PQC Library
The standards, drafts and guidance that define post-quantum cryptography.
The standards, drafts and guidance that define post-quantum cryptography.
What this means for you
- Executive / Business Leader
- Pick the "Plan migration" door for guidance and report picks rather than raw specifications; sort by Urgency, and each document's panel shows a Migration urgency value and an "Open document" link to the original.
- GRC / Risk & Compliance
- The "Cert-relevant" quick view is the FIPS 203–205, SP 800-208 and CMVP set; open any document for its Trust score, Vetting body, Peer reviewed and last-verified date, and "Authoritative sources only" under Advanced drops the rest.
- Developer / Engineer
- Search "ML-KEM", "FIPS 203" or "hybrid TLS", or open Advanced and filter by Algorithm family; the "Reference" door keeps standards, specs and policy, and "Builds on" in a document's panel lists what it depends on.
- Security Architect
- The "Reference" door holds standards, specs and policy; a document's panel lists what it "Builds on", its "Previous revisions" and the "CSWP-39 requirements" it satisfies, each linking to the matching Command Center zone.
- Researcher / Academic
- Sort by Publication date or Most cited; every document panel shows its type, region, last-verified date, Trust score, Peer reviewed status and "Previous revisions", with "Open document" going to the original source.
- Certification & Validation Engineer
- The "Cert-relevant" quick view is the FIPS 203–205, SP 800-208 and CMVP set; your categories lead with Compliance & Certification, NIST Standards and Algorithm Specifications.
- IT Ops / DevOps
- "Start here — picked for" your role sits above the doors; the "Cert-relevant" quick view is FIPS 203–205, SP 800-208 and the CMVP manual, and Lifecycle status filters to Published so you are not configuring against a draft.
- Curious Explorer
- Pick the "Learn" door for research, analysis and explainers; "Recently changed" at the top shows what was just added or updated, and the search box takes plain words like "hybrid TLS".
C++ library for BGV, BFV, CKKS, CGGI/FHEW, threshold FHE and proxy re-encryption.
Web page · 216 KB · a long read
Pure-Rust TFHE (CGGI) library from Zama with seeded client-key generation and compressed server keys; WASM bindings.
Web page · 209 KB · a long read
PCI Perspectives blog post of 14 September 2026 announcing publication of the PCI Key Management and Operations (KMO) Standard v1.0.
Web page · 83 KB · a short read
JOSE and COSE serializations for PQ/T hybrid composite signatures that combine ML-DSA with ECDSA or EdDSA (six algorithms, e.g. ML-DSA-65-ES256, ML-DSA-65-Ed25519). Revision -04 signs the message representative M' directly, uses uncompressed EC public keys and DER-encoded ECDSA components, and publishes JOSE and COSE examples in Appendix A.
Web page · 359 KB · a long read
Composite ML-KEM public keys and algorithms for X.509 (also used by CMS/S-MIME, EST and CMP): an ML-KEM key and a classical KEM key (X25519, ECDH, RSA-OAEP) under one OID in the id-pkix 1.3.6.1.5.5.7.6.55-.66 range, ML-KEM component first; .58 = id-MLKEM768-X25519-SHA3-256. Revision -21; in IESG Evaluation.
Web page · 475 KB · a long read
NIAP policy requiring CNSA 2.0 for every cryptographic function in NIAP/CCRA-certified products used in US National Security Systems: effective 2027-01-01; non-CNSA 2.0 products not accepted into NIAP evaluation from 2028-01-01 and not posted to the NIAP PCL from 2029-01-01 (CNSA 1.0 cut-offs 2027-01-01 / 2027-07-01).
PDF · 193 KB · a short read
Specifies composite post-quantum signatures — PQC plus classical under one identifier — in the SSH protocol.
Web page · 84 KB · a short read
Errata to TCG TPM 2.0 Library v1.85. Corrections to ML-DSA, ML-KEM, Labeled KEM command definitions.
PDF · 248 KB · a short read
Defines DNSSEC DS/DNSKEY/RRSIG use of the ML-DSA-44 parameter set from FIPS 204, assigning DNSSEC algorithm number 18 (mnemonic MLDSA44); basis for Cloudflare's 2026-09-10 1.1.1.1 resolver pilot.
Web page · 60 KB · a short read
Research paper (arXiv:2602.21524v2, Baseri and Waller) analysing the quantum threat to nuclear power plant I&C. States that Shor’s algorithm renders RSA and ECC "the cryptographic bedrock of industrial authentication, firmware signing, and secure communications" and models complete breaks of RSA-2048 and ECC-256/384. Cited as research, not as a specification: IEC 62645 is paywalled and IAEA NSS 33-T names no cryptographic algorithm at all.
PDF · 1.3 MB · a long read
Finalized v2.1 update to the SBOM Minimum Elements, co-authored by CISA, NSA, FBI and 15 international partner cyber agencies (Australia's ACSC, Canadian Centre for Cyber Security, Czech NUKIB, French ANSSI, German BSI, Indian CERT-In, Italian ACN, Japan's METI/NCO, NIS/NCSC, South Korea's KISA, Dutch NCSC-NL, New Zealand's NCSC-NZ, Polish NASK, Ukrainian NBU). Preserves the 2021 NTIA baseline's core principles while adding 10 new required SBOM elements (SBOM Author Signature, SBOM/Data-Format Version and Name, Component Hash Value/Algorithm, SBOM Generation Context, SBOM Tool Name/Version, Component License) plus clarified scope on 8 existing fields. Version 2.0 (Aug 2025) was a public-comment draft; this 2.1 release (July 29, 2026) is the final successor NTIA-SBOM-Minimum-Elements-2021 anticipated but had not yet seen.
PDF · 1.3 MB · a long read
Web page · 121 KB · a short read
Defines ML-KEM-512 ML-KEM-768 and ML-KEM-1024 as NamedGroups for pure PQ key agreement in TLS 1.3. WGLC issues identified requiring revision. Expires Aug 2026.
Web page · 65 KB · a short read
Defines how SLH-DSA signatures are represented in JOSE and COSE — the token and object-signing formats.
Web page · 115 KB · a short read
Composite signature OIDs binding ML-DSA-44/65/87 with classical ECDSA, RSA, Ed25519, EdDSA.
Web page · 764 KB · a long read
cosmos-sdk's own CHANGELOG.md, v0.55.0 (2026-07-27) Features section: 'Add ML-DSA-65 (FIPS 204) post-quantum validator consensus key type, with SDK key wrappers, Amino + interface-registry registration, multisig support, and a hd.MlDsa65Type constant' (PR #26436) and 'Add ML-DSA-65 (FIPS 204) support for user account keys: mnemonic-based keyring creation/recovery (--algo ml_dsa_65), transaction signing/verification' (PR #26472). Real, shipped, PR-linked code — not a roadmap or proposal.
Web page · 109 KB · a short read
Defines ML-DSA-44/65/87 and SLH-DSA-128s/192s/256s as IKEv2 authentication methods.
Web page · 93 KB · a short read
Defines how composite ML-DSA signatures — one PQC and one classical algorithm under a single identifier — are carried in SSH.
Web page · 66 KB · a short read
WG-adopted from wang-ipsecme-hybrid-kem-ikev2-frodo. Defines FrodoKEM-as-additional-KE in IKEv2.
Web page · 81 KB · a short read
Defines mlkem768x25519-sha256 and similar hybrid SSH KEX methods.
Web page · 87 KB · a short read
Maps NSA CNSA 2.0 mandate (ML-KEM-1024, ML-DSA-87) to OpenSSH config from 2027.
Web page · 74 KB · a short read
Registers post-quantum cipher suites combining ML-KEM with AEAD/hash/signature for MLS.
Web page · 71 KB · a short read
Proposes batch-issued post-quantum identity credentials built on Merkle trees, to amortise certificate size across many identities.
Web page · 102 KB · a short read
Specifies ML-KEM-512/768/1024 as standalone IKEv2 KE transforms and as additional KE within RFC 9370.
Web page · 81 KB · a short read
Proposes SIM-based EAP authentication for enterprise Wi-Fi using MILENAGE, with post-quantum considerations.
Web page · 125 KB · a short read
Defines GSS-API key exchange methods using hybrid PQ/T cryptography for SSH, updating RFC 4462 and reusing schemes from I-D.ietf-sshm-mlkem-hybrid-kex for GSS-API authentication.
Web page · 60 KB · a short read
Specifies ML-KEM key encapsulation for the initial public-key exchange in the protocol it profiles.
Web page · 93 KB · a short read
Guidance on managing stateful HBS (LMS/XMSS) state to prevent catastrophic key reuse. Covers state persistence and distributed signing strategies.
Web page · 112 KB · a short read
Framework for hybrid key exchange combining traditional and PQ algorithms in TLS 1.3.
Web page · 80 KB · a short read
LAMPS WG-adopted draft specifying composite ML-KEM (ML-KEM + RSA-OAEP / ECDH / X25519 / X448) within CMS KEMRecipientInfo per RFC 9629. Profiles the X.509 composite-KEM construction into CMS for S/MIME-encrypted email and CMS-based protocols. Latest revision -01, Proposed Standard.
Web page · 91 KB · a short read
OASIS announcement approving two public-key cryptography standards advancing post-quantum adoption — a dated marker for procurement references.
Web page · 146 KB · a short read
CA/Browser Forum requirements for ML-DSA certificates in Web PKI.
Web page · 7 KB · a quick skim
Specifies use of ML-DSA-44/65/87 signature schemes in TLS 1.3 server authentication.
Web page · 59 KB · a short read
Extends HPKE (RFC 9180) with post-quantum and hybrid PQ/T key encapsulation mechanisms including ML-KEM and hybrid combinations with X25519 and P-256. Enables quantum-safe HPKE for email encryption, messaging, and ECH.
Web page · 208 KB · a long read
Generic MLS extensions framework supporting PQ ciphersuites and other extensions.
Web page · 123 KB · a short read
Defines how JWE uses HPKE in two modes: Integrated Encryption (HPKE encrypts the payload; the header carries only "alg", the JWE Encrypted Key is the encapsulated secret, IV and tag are empty) and Key Encryption (HPKE wraps the CEK; the encapsulated secret goes in "ek"). Registers the classical DHKEM suites HPKE-0 to HPKE-7; the post-quantum and PQ/T suites are registered separately in draft-ietf-jose-hpke-pq-pqt.
Web page · 224 KB · a long read
Hybrid aPAKE combining classical CPace with post-quantum OQUAKE+ (ML-KEM-based); addresses Harvest-Now-Decrypt-Later exposure of classical PAKEs like OPAQUE-3DH/SPAKE2+.
Web page · 150 KB · a short read
Lets IKEv2 peers negotiate two or more authentication methods via a new IKEv2 Authentication Method registry value (17) and SUPPORTED_AUTH_METHODS notify, for PQC transition defense-in-depth.
Web page · 74 KB · a short read
WG-track draft specifying ML-KEM-512/768/1024 for COSE Direct Key Agreement and Key Agreement with Key Wrap modes; hybrid PQ KEMs explicitly out of scope for this document.
Web page · 78 KB · a short read
Applies Merkle tree ladders to ML-DSA for DNSSEC, addressing the response-size problem post-quantum signatures create for DNS.
Web page · 89 KB · a short read
Proposes a messaging protocol for software agents built post-quantum from the start rather than retrofitted.
Web page · 117 KB · a short read
Registers the post-quantum and PQ/T hybrid HPKE algorithms for JOSE: HPKE-12/13 (ML-KEM-768/1024) and HPKE-8/9/10 (ML-KEM-768+P-256, ML-KEM-768+X25519 i.e. X-Wing, ML-KEM-1024+P-384), all with SHAKE256 and AES-256-GCM, for Integrated Encryption and Key Encryption (-KE) per draft-ietf-jose-hpke-encrypt. Keys use the AKP key type of RFC 9964. Appendix A publishes test vectors for every algorithm.
Web page · 192 KB · a long read
Addresses a real attack class in composite ML-DSA: reusing a component key across contexts, and forging across the pair.
Web page · 55 KB · a short read
ML-KEM key exchange for IKEv2 (IPsec), pure and hybrid. Section 2.1 allows ML-KEM-512 alone in IKE_SA_INIT over UDP; ML-KEM-768/1024 SHOULD NOT be used there without a guaranteed path MTU or reliable transport.
Web page · 82 KB · a short read
WG-adopted best-practice recommendations for quantum-ready TLS/DTLS 1.3 application profiles: hybrid key exchange preferred, composite certificates for transition, External PSK as CRQC mitigation.
Web page · 103 KB · a short read
This document defines a TLS 1.3 extension for dual-certificate hybrid authentication using separate traditional and post-quantum signature algorithms.
Web page · 85 KB · a short read
Proposes ML-KEM-based authentication for IKEv2 (more efficient than ML-DSA signatures) using an Encrypted Certificate payload; accommodates ideas from the PQuAKE protocol.
Web page · 96 KB · a short read
Profiles which post-quantum signature algorithms apply to its target protocol, and what migrating to them involves.
Web page · 109 KB · a short read
Singapore guidance for organizations preparing for PQC transition.
PDF · 1.7 MB · a reference document — dip in, don’t read it through
This document specifies a Pre-Shared Key (PSK) authentication method for the Ephemeral Diffie-Hellman Over COSE (EDHOC) key exchange protocol. The PSK method enhances computational efficiency while providing mutual authentication, ephemeral key exchange, identity protection, and quantum resistance. It is particularly suited for systems where nodes share a PSK provided out-of-band
Web page · 116 KB · a short read
Obsoletes RFC 8446; consolidates TLS 1.3 errata/clarifications (does not itself define PQC key exchange -- catalogued as the current base TLS 1.3 spec that PQC hybrid-KEM drafts like draft-ietf-tls-hybrid-design extend).
Web page · 611 KB · a long read
Defines X.509v3 certificates carrying ML-DSA keys for use with SSH.
Web page · 54 KB · a short read
Spain’s CCN recommendations for a post-quantum transition, including its phased approach.
PDF · 3.1 MB · a reference document — dip in, don’t read it through
Defines certificates for single-use signing keys bound to one signed document through a signedDocumentBinding extension, so the key needs no revocation or long validity. X.509 work relevant to large PQC signatures, but not a hybrid certificate mechanism.
Web page · 95 KB · a short read
Web page · 41 KB · a short read
Microsoft publishes comprehensive QSP roadmap detailing transition to quantum-safe cryptography across all products through 2033. Covers Windows platform, Azure, signing services, and core infrastructure.
Web page · 283 KB · a long read
New Protocols and Protocol Extensions are best designed with due consideration of the functionality needed to operate and manage them. Retrofitting operations and management considerations is suboptimal. The purpose of this document is to provide guidance to authors and reviewers on what operational and management aspects should be addressed when writing documents in the IETF Stream
Web page · 186 KB · a long read
Hybrid PKI authentication for IKEv2: component keys/algorithms must not be reused across the hybrid scheme, and hybrid IKEv2 key exchange must independently be CRQC-resilient.
Web page · 73 KB · a short read
Proposes an X.509 extension that commits to a post-quantum key alongside a classical one, so a certificate can carry both without a new format.
Web page · 64 KB · a short read
OMB memorandum implementing Executive Order 14412, directing federal agencies to execute prioritized PQC migration by December 31 2030 and submit PQC Migration Plans to OMB and ONCD within 120 days. Establishes a 5-phase migration schedule (Discovery 2026-27, Pilots 2027-28, Key-Establishment Migration 2028-30, Signature Migration 2031, Full Migration by 2035) and does not apply to national security systems.
PDF · 283 KB · a short read
The European Payments Council’s guidance on cryptographic algorithms and key management — the reference European payment schemes size their migrations against.
PDF · 1.4 MB · a long read
U.S. Executive Order signed June 22 2026 mandating federal post-quantum migration: agencies name a PQC migration lead within 30 days; OMB issues guidance to inventory High Value Assets and submit migration plans within 90 days; a NIST migration pilot completes by 2027; HVAs and high-impact systems transition to PQC for key establishment (FIPS 203) by Dec 31 2030 and digital signatures (FIPS 204) by Dec 31 2031; covered contractors comply by 2030; CISA and NIST publish CBOM minimum elements and accelerate FIPS 140-3 validation.
Web page · 289 KB · a long read
Companion order to EO 14412, signed the same day. Establishes the Quantum Computer for Application Development and Discovery Science (QC-ADDS) initiative, targeting delivery of a scientifically useful quantum computer to a Department of Energy facility by 2028, and directs a National Quantum Strategy update within 180 days. Does not itself impose cryptography compliance obligations.
Web page · 296 KB · a long read
Compares hybrid key establishment against standalone ML-KEM in TLS 1.3, and what each choice costs.
Web page · 86 KB · a short read
WG-adopted draft integrating ML-KEM into EAP-AKA' FS for quantum-resistant perfect forward secrecy; defines AT_PUB_KEM/AT_KEM_CT attributes, ML-KEM-512/768/1024 parameter sets.
Web page · 91 KB · a short read
WG-adopted draft using HPKE-wrapped hybrid ML-KEM to protect EAP-AKA' Forward Secrecy against CRQC; requires ML-KEM key pairs be used in only one EAP session.
Web page · 74 KB · a short read
Defines ML-DSA (FIPS 204) signature algorithms for TLS 1.3 authentication. Submitted to the IESG; on the 2026-07-02 telechat.
Web page · 57 KB · a short read
Specifies a protocol using post-quantum algorithms alone, with no classical component to fall back on.
Web page · 76 KB · a short read
ML-KEM key exchange for IKEv2 (IPsec). Submitted to the IESG; on the 2026-07-02 telechat.
Web page · 81 KB · a short read
The Matter smart-home core specification, including the device attestation and commissioning cryptography embedded in shipped hardware.
PDF · 15.7 MB · a reference document — dip in, don’t read it through
Specifies a hybrid post-quantum protocol combining classical and PQC key establishment.
Web page · 24 KB · a quick skim
IETF specification for a compact bit-array status list to check validity states of credentials (valid revoked suspended). Provides privacy-preserving revocation: the verifier cannot determine which specific credential is being checked from the status list position alone. Used in EUDI Wallet ecosystem for credential revocation checking without revealing holder identity to the issuer.
Web page · 217 KB · a long read
Revision -05 (cited here) defined ML-KEM for JOSE/JWE direct key agreement (alg ML-KEM-512/768/1024, KMAC256 key derivation) and for COSE. Revision -06 (2026-07-06) was retitled 'Post-Quantum Key Encapsulation Mechanisms (PQ KEMs) for COSE' and no longer covers JOSE; post-quantum JWE now goes through HPKE (draft-ietf-jose-hpke-encrypt with draft-ietf-jose-hpke-pq-pqt).
Web page · 42 KB · a short read
Proposed PQC updates to PIV card interfaces: dual-stack model preserving classical keys while adding ML-DSA/ML-KEM key references and certificate containers for backward-compatible, incremental deployment.
Web page · 40 KB · a short read
Proposed PQC updates to PIV card interfaces: dual-stack model preserving classical keys while adding ML-DSA/ML-KEM key references and certificate containers for backward-compatible, incremental deployment.
Web page · 40 KB · a short read
Companion PQC algorithm/key-size update to SP 800-73-6: specifies ML-DSA and ML-KEM parameter sets approved for use within the dual-stack PIV credential model.
Web page · 40 KB · a short read
Proposes post-quantum signed receipts for AI inference, as an alternative to trusted-execution-environment attestation.
Web page · 71 KB · a short read
Proposes a way to measure how cryptographically agile an application actually is, rather than treating agility as a yes/no property.
Web page · 43 KB · a short read
Proposes a TLS-layer mechanism for servers to make a cached commitment that they support PQC key exchange. Clients that have cached the commitment refuse future connections that omit PQC, providing protection against active MITM downgrade attacks that suppress ML-KEM negotiation during the quantum transition. Introduces the concept of a downgrade limit (cached duration) analogous to HSTS for HTTP.
Web page · 70 KB · a short read
Australia’s ISM cryptography guidelines — the approved-algorithm list Australian government systems are held to, including its PQC dates.
PDF · 983 KB · a long read
Identifies what network operators cannot currently see about their own post-quantum readiness, and what telemetry would be needed.
Web page · 60 KB · a short read
Sets out what multi-tenant public infrastructure needs for post-quantum certificate rotation, and which of those needs nothing currently meets.
Web page · 58 KB · a short read
General guidance for deploying IETF-protocol applications with post-quantum algorithm support across current (non-PQC-native) deployments.
Web page · 63 KB · a short read
PKCS#11 v3.2 finalized as an OASIS Standard (3 June 2026), technically identical in content to the prior Committee Specification Draft 01 / Committee Specification 01 — no substantive changes after Working Draft 13 (16 April 2025) per the spec's own Appendix C Revision History. Adds post-quantum mechanisms: ML-KEM (CKM_ML_KEM 0x00000017, CKM_ML_KEM_KEY_PAIR_GEN 0x0000000f), ML-DSA (CKM_ML_DSA 0x0000001d, CKM_ML_DSA_KEY_PAIR_GEN 0x0000001c, CKM_HASH_ML_DSA_*), and SLH-DSA (CKM_SLH_DSA, CKM_SLH_DSA_KEY_PAIR_GEN). Introduces C_EncapsulateKey() and C_DecapsulateKey() for KEM operations, and C_WrapKeyAuthenticated()/C_UnwrapKeyAuthenticated(). New key types: CKK_ML_KEM (0x49), CKK_ML_DSA (0x4a), CKK_SLH_DSA (0x4b). New attributes: CKA_PARAMETER_SET, CKA_ENCAPSULATE, CKA_DECAPSULATE, CKA_SEED.
Web page · 5.5 MB · a long read
Defines the conformance profiles that PKCS#11 v3.2 conformance is measured against. Section 7 of the base specification states that an implementation is a conforming Provider only if it meets one or more provider profiles specified here, so the base spec mandates no mechanism on its own. Specifies Baseline Provider, Complete Provider, Extended Provider, Authentication Token, Public Certificates Token and HKDF TLS Token, plus Baseline and Extended Consumer. Baseline Provider requires a CKO_PROFILE object with CKP_BASELINE_PROVIDER and explicitly requires no mechanisms. Edited by Tim Hudson (Cryptsoft); supersedes Profiles v3.1.
PDF · 530 KB · a long read
Individual draft defining ML-DSA-44 + Ed25519 composite signatures for SSH. Replaces the earlier ML-DSA-65 composite draft.
Web page · 61 KB · a short read
Specifies the ML-DSA-44 with Ed25519 composite signature pairing for SSH.
Web page · 14 KB · a quick skim
Major v2.1 (June 2026) of Marin Ivezic's (Applied Quantum) enterprise PQC migration methodology. Phase-by-phase guide across 8 phases (0-7) plus cross-cutting Skills, SOC, and GRC layers and sector packs. v2.0/v2.1 add a two-track approach, right-sizing profiles, AI-assisted migration guidance (5.7), a data-at-rest strategy (5.6), and new appendices: framework crosswalk (G) and protocol coverage matrix (H). Informed by NIST FIPS 203/204/205, IR 8547, CNSA 2.0, ETSI, and GSMA standards. Licensed CC BY 4.0.
PDF · 1.5 MB · a long read
Three-author governance and systems-architecture analysis of organizational identity in the PQC transition. Distinguishes harvest-now-decrypt-later confidentiality risk from the integrity / non-repudiation risk created by future forgery of legacy digital signatures. Introduces the "PQC Corridor" — a bounded governance + technical migration domain coordinating scope, legal assurance, data horizons, trust boundaries, cryptographic profiles, and audit. Treats business wallets (incl. proposed European Business Wallet), qualified Verifiable Data Registries (qVDRs), and Verifiable LEIs (vLEIs) as organizational interfaces for cross-jurisdiction trust. Targets B2B, B2G, G2G, M2M, and agent-to-agent ecosystems.
Web page · 421 KB · a long read
Cloud Security Alliance monthly cryptography newsletter compiled by Dr. Dhananjoy Dey (IIIT Lucknow, CSA Quantum-Safe Security Working Group). June 2026 issue covers cryptographic maturity as a precursor to PQC, the new DST (Distributed Service Trust) Task Force report on quantum-safe thinking, and ongoing PQC migration coverage across standards bodies and industry. Published under the CSA Quantum-Safe Security Working Group.
Web page · 116 KB · a short read
Cryptanalysis paper by Daniel J. Bernstein demonstrating exploitability of ML-DSA software vulnerabilities. Reproduces two distinct bug patterns (Dilithium 1.0 implementation flaw + PlayStation 3 ECDSA-style randomness reuse) as ML-DSA software variants, each forging signatures in ~1 second on a laptop core. Provides open-source attack demos that recover equivalent secret keys from public keys + a small number of signatures. Estimates breakable-key rates over time for ML-DSA solo vs. Ed25519+ML-DSA hybrid, arguing quantitatively for hybrid signature deployment.
PDF · 546 KB · a long read
ENISA survey-based analysis of Software Bill of Materials (SBOM) adoption across the EU (June 2026). Reports survey results on adoption readiness, formats (SPDX/CycloneDX), tooling and SDLC lifecycle integration, barriers and supplier requirements; finds the EU Cyber Resilience Act (CRA) is the primary accelerator, with 79% of organisations expecting to reach SBOM maturity before the CRA becomes fully applicable. Foundational to crypto-asset inventory and CBOM for PQC migration.
PDF · 2.9 MB · a reference document — dip in, don’t read it through
NIS Cooperation Group reference document (v1.0, June 2026) detailing technical and methodological security measures for essential and important entities under the NIS2 Directive (EU) 2022/2555, aligned with Commission Implementing Regulation (EU) 2024/2690. Covers cybersecurity governance, risk management, supply-chain security, effectiveness assessment and a dedicated cryptography section (2.10 Cryptography); replaces the previous Cooperation Group reference document.
Web page · 50 KB · a short read
Published RFC form of draft-ietf-openpgp-pqc: defines post-quantum and hybrid public-key algorithms for OpenPGP — ML-KEM key encapsulation with ML-DSA / SLH-DSA / Ed25519 signatures.
Web page · 825 KB · a long read
IETF guidance relevant to the post-quantum transition; see the document for its normative scope.
Web page · 161 KB · a long read
PDF · 2.5 MB · a reference document — dip in, don’t read it through
ETSI cryptographic suites for electronic signatures and trust services — which algorithms and key sizes are approved for qualified signatures in the EU.
