco Systems); M. Richardson (SSW); S. Raza (RISE)Apr 2022
Trust 55Needs review
RFC-9146Updated

This document specifies the Connection ID (CID) construct for the Datagram Transport Layer Security (DTLS) protocol version 1.2. A CID is an identifier carried in the record layer header that gives the recipient additional information for selecting the appropriate security association. In "classical" DTLS, selecting a security association of an incoming DTLS record is accomplished with the help

Web page · 86 KB · a short read

ReleasedProtocols
IETFMar 18, 2022
Trust 79Authoritative
CRYPTREC-LS-0003-2022R1-Criteria-for-Setting-Cryptographic-SUpdated

CRYPTREC’s criteria for setting cryptographic strength requirements, which is what decides when an algorithm leaves the approved list.

PDF · 1.4 MB · a long read

ReleasedGovernment & Policy
Digital Agency (Japan); Ministry of Internal Affairs and Communications (Japan); Ministry of Economy, Trade and Industry (Japan)Mar 2022
Trust 78Authoritative
EIP-4844Updated

Introduces blob-carrying transactions for L2 data availability; uses KZG commitments (elliptic curve pairings) with a future migration path to quantum-safe polynomial commitments.

Web page · 63 KB · a short read

ReleasedBlockchain Standards
Ethereum FoundationFeb 25, 2022
Trust 54Needs review
NIST SP 800-218Updated

Secure Software Development Framework (SSDF) Version 1.1

PDF · 740 KB · a long read

ReleasedGovernment & Policy
NISTFeb 2022
Trust 87Authoritative
RFC 9180Updated

Defines HPKE combining a KEM, KDF, and AEAD into a composable hybrid encryption scheme; used as the foundation for PQC hybrid KEM constructions (ML-KEM + X25519 HPKE modes).

Web page · 351 KB · a long read

ReleasedProtocolsHigh
IETFFeb 2022
Trust 80Authoritative
NSM-8Updated

NSM-8 extends EO-14028 cybersecurity requirements to NSS, DoD, and IC systems; mandates quantum-resistant cryptography migration timelines aligned with CNSA 2.0.

Web page · 176 KB · a long read

ReleasedGovernment & PolicyHigh
NSA; White HouseJan 19, 2022
Trust 59Needs review
Weger-Code-Based-Survey-2022Updated

Comprehensive survey covering code-based cryptographic schemes including McEliece, Niederreiter, and modern variants. Directly relevant to HQC (NIST-standardized 2025) and Classic McEliece (Round 4 finalist). Covers security reductions, parameter selection, and implementation considerations.

Web page · 42 KB · a short read

Research PaperAlgorithm Specifications
Violetta Weger; Niklas Gassner; Joachim Rosenthal (University of Zurich)Jan 18, 2022
Trust 69Needs review
RFC 9142Updated

Updates SSH key-exchange method recommendations: deprecates SHA-1 and short Diffie-Hellman groups, lists current recommended methods, and frames hybrid PQ KEX work that follows.

Web page · 578 KB · a long read

ReleasedProtocols
IETF (Baushke)Jan 13, 2022
Trust 88Authoritative
CDR-EU-2022-30-RED-CybersecurityUpdated

Commission Delegated Regulation that activates the Radio Equipment Directive's cybersecurity essential requirements (Art. 3(3)(d) network protection, (e) personal data/privacy, (f) fraud protection) for internet-connected, childcare, toy and wearable radio equipment. Not PQC-specific; it is the legal hook under which EN 18031 cryptography requirements apply to EU IoT radio products, so future PQC expectations for such devices would flow through it.

Web page · 303 KB · a long read

ReleasedCompliance & Certification
European CommissionJan 12, 2022
Trust 36Needs review
ANSSI-PQC-Position-2022Updated

ANSSI publishes France's position on PQC transition, advocating hybrid post-quantum/classical schemes as the primary migration path. Provides phased approach guidance for French government and regulated entities.

PDF · 188 KB · a short read

MiscGovernment & PolicyHigh
ANSSI; French National Cybersecurity AgencyJan 4, 2022
Trust 77Authoritative
CSC-API-v2-SpecUpdated

Cloud Signature Consortium API v2 for remote digital signature services. Defines endpoints for credential listing (/csc/v2/credentials/list) credential information (/csc/v2/credentials/info) authorization (/csc/v2/credentials/authorize) and hash signing (/csc/v2/signatures/signHash). Supports Qualified Electronic Signatures (QES) via remote HSMs. Adopted by eIDAS trust service providers (QTSPs) for EUDI Wallet-compatible SCAL2 signature services.

PDF · 4.1 MB · a reference document — dip in, don’t read it through

ReleasedMigration GuidanceHigh
Cloud Signature Consortium2022
Trust 54Needs review
ref-joseph-transitioning

Outlines organizational strategies, transition timelines, and standards guidance for migrating enterprise cryptographic systems to quantum-resistant algorithms as Shor’s algorithm threatens public-key cryptography.

PDF · 1.5 MB · a long read

ReleasedIndustry & Research
David Joseph; Rafael Misoczki; Marc Manzano; Joe Tricot; Fernando Dominguez Pinuaga; Olivier Lacombe; Stefan Leichenauer; Jack HidaryJan 1, 2022
Trust 32Needs review
Purchase required
The-New-Quantum-Safe-Algorithms-Are-Here-Now-What-KeyfactorUpdated

Web page · 141 KB · a short read

MiscMigration Guidance
Keyfactor2022
Trust 26Needs review
Industry-Today-Reports-Why-Cryptography-Needs-to-Change-QuSeUpdated

Web page · 79 KB · a short read

MiscMigration Guidance
Unknown2022
Trust 26Needs review
Classic-McEliece-Implementation

PDF · 280 KB · a short read

ReleasedMigration Guidance
Unknown2022
Trust 26Needs review
Luna-HSM-Firmware-v7-9-Release-NIST-Approved-PQC-AlgorithmsUpdated

Web page · 77 KB · a short read

MiscMigration Guidance
Data Protection Support - Product News, Downloads, Customer Release Notes, & More2022
Trust 26Needs review
Secure-Domain-Name-System-DNS-Deployment-GuideUpdated

PDF · 1.1 MB · a long read

ReleasedMigration Guidance
Unknown2022
Trust 26Needs review
ISO-21448-2022-Road-vehicles-Safety-of-the-intended-function

ReleasedMigration Guidance
ISO/IEC2022
Trust 9Needs review
Purchase required
Round-3-Additional-Signatures-Post-Quantum-Cryptography-AddiUpdated

Web page · 58 KB · a short read

MiscMigration Guidance
CSRC | NIST2022
Trust 26Needs review
FIDO-FDO-v1.1-PS

FIDO Alliance specification of the FIDO Device Onboard (FDO) protocol: zero-touch, late-binding onboarding of IoT devices to an owner's platform via device attestation, ownership vouchers and the DI/TO0/TO1/TO2 protocols. Its algorithms are RSA, ECDSA and (EC)DH only; the spec itself notes quantum computers as a reason a device certificate might need an expiry.

PDF · 1.4 MB · a long read

DraftProtocols
FIDO Alliance (Editors: Geoffrey Cooper (Intel); Brad Behm (Amazon); Ankur Chakraborty (Google); Hanu Kommalapati (Microsoft); Giri Mandyam (Qualcomm); Hannes Tschofenig (ARM))2022
Trust 48Needs review
RFC-9124Updated

Informational RFC describing the information model, threats and security requirements for a firmware-update manifest for IoT devices, the basis for the SUIT CBOR manifest. Not PQC-specific; it defines the signed-manifest trust model that firmware signing algorithms (and a move to PQ or hash-based signatures) must fit.

Web page · 263 KB · a long read

ReleasedProtocols
IETF SUIT WG; B. Moran; H. Tschofenig (Arm Limited); H. Birkholz (Fraunhofer SIT)Jan 2022
Trust 57Needs review
SAND2022-1118Updated

Sandia final report (SAND2022-1118, Jan 2022) of a DOE Solar Energy Technologies Office project that drafted DER cybersecurity standards recommendations through the SunSpec/Sandia workgroup and IEEE P1547.3. Documents that IEC 62351-3 requires TLS v1.2 or higher (TLS 1.0/1.1 still specified for backward compatibility) with X.509v3 certificates per IEC 62351-9 and mutual client/server authentication, and recommends at least TLS 1.2 (TLS 1.3 recommended), mutual authentication, AES-GCM/CCM and PKI with certificate revocation for all DER protocols.

PDF · 3.7 MB · a reference document — dip in, don’t read it through

MiscIndustry & Research
Sandia National Laboratories (J. Johnson, I. Onunkwo, D. Saleem, W. Hupp, J. Peterson, R. Cryar)2022
Trust 30Needs review
RFC-9155Updated

The MD5 and SHA-1 hashing algorithms are increasingly vulnerable to attack, and this document deprecates their use in TLS 1.2 and DTLS 1.2 digital signatures. However, this document does not deprecate SHA-1 with Hashed Message Authentication Code (HMAC), as used in record protection. This document updates RFC 5246.

Web page · 181 KB · a long read

ReleasedProtocols
IETFDec 20, 2021
Trust 78Authoritative
RFC-9162Updated

IETF Standards Track RFC defining Certificate Transparency Version 2.0. Obsoletes RFC 6962. Foundational for understanding the transparency log model that Merkle Tree Certificates extend for post-quantum TLS optimization. Specifies TLS extensions for CT log artifacts and certificate inclusion proofs.

Web page · 1.2 MB · a long read

ReleasedProtocols1 rev
IETFDec 9, 2021
Trust 81Authoritative
Lattice-EstimatorUpdated

SageMath-based tool for estimating the security of lattice-based cryptographic schemes against known attacks.

Web page · 376 KB · a long read

MiscIndustry & Research
Martin Albrecht et al.Oct 29, 2021
Trust 67Needs review
China OSCCA GM/T 0108-2021

Chinese cryptography industry standard (GM/T, recommended) for decoy-state BB84 QKD products, under the State Cryptography Administration (国家密码管理局). In force 2022-05-01. A QKD product specification, not a post-quantum cryptography specification.

ReleasedProtocolsHighReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (LM-068 regional remediation)
State Cryptography Administration / OSCCA (国家密码管理局); drafting unit 安徽问天量子科技股份有限公司Oct 19, 2021
Trust 54Needs review
RFC-9068Updated

IETF Standards Track RFC defining an interoperable JWT format for OAuth 2.0 access tokens: required claims, explicit typing with typ 'at+jwt', mandatory RS256 support, and the validation steps a resource server must perform. Not PQC-specific; it is the profile that PQC-signed access tokens would follow, and its RS256 baseline is a classical signature that needs a quantum-safe successor.

Web page · 105 KB · a short read

ReleasedProtocols
IETF; V. Bertocci (Auth0)Oct 2021
Trust 58Needs review
Ethereum-EIP4337-AAUpdated

Enables smart contract wallets on Ethereum without consensus-layer changes. As a PQC migration path, EIP-4337 smart accounts can verify ML-DSA or FALCON signatures on mainnet today — no protocol change required.

Web page · 106 KB · a short read

ReleasedIndustry & ResearchHigh
Vitalik Buterin; Yoav Weiss; Ethereum FoundationSep 29, 2021
Trust 47Needs review
OpenSSL-3x-Docs

Official OpenSSL documentation covering the 3.x series. OpenSSL 3.5.0 (April 2025) introduced native ML-KEM, ML-DSA, and SLH-DSA without the OQS provider. OpenSSL 3.6.1 (January 2026) is the current stable release.

Web page · 21 KB · a quick skim

ReleasedMigration Guidance
OpenSSL ProjectSep 7, 2021
Trust 51Needs review
ISO-18013-5-mDL

International standard defining the mso_mdoc credential format for mobile driving licences and identity documents. Specifies binary CBOR encoding document structure namespace (org.iso.18013.5.1; the EUDI eu.europa.ec.eudi.pid.1 doctype is defined by the ARF PID Rulebook, not by ISO) and cryptographic protection via Mobile Security Objects (MSO) signed by the issuer. Foundational for EUDI Wallet PID credentials and proximity presentations via NFC and BLE.

Web page · 93 KB · a short read

ReleasedInternational FrameworksHigh
ISO/IEC JTC1 SC17Sep 1, 2021
Trust 84Authoritative
CRYSTALS-Kyber-Spec-v302Updated

Official algorithm specification for CRYSTALS-Kyber (now standardized as ML-KEM in FIPS 203). Covers the IND-CCA2-secure KEM construction over module lattices, parameter sets, and security analysis from the KU Leuven COSIC / Ruhr University team.

PDF · 856 KB · a long read

Research PaperAlgorithm SpecificationsHigh
KU Leuven COSIC; Ruhr University Bochum; CWI AmsterdamAug 4, 2021
Trust 50Needs review
SPDX-Spec-ISO-5962Updated

Linux Foundation SPDX specification, standardized as ISO/IEC 5962:2021 — the general software bill of materials format focused on package/file provenance and license-compliance depth. Has no dedicated cryptography object model (see CBOM module for that gap and CycloneDX as the practical workaround).

Web page · 374 KB · a long read

ReleasedAlgorithm Specifications
Linux Foundation / SPDX ProjectAug 1, 2021
Trust 81Authoritative
EIP-3607Updated

Prevents hash-collision attacks by rejecting transactions from contract accounts; a cryptographic integrity measure referenced in noble/scure library security context.

Web page · 22 KB · a quick skim

ReleasedBlockchain Standards
Ethereum FoundationJun 10, 2021
Trust 53Needs review
RFC-9000Updated

This document defines the core of the QUIC transport protocol. QUIC provides applications with flow-controlled streams for structured communication, low-latency connection establishment, and network path migration. QUIC includes security measures that ensure confidentiality, integrity, and availability in a range of deployment circumstances. Accompanying documents describe the integration of TL

Web page · 2.9 MB · a long read

ReleasedProtocols
IETFMay 27, 2021
Trust 80Authoritative
EO-14028

Biden Administration EO mandating zero-trust architecture, software supply chain security, and encryption modernization across U.S. federal systems; predecessor to PQC mandates.

Web page · 134 KB · a short read

ReleasedGovernment & PolicyHigh
White HouseMay 17, 2021
Trust 66Needs review
ENISA PQC GuidelinesUpdated

ENISA recommendations on PQC adoption strategy for European organizations.

PDF · 1.1 MB · a long read

MiscInternational FrameworksHigh
ENISAMay 2021
Trust 69Needs review
RFC 9001Updated

Defines how QUIC uses TLS 1.3 for connection establishment and record protection; the PQC hybrid key exchange for TLS 1.3 applies directly to QUIC via this integration.

Web page · 251 KB · a long read

ReleasedProtocolsHigh
IETFMay 2021
Trust 84Authoritative
ref-gidney-factor-rsa-8hUpdated

Estimation of the physical resource costs and runtime for factoring 2048-bit RSA integers using optimized Shor’s algorithm on a noisy quantum computer.

PDF · 1.3 MB · a long read

Research PaperIndustry & Research
C. Gidney and M. EkerApr 15, 2021
Trust 44Needs review
RFC 9019Updated

Defines the SUIT manifest format for secure firmware updates on constrained IoT devices. Specifies metadata fields used in PQC firmware signing workflows.

Web page · 128 KB · a short read

ReleasedMigration Guidance
IETF SUITApr 2021
Trust 79Authoritative
EIP-3541Updated

Berlin hard fork change reserving the 0xEF contract bytecode prefix for EVM Object Format; part of the EVM upgrade path referenced by @noble/secp256k1 context.

Web page · 21 KB · a quick skim

ReleasedBlockchain Standards
Ethereum FoundationMar 16, 2021
Trust 54Needs review
UNECE-WP29-R155Updated

UNECE WP.29 UN Regulation 155 mandating cybersecurity management systems for motor vehicles. Requires OEM and supplier cryptographic controls, key management, and software update security. Applicable to all new vehicle type approvals from July 2022.

PDF · 449 KB · a long read

ReleasedCompliance & Certification
UNECE WP.29Mar 2021
Trust 61Needs review
RFC 8996Updated

Formally deprecates TLS 1.0 and TLS 1.1; combined with RFC 6176 and RFC 7568, clears the protocol floor to TLS 1.3 which is required for PQC hybrid key exchange.

Web page · 141 KB · a short read

ReleasedProtocolsHigh1 rev
IETFMar 2021
Trust 82Authoritative
RFC 8998Updated

Defines Chinese SM2/SM3/SM4 cipher suites for TLS 1.3; referenced in cross-national PQC interoperability discussions and Chinese national cryptography transition plans.

Web page · 86 KB · a short read

ReleasedProtocols
IETFMar 2021
Trust 78Authoritative
CRYSTALS-Dilithium-Spec-v31Updated

Official algorithm specification for CRYSTALS-Dilithium (now standardized as ML-DSA in FIPS 204). Covers the lattice-based digital signature scheme over module lattices with EUF-CMA security, parameter sets Dilithium2/3/5, and security proofs.

PDF · 1.2 MB · a long read

Research PaperAlgorithm SpecificationsHigh
KU Leuven COSIC; Ruhr University Bochum; INRIA France; ETH ZurichFeb 8, 2021
Trust 48Needs review
MAS-CIRCULAR-IT-RISKUpdated

Monetary Authority of Singapore Technology Risk Management Guidelines — cryptography, key management, resilience for FIs.

PDF · 593 KB · a long read

ReleasedCompliance & Certification
MASJan 18, 2021
Trust 85Authoritative
IEC 62443Updated

Multi-part IEC standard for security of industrial automation and control systems. Defense-in-depth framework for OT/ICS environments including energy, utilities, and aerospace. PQC relevant for long-lived OT deployments.

Web page · 165 KB · a long read

MiscAlgorithm Specifications
IEC TC 652021
Trust 80Authoritative
WCO-SAFE-Framework-of-Standards-2021Updated

The World Customs Organization framework securing global trade supply chains, including its data-exchange and authentication expectations.

PDF · 3.0 MB · a reference document — dip in, don’t read it through

ReleasedInternational Frameworks
World Customs Organization (WCO)2021
Trust 84Authoritative
UN-Regulation-No-155-Cyber-Security-and-Cyber-Security-ManagUpdated

The UN vehicle-type-approval regulation requiring a cyber security management system — the reason automotive cryptographic changes need a documented process, not just a patch.

Web page · 567 KB · a long read

ReleasedCompliance & Certification1 rev
UNECE World Forum for Harmonization of Vehicle Regulations (WP.29)2021
Trust 85Authoritative
Migration-to-Post-Quantum-Cryptography-Project-DescriptionUpdated

PDF · 396 KB · a short read

MiscMigration Guidance
Unknown2021
Trust 31Needs review
Fee-StructureUpdated

Web page · 1.1 MB · a long read

MiscMigration Guidance
Unknown2021
Trust 26Needs review
The-early-days-of-experimental-quantum-cryptographyUpdated

Web page · 32 KB · a quick skim

Research PaperMigration Guidance
IBM Research2021
Trust 26Needs review
ISO-SAE-21434-2021-Road-vehicles-Cybersecurity-engineering

ReleasedMigration Guidance
ISO/IEC2021
Trust 9Needs review
Purchase required
PSA-Certified-Security-Model-v1-1Updated

Arm's Platform Security Model 1.1 (beta) sets out the 10 security goals and the Platform Root of Trust (secure boot, firmware update, attestation, secure storage, lifecycle) that underlie the PSA Certified framework for connected devices. Not PQC-specific; relevant to PQC migration because the root-of-trust signing, attestation and binding keys it defines are long-lived and must eventually move to quantum-safe algorithms.

PDF · 1.9 MB · a reference document — dip in, don’t read it through

DraftCompliance & Certification
Arm Limited (PSA Certified)2021
Trust 34Needs review
Alghamdi-Schukat-Cybersecurity-2021-4-12Updated

Peer-reviewed NUI Galway paper (Cybersecurity, 2021) analysing internal and external attack strategies against IEEE 1588 PTP networks and testing them on a testbed. Documents the IEEE 1588-2019 (PTP v2.1) Annex P security extension's four prongs: A integrated TLV message authentication (shared group key or TESLA delayed processing), B external transport security (IPsec, MACsec), C architecture guidance (redundancy) and D monitoring and management - and notes Annex K is obsolete.

Web page · 479 KB · a long read

Research PaperIndustry & Research
Waleed Alghamdi; Michael Schukat (School of Computer Science, National University of Ireland, Galway)2021
Trust 58Needs review
Chen-Sensors-2020-20-7345Updated

PTB (German national metrology institute) peer-reviewed paper in MDPI Sensors (2020) on resampling algorithms for precise amplitude/phase calibration of IEC 61850-9-2 Sampled Value instruments. Its Table 1 documents the IEC 61869-9 standard SV sample rates (4000, 4800, 5760, 12,800, 14,400, 15,360 and 96,000 Hz, with 4800, 14,400 and 96,000 marked preferred) and the standard's 10 mV / 1 mA amplitude quantisation.

Web page · 137 KB · a short read

Research PaperIndustry & Research
Yeying Chen, Enrico Mohns, Michael Seckelmann, Soeren de Rose (Physikalisch-Technische Bundesanstalt, PTB)Dec 21, 2020
Trust 58Needs review
KMIP-V2-1-OASISUpdated

KMIP v2.1 defines a protocol for communication between key management systems and cryptographic clients. Supports key lifecycle operations (create, locate, get, activate, revoke, destroy) over TLS. Widely implemented by enterprise HSMs (Thales, Utimaco, Entrust) and KMS solutions. Enables interoperability between key management infrastructure during PQC migration.

Web page · 3.4 MB · a long read

ReleasedProtocolsHigh
OASIS KMIP Technical CommitteeDec 14, 2020
Trust 65Needs review
DCSA-Information-Model-v3-0

The Digital Container Shipping Association’s data model for container logistics interchange.

PDF · 2.6 MB · a reference document — dip in, don’t read it through

ReleasedProtocols
Digital Container Shipping AssociationDec 8, 2020
Trust 57Needs review
RFC 8879Updated

Defines certificate compression for TLS 1.3, reducing PQC certificate chain overhead by ~30%. Key mitigation for certificate bloat on constrained IoT devices.

Web page · 60 KB · a short read

ReleasedProtocols
IETF TLSDec 2020
Trust 80Authoritative
NIST SP 800-181r1Updated

Establishes the NICE Framework taxonomy of cybersecurity Work Roles, Competency Areas, and Task/Knowledge/Skill (TKS) statements for building and assessing the cyber workforce. The hub maps its learning roles and competency areas to this framework (Components v2.2.0, 2025).

PDF · 519 KB · a long read

ReleasedMigration Guidance
NISTNov 16, 2020
Trust 86Authoritative
UK NCSC PQC GuidanceUpdated

UK NCSC position paper on quantum computing threat to public-key cryptography; recommends QSC following NIST standardisation; rejects QKD for government/military use.

Web page · 142 KB · a short read

MiscGovernment & PolicyHighReviewed (LLM) · eramusa · May 2026 · via local commit
UK NCSCNov 11, 2020
Trust 79Authoritative
NERC-CIP-010-4Updated

NERC Reliability Standard CIP-010-4 sets configuration change management, configuration monitoring, vulnerability assessment and transient-asset/removable-media requirements for BES Cyber Systems; Part 1.6 requires verifying the identity of the software source and the integrity of software before baseline changes on high and medium impact systems. Not PQC-specific; relevant to PQC migration because software source/integrity verification typically rests on classical code-signing signatures.

PDF · 354 KB · a short read

ReleasedCompliance & Certification
NERCNov 5, 2020
Trust 62Needs review
Gartner-CryptoCOE-MahdiUpdated

Canonical CryptoCOE framing by David Mahdi (then Gartner): centralized operating model for cryptographic governance and modernization.

Web page · 220 KB · a long read

MiscMigration Guidance
David Mahdi (Entrust / formerly Gartner)Nov 2020
Trust 42Needs review
DFARS-252.204-7012Updated

DFARS clause requiring adequate security (NIST SP 800-171) for covered defense information and 72-hour cyber incident reporting.

Web page · 121 KB · a short read

ReleasedCompliance & CertificationHigh
US DoD; DAR CouncilNov 1, 2020
Trust 64Needs review
DFARS-252.204-7019Updated

DFARS provision requiring offerors to have a current NIST SP 800-171 DoD Assessment on record in SPRS.

Web page · 113 KB · a short read

ReleasedCompliance & CertificationHigh
US DoD; DAR CouncilNov 1, 2020
Trust 64Needs review
DFARS-252.204-7020Updated

DFARS clause defining Basic/Medium/High NIST SP 800-171 DoD Assessment methodology and contractor cooperation requirements.

Web page · 118 KB · a short read

ReleasedCompliance & CertificationHigh
US DoD; DAR CouncilNov 1, 2020
Trust 64Needs review
NIST SP 800-208Updated

Specifies LMS and XMSS stateful hash-based signature schemes for firmware signing.

PDF · 873 KB · a long read

ReleasedDigital Signature
NISTOct 29, 2020
Trust 86Authoritative
Falcon-Spec-v12

Official specification for the Falcon submission selected by NIST as the basis for the planned FN-DSA standard. FIPS 206 remains in development; NIST has not published an Initial Public Draft or final standard. Falcon is a lattice-based signature scheme based on the NTRU lattice with compact signatures using the GPV framework and fast Fourier sampling. The Falcon specification provides the smallest signatures among NIST PQC signature finalists, but its parameters must not be represented as final FIPS 206 parameters.

PDF · 382 KB · a short read

ReleasedAlgorithm SpecificationsHighReviewed (LLM) · maintainer (automated) · Jul 2026 · via automated, plan-driven remediation (pqctoday-hub-remediation-plans-07082026/library.md, all items P1-P3); facts re-verified against rfc-editor.org, csrc.nist.gov, etsi.org, and live HTTP checks on 2026-07-09; local commit db9d8b2e on fix/hub-remediation-wave2-0708 (branch wave2-library-0708), not yet merged/pushed
INRIA France; MIT CSAIL; NTT ResearchOct 6, 2020
Trust 48Needs review
NIST-FIPS140-3-IG-PQCUpdated

Updated FIPS 140-3 Implementation Guidance adding self-test requirements for FIPS 203/204/205 PQC algorithms and new guidance for Key Encapsulation Mechanisms.

PDF · 2.6 MB · a reference document — dip in, don’t read it through

ReleasedNIST StandardsHigh1 revReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
NIST CMVPSep 21, 2020
Trust 78Authoritative
draft-ietf-tls-semistatic-dhUpdated

TLS 1.3 [RFC8446] specifies a signed Diffie-Hellman exchange modelled after SIGMA [SIGMA]. This design is suitable for endpoints whose certified credential is a signing key, which is the common situation for current TLS servers. This document describes a mode of TLS 1.3 in which one or both endpoints have a certified DH key which is used to authenticate the exchange. Note to Read

Web page · 14 KB · a quick skim

ExpiredProtocols
IETFSep 8, 2020
Trust 74Authoritative
CMVP-MGMT-MANUALUpdated

NIST Cryptographic Module Validation Program management manual — governs the CMVP lifecycle, lab conduct, certification issuance, and maintenance reporting.

PDF · 886 KB · a long read

ReleasedCompliance & CertificationReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
NIST CMVPSep 2020
Trust 89Authoritative
EIP-2929Updated

Berlin hard fork gas cost adjustments for EVM state access opcodes; indirectly affects PQC smart contract deployment costs due to larger key/signature sizes.

Web page · 42 KB · a short read

ReleasedBlockchain Standards
Ethereum FoundationSep 1, 2020
Trust 54Needs review
NIST SP 800-53Updated

Security and Privacy Controls for Information Systems and Organizations

PDF · 6.1 MB · a reference document — dip in, don’t read it through

ReleasedGovernment & Policy2 revs
NISTSep 2020
Trust 88Authoritative
EIP-2930Updated

Defines optional access list transaction type (EIP-2718 type 1); relevant to noble/scure crypto library ecosystem referenced in the library.

Web page · 28 KB · a quick skim

ReleasedBlockchain Standards
Ethereum FoundationAug 29, 2020
Trust 55Needs review
ARINC-Standard-827Updated

Defines the electronic distribution of software to aircraft, including how loadable software is signed — a signature-size-sensitive path under PQC.

Web page · 138 KB · a short read

ReleasedAlgorithm Specifications
Airlines Electronic Engineering Committee (AEEC); SAE Industry Technologies Consortia IAAug 10, 2020
Trust 71Authoritative
ETSI-GS-QKD-004Updated

Specifies the application programming interface for accessing QKD-generated keys from applications.