PDF · 303 KB · a short read
Three-phase PQC migration roadmap for Circle (USDC issuer) and the Arc blockchain. Catalogs seven quantum attack vectors on the full blockchain stack (at-rest forgery via EVM ecrecover; retroactive privacy loss; consensus disruption; history rewrite; P2P session compromise via libp2p/Noise; RPC interception; on-spend). Readiness phase: SLH-DSA-SHA2-128s on-chain precompile for smart-account signature verification; X-Wing hybrid KEM (ML-KEM-768 + X25519) for TLS 1.3 and encrypted memos; TEE-based private execution environment (AWS Nitro/SGX/TDX). Transition phase: dual-mode USDC smart contracts; post-quantum ecrecover override; multi-sig cold storage; encrypted mempool. Switch phase: full PQ validator signatures; account recovery (dual-key BIP-39 derivation; TEE-attested ZK proof; off-chain). Policy section covers quantum flag day regulatory implications for stranded USDC assets. Co-authored with Dan Boneh (Stanford).
PDF · 607 KB · a long read
Specifies a mechanism to prevent algorithm downgrade attacks in IKEv2, ensuring that PQC-capable peers cannot be forced to negotiate weaker classical algorithms. Companion to draft-ietf-ipsecme-ikev2-mlkem.
Web page · 28 KB · a quick skim
NIST IR 8320 Series Volume E. Defines a TEE plus remote-attestation plus key-release workflow for protecting AI/ML data in use within cloud workloads. Frames confidential computing as the third pillar (alongside data-at-rest and data-in-transit encryption) and ties hardware-anchored attestation into cloud KMS key release.
PDF · 907 KB · a long read
Defines the x402 cryptographic receipt format and its post-quantum requirements, anchored to Starknet.
Web page · 137 KB · a short read
Proposes a tamper-evident envelope binding theorem catalogues to their validators and proofs.
Web page · 61 KB · a short read
This document defines pure post-quantum key exchange methods based on Module-lattice post-quantum key encapsulation schemes for use in the SSH Transport Layer Protocol.
Web page · 53 KB · a short read
Hybrid X25519MLKEM768 / SecP256r1MLKEM768 key agreement for TLS 1.3. IESG-approved; in the RFC Editor queue.
Web page · 84 KB · a short read
Specifies X25519MLKEM768, SecP256r1MLKEM768, and SecP384r1MLKEM1024 hybrid groups for TLS 1.3. Normative hybrid framework: draft-ietf-tls-hybrid-design (also in RFC Ed Queue). Both drafts in final pre-publication stage as of Feb 2026.
Web page · 75 KB · a short read
Sets out post-quantum requirements for x402 STARK-based payment receipts.
Web page · 83 KB · a short read
This document describes Merkle Tree certificates, a new form of X.509 certificate that integrates public logging with certificate issuance to reduce overhead for post-quantum signatures.
Web page · 194 KB · a long read
LAMPS WG-adopted draft specifying composite ML-DSA (ML-DSA + RSA-PSS / RSA-PKCS1 / ECDSA / Ed25519 / Ed448) SignerInfo for CMS per RFC 5652. Provides CMS-specific guidance for 18 composite signature algorithm combinations operating in pre-hash mode with algorithm-specific digests (SHA-256 / SHA-512 / SHAKE256). Latest revision -04, IESG state AD Followup (DISCUSS pending), Proposed Standard.
Web page · 49 KB · a short read
Lets a primary certificate advertise where a related secondary certificate (for example one with a PQC key) can be fetched, using a new subjectInfoAccess access method (id-ad-certDiscovery) and a relatedCertificateDescriptor otherName. Supports migration where a relying party needs a certificate in another algorithm. Replaces draft-lamps-okubo-certdiscovery. OIDs are still TBD.
Web page · 85 KB · a short read
Defines FN-DSA (FALCON/FIPS 206) signature usage in CMS. Expires May 2026.
Web page · 30 KB · a quick skim
Defines how FN-DSA (the Falcon-based signature planned as FIPS 206) public keys and signatures appear in X.509 certificates and CRLs. Its OIDs under the NIST sigAlgs arc are still TBD and FIPS 206 is not final, so no deployable FN-DSA certificate exists yet. Watchlist item.
Web page · 94 KB · a short read
Defines curveSM2MLKEM768 hybrid for TLS 1.3 combining Chinese SM2 curve with ML-KEM.
Web page · 15 KB · a quick skim
Defines the use of Composite ML-DSA hybrid signatures in TLS 1.3, combining ML-DSA with classical algorithms (ECDSA, RSA) for backward-compatible migration. Extends draft-ietf-lamps-pq-composite-sigs into the TLS layer.
Web page · 33 KB · a quick skim
Algorand's three-phase quantum-resistance roadmap: (1) blockchain history protected via State Proofs with Falcon (deployed 2022), (2) lazy migration for current account security — single-sig, multisig, LSig, and App accounts each given specific Falcon rekeying paths, (3) native PQC accounts (stateless or stateful Falcon) with consensus PQC planned. First MainNet Falcon transaction via LSig account abstraction deployed November 2025.
Web page · 210 KB · a long read
Status report on the second round of the NIST additional post-quantum digital signature candidates beyond the lattice-based standards.
PDF · 389 KB · a short read
WG-adopted successor to draft-reddy-emu-pqc-eap-tls: hybrid key exchange recommended for TLS-based EAP methods; addresses large-certificate round-trip/fragmentation risk and inner-auth exposure if the outer tunnel breaks.
Web page · 64 KB · a short read
Implementation-guidance draft (co-authored by Scott Fluhrer et al.) on ML-KEM pitfalls: validate public keys via Encapsulation Key Check, guard entropy quality, retain public key alongside secret key, watch PAKE-context timing side-channels.
Web page · 74 KB · a short read
Web page · 19.3 MB · a long read
Specification of SLH-DSA/Sphincs+ digital signatures for SSH, including standalone and hybrid modes with Ed25519/Ed448.
Web page · 107 KB · a short read
110-page comprehensive analysis of quantum threats to blockchain systems by Project Eleven. Projects Q-Day likely by 2030–2033. Covers secp256k1/ECDSA vulnerability, Bitcoin and Ethereum exposure, BIP-32 HD wallet risk, stablecoin quantification, and urgent PQC migration recommendations for blockchain operators and digital asset custodians.
Web page · 195 KB · a long read
Extends TLS AuthKEM with pre-shared key authentication modes; provides a fully quantum-resistant TLS 1.3 handshake without relying on any classical asymmetric primitives.
Web page · 40 KB · a short read
Replaces classical signature-based TLS 1.3 authentication with a KEM-based handshake.
Web page · 99 KB · a short read
Monte Carlo simulation (lognormal latency, M/M/c queueing, GEV tails) showing ML-DSA and Falcon meet payment SLAs, plus a four-phase bottom-up migration cost model and a harvest-now-decrypt-later exposure estimate. Illustrates the probabilistic and activity-based cost-model families for PQC migration.
PDF · 2.2 MB · a reference document — dip in, don’t read it through
This document specifies JSON Object Signing and Encryption (JOSE) and CBOR Object Signing and Encryption (COSE) serializations for Module-Lattice-Based Digital Signature Standard (ML-DSA) defined in NIST FIPS 204. Registers ML-DSA-44/65/87 with the new Algorithm Key Pair (AKP) key type (kty=AKP, COSE kty=7) and JOSE alg names matching the COSE registrations (-48/-49/-50). HashML-DSA is explicitly out of scope (§7.2); private key is the 32-byte seed only.
Web page · 260 KB · a long read
Web Authentication Level 3 specification for browser-based public-key authentication. Targeted by ML-DSA WebAuthn drafts that add PQ COSE algorithm identifiers for passkeys.
Web page · 2.7 MB · a long read
G7 Central Bank Quantum Technologies Working Group analytical report co-chaired by Banque de France and Bank of Canada. Covers harvest-now-decrypt-later risks, PQC migration planning for financial infrastructures, and quantum computing applications in finance (optimisation, simulation, payment systems). Provides governance and interoperability considerations for central banks and financial institutions transitioning to quantum-resilient security.
Web page · 295 KB · a long read
Cisco blog outlining its internal quantum-safe architecture strategy: embedding PQC into firmware, hardware, and supply chain. Covers ML-KEM, ML-DSA adoption roadmap, crypto-agility framework, and lessons from large-scale enterprise migration planning.
Web page · 80 KB · a short read
PQShield identifies four immediate quantum threats enterprises must address: harvest-now-decrypt-later attacks, vulnerable key exchange in TLS, insecure firmware signing, and inadequate crypto-agility. Recommends prioritized PQC migration starting with key establishment.
Web page · 162 KB · a long read
ENISA/ECCG cross-protocol survey of IETF, ETSI, NIST, and ITU-T hybrid PQ/T standardisation status across 14 protocols (TLS, IKEv2, CMS/S-MIME, SSH, OpenPGP, COSE, JOSE, MLS, EAP-AKA', PKIX/X.509, HPKE, CFRG, MLKEM/FrodoKEM combiners). Maps hybrid key agreement (CatKDF/CasKDF, NIST SP 800-227) and hybrid signature status against ECCG Agreed Cryptographic Mechanisms v2.0; explicitly not an ENISA recommendation.
PDF · 1.1 MB · a long read
Surveys the security reductions underpinning post-quantum schemes: what each construction actually proves, and against which assumption.
PDF · 686 KB · a long read
Technical analysis of PQC agility requirements in MCP (Model Context Protocol) transport layer used by AI agents. Examines how LLM tool-calling infrastructure inherits TLS vulnerabilities and proposes hybrid PQC key exchange as a mitigation for AI-to-AI and AI-to-tool communication channels.
Web page · 152 KB · a long read
The Quantum Insider analysis of why 2026 is a pivotal year for quantum security: NIST standards finalized, government migration deadlines approaching, enterprise procurement cycles beginning, and hardware progress accelerating. Frames 2026 as the year quantum security moves from planning to execution.
Web page · 229 KB · a long read
ITPro/CSA analysis of 11 business channel opportunities emerging from the PQC migration wave. Covers managed PQC services, crypto-agility tooling, compliance consulting, hardware security modules, and post-quantum VPN products as revenue streams for technology vendors and MSSPs.
Web page · 1.0 MB · a long read
Quantum Insider overview of the quantum security landscape: threat timeline, key cryptographic vulnerabilities (RSA, ECDSA, DH), PQC solution categories (KEM, signatures, agility), and the competitive race among enterprises, governments, and vendors to deploy quantum-safe infrastructure.
Web page · 244 KB · a long read
Quantum Computing Report executive summary on the accelerating Q-Day timeline. Synthesizes hardware progress (Google Willow, neutral-atom systems), algorithmic improvements reducing qubit requirements, and expanded attack surface beyond RSA to ECDSA and lattice-adjacent schemes. Projects credible Q-Day risk by 2029–2030.
Web page · 135 KB · a short read
Specifies combining a traditional MLS session with a PQ MLS session for amortized hybrid security.
Web page · 45 KB · a short read
Ars Technica reporting on the first confirmed ransomware family deploying post-quantum cryptography. The ransomware uses ML-KEM for key encapsulation, making traditional decryption-key recovery impossible even with law enforcement access to command-and-control infrastructure. Marks a new threat tier for incident response.
Web page · 147 KB · a short read
Defines an X.509v3 extension encoding differences between two paired certificates. Allows a relying party to reconstruct both traditional and PQC certificates from a single cert. Alternative to composite and related-certificate (RFC 9763) hybrid approaches. Backed by DigiCert and Entrust.
Web page · 191 KB · a long read
Quantum Insider coverage of new cryptanalysis research concluding AES-128 remains secure against quantum attack under revised Grover algorithm resource estimates. Higher parallelization requirements and error correction overhead mean AES-128 provides adequate quantum security margin, contrary to earlier conservative estimates.
Web page · 222 KB · a long read
The draft post-quantum profile for US Federal PKI certificates and CRLs — what a federal PQC certificate is allowed to contain.
PDF · 700 KB · a long read
Proposes an organizational-level Cryptographic Asset Inventory schema extending CycloneDX CBoM (component-level) to hardware/software/services, with quantum-readiness compliance indicators and criticality scoring.
Web page · 68 KB · a short read
Single-author proposal for a 96-bit locator/identifier-separated IPv4 extension with hybrid ML-KEM-768+X25519 session security over UDP/4242; addresses IPv4 exhaustion, not adopted by any WG.
Web page · 108 KB · a short read
NIST draft recommendation specifying methods for generating cryptographic keys. Rev. 3 adds ML-KEM-based symmetric key establishment, PQC signature algorithm support (ML-DSA), seed-expansion via SHAKE and DRBGs, and aligns randomness guidance with SP 800-90C. Public comment period closes June 16, 2026.
Web page · 46 KB · a short read
Strategy document recommending SLH-DSA-MTL, Falcon, XMSS, LMS plus "drop-in" NIST onramp algos for DNSSEC.
Web page · 57 KB · a short read
File-level hybrid encryption protocol (X25519/Ed25519 + Kyber768, ChaCha20-Poly1305 AEAD) defining a .glock container format; individual submission, not a protocol used by any deployed system in this catalog.
Web page · 39 KB · a quick skim
Microsoft Security Blog on establishing a cryptographic inventory as the foundation of a CPM program; four-phase approach from discovery to continuous monitoring.
Web page · 307 KB · a long read
Meta Engineering case study on a large-scale PQC migration with explicit inventory, policy, and rollout framework.
Web page · 125 KB · a short read
NIST SP 800-230 extends FIPS 205 with six new SLH-DSA parameter sets (SHA2 and SHAKE at levels 1/3/5) optimised for firmware signing, software distribution, and certificate signing. Signatures are roughly half the size of FIPS 205 variants but carry a strict 2^24 signatures-per-key limit. Not for general-purpose use.
Web page · 49 KB · a short read
Defines composite-certificate hybrid authentication for IKEv2 (traditional + PQC signatures in one cert) without changing base protocol messages; requires IKEv2 Fragmentation support for larger messages.
Web page · 58 KB · a short read
CryptoNext Security becomes the first EU company to achieve full NIST quantum-safe certification across ML-KEM, ML-DSA, and SLH-DSA. Coverage of their C-Pqc library FIPS compliance milestone and implications for European organizations seeking certified PQC implementations.
Web page · 152 KB · a long read
EFF policy analysis drawing parallel between Y2K remediation urgency and the PQC migration challenge. Argues the quantum cryptography deadline is arriving faster than expected with less organizational readiness. Calls for immediate government action, vendor support timelines, and user-facing communication.
Web page · 65 KB · a short read
Australian Computer Society coverage of Google and Cloudflare jointly pushing for industry-wide PQC deployment by 2029. Both companies cite accelerating quantum hardware progress and HNDL risks as justification for a 2029 deadline — three years earlier than previously communicated targets.
Web page · 33 KB · a quick skim
Quantum XChange announces Phio TX Management Console for centralized PQC key management and crypto-agility across enterprise networks. Enables policy-based PQC algorithm selection, inventory tracking, and rollout orchestration for hybrid classical/PQC environments.
Web page · 218 KB · a long read
This document describes the use of ML-DSA digital signatures for authentication within the Secure Shell (SSH) protocol.
Web page · 61 KB · a short read
Charter of Trust PQC Working Group report comparing global PQC transition timelines across US, EU, UK, Japan, Singapore, and Australia. Covers sectoral prioritization, quantum threat landscape, attack scenarios, and a practitioner playbook for PQC migration. Contributors include Siemens, IBM, Microsoft, Infineon, Atos, and Bosch.
Web page · 100 KB · a short read
Cloudflare's official post-quantum roadmap blog. Details phased deployment: X25519MLKEM768 hybrid in TLS already deployed to all customers, plans for ML-DSA certificate signing, 2029 target for full quantum-safe infrastructure, and migration guidance for customers.
Web page · 504 KB · a long read
QSE launches QPA v2, an enterprise post-quantum migration platform providing automated cryptographic inventory discovery, risk scoring, and migration orchestration. Integrates with existing PKI and key management systems to enable phased PQC rollout without infrastructure replacement.
Web page · 137 KB · a short read
Adds HPKE (RFC 9180 base mode plus PQ/T hybrid KEM algorithms) to COSE, enabling pure and hybrid post-quantum key encapsulation for COSE_Encrypt structures. Revision -25 submitted to IESG for publication; in AD evaluation as of 2026-04-07.
Web page · 269 KB · a long read
Guidance for integrating PQC into resource-constrained devices including IoT nodes and lightweight HSMs; covers seed-based key generation, ephemeral key handling, cryptographic task offloading, and post-quantum firmware authentication.
Web page · 65 KB · a short read
Specifies sntrup761x25519-sha512 hybrid key exchange for SSH; supersedes draft-ietf-sshm-ntruprime-ssh.
Web page · 89 KB · a short read
C2PA's normative specification for Content Credentials — cryptographically signed provenance manifests (claims, assertions, hard/soft bindings) embedded in media assets, with an X.509/COSE trust and validation model. Cited by the ai-security-pqc module for content provenance; the specification is not about post-quantum cryptography, and its allowed signature algorithms are ECDSA, RSASSA-PSS and Ed25519 only.
Web page · 1.1 MB · a long read
Initial public draft of NIST SP 1800-40B (April 2026), the NCCoE practice guide volume on automating the Cryptographic Module Validation Program.
PDF · 2.5 MB · a reference document — dip in, don’t read it through
NIST report describing recommended cybersecurity activities manufacturers should consider before their IoT products are sold, so customers get the product cybersecurity capabilities and information they need; supersedes NIST IR 8259 (2020). Recommends considering quantum-safe approaches and updatable hardware to allow a later move to post-quantum cryptography (pp. 31-32), without setting a deadline.
PDF · 2.6 MB · a reference document — dip in, don’t read it through
Web page · 83 KB · a short read
Argues a CBOM is necessary but insufficient; posture management adds lifecycle, policy, observability, and assurance layers.
Web page · 84 KB · a short read
Cisco Research survey examining PQC migration status across nine widely deployed protocols: TLS, IPsec, BGP, DNSSEC, SSH, QUIC, OpenID Connect, OpenVPN, and Signal Protocol. Analyses cryptographic foundations, quantum risks, and current state of PQC migration per protocol. Finds TLS and Signal lead with hybrid PQC key exchange deployed at scale; DNSSEC and BGP face structural barriers due to signature size constraints.
PDF · 603 KB · a long read
Google Quantum AI and Ethereum Foundation whitepaper providing new resource estimates for breaking secp256k1 (256-bit ECDLP) with Shor's algorithm — under 1,200 logical qubits and 90 million Toffoli gates. Introduces fast-clock vs slow-clock CRQC distinction and "on-spend" attack concept. Surveys cryptocurrency vulnerabilities including mempool exposure, reused addresses, and P2PK outputs. Recommends migration to PQC signatures for blockchain systems.
PDF · 1.7 MB · a reference document — dip in, don’t read it through
Demonstrates that Shor's algorithm for breaking RSA and ECC can be executed with as few as ~10,000 reconfigurable neutral atom qubits — an order of magnitude fewer than prior estimates. Substantially narrows the timeline for practical quantum attacks on current public-key infrastructure.
Web page · 44 KB · a short read
Specifies SLH-DSA in Merkle Tree Ladder mode for DNSSEC to mitigate the signature-size problem.
Web page · 68 KB · a short read
EJBCA/Keyfactor primer framing CPM as continuous visibility + automated policy enforcement across certs, keys, and libraries.
Web page · 85 KB · a short read
Quantum Insider survey of 25 companies shaping the quantum cryptography and communications market in 2026. Covers PQC software vendors, QKD hardware providers, crypto-agility platform companies, and quantum networking startups. Useful vendor landscape reference for procurement and market analysis.
Web page · 236 KB · a long read
Defines ML-DSA (FIPS 204) as a new algorithm for WebAuthn/FIDO2 authentication. Specifies COSE algorithm identifiers for ML-DSA variants for use in W3C Web Authentication credentials.
Web page · 44 KB · a short read
Mechanism for TLS 1.3 servers to predict which key share a client will offer, enabling zero-RTT PQC key exchange by avoiding HelloRetryRequest. Critical for ML-KEM deployment performance given large key sizes.
Web page · 15 KB · a quick skim
NIST CSWP 37A, published 16 March 2026: the September 2024 status report of the NCCoE project on automating the Cryptographic Module Validation Program.
PDF · 834 KB · a long read
Defines FN-DSA (FALCON) algorithm identifiers and serialization for JSON Object Signing and Encryption (JOSE) and CBOR Object Signing and Encryption (COSE).
Web page · 93 KB · a short read
Overview and change summary for the TCG TPM 2.0 Library V1.85 RC4 specification. Introduces PQC algorithm IDs (TPM_ALG_MLKEM=0x00A0; TPM_ALG_MLDSA=0x00A1) and explains the rationale for enlarging TPM_BUFFER_MAX from 4096 to 8192 bytes to accommodate ML-DSA-87 signatures.
PDF · 300 KB · a short read
Defines the TPM 2.0 architecture including the four-hierarchy model (Platform/Endorsement/Storage/Owner) and their handle values (TPM_RH_ENDORSEMENT=0x4000000B; TPM_RH_OWNER=0x40000001; TPM_RH_PLATFORM=0x4000000C). Specifies PQC key roles (EK; SRK; AIK; IDevID) and the impact of ML-KEM-768 and ML-DSA-65 adoption on attestation flows and TPM_BUFFER_MAX.
PDF · 3.3 MB · a reference document — dip in, don’t read it through
Normative structure definitions for TPM 2.0 V1.85. Assigns TPM_ALG_MLKEM=0x00A0 and TPM_ALG_MLDSA=0x00A1. Defines TPMT_ASYM_SCHEME for ML-KEM encapsulation and ML-DSA signing. Specifies key-size constants: ML-KEM-768 pk=1184B/ct=1088B; ML-DSA-65 pk=1952B/sig=3309B. Sets TPM_BUFFER_MAX=8192 and TPM2B_MAX_BUFFER size.
PDF · 875 KB · a long read
PUBLISHED TPM 2.0 Library v1.85 Part 3: Commands. Supersedes the December 2025 RC4. Defines ML-DSA, ML-KEM, Labeled KEM, EdDSA TPM commands.
Web page · 41 KB · a short read
Annual expert survey of 26 global quantum computing experts on CRQC probability and timeline. Published March 2026. 2025 survey shows significant acceleration: 28-49% probability within 10 years (up from 19-34% in 2024), 51-70% within 15 years. Majority now consider a CRQC likely by 2035. Authored by Dr. Michele Mosca and Dr. Marco Piani (evolutionQ Inc.), published by the Global Risk Institute.
PDF · 9.1 MB · a reference document — dip in, don’t read it through
Defines algorithm identifiers (OIDs) for ML-KEM-512, ML-KEM-768, and ML-KEM-1024 for use in X.509 certificates and CRLs. Direct complement to RFC 9881 (ML-DSA identifiers). Required for post-quantum PKI certificate issuance.
Web page · 694 KB · a long read
Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) is a quantum-resistant Key Encapsulation Mechanism (KEM). Three parameter sets for the ML-KEM algorithm are specified by the US National Institute of Standards and Technology (NIST) in FIPS 203. In order of increasing security strength (and decreasing performance), these parameter sets are ML-KEM-512, ML-KEM-768, and ML-KEM-1024. This do
Web page · 405 KB · a long read
Specifies KEM-based authentication for IKEv2 as more efficient alternative to ML-DSA.
Web page · 97 KB · a short read
Specifies X-Wing, a general-purpose hybrid KEM combining X25519 with ML-KEM-768. Unlike the TLS named groups it is not bound to a single protocol, which is why it appears in file/secrets encryption (age, SOPS) as well as on the wire. Fixes encapsulation key at 1216 bytes, ciphertext at 1120 and shared secret at 32.
Web page · 145 KB · a short read
NIST Cybersecurity White Paper (Initial Public Draft) covering the 5G Subscription Concealed Identifier (SUCI) mechanism per 3GPP TS 33.501. Describes how SUCI protects permanent subscriber identifiers (SUPIs/IMSIs) using public-key encryption (X25519 Profile A, P-256 Profile B) to prevent IMSI-catching attacks. Authored by NIST ITL, Scarfone Cybersecurity, and The MITRE Corporation.
PDF · 2.3 MB · a reference document — dip in, don’t read it through
Empirical analysis of HNDL attack economics across TLS 1.2, TLS 1.3, QUIC, and SSH. Quantifies adversarial storage cost feasibility; proposes aggressive rekeying and hybrid PQC as defences. References production deployments by Cloudflare, Apple PQ3, AWS, and Google Chrome. Companion paper to the open-source hndl-dev simulator.
Web page · 322 KB · a long read
Australian Cyber Security Centre primer on quantum technology for the communications sector. Covers quantum threats, PQC migration priorities, and guidance for Australian telecom operators.
Web page · 320 KB · a long read
Proposes using both a classical (ECDSA) and PQC (ML-DSA) signature in IKEv2 AUTH payload for defense-in-depth during the transition period.
Web page · 29 KB · a quick skim
Google/Chrome Root Program statement of the Web PKI post-quantum plan. Chrome has NO immediate plan to add PQC X.509 certificates to its root store; instead it is pursuing Merkle Tree Certificates in three phases — Phase 1 feasibility study with Cloudflare (underway), Phase 2 CT-log bootstrapping (Q1 2027), Phase 3 the Chrome Quantum-resistant Root Store alongside the existing one (Q3 2027).
Web page · 259 KB · a long read
Defines X.509 certificate extensions that allow a certificate authority or subscriber to embed a PQC Continuity commitment directly in a certificate. A relying party that encounters this extension knows the server is committed to PQC and can refuse future classical-only connections, extending the TLS-layer draft-sheffer-tls-pqc-continuity concept into the PKI certificate layer.
Web page · 66 KB · a short read
Best practices for implementing quantum-ready usage profiles in TLS-based applications.
Web page · 97 KB · a short read
Applies the same Residue Number System compression to the elliptic-curve discrete logarithm problem, reaching 3.12n + o(n) qubits — the most space-efficient polynomial-time ECDLP algorithm published. Estimates 1,193 logical qubits for a 256-bit curve at 2^38.98 Toffoli gates across 22 runs, against 2,043 for RSA-3072 at comparable classical security.
PDF · 503 KB · a long read
Specification of Post-Quantum and Hybrid KEMs for HPKE within JOSE and COSE, including algorithm identifiers and key formats.
Web page · 155 KB · a long read
India DST Task Force under National Quantum Mission publishes phased roadmap for PQC migration. CII foundations by 2027, high-priority systems by 2028, full CII by 2029, nationwide by 2033.
PDF · 2.0 MB · a reference document — dip in, don’t read it through
HKMA Fintech Promotion Blueprint launched February 2026. Includes Quantum Preparedness Index as flagship initiative for Hong Kong banking sector PQC readiness assessment and migration planning.
Web page · 82 KB · a short read
Hong Kong Monetary Authority Fintech 2030 blueprint — commits to PQC transition for the HK banking sector, launches Quantum Preparedness Index.
PDF · 4.5 MB · a reference document — dip in, don’t read it through
ANSSI technical fact sheet (ANSSI-FT-116, 16 pp) on the post-quantum transition of SSHv2. Recommends hybrid key exchange combining a classical scheme (X25519 / sntrup761) with ML-KEM to protect SSH sessions against Harvest-Now-Decrypt-Later, with concrete OpenSSH configuration guidance for developers, administrators, and CISOs. Translated from French.
PDF · 1.4 MB · a long read
ANSSI technical fact sheet (ANSSI-FT-115, 16 pp) on the post-quantum transition of TLS 1.3. Recommends hybrid key exchange (classical + ML-KEM) and addresses ML-DSA-based authentication, giving practical migration and configuration guidance for TLS 1.3 deployments. Translated from French.
PDF · 1.9 MB · a reference document — dip in, don’t read it through
ANSSI technical fact sheet (ANSSI-FT-117, 22 pp) on the post-quantum transition of IPsec. Recommends hybrid key exchange (classical + ML-KEM) within IKEv2 to protect VPN tunnels against the quantum threat, with configuration guidance for administrators. Translated from French.
PDF · 1.5 MB · a long read
Go library for BGV/BFV and CKKS with multiparty protocols: t-of-N threshold, refresh and key switching.
Web page · 213 KB · a long read
Introduction of the Pinnacle Architecture using quantum LDPC codes to reduce the physical qubit overhead for fault-tolerant quantum computation, demonstrating RSA-2048 factoring with fewer than 100,000 physical qubits.
PDF · 1.2 MB · a long read
5G security architecture updates incorporating PQC algorithms.
PDF · 4.3 MB · a reference document — dip in, don’t read it through
Updated framework incorporating NIST finalized ML-KEM standards and additional hybrid patterns.
PDF · 199 KB · a short read
DoD Security Requirements Guide for control systems and operational technology (OT), DISA-published.
PDF · 3.0 MB · a reference document — dip in, don’t read it through
Solana Improvement Document PR proposing a Falcon-512 (FN-DSA) signature verification syscall — verification only, does not replace Ed25519, framed by its own author as exploratory ('gauging interest before committing to a PQC strategy'). Retitled mid-review from a precompile to a syscall design. The author closed the PR on 2026-06-17 ('we are going to pause this effort ... closed for now, will reopen when there is more demand'), citing a separate SBF-native Falcon implementation (PR #563) as the more promising path. As of 2026-08-16 the PR remains closed/unmerged.
Web page · 585 KB · a long read
Defines id-alg-unsigned (1.3.6.1.5.5.7.6.36) for X.509 certificates that carry no signature: a zero-length signature BIT STRING and a placeholder issuer name (id-rdna-unsigned). Updates RFC 5280. Validators must never accept id-alg-unsigned as a signature in a certification path; the format serves trust anchors and keys that need no issuer signature. Published from draft-ietf-lamps-x509-alg-none.
Web page · 70 KB · a short read
TLS-specific PQC recommendations including hybrid key exchange. Version 2026-01.
PDF · 759 KB · a long read
IPsec/IKEv2-specific PQC recommendations. Version 2026-01.
PDF · 724 KB · a long read
SSH-specific PQC recommendations for secure remote access. Version 2026-01.
PDF · 639 KB · a long read
German federal recommendations including ML-KEM ML-DSA SLH-DSA XMSS LMS FrodoKEM Classic McEliece. Version 2026-01. Expanded PQC KEM and signature recommendations.
PDF · 568 KB · a long read
Migration guidance covering challenges, anti-patterns, and best practices for PQC transition.
Web page · 70 KB · a short read
G7 Cyber Expert Group publishes roadmap for financial sector PQC migration covering inventory, risk prioritization, algorithm selection (ML-KEM, ML-DSA), testing, and transition milestones for G7 financial institutions.
PDF · 385 KB · a short read
3GPP Technical Report 33.938 v19.2.0 (2026-01), the cryptographic inventory of 3GPP specifications: enumerates where RSA, ECDSA, ECDH and ECIES are used across the 3GPP protocol suite as the basis for transition planning. Note it names neither SUCI nor ML-KEM — the ML-KEM SUCI "Profile C" is one research paper's own proposal, not a 3GPP profile (3GPP defines Profiles A and B only).
PDF · 153 KB · a short read
Adds NIST P-384/P-521 and Brainpool384/512 hybrid combinations to the OpenPGP-PQC scheme.
Web page · 348 KB · a long read
Samsung System LSI and Thales bring ML-KEM quantum-resistant capabilities to embedded Secure Element (eSE). Two dedicated PQC hardware accelerators 18x faster than software. CES Best Cybersecurity Innovation Award winner. EAL6+ certification target. Crypto-agile architecture.
Web page · 418 KB · a long read
InfoSec Global positioning of CPM/crypto-agility as Gartner-recognized categories; useful market-landscape reference.
Web page · 94 KB · a short read
Europol, FS-ISAC, and QSFF joint guidance for financial institutions on prioritising PQC migration. Introduces a Quantum Risk Score framework covering shelf life of data, exposure, and severity. Provides migration complexity assessment and cryptographic antipattern identification for financial sector risk management.
Web page · 428 KB · a long read
Establishes the vocabulary and terminology for QKD standards ensuring consistency across all ETSI QKD specifications. Defines over 100 terms related to quantum key distribution systems.
PDF · 174 KB · a short read
Real-world scale performance benchmarking of PQC migration using VIAVI TeraVM Security Test on Dell R6625 hardware. Tests ML-KEM-768 hybrid (X25519Kyber768) against classical X25519 on HAProxy TLS and Strongswan IKEv2 VPN. Finds 32% throughput drop, 3500%+ latency increase (web pages 48x slower), and 75% reduction in VPN tunnel setup rate. Covers NGFWs enterprise impact and mitigation via hardware acceleration and TLS session resumption.
Web page · 66 KB · a short read
FS-ISAC PQC Working Group, QSFF, and CFDIR QRWG position paper on financial sector PQC migration timelines. Introduces Augmented Mosca's Theorem risk framework, 4-phase transition model, and cross-jurisdictional comparison of Australia, Canada, EU, US, UK NCSC, Bank of Israel, and MAS Singapore timelines.
Web page · 20 KB · a quick skim
Presents optimized quantum circuits for Shor’s algorithm to break prime elliptic curve cryptography, estimating the physical resources and time required for such attacks.
PDF · 1.3 MB · a long read
Analysis of cross-chain public key reuse between UTXO and account-based cryptocurrencies to improve entity clustering and privacy assessment.
PDF · 905 KB · a long read
Microchip Technology announces TS1800 and TS50x post-quantum-ready root-of-trust controller family. Hardware-embedded PQC at silicon level for IoT, automotive, and embedded systems. Supports ML-KEM and ML-DSA, enabling true crypto-agility in constrained devices.
Web page · 34 KB · a quick skim
Citi GPS research report quantifying the financial system quantum threat. Estimates 19-34% probability of cryptographically relevant quantum computer by 2034 (60-82% by 2044) and $2-3.3T GDP-at-risk from a single-day quantum attack on a top-5 US bank. Covers harvest-now/decrypt-later attacks, blockchain/Bitcoin quantum exposure (~25% of bitcoin), PQC migration urgency, regulatory landscape, and recommended migration sequencing for financial institutions.
Web page · 1.6 MB · a long read
The FRMCS transport stratum specification.
PDF · 657 KB · a long read
The FRMCS service stratum specification.
PDF · 419 KB · a long read
The FRMCS on-network interworking specification.
PDF · 203 KB · a short read
PDF · 5.7 MB · a reference document — dip in, don’t read it through
Web page · 168 KB · a long read
Web page · 104 KB · a short read
Web page · 60 KB · a short read
Web page · 562 KB · a long read
Web page · 262 KB · a long read
PDF · 2.7 MB · a reference document — dip in, don’t read it through
Web page · 231 KB · a long read
Web page · 43 KB · a short read
Web page · 424 KB · a long read
PDF · 1.9 MB · a reference document — dip in, don’t read it through
PDF · 252 KB · a short read
TSA Security Directive Pipeline-2021-02G (effective May 3, 2026 to May 2, 2027) renews, without substantive change, mandatory cybersecurity measures for TSA-designated critical hazardous liquid, natural gas and LNG pipeline owner/operators: an approved Cybersecurity Implementation Plan, incident response plan, assessment program, network segmentation, access control/MFA and encryption of data in transit. Not PQC-specific; relevant to PQC migration as a binding US OT encryption and authentication mandate whose cryptography will need quantum-safe replacement.
PDF · 372 KB · a short read
Peer-reviewed analysis estimating enterprise PQC migration timelines by organization size - 5-7 years (small), 8-12 (medium), 12-15+ (large) - against a fault-tolerant quantum window of 2028-2033. Frames the cost and effort drivers: cryptographic inventory discovery, HSM and hardware refresh, hybrid-crypto operations, personnel scarcity, and inter-enterprise synchronization.
PDF · 435 KB · a long read
Strategies and practices for cryptographic agility — the ability to replace and adapt cryptographic algorithms in protocols, applications, and infrastructure without disruption. Essential companion to the PQC transition.
PDF · 1.1 MB · a long read
The certificate policy governing the US Federal PKI Common Policy Framework — the rules every federal CA operates under.
PDF · 958 KB · a long read
Security IC Platform Protection Profile including Functional Packages, Version 2.0 (16 December 2025), certified by BSI as BSI-CC-PP-0084-V2-2026.
PDF · 1.7 MB · a reference document — dip in, don’t read it through
Commission Implementing Regulation (EU) 2025/2462 of 8 December 2025, amending the EUCC scheme regulation (EU) 2024/482 on definitions, ICT product series certification, assurance continuity and state-of-the-art documents.
Web page · 259 KB · a long read
Major revision of NIST key management guidelines. Adds PQC security categories and quantum-resistant algorithms (FIPS 203/204/205), Ascon (SP 800-232), separates key establishment and key storage discussion, and replaces time-based algorithm approval status. Comment period closed Feb 2026.
PDF · 2.6 MB · a reference document — dip in, don’t read it through
Updated product category list per Executive Order 14306. Identifies cloud services web software networking hardware endpoint security as PQC-ready categories. Developed with NSA. Products must support PQC for key establishment and digital signatures.
Web page · 73 KB · a short read
Defines X.509 algorithm identifiers and parameter conventions for all 12 SLH-DSA parameter sets (FIPS 205 / SPHINCS+). Specifies absent-parameters rule and self-signed certificate requirements for hash-based PQC PKI. Companion to RFC 9881 (ML-DSA in X.509).
Web page · 156 KB · a long read
Adds a Discouraged designation to TLS/DTLS IANA registries to flag weak or deprecated cryptographic mechanisms while maintaining backward compatibility.
Web page · 100 KB · a short read
UK DSIT publishes perspectives report from critical national infrastructure (CNI) sector leads on PQC transition planning. Identifies sector-specific challenges across energy, transport, finance, and telecoms.
PDF · 2.3 MB · a reference document — dip in, don’t read it through
Cambridge Judge Business School / CCAF analysis by Philippa Coney on quantum computing threats to blockchain. Covers quantum-resilient cryptography for distributed ledgers, blockchain upgrade pathways, digital asset security, and the role of regulators in the quantum transition.
Web page · 211 KB · a long read
Experimental Rust library for Ring-LWE-based homomorphic encryption, implementing an RNS variant of the BFV scheme.
Web page · 34 KB · a quick skim
DoD CIO directive requiring all Pentagon components to inventory cryptography across all information systems. Establishes two-gate PQC approval process (intake + deployment). Sets Dec 2030 deadline for PSK replacement. Bans QKD on DoD networks.
PDF · 823 KB · a long read
IETF RFC defining SD-JWT (Selective Disclosure for JWTs) — the base selective-disclosure mechanism for JWTs using salted hashes. SD-JWT VC (verifiable credentials) is a SEPARATE IETF draft (draft-ietf-oauth-sd-jwt-vc) built on this spec and adopted by the EUDI Wallet ARF for online attestations. Text-based JSON encoding optimised for remote online services.
Web page · 2.0 MB · a long read
Latest liboqs release with updated PQC algorithm implementations including NIST-standardized ML-KEM ML-DSA and SLH-DSA. Part of Linux Foundation PQCA.
Web page · 21 KB · a quick skim
Practical roadmap for organizations to assess plan and mitigate quantum computing risks. Covers NIST FIPS 203/204/205 standards and hybrid key exchange protocols.
Web page · 98 KB · a short read
Report on the Helios 98-qubit trapped-ion quantum computer architecture, performance metrics, and operational advances by Quantinuum.
PDF · 4.0 MB · a reference document — dip in, don’t read it through
World's largest PQC conference (2500+ delegates, 30+ countries) concluded in Kuala Lumpur. Issued urgent call for global migration. Includes Malaysia national PQC plan announcement.
Web page · 80 KB · a short read
NACSA's action plan operationalising Malaysia's National Cryptography Policy (MyKriptografi) into an implementation roadmap. Built on four core pillars comprising 12 strategies, 32 programmes and 80 activities across Government, National Critical Information Infrastructure (NCII), industry, academia and the wider digital economy, and named as preparing Malaysia for "the quantum computing era". The page does not publish algorithm-level requirements or a dated PQC migration timetable.
Web page · 10 KB · a quick skim
Introduces Silithium — a fused hybrid signature combining EC-Schnorr (secp256k1) and ML-DSA-65 via an adapted Fiat-Shamir transform. Achieves Strong Non-Separability (SNS) with smaller signatures than concatenation. Defines Hybrid EU-CMA security notion covering separability, recombination, and cross-protocol attacks.
Web page · 16 KB · a quick skim
New Zealand GCSB NZISM v3.9 mandatory and recommended security controls for NZ government information systems. Cryptography chapter specifies approved algorithms, key management, PKI, and TLS requirements with PQC transition guidance.
PDF · 5.8 MB · a reference document — dip in, don’t read it through
Extends RFC 8784 PSK mixing into IKE_INTERMEDIATE and CREATE_CHILD_SA so rekeying preserves PQ protection.
Web page · 108 KB · a short read
Japan’s interim government position on PQC migration for public institutions.
PDF · 231 KB · a short read
The FRMCS system architecture replacing GSM-R for European rail — new infrastructure whose cryptography is being chosen now.
PDF · 766 KB · a long read
Operational guide to ACME/EST/CMP automation under the CA/B Forum 47-day cadence landing March 2029.
Web page · 120 KB · a short read
Defines ML-DSA (Dilithium) usage in CMS for document and message signing.
Web page · 121 KB · a short read
Cloudflare blog post explaining the Merkle Tree Certificate proposal, its motivation (PQC certificate bloat), architecture (MTCA, transparency service, subscribers), and experimental deployment results. Includes size comparison data.
Web page · 538 KB · a long read
Cloudflare's annual review of PQC adoption across the Internet, covering ML-KEM deployment in TLS 1.3, browser support (Chrome, Firefox), certificate transparency challenges, and the MTC proposal as a solution to PQ certificate bloat.
Web page · 604 KB · a long read
Open-access Springer volume (Mathematics for Industry 40) from the Crypto-Math CREST project. Covers mathematical foundations underlying NIST PQC standards: lattice theory (LWE, MLWE, NTRU, Module-LWE), code-based cryptography, hash-based signatures, isogeny-based cryptography, and multivariate schemes. Edited by leading Japanese cryptographers (Takagi, Wakayama, Kunihiro, Tanaka, Kimoto, Kudo). ISBN eBook 978-981-96-1218-5. CC BY 4.0.
Web page · 312 KB · a long read
Standalone, machine-readable naming registry introduced in CycloneDX v1.7: 96 cryptographic algorithm families (RSA, ECDSA, EdDSA, AES, ChaCha20, SHA-2/3, HKDF, ML-KEM, ML-DSA, SLH-DSA, XMSS, LMS, and more) across 14 primitive types, plus 246 elliptic curves across 15 standardization categories (NIST, Brainpool, SECG, BLS, GOST, etc). Published as versioned JSON + JSON Schema, usable independently of CycloneDX/CBOM tooling for any framework needing consistent crypto-mechanism naming.
Web page · 202 KB · a long read
OWASP CycloneDX general Bill of Materials specification, standardized as ECMA-424 — covers SBOM, SaaSBOM, HBOM, ML-BOM, VDR/VEX and CBOM as sibling BOM types sharing one object model. This is the general-BOM spec entry point; the crypto-specific CBOM capability guide is tracked separately (see OWASP-CycloneDX-CBOM-Guide).
Web page · 37 KB · a quick skim
A survey paper covering post-quantum cryptography and quantum-safe security as a combined field.
Web page · 43 KB · a short read
Treasury Board of Canada Secretariat (TBS) Security Policy Implementation Notice (SPIN 2025-01) directing all federal departments to begin PQC migration planning. Establishes inventory requirements and migration timelines for Government of Canada IT systems.
Web page · 37 KB · a quick skim
IBM Institute for Business Value report on enterprise quantum-safe readiness; organizational maturity model and investment sequencing.
Web page · 582 KB · a long read
Adds SHA-256/192, SHAKE256/256, and SHAKE256/192 parameter sets for LMS/HSS, reducing signature sizes by 35-40% compared to the original RFC 8554 SHA-256 parameter sets.
Web page · 117 KB · a short read
Defines X.509 OIDs and certificate structures for ML-DSA (Dilithium) signatures. Supersedes draft-ietf-lamps-dilithium-certificates.
Web page · 296 KB · a long read
ANSSI frequently asked questions on post-quantum cryptography covering algorithm selection, hybrid approaches, migration timelines, and practical guidance for French organizations. Updated October 2025.
Web page · 63 KB · a short read
Annual ENISA threat landscape report analyzing 4,875 incidents from July 2024 to June 2025; identifies quantum computing as a strategic long-term threat requiring proactive PQC transition planning.
PDF · 4.5 MB · a reference document — dip in, don’t read it through
Implementation study on FrodoKEM side-channel countermeasures. Analyzes power-analysis and template attacks on the discrete Gaussian sampler; proposes isochronous sampling and masking. Includes fault-injection countermeasures with sampling calibration.
PDF · 1.5 MB · a reference document — dip in, don’t read it through
UK Labour Tech policy report on defence sovereignty covering quantum commercialisation, PQC adoption pathways, quantum sensing/PNT, and the strategic case for UK sovereign quantum capability. Includes Steven Vaile chapter on quantum cybersecurity procurement reform (pp.22-23).
PDF · 1.5 MB · a reference document — dip in, don’t read it through
Invited talk slides by Bas Westerbaan (Cloudflare Research) at PQCrypto 2025. Covers the state of PQC deployment on the internet: ML-KEM adoption in TLS, maximum compatibility mode and its limits, quantum downgrade attacks (active MITM suppressing PQC negotiation), PQ Lock/PQC HSTS, PQC Continuity (draft-sheffer-tls-pqc-continuity), and Merkle Tree Certificates as a downgrade detection layer via public issuance logs.
PDF · 2.0 MB · a reference document — dip in, don’t read it through
The Global Financial Markets Association’s survey of the quantum migration landscape for financial institutions.
PDF · 1.7 MB · a reference document — dip in, don’t read it through
IETF Standards Track RFC that defines fully-specified JOSE and COSE algorithm identifiers (fixing curve, KDF and hash) and deprecates the polymorphic identifiers in RFCs 8037 and 9053, e.g. replacing EdDSA with Ed25519/Ed448. The document itself does not mention PQC; it matters for PQC migration because it sets the rule that new JOSE/COSE algorithm registrations name one fully-specified algorithm.
Web page · 124 KB · a short read
Federal Reserve FEDS Working Paper (2025-093) analysing HNFL risks for blockchain networks. Examines how quantum computers could retroactively compromise immutable on-chain transaction data across Bitcoin, Ethereum, and distributed ledger systems.
PDF · 398 KB · a short read
MAS and industry partners (DBS, HSBC, OCBC, UOB) technical report on QKD proof-of-concept sandbox (Sept 2024-March 2025). Reports 6.75M AES-256 keys/day per bank, demonstrating feasibility of quantum-safe key distribution in financial settlement systems.
Web page · 254 KB · a long read
NIST standard specifying constructions for Random Bit Generators (RBGs) that combine entropy sources with DRBGs. Defines RBG1, RBG2, RBG3, and RBGC classes for defense-in-depth randomness.
PDF · 10.1 MB · a reference document — dip in, don’t read it through
MPC-in-the-Head signature whose security rests on solving random multivariate quadratic (MQ) systems over finite fields. Best combined public-key-plus-signature sizes across all three NIST levels among MPCitH candidates, with competitive signing and verification speeds. NIST IR 8528 explicitly flagged that ROM and QROM security proofs still need further maturation.
PDF · 708 KB · a long read
Guidance for implementing KEMs securely including hybrid KEMs and FIPS 140 validation requirements.
PDF · 903 KB · a long read
Maps NCCoE PQC Migration project capabilities to NIST Cybersecurity Framework 2.0 (CSF 2.0) and SP 800-53 security controls, helping organizations align PQC migration efforts with established risk management frameworks and identify controls needed for successful PQC migration.
PDF · 593 KB · a long read
OpenID Foundation specification defining how credential issuers expose APIs for digital credential issuance. Specifies credential offer flow pre-authorisation code flow authorisation code flow and credential endpoint. Defines proof of possession using key binding JWTs. Mandatory protocol for all EUDI Wallet credential issuers (PID providers attestation issuers).
Web page · 504 KB · a long read
Demonstrates Rowhammer-based universal signature forgery on SLH-DSA. Induces DRAM bit flips during signature generation to produce valid signatures without knowledge of the private key. Emphasizes Rowhammer as a persistent remotely triggerable threat.
Web page · 44 KB · a short read
Guidelines for establishing a media sanitization program to ensure the confidentiality of information on storage media through clear, purge, and destroy methods.
PDF · 984 KB · a long read
Analysis of 10,402 real cyber-insurance claims from incidents in 2020-2024, split into SMEs (under $2B revenue) and large companies. Figures 9 and 10 give the five-year average total incident cost per tier ($264K and $10.3M), the source of the organization-size cost anchors in roiBaselines.ts.
PDF · 9.5 MB · a reference document — dip in, don’t read it through
PCI Perspectives blog post of 26 August 2025 announcing new PCI SSC guidance on authentication and cryptography.
Web page · 87 KB · a short read
Code-based KEM selected March 2025 as backup to ML-KEM. Draft FIPS expected 2026, final 2027.
PDF · 876 KB · a long read
Sectigo annual benchmark of crypto-agility and CLM automation maturity across 500+ enterprises.
Web page · 588 KB · a long read
NIST lightweight cryptography standard based on the Ascon algorithm family. Specifies Ascon-AEAD128 (authenticated encryption), Ascon-Hash256 (hash), and Ascon-XOF128/CXOF128 (extendable output functions) for constrained IoT and embedded devices.
PDF · 1.2 MB · a long read
CISA/NSA joint guidance on building an OT asset inventory and taxonomy for critical infrastructure operators.
PDF · 1.0 MB · a long read
ASC X9 report providing guidance on safely and cost-effectively migrating the financial services industry to post-quantum cryptography. Covers readiness needs assessment, migration priorities, risk frameworks, and practical implementation recommendations for financial institutions transitioning to NIST PQC standards.
PDF · 119 KB · a short read
Keyfactor framing of CBOM as a foundation for modern cryptographic management.
Web page · 140 KB · a short read
The current (pre-PQC) profile for US Federal PKI certificates and CRLs.
PDF · 573 KB · a long read
Empirical performance benchmarks comparing CRYSTALS-Kyber (ML-KEM) against RSA and ECC for key generation, encapsulation, and storage. Provides quantitative evidence that Kyber achieves faster operations and smaller key sizes than RSA while being quantum-resistant.
Web page · 43 KB · a short read
Commission Implementing Regulation (EU) 2025/1567 of 29 July 2025, under eIDAS (Regulation (EU) No 910/2014), on managing remote qualified signature and seal creation devices as qualified trust services.
Web page · 31 KB · a quick skim
Commission Implementing Regulation (EU) 2025/1570 of 29 July 2025, under eIDAS, on notifying information about certified qualified signature and seal creation devices.
Web page · 29 KB · a quick skim
This document describes how to use the ML-DSA post-quantum signature algorithm for authentication within IKEv2 as a replacement for traditional algorithms.
Web page · 61 KB · a short read
Defines SPHINCS+ (SLH-DSA), the stateless hash-based signature standard, usage in Cryptographic Message Syntax. Included for comparison with stateful LMS/XMSS schemes.
Web page · 85 KB · a short read
Peer-reviewed proposal for a post-quantum SUCI protection scheme. Defines a "Profile C" (identifier 0x3) using ML-KEM/Kyber-512 alongside the 3GPP-defined Profiles A and B. RESEARCH PROPOSAL, not a 3GPP-standardised profile — the authors state Profiles A and B are defined by 3GPP and that Profile C is their own scheme.
PDF · 447 KB · a long read
OpenID Foundation specification defining how holders present verifiable credentials to relying parties. Specifies the authorization request presentation definition (DIF PE) and presentation submission. Enables selective disclosure presentations where holders reveal only the credential attributes required by the relying party. Mandatory for EUDI Wallet credential presentation flows.
Web page · 515 KB · a long read
Enables ML-DSA post-quantum digital signatures in S/MIME certificates. IPR Exclusion period completed with no notices filed. Adopted August 22 2025.
Web page · 24 KB · a quick skim
Adds KEM key transport to CMP. Obsoletes RFC 4210.
Web page · 583 KB · a long read
NIST framework for digital identity management. SP 800-63A covers identity proofing and enrollment (Identity Assurance Levels IAL1/2/3). SP 800-63B covers authentication (Authenticator Assurance Levels AAL1/2/3). SP 800-63C covers federation (Federation Assurance Levels FAL1/2/3). Referenced in EUDI Wallet implementations for IAL/AAL equivalency mapping with European LoA (Low Substantial High).