PDF · 695 KB · a long read

ReleasedProtocols
ETSI ISG QKDAug 2020
Trust 85Authoritative
NIST-SP-800-56C-R2Updated

NIST SP 800-56C Rev.2 specifies one-step and extraction-then-expansion (EtE) key derivation methods for key-establishment schemes. The EtE approach supports hybrid shared secrets combining classical DH or PQC KEM output with a QKD-sourced entropy value — directly applicable to quantum-hybrid key exchange architectures.

PDF · 695 KB · a long read

ReleasedNIST StandardsHigh
NISTAug 2020
Trust 85Authoritative
NIST SP 800-207Updated

This document defines Zero Trust Architecture (ZTA) principles, logical components, and deployment models to shift cybersecurity defenses from network perimeters to users, assets, and resources.

PDF · 967 KB · a long read

ReleasedNIST Standards
NISTAug 2020
Trust 88Authoritative
ETSI-TS-103-673Updated

ETSI technical specification defining quantum-safe hybrid key exchange mechanisms for TLS and IKEv2 protocols.

PDF · 667 KB · a long read

ReleasedProtocolsHigh
ETSI TC CYBER QSCAug 2020
Trust 88Authoritative
NIST IR 8309Updated

Evaluates 26 second-round candidate algorithms and selects 7 finalists (CRYSTALS-Kyber/Dilithium, FALCON, NTRU, SABER, Classic McEliece, SPHINCS+) plus 8 alternates for Round 3.

PDF · 587 KB · a long read

ReleasedNIST Standards
NISTJul 22, 2020
Trust 76Authoritative
ETSI TR 103 619Updated

Strategic guidance for transitioning to quantum-safe cryptography.

PDF · 143 KB · a short read

ReleasedInternational Frameworks
ETSI QSCJul 2020
Trust 91Authoritative
NIST-SP-800-210-General-Access-Control-Guidance-for-Cloud-Sy

NIST’s general access-control guidance for cloud systems.

PDF · 1.3 MB · a long read

ReleasedMigration Guidance
NISTJul 2020
Trust 61Needs review
RFC-8792Updated

This document defines two strategies for handling long lines in width-bounded text content. One strategy, called the "single backslash" strategy, is based on the historical use of a single backslash ('\') character to indicate where line-folding has occurred, with the continuation occurring with the first character that is not a space character (' ') on the next line. The second strategy, called

Web page · 403 KB · a long read

ReleasedProtocols
IETFJun 29, 2020
Trust 78Authoritative
EMV-Break-Fix-Verify-2021Updated

Peer-reviewed formal analysis of the EMV protocol (IEEE S&P 2021, ETH Zurich). Documents offline data authentication SDA/DDA/CDA and their RSA basis. Open-access substitute for the registration-gated EMV Book 2. Verified: rsa x13, SDA x42, DDA x37, CDA x21, ECDSA x0.

PDF · 1.6 MB · a reference document — dip in, don’t read it through

Research PaperIndustry & ResearchHigh
D. Basin, R. Sasse, J. Toro-Pozo (ETH Zurich)Jun 15, 2020
Trust 74Authoritative
EIP-2718Updated

Defines a typed transaction envelope format allowing multiple transaction types; enables extensible transaction formats for future PQC signature-compatible Ethereum transactions.

Web page · 24 KB · a quick skim

ReleasedBlockchain Standards
Ethereum FoundationJun 13, 2020
Trust 54Needs review
RFC 8784Updated

Adds PPK (Post-quantum Preshared Key) to IKEv2 for quantum resistance.

Web page · 96 KB · a short read

ReleasedProtocols
IETF IPSECMEJun 2020
Trust 60Needs review
BLE-Key-Negotiation-Downgrade-2020Updated

Peer-reviewed analysis (ACM TOPS; Oxford) of Bluetooth and BLE key negotiation. Documents that Secure Connections pairing derives the Long Term Key via ECDH on NIST P-256. Open-access substitute for the registration-gated Bluetooth Core Specification. Verified: ECDH x8, P-256 x3, ECDSA x0.

PDF · 2.4 MB · a reference document — dip in, don’t read it through

Research PaperIndustry & Research
D. Antonioli, N. O. Tippenhauer, K. RasmussenJun 1, 2020
Trust 62Needs review
PCI-PTS-Program-Guide-v1-9

PCI PTS Device Testing and Approval Program Guide, Version 1.9 (June 2020): the last publicly downloadable edition of the PTS program guide.

PDF · 1.6 MB · a reference document — dip in, don’t read it through

HistoricalCompliance & CertificationReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
PCI Security Standards CouncilJun 2020
Trust 34Needs review
ANSSI-CC-PP-2016-05-M01Updated

ANSSI maintenance report ANSSI-CC-PP-2016/05-M01 (Paris, 18 May 2020), in French, for the protection profile EN 419221-5:2018 E version 1.0, with certificate ANSSI-CC-PP-2016/05 as its reference.

PDF · 167 KB · a short read

MiscCompliance & Certification
ANSSIMay 18, 2020
Trust 34Needs review
NIST-SP-800-57-Pt1-R5Updated

Primary NIST key management guideline covering key lifecycle (generation, distribution, storage, usage, rotation, archival, destruction), key types, cryptoperiods, FIPS 140 integration, and key compromise procedures. Foundation for all enterprise key management policy and HSM deployment.

PDF · 1.7 MB · a reference document — dip in, don’t read it through

ReleasedMigration GuidanceHigh
NISTMay 4, 2020
Trust 57Needs review
RFC 8778Updated

HSS/LMS signatures for CBOR Object Signing for IoT devices.

Web page · 89 KB · a short read

ReleasedProtocols
IETF COSEApr 2020
Trust 60Needs review
NIST-SP-800-175BUpdated

SP 800-175B Rev 1 defines approved cryptographic mechanisms for U.S. federal use including symmetric encryption, hash functions, digital signatures, and key establishment. Primary mapping target for NIST IR 8477 concept mappings. Superseded in PQC context by FIPS 203/204/205 but remains the baseline cryptographic guidance framework.

PDF · 1.4 MB · a long read

ReleasedNIST Standards
NISTMar 31, 2020
Trust 78Authoritative
NIST-SP-800-140AUpdated

Modifies Section 6.1 of ISO/IEC 24759 with US-specific CMVP documentation requirements.

PDF · 288 KB · a short read

ReleasedCompliance & CertificationReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
NISTMar 2020
Trust 87Authoritative
NIST-SP-800-140EUpdated

Approved authentication mechanisms for operators accessing FIPS 140-3 validated modules.

PDF · 362 KB · a short read

ReleasedCompliance & CertificationReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
NISTMar 2020
Trust 87Authoritative
NIST-SP-800-140FUpdated

Test methods required under FIPS 140-3 for non-invasive attack mitigation (side channels).

PDF · 304 KB · a short read

ReleasedCompliance & CertificationReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
NISTMar 2020
Trust 87Authoritative
RFC 8755Updated

NSA CNSA Suite algorithm identifiers for X.509 certificates and CRLs; being extended by ML-DSA CNSA 2.0 certificate profile.

Web page · 95 KB · a short read

ReleasedPKI Certificate ManagementHigh
IETF; NSAMar 2020
Trust 79Authoritative
RFC 8756Updated

NSA CNSA Suite algorithm profile for CMS signed data and enveloped data; provides the baseline NSA-approved CMS profile that CNSA 2.0 PQC algorithms extend.

Web page · 102 KB · a short read

ReleasedProtocolsHigh
IETF; NSAMar 2020
Trust 79Authoritative
NIST-SP-800-140Updated

NIST SP 800-140 (March 2020): the CMVP validation authority updates to ISO/IEC 24759, the test-requirements standard FIPS 140-3 uses for module testing.

PDF · 409 KB · a long read

ReleasedCompliance & CertificationReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
NIST (Kim Schaffer)Mar 2020
Trust 34Needs review
RFC-8705Updated

This document describes OAuth client authentication and certificate-bound access and refresh tokens using mutual Transport Layer Security (TLS) authentication with X.509 certificates. OAuth clients are provided a mechanism for authentication to the authorization server using mutual TLS, based on either self-signed certificates or public key infrastructure (PKI). OAuth authorization servers are p

Web page · 549 KB · a long read

ReleasedProtocols
IETFFeb 28, 2020
Trust 79Authoritative
RFC-8707Updated

This document specifies an extension to the OAuth 2.0 Authorization Framework defining request parameters that enable a client to explicitly signal to an authorization server about the identity of the protected resource(s) to which it is requesting access.

Web page · 263 KB · a long read

ReleasedProtocols
IETFFeb 28, 2020
Trust 79Authoritative
IETF RFC 8709Updated

Ed25519 and Ed448 Public Key Algorithms for the Secure Shell (SSH) Protocol

Web page · 215 KB · a long read

ReleasedProtocols
IETFFeb 25, 2020
Trust 89Authoritative
IETF RFC 8731Updated

Defines curve25519-sha256 and curve448-sha512 key exchange for SSH. The classical KEX baseline that mlkem768x25519-sha256 hybrid extends for post-quantum SSH in OpenSSH 9.9+.

Web page · 51 KB · a short read

ReleasedProtocolsHigh
IETF CURDLE WGFeb 2020
Trust 90Authoritative
RFC 8725Updated

Documents security pitfalls and best practices for JWT usage including algorithm confusion attacks, none-algorithm vulnerabilities, audience validation, and expiry enforcement. Essential security hardening baseline before migrating JWT signing algorithms to PQC alternatives.

Web page · 89 KB · a short read

ReleasedProtocolsHigh
IETFFeb 2020
Trust 80Authoritative
RFC 8708

Specifies how to use IETF/NIST HSS/LMS stateful hash-based signature algorithm within CMS; relevant for long-lived document signing with PQC algorithms.

Web page · 77 KB · a short read

DraftProtocolsHigh
IETF; R. HousleyFeb 2020
Trust 80Authoritative
China CACR PQC Competition Results

Results of CACR national PQC competition: Aigi-sig, LAC.PKE, Aigis-enc (lattice-based).

Web page · 30 KB · a quick skim

ReleasedGovernment & Policy
CACR ChinaFeb 1, 2020
Trust 51Needs review
BIP-340Updated

Defines 64-byte Schnorr signatures for secp256k1 with provable security, batch verification, and key aggregation (MuSig2). Required foundation for Taproot (BIP-341). BIP-360 (P2QRH) targets Taproot's Schnorr key-spend path as the primary quantum vulnerability to replace with post-quantum signatures.

Web page · 40 KB · a quick skim

ReleasedAlgorithm Specifications
Pieter Wuille; Jonas Nick; Tim Ruffing (Bitcoin Core)Jan 19, 2020
Trust 54Needs review
BIP-341Updated

Activates Taproot on Bitcoin (block 709632). Defines SegWit v1 spending with a Schnorr key-spend path and Merklized Abstract Syntax Tree (MAST) script-spend path. BIP-360 (P2QRH) specifically removes the key-spend path as quantum-vulnerable under Shor's algorithm and proposes a SegWit v3 (bc1r...) replacement.

Web page · 44 KB · a short read

ReleasedProtocols
Pieter Wuille; Jonas Nick; Anthony Towns (Bitcoin Core)Jan 19, 2020
Trust 53Needs review
ref-defeo-sqisignUpdated

Introduction of SQISign, a compact post-quantum signature scheme based on isogenies of supersingular elliptic curves and quaternion algebras.

PDF · 783 KB · a long read

Research PaperIndustry & Research
L. D. Feo et al.2020
Trust 47Needs review
NIAP-CCEVS-MANUALUpdated

NIAP CCEVS operational quality manual — roles, procedures, evaluation workflow, and assurance maintenance.

PDF · 861 KB · a long read

ReleasedCompliance & Certification
NIAPJan 2020
Trust 84Authoritative
Saudi-NCA-NCS1-2020Updated

Saudi Arabia National Cybersecurity Authority National Cryptographic Standards. Defines approved symmetric, asymmetric, and hash algorithms for Saudi government and critical infrastructure. Basis for ECC-2 cryptographic controls.

PDF · 1.1 MB · a long read

ReleasedInternational Frameworks
Saudi NCA2020
Trust 61Needs review
RFC 8702Updated

Specifies SHAKE128 and SHAKE256 (from FIPS 202) for use in CMS signatures; directly bridges FIPS 202 XOFs to the CMS layer used by PQC signing protocols.

Web page · 79 KB · a short read

ReleasedProtocolsHigh
IETFJan 2020
Trust 79Authoritative
Quantum-Computing-and-Post-Quantum-Cryptography-FAQsUpdated

PDF · 264 KB · a short read

MiscMigration Guidance
Unknown2020
Trust 31Needs review
Entanglement-based-secure-quantum-cryptography-over-1-120-kiUpdated

Web page · 549 KB · a long read

Research PaperMigration Guidance
Nature2020
Trust 26Needs review
Guide-to-IPsec-VPNsUpdated

PDF · 3.1 MB · a reference document — dip in, don’t read it through

ReleasedProtocols
Unknown2020
Trust 26Needs review
GR740-Radiation-SummaryUpdated

PDF · 1.3 MB · a long read

MiscMigration Guidance
Unknown2020
Trust 26Needs review
IEC-62351-6-2020-Power-systems-management-and-associated-inf

ReleasedMigration Guidance
IEC2020
Trust 9Needs review
Purchase required
NIST-IR-8259

NIST report describing six foundational pre-market and post-market cybersecurity activities for IoT device manufacturers, companion to the NISTIR 8259A core baseline; withdrawn on 2026-04-20 and superseded by NIST IR 8259r1. Not PQC-specific; its guidance to plan device cybersecurity capabilities (including cryptographic hardware) before market is relevant to building crypto-agility into long-lived IoT devices.

PDF · 1.6 MB · a reference document — dip in, don’t read it through

HistoricalCompliance & Certification
NIST (Michael Fagan; Katerina N. Megas; Karen Scarfone; Matthew Smith)2020
Trust 56Needs review
ASHRAE-135-2016-Addendum-bjUpdated

ANSI/ASHRAE Addendum bj to Standard 135-2016 introduces BACnet Secure Connect (BACnet/SC), a BACnet datalink option using TLS 1.3-secured WebSocket connections in a hub-and-spoke topology, with each node holding a CA-signed X.509 operational certificate. Not PQC-specific; relevant to PQC migration because BACnet/SC security for building automation depends on TLS 1.3 key exchange and certificate-based authentication that must move to quantum-safe algorithms.

PDF · 1.7 MB · a reference document — dip in, don’t read it through

ReleasedProtocolsReviewed (LLM) · eramusa · Oct 2026 · via manual data edit (library)
ASHRAE SSPC 135Nov 18, 2019
Trust 62Needs review
Liboqs-goUpdated

Go wrapper for the liboqs C library providing PQC algorithm access for Go applications.

Web page · 370 KB · a long read

MiscImplementations
Open Quantum SafeOct 16, 2019
Trust 76Authoritative
ITU-T-X509-2019Updated

Foundational ITU-T/ISO standard defining X.509 PKI certificate frameworks. Section 9.8 introduces Alternative Cryptographic Algorithms extensions (OIDs 2.5.29.72-74: SubjectAltPublicKeyInfo / AltSignatureAlgorithm / AltSignatureValue) enabling hybrid certificate support — the basis for Alt-Sig / Catalyst hybrid quantum-safe certificates.

PDF · 3.6 MB · a reference document — dip in, don’t read it through

ReleasedPKI Certificate ManagementHigh
ITU-T Study Group 17Oct 14, 2019
Trust 78Authoritative
IACR-2019-1086Updated

Peer-reviewed paper (ACM CCS 2019) presenting the formal security analysis of SPHINCS+ / SLH-DSA. Proves security in the multi-function multi-target one-way (MFOTW) model and analyzes the tight security reductions. Covers the WOTS+ one-time signature, FORS few-time signature, and HT hypertree structure.

PDF · 2.2 MB · a reference document — dip in, don’t read it through

Research PaperAlgorithm SpecificationsHigh
TU Eindhoven; Ruhr University Bochum; Stanford ACG; UC BerkeleySep 23, 2019
Trust 46Needs review
BLE-Low-Entropy-Key-Negotiation-2019Updated

IACR ePrint analysis of BLE Secure Connections; confirms ECDH on the P-256 curve for pairing. Corroborates BLE-Key-Negotiation-Downgrade-2020. Verified: ECDH x3, P-256 x2, ECDSA x0.

PDF · 817 KB · a long read

Research PaperIndustry & Research
D. Antonioli, N. O. Tippenhauer, K. RasmussenAug 1, 2019
Trust 68Needs review
RFC-8613Updated

Defines OSCORE, end-to-end application-layer protection of CoAP (and CoAP-mappable HTTP) messages using COSE, designed for constrained nodes and proxies; updates RFC 7252. Not PQC-specific; its symmetric protection depends on a shared master secret, so PQC exposure sits in the key-establishment protocol used with it (e.g. EDHOC/LAKE).

Web page · 261 KB · a long read

ReleasedProtocols
IETF CORE WG; G. Selander; J. Mattsson; F. Palombini (Ericsson AB); L. Seitz (RISE)Jul 2019
Trust 55Needs review
RFC-8610

This document proposes a notational convention to express Concise Binary Object Representation (CBOR) data structures (RFC 7049). Its main goal is to provide an easy and unambiguous way to express structures for protocol messages and data formats that use CBOR or JSON.

Web page · 566 KB · a long read

ReleasedProtocols
IETFJun 12, 2019
Trust 79Authoritative
RFC 8603Updated

NSA CNSA Suite X.509 certificate and CRL profile — the algorithm, key size and extension requirements for certificates used in National Security Systems. The TLS/DTLS cipher-suite profile is RFC 9151, a separate document.

Web page · 40 KB · a short read

ReleasedProtocolsHigh
IETF; NSAMay 2019
Trust 80Authoritative
RFC 8551Updated

S/MIME 4.0 email security standard for signing and encrypting email using CMS. Foundation for PQC email migration via RFC 9629 (KEM) and RFC 9882 (ML-DSA).

Web page · 183 KB · a long read

ReleasedProtocolsHigh1 rev
IETF LAMPSApr 2019
Trust 85Authoritative
RFC 8554Updated

Stateful hash-based signature scheme LMS. Updated by RFC 9858.

Web page · 157 KB · a long read

ReleasedIndustry & Research
IETF CFRGApr 2019
Trust 56Needs review
FIPS-140-3-STANDARDUpdated

Federal standard defining the security requirements for cryptographic modules (PKCS#11, HSMs, software libraries) validated under CMVP.

PDF · 311 KB · a short read

ReleasedCompliance & Certification1 revReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
NISTMar 22, 2019
Trust 86Authoritative
IETF RFC 8555Updated

Automatic Certificate Management Environment (ACME)

Web page · 855 KB · a long read

ReleasedMigration Guidance
IETFMar 11, 2019
Trust 88Authoritative
NIAP-CCEVS-POLICYUpdated

Latest NIAP CCEVS policy letter governing scheme operation; representative of the policy-letter series.

PDF · 297 KB · a short read

ReleasedCompliance & Certification
NIAPMar 2019
Trust 85Authoritative
NIST-SP-800-56BUpdated

SP 800-56B Rev 2 specifies RSA-based key establishment for U.S. federal use; superseded by ML-KEM per PQC migration timelines.

PDF · 1.8 MB · a reference document — dip in, don’t read it through

ReleasedNIST StandardsHigh
NISTMar 2019
Trust 80Authoritative
Liboqs-cppUpdated

C++ wrapper for the liboqs C library providing object-oriented PQC algorithm access.

Web page · 362 KB · a long read

MiscImplementations
Open Quantum SafeFeb 14, 2019
Trust 76Authoritative
PI-PROFINET-Security-Whitepaper-V105-2019

PROFIBUS & PROFINET International white paper (V1.05, Feb 2019) setting out the security concept for PROFINET protocol extensions, aligned with IEC 62443. Defines three PROFINET Security Classes - 1 Robustness (e.g. changeable SNMP default strings, read-only DCP, signed GSD files), 2 Integrity + Authenticity (cryptographically protected cyclic and acyclic communication, confidential configuration data), 3 Confidentiality (adds encryption) - using device certificates for start-up key negotiation and a MAC over cyclic frames (HMAC-SHA256 best performer, not finally selected).

PDF · 1.6 MB · a reference document — dip in, don’t read it through

ReleasedProtocols
PROFIBUS & PROFINET International (PI) Working Group Security CB/PG 10 (ed. Karl-Heinz Niemann); publisher PROFIBUS Nutzerorganisation e.V.Feb 12, 2019
Trust 51Needs review
ETSI-GS-QKD-012Updated

Control interface specification for QKD device parameters and communication channel monitoring.

PDF · 387 KB · a short read

ReleasedProtocols
ETSI ISG QKDFeb 2019
Trust 83Authoritative
ETSI-GS-QKD-014Updated

RESTful API specification for key delivery between QKD nodes and applications. Widely implemented reference API.

PDF · 459 KB · a long read

ReleasedProtocolsHigh1 rev
ETSI ISG QKDFeb 2019
Trust 85Authoritative
DVB-BlueBook-A165-Extensions-to-the-CI-Plus-SpecificationUpdated

DVB extensions to CI Plus, the conditional-access interface in broadcast receivers.

PDF · 2.0 MB · a reference document — dip in, don’t read it through

ReleasedInternational Frameworks
DVB Project / EBU-CENELEC-ETSI Joint Technical Committee BroadcastFeb 2019
Trust 72Authoritative
ASC-X9-TR-50-2019Updated

ASC X9 Technical Report investigating use of Cryptographic Message Syntax (CMS) in the presence of a quantum-capable attacker. Provides recommendations for using quantum-safe cryptography within CMS and migrating classical financial systems to quantum-safe algorithms. Published by the X9F4 workgroup.

PDF · 627 KB · a long read

ReleasedProtocols
ASC X9; X9F4 WorkgroupJan 20, 2019
Trust 67Needs review
PQCleanUpdated

Clean reference C implementations of all NIST PQC finalists and candidates. Designed for easy integration and auditing.

Web page · 368 KB · a long read

MiscImplementations
PQClean ContributorsJan 11, 2019
Trust 66Needs review
RU-Nijmegen-EMV-Course-NotesUpdated

University course material on EMV card authentication, covering SDA, DDA and CDA and the RSA signatures they rely on. Teaching material, not a specification — cited as corroborating evidence alongside the peer-reviewed analysis. Verified: SDA x17, DDA x22, CDA x10, ECDSA x0.

PDF · 1.9 MB · a reference document — dip in, don’t read it through

MiscIndustry & Research
Erik Poll, Radboud University NijmegenJan 1, 2019
Trust 54Needs review
Guidelines-for-the-Selection-Configuration-and-Use-of-TranspUpdated

PDF · 815 KB · a long read

ReleasedProtocols
Unknown2019
Trust 26Needs review
IEC-62443-4-2-2019-Security-for-industrial-automation-and-co

ReleasedMigration Guidance
IEC2019
Trust 13Needs review
Purchase required
NIST-SP-800-131A-Rev2Updated

PDF · 686 KB · a long read

ReleasedMigration GuidanceReviewed (LLM) · eramusa · Sep 2026 · via lineage/apply_secondary.py
NIST2019
Trust 26Needs review
ASHRAE-BACnet-SC-Whitepaper-2019Updated

ASHRAE SSPC 135 IT Working Group white paper introducing BACnet Secure Connect (BACnet/SC), a BACnet datalink based on TLS 1.3-secured WebSockets with 128- or 256-bit elliptic-curve cryptography, removing static IPs and BBMDs, with four deployment scenarios. Not PQC-specific; relevant to PQC migration because it fixes building-automation security on TLS 1.3 elliptic-curve key exchange and certificates.

PDF · 835 KB · a long read

MiscProtocolsReviewed (LLM) · eramusa · Oct 2026 · via manual data edit (library)
ASHRAE SSPC 135 IT Working Group (David Fisher; Bernhard Isler; Michael Osborne)2019
Trust 36Needs review
PNNL-29313-RADIANCE

DOE Grid Modernization Laboratory Consortium report (PNNL-29313, Oct 2019) surveying vulnerabilities and mitigations for energy-delivery protocols (Modbus, DNP3, IEC 61850, IEC 60870-5, ICCP, C37.118) and time synchronization. Documents IEC 62351-3 TLS security profiles for TCP/IP with X.509 node authentication (TLS 1.2 for MMS/IEC 61850), IEC 62351-9 key/certificate management incl. CRL/OCSP handling, and R-GOOSE/R-SV payload protection with symmetric keys distributed by a GDOI key distribution center (RFC 6407 + RFC 8052) with IEC 62351-9 key exchange.

PDF · 433 KB · a long read

ReleasedProtocols
Pacific Northwest National Laboratory (DOE Grid Modernization Laboratory Consortium Team)2019
Trust 29Needs review
IEEE-802-1AE-2018Updated

Defines MACsec — IEEE Layer 2 encryption standard for Ethernet networks. MACsec uses AES-GCM-128/256 for confidentiality and integrity. QKD-derived keys can be injected as Secure Association Keys (SAKs) via the MACsec Key Agreement (MKA) protocol, making MACsec a natural integration point for QKD in enterprise and telecom networks.

Web page · 55 KB · a short read

ReleasedProtocols
IEEE 802.1 Working GroupDec 26, 2018
Trust 90Authoritative
Liboqs-pythonUpdated

Python wrapper for the liboqs C library providing PQC algorithm access for Python applications and research.

Web page · 369 KB · a long read

MiscImplementations
Open Quantum SafeDec 19, 2018
Trust 76Authoritative
NIST SP 800-37Updated

Risk Management Framework for Information Systems and Organizations

PDF · 2.3 MB · a reference document — dip in, don’t read it through

ReleasedGovernment & Policy
NISTDec 2018
Trust 86Authoritative
MDPI-2018-NTRU-SingleTrace-SCA

First single-trace side-channel attack on NTRU. Recovers the secret key from a single power trace, improving upon earlier differential power analysis attacks on NTRU implementations.

Web page · 649 KB · a long read

ReleasedIndustry & Research
Applied Sciences (MDPI)Oct 23, 2018
Trust 60Needs review
RFC-8478Updated

Zstandard, or "zstd" (pronounced "zee standard"), is a data compression mechanism. This document describes the mechanism and registers a media type and content encoding to be used when transporting zstd-compressed content via Multipurpose Internet Mail Extensions (MIME). Despite use of the word "standard" as part of its name, readers are advised that this document is not an Internet Standards Tr

Web page · 127 KB · a short read

ReleasedProtocols
IETFOct 2018
Trust 79Authoritative
CIRCL-CloudflareUpdated

Go library implementing PQC algorithms (ML-KEM, ML-DSA, SLH-DSA) and hybrid key exchanges. Used in Cloudflare's production PQC deployment.

Web page · 406 KB · a long read

MiscImplementationsHigh
CloudflareSep 8, 2018
Trust 70Authoritative
RFC-8420Updated

This document describes the use of the Edwards-curve Digital Signature Algorithm (EdDSA) in the Internet Key Exchange Protocol Version 2 (IKEv2).

Web page · 117 KB · a short read

ReleasedProtocols
IETFAug 20, 2018
Trust 79Authoritative
RFC-8410

This document specifies algorithm identifiers and ASN.1 encoding formats for elliptic curve constructs using the curve25519 and curve448 curves. The signature algorithms covered are Ed25519 and Ed448. The key agreement algorithms covered are X25519 and X448. The encoding for public key, private key, and Edwards-curve Digital Signature Algorithm (EdDSA) structures is provided.

Web page · 237 KB · a long read

ReleasedProtocols
IETFAug 6, 2018
Trust 80Authoritative
RFC-8447Updated

This document describes a number of changes to TLS and DTLS IANA registries that range from adding notes to the registry all the way to changing the registration policy. These changes were mostly motivated by WG review of the TLS- and DTLS-related registries undertaken as part of the TLS 1.3 development process. This document updates the following RFCs: 3749, 5077, 4680, 5246, 5705, 5878, 6520,

Web page · 58 KB · a short read

ReleasedProtocols
IETFAug 2018
Trust 78Authoritative
RFC 8391Updated

Specifies XMSS and XMSS-MT stateful hash-based signature schemes.

Web page · 185 KB · a long read

ReleasedIndustry & Research
IETF CFRGMay 2018
Trust 56Needs review
Microsoft-PQC-ResearchUpdated

Microsoft Research PQC project including lattice-based and isogeny-based cryptography research, SymCrypt PQC integration.

Web page · 187 KB · a long read

MiscIndustry & ResearchHigh
Microsoft ResearchApr 30, 2018
Trust 76Authoritative
NIST SP 800-56AUpdated

Recommendation for Pair-Wise Key-Establishment Schemes Using Discrete Logarithm Cryptography

PDF · 1.7 MB · a reference document — dip in, don’t read it through

ReleasedAlgorithm Specifications1 rev
NISTApr 2018
Trust 88Authoritative
EBA-RTS-SCA-2018-389Updated

Regulatory Technical Standards implementing PSD2 Article 97: two-factor SCA (knowledge/possession/inherence), dynamic linking, the dedicated-interface obligation for open banking APIs (Art. 30), fallback mechanism (Art. 33), eIDAS qualified certificates for TPP identification (Art. 34), and "strong and widely recognised encryption techniques" for the channel (Art. 35) — technology-neutral, names no algorithm or TLS version.

Web page · 166 KB · a long read

ReleasedCompliance & Certification
European Banking Authority; European CommissionMar 13, 2018
Trust 64Needs review
NIST-SP-800-90BUpdated

NIST standard for validating entropy sources used in random bit generators. Defines health tests (repetition count, adaptive proportion), min-entropy estimation methods, and IID testing requirements.

PDF · 1.0 MB · a long read

ReleasedNIST StandardsHigh1 rev
NISTJan 29, 2018
Trust 90Authoritative
TCG-PC-Client-Platform-TPM-Profile-v1.07

TCG PC Client Specific Platform TPM Profile for TPM 2.0, v1.07. Applies TPM 2.0 Library v1.85 PQ algorithms (ML-DSA, ML-KEM) to PC platforms.

Web page · 112 KB · a short read

ReleasedPKI Certificate Management
Trusted Computing Group (TCG)Jan 16, 2018
Trust 88Authoritative
TCG-EK-Credential-Profile-v2.7

TCG Endorsement Key Credential Profile v2.7. Adds PQ EK templates (ML-DSA, ML-KEM) for TPM 2.0 v1.85.

Web page · 107 KB · a short read

ReleasedPKI Certificate Management
Trusted Computing Group (TCG)Jan 16, 2018
Trust 89Authoritative
ISO-26262-Road-vehicles-Functional-safety

The road-vehicle functional-safety standard. Relevant to PQC because any change to in-vehicle cryptography inherits its safety-case and re-certification burden.

Web page · 71 KB · a short read

ReleasedInternational Frameworks
ISO - International Organization for Standardization2018
Trust 79Authoritative
qStream-High-speed-Full-Entropy-RNGUpdated

PDF · 342 KB · a short read

MiscMigration Guidance
Unknown2018
Trust 26Needs review
ISO-31000-2018-Risk-management-Guidelines

ReleasedMigration Guidance
ISO/IEC2018
Trust 9Needs review
Purchase required
Commission-Delegated-Regulation-EU-2018-389-of-27-November-2Updated

PDF · 494 KB · a long read

ReleasedMigration Guidance
Unknown2018
Trust 26Needs review
RFC 8268Updated

Adds stronger MODP DH groups (4096-8192 bit) to SSH; being superseded by ML-KEM PQC key exchange for post-quantum SSH implementations.

Web page · 23 KB · a quick skim

ReleasedProtocolsHigh
IETFDec 2017
Trust 83Authoritative
RFC-7159Updated

JavaScript Object Notation (JSON) is a lightweight, text-based, language-independent data interchange format. It was derived from the ECMAScript Programming Language Standard. JSON defines a small set of formatting rules for the portable representation of structured data. This document removes inconsistencies with other specifications of JSON, repairs specification errors, and offers experience-

Web page · 38 KB · a quick skim

ReleasedProtocols
IETFDec 2017
Trust 77Authoritative
ETSI-TR-103-570

Compares quantum-safe key exchange proposals from the academic literature including LWE, Ring-LWE, and SIDH-based schemes. Evaluates performance and security tradeoffs for standardization.

PDF · 444 KB · a long read

ReleasedAlgorithm Specifications
ETSI TC CYBER WG QSCOct 2017
Trust 83Authoritative
NAIC-Insurance-Data-Security-Model-Law-MDL-668Updated

The US state-level model law governing insurer data security, including encryption expectations for policyholder data.

PDF · 238 KB · a short read

ReleasedCompliance & Certification
National Association of Insurance Commissioners (NAIC)Oct 2017
Trust 81Authoritative
SCA-2017-AES-CNN-JitterUpdated

The foundational deep-learning side-channel attack paper (CHES 2017): shows a CNN can profile and recover AES keys through jitter-based hiding countermeasures without trace realignment. AES is the current, widely-deployed symmetric standard — this shows AI-assisted attacks defeat production countermeasures today, with no dependence on quantum computing or PQC migration status.

PDF · 1.9 MB · a reference document — dip in, don’t read it through

Research PaperIndustry & Research
Eleonora Cagli; Cecile Dumas; Emmanuel Prouff (CEA-Leti)Sep 25, 2017
Trust 77Authoritative
RFC-8240Updated

This document provides a summary of the Internet of Things Software Update (IoTSU) Workshop that took place at Trinity College Dublin, Ireland on the 13th and 14th of June, 2016. The main goal of the workshop was to foster a discussion on requirements, challenges, and solutions for bringing software and firmware updates to IoT devices. This report summarizes the discussions and lists recommendatio

Web page · 287 KB · a long read

ReleasedProtocols
IETFSep 10, 2017
Trust 76Authoritative
RFC-8230Updated

The CBOR Object Signing and Encryption (COSE) specification defines cryptographic message encodings using Concise Binary Object Representation (CBOR). This specification defines algorithm encodings and representations enabling RSA algorithms to be used for COSE messages. Encodings are specified for the use of RSA Probabilistic Signature Scheme (RSASSA-PSS) signatures, RSA Encryption Scheme - Opt

Web page · 174 KB · a long read

ReleasedProtocols
IETFSep 5, 2017
Trust 79Authoritative
IACR-2022-1031Updated

Peer-reviewed academic paper (Journal of Cryptology 2022) presenting the full security analysis and design rationale for CRYSTALS-Kyber / ML-KEM. Proves IND-CCA2 security under Module-LWE assumption in the ROM and QROM. Essential reading for implementers and security evaluators.

PDF · 469 KB · a long read

Research PaperAlgorithm SpecificationsHigh
KU Leuven COSIC; Ruhr University BochumJul 5, 2017
Trust 47Needs review
IACR-2018-952Updated

Peer-reviewed academic paper (TCHES 2018) presenting the design and security analysis of CRYSTALS-Dilithium / ML-DSA. Proves EUF-CMA security under Module-LWE and Module-SIS assumptions. Covers the Fiat-Shamir with Aborts paradigm and rejection sampling technique.

PDF · 884 KB · a long read

Research PaperAlgorithm SpecificationsHigh
KU Leuven COSIC; Ruhr University Bochum; INRIA France; ETH ZurichJul 5, 2017
Trust 47Needs review
ACSC-Essential-Eight

Australian Cyber Security Centre (ACSC) Essential Eight Maturity Model — eight prioritised mitigation strategies. Mandatory for Australian federal government agencies; widely adopted by APRA-regulated entities and critical infrastructure. Cryptographic patching and application hardening requirements at ML3 directly intersect PQC migration planning.

Web page · 436 KB · a long read

ReleasedGovernment & PolicyHigh
ASD; ACSC; Australian Signals DirectorateJun 30, 2017
Trust 85Authoritative
Ouroboros-Praos-An-Adaptively-Secure-Semi-synchronous-ProofUpdated

IACR ePrint / EUROCRYPT 2018 paper introducing Ouroboros Praos, the proof-of-stake consensus protocol Cardano runs. Defines the two core primitives at the protocol-design level: a forward-secure digital signature scheme (realized in production as a Key-Evolving Signature, KES) for block signing, and a verifiable random function (VRF) for private, unbiasable slot-leader election. The paper itself is curve-agnostic — it does not name Ed25519; the concrete Cardano instantiation is documented separately (see the cardano-crypto-praos VRF source and the input-output-hk/kes KES implementation).

PDF · 777 KB · a long read

Research PaperIndustry & Research
Bernardo David; Peter Gazi; Aggelos Kiayias; Alexander RussellJun 16, 2017
Trust 70Authoritative
RFC-8126Updated

Many protocols make use of points of extensibility that use constants to identify various protocol parameters. To ensure that the values in these fields do not have conflicting uses and to promote interoperability, their allocations are often coordinated by a central record keeper. For IETF protocols, that role is filled by the Internet Assigned Numbers Authority (IANA). To make assignments in a

Web page · 140 KB · a short read

ReleasedProtocols
IETFJun 2017
Trust 78Authoritative
RFC-8052Updated

IETF Standards Track RFC defining Group Domain of Interpretation (GDOI) payloads so IEC 62351-9 key management can distribute security policy and group keys (AES-GCM, HMAC-SHA256) protecting IEC 61850 GOOSE and Sampled Values multicast in power substations. Not PQC-specific; relevant to PQC migration because substation group-key distribution depends on GDOI's classical public-key authentication.

Web page · 67 KB · a short read

ReleasedProtocols
IETF; B. Weis, M. Seewald (Cisco Systems); H. Falk (SISCO)Jun 2017
Trust 57Needs review
RFC 8174Updated

Clarifies that only uppercase RFC 2119 keywords carry normative weight; updates BCP 14.

Web page · 8 KB · a quick skim

ReleasedAlgorithm Specifications
IETF; B. LeibaMay 2017
Trust 81Authoritative
Bernstein-Lange-Fallout-2017Updated

Survey paper by Bernstein and Lange analysing the NIST PQC standardisation landscape at its launch, covering all major algorithm families (lattice, code-based, hash-based, multivariate, isogeny) and migration strategy considerations. Companion to the foundational Bernstein-Buchmann-Dahmen PQC book (already in library).

PDF · 421 KB · a long read

Research PaperAlgorithm Specifications
Daniel J. Bernstein (UIC); Tanja Lange (TU Eindhoven)Apr 10, 2017
Trust 73Authoritative
ETSI-GR-QSC-004

Presents quantum threat assessment across banking/finance, intelligent transport, IoT, and digital media. Analyzes Shor and Grover algorithm impacts on deployed cryptographic systems.

PDF · 264 KB · a short read

ReleasedInternational Frameworks
ETSI ISG QSCMar 2017
Trust 87Authoritative
ETSI-GR-QSC-003

Examines real-world PQC deployment scenarios including network security, TLS, IoT, and satellite communications. Analyzes migration challenges across telecom, government, and critical infrastructure sectors.

PDF · 155 KB · a short read

ReleasedInternational Frameworks
ETSI ISG QSCFeb 2017
Trust 83Authoritative
ETSI-GR-QSC-006

Analyzes the impact of quantum computing on symmetric key cryptography. Concludes that 256-bit symmetric ciphers and hash functions will remain secure against quantum attacks through 2050.

PDF · 113 KB · a short read

ReleasedInternational Frameworks
ETSI ISG QSCFeb 2017
Trust 84Authoritative
NIST PQC FAQUpdated

NIST FAQ on PQC standardization process, algorithm selection criteria, and migration guidance for the FIPS 203/204/205 standards.

Web page · 132 KB · a short read

MiscNIST StandardsHigh
NISTJan 3, 2017
Trust 82Authoritative
RFC-8032Updated

IETF standard for EdDSA including Ed25519 and Ed448. Used by Solana. Deterministic nonce eliminates nonce-reuse vulnerabilities.

Web page · 174 KB · a long read

ReleasedDigital SignatureHigh
IETFJan 2017
Trust 86Authoritative
RFC 8037Updated

Defines JWK and JWA algorithm identifiers for Ed25519/Ed448 signatures and X25519/X448 key agreement; used in hybrid PQC JOSE/JWT implementations alongside ML-KEM.

Web page · 33 KB · a quick skim

ReleasedProtocolsHigh
IETFJan 2017
Trust 79Authoritative
LoRaWAN-Specification-v1-1Updated

LoRa Alliance LoRaWAN 1.1 MAC-layer specification for low-power wide-area networks of battery-powered end-devices, defining device classes, activation, and the AES-128-based key hierarchy (NwkKey/AppKey root keys, CMAC integrity). Not PQC-specific; it uses symmetric cryptography for radio transmissions, so its PQC-migration relevance is confirming 128-bit symmetric key strength.

PDF · 2.3 MB · a reference document — dip in, don’t read it through

ReleasedProtocolsReviewed (LLM) · eramusa · Oct 2026 · via manual data edit (library)
LoRa Alliance Technical Committee2017
Trust 48Needs review
NIST-SP-800-185Updated

Defines the SHA-3 derived functions: cSHAKE, KMAC, TupleHash and ParallelHash. KMAC in particular is what several PQC KEM constructions derive keys with.

Web page · 45 KB · a short read

ReleasedNIST Standards
John Kelsey; Shu-jen Chang; Ray Perlner (NIST)Dec 22, 2016
Trust 89Authoritative
ANSSI-CC-PP-2016-05-EN-419221-5Updated

The protection profile certified by ANSSI as ANSSI-CC-PP-2016/05: Protection Profiles for TSP Cryptographic Modules, Part 5 (Cryptographic Module for Trust Services). The captured text is the prEN 419 221-5 v0.15 edition dated 2016-11-29.

PDF · 722 KB · a long read

DraftCompliance & Certification
CEN (certified by ANSSI)Nov 29, 2016
Trust 34Needs review
RFC 8017Updated

Documents RSA cryptographic primitives, encryption and signature schemes, and ASN.1 representations; the primary reference for RSA being phased out in the PQC transition.

Web page · 190 KB · a long read

ReleasedAlgorithm SpecificationsHigh
K. Moriarty; B. Kaliski; J. Jonsson; A. RuschNov 2016
Trust 66Needs review
EIP-155Updated

Introduces chain ID into Ethereum transaction signing to prevent cross-chain replay attacks.

Web page · 18 KB · a quick skim

ReleasedProtocolsHigh
Vitalik ButerinOct 14, 2016
Trust 47Needs review
NIST-CMVP-MIP-ListUpdated

Authoritative list of cryptographic modules currently undergoing FIPS 140-3 validation. Queue backlog often 18–24 months; critical for Assurance-pillar monitoring.

Web page · 143 KB · a short read

MiscMigration GuidanceReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
NIST CMVPOct 11, 2016
Trust 83Authoritative
NIST-CMVP-Validated-Modules

Authoritative searchable database of FIPS 140-2/140-3 validated modules with cert number, status (active/historical/revoked), sunset date, and platform binding.

Web page · 51 KB · a short read

ReleasedMigration GuidanceReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
NIST CMVPOct 11, 2016
Trust 87Authoritative
NIST-ACVPUpdated

Algorithm-level validation protocol. NIST's ACVTS speaks ACVP to test implementations for CAVP, which issues the algorithm validation certificate a FIPS 140-3 module cert requires; ACVP itself is the protocol, not the certifying program. Each FIPS 203/204/205 revision requires a fresh CAVP algorithm re-validation.

Web page · 316 KB · a long read

DraftMigration GuidanceReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
NIST CAVPOct 5, 2016
Trust 90Authoritative
RFC-7932

This specification defines a lossless compressed data format that compresses data using a combination of the LZ77 algorithm and Huffman coding, with efficiency comparable to the best currently available general-purpose compression methods.

Web page · 1.1 MB · a long read

ReleasedProtocols
IETFJul 29, 2016
Trust 79Authoritative
ETSI-GR-QSC-001

ETSI QSC overview of post-quantum algorithmic families including lattice-based, code-based, hash-based, and multivariate schemes. Provides framework for assessing PQC primitives for key establishment and authentication.

PDF · 426 KB · a long read

ReleasedInternational Frameworks
ETSI ISG QSCJul 2016
Trust 85Authoritative
RFC-7924Updated

Transport Layer Security (TLS) handshakes often include fairly static information, such as the server certificate and a list of trusted certification authorities (CAs). This information can be of considerable size, particularly if the server certificate is bundled with a complete certificate chain (i.e., the certificates of intermediate CAs up to the root CA). This document defines an extension

Web page · 43 KB · a short read

ReleasedProtocols
IETFJul 2016
Trust 79Authoritative
RFC-7925Updated

Defines TLS and DTLS 1.2 profiles (PSK, raw public key and certificate modes, ciphersuites, certificate profile) for constrained IoT devices. Not PQC-specific; its ECC-based ciphersuites and certificate profile are what constrained deployments must migrate away from, and it is being updated by the TLS/DTLS 1.3 IoT profile draft.

Web page · 181 KB · a long read

ReleasedProtocols
IETF DICE WG; H. Tschofenig, Ed. (ARM Ltd.); T. Fossati (Nokia)Jul 2016
Trust 58Needs review
ETSI-EG-203-310Updated

Addresses business continuity planning for the post-quantum transition. Covers Certificate Authority re-assertion in PKI, algorithm selection criteria, and impact of Shor and Grover algorithms.

PDF · 81 KB · a short read

ReleasedInternational Frameworks
ETSI TC CYBERJun 2016
Trust 84Authoritative
RFC-7841Updated

RFC documents contain a number of fixed elements such as the title page header, standard boilerplates, and copyright/IPR statements. This document describes them and introduces some updates to reflect current usage and requirements of RFC publication. In particular, this updated structure is intended to communicate clearly the source of RFC creation and review. This document obsoletes RFC 5741,

Web page · 213 KB · a long read

HistoricalProtocols
IETFMay 25, 2016
Trust 78Authoritative
ETSI-GS-QKD-011Updated

Methods for characterizing individual QKD components such as single-photon sources and detectors.

PDF · 923 KB · a long read

ReleasedMigration Guidance
ETSI ISG QKDMay 2016
Trust 83Authoritative
NIST IR 8105Updated

Foundational NIST report examining quantum computing threats to current cryptographic standards. Outlines the need for and announces the PQC standardization initiative that produced FIPS 203/204/205.

PDF · 200 KB · a short read

ReleasedNIST Standards
NISTApr 28, 2016
Trust 80Authoritative
GDPR-REG-2016-679Updated

EU data protection regulation mandating appropriate technical measures including encryption to protect personal data. Article 32 requires state-of-the-art cryptographic controls; PQC transition relevant to long-term data protection.

PDF · 982 KB · a long read

ReleasedCompliance & CertificationHigh
European Parliament; Council of the EUApr 27, 2016
Trust 64Needs review
SLIP-0010Updated

Extends BIP-32 to support Ed25519 and other non-secp256k1 curves for HD derivation; required for Solana.

Web page · 421 KB · a long read

ReleasedIndustry & ResearchHigh
SatoshiLabsApr 26, 2016
Trust 46Needs review
CID-EU-2016-650-QSCD-Security-AssessmentUpdated

Commission Implementing Decision (EU) 2016/650 of 25 April 2016, setting the standards for the security assessment of qualified signature and seal creation devices under eIDAS Articles 30(3) and 39(2).

Web page · 280 KB · a long read

ReleasedCompliance & Certification
European CommissionApr 25, 2016
Trust 34Needs review
FERC-Security-Program-for-Hydropower-Projects-Division-of-Da

FERC’s security programme for hydropower projects, covering both physical and cyber controls at dams.

PDF · 437 KB · a long read

ReleasedMigration Guidance
FERC Division of Dam Safety and InspectionsMar 30, 2016
Trust 55Needs review
ETSI-EN-319-422-V1-1-1-Time-stamping-protocol-and-time-stamp

The EU profile for time-stamping protocol and token formats used by qualified trust services.

PDF · 70 KB · a short read

ReleasedProtocols
ETSIMar 2016
Trust 57Needs review
Peikert-Lattice-Survey-2016Updated

Comprehensive survey by Chris Peikert covering a decade of lattice-based cryptography, from foundational hardness problems (LWE, SIS, NTRU) through practical constructions. Essential reference for understanding the mathematical underpinnings of NIST-standardized ML-KEM and ML-DSA.

PDF · 704 KB · a long read

Research PaperAlgorithm Specifications
Chris Peikert (University of Michigan)Feb 17, 2016
Trust 72Authoritative
EIP-55Updated

Ethereum standard for checksummed mixed-case hex address encoding using Keccak-256 to detect typos.

Web page · 22 KB · a quick skim

ReleasedProtocolsHigh
Vitalik ButerinJan 14, 2016
Trust 46Needs review
ref-amy-sha2-preimageUpdated

Estimation of the computational cost of generic quantum pre-image attacks on SHA-2 and SHA-3 using Grover’s algorithm on a surface-code-based fault-tolerant quantum computer.

PDF · 495 KB · a long read

Research PaperIndustry & Research
M. Amy et al.2016
Trust 53Needs review
CNSSP 15Updated

NSA/CNSS policy governing the use of public/commercial cryptographic standards for secure information sharing across US national security systems; referenced alongside CNSA 2.0 in PQC transition planning documents.

PDF · 260 KB · a short read

ReleasedGovernment & PolicyHigh1 rev
CNSS; NSA2016
Trust 68Needs review
RFC 7748Updated

Defines X25519 and X448 ECDH functions on Curve25519 and Curve448; used in hybrid PQC key exchange (ML-KEM + X25519) as the classical component per CNSA 2.0 guidance.

Web page · 49 KB · a short read

ReleasedProtocolsHigh
IETFJan 2016
Trust 80Authoritative
Falcon-Towards-FN-DSA-Technical-OverviewUpdated

PDF · 578 KB · a long read

MiscMigration Guidance
Unknown2016
Trust 31Needs review
Regulation-EU-2016-679-General-Data-Protection-RegulationUpdated

Web page · 1.1 MB · a long read

ReleasedMigration Guidance
Unknown2016
Trust 26Needs review
NIST-Cryptographic-Algorithm-Validation-Program-CAVPUpdated

NIST program overview: CAVP provides validation testing of FIPS-approved cryptographic algorithms and their components. Labs test implementations via NIST's Automated Cryptographic Validation Test System (ACVTS), which speaks the ACVP protocol; CAVP itself issues the resulting algorithm validation certificate. Algorithm validation is a prerequisite for FIPS 140-3 module validation under CMVP.

Web page · 64 KB · a short read

MiscMigration Guidance
NIST CAVP2016
Trust 64Needs review
Accessing-the-ACVTS-Demo-and-Prod-EnvironmentsUpdated

How a lab or vendor gains access to NIST's Automated Cryptographic Validation Test System (ACVTS): the semi-volatile Demo environment (open request, a sandbox for testing ACVP client applications) versus the Prod environment (restricted to NVLAP-accredited CST and 17ACVT laboratories — the only environment that issues CAVP algorithm validation certificates).

Web page · 55 KB · a short read

MiscMigration Guidance
NIST CAVP2016
Trust 64Needs review
Derbyshire-IChemE-Hazards26-2016Updated

IChemE Hazards 26 (2016) paper by a DNV GL functional-safety engineer summarising the changes in IEC 61511 Edition 2 for safety instrumented systems. Documents the new Clause 8.2.4 requirement that a security risk assessment of the SIS is mandatory (per Note 4 it may be done per SIF), referencing ISA TR84.00.09, ISO/IEC 27001:2013 and IEC 62443-2-1:2010 as guidance.

PDF · 509 KB · a long read

Research PaperIndustry & Research
Andrew W. Derbyshire (DNV GL), IChemE Hazards 262016
Trust 48Needs review
BIP-141Updated

Activates Segregated Witness on Bitcoin separating signature data (witness) from transaction inputs. Introduces SegWit witness versioning (v0 P2WPKH/P2WSH, v1 Taproot). BIP-360 (P2QRH) introduces SegWit v3 (bc1r...) as a quantum-resistant output type building directly on this witness versioning scheme.

Web page · 26 KB · a quick skim

ReleasedProtocols
Eric Lombrozo; Johnson Lau; Pieter Wuille (Bitcoin Core)Dec 21, 2015
Trust 54Needs review
UNISIG-SUBSET-137-ERTMS-ETCS-On-line-Key-Management-FFFISUpdated

The European rail signalling standard for online key management — long-lived keys on infrastructure that is replaced on a decades-long cycle.

PDF · 1.6 MB · a reference document — dip in, don’t read it through

ReleasedProtocols
UNISIG (Alstom, Ansaldo, AZD, Bombardier, CAF, Siemens, Thales)Dec 17, 2015
Trust 74Authoritative
PSD2-Directive-EU-2015-2366Updated

Directive establishing Strong Customer Authentication (Article 97) for EU payment services and the legal basis for third-party access to payment accounts (open banking) implemented by PISPs/AISPs.

Web page · 1.1 MB · a long read

ReleasedCompliance & Certification
European Parliament; Council of the EUNov 25, 2015
Trust 67Needs review
EIP-2Updated

Ethereum Homestead changes including stricter ECDSA signature malleability rules; foundational for Ethereum cryptographic security baseline referenced by noble/scure libraries.

Web page · 20 KB · a quick skim

ReleasedBlockchain Standards
Ethereum FoundationNov 15, 2015
Trust 53Needs review
RFC 7693Updated

Specifies BLAKE2b and BLAKE2s fast cryptographic hash functions; used in several PQC system implementations as a performance-optimized alternative to SHA-3.

Web page · 67 KB · a short read

ReleasedProtocols
IETFNov 2015
Trust 77Authoritative
NIST-SP-800-152Updated

Profile for key management systems used in U.S. federal agencies; referenced in PQC migration planning for key lifecycle and algorithm agility requirements.

PDF · 1.8 MB · a reference document — dip in, don’t read it through

ReleasedNIST Standards
NISTOct 28, 2015
Trust 77Authoritative
IETF RFC 7662Updated

This specification defines a method for protected resources to query an OAuth 2.0 authorization server to determine the active state and meta-information of an OAuth 2.0 token.

Web page · 223 KB · a long read

ReleasedMigration Guidance
IETFOct 19, 2015
Trust 87Authoritative
RFC-7638Updated

This specification defines a method for computing a hash value over a JSON Web Key (JWK). It defines which fields in a JWK are used in the hash computation, the method of creating a canonical form for those fields, and how to convert the resulting Unicode string into a byte sequence to be hashed. The resulting hash value can be used for identifying or selecting the key represented by the JWK tha

Web page · 187 KB · a long read

ReleasedProtocols
IETFSep 8, 2015
Trust 80Authoritative
FIPS 202Updated

Defines SHA-3 (Keccak) and SHAKE128/SHAKE256 XOFs; SHAKE is used as the internal XOF in FIPS 203 (ML-KEM) and FIPS 205 (SLH-DSA).

PDF · 1.5 MB · a long read

ReleasedNIST StandardsHigh
NISTAug 5, 2015
Trust 76Authoritative
FIPS-180-4Updated

Specifies SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/224, and SHA-512/256 hash functions. SHA-256 and SHA-512 are used in PQC hybrid signing mechanisms (CKM_SHA256_RSA_PKCS, CKM_ECDSA_SHA256) and as the digest algorithm in CMS SignedData firmware envelopes.

PDF · 833 KB · a long read

ReleasedNIST Standards1 rev
NISTAug 4, 2015
Trust 84Authoritative
NIST-SP-800-90A-R1Updated

NIST standard defining three approved DRBG mechanisms (CTR_DRBG, Hash_DRBG, HMAC_DRBG) for generating pseudorandom bits from seed entropy. All mechanisms use symmetric primitives and are quantum-safe.

Web page · 83 KB · a short read

ReleasedNIST StandardsHigh2 revs
NISTJun 24, 2015
Trust 93Authoritative
RFC 7568Updated

Formally deprecates SSLv3 (POODLE vulnerability); part of the protocol deprecation chain enabling TLS 1.3 adoption required for PQC hybrid key exchange.

Web page · 20 KB · a quick skim

ReleasedProtocolsHigh
IETFJun 2015
Trust 82Authoritative
RFC 7519Updated

Defines JWT as a compact URL-safe representation of claims between parties. Specifies the three-part structure (header.payload.signature), registered claim names (iss, sub, aud, exp, iat), and how JWS and JWE are used for signing and encryption. Foundation document for all JWT-based PQC migration work.

Web page · 84 KB · a short read

ReleasedProtocolsHigh
IETFMay 2015
Trust 84Authoritative
RFC 7515Updated

Defines the JWS standard for representing digitally signed content in JSON. Specifies the compact serialization (header.payload.signature) used in every signed JWT and the alg header parameter registry that PQC JOSE drafts extend with ML-DSA and SLH-DSA identifiers.

Web page · 166 KB · a long read

ReleasedProtocolsHigh
IETFMay 2015
Trust 88Authoritative
RFC 7516Updated

Defines the JWE standard for encrypting arbitrary content using JSON data structures. Specifies the 5-part compact serialization and key agreement mechanisms (ECDH-ES, RSA-OAEP) that ML-KEM replaces in PQC migration. Core reference for JWE encryption and PQC token confidentiality.

Web page · 138 KB · a short read

ReleasedProtocolsHigh
IETFMay 2015
Trust 87Authoritative
RFC 7517Updated

Defines the JWK format for representing cryptographic keys as JSON. JWKS endpoints publish public keys for JWT signature verification. PQC migration significantly increases JWKS response sizes: ML-DSA-65 public keys are 1952 bytes vs 65 bytes for P-256, challenging HTTP header limits and caching strategies.