PDF · 858 KB · a long read
Bank for International Settlements paper outlining quantum-readiness roadmap for global financial systems. Covers cryptographic inventory, migration timelines, and cross-border interoperability for central banks.
PDF · 2.2 MB · a reference document — dip in, don’t read it through
CMP profile for HSM-based certificate lifecycle management; enables PQC key generation and ML-DSA certificate enrollment directly from PKCS#11-compliant HSMs.
Web page · 78 KB · a short read
Hong Kong Legislative Council enacts critical infrastructure cybersecurity legislation requiring operators to protect computer systems including cryptographic controls relevant to PQC migration.
Web page · 13 KB · a quick skim
Web page · 42 KB · a short read
Defines a taxonomy for hybrid digital signature schemes combining classical and PQC algorithms; informs IETF composite signature standards.
Web page · 75 KB · a short read
ASC X9 Financial PKI launched June 2025 (key ceremony June 13). Industry-specific PKI infrastructure for financial services built with DigiCert as managed provider. Supports both legacy algorithms for backward compatibility and post-quantum cryptography (ML-KEM, ML-DSA) for next-generation algorithm transition. Purpose-built for payment terminal interoperability, cross-enterprise authentication, and secure device communication.
Web page · 119 KB · a short read
APRA Prudential Standard CPS 234 mandates that all APRA-regulated entities (banks, insurers, superannuation funds) maintain information security capabilities commensurate with threats. Requires board accountability, policy frameworks, and cryptographic controls for sensitive data. PQC transition is in scope as a material vulnerability in long-lived cryptographic infrastructure.
Web page · 1.0 MB · a long read
Trump administration EO directing DHS/CISA to publish PQC product categories. Requires TLS 1.3 adoption by 2030. Amends EO 13694 and EO 14144. Retains PQC migration provisions from Biden era.
Web page · 321 KB · a long read
Joint industry whitepaper from HSBC, InfoSec Global (Keyfactor), and Thales covering Ten Strategic Principles for cryptographic inventory. Presents the business case for proactive cryptographic discovery, CBOM generation methodology, crypto agility frameworks, and enterprise case studies for PQC migration readiness planning.
PDF · 15.4 MB · a reference document — dip in, don’t read it through
Defines terminology for PQ/T hybrid schemes including composite KEMs and signatures.
Web page · 98 KB · a short read
Defines OIDs and certificate structures for stateful hash-based signatures in X.509.
Web page · 148 KB · a short read
Defines a CSR attribute (relatedCertRequest) and X.509 extension (RelatedCertificate) that bind two certificates to the same end entity. Enables non-composite hybrid authentication using separate traditional and PQC certificates (the catalyst approach). Published as RFC 9763.
Web page · 80 KB · a short read
GSA Federal Acquisition Service guide for federal agencies procuring PQC-capable products. Covers PQC planning and implementation use cases, Quantum Security-as-a-Service (QSaaS), Quantum SD-WAN, and PQC + Zero Trust Architecture integration.
PDF · 5.4 MB · a reference document — dip in, don’t read it through
US government adoption requirements for ML-KEM-1024, ML-DSA-87, SLH-DSA, LMS/XMSS. Level 5 recommended.
PDF · 587 KB · a long read
The W3C data model for verifiable credentials. Its signature suites are where post-quantum algorithms have to land for digital identity.
Web page · 1.0 MB · a long read
Dubai Electronic Security Center (DESC) launches PQC guideline at GISEC Global 2025 to prepare Dubai digital infrastructure for quantum threats. Migration framework for Dubai government and private sector.
Web page · 235 KB · a long read
The US health-IT certification criterion for end-user device encryption.
Web page · 409 KB · a long read
The US health-IT certification criterion for data integrity, which is where signature algorithms are pinned.
Web page · 393 KB · a long read
The US health-IT certification criterion for trusted connections — the TLS requirements certified health software must meet.
Web page · 396 KB · a long read
Includes PQC algorithms in Agreed Cryptographic Mechanisms for EUCC certification.
PDF · 407 KB · a long read
PQCC publishes PQC Migration Roadmap with four-category framework: Preparation, Prioritization, Migration, and Sustainment. Practical guidance for organizations at any stage of PQC transition.
PDF · 750 KB · a long read
Estimation of the physical qubit and time costs required to factor 2048-bit RSA integers using noisy quantum computers.
PDF · 4.2 MB · a reference document — dip in, don’t read it through
PDF · 187 KB · a short read
OpenSSL 3.5.0 (April 29, 2025) is the first version to include ML-KEM (FIPS 203), ML-DSA (FIPS 204), SLH-DSA (FIPS 205), and X25519MLKEM768 hybrid TLS natively, without the OQS provider. This is the foundational library release enabling mainstream PQC adoption across TLS stacks, VPNs, and cryptographic applications worldwide.
Web page · 49 KB · a short read
Companion guidance to PKCS#11 v3.2 and a normative reference of it. v3.2 moved the session-state model, the user/login model and the object-access matrix out of the base specification and into this document — the spec says only that CK_STATE holds the session state 'as described in [PKCS11-UG]'. Auditing session, login or private-object access behaviour against the base specification alone will therefore find no governing text. Note the process asymmetry: this is a non-standards-track Committee Note that the Standard nevertheless cites normatively. Edited by Dieter Bong (Utimaco); supersedes the v2.40 Usage Guide.
PDF · 468 KB · a long read
CA/Browser Forum Ballot SC-081v3 establishing requirements for post-quantum key exchange in TLS certificates issued by publicly trusted CAs. Affects all Web PKI certificate issuers.
Web page · 35 KB · a quick skim
PQCC publishes structured workbook to assist organizations in creating centralized cryptographic inventories for PQC migration planning. Covers asset identification, risk prioritization, and migration scheduling.
Web page · 88 KB · a short read
ETSI standard defining policy and security requirements for Qualified Trust Service Providers (QTSPs) issuing qualified certificates under eIDAS. Forms the basis for European CA auditing under WebTrust/ETSI audit schemes and the EUDI Trust Framework for credential issuer accreditation. Part 1 covers general requirements; Part 2 covers NCP/NCP+/QCP/eIDAS policies.
PDF · 362 KB · a short read
UK Cross Market Operational Resilience Group (CMORG) publishes PQC guidance for UK financial sector. Covers threat landscape, algorithm selection, migration planning, and prioritization for UK banks and financial market infrastructures.
PDF · 277 KB · a short read
ETSI announcement of its quantum-safe hybrid key-exchange standard — useful as a dated marker of when the specification became citable.
Web page · 137 KB · a short read
Forrester Principal Analyst Sandy Carielli on why crypto-agility and posture management investments are justified on operational merit alone.
Web page · 654 KB · a long read
UK NCSC three-phase PQC migration timeline guidance. Phase 1 (by 2028): discovery and planning; Phase 2 (2028-2031): active migration of priority systems; Phase 3 (by 2035): complete PQC migration. Includes sector-specific guidance for UK government and CNI.
PDF · 202 KB · a short read
Proposed TLS Certificate Compression scheme using a shared dictionary of root and intermediate WebPKI certificates. Streamlines transition toward post-quantum cryptography by removing root and intermediate certificates from the TLS certificate chain while preserving trust verification. Reportedly provides superior compression vs competing approaches. Cited by PQCC April 2026 transport-issues panel as mitigation for TCP Initial Congestion Window and QUIC amplification protection.
Web page · 50 KB · a short read
Web page · 41 KB · a short read
Web page · 41 KB · a short read
Documents HQC selection as fourth PQC standard providing code-based cryptographic diversity.
Web page · 50 KB · a short read
GSMA survey of post-quantum cryptography government initiatives across countries and regions as of March 2025. Covers national PQC programs, regulatory developments, and migration timelines for 30+ countries.
PDF · 207 KB · a short read
Framework for hybrid ECDH + ML-KEM with standard key combiners (concatenation, HKDF).
PDF · 252 KB · a short read
Japanese government evaluation of PQC algorithms covering ML-KEM/DSA/SLH-DSA/FN-DSA/HQC with security analysis and migration guidance based on Mosca's inequality framework.
PDF · 1.3 MB · a long read
MPC-in-the-Head signature built on the syndrome decoding problem for random linear codes over finite fields — one of the most-studied hard problems in code-based cryptography, dating to McEliece (1978). Among the MPCitH candidates, only FAEST (AES-based) shares a comparably well-analysed security foundation. Tradeoff: typically slower than its MPCitH peers, though sizes are competitive when tuned.
PDF · 576 KB · a long read
Original UOV construction by Kipnis-Patarin-Goubin (1999). Public key is a system of multivariate quadratic polynomials with the secret oil/vinegar partition hidden inside. Tiny 96 B signatures at NIST L1; large public key (~66 KB raw, ~1.2 KB compressed) and private key (~237 KB). 2025 Ran wedge attack pushed three of four parameter sets (uov-Ip, uov-III, uov-V) below their security targets; reparameterisation in odd-characteristic fields restores security.
PDF · 742 KB · a long read
Lattice signature that eliminates FN-DSA's floating-point Gaussian-sampling pain — pure integer arithmetic on a rank-2 module lattice with a Gram matrix as the public key. Compact 555 B signatures at NIST L1 — smaller than both ML-DSA and FN-DSA — and dramatically easier to implement in constant time on constrained hardware. Security rests on newer assumptions: the Search Module Lattice Isomorphism Problem (smLIP) and the One-More-Shortest-Vector Problem (omSVP). NIST flagged these for further community analysis; Round 2 included a refined omSVP definition addressing a discrepancy found during evaluation.
PDF · 1.1 MB · a long read
Technical architecture and reference framework for the European Digital Identity Wallet. Defines credential formats (mso_mdoc per ISO 18013-5 and SD-JWT VC (draft-ietf-oauth-sd-jwt-vc)) trust framework protocol requirements (OpenID4VCI OpenID4VP) and cryptographic security requirements. Specifies no PQC migration roadmap — the Dec 2026/2030/2035 transition dates come from the NIS Cooperation Group Coordinated Implementation Roadmap (June 2025), not from the ARF.
Web page · 417 KB · a long read
Defines KEMAC (Key Encapsulation Mechanism with Access Control) scheme called Covercrypt. Provides pre- and post-quantum security through hybridization with precise data access control. Encapsulation and decapsulation in hundreds of microseconds.
PDF · 258 KB · a short read
Defines RSA-KEM usage in CMS EnvelopedData using KEMRecipientInfo. Obsoletes RFC 5990. Supports hybrid RSA+ML-KEM migration scenarios for S/MIME.
Web page · 143 KB · a short read
Czech NUKIB publishes minimum requirements for cryptographic algorithms including PQC readiness guidance. Sets 2027 deadline for key establishment migration and recommends hybrid PQC approaches for Czech government systems.
PDF · 382 KB · a short read
Industry white paper examining post-quantum cryptography impacts on 5G and telecommunications network security. Covers PQC algorithm readiness, protocol migration for 5G NR and core network, and vendor ecosystem status.
PDF · 6.8 MB · a reference document — dip in, don’t read it through
PDF · 844 KB · a long read
ATIS analysis of where post-quantum algorithms have to land in 3GPP 5G architecture, and what each insertion point costs.
PDF · 3.8 MB · a reference document — dip in, don’t read it through
SMAUG-T is a post-quantum KEM selected as a South Korean national PQC standard by KpqC in January 2025. Based on Module-LWE and Module-LWR assumptions. The “T” (Twisted) refers to a key derivation tweak improving security margins. Developed by CryptoLab Inc.
PDF · 584 KB · a long read
AIMer is a post-quantum signature scheme selected as a South Korean national PQC standard by KpqC in January 2025. Based on the MPC-in-the-head (MPCitH) paradigm using the AIM one-way function. Offers competitive signature sizes without lattice assumptions, providing security diversity.
PDF · 737 KB · a long read
HAETAE is a lattice-based digital signature scheme selected as a South Korean national PQC standard by KpqC in January 2025. Developed by CryptoLab Inc. Uses a Fiat-Shamir with Aborts variant over module lattices, offering efficient signatures competitive with ML-DSA.
Web page · 169 KB · a long read
Master's thesis from Radboud University providing a practical implementation and performance analysis of Merkle Tree Certificates in TLS 1.3. Evaluates tree construction, proof generation, and handshake overhead with ML-DSA.
PDF · 962 KB · a long read
This specification defines a JSON Web Token (JWT) response format for OAuth 2.0 Token Introspection to provide stronger assurance and cryptographic security for token state verification.
Web page · 384 KB · a long read
Most aggressive size optimisation in the multivariate family: combines a MAYO-like whipping structure with a noncommutative block-ring structure. SNOVA l=4 at NIST L1: pk=1,016 B, sk=48 B, sig=248 B. Hit hardest by the 2025 wedge attack — most original parameter sets broken, sometimes by a wide margin. Odd-characteristic reparameterisation proposed; resulting Category-1 sizes are smaller than FN-DSA. NIST IR 8528 notes SNOVA has 'not reached a stable form'.
PDF · 506 KB · a long read
DoD crosswalk mapping CMMC practices to their source NIST SP 800-171 / 800-172 requirements.
PDF · 429 KB · a long read
DoD guidance on Supplier Performance Risk System (SPRS) scoring in relation to CMMC assessment levels.
PDF · 521 KB · a long read
Biden administration executive order on cybersecurity including PQC provisions. Mandates PQC-ready systems for federal agencies and sets security standards for critical infrastructure.
Web page · 146 KB · a short read
Updated voluntary CISA/FBI guidance for software manufacturers. Bad Practice #7 (Cryptographic Weaknesses) explicitly recommends manufacturers begin supporting standardized PQC algorithms consistent with NIST guidance and avoid deprecated algorithms.
Web page · 89 KB · a short read
Korea selects HAETAE and AIMer (signatures) plus SMAUG-T and NTRU+ (KEMs) as national PQC standards. Target standardization by 2029 migration by 2035.
Web page · 13 KB · a quick skim
Updated HSS/LMS usage in CMS. Obsoletes RFC 8708.
Web page · 86 KB · a short read
EU NIS Cooperation Group coordinated roadmap v1.1 for PQC transition across EU member states. Provides harmonized timelines, priority sectors, and cross-border coordination mechanisms.
PDF · 553 KB · a long read
India CERT-In v2.0 guidelines on software, quantum, cryptographic, AI, and hardware bills of materials. Includes CBOM and QBOM specifications for cryptographic inventory and quantum-readiness assessment of Indian organizations.
PDF · 1.7 MB · a reference document — dip in, don’t read it through
Europol Quantum Safe Financial Forum call to action for European financial institutions to begin immediate PQC migration planning. Addresses harvest-now-decrypt-later threats to financial data and recommends coordinated sector response.
Web page · 98 KB · a short read
Telecommunications Engineering Centre (TEC) India technical report on migrating to post-quantum cryptography. Covers algorithm selection (ML-KEM, ML-DSA, SLH-DSA), hybrid approaches, protocol migration for Indian telecom, and implementation guidance for operators.
PDF · 1.8 MB · a reference document — dip in, don’t read it through
Updated analysis of quantum computing impact specifically on symmetric cryptography including block ciphers, stream ciphers, hash functions, and MACs. Successor to GR QSC 006.
PDF · 350 KB · a short read
JPMorgan Chase presentation at Real World PQC 2025 conference on financial sector PQC migration challenges and strategies.
PDF · 2.3 MB · a reference document — dip in, don’t read it through
Presentation by Tjerand Silde (NTNU / PONE Biometrics) on quantum-safe cryptography challenges including FIDO, secure authentication, and SNDL threats.
PDF · 6.0 MB · a reference document — dip in, don’t read it through
PROACT 2025 slides on side-channel and fault-injection attacks on ML-KEM and ML-DSA lattice implementations. Demonstrates single-trace key recovery on unmasked implementations and effectiveness against masked and shuffled countermeasures.
PDF · 5.6 MB · a reference document — dip in, don’t read it through
Overview of nonce reuse vulnerabilities in cryptographic protocols. Weak PRNGs and protocol misconfigurations cause repeated nonces enabling key recovery and forgery attacks across PQC and classical schemes.
Web page · 224 KB · a long read
Analysis of cryptographic failures in the OWASP Top 10. Real-world vulnerabilities from misconfigurations, weak key management, and insecure protocol usage rather than algorithmic weaknesses.
Web page · 139 KB · a short read
Analysis of technical and economic challenges in migrating modern blockchains to Post-Quantum Cryptography.
PDF · 395 KB · a short read
Argues that pay-to-pubkey-hash outputs can remain quantum secure despite mempool exposure, provided spending after reveal is restricted to a quantum-resistant signature scheme.
Web page · 8 KB · a quick skim
Introduction of hash-based non-interactive multi-signature schemes based on XMSS variants for Ethereum’s proof-of-stake consensus.
Web page · 18 KB · a quick skim
US Treasury sector risk management plan for financial services covering quantum computing as an emerging technology risk. Identifies PQC migration as a priority resilience initiative and outlines coordinated government-industry response.
PDF · 3.1 MB · a reference document — dip in, don’t read it through
The mandatory security controls every Swift-connected institution attests to annually, including its cryptographic requirements.
PDF · 4.6 MB · a reference document — dip in, don’t read it through
DoD CIO streamlined top-10 IT cybersecurity practices campaign for small/mid-sized Defense Industrial Base partners, companion to the CMMC/DFARS compliance track.
PDF · 1.6 MB · a reference document — dip in, don’t read it through
Longitudinal study of cyber-incident frequency, likelihood and loss. Figure 6 gives the annual probability that a typical firm suffers a significant incident (2.5% in 2008 rising to 9.3% in 2024); Figure 7 splits that by revenue tier. Source of the organization-size breach-probability defaults in the Breach Scenario Simulator, ROI Calculator and Cost of Inaction Analyzer.
PDF · 2.6 MB · a reference document — dip in, don’t read it through
Web page · 88 KB · a short read
Web page · 42 KB · a short read
Web page · 163 KB · a long read
Web page · 323 KB · a long read
Web page · 323 KB · a long read
Web page · 337 KB · a long read
Web page · 172 KB · a long read
PDF · 665 KB · a long read
Web page · 56 KB · a short read
Commission Implementing Decision that publishes EN 18031-1, -2 and -3:2024 in the Official Journal as harmonised standards under the Radio Equipment Directive, with notices that withhold presumption of conformity in specific cases (e.g. where the user may opt not to set a password). Not PQC-specific; it determines which cybersecurity standard EU IoT radio products are assessed against, including its cryptography clauses.
Web page · 279 KB · a long read
NIST NCCoE practice guide volume (SP 1800-36B, Nov 2025, final) describing the approach, architecture and security characteristics of example builds for trusted network-layer onboarding and lifecycle management of IP-based IoT devices (Wi-Fi Easy Connect/DPP, BRSKI per RFC 8995, Thread, EST). Documents IEEE 802.1AR-2018 device identity in onboarding: for BRSKI the birth credential is an 802.1AR certificate installed as the device's IDevID (carrying the MASA location and voucher trust anchors), with an LDevID issued during network-layer onboarding.
PDF · 3.6 MB · a reference document — dip in, don’t read it through
Web page · 18 KB · a quick skim
This specification defines a method for computing a hash value over a CBOR Object Signing and Encryption (COSE) Key. It specifies which fields within the COSE Key structure are included in the cryptographic hash computation, the process for creating a canonical representation of these fields, and how to hash the resulting byte sequence. The resulting hash value, referred to as a "thumbprint", ca
Web page · 332 KB · a long read
Ethereum Foundation research post outlining the full roadmap to post-quantum Ethereum. Covers STARK-based and lattice-based signature replacement for ECDSA and BLS12-381, and describes the emergency quantum fork path for an unplanned Q-Day.
Web page · 467 KB · a long read
Proposes a new Bitcoin output type (SegWit v3, bc1r...) using post-quantum signatures via a soft fork. Removes the quantum-vulnerable key-spend path from Taproot. Exact PQC algorithms to be standardized in a companion BIP; ML-DSA and FALCON-512 are leading candidates under community discussion. Authored by Hunter Beast to address the HNFL risk to Bitcoin public keys.
Web page · 476 KB · a long read
Commission Implementing Regulation (EU) 2024/3144 of 18 December 2024, amending the EUCC scheme regulation (EU) 2024/482 on applicable international standards and correcting it.
Web page · 74 KB · a short read
Deloitte analyst brief arguing CPM investment is defensible on operational and regulatory grounds independent of quantum-arrival timing.
Web page · 332 KB · a long read
First biennial NIS2-mandated cybersecurity report for the EU; identifies PQC as a top emerging technology topic and warns most European stakeholders remain underprepared for the quantum transition.
PDF · 10.6 MB · a reference document — dip in, don’t read it through
Australian Signals Directorate (ASD) ISM cryptography guidelines update (December 2024). Mandates transition to NIST-standardized PQC algorithms for Australian government systems, sets migration timelines, and provides algorithm selection guidance.
PDF · 1.2 MB · a long read
The PQC Migration Handbook (2nd ed., December 2024) by AIVD, CWI and TNO — Diagnosis/Planning/Execution migration guidance, 'no-regret moves', crypto-agility, a detailed PQC-method overview, and international legislation. Named in the Applied Quantum framework's Appendix G crosswalk. 117 pages.
PDF · 2.3 MB · a reference document — dip in, don’t read it through
Defines UEFI Secure Boot: authenticating firmware images via EFI_CERT_X509 entries in the Secure Boot database (db). Specifies key enrollment, dbx revocation, and signature verification using PKCS#7 SignedData at boot time. Relevant to PQC migration as RSA/ECDSA signing keys must be replaced with ML-DSA or SLH-DSA.
PDF · 16.7 MB · a reference document — dip in, don’t read it through
Web page · 269 KB · a long read
Roadmap for transitioning from classical to post-quantum cryptography. The only published draft is the Initial Public Draft of 2024-11-12 (comment period closed 2025-01-10; final version pending). It retains the 2030 deprecation and 2035 disallowment targets.
PDF · 722 KB · a long read
IACR ePrint paper summarizing side-channel and fault-injection attacks targeting Classic McEliece including additive FFT and Gaussian elimination. Proposes a hardened FPGA/ASIC hardware design mitigating both attack classes.
PDF · 938 KB · a long read
Joint statement by 21 European nation cybersecurity agencies (including BSI, ANSSI, NCSC-NL) urging coordinated EU PQC migration. Endorses NIST-standardized algorithms and sets common migration principles for European organizations.
PDF · 822 KB · a long read
BSI Beschleunigte Sicherheitszertifizierung — German accelerated security-certification scheme, implementing EN 17640 Fixed-time Cybersecurity Evaluation Methodology (FiT CEM).
PDF · 533 KB · a long read
Spain’s CCN list of cryptographic mechanisms authorised for classified and public-sector systems.
PDF · 2.2 MB · a reference document — dip in, don’t read it through
Documents evaluation criteria and selection of 14 second-round candidates (CROSS, FAEST, HAWK, LESS, MAYO, Mirath, MQOM, PERK, QR-UOV, RYDE, SDitH, SNOVA, SQIsign, UOV) from 40 first-round submissions in NIST's additional PQC digital signature call.
Web page · 50 KB · a short read
AES-based MPC-in-the-Head signature using the VOLE-in-the-Head paradigm. Security reduces directly to AES — the most-studied symmetric cipher in existence — making FAEST the most conservative foundation among the MPCitH candidates. Smallest public and private keys in the contest (32 B each); signatures are kilobytes (FAEST-128f: 6,336 B). NIST selected it explicitly for the strength of its symmetric-primitive trust argument.
PDF · 1.2 MB · a long read
UOV variant that uses a 'whipping' algorithm to expand a small seed key into a full UOV instance — drastically reducing the public-key bloat that plagues raw UOV. MAYO-1 at NIST L1: pk=1,168 B, sk=24 B, sig=321 B. MAYO-2 lost ~30 bits to the 2025 wedge attack at Category 1; reparameterisation in progress and expected to recover.
PDF · 626 KB · a long read
UOV variant in odd-characteristic fields using quotient-ring mathematics to reduce the public-key representation size. The only multivariate candidate that emerged from the 2025 Ran wedge attack unscathed — its use of odd-characteristic fields makes it immune to the original exterior-product exploit, and subsequent extensions to odd characteristics did not reduce security below existing attack complexities.
PDF · 622 KB · a long read
Isogeny-based signature scheme — the only post-quantum candidate built on supersingular elliptic-curve isogenies. Smallest combined public-key+signature of any PQC candidate by a wide margin: SQIsign-I (NIST L1) is pk=64 B, sig=177 B (up from 148 B in Round 1, traded for a 20× signing speedup). Round 2 redesign switched to higher-dimensional isogenies, simplifying the security analysis and dramatically improving performance. SQIsign avoids the auxiliary-torsion structure that enabled the 2022 SIKE break.
PDF · 1.2 MB · a long read
EU regulation imposing mandatory cybersecurity requirements on hardware and software products with digital elements. Annex I requires cryptographic best practices; PQC migration relevant for product lifecycle compliance.
PDF · 1.8 MB · a reference document — dip in, don’t read it through
Guidance for integrating PQC into TLS, IKE, and 5G infrastructure.
PDF · 3.3 MB · a reference document — dip in, don’t read it through
Algorithm deprecation roadmap: SHA-1 and RSA/ECC <128-bit disallowed after 2030. Establishes federal algorithm retirement calendar aligned with PQC transition. References FIPS 203/204/205 as post-2030 replacements.
PDF · 928 KB · a long read
CISA guidance on PQC considerations specific to operational technology (OT) environments. Addresses unique migration challenges in ICS/SCADA systems including constrained devices, legacy protocols, and long operational lifetimes.
PDF · 1.4 MB · a long read
Examines how quantum computing affects the validity of existing cryptographic security proofs. Analyzes whether classical reduction-based proofs remain meaningful in a post-quantum setting.
PDF · 255 KB · a short read
Provides practical guidance on deploying hybrid classical-plus-PQC schemes. Addresses implementation considerations, key combiner design, protocol integration, and performance tradeoffs.
PDF · 233 KB · a short read
Provides a structured, repeatable framework for organizations planning quantum-safe cryptographic migrations. Covers discovery, assessment, planning, execution, and validation phases.
PDF · 506 KB · a long read
Analysis of the cumulative downtime required to upgrade the Bitcoin network from ECDSA to post-quantum cryptosystems to prevent quantum attacks.
Web page · 41 KB · a short read
DigiCert 5-level PQC maturity model mapped to organizational readiness; companion to CPM maturity frameworks.
PDF · 1.7 MB · a reference document — dip in, don’t read it through
DC3/DCISE overview of the free Defense Industrial Base Cybersecurity as a Service program for DIB partners.
PDF · 226 KB · a short read
BSI (Germany) standard defining functionality classes DRG.1–DRG.4 for deterministic RNGs and PTG.1–PTG.3 for physical/true RNGs. AIS 31 compliance is required for Common Criteria RNG evaluations and is cited by QRNG hardware certifications including ID Quantique Quantis.
PDF · 6.1 MB · a reference document — dip in, don’t read it through
European baseline security requirements for consumer-IoT devices — crypto, default passwords, update integrity.
PDF · 976 KB · a long read
DoD CMMC v2.13 three-level maturity framework (Foundational/Advanced/Expert) based on NIST SP 800-171 and 800-172. Required for defense contractors handling CUI. Cryptographic controls span key management, PKI, and access control.
PDF · 977 KB · a long read
DoD CMMC Level 1 (Foundational) scoping guidance defining assessment boundary for FCI-handling systems.
PDF · 589 KB · a long read
DoD CMMC Level 1 self-assessment methodology and 15 basic safeguarding requirements (FAR 52.204-21 aligned).
PDF · 820 KB · a long read
DoD CMMC Level 2 (Advanced) scoping guidance defining assessment boundary for CUI-handling systems, NIST SP 800-171 aligned.
PDF · 700 KB · a long read
DoD CMMC Level 2 assessment methodology against the 110 NIST SP 800-171 security requirements.
PDF · 2.3 MB · a reference document — dip in, don’t read it through
Demonstration of below-threshold quantum error correction performance using surface codes on superconducting processors.
PDF · 3.8 MB · a reference document — dip in, don’t read it through
CISA strategy outlining approach for US organizations to adopt automated tools for PQC cryptographic discovery and inventory. Provides methodology for identifying all classical cryptography in use and building migration roadmaps.
PDF · 538 KB · a long read
UK NCSC white paper providing updated guidance on PQC migration preparation. Covers algorithm selection, hybrid PQC, migration prioritization framework, and UK-specific timelines. Updates 2023 guidance and aligns with NIST finalized standards.
PDF · 134 KB · a short read
Specifies ML-KEM (Kyber) with three parameter sets (512, 768, 1024) for quantum-resistant key establishment. Errata Oct 2024.
PDF · 1.3 MB · a long read
Specifies ML-DSA (Dilithium) signature algorithms with three parameter sets (44, 65, 87). Errata Oct 2024.
PDF · 3.3 MB · a reference document — dip in, don’t read it through
Specifies SLH-DSA (SPHINCS+) stateless hash-based signatures with 12 parameter sets. The stateless alternative to LMS/XMSS — no state management required, but larger signatures.
PDF · 1.1 MB · a long read
IBM Research contributions to NIST PQC standards including co-invention of CRYSTALS-Kyber (ML-KEM) and CRYSTALS-Dilithium (ML-DSA).
Web page · 87 KB · a short read
A rigorous proof and adaptation of the LaBRADOR proof system to aggregate Falcon signatures, introducing predicate special soundness for knowledge soundness analysis.
PDF · 1.3 MB · a long read
Defines CMS KEMRecipientInfo structure for PQ KEMs including ML-KEM.
Web page · 87 KB · a short read
ENISA market analysis of EU cryptographic products and services, highlighting PQC readiness gaps across European stakeholders and Cryptography-as-a-Service market trends.
PDF · 3.6 MB · a reference document — dip in, don’t read it through
USENIX Security 2024 paper demonstrating timing side-channel attacks on HQC. Compiler-emitted variable-time division instructions leak secret data; constructs a Plaintext-Checking oracle to recover HQC secret keys.
PDF · 672 KB · a long read
Adds persistent symmetric (KDF / KEK-style) key packets to OpenPGP for hybrid encryption modes.
Web page · 23 KB · a quick skim
White House report estimating $7.1B government-wide PQC migration cost. Provides status of agency inventories, migration planning, and budget projections through 2035.
PDF · 1.2 MB · a long read
Specifies OpenPGP message formats for encryption, digital signatures, compression, and key management with modern cryptographic practices; prepares ecosystem for PQC signature integration.
Web page · 878 KB · a long read
Introduces a mechanism for IKEv2 peers to announce supported authentication methods, enabling negotiation of PQC signature algorithms for hybrid key exchange.
Web page · 82 KB · a short read
The UIC technical specification for the Future Railway Mobile Communication System.
PDF · 700 KB · a long read
Specifies the algorithms and key sizes permitted for US federal PIV credentials — the gate any PQC identity credential has to pass.
PDF · 694 KB · a long read
Standardizes XMSS and LMS stateful hash-based signatures at ISO level.
Web page · 88 KB · a short read
Singapore guidance for organizations preparing for PQC transition.
PDF · 1.7 MB · a reference document — dip in, don’t read it through
NATO's first Quantum Technologies Strategy establishing quantum-safe cryptography as a priority for Alliance cybersecurity. Commits NATO and member nations to post-quantum migration of classified communications and critical military systems.
Web page · 314 KB · a long read
EU regulation establishing the European Digital Identity framework mandating EUDI Wallets for all member states by late 2026. Requires private sector acceptance by late 2027. Introduces Qualified Electronic Attestations of Attributes (QEAA) and specifies the trust framework for digital identity across EU. Supersedes eIDAS 1.0.
Web page · 836 KB · a long read
Allows EOAs to set executable code via signed authorisation tuples (Pectra hard fork). Provides a bridge for PQC migration: a delegated smart contract can verify ML-DSA or FALCON signatures on behalf of the EOA, enabling quantum-safe signing without full account migration. Note: EIP-7702 authorisation tuples are themselves signed with secp256k1; quantum resistance is provided by the delegated contract's verification logic.
Web page · 58 KB · a short read
The controls US contractors must apply to controlled unclassified information, including its cryptographic requirements.
PDF · 1.6 MB · a reference document — dip in, don’t read it through
NIST assessment procedures for the security requirements in NIST SP 800-171 Rev. 3, used to verify CMMC Level 2 compliance.
PDF · 1.2 MB · a long read
Normative registry of signing algorithms Sigstore clients and services must support. Names the ECDSA (ecdsa-sha2-256-nistp256, P-384, P-521), RSA-PKCS1/PSS and Ed25519 variants, and the ML-DSA-44/65/87 pure variants being integrated. Cited as the proof that Sigstore-based software supply-chain signing uses ECDSA today and ML-DSA as its post-quantum replacement.
Web page · 5 KB · a quick skim
EU-wide coordination framework for member state PQC transitions. Target 2030 for critical systems.
PDF · 110 KB · a short read
European Commission formal Recommendation calling on EU member states to implement PQC migration roadmaps and coordinated timelines by 2030. Sets interoperability and procurement requirements for EU digital infrastructure.
PDF · 483 KB · a long read
Joint position paper from BSI, ANSSI, NLNCSA, and SNCSA on quantum key distribution (QKD). Concludes QKD alone is insufficient for government communications and recommends PQC as primary quantum-safe approach, with QKD as complementary where justified.
PDF · 476 KB · a long read
Lightweight authenticated key-establishment protocol for constrained IoT devices. Provides mutual authentication and forward secrecy in 3 messages over COSE; intended as the security handshake under OSCORE.
Web page · 1.8 MB · a long read
Academic survey on PQC covering lattice-based, code-based, multivariate, and hash-based schemes with analysis of quantum threats to classical cryptography.
PDF · 955 KB · a long read
Chinese national recommended standard (GB/T) defining quantum-communication terms and definitions, including QKD. In force 2024-10-01. It is a terminology standard for quantum communication, not a post-quantum cryptography standard.
Web page · 24 KB · a quick skim
FCC Report and Order establishing the voluntary U.S. Cyber Trust Mark labeling program for consumer wireless IoT products, with accredited-lab testing, Cybersecurity Label Administrators, a QR-code registry and NISTIR 8425 baseline criteria. Not PQC-specific; it is the US conformity scheme through which future IoT cryptographic expectations (including PQC) could be applied to consumer devices.
PDF · 647 KB · a long read
CCRA requirements for assurance continuity (maintaining or re-evaluating certificates after product changes), version 3.1, issued 29 February 2024.
PDF · 325 KB · a short read
NIST Cybersecurity Framework 2.0 (CSWP 29) — the six functions (Govern, Identify, Protect, Detect, Respond, Recover) and their subcategories. The anchor framework for the Applied Quantum PQC Migration Framework's Appendix G crosswalk (phase ↔ CSF function/subcategory). Foundational cyber risk-management framework.
PDF · 1.5 MB · a reference document — dip in, don’t read it through
NIST IR 8477 defines the NIST methodology for creating typed concept mappings (subset_of, superset_of, equivalent, intersects_with) between any cybersecurity or privacy documentary standards, submitted via the NIST OLIR process and hosted in CPRT. SP 800-218 (SSDF) is the primary worked example in §3. No PQC content.
PDF · 912 KB · a long read
Apple's technical whitepaper describing PQ3, the post-quantum protocol upgrade for iMessage. Achieves Level 3 PQC security by combining ML-KEM with periodic key rotation to protect both initial key establishment and ongoing message exchange. Independently verified by ETH Zurich and University of Waterloo.
Web page · 106 KB · a short read
Monetary Authority of Singapore (MAS) advisory requiring Singapore financial institutions to develop quantum risk management programs. Establishes timeline for financial sector PQC planning and mandates cryptographic inventory assessments.
PDF · 139 KB · a short read
Cuts the logical-qubit cost of Shor's factoring algorithm by computing approximate modular exponentiations with a Residue Number System, removing the assumption that n-bit arithmetic needs an n-qubit register. Estimates 1,730 logical qubits and 2^36 Toffoli gates for RSA-2048 — the source of the revised figure, and the basis Gidney 2025 builds on to reach fewer than 1M noisy physical qubits.
PDF · 581 KB · a long read
Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule
PDF · 1.6 MB · a reference document — dip in, don’t read it through
ITU guidance on implementing quantum-safe cryptography in telecommunications.
PDF · 527 KB · a long read
Research paper (IACR ePrint 2024/046, Dowling and Wimalasiri, University of Sheffield) on securing Controller-Pilot Data Link Communications (CPDLC) between air traffic control and aircraft. States that ECDSA "has been proposed as a suitable scheme for securing ACARS messages by the ACARS message security standard" (ARINC 823P1), analyses ECDH over P-384 as the classical key exchange, and proposes Kyber/ML-KEM with Dilithium for the post-quantum variant. Cited as research: ARINC 811 and 823 are sold through SAE and cannot be cited.
PDF · 817 KB · a long read
Saudi Arabia NCA releases updated Essential Cybersecurity Controls 2024 with expanded cryptography domain covering PQC awareness. Applicable to all Saudi government entities and critical infrastructure.
PDF · 1.2 MB · a long read
ITU-T recommendation providing security guidelines for the application of quantum-safe cryptographic mechanisms in telecommunications.
PDF · 1.6 MB · a reference document — dip in, don’t read it through
NIST seminar on practical fault injection attacks targeting Kyber and Dilithium on ARM Cortex-M4. Covers clock/voltage glitching, laser and electromagnetic fault injection exploiting polynomial multiplication and decryption routines.
PDF · 11.3 MB · a reference document — dip in, don’t read it through
NSA CSfC program addendum incorporating post-quantum cryptography requirements under CNSA 2.0. Governs classified systems transitioning to PQC algorithms.
PDF · 1.5 MB · a long read
Updated Common Criteria Protection Profile for Prepare-and-Measure QKD modules aligned with CC:2022 Revision 1. World's first QKD Protection Profile, certified by BSI as BSI-CC-PP-0120-2024.
PDF · 891 KB · a long read
EMVCo's position on the quantum threat to EMV chip cryptography, covering the RSA-based offline data authentication in Book 2 and EMVCo’s intended migration approach.
PDF · 302 KB · a short read
IETF RFC 9563 specifies SM2 for DNSSEC (algorithm number 17): 64-octet uncompressed public key (x||y), 64-octet signature (32-octet r || 32-octet s each). Used as the primary source for SM2's ALGORITHM_REGISTRY byte sizes.
Web page · 16 KB · a quick skim
Web page · 81 KB · a short read
Web page · 284 KB · a long read
PDF · 395 KB · a short read
Web page · 1.5 MB · a long read
PCI SSC program page for the Point-to-Point Encryption (P2PE) standard.
Web page · 727 KB · a long read
CEN/CENELEC harmonised standard specifying common security requirements and assessment criteria (access control, authentication, secure update, secure communication, confidential cryptographic keys, best-practice cryptography) for internet-connected radio equipment under the RED delegated act. Not PQC-specific; its best-practice cryptography requirement is where post-quantum algorithm expectations for EU IoT radio products would land.
Web page · 296 KB · a long read
CEN/CENELEC JTC 13 harmonised European Standard (EN 18031-3, August 2024) specifying common security requirements and assessment criteria for internet-connected radio equipment that lets the holder or user transfer money, monetary value or virtual currency, supporting the RED Delegated Regulation (EU) 2022/30 (Annex ZA). Requirement families cover access control, authentication, secure update, secure storage, secure communication, logging, confidential cryptographic keys, general equipment capabilities and best-practice cryptography ([CRY-1]), with mappings to EN IEC 62443-4-2:2019, ETSI EN 303 645 and SESIP.
PDF · 1.3 MB · a long read
SESIP Profile (JSADEN012 v2.0) defining the Target of Evaluation, assets, security objectives and SESIP security functional requirements for a PSA Certified Level 2 laboratory evaluation of an IoT chip's Root of Trust. Not PQC-specific, but it ties key strength to NIST SP 800-57 Part 1 and states RSA-2048 is accepted only for products certified before the end of 2026, making it a lever for future quantum-safe algorithm requirements in IoT certification.
PDF · 705 KB · a long read
UPV/EHU conference paper (ICREPQ'24) simulating a Docker-virtualised IEC 61850 substation protection system and showing that adding virtual IEDs raises the tripping communication delay (37 ms baseline, about +3 ms with 1 extra IED and +44 ms with 7). Documents the IEC 61850-5 transfer-time classes TT0-TT6 (TT0 >1000 ms, TT1 1000 ms, TT2 500 ms, TT3 100 ms, TT4 20 ms, TT5 10 ms, TT6 3 ms for trips and blockings).
PDF · 550 KB · a long read
This memo specifies two prime-order groups, ristretto255 and decaf448, suitable for safely implementing higher-level and complex cryptographic protocols. The ristretto255 group can be implemented using Curve25519, allowing existing Curve25519 implementations to be reused and extended to provide a prime-order group. Likewise, the decaf448 group can be implemented using edwards448. This document i
Web page · 128 KB · a short read
ANSSI publishes France's position on PQC transition, advocating hybrid post-quantum/classical schemes as the primary migration path. Provides phased approach guidance for French government and regulated entities.
PDF · 186 KB · a short read
Updated guidance on hybridization requirements and timeline phases through 2030+.
PDF · 172 KB · a short read
NERC Reliability Standard CIP-012-2 requires Control Center owners/operators to implement documented plans that protect the confidentiality, integrity and availability of Real-time Assessment and Real-time monitoring data transmitted between Control Centers (adds availability and link recovery to CIP-012-1). Not PQC-specific; relevant to PQC migration because encryption of inter-Control-Center links is a listed mitigation and will need quantum-safe replacement in North American grid OT.
PDF · 231 KB · a short read
Practical guidance for enterprise PQC migration with use cases and reference architectures.
PDF · 1.6 MB · a reference document — dip in, don’t read it through
BIS Innovation Hub Project Leap Phase 2 tests CRYSTALS-Dilithium post-quantum digital signatures in the Eurosystem T2 payment system. Demonstrates functional feasibility, performance benchmarks (PQC ~7.4× slower than RSA), interoperability across central bank configurations, and identifies challenges for hybrid cryptography migration.
PDF · 1.4 MB · a long read
Volume B — Tools and techniques for cryptographic discovery. Guides organizations in identifying quantum-vulnerable cryptography across their environments as the first step in PQC migration.
PDF · 1.7 MB · a reference document — dip in, don’t read it through
AUTOSAR Classic Platform software specification for the Crypto Driver, the in-vehicle ECU cryptographic abstraction. Enumerates the algorithm families an ECU stack must expose, including CRYPTO_ALGOFAM_ECDSA and CRYPTO_ALGOFAM_ECDH alongside RSA, ED25519 and BRAINPOOL. Cited as the proof that in-vehicle networks use ECDH and ECDSA; note MACsec (802.1AE) itself is AES-GCM and names neither.
PDF · 846 KB · a long read
Specifies minimum documentation requirements for FIPS 140-3 Security Policy documents; part of the NIST SP 800-140 series that defines the CMVP submission and validation framework.
PDF · 589 KB · a long read
New York Department of Financial Services cybersecurity regulation for covered entities (banks, insurers, money transmitters).
PDF · 696 KB · a long read
Signal's specification for PQXDH, extending the X3DH key agreement protocol with post-quantum security using ML-KEM. Deployed in Signal Messenger since September 2023. Provides forward secrecy and post-quantum confidentiality for initial key establishment in Signal's end-to-end encryption.
Web page · 64 KB · a short read
Canadian Centre for Cyber Security guidance on PQC adoption.
PDF · 649 KB · a long read
Defines DPoP for binding OAuth 2.0 tokens to a client public key using signed proof-of-possession JWTs. DPoP proof JWTs use ECDSA signatures that are quantum-vulnerable. Migration to ML-DSA-signed DPoP proofs requires JOSE PQC standardization and results in significantly larger proof headers per request.
Web page · 220 KB · a long read
NIST guidance for securing industrial control systems (ICS), SCADA, DCS, and OT networks. Covers the Purdue model, network architecture, and security controls for critical infrastructure.
PDF · 8.6 MB · a reference document — dip in, don’t read it through
GSMA guidelines for performing Quantum Cryptanalytic Risk Assessment (QCRA) in telecom. Adapts NIST RMF and ISO/IEC 27000 for quantum risk. Introduces the Crypto Agility Risk Assessment Framework (CARAF).
PDF · 1.2 MB · a long read
Joint CISA/NSA/NIST guidance on preparing organizations for post-quantum cryptography migration. Outlines a four-step quantum-readiness roadmap: establish governance; inventory vulnerable cryptography; assess priorities; engage vendors and plan transitions. Foundational regulatory baseline for federal and critical-infrastructure organizations and the most-cited US migration-readiness document.
PDF · 558 KB · a long read
Presentation of an end-to-end fault-tolerant quantum memory protocol using high-rate LDPC codes with low overhead and high error thresholds.
PDF · 858 KB · a long read
This document specifies a number of algorithms for encoding or hashing an arbitrary string to a point on an elliptic curve. This document is a product of the Crypto Forum Research Group (CFRG) in the IRTF.
Web page · 2.2 MB · a long read
Chinese national recommended standard (GB/T) setting basic requirements for applying quantum secure communication (QKD-based). In force 2024-03-01. It is a quantum-communication standard, not a post-quantum cryptography standard.
Web page · 24 KB · a quick skim
Announcement of the implementation of Hybrid Kyber KEM to protect Chrome traffic.
Web page · 179 KB · a long read
Presentation of a high-threshold, low-overhead fault-tolerant quantum memory protocol using bivariate bicycle LDPC codes.
PDF · 2.8 MB · a reference document — dip in, don’t read it through
Profiled deep-learning power analysis recovers secret and shared keys from first-, second-, and third-order masked Kyber-768 implementations on ARM Cortex-M4 — demonstrating that AI/ML side-channel analysis defeats standard masking countermeasures today, with no quantum computer or classical mathematical break of the underlying lattice problem required.
PDF · 3.9 MB · a reference document — dip in, don’t read it through
Key establishment protocol for efficient asynchronous group key establishment with forward secrecy and post-compromise security for groups of two to thousands. Uses HPKE tree-based key encapsulation (TreeKEM). Foundation for PQC group messaging via draft-ietf-mls-pq-ciphersuites (ML-KEM + hybrid KEMs).
Web page · 638 KB · a long read
List of approved security functions (algorithms) that FIPS 140-3 modules may implement under CMVP.
PDF · 720 KB · a long read
Approved methods for sensitive security parameter (SSP) generation and establishment under FIPS 140-3.
PDF · 730 KB · a long read
The organizational separation between operators of TLS and DTLS endpoints and the certification authority can create limitations. For example, the lifetime of certificates, how they may be used, and the algorithms they support are ultimately determined by the Certification Authority (CA). This document describes a mechanism to overcome some of these limitations by enabling operators to delegate
Web page · 74 KB · a short read
Canadian Forum for Digital Infrastructure Resilience (CFDIR) publishes quantum-readiness best practices for Canadian organizations covering PQC algorithm selection, hybrid approaches, and migration planning.
PDF · 2.9 MB · a reference document — dip in, don’t read it through
Singapore IMDA, CSA, and GovTech launch National Quantum-Safe Network Plus (NQSN+) to pilot quantum-safe networking solutions. Connects government, financial sector, and critical infrastructure operators.
Web page · 140 KB · a short read
Resource estimates for breaking 256-bit elliptic curve private keys using Shor’s algorithm on fault-tolerant quantum computers with active-volume architectures.
PDF · 3.3 MB · a reference document — dip in, don’t read it through
OWASP CycloneDX specification for the Cryptographic Bill of Materials (CBOM). Defines the schema, asset classes (algorithms, certificates, protocols, related cryptographic material), and discovery/enumeration guidance. The canonical format reference for CBOM tooling interoperability.
Web page · 38 KB · a quick skim
Preliminary draft (June 2023) of NIST SP 1800-40A, the executive-summary volume of the NCCoE project on automating the Cryptographic Module Validation Program.
PDF · 293 KB · a short read
EU crypto-asset regulation establishing prudential and operational requirements for crypto-asset service providers and issuers. Article 30 requires ICT security and cryptographic controls aligned with DORA.
PDF · 1.6 MB · a reference document — dip in, don’t read it through
In 2000, NIST announced the selection of the Rijndael block cipher family as the winner of the Advanced Encryption Standard (AES) competition. Block ciphers are the foundation for many cryptographic services, especially those that provide assurance of the confidentiality of data. Three members of the Rijndael family are specified in this Standard: AES-128, AES-192, and AES-256. Each of them trans
Web page · 44 KB · a short read
Reviews deployment of cryptographic security mechanisms in Intelligent Transport Systems (ITS) and Cooperative ITS. Assesses quantum computing vulnerability of V2X communications and trust roots.
PDF · 693 KB · a long read
Enables multiple key exchanges in single IKEv2 SA for hybrid PQ+classical.
Web page · 153 KB · a long read
Australia's whole-of-government quantum strategy establishing five themes: R&D and investment in quantum technologies; access to quantum infrastructure and materials; a skilled and growing quantum workforce; standards and frameworks supporting national interests; and a trusted, ethical, and inclusive quantum ecosystem. Sets the national vision for Australia to be a top-10 global quantum nation by 2045.
PDF · 17.6 MB · a reference document — dip in, don’t read it through
CCRA Management Committee policy CCMC-2023-04-001 (20 April 2023) on the transition from CC v3.1 to CC:2022 and CEM:2022.
PDF · 157 KB · a short read
A framework of graduated levels (Build L1-L3) for supply-chain integrity, defining provenance requirements for how an artifact was produced. Cited by the sandbox supply-chain-signing scenario, which demonstrates SLSA-style provenance signed with ML-DSA rather than ECDSA. A governance and process specification, not a cryptographic algorithm spec.
Web page · 20 KB · a quick skim
Volume A — Executive summary and business case for enterprise PQC migration. Frames the challenge of transitioning to quantum-resistant cryptography and outlines the NCCoE migration project scope.
Web page · 41 KB · a short read
Japan’s CRYPTREC list of ciphers approved for government procurement — the reference a Japanese public-sector migration is measured against.
PDF · 240 KB · a short read
Security requirements for QKD modules. Defines protection profiles and security targets analogous to Common Criteria for QKD hardware.
Web page · 88 KB · a short read
Testing methodology and evaluation criteria for QKD modules. Provides test vectors and conformance assessment procedures.
Web page · 88 KB · a short read
US EPA cybersecurity guidance for water and wastewater systems — operational technology with very long replacement cycles.
PDF · 458 KB · a long read
Specifies RSA, ECDSA, EdDSA. Removes DSA. Errata May 2025. Transition to PQC planned.
PDF · 1.8 MB · a reference document — dip in, don’t read it through
Specifies the elliptic curves and domain parameters NIST approves for discrete-logarithm cryptography — the classical curves a PQC migration is replacing.
Web page · 45 KB · a short read
Defines the Rosenpass protocol for adding PQC to WireGuard. Runs a separate ML-KEM-768 + Classic McEliece handshake and injects the combined shared secret as a WireGuard pre-shared key (PSK). Formally verified with ProVerif.
PDF · 347 KB · a short read
IETF BCP for DNSSEC; consolidates operational guidance and references PQ work as future work.
Web page · 98 KB · a short read
Foundational GSMA whitepaper analysing quantum-computing impact on telecom. Covers PQC technology dependencies, transition timelines, and market drivers across 2G/3G/4G/5G domains. Excludes QKD.
PDF · 1.2 MB · a long read
Analysis of design goals and security properties for hybrid digital signature schemes combining classical and post-quantum algorithms.
PDF · 1.0 MB · a long read
NIST's voluntary framework for managing risks in the design, development, deployment and use of AI systems, organised around the Govern/Map/Measure/Manage core. Cited by the ai-security-pqc module as the AI-risk governance anchor; the document itself contains no mention of cryptography, encryption or quantum computing and does not address post-quantum migration.
PDF · 1.9 MB · a reference document — dip in, don’t read it through
Web page · 121 KB · a short read
Web page · 95 KB · a short read
PDF · 126 KB · a short read
Web page · 25 KB · a quick skim
PDF · 1.2 MB · a long read
UK statutory instrument under the PSTI Act 2022 setting mandatory security requirements for consumer connectable products: no universal default passwords, a vulnerability-reporting policy, and a published minimum security-update support period, with deemed compliance via ETSI EN 303 645 or ISO/IEC 29147 provisions. Not PQC-specific; its defined support period matters for PQC planning because devices sold now must be supported into the quantum-risk window.