Web page · 118 KB · a short read

ReleasedProtocolsHigh
IETFMay 2015
Trust 88Authoritative
RFC 7518Updated

Defines the algorithm registry for JOSE including RS256, ES256, ECDH-ES, AES-GCM, and HMAC. All currently registered signature and key agreement algorithms are quantum-vulnerable to Shor's algorithm. PQC JOSE drafts extend this registry with ML-DSA and ML-KEM algorithm identifiers.

Web page · 203 KB · a long read

ReleasedProtocolsHigh
IETFMay 2015
Trust 88Authoritative
RFC 7468Updated

Defines PEM label text encoding for X.509 certificates, PKCS#8 keys, and CMS structures; PQC keys (ML-KEM, ML-DSA) are encoded in these formats for interoperability.

Web page · 56 KB · a short read

ReleasedPKI Certificate ManagementProtocolsHigh
IETFApr 2015
Trust 83Authoritative
RFC-7479Updated

The Ed25519 signature algorithm has been implemented in OpenSSH. This document updates the IANA "SSHFP RR Types for public key algorithms" registry by adding an algorithm number for Ed25519.

Web page · 100 KB · a short read

ReleasedProtocols
IETFMar 10, 2015
Trust 80Authoritative
CI-Plus-Spec-v1.3.2Updated

The base CI Plus technical specification (313 pages) governing CICAM/Host mutual authentication and link encryption in DVB conditional access. Normative Annex I specifies RSA signatures under PKCS#1 (RSASSA-PSS), and the Service Operator CRL is "signed by the Service Operator's private RSA key" and verified with the corresponding public key. Holds the cryptography that DVB BlueBook A165 defers to — A165 itself names no algorithm at all.

PDF · 7.5 MB · a reference document — dip in, don’t read it through

ReleasedAlgorithm Specifications
CI Plus LLPMar 1, 2015
Trust 44Needs review
RFC-7465

This document requires that Transport Layer Security (TLS) clients and servers never negotiate the use of RC4 cipher suites when they establish connections. This applies to all TLS versions. This document updates RFCs 5246, 4346, and 2246.

Web page · 117 KB · a short read

ReleasedProtocols
IETFFeb 18, 2015
Trust 78Authoritative
RFC-7427Updated

The Internet Key Exchange Version 2 (IKEv2) protocol has limited support for the Elliptic Curve Digital Signature Algorithm (ECDSA). The current version only includes support for three Elliptic Curve groups, and there is a fixed hash algorithm tied to each group. This document generalizes IKEv2 signature support to allow any signature method supported by PKIX and also adds signature hash algorit

Web page · 249 KB · a long read

ReleasedProtocols
IETFJan 6, 2015
Trust 79Authoritative
RFC-7383Updated

This document describes a way to avoid IP fragmentation of large Internet Key Exchange Protocol version 2 (IKEv2) messages. This allows IKEv2 messages to traverse network devices that do not allow IP fragments to pass through.

Web page · 257 KB · a long read

ReleasedProtocols
IETFNov 6, 2014
Trust 79Authoritative
FPLLLUpdated

C++ library implementing lattice reduction algorithms (LLL, BKZ) used for cryptanalysis of lattice-based PQC schemes.

Web page · 447 KB · a long read

MiscIndustry & Research
FPLLL ContributorsOct 7, 2014
Trust 67Needs review
IETF RFC 7296Updated

Defines IKEv2 for establishing IPsec Security Associations. Foundational protocol for VPN key exchange; all PQC IKEv2 extensions (RFC 9370, draft-ietf-ipsecme-ikev2-mlkem) build on this specification.

Web page · 415 KB · a long read

ReleasedProtocolsHigh2 revs
IETF IPSECMEOct 2014
Trust 92Authoritative
KLEPTO-2014-DualEC-BackdoorUpdated

The definitive practical demonstration of the NSA-inserted Dual_EC_DRBG kleptographic backdoor (Young-Yung SETUP construction, applied to an elliptic-curve PRNG) working end-to-end against real TLS implementations, including RSA BSAFE and OpenSSL-FIPS. This is a CLASSICAL cryptography backdoor, entirely unrelated to quantum computing — proof that current, widely-deployed crypto can be covertly broken today.

PDF · 365 KB · a short read

Research PaperProtocolsHigh
Stephen Checkoway; Matthew Fredrikson; Ruben Niederhagen; Adam Everspaugh; Matthew Green; Tanja Lange; Thomas Ristenpart; Daniel J. Bernstein; Jake Maskiewicz; Hovav ShachamAug 20, 2014
Trust 72Authoritative
EIDAS-REG-910-2014Updated

Original EU electronic identification and trust services regulation. Defines qualified electronic signatures, seals, and timestamps. Superseded by eIDAS 2.0 (EU 2024/1183) but basis for current QTSP compliance.

Web page · 615 KB · a long read

ReleasedCompliance & Certification1 rev
European Parliament; Council of the EUJul 23, 2014
Trust 68Needs review
eIDAS-Regulation-EU-910-2014-consolidated-text-as-amended-by

Regulation (EU) No 910/2014 on electronic identification and trust services, in its EUR-Lex consolidated form as amended by Regulation (EU) 2024/1183.

PDF · 729 KB · a long read

ReleasedCompliance & Certification
European Parliament; Council of the EUJul 23, 2014
Trust 64Needs review
RFC-7301

This document describes a Transport Layer Security (TLS) extension for application-layer protocol negotiation within the TLS handshake. For instances in which multiple application protocols are supported on the same TCP or UDP port, this extension allows the application layer to negotiate which protocol will be used within the TLS connection.

Web page · 144 KB · a short read

ReleasedProtocols
IETFJul 11, 2014
Trust 79Authoritative
RFC 7250Updated

Allows TLS/DTLS to use raw public keys instead of X.509 certificates, eliminating certificate chain overhead on ultra-constrained IoT devices. ~70% size reduction.

Web page · 47 KB · a short read

ReleasedProtocols
IETF TLSJun 2014
Trust 84Authoritative
RFC-7252Updated

IETF Standards Track specification of CoAP, a lightweight RESTful request/response protocol for constrained nodes and lossy networks, secured with DTLS (PreSharedKey, RawPublicKey or Certificate modes, with mandatory ECDHE-ECDSA on secp256r1 for the public-key modes). Not PQC-specific; it matters for PQC migration because its mandatory-to-implement DTLS key exchange and authentication are classical elliptic-curve algorithms embedded in long-lived IoT devices.

Web page · 320 KB · a long read

ReleasedProtocols
IETF; Z. Shelby (ARM); K. Hartke; C. Bormann (Universitaet Bremen TZI)Jun 2014
Trust 56Needs review
RFC 7228Updated

Defines terminology and device classes (Class 0-2) for constrained-node IoT networks, including RAM/Flash constraints. Foundation for IoT PQC algorithm selection.

Web page · 46 KB · a short read

ReleasedMigration Guidance
IETFMay 2014
Trust 85Authoritative
BIP-44

Defines multi-coin and multi-account HD wallet derivation path structure across blockchains.

Web page · 7 KB · a quick skim

ReleasedIndustry & ResearchHigh
Marek Palatinus; Pavol RusnakApr 24, 2014
Trust 46Needs review
BIP-43Updated

Bitcoin Improvement Proposal defining the purpose field for BIP-32 HD wallet derivation paths; referenced by noble/secp256k1 and @scure/bip32 cryptographic libraries in the library.

Web page · 284 KB · a long read

ReleasedBlockchain Standards
Bitcoin CoreApr 24, 2014
Trust 56Needs review
Ethereum-Yellow-PaperUpdated

Formal specification of the Ethereum Virtual Machine by Gavin Wood. Defines Keccak-256 address derivation and ECDSA signing.

PDF · 598 KB · a long read

Research PaperIndustry & ResearchHigh
Gavin Wood (Ethereum Foundation)2014
Trust 48Needs review
PCI-DSS-QRGUpdated

Free quick-reference guide to PCI DSS v4.0 — full standard paywalled, QRG is freely redistributable.

PDF · 1.5 MB · a long read

MiscCompliance & Certification
PCI Security Standards Council2014
Trust 86Authoritative
ZA-POPIA-TEXTUpdated

South Africa national personal-information protection law — crypto/key-management considered under security-safeguards obligation.

Web page · 41 KB · a short read

MiscCompliance & Certification
Republic of South AfricaNov 26, 2013
Trust 83Authoritative
IETF-RFC-7030-EST

IETF automated cert enrollment protocol, alongside ACME and CMP. Common for internal PKI under the CLM automation umbrella.

Web page · 604 KB · a long read

ReleasedMigration Guidance
IETFOct 23, 2013
Trust 88Authoritative
BIP-39

Standard for encoding entropy as a human-readable mnemonic phrase for wallet seed backup and recovery.

Web page · 7 KB · a quick skim

ReleasedIndustry & ResearchHigh
Marek Palatinus; Pavol Rusnak; Aaron Voisine; Sean BoweSep 10, 2013
Trust 47Needs review
RFC-7009Updated

This document proposes an additional endpoint for OAuth authorization servers, which allows clients to notify the authorization server that a previously obtained refresh or access token is no longer needed. This allows the authorization server to clean up security credentials. A revocation request will invalidate the actual token and, if applicable, other tokens based on the same authorization g

Web page · 178 KB · a long read

ReleasedProtocols
IETFAug 22, 2013
Trust 79Authoritative
IETF RFC 6979Updated

This document defines a deterministic digital signature generation procedure for DSA and ECDSA that eliminates the need for high-quality randomness during signature generation.

Web page · 542 KB · a long read

ReleasedAlgorithm Specifications
IETFAug 8, 2013
Trust 87Authoritative
RFC-6960

This document specifies a protocol useful in determining the current status of a digital certificate without requiring Certificate Revocation Lists (CRLs). Additional mechanisms addressing PKIX operational requirements are specified in separate documents. This document obsoletes RFCs 2560 and 6277. It also updates RFC 5912.

Web page · 420 KB · a long read

ReleasedProtocols
IETFJun 6, 2013
Trust 80Authoritative
RFC-6928Updated

This document proposes an experiment to increase the permitted TCP initial window (IW) from between 2 and 4 segments, as specified in RFC 3390, to 10 segments with a fallback to the existing recommendation when performance issues are detected. It discusses the motivation behind the increase, the advantages and disadvantages of the higher initial window, and presents results from several large-sca

Web page · 316 KB · a long read

ReleasedProtocols
IETFApr 29, 2013
Trust 78Authoritative
RFC-6763

This document specifies how DNS resource records are named and structured to facilitate service discovery. Given a type of service that a client is looking for, and a domain in which the client is looking for that service, this mechanism allows clients to discover a list of named instances of that desired service, using standard DNS queries. This mechanism is referred to as DNS-based Service Dis

Web page · 536 KB · a long read

ReleasedProtocols
IETFFeb 20, 2013
Trust 79Authoritative
AACS-Introduction-and-Common-Cryptographic-Elements-Book-RevUpdated

The Advanced Access Content System’s cryptographic elements — a long-lived content-protection scheme with keys embedded in shipped hardware.

PDF · 1.9 MB · a reference document — dip in, don’t read it through

ReleasedAlgorithm Specifications
AACS LA LLC (Intel, IBM, Microsoft, Panasonic, Sony, Toshiba, Disney, Warner Bros.)Oct 26, 2012
Trust 75Authoritative
RFC-6750

This specification describes how to use bearer tokens in HTTP requests to access OAuth 2.0 protected resources. Any party in possession of a bearer token (a "bearer") can use it to get access to the associated resources (without demonstrating possession of a cryptographic key). To prevent misuse, bearer tokens need to be protected from disclosure in storage and in transport. [STANDARDS-TRACK]

Web page · 243 KB · a long read

ReleasedProtocols
IETFOct 13, 2012
Trust 79Authoritative
RFC 6749Updated

Defines the OAuth 2.0 authorization framework enabling secure delegated access using access tokens. Access tokens and ID tokens issued by authorization servers are typically JWTs signed with RSA or ECDSA. PQC migration requires updating JWT signing across all OAuth authorization servers and resource server token validation.

Web page · 202 KB · a long read

ReleasedProtocolsHigh
IETFOct 2012
Trust 84Authoritative
NIST SP 800-30Updated

NIST's risk-assessment methodology, including the five-level qualitative scale (Very Low / Low / Moderate / High / Very High) used for likelihood and impact. Anchors the 5x5 risk matrices in the Command Center's Risk Register and Risk Heatmap tools.

PDF · 827 KB · a long read

ReleasedGovernment & Policy
NISTSep 2012
Trust 86Authoritative
RFC-6594Updated

This document updates the IANA registries in RFC 4255, which defines SSHFP, a DNS Resource Record (RR) that contains a standard Secure Shell (SSH) key fingerprint used to verify SSH host keys using DNS Security Extensions (DNSSEC). This document defines additional options supporting SSH public keys applying the Elliptic Curve Digital Signature Algorithm (ECDSA) and the implementation of fingerpri

Web page · 178 KB · a long read

ReleasedProtocols
IETFApr 7, 2012
Trust 79Authoritative
BIP-32Updated

Defines HD wallet key derivation from a single seed enabling deterministic generation of unlimited key pairs.

Web page · 28 KB · a quick skim

ReleasedIndustry & ResearchHigh
Pieter Wuille (Bitcoin Core)Feb 11, 2012
Trust 55Needs review
ANSI X9.63

ANSI standard specifying ECDH key agreement for financial services; a predecessor to NIST SP 800-56A for institutional adoption.

Web page · 33 KB · a quick skim

ReleasedAlgorithm SpecificationsHigh
ANSI X9Nov 1, 2011
Trust 54Needs review
RFC 6234Updated

Reference implementation and specification of SHA-224/256/384/512 (SHA-2) and HMAC/HKDF derivations; cited by PQC hybrid KDF specifications.

Web page · 272 KB · a long read

ReleasedAlgorithm Specifications
IETF; D. Eastlake 3rd; T. HansenMay 2011
Trust 80Authoritative
RFC 6176Updated

Formally prohibits SSL 2.0; part of the TLS deprecation chain alongside RFC 7568 (SSLv3) and RFC 8996 (TLS 1.0/1.1) that clears the path for TLS 1.3 + PQC hybrid.

Web page · 11 KB · a quick skim

ReleasedProtocolsHigh
IETFMar 2011
Trust 82Authoritative
RFC 6090Updated

Provides compact ECC algorithm descriptions for IETF implementers; referenced as an ECC foundation in documents discussing classical-to-PQC algorithm displacement.

Web page · 103 KB · a short read

ReleasedProtocolsHigh
IETFFeb 2011
Trust 79Authoritative
NIST-SP-800-132Updated

NIST SP 800-132 specifies PBKDF2 for password-based key derivation in IAM systems, credential vaults, and token signing key derivation. Quantum-safe when using PBKDF2-SHA-256 with sufficient iterations (≥10,000); key length should be ≥256 bits.

PDF · 129 KB · a short read

ReleasedNIST Standards
NISTDec 22, 2010
Trust 83Authoritative
ETSI-GS-QKD-003Updated

Defines QKD system components and their internal interfaces for interoperability.

PDF · 1.2 MB · a long read

ReleasedProtocols
ETSI ISG QKDDec 2010
Trust 84Authoritative
ETSI-GS-QKD-005Updated

Framework for security proofs of QKD protocols including BB84 and related variants.

PDF · 141 KB · a short read

ReleasedIndustry & Research
ETSI ISG QKDDec 2010
Trust 82Authoritative
ETSI-GS-QKD-008Updated

Security requirements and evaluation criteria for QKD modules analogous to Common Criteria.

PDF · 322 KB · a short read

ReleasedKEM
ETSI ISG QKDDec 2010
Trust 84Authoritative
RFC-6024Updated

A trust anchor represents an authoritative entity via a public key and associated data. The public key is used to verify digital signatures, and the associated data is used to constrain the types of information for which the trust anchor is authoritative. A relying party uses trust anchors to determine if a digitally signed object is valid by verifying a digital signature using the trust anchor'

Web page · 221 KB · a long read

ReleasedProtocols
IETFOct 25, 2010
Trust 79Authoritative
RFC-6019Updated

This document specifies a new ASN.1 type for representing time: BinaryTime. This document also specifies an alternate to the signing-time attribute for use with the Cryptographic Message Syntax (CMS) SignedData and AuthenticatedData content types; the binary-signing-time attribute uses BinaryTime. CMS and the signing-time attribute are defined in RFC 5652. [STANDARDS-TRACK]

Web page · 113 KB · a short read

ReleasedProtocols
IETFSep 24, 2010
Trust 79Authoritative
RFC 5958Updated

Defines OneAsymmetricKey (PKCS#8v2) for private key storage; used in PQC key serialization for ML-KEM and ML-DSA private keys exported from HSMs.

Web page · 35 KB · a quick skim

ReleasedPKI Certificate ManagementHigh
IETFAug 2010
Trust 83Authoritative
ETSI-GS-QKD-002Updated

Use cases for quantum key distribution including government communications and financial networks.

PDF · 893 KB · a long read

ReleasedIndustry & Research
ETSI ISG QKDJun 2010
Trust 83Authoritative
RFC 5912Updated

ASN.1 2002 syntax modules for PKIX including certificates, CRL, and OCSP — foundational for PQC composite certificate encoding.

Web page · 244 KB · a long read

ReleasedPKI Certificate Management
IETF; P. Hoffman; J. SchaadJun 2010
Trust 82Authoritative
RFC 5911Updated

ASN.1 2002 syntax modules for CMS and S/MIME; used by PQC composite signature and KEM RFCs for algorithm identifier structures.

Web page · 118 KB · a short read

ReleasedProtocols
IETF; P. Hoffman; J. SchaadJun 2010
Trust 82Authoritative
RFC 5903Updated

Web page · 39 KB · a quick skim

ReleasedProtocols
IETF (D. Fu, J. Solinas)Jun 2010
Trust 31Needs review
RFC-5763

This document specifies how to use the Session Initiation Protocol (SIP) to establish a Secure Real-time Transport Protocol (SRTP) security context using the Datagram Transport Layer Security (DTLS) protocol. It describes a mechanism of transporting a fingerprint attribute in the Session Description Protocol (SDP) that identifies the key that will be presented during the DTLS handshake. The key

Web page · 432 KB · a long read

ReleasedProtocols
IETFMay 11, 2010
Trust 80Authoritative
RFC 5869Updated

RFC 5869 defines HKDF: HKDF-Extract(salt, IKM) → PRK binds input keying material to a salt; HKDF-Expand(PRK, info, L) derives L bytes bound to a context string preventing cross-protocol key reuse (§3.2). Used in TLS 1.3, IKEv2, and PQC envelope encryption to derive AES wrapping keys from ML-KEM shared secrets per SP 800-56C Rev 2 §4.

Web page · 33 KB · a quick skim

ReleasedProtocols
IETF; H. Krawczyk; P. EronenMay 2010
Trust 84Authoritative
NIST-SP-800-22-R1A

NIST statistical test suite defining 15 statistical tests (Monobit, Runs, Chi-Squared, DFT, Serial, and more) for evaluating randomness quality of bit sequences produced by cryptographic RBGs. Used for validating entropy source output quality prior to NIST ESV submission.

PDF · 7.6 MB · a reference document — dip in, don’t read it through

ReleasedNIST Standards
NISTApr 30, 2010
Trust 86Authoritative
SEC2-v2

SECG standard defining domain parameters for secp256k1 and other elliptic curves used by Bitcoin and Ethereum.

PDF · 307 KB · a short read

ReleasedAlgorithm SpecificationsHigh
Standards for Efficient Cryptography Group (SECG)Jan 27, 2010
Trust 52Needs review
Regev-LWE-SurveyUpdated

Oded Regev’s foundational survey introducing and analysing the Learning with Errors (LWE) problem. LWE is the core hardness assumption underlying ML-KEM (FIPS 203) and ML-DSA (FIPS 204). Won the 2018 Gödel Prize. Essential reading for understanding why lattice-based PQC is believed to be quantum-resistant.

PDF · 652 KB · a long read

Research PaperAlgorithm Specifications
Oded Regev (Courant Institute, NYU)2010
Trust 70Authoritative
RFC 5754Updated

Specifies how to use SHA-224, SHA-256, SHA-384, SHA-512 within CMS (PKCS#7) for digital signatures and message authentication.

Web page · 30 KB · a quick skim

ReleasedProtocols
IETF; S. TurnerJan 2010
Trust 78Authoritative
A-Public-Key-Cryptosystem-Based-On-Algebraic-Coding-TheoryUpdated

PDF · 16.0 MB · a reference document — dip in, don’t read it through

Research PaperMigration Guidance
Unknown2010
Trust 26Needs review
ISO-10681-1-2010-Road-vehicles-Communication-on-FlexRay-Part

ReleasedMigration Guidance
ISO/IEC2010
Trust 9Needs review
Purchase required
IETF RFC 5656Updated

Elliptic Curve Algorithm Integration in the Secure Shell Transport Layer

Web page · 257 KB · a long read

ReleasedMigration Guidance
IETFDec 14, 2009
Trust 89Authoritative
IETF RFC 5649Updated

RFC 5649 extends RFC 3394 AES Key Wrap with a padding scheme for arbitrary-length plaintexts. The 8-byte Alternative Initial Value (AIV) includes a fixed 4-byte constant (0xA65959A6) and a 4-byte plaintext length. Wrapping a 32-byte DEK produces 48 bytes. Used as CKM_AES_KEY_WRAP_KWP in PKCS#11 v3.2.

Web page · 156 KB · a long read

ReleasedAlgorithm Specifications
IETFSep 17, 2009
Trust 89Authoritative
RFC 5652Updated

Core CMS standard defining SignedData, EnvelopedData, and AuthEnvelopedData structures. Foundation for S/MIME email signing and encryption. All PQC CMS RFCs (9629, 9882, 9814, 9708, 9690) extend this format.

Web page · 153 KB · a long read

ReleasedProtocolsHigh
IETF SMIME WGSep 2009
Trust 82Authoritative
SEC 1Updated

SECG SEC 1 v2.0 defines elliptic curve public key operations, point encoding, and ECIES; widely implemented in TLS, SSH, and PKCS#11 stacks undergoing PQC migration.

PDF · 970 KB · a long read

ReleasedAlgorithm SpecificationsHigh
SECGMay 21, 2009
Trust 58Needs review
IETF RFC 5480

Elliptic Curve Cryptography Subject Public Key Information

Web page · 218 KB · a long read

ReleasedMigration Guidance
IETFMar 10, 2009
Trust 87Authoritative
HITECH-PL-111-5Updated

Health Information Technology for Economic and Clinical Health Act — HIPAA breach notification, ePHI encryption incentives.

Web page · 1.4 MB · a long read

ReleasedCompliance & Certification
US CongressFeb 17, 2009
Trust 85Authoritative
HIPAA-Administrative-Simplification-Enforcement-Interim-Fina

PDF · 78 KB · a short read

ReleasedMigration Guidance
Unknown2009
Trust 26Needs review
Bernstein-Lange-PQC-SurveyUpdated

Foundational academic book edited by Daniel J. Bernstein and Tanja Lange (Springer 2009) covering all major families of post-quantum cryptography: lattice-based, code-based, hash-based, and multivariate. Essential reference for understanding the mathematical foundations of PQC algorithms before the NIST standardization era.

Web page · 269 KB · a long read

Research PaperAlgorithm Specifications
TU Eindhoven; Ruhr University BochumNov 19, 2008
Trust 47Needs review
Bitcoin-WhitepaperUpdated

Satoshi Nakamoto foundational paper introducing Bitcoin and blockchain: proof-of-work consensus and ECDSA-based ownership.

PDF · 184 KB · a short read

Research PaperIndustry & ResearchHigh
Satoshi NakamotoOct 31, 2008
Trust 50Needs review
FIPS-198-1Updated

FIPS 198-1 specifies HMAC, a mechanism for message authentication using cryptographic hash functions. HMAC-SHA-256 is used for session token integrity in IAM. Quantum-safe: HMAC based on SHA-2/SHA-3 remains secure post-quantum assuming ≥256-bit output.

PDF · 129 KB · a short read

ReleasedNIST Standards1 rev
NISTJul 16, 2008
Trust 83Authoritative
RFC 5280Updated

Establishes X.509 v3 certificate format, extensions, revocation lists, and PKI path validation; foundational reference for hybrid and pure PQC certificate formats.

Web page · 417 KB · a long read

ReleasedPKI Certificate ManagementHigh
D. Cooper; S. Santesson; S. Farrell; S. Boeyen; R. Housley; W. PolkMay 2008
Trust 65Needs review
RFC-5234

Internet technical specifications often need to define a formal syntax. Over the years, a modified version of Backus-Naur Form (BNF), called Augmented BNF (ABNF), has been popular among many Internet specifications. The current specification documents ABNF. It balances compactness and simplicity with reasonable representational power. The differences between standard BNF and ABNF involve namin

Web page · 205 KB · a long read

ReleasedProtocols
IETFJan 31, 2008
Trust 78Authoritative
Summary-of-the-HIPAA-Privacy-RuleUpdated

Web page · 281 KB · a long read

MiscMigration Guidance
HHS.gov2008
Trust 26Needs review
RFC 5083Updated

Defines AuthEnvelopedData content type for AEAD-based encryption in CMS. The authenticated-enveloped structure with AES-GCM provides both confidentiality and integrity — the preferred encryption mode for PQC email migration via RFC 9629.

Web page · 28 KB · a quick skim

ReleasedProtocolsHigh
IETF SMIME WGNov 2007
Trust 79Authoritative
NIST SP 800-111Updated

Guide to Storage Encryption Technologies for End User Devices

PDF · 224 KB · a short read

ReleasedGovernment & Policy
NISTNov 2007
Trust 87Authoritative
NIST-SP-800-38DUpdated

NIST SP 800-38D specifies GCM and GMAC for AES. GCM provides authenticated encryption using a 96-bit (12-byte) nonce and a 16-byte authentication tag appended to ciphertext. Nonce uniqueness per key is mandatory — reuse lets an attacker recover the keystream and forge authentication tags (SP 800-38D §8). Used as CKM_AES_GCM in PKCS#11 v3.2.

PDF · 272 KB · a short read

ReleasedAlgorithm Specifications
NISTNov 2007
Trust 90Authoritative
RFC 5056Updated

Framework for tying application-layer authentication to the security context of the underlying channel; relevant for hybrid PQC channel binding in TLS and IKEv2.

Web page · 63 KB · a short read

ReleasedProtocols
IETFNov 2007
Trust 82Authoritative
AUSTRAC-AML-CTF-ActUpdated

Anti-Money Laundering and Counter-Terrorism Financing Act 2006 — enforced by AUSTRAC. Regulated reporting entities (banks, fintechs, crypto exchanges, and post-2024 reforms: lawyers, accountants, real estate agents) must maintain secure cryptographic systems for AUSTRAC reporting and transaction record-keeping. Integrity and authenticity controls over financial intelligence data are in scope.

Web page · 290 KB · a long read

ReleasedGovernment & Policy
AUSTRAC; Australian Transaction Reports and Analysis CentreDec 12, 2006
Trust 85Authoritative
IETF RFC 4556

Public Key Cryptography for Initial Authentication in Kerberos (PKINIT)

Web page · 452 KB · a long read

ReleasedMigration Guidance
IETFJun 30, 2006
Trust 87Authoritative
ISO/IEC 18033-2:2006

ISO/IEC 18033-2 specifies asymmetric encryption algorithms including RSA-OAEP and HIME(R); referenced in cross-national cryptographic equivalence analyses for PQC transition.

Web page · 102 KB · a short read

ReleasedInternational FrameworksHigh
ISO/IEC JTC 1/SC 27May 1, 2006
Trust 63Needs review
RFC 4419Updated

Defines runtime DH group negotiation for SSH-2; the PQC SSH drafts replace this with ML-KEM key exchange while maintaining the group exchange signaling model.

Web page · 23 KB · a quick skim

ReleasedProtocolsHigh
IETFMar 2006
Trust 83Authoritative
RFC-4255Updated

This document describes a method of verifying Secure Shell (SSH) host keys using Domain Name System Security (DNSSEC). The document defines a new DNS resource record that contains a standard SSH key fingerprint. [STANDARDS-TRACK]

Web page · 158 KB · a long read

ReleasedProtocols
IETFJan 6, 2006
Trust 79Authoritative
RFC 4251Updated

Defines the SSH architectural framework covering transport layer, user authentication, and connection multiplexing for secure remote access.

Web page · 89 KB · a short read

ReleasedProtocols
Tatu Ylonen; Chris M. Lonvick (Ed.)Jan 2006
Trust 65Needs review
RFC 4253Updated

Defines the SSH transport layer including key exchange, server authentication, and encryption. The key exchange phase is where QKD-derived pre-shared keys can be injected via the ext-info mechanism or future SSH KEX extensions. Foundational standard for understanding QKD integration into SSH.

Web page · 86 KB · a short read

ReleasedProtocols
Tatu Ylonen; Chris M. Lonvick (Ed.)Jan 2006
Trust 92Authoritative
ISO/IEC 18033-2:2006/AMD1:2017

Amendment 1 to ISO/IEC 18033-2, adding the FACE asymmetric cipher. Classical, NOT post-quantum — the row previously claimed "Post-Quantum KEMs including FrodoKEM alignment" and linked to an unrelated standard (ISO 8144-1 mineral wool insulation). The post-quantum content of ISO/IEC 18033-2 is in Amendment 2:2026 (FrodoKEM, Classic McEliece, ML-KEM).

Web page · 80 KB · a short read

ReleasedInternational Frameworks
ISO/IEC JTC 1/SC 272006
Trust 80Authoritative
RFC 4250Updated

Registry of SSH protocol algorithm names and identifiers; being updated to include ML-KEM and ML-DSA algorithm names for post-quantum SSH key exchange.

Web page · 63 KB · a short read

ReleasedProtocolsHigh
IETFJan 2006
Trust 82Authoritative
RFC 4252Updated

Defines the SSH-2 user authentication layer; being updated for PQC public-key authentication methods using ML-DSA host keys.

Web page · 43 KB · a short read

ReleasedProtocolsHigh
IETFJan 2006
Trust 84Authoritative
RFC 4254Updated

Defines the SSH-2 connection multiplexing protocol; the connection layer operates over PQC-secured channels when quantum-resistant key exchange is negotiated.

Web page · 62 KB · a short read

ReleasedProtocolsHigh
IETFJan 2006
Trust 82Authoritative
ISO-IEC-18033-2-2006-Amd-2-2026-Information-technology-Secur

The 2026 amendment adding post-quantum KEMs to the ISO/IEC 18033-2 encryption-algorithms standard.

Web page · 84 KB · a short read

ReleasedInternational FrameworksHigh
ISO/IEC JTC 1/SC 272006
Trust 80Authoritative
ARINC-Standard-811Updated

Aviation information-security concepts and process framework — the vocabulary an aircraft programme uses when arguing a cryptographic change is safe.

Web page · 142 KB · a short read

ReleasedAlgorithm Specifications
Airlines Electronic Engineering Committee (AEEC); SAE Industry Technologies Consortia IADec 20, 2005
Trust 71Authoritative
RFC 4301Updated

Provides the IPsec architectural framework for security services at the IP layer; foundation for all IKEv2 and ESP PQC migration work.

Web page · 299 KB · a long read

ReleasedProtocols
Stephen Kent; Karen Seo (BBN Technologies)Dec 2005
Trust 63Needs review
RFC 4303Updated

Defines the ESP protocol for confidentiality, data origin authentication, integrity, and anti-replay in IPv4/IPv6; requires PQC-aware encryption updates.

Web page · 131 KB · a short read

ReleasedProtocols
Stephen Kent (BBN Technologies)Dec 2005
Trust 63Needs review
RFC 4302Updated

Defines the IPsec AH protocol for data origin authentication and integrity; used in IKEv2 tunnels being updated for PQC algorithm negotiation.

Web page · 100 KB · a short read

ReleasedProtocolsHigh
IETFDec 2005
Trust 82Authoritative
ANSI X9.62

ANSI standard specifying ECDSA for financial services; defines elliptic curve parameters and signature operations now being superseded by ML-DSA in PQC migration.

Web page · 33 KB · a quick skim

ReleasedAlgorithm SpecificationsHigh
ANSI X9Nov 1, 2005
Trust 55Needs review
Purchase required
RFC 4056Updated

Specifies RSASSA-PSS algorithm identifier for X.509 certificates; relevant for hybrid certificate schemes combining classical RSA with PQC signatures.

Web page · 16 KB · a quick skim

ReleasedPKI Certificate ManagementHigh
IETFJun 2005
Trust 84Authoritative
OASIS-SAML-2-0-CoreUpdated

Core SAML 2.0 specification defining XML-based authentication and authorization assertions used in enterprise SSO and identity federation. PQC migration requires replacing RSA/ECDSA XML signatures with ML-DSA equivalents.

PDF · 630 KB · a long read

ReleasedProtocolsHigh
OASIS Security Services TCMar 15, 2005
Trust 84Authoritative
RFC 4034

Base DNSSEC RR formats (DNSKEY, RRSIG, NSEC, DS). Classical-only; PQ adoption pending IANA codepoint assignment.

Web page · 139 KB · a short read

ReleasedProtocols
R. Arends; R. Austein; M. Larson; D. Massey; S. RoseMar 2005
Trust 89Authoritative
ANSSI-PG-083-v3-2026

ANSSI cryptographic algorithm rules and recommendations v3.00 — first update since 2020 and first version to explicitly address the quantum threat. Covers symmetric crypto (AES, block/stream ciphers, MAC, hash), asymmetric crypto (factorisation, discrete log, lattice/LWE), key encapsulation, digital signatures, entity authentication, and random number generation. Licensed Licence Ouverte v2.0.

PDF · 1.4 MB · a long read

ReleasedCompliance & CertificationHigh
ANSSINov 19, 2004
Trust 85Authoritative
IEEE 1363a

IEEE 1363a extends IEEE 1363 with additional DL-based schemes; referenced alongside its parent standard in legacy cryptography displacement analysis.

ReleasedAlgorithm SpecificationsHigh
IEEESep 2, 2004
Trust 68Needs review
FIPS 199Updated

Standards for Security Categorization of Federal Information and Information Systems

Web page · 44 KB · a short read

ReleasedGovernment & Policy
NISTFeb 2004
Trust 90Authoritative
RFC-3647Updated

This document presents a framework to assist the writers of certificate policies or certification practice statements for participants within public key infrastructures, such as certification authorities, policy authorities, and communities of interest that wish to rely on certificates. In particular, the framework provides a comprehensive list of topics that potentially (at the writer's discreti

Web page · 817 KB · a long read

ReleasedProtocols
IETFNov 5, 2003
Trust 79Authoritative
RFC 3560Updated

Specifies RSASSA-PSS for CMS SignedData; RSASSA-PSS is the preferred RSA signature scheme in FIPS 186-5 and is referenced in PQC hybrid signature composite RFCs.

Web page · 45 KB · a short read

ReleasedProtocolsHigh
IETFJul 2003
Trust 84Authoritative
RFC 3394Updated

Defines the AES key wrap algorithm used to protect symmetric keys in CMS and PKCS#11; used in hybrid PQC schemes that wrap classical keys with ML-KEM-derived symmetric keys.

Web page · 119 KB · a short read

ReleasedProtocols
IETFSep 2002
Trust 81Authoritative
RFC 3370Updated

Specifies RSA, DSA, DH, and hash algorithm identifiers for CMS; the PQC CMS RFCs (RFC 9629, draft composites) augment this with ML-KEM/ML-DSA identifiers.

Web page · 63 KB · a short read

ReleasedProtocolsHigh
IETFAug 2002
Trust 84Authoritative
Security-Requirements-for-Cryptographic-Modules

Web page · 46 KB · a short read

ReleasedMigration Guidance
CSRC | NIST2002
Trust 26Needs review
RFC-3161-Internet-X-509-Public-Key-Infrastructure-Time-Stamp

Defines the Time-Stamp Protocol. Timestamps must remain verifiable for decades, which makes them one of the sharpest post-quantum signature problems.

Web page · 55 KB · a short read

ReleasedProtocolsPKI Certificate Management
IETFAug 2001
Trust 62Needs review
IEEE 1363

IEEE 1363 defines RSA, DL, and EC public-key schemes including ECDH, ECDSA, and ECIES; foundational reference for classical algorithms being superseded in PQC migration.

ReleasedAlgorithm SpecificationsHigh
IEEEAug 29, 2000
Trust 78Authoritative
ISO-IEC-17799-2000Updated

The original code of practice for information security management, ancestor of ISO/IEC 27002. Cited where legacy control mappings still reference it.

Web page · 76 KB · a short read

ExpiredInternational Frameworks
ISO/IEC JTC 1/SC 272000
Trust 83Authoritative
ISO-14971-2000Updated

Risk management for medical devices. Governs whether a cryptographic change to a device is treated as a design change requiring re-assessment.

Web page · 78 KB · a short read

ExpiredCompliance & Certification
ISO/TC 2102000
Trust 80Authoritative
COPPA-16-CFR-312Updated

US Children's Online Privacy Protection Rule — consent and data-handling for services directed to under-13 users.

Web page · 159 KB · a long read

ReleasedCompliance & Certification
US FTCOct 21, 1998
Trust 80Authoritative
RFC-2397Updated

A new URL scheme, "data", is defined. It allows inclusion of small data items as "immediate" data, as if it had been included externally. [STANDARDS-TRACK]

Web page · 107 KB · a short read

ReleasedProtocols
IETFAug 1, 1998
Trust 78Authoritative
FDA-21-CFR-11Updated

US FDA rule for electronic records and signatures in FDA-regulated activities — crypto and audit-trail controls.

Web page · 109 KB · a short read

ReleasedCompliance & Certification
US FDAMar 20, 1997
Trust 81Authoritative
RFC 2119Updated

Defines normative requirement level keywords (MUST, SHOULD, MAY, etc.) used throughout IETF RFCs including all PQC protocol specifications.

Web page · 6 KB · a quick skim

ReleasedAlgorithm Specifications
IETF; S. BradnerMar 1997
Trust 82Authoritative
NIAPUpdated

NIAP administers the U.S. implementation of Common Criteria; mandates evaluated cryptographic modules meet CNSA 2.0 algorithm requirements as PQC standards are finalized.

Web page · 84 KB · a short read

MiscGovernment & PolicyHigh
NSA; NIST1997
Trust 80Authoritative
The-Art-of-Computer-Programming-Volume-2-Seminumerical-Algor

ReleasedMigration Guidance
Unknown1997
Trust 9Needs review
Purchase required
HIPAA-45-CFR-164Updated

US Health Insurance Portability and Accountability Act Security Rule — administrative, physical, and technical safeguards for ePHI.

Web page · 686 KB · a long read

ReleasedCompliance & Certification
US HHSAug 21, 1996
Trust 84Authoritative
RFC-1950Updated

This specification defines a lossless compressed data format. This memo provides information for the Internet community. This memo does not specify an Internet standard of any kind.

Web page · 140 KB · a short read

ReleasedProtocols
IETFMay 1, 1996
Trust 78Authoritative
RFC 1847Updated

Defines MIME multipart/signed and multipart/encrypted content types; foundational for S/MIME which is being updated for PQC algorithm identifiers.

Web page · 67 KB · a short read

ReleasedProtocols
IETFOct 1995
Trust 84Authoritative
AU-Privacy-Act-APPsUpdated

Privacy Act 1988 (Cth) with Australian Privacy Principles — enforced by the OAIC. APP 11 requires organisations to take reasonable steps to protect personal information, including robust cryptographic controls. Harvest-now-decrypt-later attacks on personal financial data directly implicate long-term cryptographic security. 2024 reforms increased penalties up to AU$50M for serious breaches.

Web page · 299 KB · a long read

ReleasedGovernment & PolicyHigh
OAIC; Office of the Australian Information CommissionerDec 14, 1988
Trust 85Authoritative
FERPA-34-CFR-99Updated

US Family Educational Rights and Privacy Act — education records privacy requirements.

Web page · 281 KB · a long read

ReleasedCompliance & Certification
US EDAug 21, 1974
Trust 83Authoritative
ICAO-Assembly-Resolution-A41-19-Aviation-Cybersecurity

PDF · 124 KB · a short read

ReleasedGovernment & Policy
Unknown
Trust 28Needs review
10-CFR-73-54-Protection-of-Digital-Computer-and-CommunicatioUpdated

Web page · 82 KB · a short read

ReleasedGovernment & Policy
Unknown
Trust 28Needs review
Munich-Re-Cyber-Insurance-Risks-and-Trends-2025Updated

Web page · 135 KB · a short read

MiscIndustry & Research
Unknown
Trust 29Needs review
HHS-HIPAA-Security-Rule-45-CFR-Part-164-Subpart-CUpdated

Web page · 146 KB · a short read

ReleasedGovernment & Policy
Unknown
Trust 28Needs review
Federal-PKI-Policy-AuthorityUpdated

Web page · 158 KB · a long read

MiscGovernment & Policy
Unknown
Trust 29Needs review
Internet2-InCommon-FederationUpdated

Web page · 141 KB · a short read

MiscIndustry & Research
Unknown
Trust 36Needs review
FDA-DSCSA-Standards-for-the-Interoperable-Exchange-of-Inform

PDF · 243 KB · a short read

ReleasedGovernment & Policy
Unknown
Trust 29Needs review
FDA-Drug-Supply-Chain-Security-Act-DSCSAUpdated

Web page · 47 KB · a short read

MiscGovernment & Policy
Unknown
Trust 33Needs review
49-CFR-Part-236-Subpart-I-Positive-Train-Control-SystemsUpdated

Web page · 354 KB · a long read

ReleasedGovernment & Policy
Unknown
Trust 29Needs review
IMO-Maritime-Cyber-Risk-Management-Guidelines

PDF · 198 KB · a short read

ReleasedGovernment & Policy
Unknown
Trust 34Needs review
EPA-America-s-Water-Infrastructure-Act-AWIA-Section-2013Updated

Web page · 75 KB · a short read

MiscGovernment & Policy
Unknown
Trust 28Needs review
A-First-Look-at-Digital-Rights-Management-Systems-for-SecureUpdated

Web page · 41 KB · a short read

Research PaperIndustry & Research
Unknown
Trust 43Needs review
Ethereum-Foundation-Roadmap-Account-AbstractionUpdated

Web page · 305 KB · a long read

MiscIndustry & Research
Unknown
Trust 37Needs review
Mastercard-Migration-to-Post-Quantum-Cryptography-White-PapeUpdated

PDF · 2.4 MB · a reference document — dip in, don’t read it through

MiscIndustry & Research
Unknown
Trust 40Needs review
PCI-DSS-v4-0-1-Requirements-and-Testing-ProceduresUpdated

PDF · 4.5 MB · a reference document — dip in, don’t read it through

ReleasedAlgorithm SpecificationsReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
Unknown
Trust 29Needs review
FDA-Cybersecurity-in-Medical-Devices-Premarket-Guidance-2023

PDF · 1.2 MB · a long read

ReleasedGovernment & Policy
Unknown
Trust 35Needs review
EPA-Cybersecurity-for-the-Water-SectorUpdated

Web page · 59 KB · a short read

MiscGovernment & Policy
Unknown
Trust 28Needs review
University-of-Toronto-Researcher-Leads-Effort-to-Protect-PowUpdated

Web page · 142 KB · a short read

MiscIndustry & Research
Unknown
Trust 35Needs review
Solana-Docs-TransactionsUpdated

Official Solana developer documentation for transaction structure. States each signer provides one 64-byte Ed25519 signature per transaction, including validator vote transactions (ordinary transactions in Solana's architecture, not a separate consensus-layer scheme). Also documents the 1,232-byte max transaction size (IPv6 MTU-derived) and 150-slot blockhash expiry.

Web page · 796 KB · a long read

MiscBlockchain Standards
Solana Foundation
Trust 45Needs review
CIP-3-Wallet-key-generation-BIP32-Ed25519Updated

Cardano Improvement Proposal documenting the key-derivation algorithms used across the Cardano wallet ecosystem. Cardano HD wallets use a variation of BIP-32 called ED25519-BIP32 (extended Ed25519): the master key is a 96-byte extended private key (64-byte extended Ed25519 secret key + 32-byte chain code). Documents four historical master-key schemes (Byron, deprecated; Icarus, current recommended; Icarus-Trezor; Ledger/BitBox02).

Web page · 278 KB · a long read

ReleasedBlockchain Standards
Matthias Benkort; Sebastien Guillemot
Trust 45Needs review
Cardano-cardano-crypto-praos-VRF-suite-ECVRF-ED25519-SHA512Updated

IntersectMBO/cardano-base source file (cardano-crypto-praos/cbits/crypto_vrf.h) pinning Cardano's production VRF choice: 'SUITE = 0x04 /* ECVRF-ED25519-SHA512-ELL2 */', built on the ietfdraft13 primitive — the suite RFC 9381 (Verifiable Random Functions) later standardized as ECVRF-EDWARDS25519-SHA512-ELL2, suite_string 0x04.

Web page · 288 KB · a long read

MiscBlockchain Standards
IntersectMBO (Cardano engineering)
Trust 45Needs review
input-output-hk-kes-Cardano-Key-Evolving-Signatures-Sum6KesUpdated

IOG's Rust implementation of Cardano's Key-Evolving Signature (KES) scheme: the 'sum' composition from Malkin/Micciancio/Miner's forward-secure-signature paper, using Ed25519 (via ed25519_dalek, strict verification) as the depth-zero signature algorithm. Cardano production uses Sum6Kes (2^6 = 64 key evolutions); SumCompact6Kes offers an asymptotically smaller signature.

Web page · 282 KB · a long read

MiscBlockchain Standards
Input Output (IOG)
Trust 46Needs review
Chainlink-Off-chain-Reporting-Protocol-3-0-OCR3Updated

Chainlink Labs research paper specifying OCR3, the off-chain consensus protocol behind Chainlink's price/data-feed oracle network. Digital signatures use standard elliptic-curve schemes: protocol-internal node-to-node signatures are 'typically' EdDSA, while the final on-chain attestation a consuming smart contract verifies is 'typically implemented by ECDSA' — the paper is explicit that the exact scheme depends on context and the target blockchain, not a single fixed algorithm.

PDF · 1.1 MB · a long read

Research PaperIndustry & Research
Lorenz Breidenbach; Christian Cachin
Trust 45Needs review
Safe-Wallet-Safe-sol-multisig-signature-verificationUpdated

Safe (formerly Gnosis Safe) smart-account contract source. checkNSignatures() enforces an M-of-N owner threshold on-chain: each of the required signatures is verified independently — ECDSA via ecrecover by default, plus EIP-1271 contract signatures, EIP-191, pre-approved hashes, and secp256r1/passkey signatures via the RIP-7212 precompile — with owner addresses required in strict ascending order to prevent duplicate counting. A plain multisig, not an aggregated threshold signature scheme.

Web page · 129 KB · a short read

MiscBlockchain Standards
Safe Ecosystem Foundation
Trust 47Needs review
Wormhole-Docs-VAAs-Guardian-signature-schemeUpdated

Official Wormhole documentation for VAAs (Verifiable Action Approvals) — the cross-chain message-attestation format signed by Wormhole's 19-member Guardian network. Each Guardian independently ECDSA-signs a keccak256 double-hash of the message body; once 13 of 19 (two-thirds supermajority) signatures are collected, they are combined with the message into a VAA. A plain M-of-N multisig, not an aggregated threshold signature.

Web page · 172 KB · a long read

MiscBlockchain Standards
Wormhole Foundation
Trust 45Needs review
Polkadot-Wiki-Cryptography-sr25519-BABEUpdated

Official Polkadot Wiki page on cryptography. Documents three account-signing options — sr25519 (Schnorrkel, primary), Ed25519, and ECDSA/secp256k1 — and states BABE consensus uses sr25519 keys because they support both VRF and digital-signature roles. Notes 'no differences in security between ed25519 and sr25519 for simple signatures.'

Web page · 129 KB · a short read

MiscBlockchain Standards
Web3 Foundation
Trust 45Needs review
CometBFT-Docs-Validators-Ed25519-consensus-signingUpdated

Official CometBFT documentation for validators. States 'Currently CometBFT uses Ed25519 keys which are widely supported across the security sector and HSMs' for signing consensus votes/precommits — the consensus engine underlying the Cosmos Hub and every Cosmos SDK chain.

Web page · 485 KB · a long read

MiscBlockchain Standards
Interchain Foundation
Trust 45Needs review
Avalanche-Docs-Cryptographic-PrimitivesUpdated

Official Avalanche developer documentation for cryptographic primitives. States: 'The Avalanche virtual machine uses elliptic curve cryptography, specifically secp256k1, for its signatures on the blockchain.' X-Chain/P-Chain addressing also relies on secp256k1, hashing the ECDSA public key like Bitcoin.

Web page · 675 KB · a long read

MiscBlockchain Standards
Ava Labs
Trust 45Needs review
Avalanche-Docs-What-is-ICM-Warp-Messaging-BLSUpdated

Official Avalanche developer documentation for Interchain Messaging (ICM, formerly Avalanche Warp Messaging). 'ICM uses the BLS signature scheme, which allows message recipients to verify the authenticity of these messages... every validator on the Avalanche network holds a BLS key pair.' Signatures from a threshold of the source subnet's stake are aggregated into a single BLS multi-signature — a genuine aggregated threshold signature, unlike the plain N-signature multisig Wormhole and Safe use.

Web page · 603 KB · a long read

MiscBlockchain Standards
Ava Labs
Trust 45Needs review
Arbitrum-Docs-Inside-AnyTrust-DAC-BLS-signingUpdated

Official Arbitrum documentation for the AnyTrust protocol. AnyTrust chains use a Data Availability Committee (DAC, N members, 2-of-N honesty assumption): each member signs (data hash, expiry) with a BLS key; once enough signatures are collected the sequencer aggregates them into 'a BLS aggregated signature (over the BLS12-381 curve)' forming a DACert, posted to the L1 inbox contract. No mention of ECDSA for this specific mechanism — it is BLS end to end.

Web page · 32 KB · a quick skim

MiscBlockchain Standards
Offchain Labs
Trust 44Needs review
3GPP-TS-35-216-SNOW-3G-SpecificationUpdated

ETSI TS 135 216 V17.0.0 (2022-04), 'Specification of the 3GPP Confidentiality and Integrity Algorithms UEA2 & UIA2; Document 2: SNOW 3G specification.' The stream cipher underlying UMTS/LTE's 128-EEA1/128-EIA1 confidentiality and integrity algorithms.

PDF · 81 KB · a short read

ReleasedBlockchain Standards
ETSI / 3GPP SAGEApr 1, 2022
Trust 62Needs review
3GPP-TS-35-222-ZUC-SpecificationUpdated

ETSI TS 135 222 V17.0.0 (2022-04), 'Specification of the 3GPP Confidentiality and Integrity Algorithms EEA3 & EIA3; Document 2: ZUC specification.' The stream cipher underlying LTE's 128-EEA3/128-EIA3 algorithms, carried forward into 5G.

PDF · 79 KB · a short read

ReleasedBlockchain Standards
ETSI / 3GPP SAGEApr 1, 2022
Trust 62Needs review
Internet2-PQC-Demo-on-the-National-BackboneUpdated

Internet2, with Ciena and Purism, ran a live PQC demonstration on a 1,390-mile Albuquerque-Las Vegas segment of the Internet2 national R&E backbone: 'FIPS 203-compliant solution was used for both quantum-safe encryption and quantum-safe key exchange,' at 10 Gbps line rate.

Web page · 145 KB · a short read

MiscIndustry & Research
Internet2; Ciena; Purism
Trust 58Needs review
IETF-LAMPS-Composite-ML-DSA-Signatures-draft-19-RFC-Ed-QueueUpdated

IETF LAMPS WG composite-signature draft, version 19, now in the RFC Editor Queue awaiting publication: 'This document defines combinations of ML-DSA in hybrid with traditional algorithms RSASSA-PKCS1-v1.5, RSASSA-PSS, ECDSA, Ed25519, and Ed448.' Defines composite X.509 certificate signing, not a TLS-handshake profile.

Web page · 799 KB · a long read

DraftInternational Frameworks
M. Ounsworth; J. Gray; M. Pala; J. Klaussner; S. Fluhrer (IETF LAMPS WG)
Trust 59Needs review
GSMA-PQ-04-Post-Quantum-Cryptography-in-the-IoT-EcosystemUpdated

GSMA official guidance (v1.0, 2024-11-25) on PQC for IoT, including eSIM/Remote SIM Provisioning (RSP): names ML-KEM (FIPS 203), ML-DSA (FIPS 204), SLH-DSA (FIPS 205), LMS and XMSS as the target algorithms, and states 'RSP for IoT is vulnerable to quantum attacks due to the recommended use of TLS, DTLS and recommended cipher suites that include asymmetric cryptography (e.g. in form of ECDHE, ECDSA, etc.)... The GSMA eSIM Group is actively working on a PQC version of RSP.'

PDF · 647 KB · a long read

ReleasedBlockchain Standards
GSMA
Trust 62Needs review
BFO-Post-Quantum-Cryptography-Is-Coming-to-PDFUpdated

BFO (PDF software vendor) blog account of the first ML-DSA-signed and SLH-DSA-signed PDF exchanges with Adobe (May 2025), and an agreement at PDF Days 2025 to formally add these algorithms to the PDF specification. Provisional — the formal PDF Association/ISO 32000 specification text had not yet landed as of this fetch; cited here as evidence of real, already-happened vendor interoperability testing, not a ratified standard.

Web page · 29 KB · a quick skim

MiscIndustry & Research
BFO (Big Faceless Organization)
Trust 54Needs review
PCI-SSC-Key-Blocks-101-104-AES-TDES-key-managementUpdated

PCI Security Standards Council's own blog on key-block requirements for POS/PIN key management: 'the PCI SSC recommends that entities... migrate to AES as it is a stronger cryptographic algorithm' than Triple DES (TDES), and 'both AES and TDES keys are required to be managed in key blocks as stipulated by ANSI X9.' Classical-only — no PQC content.

Web page · 85 KB · a short read

MiscBlockchain Standards
PCI Security Standards Council
Trust 58Needs review
Apple-Pay-Guide-Process-Payment-ECDH-SHAUpdated

Apple's own developer documentation for processing Apple Pay payment tokens: 'Reading, verifying, and processing payment information requires an understanding of several areas of cryptography such as calculating an SHA-1 hash, reading and validating a PKCS #7 signature, and performing elliptic curve Diffie-Hellman key exchange.' Classical-only — no PQC content.

Web page · 14 KB · a quick skim

MiscBlockchain Standards
Apple Inc.
Trust 44Needs review
W3C-Secure-Payment-Confirmation

W3C Secure Payment Confirmation spec — strong customer authentication at online checkout, built on WebAuthn/FIDO2. Names ES256 (ECDSA) and RS256 (RSA) in its normative registration/authentication examples. Classical-only — no PQC content.

Web page · 612 KB · a long read

ReleasedInternational Frameworks
W3C
Trust 51Needs review
AWS-Security-Blog-ML-KEM-Post-Quantum-TLS-in-KMS-ACM-SecretsUpdated

AWS's own security blog announcing GA: 'AWS Key Management Service (AWS KMS), AWS Certificate Manager (ACM), and AWS Secrets Manager endpoints now support Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) for hybrid post-quantum key agreement... in all AWS Regions,' hybridized with X25519.

Web page · 1.1 MB · a long read

MiscProtocols
Amazon Web Services
Trust 53Needs review
Google-Cloud-Blog-Quantum-Safe-Digital-Signatures-in-Cloud-KUpdated

Google Cloud's own product blog announcing GA: 'we are announcing the general availability of our quantum-safe digital signatures (ML-DSA, SLH-DSA) and post-quantum key encapsulation (ML-KEM) in Google Cloud Key Management Service (Cloud KMS),' naming ML-DSA-44/65/87 and SLH-DSA-SHA2-128s parameter sets.

Web page · 282 KB · a long read

MiscIndustry & Research
Google Cloud
Trust 58Needs review
Securosys-Primus-HSM-CyberVault-PQC-readyUpdated

Securosys (Swiss HSM manufacturer) product announcement: 'The CyberVault Series implements the HSS-LMS and XMSS algorithms and has already received NIST certification for the recently released ML-KEM, ML-DSA, and SLH-DSA algorithms.' Vendor-stated certification claim, not independently verified against the CMVP database in this pass.

Web page · 244 KB · a long read

MiscIndustry & Research
Securosys SA
Trust 53Needs review
ACS-ACOSJ-P-PBOC-3.0-DC-EC-CardUpdated

ACS ACOSJ-P Java Card smart-card product spec sheet, listing "SM2/SM3/SM4" under Cryptographic Features alongside DES/3DES/RSA/SHA, directly next to "Compliant with PBOC 3.0 Debit/Credit" and "Compliant with PBOC 3.0 QPBOC" certification lines — cited as evidence that Chinas national SM2 signature algorithm is a real, deployed option in PBOC 3.0 payment cards, not a paper standard.