PDF · 251 KB · a short read
CEN/CENELEC European Standard (EN 17927:2023) defining SESIP, a methodology for security evaluation of IoT platforms and platform parts with reusable security functional and assurance requirements and SESIP assurance levels; drafted from the reseller listing and free sample only. Not PQC-specific; relevant to PQC migration as the evaluation basis IoT certification schemes (e.g. PSA Certified) reuse, where future quantum-safe cryptographic requirements would be assessed.
Web page · 305 KB · a long read
ODVA technology overview of CIP Security, the EtherNet/IP security extension: five security profiles (EtherNet/IP Confidentiality, CIP User Authentication, Resource-Constrained, Pull Model, Device-Based Firewall) built on X.509v3 certificates or PSKs, TLS/DTLS, HMAC, AES and OAuth 2.0/OpenID Connect tokens. Not PQC-specific; relevant to PQC migration because device identity and secure transport in EtherNet/IP rest on classical certificates and TLS/DTLS key exchange.
PDF · 497 KB · a long read
US legislation requiring OMB to prioritize PQC migration across federal agencies. Established annual reporting requirements and directed NIST to maintain updated PQC guidance.
Web page · 362 KB · a long read
US federal law requiring federal agencies to inventory and migrate cryptographic systems to quantum-resistant standards. Directs NIST and OMB to develop migration guidelines and establishes annual reporting requirements for PQC migration progress.
PDF · 208 KB · a short read
EU cybersecurity directive mandating risk-management measures and incident reporting for essential and important entities. Requires cryptographic controls and supply-chain security. Implemented by member states by Oct 2024.
PDF · 1.3 MB · a long read
EU regulation requiring financial entities to manage ICT risk including cryptographic controls, incident reporting, and digital operational resilience testing. Applicable from Jan 2025.
Web page · 1.0 MB · a long read
US Federal Railroad Administration guidance on Positive Train Control, including the message authentication it depends on.
PDF · 277 KB · a short read
IBM Research introduction to CBOM as the data artifact underpinning quantum-safe enterprise transformation.
Web page · 68 KB · a short read
Practical kleptographic (SETUP) backdoor demonstrated in Kyber/ML-KEM key generation — the generated public key covertly leaks the secret key to whoever holds the backdoor key. Validated end-to-end on TLS 1.3. A deliberately-subverted implementation, not a math or quantum-computer break: proof that a correctly-specified PQC algorithm can still be broken today via a compromised implementation or supply chain.
PDF · 355 KB · a short read
Transports IKE and IPsec packets over a TCP connection so they can cross networks that block UDP. Obsoletes RFC 8229. draft-ietf-ipsecme-ikev2-mlkem-09 names it as a reliable transport that permits ML-KEM-768/1024 in IKE_SA_INIT.
Web page · 628 KB · a long read
ASC X9 informative report assessing quantum computing risks to the financial services industry. Covers cryptographic threats, harvest-now-decrypt-later attacks, timeline projections, and migration priorities for financial institutions. Produced by the X9F Quantum Computing Risk Study Group.
PDF · 1.9 MB · a reference document — dip in, don’t read it through
NTRU+ is a post-quantum KEM selected as a South Korean national PQC standard by KpqC in January 2025. Based on NTRU lattice assumptions with improved key sizes over classic NTRU. Targets NIST-equivalent security levels L1, L3, and L5. National standard target year: 2029, migration by 2035.
PDF · 479 KB · a long read
OMB memo requiring federal agencies to submit cryptographic system inventories per NSM-10. Sets deadlines for PQC migration planning across US government systems.
PDF · 255 KB · a short read
OASIS Standard defining CSAF 2.0, whose Profile 5 is the Vulnerability Exploitability eXchange (VEX) — a machine-readable statement of whether a product is actually affected by a given vulnerability. VEX complements an SBOM: the SBOM says what components are present, VEX says which of their known vulnerabilities are exploitable in this product.
PDF · 736 KB · a long read
CC:2022 Part 2 — catalog of security functional requirements (SFRs) used to construct protection profiles and security targets.
PDF · 3.2 MB · a reference document — dip in, don’t read it through
CC:2022 Part 3 — assurance classes and families (ADV, AGD, ALC, ATE, AVA, etc.) used to define Evaluation Assurance Levels (EALs).
PDF · 2.9 MB · a reference document — dip in, don’t read it through
Companion to CC:2022 parts 1–3 — methodology evaluators apply when assessing conformance to protection profiles and security targets.
PDF · 3.6 MB · a reference document — dip in, don’t read it through
Common Criteria (ISO/IEC 15408) provides a framework for computer security certification. Relevant to PQC module evaluation.
PDF · 4.5 MB · a reference document — dip in, don’t read it through
IETF BCP for secure TLS/DTLS configuration. Notes PQC is work-in-progress; will be updated when PQ specs published.
Web page · 247 KB · a long read
CC:2022 Revision 1 Part 4 (CCMB-2022-11-004): the framework for specifying evaluation methods and activities.
PDF · 596 KB · a long read
CC:2022 Revision 1 Part 5 (CCMB-2022-11-005): the pre-defined packages of security requirements.
PDF · 586 KB · a long read
International standard specifying requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS). Serves as the governance anchor for accepting residual risk and operating the standing security capabilities handed to business-as-usual after a PQC migration.
Web page · 136 KB · a short read
NIST PQC Round 4 finalist specification for Classic McEliece, a code-based KEM with 50+ years of cryptanalytic scrutiny. Uses binary Goppa codes. Largest key sizes of all NIST finalists but conservative security assumptions and established mathematical foundations.
PDF · 249 KB · a short read
Specification of BIKE (Bit Flipping Key Encapsulation), a code-based KEM advanced to NIST Round 4 alongside Classic McEliece and HQC. Defines parameter sets BIKE-1, BIKE-3, BIKE-5 (NIST Levels 1/3/5).
PDF · 811 KB · a long read
FAQ document with implementation timelines: 2025-2030 prefer, 2030-2033 exclusive, 2035 complete.
PDF · 442 KB · a long read
NIST SP 800-108 Rev.1 specifies key derivation functions (KDFs) based on pseudorandom functions including counter mode feedback mode and double-pipeline mode using HMAC or CMAC. Directly implemented in PKCS#11 v3.0 as CKM_SP800_108_COUNTER_KDF and used in HSM-based QKD key derivation pipelines.
PDF · 745 KB · a long read
Defines COSE protocol for signatures, MACs, and encryption using CBOR serialization; critical path for PQC adoption in IoT and constrained device environments.
Web page · 313 KB · a long read
Defines initial cryptographic algorithm identifiers for COSE (used in CBOR-based protocols like IoT, CWTLS, JOSE); ML-KEM and ML-DSA COSE algorithm IDs are being registered.
Web page · 252 KB · a long read
Transmission Control Protocol (TCP) — foundational IETF transport standard (1981), obsoleted by RFC 9293 (2022). Provides reliable, ordered, byte-stream delivery over IP. Underpins TLS, HTTPS, and virtually every PQC protocol deployment; referenced as a dependency in protocol migration analysis.
Web page · 264 KB · a long read
Demonstrates end-to-end key recovery on FrodoKEM using Rowhammer DRAM bit flips. Forces key generation to produce high-error public keys, enabling decryption-failure attacks for full secret key recovery.
PDF · 850 KB · a long read
Documents selection of CRYSTALS-Kyber (ML-KEM), CRYSTALS-Dilithium (ML-DSA), FALCON (FN-DSA), and SPHINCS+ (SLH-DSA) for standardization. Advances HQC, BIKE, Classic McEliece, and SIKE to Round 4.
PDF · 885 KB · a long read
RFC 9258 defines an external PSK importer interface for TLS 1.3 (RFC 8446). It allows QKD-derived keys delivered via ETSI GS QKD 014 to be bound to a specific KDF and hash algorithm and imported as a TLS 1.3 pre-shared key — enabling QKD integration without any TLS protocol modifications.
Web page · 100 KB · a short read
ENISA study on integrating post-quantum cryptography into existing security protocols and systems. Analyzes PQC integration challenges for TLS, PKI, and code signing; provides recommendations for European organizations on algorithm selection and migration priorities.
PDF · 1.3 MB · a long read
First published use of transformer models (the same architecture family behind modern LLMs) to attack LWE-based lattice cryptography — recovers sparse binary secrets for small-to-mid LWE dimensions (up to n=128). Does not threaten standardized ML-KEM/ML-DSA parameter sets, but establishes AI-assisted cryptanalysis as an active, real research direction against lattice-based PQC, not a hypothetical one.
Web page · 9 KB · a quick skim
Official specification for SPHINCS+ (standardized as SLH-DSA in FIPS 205). A stateless hash-based signature scheme providing security based solely on hash function security. Covers SPHINCS+-SHA2 and SPHINCS+-SHAKE parameter sets at security levels 1, 3, and 5.
PDF · 1.0 MB · a long read
IMO guidelines on maritime cyber risk management — the baseline a vessel’s cryptographic posture is assessed against.
PDF · 425 KB · a long read
The Hypertext Transfer Protocol (HTTP) is a stateless application-level protocol for distributed, collaborative, hypertext information systems. This document describes the overall architecture of HTTP, establishes common terminology, and defines aspects of the protocol that are shared by all versions. In this definition are core protocol elements, extensibility mechanisms, and the "http" and "http
Web page · 4.7 MB · a long read
CCCS practical guidance on cryptographic agility — the ability to swap cryptographic algorithms via configuration without major software/hardware changes. Covers inventory, vendor selection (CMVP/CC certification), protocol negotiation, and phased quantum transition strategy. Companion to ITSAP.00.017 (quantum threat) and ITSM.40.001 (PQC migration roadmap).
Web page · 66 KB · a short read
US National Security Memorandum directing federal agencies to inventory cryptographic systems and transition to PQC. Established key milestones for quantum-resistant standards adoption.
Web page · 164 KB · a long read
McKinsey Digital piece on sequencing PQC preparation, with inventory and governance as the first no-regret investments.
Web page · 183 KB · a long read
Defines intermediate exchange for IKEv2 enabling PQC key exchange payloads that exceed single-packet size limits.
Web page · 70 KB · a short read
Defines the control interface between QKD network layer and SDN controllers for programmable quantum networks.
PDF · 519 KB · a long read
Orchestration interface for managing QKD resources in SDN environments. Defines YANG data models for interoperability between QKD network layer, SDN controllers, and orchestrators. Enables multi-domain key routing and programmable quantum networks.
PDF · 363 KB · a short read
Specifies DTLS 1.3 — the UDP-based variant of TLS 1.3 used for CoAP and constrained IoT communications. Key reference for PQC handshake overhead analysis on constrained devices.
Web page · 265 KB · a long read
NSA CNSA Suite profile for TLS and DTLS 1.2/1.3 — the cipher-suite, certificate and extension requirements a CNSA-compliant TLS deployment must meet. Superseded in direction by CNSA 2.0, which mandates ML-KEM and ML-DSA.
Web page · 96 KB · a short read
Defines EST-coaps, carrying Enrollment over Secure Transport (EST, RFC 7030) certificate-provisioning payloads over CoAP secured with DTLS so constrained devices can enroll certificates. Not PQC-specific; it is a likely path for re-provisioning constrained devices with post-quantum certificates, where larger PQ payloads stress CoAP block transfer.
Web page · 193 KB · a long read
This document specifies the Connection ID (CID) construct for the Datagram Transport Layer Security (DTLS) protocol version 1.2. A CID is an identifier carried in the record layer header that gives the recipient additional information for selecting the appropriate security association. In "classical" DTLS, selecting a security association of an incoming DTLS record is accomplished with the help
Web page · 86 KB · a short read
CRYPTREC’s criteria for setting cryptographic strength requirements, which is what decides when an algorithm leaves the approved list.
PDF · 1.4 MB · a long read
Introduces blob-carrying transactions for L2 data availability; uses KZG commitments (elliptic curve pairings) with a future migration path to quantum-safe polynomial commitments.
Web page · 63 KB · a short read
Secure Software Development Framework (SSDF) Version 1.1
PDF · 740 KB · a long read
Defines HPKE combining a KEM, KDF, and AEAD into a composable hybrid encryption scheme; used as the foundation for PQC hybrid KEM constructions (ML-KEM + X25519 HPKE modes).
Web page · 351 KB · a long read
NSM-8 extends EO-14028 cybersecurity requirements to NSS, DoD, and IC systems; mandates quantum-resistant cryptography migration timelines aligned with CNSA 2.0.
Web page · 176 KB · a long read
Comprehensive survey covering code-based cryptographic schemes including McEliece, Niederreiter, and modern variants. Directly relevant to HQC (NIST-standardized 2025) and Classic McEliece (Round 4 finalist). Covers security reductions, parameter selection, and implementation considerations.
Web page · 42 KB · a short read
Updates SSH key-exchange method recommendations: deprecates SHA-1 and short Diffie-Hellman groups, lists current recommended methods, and frames hybrid PQ KEX work that follows.
Web page · 578 KB · a long read
Commission Delegated Regulation that activates the Radio Equipment Directive's cybersecurity essential requirements (Art. 3(3)(d) network protection, (e) personal data/privacy, (f) fraud protection) for internet-connected, childcare, toy and wearable radio equipment. Not PQC-specific; it is the legal hook under which EN 18031 cryptography requirements apply to EU IoT radio products, so future PQC expectations for such devices would flow through it.
Web page · 303 KB · a long read
ANSSI publishes France's position on PQC transition, advocating hybrid post-quantum/classical schemes as the primary migration path. Provides phased approach guidance for French government and regulated entities.
PDF · 188 KB · a short read
Cloud Signature Consortium API v2 for remote digital signature services. Defines endpoints for credential listing (/csc/v2/credentials/list) credential information (/csc/v2/credentials/info) authorization (/csc/v2/credentials/authorize) and hash signing (/csc/v2/signatures/signHash). Supports Qualified Electronic Signatures (QES) via remote HSMs. Adopted by eIDAS trust service providers (QTSPs) for EUDI Wallet-compatible SCAL2 signature services.
PDF · 4.1 MB · a reference document — dip in, don’t read it through
Outlines organizational strategies, transition timelines, and standards guidance for migrating enterprise cryptographic systems to quantum-resistant algorithms as Shor’s algorithm threatens public-key cryptography.
PDF · 1.5 MB · a long read
Web page · 141 KB · a short read
Web page · 79 KB · a short read
PDF · 280 KB · a short read
Web page · 77 KB · a short read
PDF · 1.1 MB · a long read
Web page · 58 KB · a short read
FIDO Alliance specification of the FIDO Device Onboard (FDO) protocol: zero-touch, late-binding onboarding of IoT devices to an owner's platform via device attestation, ownership vouchers and the DI/TO0/TO1/TO2 protocols. Its algorithms are RSA, ECDSA and (EC)DH only; the spec itself notes quantum computers as a reason a device certificate might need an expiry.
PDF · 1.4 MB · a long read
Informational RFC describing the information model, threats and security requirements for a firmware-update manifest for IoT devices, the basis for the SUIT CBOR manifest. Not PQC-specific; it defines the signed-manifest trust model that firmware signing algorithms (and a move to PQ or hash-based signatures) must fit.
Web page · 263 KB · a long read
Sandia final report (SAND2022-1118, Jan 2022) of a DOE Solar Energy Technologies Office project that drafted DER cybersecurity standards recommendations through the SunSpec/Sandia workgroup and IEEE P1547.3. Documents that IEC 62351-3 requires TLS v1.2 or higher (TLS 1.0/1.1 still specified for backward compatibility) with X.509v3 certificates per IEC 62351-9 and mutual client/server authentication, and recommends at least TLS 1.2 (TLS 1.3 recommended), mutual authentication, AES-GCM/CCM and PKI with certificate revocation for all DER protocols.
PDF · 3.7 MB · a reference document — dip in, don’t read it through
The MD5 and SHA-1 hashing algorithms are increasingly vulnerable to attack, and this document deprecates their use in TLS 1.2 and DTLS 1.2 digital signatures. However, this document does not deprecate SHA-1 with Hashed Message Authentication Code (HMAC), as used in record protection. This document updates RFC 5246.
Web page · 181 KB · a long read
IETF Standards Track RFC defining Certificate Transparency Version 2.0. Obsoletes RFC 6962. Foundational for understanding the transparency log model that Merkle Tree Certificates extend for post-quantum TLS optimization. Specifies TLS extensions for CT log artifacts and certificate inclusion proofs.
Web page · 1.2 MB · a long read
SageMath-based tool for estimating the security of lattice-based cryptographic schemes against known attacks.
Web page · 376 KB · a long read
Chinese cryptography industry standard (GM/T, recommended) for decoy-state BB84 QKD products, under the State Cryptography Administration (国家密码管理局). In force 2022-05-01. A QKD product specification, not a post-quantum cryptography specification.
IETF Standards Track RFC defining an interoperable JWT format for OAuth 2.0 access tokens: required claims, explicit typing with typ 'at+jwt', mandatory RS256 support, and the validation steps a resource server must perform. Not PQC-specific; it is the profile that PQC-signed access tokens would follow, and its RS256 baseline is a classical signature that needs a quantum-safe successor.
Web page · 105 KB · a short read
Enables smart contract wallets on Ethereum without consensus-layer changes. As a PQC migration path, EIP-4337 smart accounts can verify ML-DSA or FALCON signatures on mainnet today — no protocol change required.
Web page · 106 KB · a short read
Official OpenSSL documentation covering the 3.x series. OpenSSL 3.5.0 (April 2025) introduced native ML-KEM, ML-DSA, and SLH-DSA without the OQS provider. OpenSSL 3.6.1 (January 2026) is the current stable release.
Web page · 21 KB · a quick skim
International standard defining the mso_mdoc credential format for mobile driving licences and identity documents. Specifies binary CBOR encoding document structure namespace (org.iso.18013.5.1; the EUDI eu.europa.ec.eudi.pid.1 doctype is defined by the ARF PID Rulebook, not by ISO) and cryptographic protection via Mobile Security Objects (MSO) signed by the issuer. Foundational for EUDI Wallet PID credentials and proximity presentations via NFC and BLE.
Web page · 93 KB · a short read
Official algorithm specification for CRYSTALS-Kyber (now standardized as ML-KEM in FIPS 203). Covers the IND-CCA2-secure KEM construction over module lattices, parameter sets, and security analysis from the KU Leuven COSIC / Ruhr University team.
PDF · 856 KB · a long read
Linux Foundation SPDX specification, standardized as ISO/IEC 5962:2021 — the general software bill of materials format focused on package/file provenance and license-compliance depth. Has no dedicated cryptography object model (see CBOM module for that gap and CycloneDX as the practical workaround).
Web page · 374 KB · a long read
Prevents hash-collision attacks by rejecting transactions from contract accounts; a cryptographic integrity measure referenced in noble/scure library security context.
Web page · 22 KB · a quick skim
This document defines the core of the QUIC transport protocol. QUIC provides applications with flow-controlled streams for structured communication, low-latency connection establishment, and network path migration. QUIC includes security measures that ensure confidentiality, integrity, and availability in a range of deployment circumstances. Accompanying documents describe the integration of TL
Web page · 2.9 MB · a long read
Biden Administration EO mandating zero-trust architecture, software supply chain security, and encryption modernization across U.S. federal systems; predecessor to PQC mandates.
Web page · 134 KB · a short read
ENISA recommendations on PQC adoption strategy for European organizations.
PDF · 1.1 MB · a long read
Defines how QUIC uses TLS 1.3 for connection establishment and record protection; the PQC hybrid key exchange for TLS 1.3 applies directly to QUIC via this integration.
Web page · 251 KB · a long read
Estimation of the physical resource costs and runtime for factoring 2048-bit RSA integers using optimized Shor’s algorithm on a noisy quantum computer.
PDF · 1.3 MB · a long read
Defines the SUIT manifest format for secure firmware updates on constrained IoT devices. Specifies metadata fields used in PQC firmware signing workflows.
Web page · 128 KB · a short read
Berlin hard fork change reserving the 0xEF contract bytecode prefix for EVM Object Format; part of the EVM upgrade path referenced by @noble/secp256k1 context.
Web page · 21 KB · a quick skim
UNECE WP.29 UN Regulation 155 mandating cybersecurity management systems for motor vehicles. Requires OEM and supplier cryptographic controls, key management, and software update security. Applicable to all new vehicle type approvals from July 2022.
PDF · 449 KB · a long read
Formally deprecates TLS 1.0 and TLS 1.1; combined with RFC 6176 and RFC 7568, clears the protocol floor to TLS 1.3 which is required for PQC hybrid key exchange.
Web page · 141 KB · a short read
Defines Chinese SM2/SM3/SM4 cipher suites for TLS 1.3; referenced in cross-national PQC interoperability discussions and Chinese national cryptography transition plans.
Web page · 86 KB · a short read
Official algorithm specification for CRYSTALS-Dilithium (now standardized as ML-DSA in FIPS 204). Covers the lattice-based digital signature scheme over module lattices with EUF-CMA security, parameter sets Dilithium2/3/5, and security proofs.
PDF · 1.2 MB · a long read
Monetary Authority of Singapore Technology Risk Management Guidelines — cryptography, key management, resilience for FIs.
PDF · 593 KB · a long read
Multi-part IEC standard for security of industrial automation and control systems. Defense-in-depth framework for OT/ICS environments including energy, utilities, and aerospace. PQC relevant for long-lived OT deployments.
Web page · 165 KB · a long read
The World Customs Organization framework securing global trade supply chains, including its data-exchange and authentication expectations.
PDF · 3.0 MB · a reference document — dip in, don’t read it through
The UN vehicle-type-approval regulation requiring a cyber security management system — the reason automotive cryptographic changes need a documented process, not just a patch.
Web page · 567 KB · a long read
PDF · 396 KB · a short read
Web page · 1.1 MB · a long read
Web page · 32 KB · a quick skim
Arm's Platform Security Model 1.1 (beta) sets out the 10 security goals and the Platform Root of Trust (secure boot, firmware update, attestation, secure storage, lifecycle) that underlie the PSA Certified framework for connected devices. Not PQC-specific; relevant to PQC migration because the root-of-trust signing, attestation and binding keys it defines are long-lived and must eventually move to quantum-safe algorithms.
PDF · 1.9 MB · a reference document — dip in, don’t read it through
Peer-reviewed NUI Galway paper (Cybersecurity, 2021) analysing internal and external attack strategies against IEEE 1588 PTP networks and testing them on a testbed. Documents the IEEE 1588-2019 (PTP v2.1) Annex P security extension's four prongs: A integrated TLV message authentication (shared group key or TESLA delayed processing), B external transport security (IPsec, MACsec), C architecture guidance (redundancy) and D monitoring and management - and notes Annex K is obsolete.
Web page · 479 KB · a long read
PTB (German national metrology institute) peer-reviewed paper in MDPI Sensors (2020) on resampling algorithms for precise amplitude/phase calibration of IEC 61850-9-2 Sampled Value instruments. Its Table 1 documents the IEC 61869-9 standard SV sample rates (4000, 4800, 5760, 12,800, 14,400, 15,360 and 96,000 Hz, with 4800, 14,400 and 96,000 marked preferred) and the standard's 10 mV / 1 mA amplitude quantisation.
Web page · 137 KB · a short read
KMIP v2.1 defines a protocol for communication between key management systems and cryptographic clients. Supports key lifecycle operations (create, locate, get, activate, revoke, destroy) over TLS. Widely implemented by enterprise HSMs (Thales, Utimaco, Entrust) and KMS solutions. Enables interoperability between key management infrastructure during PQC migration.
Web page · 3.4 MB · a long read
The Digital Container Shipping Association’s data model for container logistics interchange.
PDF · 2.6 MB · a reference document — dip in, don’t read it through
Defines certificate compression for TLS 1.3, reducing PQC certificate chain overhead by ~30%. Key mitigation for certificate bloat on constrained IoT devices.
Web page · 60 KB · a short read
Establishes the NICE Framework taxonomy of cybersecurity Work Roles, Competency Areas, and Task/Knowledge/Skill (TKS) statements for building and assessing the cyber workforce. The hub maps its learning roles and competency areas to this framework (Components v2.2.0, 2025).
PDF · 519 KB · a long read
UK NCSC position paper on quantum computing threat to public-key cryptography; recommends QSC following NIST standardisation; rejects QKD for government/military use.
Web page · 142 KB · a short read
NERC Reliability Standard CIP-010-4 sets configuration change management, configuration monitoring, vulnerability assessment and transient-asset/removable-media requirements for BES Cyber Systems; Part 1.6 requires verifying the identity of the software source and the integrity of software before baseline changes on high and medium impact systems. Not PQC-specific; relevant to PQC migration because software source/integrity verification typically rests on classical code-signing signatures.
PDF · 354 KB · a short read
Canonical CryptoCOE framing by David Mahdi (then Gartner): centralized operating model for cryptographic governance and modernization.
Web page · 220 KB · a long read
DFARS clause requiring adequate security (NIST SP 800-171) for covered defense information and 72-hour cyber incident reporting.
Web page · 121 KB · a short read
DFARS provision requiring offerors to have a current NIST SP 800-171 DoD Assessment on record in SPRS.
Web page · 113 KB · a short read
DFARS clause defining Basic/Medium/High NIST SP 800-171 DoD Assessment methodology and contractor cooperation requirements.
Web page · 118 KB · a short read
Specifies LMS and XMSS stateful hash-based signature schemes for firmware signing.
PDF · 873 KB · a long read
Official specification for the Falcon submission selected by NIST as the basis for the planned FN-DSA standard. FIPS 206 remains in development; NIST has not published an Initial Public Draft or final standard. Falcon is a lattice-based signature scheme based on the NTRU lattice with compact signatures using the GPV framework and fast Fourier sampling. The Falcon specification provides the smallest signatures among NIST PQC signature finalists, but its parameters must not be represented as final FIPS 206 parameters.
PDF · 382 KB · a short read
Updated FIPS 140-3 Implementation Guidance adding self-test requirements for FIPS 203/204/205 PQC algorithms and new guidance for Key Encapsulation Mechanisms.