Web page · 93 KB · a short read

MiscIndustry & Research
Advanced Card Systems (ACS)
Trust 47Needs review
PCI-PIN-v3-1-ROC-Reporting-TemplateUpdated

Official PCI SSC reporting template restating PCI PIN v3.1 requirements verbatim. Requirement 1-3: "All hardware security modules (HSMs) shall be either: FIPS140-2 or FIPS 140-3 Level 3 or higher certified, or PCI approved." Cited because the PCI PIN standard PDF itself sits behind a click-through agreement gate (excluded per the no-gated-sources rule); this template is the same PCI SSC primary text, freely retrievable.

PDF · 3.0 MB · a reference document — dip in, don’t read it through

ReleasedCompliance & Certification1 revReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
PCI PIN Security Requirements v3.1
Trust 57Needs review
PCI-PTS-HSM-Modular-Security-Requirements-v4-0Updated

The PCI PTS HSM approval program standard. Its own scope statement limits it to payment functions (PIN processing, 3-D Secure, card production, key generation/injection) and states it "does not aim to develop a standard for general-purpose HSMs".

PDF · 819 KB · a long read

ReleasedCompliance & CertificationReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
PCI PTS Hardware Security Module (HSM) Modular Security Requirements v4.0
Trust 57Needs review
PCI-Card-Production-Logical-Security-v3-0-1Updated

Section 7.14(c): "HSMs used for key management or otherwise used for the protection of sensitive data must be approved by PCI or certified to FIPS 140-2 or 140-3 Level 3 or higher certification for physical security." Retrieved from a third-party host because pcisecuritystandards.org gates the document; cover page verified genuine PCI SSC.

PDF · 1.9 MB · a reference document — dip in, don’t read it through

ReleasedCompliance & Certification
PCI Card Production and Provisioning
Trust 57Needs review
PCI-3DS-Core-v1-0-ROC-Reporting-TemplateUpdated

Requirement P2-6.1.2 (ACS and DS roles only): key management performed using an HSM that is either "FIPS 140-2 Level 3 (overall) or higher certified, or PCI PTS HSM approved". Note this document references FIPS 140-2 only — it has not been updated to 140-3, unlike PCI PIN v3.1.

PDF · 1.5 MB · a long read

ReleasedCompliance & Certification
PCI 3DS Core Security Standard v1.0
Trust 57Needs review
PCI-P2PE-Security-Requirements-v3-1

Requirement 1A-1.1 requires account-data encryption on a PCI PTS POI device approved with SRED. Requirement 4A-1.1 sets the HSM bar at "FIPS 140-2 or 140-3 Level 3 (overall) or higher certified". Its applicability matrix writes "Level 3 or 4" as prose for "or higher" — not a Level 4 mandate. Superseded by P2PE v3.2 (June 2025); v3.2 is not publicly downloadable, so v3.1 is cited as the last public text.

PDF · 2.0 MB · a reference document — dip in, don’t read it through

HistoricalCompliance & CertificationReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
PCI Point-to-Point Encryption Security Requirements and Testing Procedures v3.1
Trust 57Needs review
SWIFT-Qualified-Certificates-Certificate-Policy

Section 6.2.11 Cryptographic Module Rating: "The SWIFTNet PKI CA uses an HSM that is compliant with FIPS 140-1 or FIPS 140-2 Level 3. Subscribers use HSMs that comply with minimally FIPS 140-1 or 140-2 level 2." The subscriber floor (Level 2) is lower than the Level 3 asserted in the CSCF; no SWIFT document reconciles the two.

PDF · 232 KB · a short read

ReleasedCompliance & Certification
SWIFT Qualified Certificates
Trust 54Needs review
CNSSP-11-IA-Product-Acquisition-PolicyUpdated

Section IV para 5: "All COTS IA and IA-enabled IT products acquired for use to protect information on NSS shall comply with the requirements of the NIAP program in accordance with NSA-approved processes and, where applicable, the requirements of the Federal Information Processing Standard (FIPS) Cryptographic validation program(s)." Scope is National Security Systems only.

PDF · 451 KB · a long read

ReleasedCompliance & Certification
CNSS Policy No. 11
Trust 56Needs review
DoD-Cloud-Service-Provider-SRG-V1R7Updated

Section 5.2.4.3: "Cryptographic hardware security modules used in cloud-based KMS must have received FIPS 140-2 or FIPS 140-3 Level 3 accreditation" and "Cloud-based KMS components must have been evaluated against and determined to comply with applicable National Information Assurance Partnership (NIAP) Protection Profiles." This — not FedRAMP — is the real US federal Level 3 mandate for cloud KMS/HSM.

PDF · 2.7 MB · a reference document — dip in, don’t read it through

ReleasedCompliance & Certification
DoD Cloud Service Provider (CSP) Security Requirements Guide V1R7
Trust 54Needs review
UnionPay-UPCA-GZ-12-01-Terminal-Security-Certification-Rules-v4-2Updated

UnionPay’s own terminal security certification scheme, effective 2025-01-07. Read in full: contains ZERO occurrences of PCI, PTS, POI, FIPS, EAL, ISO 15408 or Common Criteria. Testing basis is UnionPay’s own 《中国银联支付受理终端安全规范》; the only compulsory external certification named is China 3C.

PDF · 253 KB · a short read

ReleasedCompliance & Certification
China UnionPay Payment Terminal Device Security Certification Implementation Rules (UPCA-GZ-12-01 V4.2)
Trust 52Needs review
CIR-EU-2025-1943-Qualified-Certificates-Reference-StandardsUpdated

Annex I point 1 (adapting ETSI EN 319 411-2 clause 6.5.2, GEN-6.5.2-02): TSP key generation "shall be carried out within a secure cryptographic device which is a trustworthy system certified in accordance with: Common Criteria ... EAL 4 or higher; or the European Common Criteria-based cybersecurity certification scheme (EUCC) ... EAL 4 or higher; or until 31.12.2030, FIPS PUB 140-3 level 3." Three ALTERNATIVE routes, with the FIPS route sunsetting 2030-12-31.

Web page · 40 KB · a quick skim

ReleasedCompliance & Certification
Commission Implementing Regulation (EU) 2025/1943
Trust 57Needs review
CIR-EU-2025-1929-Qualified-Electronic-Time-StampsUpdated

Annex point 1(6) (adapting ETSI EN 319 421 clause 7.6.2, TIS-7.6.2-03): TSU key generation must occur in a secure cryptographic device certified to Common Criteria EAL 4+, or EUCC EAL 4+, or until 31.12.2030 FIPS PUB 140-3 level 3. eIDAS Article 42 itself imposes no cryptographic-module requirement; it enters solely via this implementing act.

Web page · 25 KB · a quick skim

ReleasedCompliance & Certification
Commission Implementing Regulation (EU) 2025/1929
Trust 57Needs review
CIR-EU-2024-2981-EU-Digital-Identity-Wallet-CertificationUpdated

Requires the wallet secure cryptographic device to be evaluated at EAL4 with AVA_VAN.5 under EUCC. Contains ZERO occurrences of FIPS — unlike the qualified-trust-service track, the wallet route has no FIPS alternative.

Web page · 135 KB · a short read

ReleasedCompliance & Certification
Commission Implementing Regulation (EU) 2024/2981
Trust 56Needs review
CIR-EU-2024-482-EUCC-Cybersecurity-Certification-SchemeUpdated

Establishes EUCC, built on the SOG-IS MRA. Article 49 ends the effects of national CC schemes covered by EUCC 12 months after entry into force; Article 50 applies it from 27 February 2025. Annex II lists EN 419241-2:2019 and EN 419221-5:2018 as protection profiles certified at AVA_VAN level 4 or 5 for remote qualified signature creation devices.

Web page · 125 KB · a short read

ReleasedCompliance & Certification
Commission Implementing Regulation (EU) 2024/482
Trust 56Needs review
NIST-CMVP-140-2-to-140-3-Transition-TimelineUpdated

Authoritative CMVP transition schedule: "September 22, 2021 — CMVP no longer accepts FIPS 140-2 submissions for new validation certificates" and "September 21, 2026 — FIPS 140-2 active modules can be used until this date for new systems. After this date, FIPS 140-2 validation certificates will be moved to the Historical List." Note the page contradicts itself on the submission cut-off (table says 2021-09-22, prose says 2022-04-01); both are recorded here unreconciled.

Web page · 48 KB · a short read

MiscCompliance & CertificationReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
NIST CMVP
Trust 59Needs review
China-Cryptography-Law-2019-NPC

Article 25 makes commercial cryptography certification VOLUNTARY by default ("鼓励商用密码从业单位自愿接受商用密码检测认证"). Article 26 makes it compulsory for products listed in the Network Critical Equipment and Network Security Special Products Catalogue, and for commercial cryptography services using such products. Verified identically on OSCCA and NPC.

Web page · 15 KB · a quick skim

ReleasedCompliance & Certification
Cryptography Law of the People’s Republic of China (中华人民共和国密码法)
Trust 55Needs review
CABF-TLS-BR-v2-2-9Updated

SS6.2.7: "The CA SHALL protect its Private Key in a system or device that has been validated as meeting at least FIPS 140-2 level 3, FIPS 140-3 level 3, or an appropriate Common Criteria Protection Profile or Security Target, EAL 4 (or higher)." Binds the CA key only, not subscriber TLS server keys.

PDF · 2.2 MB · a reference document — dip in, don’t read it through

ReleasedCompliance & CertificationProtocols
CA/Browser Forum
Trust 59Needs review
CABF-SMIME-BR-v1-0-15Updated

SS6.2.7, same FIPS140-2/140-3 L3 or CC EAL4+ any-of requirement as the TLS BRs, applied to S/MIME-issuing CA keys.

PDF · 314 KB · a short read

ReleasedCompliance & Certification
CA/Browser Forum
Trust 59Needs review
CABF-Code-Signing-BR-v3-11Updated

SS6.2.7.3: Signing Services shall protect Subscriber Private Keys in a Hardware Crypto Module conforming to at least FIPS 140-2 level 3 or Common Criteria EAL 4+ — the one BR that also reaches the SUBSCRIBER key, not just the CA.

PDF · 360 KB · a short read

ReleasedCompliance & Certification
CA/Browser Forum
Trust 59Needs review
ICANN-Root-Zone-KSK-DPS-8th-EditionUpdated

SS5.2.1: "HSMs shall meet either FIPS 140-2 or FIPS 140-3, at level 3 or higher" for RZ KSK generation and storage — the DNS root zone KSK operator only, not general DNSSEC.

Web page · 260 KB · a long read

ReleasedCompliance & Certification
DNSSEC Practice Statement for the Root Zone KSK Operator, 8th Edition
Trust 58Needs review
NIST-SP-800-63B-4Updated

S3.2.12 (2.3.2 in some numbering): FIPS 140 module validation is required only of GOVERNMENT verifiers/authenticators, at Level 1 or higher for AAL3 — a downgrade from SP 800-63B-3 which required Level 2 overall / Level 3 physical.

PDF · 994 KB · a long read

ReleasedCompliance & Certification
NIST SP 800-63B-4
Trust 57Needs review
Chrome-Root-Program-Policy-v1-8

Chrome's root-store policy incorporates the CA/Browser Forum Baseline Requirements by reference rather than restating an independent HSM-certification requirement.

Web page · 65 KB · a short read

ReleasedCompliance & Certification
Chrome Root Program Policy, Version 1.8
Trust 56Needs review
C-ITS-Certificate-Policy-Release-3.0Updated

SS6.1.5.2: "The cryptographic module for the End-Entities shall be certified against one of the CPA approved protection profiles (PPs), with at least an assurance level EAL4 augmented with AVA_VAN.4." Governs European V2X (vehicle-to-everything) certificate issuance.

PDF · 1.8 MB · a reference document — dip in, don’t read it through

ReleasedCompliance & Certification
Certificate Policy for Deployment and Operation of European C-ITS, Release 3.0
Trust 58Needs review
BSI-CC-PP-0114-V2X-HSMUpdated

The Car 2 Car Communication Consortium-sponsored Common Criteria Protection Profile named by the C-ITS Certificate Policy as an approved route for V2X HSM certification.

PDF · 1.1 MB · a long read

ReleasedCompliance & Certification
BSI-CC-PP-0114-2021
Trust 59Needs review
SCMS-Manager-EE-Requirements-v1-00

US V2X Security Credential Management System requirements: back-end/TMC systems require a FIPS 140-2 Level 3 validated HSM; end-entity (in-vehicle) devices explicitly do NOT require a FIPS validation certificate.

PDF · 1.0 MB · a long read

ReleasedCompliance & CertificationProtocols
SCMS Manager
Trust 54Needs review
UNECE-R156Updated

Binding UN vehicle type-approval regulation for software-update security. Requires software authenticity/integrity protection but names no cryptographic-module certification scheme.

PDF · 623 KB · a long read

ReleasedCompliance & Certification
UN Regulation No. 156
Trust 56Needs review
EU-2016-799-Smart-TachographUpdated

Annex 1C Appendix 10, SEC_001: "The following components of the smart tachograph system shall be security certified according to the Common Criteria scheme: vehicle unit, tachograph card, motion sensor, external GNSS facility." Scoped to digital-tachograph components only, not general in-vehicle key storage.

PDF · 18.9 MB · a reference document — dip in, don’t read it through

ReleasedCompliance & Certification
Commission Implementing Regulation (EU) 2016/799
Trust 57Needs review
EU-2023-203-Part-ISUpdated

EASA information-security management regulation for aviation. Contains no cryptographic requirement of any kind, and names no certification scheme.

PDF · 748 KB · a long read

ReleasedCompliance & Certification
Commission Implementing Regulation (EU) 2023/203
Trust 55Needs review
UNISIG-SUBSET-114Updated

ERTMS/ETCS off-line key-management functional interface specification. Names no cryptographic-module certification scheme for key-management-centre HSMs.

PDF · 1.2 MB · a long read

ReleasedCompliance & Certification
UNISIG SUBSET-114 v1.1.0
Trust 57Needs review
NIST-SP-800-213Updated

Notes CMVP/FIPS 140 as something organizations "should be aware of" when selecting cryptographic modules for IoT devices — an advisory footnote, not a requirement.

PDF · 2.4 MB · a reference document — dip in, don’t read it through

ReleasedCompliance & Certification
NIST SP 800-213
Trust 57Needs review
NIST-IR-8259AUpdated

Baseline cybersecurity capabilities for IoT devices. Names no cryptographic-module certification requirement.

PDF · 978 KB · a long read

ReleasedCompliance & Certification
NISTIR 8259A
Trust 58Needs review
GSMA-SGP24-v2-4-4Updated

SS4.2: "The IC/hardware platform on which the eUICC is based shall be certified to either PP-0084 or PP-0035." Governs eSIM/eUICC hardware Common Criteria certification.

PDF · 447 KB · a long read

ReleasedCompliance & Certification
GSMA SGP.24
Trust 56Needs review
BSI-CC-PP-0100-V2-2025-eUICCUpdated

The eUICC-functional-level Common Criteria Protection Profile (EAL4 augmented ALC_DVS.2 + AVA_VAN.5) referenced by GSMA SGP.24/25 for eSIM certification.

PDF · 3.4 MB · a reference document — dip in, don’t read it through

ReleasedCompliance & Certification
BSI-CC-PP-0100-V2-2025
Trust 59Needs review
ENISA-eUICC-EUCCUpdated

ENISA public-consultation specification extending the EUCC Common Criteria scheme to cover eUICC certification, aligning with the existing BSI Protection Profiles.

PDF · 1.5 MB · a long read

DraftCompliance & Certification
ENISA
Trust 57Needs review
DORA-RTS-2024-1774Updated

DORA implementing technical standard on ICT risk management. Sets encryption and key-management policy requirements but names no cryptographic-module certification scheme.

PDF · 1.1 MB · a long read

ReleasedCompliance & Certification
Commission Delegated Regulation (EU) 2024/1774
Trust 56Needs review
MovieLabs-ECP-v1-4Updated

Studio-consortium content-protection specification. Its certification clause requires third-party/trusted-implementer review but names no external certification scheme (FIPS/CC/PCI).

PDF · 303 KB · a short read

ReleasedCompliance & Certification
MovieLabs Specification for Enhanced Content Protection v1.4
Trust 57Needs review
SFC-VATP-Guidelines

SS10.8(a): "Where practicable, seeds and private keys should be generated offline and kept in a secure environment, such as a HSM, with appropriate certification." Hong Kong VATP custody requirement — names no specific scheme, "appropriate certification" only.

PDF · 666 KB · a long read

ReleasedCompliance & Certification
Guidelines for Virtual Asset Trading Platform Operators (Hong Kong SFC)
Trust 56Needs review
VARA-Custody-RulebookUpdated

Dubai virtual-asset custody rulebook. Checked directly: zero occurrences of FIPS/140/Common Criteria — the widely-repeated claim that VARA requires FIPS 140-2 Level 3 HSMs traces to vendor blogs, not this regulation.

PDF · 367 KB · a short read

ReleasedCompliance & Certification
VARA Custody Services Rulebook (Dubai), Version 2
Trust 56Needs review
VARA-Technology-Information-RulebookUpdated

Dubai virtual-asset technology rulebook. Checked directly: zero occurrences of FIPS/140/Common Criteria.

PDF · 379 KB · a short read

ReleasedCompliance & Certification
VARA Technology and Information Rulebook (Dubai), Version 2
Trust 56Needs review
NERC-CIP-005-7Updated

Requires encrypted remote-access sessions (R2.2) but names no algorithm, certification level, or validation scheme.

PDF · 326 KB · a short read

ReleasedCompliance & Certification
NERC CIP-005-7
Trust 53Needs review
NERC-CIP-007-6Updated

System security management requirements for BES Cyber Systems; no cryptographic-module certification named.

PDF · 638 KB · a long read

ReleasedCompliance & Certification
NERC CIP-007-6
Trust 53Needs review
NERC-CIP-011-3Updated

BES Cyber System information-protection requirements; no cryptographic-module certification named.

PDF · 268 KB · a short read

ReleasedCompliance & Certification
NERC CIP-011-3
Trust 53Needs review
IETF-RFC-6484Updated

The RPKI CP requires each CA's Certification Practice Statement to describe its cryptographic-module standards, but sets no floor itself — the floor (e.g. ARIN's FIPS 140-2 Level 4) is set per-CA in the CPS, not by this policy.

Web page · 78 KB · a short read

ReleasedCompliance & Certification
RFC 6484
Trust 57Needs review
PCI-SSC-Blog-Publishes-PTS-HSM-v5-0Updated

PCI SSC's own announcement (18 May 2026): v5.0 adds "support for post-quantum cryptography considerations" and new definitions covering PQC — terminology/guidance, not a mandated PQC algorithm or parameter set. Also adds EC-SDSA (a classical ECC scheme, unrelated to PQC) as a separate, unrelated change.

Web page · 82 KB · a short read

MiscCompliance & CertificationReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
PCI SSC Publishes PCI PTS HSM v5.0 (PCI Perspectives blog)
Trust 57Needs review
PCI-SSC-Bulletin-PTS-HSM-v4-ExtensionUpdated

PTS HSM v4 remains usable for NEW device-security approvals until 2027-06-30 despite v5.0's publication; v4 device-approval expiry extended April 2032 -> April 2033; v3 device-approval expiry extended to April 2028. No v5.0-specific PQC deadline exists.

PDF · 110 KB · a short read

MiscCompliance & CertificationReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
PCI SSC Bulletin: Extension of PCI PTS HSM v4 Security Requirements and Device Approval Expiration Dates
Trust 56Needs review
draft-bokovoy-kitten-pkinit-pqc-01Updated

Web page · 149 KB · a short read

DraftProtocols
IETF Individual Submission
Trust 60Needs review
RFC-6488Updated

Web page · 77 KB · a short read

ReleasedPKI Certificate Management
IETF SIDR Working Group
Trust 58Needs review
Implementation-of-a-Hybrid-QKD-PQC-Network-and-ApplicationsUpdated

Web page · 299 KB · a long read

Research PaperIndustry & Research
Unknown
Trust 30Needs review
The-supersingular-isogeny-problem-in-time-and-memory-p-1-3-oUpdated

Web page · 15 KB · a quick skim

Research PaperIndustry & Research
Unknown
Trust 28Needs review
Solving-the-supersingular-isogeny-problem-in-time-p-2-5-o-1Updated

Web page · 15 KB · a quick skim

Research PaperIndustry & Research
Unknown
Trust 28Needs review
OFFICIAL-COMMENT-SQIsign-livesUpdated

Web page · 895 KB · a long read

MiscIndustry & Research
Unknown
Trust 30Needs review
Discovering-cryptographic-weaknesses-with-ClaudeUpdated

Web page · 189 KB · a long read

MiscIndustry & Research
Unknown
Trust 38Needs review
HAWK-n-Key-Recovery-Reduces-to-SVP-in-Dimension-n-2-1Updated

Web page · 1.5 MB · a long read

MiscIndustry & Research
Unknown
Trust 37Needs review
A-Polynomial-Time-Quantum-Algorithm-for-the-Dihedral-Coset-PUpdated

Web page · 16 KB · a quick skim

Research PaperIndustry & Research
Unknown
Trust 28Needs review
Quasipolynomial-Cryptanalysis-of-the-McEliece-Cryptosystem-oUpdated

Web page · 16 KB · a quick skim

Research PaperIndustry & Research
Unknown
Trust 30Needs review
PKI-Consortium-Launches-the-CBOM-Profiles-Working-GroupUpdated

Web page · 74 KB · a short read

MiscMigration Guidance
PKI Consortium
Trust 37Needs review
RFC-9908Updated

Web page · 115 KB · a short read

ReleasedProtocols
IETF
Trust 63Needs review
Post-Quantum-Protocols-for-Banking-ApplicationsUpdated

PDF · 524 KB · a long read

Research PaperIndustry & ResearchHigh
Luk Bettale; Marco De Oliveira; Emmanuelle Dottax (IDEMIA)
Trust 52Needs review
RFC-9954-Hybrid-Key-Exchange-in-TLS-1-3Updated

Web page · 110 KB · a short read

ReleasedProtocols
D. Stebila (University of Waterloo); S. Fluhrer (Cisco Systems); S. Gueron (U. Haifa & Meta)
Trust 65Needs review
RFC-2986-PKCS-10-Certification-Request-Syntax-Specification

This memo represents a republication of PKCS #10 v1.7 from RSA Laboratories' Public-Key Cryptography Standards (PKCS) series, and change control is retained within the PKCS process.

Web page · 69 KB · a short read

ReleasedMigration Guidance
IETF
Trust 42Needs review
RFC-3526-More-Modular-Exponential-MODP-Diffie-Hellman-groupsUpdated

This document defines new Modular Exponential (MODP) Groups for the Internet Key Exchange (IKE) protocol.

Web page · 24 KB · a quick skim

ReleasedMigration Guidance
IETF
Trust 39Needs review
RFC-4211-Internet-X-509-PKI-Certificate-Request-Message-Form

This document describes the Certificate Request Message Format (CRMF) syntax and semantics.

Web page · 102 KB · a short read

DraftPKI Certificate Management
IETF
Trust 39Needs review
RFC-5816-ESSCertIDv2-Update-for-RFC-3161Updated

This document updates RFC 3161 . It allows the use of ESSCertIDv2, as defined in RFC 5035 , to specify the hash of a signer certificate when the hash is calculated with a function other than the Secure Hash Algorithm (SHA-1).

Web page · 15 KB · a quick skim

ReleasedMigration Guidance
IETF
Trust 39Needs review
RFC-6066-Transport-Layer-Security-TLS-Extensions-Extension-DUpdated

This document provides specifications for existing TLS extensions.

Web page · 67 KB · a short read

ReleasedProtocols
IETF
Trust 39Needs review
RFC-7512-The-PKCS-11-URI-SchemeUpdated

This memo specifies a PKCS #11 Uniform Resource Identifier (URI) Scheme for identifying PKCS #11 objects stored in PKCS #11 tokens and also for identifying PKCS #11 tokens, slots, or libraries.

Web page · 59 KB · a short read

ReleasedMigration Guidance
IETF
Trust 39Needs review
RFC-9360-CBOR-Object-Signing-and-Encryption-COSE-Header-ParaUpdated

Web page · 84 KB · a short read

ReleasedPKI Certificate Management
IETF
Trust 41Needs review
NIST-SP-800-38B-Recommendation-for-Block-Cipher-Modes-of-OpeUpdated

PDF · 253 KB · a short read

ReleasedMigration Guidance
NIST
Trust 35Needs review
NIST-SP-800-38F-Recommendation-for-Block-Cipher-Modes-of-OpeUpdated

PDF · 289 KB · a short read

ReleasedMigration Guidance
NIST
Trust 36Needs review
NIST-SP-800-38A-Recommendation-for-Block-Cipher-Modes-of-OpeUpdated

PDF · 378 KB · a short read

ReleasedMigration Guidance
NIST
Trust 35Needs review
NIST-SP-800-207A-A-Zero-Trust-Architecture-Model-for-AccessUpdated

PDF · 1.4 MB · a long read

ReleasedMigration Guidance
NIST
Trust 35Needs review
NIST-SP-800-89-Recommendation-for-Obtaining-Assurances-for-DUpdated

Entities participating in the generation or verification of digital signatures depend on the authenticity of the process.

PDF · 226 KB · a short read

ReleasedMigration Guidance
NIST
Trust 36Needs review
NIST-SP-800-60-Vol-1-Rev-1-Guide-for-Mapping-Types-of-InformUpdated

PDF · 338 KB · a short read

ReleasedMigration Guidance
NIST
Trust 35Needs review
NIST-SP-800-128-Guide-for-Security-Focused-Configuration-ManUpdated

PDF · 1.5 MB · a reference document — dip in, don’t read it through

ReleasedMigration Guidance
NIST
Trust 35Needs review
FIPS-200-Minimum-Security-Requirements-for-Federal-InformatiUpdated

PDF · 219 KB · a short read

ReleasedMigration Guidance
NIST
Trust 34Needs review
NIST-SP-800-161r1-upd1-Cybersecurity-Supply-Chain-Risk-ManagUpdated

PDF · 3.5 MB · a reference document — dip in, don’t read it through

ReleasedMigration Guidance
NIST
Trust 34Needs review
ISO-IEC-11889-2015-Information-technology-Trusted-Platform-M

Web page · 87 KB · a short read

ReleasedMigration Guidance
ISO/IEC
Trust 21Needs review
Purchase required
ISO-IEC-27005-2022-Guidance-on-managing-information-securityUpdated

Web page · 84 KB · a short read

ExpiredMigration Guidance
ISO/IEC
Trust 32Needs review
Purchase required
ISO-IEC-15408-1-2022-Evaluation-criteria-for-IT-security-ComUpdated

Web page · 86 KB · a short read

ExpiredMigration Guidance
ISO/IEC
Trust 34Needs review
Purchase required
ISO-IEC-19794-2-2011-Biometric-data-interchange-formats-Part

Web page · 104 KB · a short read

ReleasedMigration Guidance
ISO/IEC
Trust 20Needs review
Purchase required
ISO-IEC-20085-1-2019-Test-tool-requirements-and-test-tool-ca

Web page · 88 KB · a short read

ReleasedMigration Guidance
ISO/IEC
Trust 19Needs review
Purchase required
ISO-IEC-7816-4-2020-Identification-cards-Integrated-circuit

Web page · 86 KB · a short read

ReleasedMigration Guidance
ISO/IEC
Trust 33Needs review
Purchase required
RFC-9700-Best-Current-Practice-for-OAuth-2-0-SecurityUpdated

Web page · 262 KB · a long read

ReleasedMigration Guidance
IETF
Trust 39Needs review
DO-326A-Airworthiness-Security-Process-Specification

ReleasedMigration Guidance
Unknown
Trust 21Needs review
Purchase required
Integrated-Methodology-for-Information-Security-Risk-ManagemUpdated

Peer-reviewed IJACSA paper (2023) applying ISO/IEC 27005:2018's risk assessment methodology (asset/threat/vulnerability identification, likelihood x consequence scoring, treatment selection) combined with NIST SP 800-30 guidance to an insurance-sector case study. Cited as the open, reachable source for ISO 27005's actual methodology since the standard itself is sold and not held.

Web page · 109 KB · a short read

Research PaperMigration Guidance
Arief Prabawa Putra, Benfano Soewito (Bina Nusantara University)
Trust 36Needs review
Agile-Post-Quantum-Secure-Cryptography-in-AvionicsUpdated

IACR ePrint 2024/667. Integrates a post-quantum-secure HPKE variant (ML-KEM/ML-DSA alongside classical ciphers) into an ARINC 653 avionics software partition. Covers DO-178C's certification process in depth (module/application/system acceptance, Reusable Software Components for certification-credit reuse) and how partitioning contains the recertification blast radius of a crypto change.

Web page · 18 KB · a quick skim

Research PaperMigration Guidance
Karolin Varner, Wanja Zaeske, Sven Friedrich, Aaron Kaiser, Alice Bowman (DLR, Max Planck Institute for Security and Privacy, Rosenpass e.V.)
Trust 45Needs review
DO-178C-Costs-vs-Benefits-AnalysisUpdated

AFuzion (a DO-178C certification consultancy) technical whitepaper on DO-178C cost/schedule by Design Assurance Level. Discusses per-DAL cost and schedule delta qualitatively (a referenced chart, not machine-readable); does not itself state a specific re-certification dollar figure or year range.

Web page · 211 KB · a long read

MiscMigration Guidance
AFuzion Inc.
Trust 28Needs review
ARINC-429-Cyber-vulnerabilities-and-Voltage-Data-in-a-HardwaUpdated

arXiv:2408.16714. Builds a hardware-in-the-loop ARINC 429 simulator and demonstrates a real denial-of-service attack via a compromised bus. States ARINC 429's actual technical characteristics -- 32-bit words, 12.5/100 Kbits/s slow/fast rates -- and discusses why adding message encryption or authentication to the protocol is impractical.

PDF · 3.1 MB · a reference document — dip in, don’t read it through

Research PaperMigration Guidance
Connor Trask, Steve Movit, Justace Clutter, Rosene Clark, Mark Herrera, Kelly Tran
Trust 29Needs review
Vehicle-Security-Post-Quantum-Security-to-the-CAN-NetworkUpdated

Industry trade article covering a University of Tennessee PUF-based post-quantum CAN-FD security framework. States that standard CAN's payload size is too small for PQC and that CAN-FD's increased payload capacity is what makes PQC on the bus feasible.

Web page · 866 KB · a long read

MiscMigration Guidance
Semiconductor Engineering
Trust 31Needs review
Critical-Role-of-MACsec-in-Automotive-SecurityUpdated

TI technical whitepaper (SNLA462) on MACsec (IEEE 802.1AE) securing 100BASE-T1 Automotive Ethernet backbone links, contrasted with software-layer TLS/SSL. Grounds why Automotive Ethernet backbones (not CAN/LIN) are the automotive PQC migration target.

PDF · 390 KB · a short read

MiscMigration Guidance
Texas Instruments
Trust 30Needs review
AI-models-collapse-when-trained-on-recursively-generated-datUpdated

Nature 631, 755-759 (2024), CC-BY 4.0. Demonstrates that generative models trained recursively on their own synthetic output degenerate ("model collapse") -- the tails of the real data distribution disappear.

Web page · 367 KB · a long read

Research PaperMigration Guidance
Ilia Shumailov, Zakhar Shumaylov, Yiren Zhao, Nicolas Papernot, Ross Anderson, Yarin Gal
Trust 27Needs review
Secure-Use-of-the-Agent-Payments-Protocol-AP2Updated

CSA security analysis of Google's Agent Payments Protocol (AP2) for agent-to-agent commerce -- cryptographically signed Mandates (ECDSA), identified quantum-threat weaknesses, and a hybrid-scheme roadmap.

Web page · 1.2 MB · a long read

MiscMigration Guidance
Cloud Security Alliance
Trust 32Needs review
A-Post-Quantum-Future-for-Let-s-EncryptUpdated

Official Let's Encrypt announcement (2026-06-03) of its post-quantum roadmap: Merkle Tree Certificates, targeting late-2026 staging and 2027 production, chosen because ML-DSA-44 signatures alone would push TLS handshakes well past 10KB.

Web page · 39 KB · a quick skim

MiscMigration Guidance
Let's Encrypt (Internet Security Research Group)
Trust 40Needs review
Docker-Content-Trust-Retirement-and-Migration-GuidanceUpdated

Official Docker blog (2026-06-16): Docker Content Trust and the Notary v1 service are being fully retired, first announced July 2025. Confirms DCT/Notary v1 has no PQC roadmap and points to Sigstore/Notation as modern replacements.

Web page · 252 KB · a long read

MiscMigration Guidance
Docker, Inc.
Trust 29Needs review
Analysis-of-the-Codecov-Supply-Chain-CompromiseUpdated

Technical analysis of the April 2021 Codecov Bash Uploader supply chain compromise -- an unsigned CI script was modified to exfiltrate CI environment secrets (AWS IAM keys, deploy keys, tokens) from over 23,000 affected customers.

Web page · 431 KB · a long read

MiscMigration Guidance
Rapid7
Trust 28Needs review
Template-and-CPA-Side-Channel-Attacks-on-the-Kyber-ML-KEM-PaUpdated

IACR ePrint 2025/1577. Profiled (template) and unprofiled (CPA) side-channel attacks on ML-KEM's NTT-domain pair-pointwise multiplication during decapsulation, yielding full key recovery.

Web page · 16 KB · a quick skim

Research PaperMigration Guidance
Unknown
Trust 44Needs review
Migration-to-Post-Quantum-Cryptography-From-ECDSA-to-ML-DSAUpdated

IACR ePrint 2025/2025. Covers migration of ECDSA-dependent security features -- secure boot, remote attestation -- to ML-DSA, motivated by Shor's algorithm breaking discrete-log/ECDSA.

Web page · 15 KB · a quick skim

Research PaperMigration Guidance
Unknown
Trust 44Needs review
Quantum-cryptography-Public-key-distribution-and-coin-tossinUpdated

Original 1984 BB84 protocol paper (arXiv reprint of the 1984 IEEE conference paper). Defines the rectilinear and diagonal conjugate photon-polarization bases and the sifting/eavesdropper-detection procedure that underlies quantum key distribution.

PDF · 1.2 MB · a long read

Research PaperMigration Guidance
Charles H. Bennett, Gilles Brassard
Trust 28Needs review
Micius-quantum-experiments-in-spaceUpdated

Comprehensive review of the Micius satellite's quantum experiments: satellite-based entanglement distribution over 1200km (2017) and entanglement-based QKD over 1120km (2020), the latter generating no key material aboard the satellite itself.

Web page · 44 KB · a short read

Research PaperMigration Guidance
Unknown
Trust 37Needs review
Simple-Proof-of-Security-of-the-BB84-Quantum-Key-DistributioUpdated

Physical Review Letters 85, 441 (2000). Proves BB84's security via an entanglement-purification-based protocol, extending the tolerable bit/phase error rate to just under 11% (the QBER eavesdropper-detection threshold).

PDF · 268 KB · a short read

Research PaperMigration Guidance
Peter W. Shor, John Preskill
Trust 28Needs review
Polynomial-Time-Algorithms-for-Prime-Factorization-and-DiscrUpdated

SIAM J. Comput. 26, 1484-1509 (1997); arXiv preprint quant-ph/9508027. Shor's original paper describing polynomial-time quantum algorithms for integer factoring and discrete logarithms -- the basis for the quantum break of RSA and elliptic-curve cryptography.

Web page · 42 KB · a short read

Research PaperMigration Guidance
Peter W. Shor
Trust 36Needs review
A-fast-quantum-mechanical-algorithm-for-database-searchUpdated

STOC '96 / arXiv quant-ph/9605043. Grover's original quadratic-speedup quantum search algorithm -- the basis for halving symmetric-key effective security levels under a quantum attacker.

PDF · 67 KB · a short read

Research PaperMigration Guidance
Lov K. Grover
Trust 28Needs review
Cybersecurity-in-Medical-Devices-Quality-System-Consideratio

FDA final guidance (Federal Register, 2023-09-27), effective under FD&C Act section 524B: mandates premarket cybersecurity submissions -- a cybersecurity plan, SBOM, and vulnerability management -- for internet-connected 'cyber devices.' Supersedes the 2014 guidance.

Web page · 84 KB · a short read

ReleasedMigration Guidance
U.S. Food and Drug Administration
Trust 28Needs review
TCG-Hardware-Requirements-for-a-Device-Identifier-CompositioUpdated

TCG DICE specification (Family 2.0, Rev 78, 2018). Defines minimal hardware requirements for deriving a Compound Device Identifier from a Unique Device Secret and first mutable code -- a lightweight hardware root of trust suitable for constrained MCUs.

PDF · 938 KB · a long read

ReleasedMigration Guidance
Trusted Computing Group
Trust 29Needs review
Debian-Security-Advisory-DSA-1571-1-openssl-predictable-randUpdated

Official 2008 Debian Security Advisory (DSA-1571-1) for CVE-2008-0166: an incorrect Debian-specific OpenSSL patch left only the process ID as entropy input, limiting keys to ~32,767 possible outcomes.

Web page · 26 KB · a quick skim

MiscMigration Guidance
Debian Security Team
Trust 29Needs review
Cybersecurity-in-an-Era-with-Quantum-Computers-Will-We-Be-ReUpdated

IEEE Security & Privacy 16(5), 2018; IACR ePrint 2015/1075. Introduces the quantum-risk inequality (shelf-life + migration time > time-to-CRQC means a serious problem today) used across the corpus as "Mosca's Theorem" for migration prioritization.

PDF · 65 KB · a short read

Research PaperMigration Guidance
Michele Mosca
Trust 30Needs review
Mapping-Quantum-Threats-An-Engineering-Inventory-of-CryptogrUpdated

arXiv:2509.24623. Engineering inventory of cryptographic dependencies across TLS/QUIC/PKI, distinguishing HNDL (confidentiality break via harvested ciphertext) from certificate/signature forgery (integrity break once Shor's algorithm can forge RSA/ECDSA signatures).

PDF · 306 KB · a short read

Research PaperMigration Guidance
Unknown
Trust 30Needs review
Integrating-Remote-Attestation-with-Transport-Layer-SecurityUpdated

arXiv:1801.05863. Describes Intel SGX's remote attestation architecture -- the enclave's Quoting Enclave signs an attestation report using the platform's Attestation Key, producing a verifiable quote.

Web page · 41 KB · a short read

Research PaperMigration Guidance
Unknown
Trust 37Needs review
Intel-SGX-ExplainedUpdated

Costan & Devadas (MIT). Definitive academic explainer of Intel SGX architecture: threat model (all privileged software including kernel/hypervisor treated as potentially malicious), Memory Encryption Engine for DRAM confidentiality, and EGETKEY-derived Seal Keys tied to enclave measurement (MRENCLAVE/MRSIGNER).

Web page · 14 KB · a quick skim

Research PaperMigration Guidance
Unknown
Trust 36Needs review
SoK-Hardware-supported-Trusted-Execution-EnvironmentsUpdated

Schneider et al. Systematization-of-knowledge survey of hardware-supported TEE architectures including Intel SGX/TDX, ARM TrustZone/CCA, AMD SEV, and RISC-V Keystone, comparing isolation, sealing, and attestation mechanisms.

Web page · 41 KB · a short read

Research PaperMigration Guidance
Unknown
Trust 36Needs review
The-Security-Design-of-the-AWS-Nitro-SystemUpdated

Official AWS whitepaper describing the Nitro System's hardware-isolation architecture (Nitro Cards, Nitro Security Chip, Nitro Hypervisor) underlying AWS Nitro Enclaves, including how it removes administrator/operator access to customer workload memory.

PDF · 602 KB · a long read

MiscMigration Guidance
Unknown
Trust 30Needs review
MTU-and-Deep-SSL-Inspection-Essential-Insights-for-2026Updated

Technical blog explaining why post-quantum/hybrid TLS key exchange (larger ML-KEM key shares, ClientHello split across packets) breaks MTU assumptions baked into deep SSL/TLS inspection appliances (WAF, NGFW), citing Meta's and Google's own documented Kyber768/ML-KEM rollout data.

Web page · 275 KB · a long read

MiscMigration Guidance
Unknown
Trust 37Needs review
Post-quantum-between-Cloudflare-and-origin-serversUpdated

Official Cloudflare docs describing post-quantum key agreement (X25519MLKEM768) and post-quantum signatures (ML-DSA) on the edge-to-origin TLS connection, distinct from the client-to-edge connection -- the architecture underlying origin shielding and per-leg PQC configuration at CDN scale.

Web page · 163 KB · a long read

MiscMigration Guidance
Unknown
Trust 39Needs review
TLS-Termination-Models-SSL-Passthrough-vs-SSL-Termination-vsUpdated

Technical explainer of the three standard load-balancer TLS handling patterns -- SSL Passthrough (no intermediate decryption), SSL Termination/Offloading, and SSL Bridging/Re-Encryption (proxy terminates then re-encrypts to backend, enabling inspection while preserving backend encryption).

Web page · 80 KB · a short read

MiscProtocols
Unknown
Trust 29Needs review
Signature-Correction-Attack-on-Dilithium-Signature-SchemeUpdated

Demonstrates that a single bit-flip fault (e.g. via Rowhammer, the same fault class as a radiation-induced Single Event Upset) in a lattice-based Dilithium/ML-DSA secret key vector corrupts subsequent signing operations and enables recovery of most of the secret key from the resulting faulty signatures.

Web page · 43 KB · a short read

Research PaperMigration Guidance
Unknown
Trust 38Needs review
RAD750Updated

Reference on the RAD750 radiation-hardened PowerPC processor widely used in spacecraft, confirming its 110-200 MHz clock rate, SEU/latch-up radiation hardening, and use of FPGA/ASIC coprocessors for cryptographic acceleration.

Web page · 137 KB · a short read

MiscMigration Guidance
Unknown
Trust 27Needs review
Potential-Data-Link-Candidates-for-Civilian-Unmanned-AircrafUpdated

Survey of aeronautical/UAS datalink technologies, covering legacy VHF ACARS alongside newer candidate links.

Web page · 44 KB · a short read

Research PaperMigration Guidance
Unknown
Trust 36Needs review
Advanced-Physical-Layer-Technologies-in-VHF-Data-Link-for-AeUpdated

Confirms VHF ACARS avionics data rate of 2400 bps and discusses physical-layer bandwidth constraints of legacy aeronautical VHF datalinks.

PDF · 955 KB · a long read

Research PaperMigration Guidance
Unknown
Trust 29Needs review
15-CFR-742-15-Encryption-itemsUpdated

Official eCFR text of the EAR's encryption export control section, defining ECCN 5E002 (encryption technology) and licensing requirements for cryptographic items and technology.

ReleasedMigration Guidance
Unknown
Trust 22Needs review
Toward-Space-Based-Public-Key-Systems-Enabling-Secure-SpaceUpdated

Academic paper on in-orbit PKI/trust services for space communications, with a baseline latency analysis computing LEO/GEO round-trip latencies at various altitudes and discussing key/certificate management under limited communication windows and orbital handoffs.

PDF · 3.9 MB · a reference document — dip in, don’t read it through

Research PaperMigration Guidance
Unknown
Trust 31Needs review
Starlink-Constellation-Deployment-Configuration-and-DynamicsUpdated

Empirical study of Starlink LEO constellation dynamics, finding satellites have an operational lifespan of 4-6 years against a nominal five-year design life.

PDF · 3.3 MB · a reference document — dip in, don’t read it through

Research PaperMigration Guidance
Unknown
Trust 27Needs review
System-Architecting-for-GEO-Communication-Satellite-ConsiderUpdated

Academic paper on GEO communication satellite system architecture, confirming the industry-standard 15-year design lifetime baseline for GEO satellites.

PDF · 1.6 MB · a reference document — dip in, don’t read it through

Research PaperMigration Guidance
Unknown
Trust 27Needs review
What-are-timing-attacks-and-how-will-they-impact-postquantumUpdated

Sectigo explainer on timing/side-channel attacks against post-quantum cryptographic implementations, identifying constant-time algorithms as one of the most important countermeasures.

Web page · 588 KB · a long read

MiscMigration Guidance
Unknown
Trust 32Needs review
CAR-2-CAR-Communication-Consortium-HSM-Protection-ProfileUpdated

Common Criteria Protection Profile for the V2X Hardware Security Module used in Cooperative Intelligent Transport Systems, covering online/offline private key import and HSM security requirements for vehicle-to-vehicle/infrastructure communication.

PDF · 1.4 MB · a long read

ReleasedMigration Guidance
Unknown
Trust 30Needs review
cosign-CHANGELOGUpdated

Primary-source release changelog for cosign, the Sigstore project's container-signing CLI. As of the cached snapshot, contains no ML-DSA/post-quantum entries -- confirms PQC support has not yet shipped.

MiscMigration Guidance
Unknown
Trust 22Needs review
Prometheus-Metrics-cert-manager-DocumentationUpdated

Official cert-manager documentation describing its built-in Prometheus metrics exporter for monitoring certificate issuance, renewal, and expiry in Kubernetes clusters.

Web page · 181 KB · a long read

MiscMigration Guidance
Unknown
Trust 28Needs review
x509-certificate-exporterUpdated

Official repository for x509-certificate-exporter, a Prometheus exporter purpose-built for monitoring X.509 certificate expiry across Kubernetes TLS secrets, ConfigMaps, and on-disk files.

Web page · 366 KB · a long read

MiscPKI Certificate Management
Unknown
Trust 29Needs review
The-Importance-and-Effectiveness-of-Cyber-Risk-QuantificatioUpdated

Official FAIR Institute overview of the FAIR (Factor Analysis of Information Risk) model -- the only internationally recognized quantitative model for measuring and expressing cyber/information risk in financial terms.

Web page · 104 KB · a short read

MiscMigration Guidance
Unknown
Trust 28Needs review
The-Open-FAIR-Body-of-Knowledge

Official Open Group standard page for Open FAIR (O-RT Risk Taxonomy Standard and O-RA Risk Analysis Standard), the formal standardization of the FAIR quantitative risk model.

Web page · 87 KB · a short read

ReleasedMigration Guidance
Unknown
Trust 28Needs review
Layered-Performance-Analysis-of-TLS-1-3-Handshakes-ClassicalUpdated

Layered latency-decomposition study of TLS 1.3 handshakes across classical, hybrid PQC, and pure PQC key-exchange configurations, measuring per-protocol-layer latency and connection throughput under realistic network conditions.

PDF · 619 KB · a long read

Research PaperProtocols
Unknown
Trust 40Needs review
SMART-App-LaunchUpdated

Official HL7 FHIR SMART App Launch specification, describing OAuth 2.0-based authorization patterns for FHIR API client applications, including token issuance and required client-authentication signature algorithms.

ReleasedMigration Guidance
Unknown
Trust 23Needs review
Deep-CNN-Face-Matchers-Inherently-Support-Revocable-BiometriUpdated

Proposes a framework where deep-CNN face matchers inherently support revocable biometric templates (via non-linear model transformations), contrasted against fingerprint/iris templates which are traditionally considered permanently irreplaceable once compromised.

PDF · 5.0 MB · a reference document — dip in, don’t read it through

Research PaperMigration Guidance
Unknown
Trust 29Needs review
OpenSSH-Post-Quantum-CryptographyUpdated

Official OpenSSH project FAQ on post-quantum cryptography status. Confirms hybrid post-quantum KEY EXCHANGE (mlkem768x25519-sha256, default since OpenSSH 10.0) is shipped, but as of this page OpenSSH does NOT yet support any post-quantum host-key or user-key SIGNATURE algorithm -- ML-DSA SSH keys do not exist yet ('OpenSSH will add support for post-quantum signature algorithms in the future').

Web page · 8 KB · a quick skim

MiscProtocols
Unknown
Trust 38Needs review
Understanding-standards-ETSIUpdated

Official ETSI page explaining its deliverable types -- confirms Technical Specification (TS) contains technical requirements for rapid implementation, while Technical Report (TR) contains explanatory/informative material.

Web page · 151 KB · a long read

MiscMigration Guidance
Unknown
Trust 28Needs review
Post-Quantum-Use-In-Protocols-pquip-IETF-Working-Group-ChartUpdated

Official IETF charter page for the PQUIP (Post-Quantum Use In Protocols) working group, which coordinates PQC transition guidance across other IETF working groups (LAMPS, TLS, IPSECME, COSE).

Web page · 39 KB · a quick skim

MiscMigration Guidance
Unknown
Trust 29Needs review
Introduction-to-the-IETFUpdated

Official IETF 'about' page. Confirms the IETF has no formal membership -- anyone can participate in an open, non-governmental standards process.

Web page · 86 KB · a short read

MiscMigration Guidance
Unknown
Trust 28Needs review
Evaluation-of-Time-Critical-Communications-for-IEC-61850-SubUpdated

Academic evaluation of IEC 61850 substation network time-critical communications, confirming GOOSE Type 1-A mission-critical messages require less than four milliseconds end-to-end delay.

Web page · 43 KB · a short read

Research PaperMigration Guidance
Unknown
Trust 37Needs review
IEC-61850-Meets-IEC-62351-Securing-GOOSE-Power-Grid-WeaknessUpdated

OT security technical explainer on IEC 62351-6 GOOSE message security, confirming HMAC-based (symmetric-key) message authentication rather than asymmetric digital signatures, driven by GOOSE's strict sub-4ms timing requirements.

Web page · 66 KB · a short read

MiscMigration Guidance
Unknown
Trust 30Needs review
Understanding-Programs-and-ProjectsUpdated

Official PMI article defining a program as "a group of related projects managed in a coordinated way to obtain benefits and control not available from managing them individually" -- the basis for classifying multi-year, multi-system PQC migrations as programs rather than single projects.

Web page · 455 KB · a long read

Research PaperMigration Guidance
Unknown
Trust 28Needs review
About-Updating-SafeNet-Network-HSMUpdated

Official Thales Luna HSM documentation describing the standard firmware-update practice: ship with the current FIPS-validated firmware installed while holding a candidate update as a ready-but-not-installed standby version, with rollback to the prior version, allowing safe migration without losing FIPS compliance mid-transition.

Web page · 27 KB · a quick skim

MiscMigration Guidance
Unknown
Trust 29Needs review
oqs-provider-OpenSSL-3-provider-containing-post-quantum-algoUpdated

Official Open Quantum Safe GitHub repository for oqsprovider, the OpenSSL 3 provider that adds post-quantum algorithms as a dynamically-loadable plug-in independent of OpenSSL's core logic, as an alternative to static library integration.

Web page · 432 KB · a long read

MiscMigration Guidance
Unknown
Trust 38Needs review
Crypto-getRandomValues-method-Web-APIs-MDNUpdated

MDN Web APIs reference for Crypto.getRandomValues(), confirming implementations use a PRNG seeded from a platform-specific entropy source (e.g. /dev/urandom) rather than a raw hardware RNG directly.

Web page · 156 KB · a long read

MiscMigration Guidance
Unknown
Trust 28Needs review
ALTER-DATABASE-ENCRYPTION-KEY-Transact-SQLUpdated

Official Microsoft Learn Transact-SQL reference for ALTER DATABASE ENCRYPTION KEY, confirming the REGENERATE WITH ALGORITHM syntax for online TDE key re-encryption.

Web page · 53 KB · a short read

MiscMigration Guidance
Unknown
Trust 28Needs review
sys-dm-database-encryption-keys-Transact-SQLUpdated

Official Microsoft Learn documentation for the sys.dm_database_encryption_keys dynamic management view, used to enumerate SQL Server TDE-encrypted databases.

Web page · 57 KB · a short read

MiscMigration Guidance
Unknown
Trust 28Needs review
Choosing-a-Cloud-Key-Management-ModelUpdated

Cloud Security Alliance article distinguishing key-responsibility models -- confirms Hold Your Own Key (HYOK): "The customer maintains control of keys in their own KMS," giving high assurance the cloud provider cannot decrypt data, contrasted with BYOK's provider-boundary key handling.

Web page · 138 KB · a short read

MiscMigration Guidance
Unknown
Trust 29Needs review
21-CFR-312-62-Investigator-recordkeeping-and-record-retentioUpdated

Official eCFR text for 21 CFR 312.62, the FDA regulation specifying investigator record retention: 2 years following marketing-application approval (or 2 years after investigation discontinuation if no application is approved).

ReleasedMigration Guidance
Unknown
Trust 22Needs review
Visa-Token-ServiceUpdated

Official Visa product page for Visa Token Service (VTS), confirming it substitutes card numbers (PANs) with tokens for digital and mobile wallet payments (Apple Pay, Google Pay, Samsung Pay).

MiscMigration Guidance
Unknown
Trust 21Needs review
EMV-Key-Management-ExplainedUpdated

Cryptomathic white paper on the EMV card personalization and key-management workflow. Confirms the general personalization process but not the specific 'KIF injection'/5-7 year migration timeline claim; kept as a legitimate reference on EMV key management, not force-cited to that specific claim.

PDF · 2.8 MB · a reference document — dip in, don’t read it through

MiscMigration Guidance
Unknown
Trust 30Needs review
Secret-Zero-Tackling-the-Secret-Zero-ProblemUpdated

Secrets-management glossary article defining the 'Secret Zero' problem: the chicken-and-egg dilemma of securely providing the initial secret needed to unlock a secrets vault or bootstrap further secure access.

Web page · 206 KB · a long read

MiscMigration Guidance
Unknown
Trust 27Needs review
Toward-Quantum-Safe-6G-Experimental-Evaluation-of-Post-QuantUpdated

Experimental evaluation of post-quantum cryptography (ML-KEM) performance overhead for 6G control-plane and TLS communications, including WAN-emulated network conditions. Checked for pqc-testing-validation's specific IKEv2 WAN-latency claims (no exact match found there); kept as a legitimate PQC performance reference.

PDF · 1.1 MB · a long read

Research PaperMigration Guidance
Unknown
Trust 39Needs review
LoRaWAN-Regional-ParametersUpdated

Official LoRa Alliance specification defining region-specific radio parameters, confirming the 222-byte maximum application payload for EU863-870 at SF7/SF8, 125 kHz data rates.

Web page · 104 KB · a short read

ReleasedMigration GuidanceReviewed (LLM) · eramusa · Oct 2026 · via manual data edit (library)
Unknown
Trust 37Needs review
Post-Quantum-Algorithms-Luna-HSMUpdated

Thales's official Luna HSM documentation confirming ML-KEM (CKM_ML_KEM) and ML-DSA (CKM_ML_DSA) algorithm support requires Luna HSM Firmware 7.9.0 or newer (LMS-HSS separately available since 7.8.9).

Web page · 47 KB · a short read

MiscMigration Guidance
Unknown
Trust 38Needs review
A-Multifaceted-Look-at-Starlink-PerformanceUpdated

Peer-reviewed (WWW '24) longitudinal measurement study of Starlink LEO latency (~19.2M samples); finds terminal-to-ground-station 'bent-pipe' latency ~40ms and median RTT ~39-40ms globally within the dense 53-degree shell, consistent with ~20ms one-way delay.

PDF · 2.9 MB · a reference document — dip in, don’t read it through

Research PaperMigration Guidance
Unknown
Trust 28Needs review
Summary-of-NATO-s-Quantum-Technologies-StrategyUpdated

Web page · 329 KB · a long read

MiscMigration Guidance
Unknown
Trust 28Needs review
Singapore-Financial-Sector-QKD-Sandbox-Technical-ReportUpdated

PDF · 4.7 MB · a reference document — dip in, don’t read it through

MiscMigration Guidance
Unknown
Trust 39Needs review
PKI-Consortium-Post-Quantum-Cryptography-Conference-2025-KuaUpdated

Web page · 1.2 MB · a long read

MiscMigration Guidance
Unknown
Trust 39Needs review
Singapore-National-Quantum-Safe-Network-Plus-NQSNUpdated

MiscMigration Guidance
Unknown
Trust 21Needs review
Cross-Issuer-ZKP-Federation-for-Post-Quantum-Agentic-PaymentUpdated

Defines a protocol composing independently-issued post-quantum ZKP credentials (Falcon-1024/ML-DSA-65 signed) from different issuers into one federation token for agentic payment networks.

Web page · 46 KB · a short read

DraftProtocols
Christopher Hopley (AlgoVoi)
Trust 48Needs review
Concrete-Hybrid-PQ-T-Key-Encapsulation-MechanismsUpdated

Web page · 369 KB · a long read

ExpiredMigration Guidance
Unknown
Trust 38Needs review
Post-quantum-Hybrid-ECDHE-SCloud-Key-Exchange-for-TLS-1-3Updated

Specifies three hybrid key exchange mechanisms for TLS 1.3 combining ECDHE with the SCloud+ post-quantum KEM (X25519SCloud+128, SecP256r1SCloud+192, SecP384r1SCloud+256).

Web page · 68 KB · a short read

DraftKEMProtocols
Guilin Wang (Huawei); Anyu Wang (Tsinghua University)
Trust 48Needs review
Post-Quantum-Credential-Binding-for-x402-Agentic-Payment-AutUpdated

Defines Falcon-1024/ML-DSA-65 credential binding, envelope format, and session-token issuance for x402 agentic payment authorization.