PDF · 2.6 MB · a reference document — dip in, don’t read it through
TLS 1.3 [RFC8446] specifies a signed Diffie-Hellman exchange modelled after SIGMA [SIGMA]. This design is suitable for endpoints whose certified credential is a signing key, which is the common situation for current TLS servers. This document describes a mode of TLS 1.3 in which one or both endpoints have a certified DH key which is used to authenticate the exchange. Note to Read
Web page · 14 KB · a quick skim
NIST Cryptographic Module Validation Program management manual — governs the CMVP lifecycle, lab conduct, certification issuance, and maintenance reporting.
PDF · 886 KB · a long read
Berlin hard fork gas cost adjustments for EVM state access opcodes; indirectly affects PQC smart contract deployment costs due to larger key/signature sizes.
Web page · 42 KB · a short read
Security and Privacy Controls for Information Systems and Organizations
PDF · 6.1 MB · a reference document — dip in, don’t read it through
Defines optional access list transaction type (EIP-2718 type 1); relevant to noble/scure crypto library ecosystem referenced in the library.
Web page · 28 KB · a quick skim
Defines the electronic distribution of software to aircraft, including how loadable software is signed — a signature-size-sensitive path under PQC.
Web page · 138 KB · a short read
Specifies the application programming interface for accessing QKD-generated keys from applications.
PDF · 695 KB · a long read
NIST SP 800-56C Rev.2 specifies one-step and extraction-then-expansion (EtE) key derivation methods for key-establishment schemes. The EtE approach supports hybrid shared secrets combining classical DH or PQC KEM output with a QKD-sourced entropy value — directly applicable to quantum-hybrid key exchange architectures.
PDF · 695 KB · a long read
This document defines Zero Trust Architecture (ZTA) principles, logical components, and deployment models to shift cybersecurity defenses from network perimeters to users, assets, and resources.
PDF · 967 KB · a long read
ETSI technical specification defining quantum-safe hybrid key exchange mechanisms for TLS and IKEv2 protocols.
PDF · 667 KB · a long read
Evaluates 26 second-round candidate algorithms and selects 7 finalists (CRYSTALS-Kyber/Dilithium, FALCON, NTRU, SABER, Classic McEliece, SPHINCS+) plus 8 alternates for Round 3.
PDF · 587 KB · a long read
Strategic guidance for transitioning to quantum-safe cryptography.
PDF · 143 KB · a short read
NIST’s general access-control guidance for cloud systems.
PDF · 1.3 MB · a long read
This document defines two strategies for handling long lines in width-bounded text content. One strategy, called the "single backslash" strategy, is based on the historical use of a single backslash ('\') character to indicate where line-folding has occurred, with the continuation occurring with the first character that is not a space character (' ') on the next line. The second strategy, called
Web page · 403 KB · a long read
Peer-reviewed formal analysis of the EMV protocol (IEEE S&P 2021, ETH Zurich). Documents offline data authentication SDA/DDA/CDA and their RSA basis. Open-access substitute for the registration-gated EMV Book 2. Verified: rsa x13, SDA x42, DDA x37, CDA x21, ECDSA x0.
PDF · 1.6 MB · a reference document — dip in, don’t read it through
Defines a typed transaction envelope format allowing multiple transaction types; enables extensible transaction formats for future PQC signature-compatible Ethereum transactions.
Web page · 24 KB · a quick skim
Adds PPK (Post-quantum Preshared Key) to IKEv2 for quantum resistance.
Web page · 96 KB · a short read
Peer-reviewed analysis (ACM TOPS; Oxford) of Bluetooth and BLE key negotiation. Documents that Secure Connections pairing derives the Long Term Key via ECDH on NIST P-256. Open-access substitute for the registration-gated Bluetooth Core Specification. Verified: ECDH x8, P-256 x3, ECDSA x0.
PDF · 2.4 MB · a reference document — dip in, don’t read it through
PCI PTS Device Testing and Approval Program Guide, Version 1.9 (June 2020): the last publicly downloadable edition of the PTS program guide.
PDF · 1.6 MB · a reference document — dip in, don’t read it through
ANSSI maintenance report ANSSI-CC-PP-2016/05-M01 (Paris, 18 May 2020), in French, for the protection profile EN 419221-5:2018 E version 1.0, with certificate ANSSI-CC-PP-2016/05 as its reference.
PDF · 167 KB · a short read
Primary NIST key management guideline covering key lifecycle (generation, distribution, storage, usage, rotation, archival, destruction), key types, cryptoperiods, FIPS 140 integration, and key compromise procedures. Foundation for all enterprise key management policy and HSM deployment.
PDF · 1.7 MB · a reference document — dip in, don’t read it through
HSS/LMS signatures for CBOR Object Signing for IoT devices.
Web page · 89 KB · a short read
SP 800-175B Rev 1 defines approved cryptographic mechanisms for U.S. federal use including symmetric encryption, hash functions, digital signatures, and key establishment. Primary mapping target for NIST IR 8477 concept mappings. Superseded in PQC context by FIPS 203/204/205 but remains the baseline cryptographic guidance framework.
PDF · 1.4 MB · a long read
Modifies Section 6.1 of ISO/IEC 24759 with US-specific CMVP documentation requirements.
PDF · 288 KB · a short read
Approved authentication mechanisms for operators accessing FIPS 140-3 validated modules.
PDF · 362 KB · a short read
Test methods required under FIPS 140-3 for non-invasive attack mitigation (side channels).
PDF · 304 KB · a short read
NSA CNSA Suite algorithm identifiers for X.509 certificates and CRLs; being extended by ML-DSA CNSA 2.0 certificate profile.
Web page · 95 KB · a short read
NSA CNSA Suite algorithm profile for CMS signed data and enveloped data; provides the baseline NSA-approved CMS profile that CNSA 2.0 PQC algorithms extend.
Web page · 102 KB · a short read
NIST SP 800-140 (March 2020): the CMVP validation authority updates to ISO/IEC 24759, the test-requirements standard FIPS 140-3 uses for module testing.
PDF · 409 KB · a long read
This document describes OAuth client authentication and certificate-bound access and refresh tokens using mutual Transport Layer Security (TLS) authentication with X.509 certificates. OAuth clients are provided a mechanism for authentication to the authorization server using mutual TLS, based on either self-signed certificates or public key infrastructure (PKI). OAuth authorization servers are p
Web page · 549 KB · a long read
This document specifies an extension to the OAuth 2.0 Authorization Framework defining request parameters that enable a client to explicitly signal to an authorization server about the identity of the protected resource(s) to which it is requesting access.
Web page · 263 KB · a long read
Ed25519 and Ed448 Public Key Algorithms for the Secure Shell (SSH) Protocol
Web page · 215 KB · a long read
Defines curve25519-sha256 and curve448-sha512 key exchange for SSH. The classical KEX baseline that mlkem768x25519-sha256 hybrid extends for post-quantum SSH in OpenSSH 9.9+.
Web page · 51 KB · a short read
Documents security pitfalls and best practices for JWT usage including algorithm confusion attacks, none-algorithm vulnerabilities, audience validation, and expiry enforcement. Essential security hardening baseline before migrating JWT signing algorithms to PQC alternatives.
Web page · 89 KB · a short read
Specifies how to use IETF/NIST HSS/LMS stateful hash-based signature algorithm within CMS; relevant for long-lived document signing with PQC algorithms.
Web page · 77 KB · a short read
Results of CACR national PQC competition: Aigi-sig, LAC.PKE, Aigis-enc (lattice-based).
Web page · 30 KB · a quick skim
Defines 64-byte Schnorr signatures for secp256k1 with provable security, batch verification, and key aggregation (MuSig2). Required foundation for Taproot (BIP-341). BIP-360 (P2QRH) targets Taproot's Schnorr key-spend path as the primary quantum vulnerability to replace with post-quantum signatures.
Web page · 40 KB · a quick skim
Activates Taproot on Bitcoin (block 709632). Defines SegWit v1 spending with a Schnorr key-spend path and Merklized Abstract Syntax Tree (MAST) script-spend path. BIP-360 (P2QRH) specifically removes the key-spend path as quantum-vulnerable under Shor's algorithm and proposes a SegWit v3 (bc1r...) replacement.
Web page · 44 KB · a short read
Introduction of SQISign, a compact post-quantum signature scheme based on isogenies of supersingular elliptic curves and quaternion algebras.
PDF · 783 KB · a long read
NIAP CCEVS operational quality manual — roles, procedures, evaluation workflow, and assurance maintenance.
PDF · 861 KB · a long read
Saudi Arabia National Cybersecurity Authority National Cryptographic Standards. Defines approved symmetric, asymmetric, and hash algorithms for Saudi government and critical infrastructure. Basis for ECC-2 cryptographic controls.
PDF · 1.1 MB · a long read
Specifies SHAKE128 and SHAKE256 (from FIPS 202) for use in CMS signatures; directly bridges FIPS 202 XOFs to the CMS layer used by PQC signing protocols.
Web page · 79 KB · a short read
PDF · 264 KB · a short read
Web page · 549 KB · a long read
PDF · 3.1 MB · a reference document — dip in, don’t read it through
PDF · 1.3 MB · a long read
NIST report describing six foundational pre-market and post-market cybersecurity activities for IoT device manufacturers, companion to the NISTIR 8259A core baseline; withdrawn on 2026-04-20 and superseded by NIST IR 8259r1. Not PQC-specific; its guidance to plan device cybersecurity capabilities (including cryptographic hardware) before market is relevant to building crypto-agility into long-lived IoT devices.
PDF · 1.6 MB · a reference document — dip in, don’t read it through
ANSI/ASHRAE Addendum bj to Standard 135-2016 introduces BACnet Secure Connect (BACnet/SC), a BACnet datalink option using TLS 1.3-secured WebSocket connections in a hub-and-spoke topology, with each node holding a CA-signed X.509 operational certificate. Not PQC-specific; relevant to PQC migration because BACnet/SC security for building automation depends on TLS 1.3 key exchange and certificate-based authentication that must move to quantum-safe algorithms.
PDF · 1.7 MB · a reference document — dip in, don’t read it through
Go wrapper for the liboqs C library providing PQC algorithm access for Go applications.
Web page · 370 KB · a long read
Foundational ITU-T/ISO standard defining X.509 PKI certificate frameworks. Section 9.8 introduces Alternative Cryptographic Algorithms extensions (OIDs 2.5.29.72-74: SubjectAltPublicKeyInfo / AltSignatureAlgorithm / AltSignatureValue) enabling hybrid certificate support — the basis for Alt-Sig / Catalyst hybrid quantum-safe certificates.
PDF · 3.6 MB · a reference document — dip in, don’t read it through
Peer-reviewed paper (ACM CCS 2019) presenting the formal security analysis of SPHINCS+ / SLH-DSA. Proves security in the multi-function multi-target one-way (MFOTW) model and analyzes the tight security reductions. Covers the WOTS+ one-time signature, FORS few-time signature, and HT hypertree structure.
PDF · 2.2 MB · a reference document — dip in, don’t read it through
IACR ePrint analysis of BLE Secure Connections; confirms ECDH on the P-256 curve for pairing. Corroborates BLE-Key-Negotiation-Downgrade-2020. Verified: ECDH x3, P-256 x2, ECDSA x0.
PDF · 817 KB · a long read
Defines OSCORE, end-to-end application-layer protection of CoAP (and CoAP-mappable HTTP) messages using COSE, designed for constrained nodes and proxies; updates RFC 7252. Not PQC-specific; its symmetric protection depends on a shared master secret, so PQC exposure sits in the key-establishment protocol used with it (e.g. EDHOC/LAKE).
Web page · 261 KB · a long read
This document proposes a notational convention to express Concise Binary Object Representation (CBOR) data structures (RFC 7049). Its main goal is to provide an easy and unambiguous way to express structures for protocol messages and data formats that use CBOR or JSON.
Web page · 566 KB · a long read
NSA CNSA Suite X.509 certificate and CRL profile — the algorithm, key size and extension requirements for certificates used in National Security Systems. The TLS/DTLS cipher-suite profile is RFC 9151, a separate document.
Web page · 40 KB · a short read
S/MIME 4.0 email security standard for signing and encrypting email using CMS. Foundation for PQC email migration via RFC 9629 (KEM) and RFC 9882 (ML-DSA).
Web page · 183 KB · a long read
Stateful hash-based signature scheme LMS. Updated by RFC 9858.
Web page · 157 KB · a long read
Federal standard defining the security requirements for cryptographic modules (PKCS#11, HSMs, software libraries) validated under CMVP.
PDF · 311 KB · a short read
Automatic Certificate Management Environment (ACME)
Web page · 855 KB · a long read
Latest NIAP CCEVS policy letter governing scheme operation; representative of the policy-letter series.
PDF · 297 KB · a short read
SP 800-56B Rev 2 specifies RSA-based key establishment for U.S. federal use; superseded by ML-KEM per PQC migration timelines.
PDF · 1.8 MB · a reference document — dip in, don’t read it through
C++ wrapper for the liboqs C library providing object-oriented PQC algorithm access.
Web page · 362 KB · a long read
PROFIBUS & PROFINET International white paper (V1.05, Feb 2019) setting out the security concept for PROFINET protocol extensions, aligned with IEC 62443. Defines three PROFINET Security Classes - 1 Robustness (e.g. changeable SNMP default strings, read-only DCP, signed GSD files), 2 Integrity + Authenticity (cryptographically protected cyclic and acyclic communication, confidential configuration data), 3 Confidentiality (adds encryption) - using device certificates for start-up key negotiation and a MAC over cyclic frames (HMAC-SHA256 best performer, not finally selected).
PDF · 1.6 MB · a reference document — dip in, don’t read it through
Control interface specification for QKD device parameters and communication channel monitoring.
PDF · 387 KB · a short read
RESTful API specification for key delivery between QKD nodes and applications. Widely implemented reference API.
PDF · 459 KB · a long read
DVB extensions to CI Plus, the conditional-access interface in broadcast receivers.
PDF · 2.0 MB · a reference document — dip in, don’t read it through
ASC X9 Technical Report investigating use of Cryptographic Message Syntax (CMS) in the presence of a quantum-capable attacker. Provides recommendations for using quantum-safe cryptography within CMS and migrating classical financial systems to quantum-safe algorithms. Published by the X9F4 workgroup.
PDF · 627 KB · a long read
Clean reference C implementations of all NIST PQC finalists and candidates. Designed for easy integration and auditing.
Web page · 368 KB · a long read
University course material on EMV card authentication, covering SDA, DDA and CDA and the RSA signatures they rely on. Teaching material, not a specification — cited as corroborating evidence alongside the peer-reviewed analysis. Verified: SDA x17, DDA x22, CDA x10, ECDSA x0.
PDF · 1.9 MB · a reference document — dip in, don’t read it through
PDF · 815 KB · a long read
PDF · 686 KB · a long read
ASHRAE SSPC 135 IT Working Group white paper introducing BACnet Secure Connect (BACnet/SC), a BACnet datalink based on TLS 1.3-secured WebSockets with 128- or 256-bit elliptic-curve cryptography, removing static IPs and BBMDs, with four deployment scenarios. Not PQC-specific; relevant to PQC migration because it fixes building-automation security on TLS 1.3 elliptic-curve key exchange and certificates.
PDF · 835 KB · a long read
DOE Grid Modernization Laboratory Consortium report (PNNL-29313, Oct 2019) surveying vulnerabilities and mitigations for energy-delivery protocols (Modbus, DNP3, IEC 61850, IEC 60870-5, ICCP, C37.118) and time synchronization. Documents IEC 62351-3 TLS security profiles for TCP/IP with X.509 node authentication (TLS 1.2 for MMS/IEC 61850), IEC 62351-9 key/certificate management incl. CRL/OCSP handling, and R-GOOSE/R-SV payload protection with symmetric keys distributed by a GDOI key distribution center (RFC 6407 + RFC 8052) with IEC 62351-9 key exchange.
PDF · 433 KB · a long read
Defines MACsec — IEEE Layer 2 encryption standard for Ethernet networks. MACsec uses AES-GCM-128/256 for confidentiality and integrity. QKD-derived keys can be injected as Secure Association Keys (SAKs) via the MACsec Key Agreement (MKA) protocol, making MACsec a natural integration point for QKD in enterprise and telecom networks.
Web page · 55 KB · a short read
Python wrapper for the liboqs C library providing PQC algorithm access for Python applications and research.
Web page · 369 KB · a long read
Risk Management Framework for Information Systems and Organizations
PDF · 2.3 MB · a reference document — dip in, don’t read it through
First single-trace side-channel attack on NTRU. Recovers the secret key from a single power trace, improving upon earlier differential power analysis attacks on NTRU implementations.
Web page · 649 KB · a long read
Zstandard, or "zstd" (pronounced "zee standard"), is a data compression mechanism. This document describes the mechanism and registers a media type and content encoding to be used when transporting zstd-compressed content via Multipurpose Internet Mail Extensions (MIME). Despite use of the word "standard" as part of its name, readers are advised that this document is not an Internet Standards Tr
Web page · 127 KB · a short read
Go library implementing PQC algorithms (ML-KEM, ML-DSA, SLH-DSA) and hybrid key exchanges. Used in Cloudflare's production PQC deployment.
Web page · 406 KB · a long read
This document describes the use of the Edwards-curve Digital Signature Algorithm (EdDSA) in the Internet Key Exchange Protocol Version 2 (IKEv2).
Web page · 117 KB · a short read
This document specifies algorithm identifiers and ASN.1 encoding formats for elliptic curve constructs using the curve25519 and curve448 curves. The signature algorithms covered are Ed25519 and Ed448. The key agreement algorithms covered are X25519 and X448. The encoding for public key, private key, and Edwards-curve Digital Signature Algorithm (EdDSA) structures is provided.
Web page · 237 KB · a long read
This document describes a number of changes to TLS and DTLS IANA registries that range from adding notes to the registry all the way to changing the registration policy. These changes were mostly motivated by WG review of the TLS- and DTLS-related registries undertaken as part of the TLS 1.3 development process. This document updates the following RFCs: 3749, 5077, 4680, 5246, 5705, 5878, 6520,
Web page · 58 KB · a short read
Specifies XMSS and XMSS-MT stateful hash-based signature schemes.
Web page · 185 KB · a long read
Microsoft Research PQC project including lattice-based and isogeny-based cryptography research, SymCrypt PQC integration.
Web page · 187 KB · a long read
Recommendation for Pair-Wise Key-Establishment Schemes Using Discrete Logarithm Cryptography
PDF · 1.7 MB · a reference document — dip in, don’t read it through
Regulatory Technical Standards implementing PSD2 Article 97: two-factor SCA (knowledge/possession/inherence), dynamic linking, the dedicated-interface obligation for open banking APIs (Art. 30), fallback mechanism (Art. 33), eIDAS qualified certificates for TPP identification (Art. 34), and "strong and widely recognised encryption techniques" for the channel (Art. 35) — technology-neutral, names no algorithm or TLS version.
Web page · 166 KB · a long read
NIST standard for validating entropy sources used in random bit generators. Defines health tests (repetition count, adaptive proportion), min-entropy estimation methods, and IID testing requirements.
PDF · 1.0 MB · a long read
TCG PC Client Specific Platform TPM Profile for TPM 2.0, v1.07. Applies TPM 2.0 Library v1.85 PQ algorithms (ML-DSA, ML-KEM) to PC platforms.
Web page · 112 KB · a short read
TCG Endorsement Key Credential Profile v2.7. Adds PQ EK templates (ML-DSA, ML-KEM) for TPM 2.0 v1.85.
Web page · 107 KB · a short read
The road-vehicle functional-safety standard. Relevant to PQC because any change to in-vehicle cryptography inherits its safety-case and re-certification burden.
Web page · 71 KB · a short read
PDF · 342 KB · a short read
PDF · 494 KB · a long read
Adds stronger MODP DH groups (4096-8192 bit) to SSH; being superseded by ML-KEM PQC key exchange for post-quantum SSH implementations.
Web page · 23 KB · a quick skim
JavaScript Object Notation (JSON) is a lightweight, text-based, language-independent data interchange format. It was derived from the ECMAScript Programming Language Standard. JSON defines a small set of formatting rules for the portable representation of structured data. This document removes inconsistencies with other specifications of JSON, repairs specification errors, and offers experience-
Web page · 38 KB · a quick skim
Compares quantum-safe key exchange proposals from the academic literature including LWE, Ring-LWE, and SIDH-based schemes. Evaluates performance and security tradeoffs for standardization.
PDF · 444 KB · a long read
The US state-level model law governing insurer data security, including encryption expectations for policyholder data.
PDF · 238 KB · a short read
The foundational deep-learning side-channel attack paper (CHES 2017): shows a CNN can profile and recover AES keys through jitter-based hiding countermeasures without trace realignment. AES is the current, widely-deployed symmetric standard — this shows AI-assisted attacks defeat production countermeasures today, with no dependence on quantum computing or PQC migration status.
PDF · 1.9 MB · a reference document — dip in, don’t read it through
This document provides a summary of the Internet of Things Software Update (IoTSU) Workshop that took place at Trinity College Dublin, Ireland on the 13th and 14th of June, 2016. The main goal of the workshop was to foster a discussion on requirements, challenges, and solutions for bringing software and firmware updates to IoT devices. This report summarizes the discussions and lists recommendatio
Web page · 287 KB · a long read
The CBOR Object Signing and Encryption (COSE) specification defines cryptographic message encodings using Concise Binary Object Representation (CBOR). This specification defines algorithm encodings and representations enabling RSA algorithms to be used for COSE messages. Encodings are specified for the use of RSA Probabilistic Signature Scheme (RSASSA-PSS) signatures, RSA Encryption Scheme - Opt
Web page · 174 KB · a long read
Peer-reviewed academic paper (Journal of Cryptology 2022) presenting the full security analysis and design rationale for CRYSTALS-Kyber / ML-KEM. Proves IND-CCA2 security under Module-LWE assumption in the ROM and QROM. Essential reading for implementers and security evaluators.
PDF · 469 KB · a long read
Peer-reviewed academic paper (TCHES 2018) presenting the design and security analysis of CRYSTALS-Dilithium / ML-DSA. Proves EUF-CMA security under Module-LWE and Module-SIS assumptions. Covers the Fiat-Shamir with Aborts paradigm and rejection sampling technique.
PDF · 884 KB · a long read
Australian Cyber Security Centre (ACSC) Essential Eight Maturity Model — eight prioritised mitigation strategies. Mandatory for Australian federal government agencies; widely adopted by APRA-regulated entities and critical infrastructure. Cryptographic patching and application hardening requirements at ML3 directly intersect PQC migration planning.
Web page · 436 KB · a long read
IACR ePrint / EUROCRYPT 2018 paper introducing Ouroboros Praos, the proof-of-stake consensus protocol Cardano runs. Defines the two core primitives at the protocol-design level: a forward-secure digital signature scheme (realized in production as a Key-Evolving Signature, KES) for block signing, and a verifiable random function (VRF) for private, unbiasable slot-leader election. The paper itself is curve-agnostic — it does not name Ed25519; the concrete Cardano instantiation is documented separately (see the cardano-crypto-praos VRF source and the input-output-hk/kes KES implementation).
PDF · 777 KB · a long read
Many protocols make use of points of extensibility that use constants to identify various protocol parameters. To ensure that the values in these fields do not have conflicting uses and to promote interoperability, their allocations are often coordinated by a central record keeper. For IETF protocols, that role is filled by the Internet Assigned Numbers Authority (IANA). To make assignments in a
Web page · 140 KB · a short read
IETF Standards Track RFC defining Group Domain of Interpretation (GDOI) payloads so IEC 62351-9 key management can distribute security policy and group keys (AES-GCM, HMAC-SHA256) protecting IEC 61850 GOOSE and Sampled Values multicast in power substations. Not PQC-specific; relevant to PQC migration because substation group-key distribution depends on GDOI's classical public-key authentication.
Web page · 67 KB · a short read
Clarifies that only uppercase RFC 2119 keywords carry normative weight; updates BCP 14.
Web page · 8 KB · a quick skim
Survey paper by Bernstein and Lange analysing the NIST PQC standardisation landscape at its launch, covering all major algorithm families (lattice, code-based, hash-based, multivariate, isogeny) and migration strategy considerations. Companion to the foundational Bernstein-Buchmann-Dahmen PQC book (already in library).
PDF · 421 KB · a long read
Presents quantum threat assessment across banking/finance, intelligent transport, IoT, and digital media. Analyzes Shor and Grover algorithm impacts on deployed cryptographic systems.
PDF · 264 KB · a short read
Examines real-world PQC deployment scenarios including network security, TLS, IoT, and satellite communications. Analyzes migration challenges across telecom, government, and critical infrastructure sectors.
PDF · 155 KB · a short read
Analyzes the impact of quantum computing on symmetric key cryptography. Concludes that 256-bit symmetric ciphers and hash functions will remain secure against quantum attacks through 2050.
PDF · 113 KB · a short read
NIST FAQ on PQC standardization process, algorithm selection criteria, and migration guidance for the FIPS 203/204/205 standards.
Web page · 132 KB · a short read
IETF standard for EdDSA including Ed25519 and Ed448. Used by Solana. Deterministic nonce eliminates nonce-reuse vulnerabilities.
Web page · 174 KB · a long read
Defines JWK and JWA algorithm identifiers for Ed25519/Ed448 signatures and X25519/X448 key agreement; used in hybrid PQC JOSE/JWT implementations alongside ML-KEM.
Web page · 33 KB · a quick skim
LoRa Alliance LoRaWAN 1.1 MAC-layer specification for low-power wide-area networks of battery-powered end-devices, defining device classes, activation, and the AES-128-based key hierarchy (NwkKey/AppKey root keys, CMAC integrity). Not PQC-specific; it uses symmetric cryptography for radio transmissions, so its PQC-migration relevance is confirming 128-bit symmetric key strength.
PDF · 2.3 MB · a reference document — dip in, don’t read it through
Defines the SHA-3 derived functions: cSHAKE, KMAC, TupleHash and ParallelHash. KMAC in particular is what several PQC KEM constructions derive keys with.
Web page · 45 KB · a short read
The protection profile certified by ANSSI as ANSSI-CC-PP-2016/05: Protection Profiles for TSP Cryptographic Modules, Part 5 (Cryptographic Module for Trust Services). The captured text is the prEN 419 221-5 v0.15 edition dated 2016-11-29.
PDF · 722 KB · a long read
Documents RSA cryptographic primitives, encryption and signature schemes, and ASN.1 representations; the primary reference for RSA being phased out in the PQC transition.
Web page · 190 KB · a long read
Introduces chain ID into Ethereum transaction signing to prevent cross-chain replay attacks.