Web page · 43 KB · a short read

DraftDigital Signature
Christopher Hopley (AlgoVoi)
Trust 49Needs review
Update-to-Post-quantum-Hybrid-ECDHE-MLKEM-Key-Agreement-forUpdated

Quick update to the to-be RFC for ECDHE-MLKEM, recommending three hybrid key agreement mechanisms in TLS 1.3.

Web page · 55 KB · a short read

ExpiredKEMProtocols
Muhammad Usama Sardar (TU Dresden)
Trust 47Needs review
Hybrid-PQ-T-Key-Encapsulation-MechanismsUpdated

Web page · 211 KB · a long read

DraftMigration Guidance
Unknown
Trust 38Needs review
Mathematics-of-Isogeny-Based-CryptographyUpdated

Web page · 40 KB · a short read

Research PaperMigration Guidance
Unknown
Trust 28Needs review
A-look-at-the-latest-post-quantum-signature-standardizationUpdated

Web page · 568 KB · a long read

MiscMigration Guidance
Unknown
Trust 40Needs review
draft-becker-cnsa2-smime-profileUpdated

Web page · 66 KB · a short read

DraftMigration Guidance
Unknown
Trust 38Needs review
Zemlyanika-Module-LWE-based-KEM-with-the-power-of-two-moduluUpdated

Research PaperMigration Guidance
Unknown
Trust 24Needs review
Lattice-based-Signature-Schemes-for-BitcoinUpdated

Web page · 17 KB · a quick skim

Research PaperMigration Guidance
Unknown
Trust 31Needs review
shrincs-bip-SHRINCS-md-at-main-SHRINCS-shrincs-bip-GitHubUpdated

Web page · 1.6 MB · a long read

DraftMigration Guidance
Unknown
Trust 39Needs review
specs-archive-dev-cryptographic-specs-falcon-deterministic-pUpdated

Web page · 235 KB · a long read

MiscMigration Guidance
Unknown
Trust 29Needs review
Hypericum-a-post-quantum-digital-signature-for-standardizatiUpdated

Web page · 2.5 MB · a long read

Research PaperMigration Guidance
Unknown
Trust 38Needs review
tc26-Kodieum-Kryptonit-PQ-MechanismUpdated

Web page · 46 KB · a short read

MiscMigration Guidance
Unknown
Trust 29Needs review
Verifying-and-optimizing-post-quantum-cryptography-at-AmazonUpdated

Web page · 313 KB · a long read

MiscMigration Guidance
Unknown
Trust 38Needs review
Quantumglow-Will-Solana-s-Performance-Survive-Quantum-ComputUpdated

Web page · 278 KB · a long read

MiscMigration Guidance
Unknown
Trust 32Needs review
BIP-361-Post-Quantum-Migration-and-Legacy-Signature-SunsetUpdated

Web page · 22 KB · a quick skim

DraftMigration Guidance
Unknown
Trust 30Needs review
Institute-of-Commercial-Cryptography-StandardsUpdated

Web page · 63 KB · a short read

MiscMigration Guidance
Unknown
Trust 29Needs review
What-Are-NIST-PQC-Standards-Palo-Alto-NetworksUpdated

Web page · 712 KB · a long read

MiscMigration Guidance
Unknown
Trust 39Needs review
ZIP-2005-Ironwood-Quantum-RecoverabilityUpdated

Web page · 192 KB · a long read

MiscMigration Guidance
Unknown
Trust 30Needs review
A-Scenario-Based-Evaluation-of-CRQC-AI-Vulnerability-SpectruUpdated

Web page · 44 KB · a short read

Research PaperProtocols
arXiv.org
Trust 38Needs review
Post-Quantum-Key-Encapsulation-Scheme-Kodiyum

PDF · 165 KB · a short read

ReleasedMigration Guidance
Unknown
Trust 31Needs review
Resistance-Analysis-of-Post-Quantum-Signature-Scheme-Shipovn

PDF · 268 KB · a short read

ReleasedMigration Guidance
Unknown
Trust 30Needs review
Looma-Low-Latency-Post-Quantum-Authentication-for-TLS-1-3-inUpdated

Web page · 103 KB · a short read

ExpiredProtocols
IETF Datatracker
Trust 39Needs review
Post-Quantum-EDHOC-Initiator-and-Responder-using-signature-aUpdated

Web page · 240 KB · a long read

ExpiredMigration Guidance
IETF Datatracker
Trust 38Needs review
The-Internet-Identity-Card-IIC-Credential-Format-A-Self-ContUpdated

Web page · 62 KB · a short read

DraftMigration Guidance
IETF Datatracker
Trust 39Needs review
Anchors-Post-Quantum-Command-Provenance-for-Autonomous-MachiUpdated

Web page · 61 KB · a short read

DraftMigration Guidance
IETF Datatracker
Trust 38Needs review
Post-Quantum-Cryptography-Recommendations-for-Key-FragmentatUpdated

Web page · 78 KB · a short read

DraftMigration Guidance
IETF Datatracker
Trust 38Needs review
Post-Quantum-Evidence-Records-with-Algorithm-Agility-WathiqaUpdated

Web page · 73 KB · a short read

DraftMigration Guidance
IETF Datatracker
Trust 39Needs review
Keyfactor-and-Quantinuum-Announce-Integration-to-Future-ProoUpdated

Web page · 176 KB · a long read

MiscMigration Guidance
Unknown
Trust 26Needs review
White-House-PQC-Executive-Order-Signals-New-Security-Era-SanUpdated

Web page · 25 KB · a quick skim

MiscMigration Guidance
Unknown
Trust 26Needs review
A-Q-A-with-Atsushi-Yamada-PQC-Addressing-Risk-Management-NeeUpdated

Web page · 24 KB · a quick skim

MiscMigration Guidance
ISARA Corporation
Trust 26Needs review
Quantum-Safe-Cryptography-Helping-customers-prepare-againstUpdated

Web page · 198 KB · a long read

MiscMigration Guidance
Vodafone
Trust 26Needs review
IonQ-IonQ-Appoints-Marco-Pistoia-as-Senior-Vice-President-ofUpdated

Web page · 94 KB · a short read

MiscMigration Guidance
Unknown
Trust 26Needs review
New-PQC-Standards-Set-to-Transform-Cybersecurity-SandboxAQUpdated

Web page · 35 KB · a quick skim

MiscMigration Guidance
Unknown
Trust 26Needs review
Post-quantum-cryptography-on-Ethereum-ethereum-orgUpdated

Web page · 374 KB · a long read

MiscMigration Guidance
ethereum.org
Trust 26Needs review
PKCS-12-Personal-Information-Exchange-Syntax-v1-1Updated

Web page · 119 KB · a short read

ReleasedMigration Guidance
IETF Datatracker
Trust 31Needs review
A-Standard-for-the-Transmission-of-IP-Datagrams-over-EtherneUpdated

Web page · 35 KB · a quick skim

ReleasedMigration Guidance
IETF Datatracker
Trust 31Needs review
IEEE-Standard-for-Ethernet

Web page · 272 KB · a long read

ReleasedMigration Guidance
IEEE Standards Association
Trust 26Needs review
Road-vehicles-Controller-area-network-CAN-Part-1-Data-link-l

ReleasedMigration Guidance
ISO
Trust 9Needs review
Purchase required
Use-of-FN-DSA-in-TLS-1-3Updated

Web page · 55 KB · a short read

DraftProtocols
Unknown
Trust 26Needs review
429P2-17-Digital-Information-Transfer-System-DITS-Part-2-Dis

ReleasedMigration Guidance
SAE ITC (ARINC)
Trust 9Needs review
Purchase required
618-9-Air-Ground-Character-Oriented-Protocol-Specification

ReleasedMigration Guidance
SAE ITC (ARINC)
Trust 9Needs review
Purchase required
Avionics-Application-Software-Standard-Interface-Part-0-Over

ReleasedMigration Guidance
SAE ITC (ARINC)
Trust 9Needs review
Purchase required
Bech32m-format-for-v1-witness-addressesUpdated

Web page · 404 KB · a long read

ReleasedMigration Guidance
GitHub
Trust 26Needs review
IEEE-Standard-for-Smart-Energy-Profile-Application-Protocol

ReleasedMigration Guidance
IEEE Standards Association
Trust 9Needs review
Purchase required
Chosen-Ciphertext-Attacks-Against-Protocols-Based-on-the-RSAUpdated

Web page · 278 KB · a long read

Research PaperMigration Guidance
SpringerLink
Trust 26Needs review
Key-encapsulation-mechanismsUpdated

Web page · 145 KB · a short read

MiscMigration Guidance
Google Cloud Documentation
Trust 26Needs review
Ubuntu-24-04-LTS-release-notesUpdated

Web page · 177 KB · a long read

MiscMigration Guidance
Ubuntu release notes
Trust 26Needs review
Lightweight-Directory-Access-Protocol-v3-UTF-8-String-Repres

Web page · 22 KB · a quick skim

ReleasedMigration Guidance
Unknown
Trust 31Needs review
Network-Domain-Security-NDS-Authentication-Framework-AF

Web page · 779 KB · a long read

ReleasedMigration Guidance
Unknown
Trust 26Needs review
Characteristics-of-the-Universal-Subscriber-Identity-ModuleUpdated

Web page · 1.6 MB · a long read

ReleasedMigration Guidance
Unknown
Trust 26Needs review
Numbering-addressing-and-identification

Web page · 1.5 MB · a long read

ReleasedMigration Guidance
Unknown
Trust 26Needs review
X25519Kyber768Draft00-hybrid-post-quantum-KEM-for-HPKEUpdated

Web page · 85 KB · a short read

ExpiredMigration Guidance
IETF Datatracker
Trust 26Needs review
SSLkeysUpdated

Web page · 86 KB · a short read

MiscMigration Guidance
Unknown
Trust 26Needs review
45-CFR-164-312-Technical-safeguardsUpdated

Web page · 73 KB · a short read

ReleasedMigration Guidance
Unknown
Trust 26Needs review
OpenSSH-9-9Updated

Web page · 8 KB · a quick skim

MiscProtocols
Unknown
Trust 26Needs review
Electronic-Signatures-and-Infrastructures-ESI-Algorithms-andUpdated

PDF · 432 KB · a long read

ReleasedMigration Guidance
Unknown
Trust 26Needs review
ChaCha20-and-Poly1305-for-IETF-ProtocolsUpdated

Web page · 151 KB · a long read

ReleasedMigration Guidance
IETF Datatracker
Trust 31Needs review
FrodoKEM-key-encapsulation-from-learning-with-errorsUpdated

Web page · 90 KB · a short read

DraftMigration Guidance
IETF Datatracker
Trust 26Needs review
GNU-General-Public-LicenseUpdated

Web page · 50 KB · a short read

MiscMigration Guidance
Unknown
Trust 26Needs review
Multiple-Authentication-Exchanges-in-the-Internet-Key-ExchanUpdated

Web page · 66 KB · a short read

ReleasedProtocols
IETF Datatracker
Trust 31Needs review
Quantinuum-s-Quantum-Origin-Becomes-First-Software-Quantum-RUpdated

Web page · 166 KB · a long read

MiscMigration Guidance
Unknown
Trust 26Needs review
IEEE-Std-802-3bp-2016-1000BASE-T1-PHYUpdated

Web page · 3 KB · a quick skim

ReleasedMigration Guidance
Unknown
Trust 26Needs review
The-Straits-Times-DBS-PayLah-users-can-scan-UnionPay-QR-codeUpdated

Web page · 35 KB · a quick skim

MiscMigration Guidance
Unknown
Trust 26Needs review
The-Total-Economic-Impact-Of-DigiCert-ONEUpdated

Web page · 413 KB · a long read

MiscMigration Guidance
Unknown
Trust 26Needs review
Factoring-using-2n-2-qubits-with-Toffoli-based-modular-multiUpdated

Web page · 41 KB · a short read

Research PaperMigration Guidance
arXiv.org
Trust 26Needs review
SolarWinds-Corporation-Form-8-K-December-14-2020Updated

Web page · 45 KB · a short read

MiscMigration Guidance
Unknown
Trust 26Needs review
Cards-and-security-devices-for-personal-identification-Conta

ReleasedMigration Guidance
ISO/IEC
Trust 9Needs review
Purchase required
Cards-and-security-devices-for-personal-identification-Conta-2

ReleasedMigration Guidance
ISO/IEC
Trust 9Needs review
Purchase required
Road-vehicles-Vehicle-to-grid-communication-interface-Part-1

ReleasedMigration Guidance
ISO/IEC
Trust 9Needs review
Purchase required
Road-vehicles-Vehicle-to-grid-communication-interface-Part-2

ReleasedMigration Guidance
ISO/IEC
Trust 9Needs review
Purchase required
Codes-for-the-representation-of-names-of-countries-and-their

ReleasedMigration Guidance
ISO/IEC
Trust 9Needs review
Purchase required
664P7-1-Aircraft-Data-Network-Part-7-Avionics-Full-Duplex-Sw

ReleasedMigration Guidance
SAE ITC (ARINC)
Trust 9Needs review
Purchase required
740-17-Encryption-commodities-software-and-technology-ENCUpdated

Web page · 128 KB · a short read

ReleasedMigration Guidance
Unknown
Trust 26Needs review
Specification-of-the-MILENAGE-algorithm-set-An-example-algorUpdated

Web page · 536 KB · a long read

ReleasedMigration Guidance
Unknown
Trust 26Needs review
Satellite-Relayed-Intercontinental-Quantum-NetworkUpdated

Web page · 48 KB · a short read

Research PaperMigration Guidance
arXiv.org
Trust 26Needs review
102-3-Penalty-adjustment-and-tableUpdated

Web page · 273 KB · a long read

ReleasedMigration Guidance
Unknown
Trust 26Needs review
ICS-Medical-Advisory-ICSMA-17-241-01-Abbott-Laboratories-AccUpdated

Web page · 60 KB · a short read

MiscMigration Guidance
Cybersecurity and Infrastructure Security Agency CISA
Trust 26Needs review
15-CFR-740-13-Technology-and-software-unrestricted-TSUUpdated

Web page · 87 KB · a short read

ReleasedMigration Guidance
Unknown
Trust 26Needs review
3GPP-TS-35-240-Specification-of-the-Snow-5G-based-256-bits-aUpdated

Web page · 228 KB · a long read

DraftMigration Guidance
Unknown
Trust 26Needs review
3GPP-TS-35-246-Specification-of-the-ZUC-256-based-256-bits-aUpdated

Web page · 228 KB · a long read

DraftMigration Guidance
Unknown
Trust 26Needs review
A-tweezer-array-with-6100-highly-coherent-atomic-qubitsUpdated

Web page · 46 KB · a short read

Research PaperMigration Guidance
arXiv.org
Trust 26Needs review
Architectural-mechanisms-of-a-universal-fault-tolerant-quantUpdated

Web page · 52 KB · a short read

Research PaperMigration Guidance
arXiv.org
Trust 26Needs review
IBM-Quantum-Nighthawk-and-Loon-announcement-12-November-2025Updated

Web page · 61 KB · a short read

MiscMigration Guidance
IBM Newsroom
Trust 26Needs review
Logical-computation-demonstrated-with-a-neutral-atom-quantumUpdated

Web page · 54 KB · a short read

Research PaperMigration Guidance
arXiv.org
Trust 26Needs review
Quantum-Circuit-Optimization-with-AlphaTensorUpdated

PDF · 2.4 MB · a reference document — dip in, don’t read it through

Research PaperMigration Guidance
arXiv.org
Trust 26Needs review
Quantum-Resource-Estimates-for-Computing-Elliptic-Curve-DiscUpdated

PDF · 866 KB · a long read

Research PaperMigration Guidance
arXiv.org
Trust 26Needs review
RFC-2315-PKCS-7-Cryptographic-Message-Syntax-Version-1-5Updated

Web page · 307 KB · a long read

ReleasedMigration Guidance
Unknown
Trust 31Needs review
IBM-Quantum-Development-RoadmapUpdated

Web page · 51 KB · a short read

MiscMigration Guidance
Unknown
Trust 26Needs review
IBM-Debuts-Next-Generation-Quantum-Processor-IBM-Quantum-SysUpdated

PDF · 10.8 MB · a reference document — dip in, don’t read it through

MiscMigration Guidance
IBM Newsroom
Trust 26Needs review
IBM-Quantum-System-Two-the-era-of-quantum-utility-is-hereUpdated

Web page · 124 KB · a short read

MiscMigration Guidance
Unknown
Trust 26Needs review
PCI-PTS-Listing-Field-DefinitionsUpdated

PCI PTS approved-device listing detail page. Its header defines the listing fields (approval number, version, expiry, restricted or unrestricted HSM use, remote-managed HSM, ISO PIN block format 4, and a Post-Quantum Cryptography notation).

Web page · 30 KB · a quick skim

MiscCompliance & CertificationReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
PCI Security Standards Council
Trust 34Needs review
NIST-CMVP-ESVUpdated

NIST GitHub hub for the Entropy Source Validation Test System (ESVTS). It holds the protocol documentation, issue tracker and a Python client for submitting entropy sources and random bit generators for assessment against SP 800-90B and SP 800-90C.

Web page · 274 KB · a long read

MiscCompliance & CertificationReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
NIST (usnistgov)
Trust 34Needs review
RFC 6605Updated

Web page · 62 KB · a short read

ReleasedMigration GuidanceReviewed (LLM) · eramusa · Sep 2026 · via review-proposals (threats second-source pilot) + lineage/apply_secondary.py
IETF
Trust 31Needs review
draft-fregly-research-agenda-for-pqc-dnssec-00Updated

Web page · 84 KB · a short read

ExpiredMigration GuidanceReviewed (LLM) · eramusa · Sep 2026 · via review-proposals (threats second-source pilot) + lineage/apply_secondary.py
IETF
Trust 26Needs review
RFC 7935Updated

Web page · 75 KB · a short read

ReleasedMigration GuidanceReviewed (LLM) · eramusa · Sep 2026 · via review-proposals (threats second-source pilot) + lineage/apply_secondary.py
IETF
Trust 31Needs review
GSA-FICAM-PQC-ReadinessUpdated

Web page · 30 KB · a quick skim

MiscMigration GuidanceReviewed (LLM) · eramusa · Sep 2026 · via lineage/apply_secondary.py
GSA — Federal Identity, Credential, and Access Management (FICAM)
Trust 26Needs review
Post-quantum-questions-to-ask-your-vendors-Cyber-gov-auUpdated

Web page · 356 KB · a long read

MiscMigration GuidanceReviewed (LLM) · eramusa · Sep 2026 · via lineage/apply_secondary.py
Unknown
Trust 26Needs review
Cloud-HSM-architecture-Security-Google-Cloud-DocumentationUpdated

Web page · 172 KB · a long read

MiscMigration GuidanceReviewed (LLM) · eramusa · Sep 2026 · via lineage/apply_secondary.py
Google Cloud Documentation
Trust 26Needs review
Planning-for-post-quantum-cryptography-Cyber-gov-auUpdated

Web page · 333 KB · a long read

MiscMigration GuidanceReviewed (LLM) · eramusa · Sep 2026 · via lineage/apply_secondary.py
Unknown
Trust 26Needs review
RFC 10024Updated

Web page · 96 KB · a short read

ReleasedProtocolsReviewed (LLM) · eramusa · Sep 2026 · via lineage/apply_secondary.py
IETF
Trust 31Needs review
NIST-CSWP-37B-IPDUpdated

PDF · 1.5 MB · a long read

DraftCompliance & CertificationReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
NIST (Celi; Calis; Souppaya; Barker; Scarfone; Geddis) with Strativia, MITRE, atsec, Cisco, AWS
Trust 48Needs review
CCMC-011-CCRA-EUCC-CoexistenceUpdated

PDF · 126 KB · a short read

ReleasedCompliance & Certification
CCRA Management Committee (CCMC)
Trust 48Needs review
ENISA-EUCC-HSM-PP-FPT-PHP-Interpretation

PDF · 402 KB · a long read

ReleasedCompliance & Certification
ENISA; ECCG EUCC maintenance subgroup
Trust 48Needs review
ENISA-EUCC-Assurance-Continuity-Change-Scenarios

PDF · 880 KB · a long read

ReleasedCompliance & Certification
ENISA; ECCG subgroup on EUCC maintenance and review (EsEm)
Trust 48Needs review
ENISA-EUCC-Product-Series-Methodology

PDF · 410 KB · a long read

ReleasedCompliance & Certification
ENISA; ECCG subgroup on EUCC maintenance and review (EsEm)
Trust 48Needs review
ANSSI-CC-PP-2018-02-EN-419241-2

PDF · 1.4 MB · a long read

ReleasedCompliance & Certification
CEN/TC 224 (certified by ANSSI)
Trust 50Needs review
usnistgov-ACVP-Automated-Cryptographic-Validation-Protocol-SUpdated

usnistgov/ACVP GitHub repository: the algorithm-neutral ACVP JSON protocol core specification plus per-algorithm test-type and registration-capability sub-specifications (ML-DSA, SLH-DSA, SHA, at this commit). ACVP is the wire protocol NIST's ACVTS speaks — it is not itself a certifying program; CAVP issues the algorithm validation certificate. Pinned at commit 892fd147.

Web page · 485 KB · a long read

MiscProtocols
NIST (usnistgov)
Trust 57Needs review
usnistgov-ACVP-Server-Public-Reference-Sample-Vector-SetsUpdated

usnistgov/ACVP-Server GitHub repository (Gen/Vals): NIST's reference implementation that generates and verifies ACVP test vector sets — the source of every pinned public NIST ACVP-Server reference-sample vector file this program cites. Distinct from ACVTS (the hosted Demo/Prod services) and from CAVP (the certifying program); this repository is code, not a certificate.

Web page · 370 KB · a long read

MiscImplementations
NIST (usnistgov)
Trust 54Needs review
NIST-CMVP-ESV-Program

ReleasedMigration GuidanceReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
Unknown
Trust 13Needs review
NIST-CMVP-ESV-AnnouncementsUpdated

Web page · 79 KB · a short read

MiscMigration GuidanceReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
Unknown
Trust 29Needs review
NIST-CMVP-MIS-SP800-140B

ReleasedMigration GuidanceReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
Unknown
Trust 13Needs review
NIST-ACMVP-Protocol-WorkstreamUpdated

Web page · 163 KB · a long read

MiscMigration GuidanceReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
Unknown
Trust 30Needs review
NCCoE-Automation-of-the-CMVPUpdated

Web page · 104 KB · a short read

MiscMigration GuidanceReviewed (LLM) · eramusa · Sep 2026 · via manual data edit (library)
NCCoE
Trust 28Needs review
Considerations-for-Selecting-Post-Quantum-Algorithms-for-DNSUpdated

Web page · 8 KB · a quick skim

DraftMigration Guidance
Unknown
Trust 26Needs review
Security-Considerations-for-ML-DSAUpdated

Web page · 33 KB · a quick skim

ExpiredMigration Guidance
Unknown
Trust 38Needs review
draft-ietf-lake-pqsuitesUpdated

LAKE WG draft defining quantum-resistant cipher suites for the LAKE protocol (formerly EDHOC, RFC 9528) using ML-KEM-512/1024 for key exchange and ML-DSA-44/87 for signatures, and renaming EDHOC to LAKE with registry columns marking DH/NIKE dependence. Directly PQC: KEM-based exchange cannot use the DH-based methods 0-3, and PQ/T hybrid KEMs are discussed for transition.

Web page · 30 KB · a quick skim

DraftProtocols1 rev
IETF LAKE WG; G. Selander; J. Preuß Mattsson (Ericsson); C. Papon (Limoges University)Sep 19, 2026
Trust 62Needs review
draft-ietf-cose-cbor-encoded-certUpdated

COSE WG draft defining C509, a CBOR encoding of X.509 certificates (invertible re-encoding or natively signed CBOR) plus CBOR certification requests, COSE headers and a TLS certificate type, cutting RFC 7925-profiled IoT certificate size by over 50%. PQC-relevant: it is extensible to PQ algorithms, but its own size tables show only marginal savings for ML-DSA-65 and FN-DSA-512 chains because PQ keys and signatures dominate.

Web page · 249 KB · a long read

DraftPKI Certificate Management
IETF COSE WG; J. Preuß Mattsson; G. Selander (Ericsson AB); S. Raza (University of Glasgow); J. Höglund (RISE AB); M. Furuhed (IN Groupe); L. Liao (NIO Inc.)Sep 24, 2026
Trust 56Needs review
draft-ietf-uta-tls13-iot-profileUpdated

UTA WG draft defining TLS/DTLS 1.3 profiles for constrained IoT devices and updating RFC 7925's X.509 certificate profile and ciphersuite requirements. It says plainly that its profile is classical and not quantum-resistant, points to draft-ietf-uta-pqc-app for PQC guidance, and notes RFC 9973 external-PSK mixing as a transitional measure against harvest-now-decrypt-later.

Web page · 106 KB · a short read

DraftProtocols
IETF UTA WG; H. Tschofenig (UniBw M.); T. Fossati (NVIDIA); M. Richardson (Sandelman Software Works); D. Migault (Ericsson)Sep 3, 2026
Trust 52Needs review
draft-ietf-suit-manifestUpdated

SUIT WG draft defining the CBOR-based SUIT manifest format: an envelope of COSE-authenticated metadata and command sequences describing where to fetch firmware/code, which devices it applies to and how to install and invoke it, meeting the RFC 9124 requirements. Not a PQC spec, but its envelope design explicitly accommodates large post-quantum signatures for constrained devices.

Web page · 229 KB · a long read

DraftProtocols
IETF SUIT WG; B. Moran (Arm Limited); H. Tschofenig (H-BRS); H. Birkholz (Fraunhofer SIT); K. Zandberg (Inria); Ø. Rønningstad (Nordic Semiconductor)Jun 18, 2026
Trust 49Needs review
draft-ietf-iotops-7228bisUpdated

IOTOPS WG draft that revises and will obsolete RFC 7228, giving terminology for constrained-node networks, including device classes (now with narrative for Class 3 and 4 devices beyond Class 2), M-group/J-group device groups, energy and physical-layer bitrate classes. Not PQC-specific; its device classes are the common yardstick for judging whether a device can run PQC (draft-ietf-lake-pqsuites and the TLS 1.3 IoT profile both cite it).

Web page · 80 KB · a short read

DraftMigration Guidance
IETF IOTOPS WG; C. Bormann (Universität Bremen TZI); M. Ersue; A. Keränen (Ericsson); C. Gomez (Universitat Politecnica de Catalunya)Jul 6, 2026
Trust 53Needs review
OPC-10000-2Updated

OPC UA Part 2 (v1.05.06) describes the OPC UA security model: threats to industrial deployments, security objectives, SecureChannel and session architecture, SecurityPolicies, application/user authentication with X.509 certificates, and a mapping to IEC 62443-4-2, with an annex comparing RSA and ECC. Not PQC-specific; relevant to PQC migration because all OPC UA SecurityPolicies currently rely on RSA or ECC for certificates, signatures and key establishment.

Web page · 407 KB · a long read

ReleasedProtocolsReviewed (LLM) · eramusa · Oct 2026 · via manual data edit (library)
OPC Foundation
Trust 50Needs review
OPC-10000-7Updated

OPC UA Part 7 (v1.05.02) specifies the structure of OPC UA Profiles, Facets and Conformance Units used to group features for tool-based and lab-based certification testing; the profiles themselves, including security policy profiles, are maintained in the OPC Foundation online profiles database. Not PQC-specific; relevant to PQC migration because new quantum-safe SecurityPolicies would enter OPC UA via these profiles (current changes add ECC-curve25519 and ECC-nist256 policies).

Web page · 57 KB · a short read

ReleasedProtocolsReviewed (LLM) · eramusa · Oct 2026 · via manual data edit (library)
OPC Foundation
Trust 50Needs review
HSE-ECI-Functional-Safety

UK HSE regulator guidance page on functional safety of safety instrumented systems, alarm systems and BPCS in the process industries. States that BS EN 61508 is the general benchmark of good practice and BS EN 61511 (edition 2) is the benchmark standard for managing functional safety in the process industries, summarising its safety-lifecycle principles and Functional Safety Assessment.

Web page · 43 KB · a short read

ReleasedGovernment & Policy
UK Health and Safety Executive (HSE)Jun 29, 2026
Trust 29Needs review
ISO-IEC-28033

DraftMigration Guidance
ISO/IEC
Trust 9Needs review
Purchase required

Next step

See what changed

The revisions page lists the corrections made to the documents and data in the library.