Web page · 18 KB · a quick skim
Authoritative list of cryptographic modules currently undergoing FIPS 140-3 validation. Queue backlog often 18–24 months; critical for Assurance-pillar monitoring.
Web page · 143 KB · a short read
Authoritative searchable database of FIPS 140-2/140-3 validated modules with cert number, status (active/historical/revoked), sunset date, and platform binding.
Web page · 51 KB · a short read
Algorithm-level validation protocol. NIST's ACVTS speaks ACVP to test implementations for CAVP, which issues the algorithm validation certificate a FIPS 140-3 module cert requires; ACVP itself is the protocol, not the certifying program. Each FIPS 203/204/205 revision requires a fresh CAVP algorithm re-validation.
Web page · 316 KB · a long read
This specification defines a lossless compressed data format that compresses data using a combination of the LZ77 algorithm and Huffman coding, with efficiency comparable to the best currently available general-purpose compression methods.
Web page · 1.1 MB · a long read
ETSI QSC overview of post-quantum algorithmic families including lattice-based, code-based, hash-based, and multivariate schemes. Provides framework for assessing PQC primitives for key establishment and authentication.
PDF · 426 KB · a long read
Transport Layer Security (TLS) handshakes often include fairly static information, such as the server certificate and a list of trusted certification authorities (CAs). This information can be of considerable size, particularly if the server certificate is bundled with a complete certificate chain (i.e., the certificates of intermediate CAs up to the root CA). This document defines an extension
Web page · 43 KB · a short read
Defines TLS and DTLS 1.2 profiles (PSK, raw public key and certificate modes, ciphersuites, certificate profile) for constrained IoT devices. Not PQC-specific; its ECC-based ciphersuites and certificate profile are what constrained deployments must migrate away from, and it is being updated by the TLS/DTLS 1.3 IoT profile draft.
Web page · 181 KB · a long read
Addresses business continuity planning for the post-quantum transition. Covers Certificate Authority re-assertion in PKI, algorithm selection criteria, and impact of Shor and Grover algorithms.
PDF · 81 KB · a short read
RFC documents contain a number of fixed elements such as the title page header, standard boilerplates, and copyright/IPR statements. This document describes them and introduces some updates to reflect current usage and requirements of RFC publication. In particular, this updated structure is intended to communicate clearly the source of RFC creation and review. This document obsoletes RFC 5741,
Web page · 213 KB · a long read
Methods for characterizing individual QKD components such as single-photon sources and detectors.
PDF · 923 KB · a long read
Foundational NIST report examining quantum computing threats to current cryptographic standards. Outlines the need for and announces the PQC standardization initiative that produced FIPS 203/204/205.
PDF · 200 KB · a short read
EU data protection regulation mandating appropriate technical measures including encryption to protect personal data. Article 32 requires state-of-the-art cryptographic controls; PQC transition relevant to long-term data protection.
PDF · 982 KB · a long read
Extends BIP-32 to support Ed25519 and other non-secp256k1 curves for HD derivation; required for Solana.
Web page · 421 KB · a long read
Commission Implementing Decision (EU) 2016/650 of 25 April 2016, setting the standards for the security assessment of qualified signature and seal creation devices under eIDAS Articles 30(3) and 39(2).
Web page · 280 KB · a long read
FERC’s security programme for hydropower projects, covering both physical and cyber controls at dams.
PDF · 437 KB · a long read
The EU profile for time-stamping protocol and token formats used by qualified trust services.
PDF · 70 KB · a short read
Comprehensive survey by Chris Peikert covering a decade of lattice-based cryptography, from foundational hardness problems (LWE, SIS, NTRU) through practical constructions. Essential reference for understanding the mathematical underpinnings of NIST-standardized ML-KEM and ML-DSA.
PDF · 704 KB · a long read
Ethereum standard for checksummed mixed-case hex address encoding using Keccak-256 to detect typos.
Web page · 22 KB · a quick skim
Estimation of the computational cost of generic quantum pre-image attacks on SHA-2 and SHA-3 using Grover’s algorithm on a surface-code-based fault-tolerant quantum computer.
PDF · 495 KB · a long read
NSA/CNSS policy governing the use of public/commercial cryptographic standards for secure information sharing across US national security systems; referenced alongside CNSA 2.0 in PQC transition planning documents.
PDF · 260 KB · a short read
Defines X25519 and X448 ECDH functions on Curve25519 and Curve448; used in hybrid PQC key exchange (ML-KEM + X25519) as the classical component per CNSA 2.0 guidance.
Web page · 49 KB · a short read
PDF · 578 KB · a long read
Web page · 1.1 MB · a long read
NIST program overview: CAVP provides validation testing of FIPS-approved cryptographic algorithms and their components. Labs test implementations via NIST's Automated Cryptographic Validation Test System (ACVTS), which speaks the ACVP protocol; CAVP itself issues the resulting algorithm validation certificate. Algorithm validation is a prerequisite for FIPS 140-3 module validation under CMVP.
Web page · 64 KB · a short read
How a lab or vendor gains access to NIST's Automated Cryptographic Validation Test System (ACVTS): the semi-volatile Demo environment (open request, a sandbox for testing ACVP client applications) versus the Prod environment (restricted to NVLAP-accredited CST and 17ACVT laboratories — the only environment that issues CAVP algorithm validation certificates).
Web page · 55 KB · a short read
IChemE Hazards 26 (2016) paper by a DNV GL functional-safety engineer summarising the changes in IEC 61511 Edition 2 for safety instrumented systems. Documents the new Clause 8.2.4 requirement that a security risk assessment of the SIS is mandatory (per Note 4 it may be done per SIF), referencing ISA TR84.00.09, ISO/IEC 27001:2013 and IEC 62443-2-1:2010 as guidance.
PDF · 509 KB · a long read
Activates Segregated Witness on Bitcoin separating signature data (witness) from transaction inputs. Introduces SegWit witness versioning (v0 P2WPKH/P2WSH, v1 Taproot). BIP-360 (P2QRH) introduces SegWit v3 (bc1r...) as a quantum-resistant output type building directly on this witness versioning scheme.
Web page · 26 KB · a quick skim
The European rail signalling standard for online key management — long-lived keys on infrastructure that is replaced on a decades-long cycle.
PDF · 1.6 MB · a reference document — dip in, don’t read it through
Directive establishing Strong Customer Authentication (Article 97) for EU payment services and the legal basis for third-party access to payment accounts (open banking) implemented by PISPs/AISPs.
Web page · 1.1 MB · a long read
Ethereum Homestead changes including stricter ECDSA signature malleability rules; foundational for Ethereum cryptographic security baseline referenced by noble/scure libraries.
Web page · 20 KB · a quick skim
Specifies BLAKE2b and BLAKE2s fast cryptographic hash functions; used in several PQC system implementations as a performance-optimized alternative to SHA-3.
Web page · 67 KB · a short read
Profile for key management systems used in U.S. federal agencies; referenced in PQC migration planning for key lifecycle and algorithm agility requirements.
PDF · 1.8 MB · a reference document — dip in, don’t read it through
This specification defines a method for protected resources to query an OAuth 2.0 authorization server to determine the active state and meta-information of an OAuth 2.0 token.
Web page · 223 KB · a long read
This specification defines a method for computing a hash value over a JSON Web Key (JWK). It defines which fields in a JWK are used in the hash computation, the method of creating a canonical form for those fields, and how to convert the resulting Unicode string into a byte sequence to be hashed. The resulting hash value can be used for identifying or selecting the key represented by the JWK tha
Web page · 187 KB · a long read
Defines SHA-3 (Keccak) and SHAKE128/SHAKE256 XOFs; SHAKE is used as the internal XOF in FIPS 203 (ML-KEM) and FIPS 205 (SLH-DSA).
PDF · 1.5 MB · a long read
Specifies SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/224, and SHA-512/256 hash functions. SHA-256 and SHA-512 are used in PQC hybrid signing mechanisms (CKM_SHA256_RSA_PKCS, CKM_ECDSA_SHA256) and as the digest algorithm in CMS SignedData firmware envelopes.
PDF · 833 KB · a long read
NIST standard defining three approved DRBG mechanisms (CTR_DRBG, Hash_DRBG, HMAC_DRBG) for generating pseudorandom bits from seed entropy. All mechanisms use symmetric primitives and are quantum-safe.
Web page · 83 KB · a short read
Formally deprecates SSLv3 (POODLE vulnerability); part of the protocol deprecation chain enabling TLS 1.3 adoption required for PQC hybrid key exchange.
Web page · 20 KB · a quick skim
Defines JWT as a compact URL-safe representation of claims between parties. Specifies the three-part structure (header.payload.signature), registered claim names (iss, sub, aud, exp, iat), and how JWS and JWE are used for signing and encryption. Foundation document for all JWT-based PQC migration work.
Web page · 84 KB · a short read
Defines the JWS standard for representing digitally signed content in JSON. Specifies the compact serialization (header.payload.signature) used in every signed JWT and the alg header parameter registry that PQC JOSE drafts extend with ML-DSA and SLH-DSA identifiers.
Web page · 166 KB · a long read
Defines the JWE standard for encrypting arbitrary content using JSON data structures. Specifies the 5-part compact serialization and key agreement mechanisms (ECDH-ES, RSA-OAEP) that ML-KEM replaces in PQC migration. Core reference for JWE encryption and PQC token confidentiality.
Web page · 138 KB · a short read
Defines the JWK format for representing cryptographic keys as JSON. JWKS endpoints publish public keys for JWT signature verification. PQC migration significantly increases JWKS response sizes: ML-DSA-65 public keys are 1952 bytes vs 65 bytes for P-256, challenging HTTP header limits and caching strategies.
Web page · 118 KB · a short read
Defines the algorithm registry for JOSE including RS256, ES256, ECDH-ES, AES-GCM, and HMAC. All currently registered signature and key agreement algorithms are quantum-vulnerable to Shor's algorithm. PQC JOSE drafts extend this registry with ML-DSA and ML-KEM algorithm identifiers.
Web page · 203 KB · a long read
Defines PEM label text encoding for X.509 certificates, PKCS#8 keys, and CMS structures; PQC keys (ML-KEM, ML-DSA) are encoded in these formats for interoperability.
Web page · 56 KB · a short read
The Ed25519 signature algorithm has been implemented in OpenSSH. This document updates the IANA "SSHFP RR Types for public key algorithms" registry by adding an algorithm number for Ed25519.
Web page · 100 KB · a short read
The base CI Plus technical specification (313 pages) governing CICAM/Host mutual authentication and link encryption in DVB conditional access. Normative Annex I specifies RSA signatures under PKCS#1 (RSASSA-PSS), and the Service Operator CRL is "signed by the Service Operator's private RSA key" and verified with the corresponding public key. Holds the cryptography that DVB BlueBook A165 defers to — A165 itself names no algorithm at all.
PDF · 7.5 MB · a reference document — dip in, don’t read it through
This document requires that Transport Layer Security (TLS) clients and servers never negotiate the use of RC4 cipher suites when they establish connections. This applies to all TLS versions. This document updates RFCs 5246, 4346, and 2246.
Web page · 117 KB · a short read
The Internet Key Exchange Version 2 (IKEv2) protocol has limited support for the Elliptic Curve Digital Signature Algorithm (ECDSA). The current version only includes support for three Elliptic Curve groups, and there is a fixed hash algorithm tied to each group. This document generalizes IKEv2 signature support to allow any signature method supported by PKIX and also adds signature hash algorit
Web page · 249 KB · a long read
This document describes a way to avoid IP fragmentation of large Internet Key Exchange Protocol version 2 (IKEv2) messages. This allows IKEv2 messages to traverse network devices that do not allow IP fragments to pass through.
Web page · 257 KB · a long read
C++ library implementing lattice reduction algorithms (LLL, BKZ) used for cryptanalysis of lattice-based PQC schemes.
Web page · 447 KB · a long read
Defines IKEv2 for establishing IPsec Security Associations. Foundational protocol for VPN key exchange; all PQC IKEv2 extensions (RFC 9370, draft-ietf-ipsecme-ikev2-mlkem) build on this specification.
Web page · 415 KB · a long read
The definitive practical demonstration of the NSA-inserted Dual_EC_DRBG kleptographic backdoor (Young-Yung SETUP construction, applied to an elliptic-curve PRNG) working end-to-end against real TLS implementations, including RSA BSAFE and OpenSSL-FIPS. This is a CLASSICAL cryptography backdoor, entirely unrelated to quantum computing — proof that current, widely-deployed crypto can be covertly broken today.
PDF · 365 KB · a short read
Original EU electronic identification and trust services regulation. Defines qualified electronic signatures, seals, and timestamps. Superseded by eIDAS 2.0 (EU 2024/1183) but basis for current QTSP compliance.
Web page · 615 KB · a long read
Regulation (EU) No 910/2014 on electronic identification and trust services, in its EUR-Lex consolidated form as amended by Regulation (EU) 2024/1183.
PDF · 729 KB · a long read
This document describes a Transport Layer Security (TLS) extension for application-layer protocol negotiation within the TLS handshake. For instances in which multiple application protocols are supported on the same TCP or UDP port, this extension allows the application layer to negotiate which protocol will be used within the TLS connection.
Web page · 144 KB · a short read
Allows TLS/DTLS to use raw public keys instead of X.509 certificates, eliminating certificate chain overhead on ultra-constrained IoT devices. ~70% size reduction.
Web page · 47 KB · a short read
IETF Standards Track specification of CoAP, a lightweight RESTful request/response protocol for constrained nodes and lossy networks, secured with DTLS (PreSharedKey, RawPublicKey or Certificate modes, with mandatory ECDHE-ECDSA on secp256r1 for the public-key modes). Not PQC-specific; it matters for PQC migration because its mandatory-to-implement DTLS key exchange and authentication are classical elliptic-curve algorithms embedded in long-lived IoT devices.
Web page · 320 KB · a long read
Defines terminology and device classes (Class 0-2) for constrained-node IoT networks, including RAM/Flash constraints. Foundation for IoT PQC algorithm selection.
Web page · 46 KB · a short read
Defines multi-coin and multi-account HD wallet derivation path structure across blockchains.
Web page · 7 KB · a quick skim
Bitcoin Improvement Proposal defining the purpose field for BIP-32 HD wallet derivation paths; referenced by noble/secp256k1 and @scure/bip32 cryptographic libraries in the library.
Web page · 284 KB · a long read
Formal specification of the Ethereum Virtual Machine by Gavin Wood. Defines Keccak-256 address derivation and ECDSA signing.
PDF · 598 KB · a long read
Free quick-reference guide to PCI DSS v4.0 — full standard paywalled, QRG is freely redistributable.
PDF · 1.5 MB · a long read
South Africa national personal-information protection law — crypto/key-management considered under security-safeguards obligation.
Web page · 41 KB · a short read
IETF automated cert enrollment protocol, alongside ACME and CMP. Common for internal PKI under the CLM automation umbrella.
Web page · 604 KB · a long read
Standard for encoding entropy as a human-readable mnemonic phrase for wallet seed backup and recovery.
Web page · 7 KB · a quick skim
This document proposes an additional endpoint for OAuth authorization servers, which allows clients to notify the authorization server that a previously obtained refresh or access token is no longer needed. This allows the authorization server to clean up security credentials. A revocation request will invalidate the actual token and, if applicable, other tokens based on the same authorization g
Web page · 178 KB · a long read
This document defines a deterministic digital signature generation procedure for DSA and ECDSA that eliminates the need for high-quality randomness during signature generation.
Web page · 542 KB · a long read
This document specifies a protocol useful in determining the current status of a digital certificate without requiring Certificate Revocation Lists (CRLs). Additional mechanisms addressing PKIX operational requirements are specified in separate documents. This document obsoletes RFCs 2560 and 6277. It also updates RFC 5912.
Web page · 420 KB · a long read
This document proposes an experiment to increase the permitted TCP initial window (IW) from between 2 and 4 segments, as specified in RFC 3390, to 10 segments with a fallback to the existing recommendation when performance issues are detected. It discusses the motivation behind the increase, the advantages and disadvantages of the higher initial window, and presents results from several large-sca
Web page · 316 KB · a long read
This document specifies how DNS resource records are named and structured to facilitate service discovery. Given a type of service that a client is looking for, and a domain in which the client is looking for that service, this mechanism allows clients to discover a list of named instances of that desired service, using standard DNS queries. This mechanism is referred to as DNS-based Service Dis
Web page · 536 KB · a long read
The Advanced Access Content System’s cryptographic elements — a long-lived content-protection scheme with keys embedded in shipped hardware.
PDF · 1.9 MB · a reference document — dip in, don’t read it through
This specification describes how to use bearer tokens in HTTP requests to access OAuth 2.0 protected resources. Any party in possession of a bearer token (a "bearer") can use it to get access to the associated resources (without demonstrating possession of a cryptographic key). To prevent misuse, bearer tokens need to be protected from disclosure in storage and in transport. [STANDARDS-TRACK]
Web page · 243 KB · a long read
Defines the OAuth 2.0 authorization framework enabling secure delegated access using access tokens. Access tokens and ID tokens issued by authorization servers are typically JWTs signed with RSA or ECDSA. PQC migration requires updating JWT signing across all OAuth authorization servers and resource server token validation.
Web page · 202 KB · a long read
NIST's risk-assessment methodology, including the five-level qualitative scale (Very Low / Low / Moderate / High / Very High) used for likelihood and impact. Anchors the 5x5 risk matrices in the Command Center's Risk Register and Risk Heatmap tools.
PDF · 827 KB · a long read
This document updates the IANA registries in RFC 4255, which defines SSHFP, a DNS Resource Record (RR) that contains a standard Secure Shell (SSH) key fingerprint used to verify SSH host keys using DNS Security Extensions (DNSSEC). This document defines additional options supporting SSH public keys applying the Elliptic Curve Digital Signature Algorithm (ECDSA) and the implementation of fingerpri
Web page · 178 KB · a long read
Defines HD wallet key derivation from a single seed enabling deterministic generation of unlimited key pairs.
Web page · 28 KB · a quick skim
ANSI standard specifying ECDH key agreement for financial services; a predecessor to NIST SP 800-56A for institutional adoption.
Web page · 33 KB · a quick skim
Reference implementation and specification of SHA-224/256/384/512 (SHA-2) and HMAC/HKDF derivations; cited by PQC hybrid KDF specifications.
Web page · 272 KB · a long read
Formally prohibits SSL 2.0; part of the TLS deprecation chain alongside RFC 7568 (SSLv3) and RFC 8996 (TLS 1.0/1.1) that clears the path for TLS 1.3 + PQC hybrid.
Web page · 11 KB · a quick skim
Provides compact ECC algorithm descriptions for IETF implementers; referenced as an ECC foundation in documents discussing classical-to-PQC algorithm displacement.
Web page · 103 KB · a short read
NIST SP 800-132 specifies PBKDF2 for password-based key derivation in IAM systems, credential vaults, and token signing key derivation. Quantum-safe when using PBKDF2-SHA-256 with sufficient iterations (≥10,000); key length should be ≥256 bits.
PDF · 129 KB · a short read
Defines QKD system components and their internal interfaces for interoperability.
PDF · 1.2 MB · a long read
Framework for security proofs of QKD protocols including BB84 and related variants.
PDF · 141 KB · a short read
Security requirements and evaluation criteria for QKD modules analogous to Common Criteria.
PDF · 322 KB · a short read
A trust anchor represents an authoritative entity via a public key and associated data. The public key is used to verify digital signatures, and the associated data is used to constrain the types of information for which the trust anchor is authoritative. A relying party uses trust anchors to determine if a digitally signed object is valid by verifying a digital signature using the trust anchor'
Web page · 221 KB · a long read
This document specifies a new ASN.1 type for representing time: BinaryTime. This document also specifies an alternate to the signing-time attribute for use with the Cryptographic Message Syntax (CMS) SignedData and AuthenticatedData content types; the binary-signing-time attribute uses BinaryTime. CMS and the signing-time attribute are defined in RFC 5652. [STANDARDS-TRACK]
Web page · 113 KB · a short read
Defines OneAsymmetricKey (PKCS#8v2) for private key storage; used in PQC key serialization for ML-KEM and ML-DSA private keys exported from HSMs.
Web page · 35 KB · a quick skim
Use cases for quantum key distribution including government communications and financial networks.
PDF · 893 KB · a long read
ASN.1 2002 syntax modules for PKIX including certificates, CRL, and OCSP — foundational for PQC composite certificate encoding.
Web page · 244 KB · a long read
ASN.1 2002 syntax modules for CMS and S/MIME; used by PQC composite signature and KEM RFCs for algorithm identifier structures.
Web page · 118 KB · a short read
Web page · 39 KB · a quick skim
This document specifies how to use the Session Initiation Protocol (SIP) to establish a Secure Real-time Transport Protocol (SRTP) security context using the Datagram Transport Layer Security (DTLS) protocol. It describes a mechanism of transporting a fingerprint attribute in the Session Description Protocol (SDP) that identifies the key that will be presented during the DTLS handshake. The key
Web page · 432 KB · a long read
RFC 5869 defines HKDF: HKDF-Extract(salt, IKM) → PRK binds input keying material to a salt; HKDF-Expand(PRK, info, L) derives L bytes bound to a context string preventing cross-protocol key reuse (§3.2). Used in TLS 1.3, IKEv2, and PQC envelope encryption to derive AES wrapping keys from ML-KEM shared secrets per SP 800-56C Rev 2 §4.
Web page · 33 KB · a quick skim
NIST statistical test suite defining 15 statistical tests (Monobit, Runs, Chi-Squared, DFT, Serial, and more) for evaluating randomness quality of bit sequences produced by cryptographic RBGs. Used for validating entropy source output quality prior to NIST ESV submission.
PDF · 7.6 MB · a reference document — dip in, don’t read it through
SECG standard defining domain parameters for secp256k1 and other elliptic curves used by Bitcoin and Ethereum.
PDF · 307 KB · a short read
Oded Regev’s foundational survey introducing and analysing the Learning with Errors (LWE) problem. LWE is the core hardness assumption underlying ML-KEM (FIPS 203) and ML-DSA (FIPS 204). Won the 2018 Gödel Prize. Essential reading for understanding why lattice-based PQC is believed to be quantum-resistant.
PDF · 652 KB · a long read
Specifies how to use SHA-224, SHA-256, SHA-384, SHA-512 within CMS (PKCS#7) for digital signatures and message authentication.
Web page · 30 KB · a quick skim
PDF · 16.0 MB · a reference document — dip in, don’t read it through
Elliptic Curve Algorithm Integration in the Secure Shell Transport Layer
Web page · 257 KB · a long read
RFC 5649 extends RFC 3394 AES Key Wrap with a padding scheme for arbitrary-length plaintexts. The 8-byte Alternative Initial Value (AIV) includes a fixed 4-byte constant (0xA65959A6) and a 4-byte plaintext length. Wrapping a 32-byte DEK produces 48 bytes. Used as CKM_AES_KEY_WRAP_KWP in PKCS#11 v3.2.
Web page · 156 KB · a long read
Core CMS standard defining SignedData, EnvelopedData, and AuthEnvelopedData structures. Foundation for S/MIME email signing and encryption. All PQC CMS RFCs (9629, 9882, 9814, 9708, 9690) extend this format.
Web page · 153 KB · a long read
SECG SEC 1 v2.0 defines elliptic curve public key operations, point encoding, and ECIES; widely implemented in TLS, SSH, and PKCS#11 stacks undergoing PQC migration.
PDF · 970 KB · a long read
Elliptic Curve Cryptography Subject Public Key Information
Web page · 218 KB · a long read
Health Information Technology for Economic and Clinical Health Act — HIPAA breach notification, ePHI encryption incentives.
Web page · 1.4 MB · a long read
PDF · 78 KB · a short read
Foundational academic book edited by Daniel J. Bernstein and Tanja Lange (Springer 2009) covering all major families of post-quantum cryptography: lattice-based, code-based, hash-based, and multivariate. Essential reference for understanding the mathematical foundations of PQC algorithms before the NIST standardization era.
Web page · 269 KB · a long read
Satoshi Nakamoto foundational paper introducing Bitcoin and blockchain: proof-of-work consensus and ECDSA-based ownership.
PDF · 184 KB · a short read
FIPS 198-1 specifies HMAC, a mechanism for message authentication using cryptographic hash functions. HMAC-SHA-256 is used for session token integrity in IAM. Quantum-safe: HMAC based on SHA-2/SHA-3 remains secure post-quantum assuming ≥256-bit output.
PDF · 129 KB · a short read
Establishes X.509 v3 certificate format, extensions, revocation lists, and PKI path validation; foundational reference for hybrid and pure PQC certificate formats.
Web page · 417 KB · a long read
Internet technical specifications often need to define a formal syntax. Over the years, a modified version of Backus-Naur Form (BNF), called Augmented BNF (ABNF), has been popular among many Internet specifications. The current specification documents ABNF. It balances compactness and simplicity with reasonable representational power. The differences between standard BNF and ABNF involve namin
Web page · 205 KB · a long read
Web page · 281 KB · a long read
Defines AuthEnvelopedData content type for AEAD-based encryption in CMS. The authenticated-enveloped structure with AES-GCM provides both confidentiality and integrity — the preferred encryption mode for PQC email migration via RFC 9629.
Web page · 28 KB · a quick skim
Guide to Storage Encryption Technologies for End User Devices
PDF · 224 KB · a short read
NIST SP 800-38D specifies GCM and GMAC for AES. GCM provides authenticated encryption using a 96-bit (12-byte) nonce and a 16-byte authentication tag appended to ciphertext. Nonce uniqueness per key is mandatory — reuse lets an attacker recover the keystream and forge authentication tags (SP 800-38D §8). Used as CKM_AES_GCM in PKCS#11 v3.2.
PDF · 272 KB · a short read
Framework for tying application-layer authentication to the security context of the underlying channel; relevant for hybrid PQC channel binding in TLS and IKEv2.
Web page · 63 KB · a short read
Anti-Money Laundering and Counter-Terrorism Financing Act 2006 — enforced by AUSTRAC. Regulated reporting entities (banks, fintechs, crypto exchanges, and post-2024 reforms: lawyers, accountants, real estate agents) must maintain secure cryptographic systems for AUSTRAC reporting and transaction record-keeping. Integrity and authenticity controls over financial intelligence data are in scope.
Web page · 290 KB · a long read
Public Key Cryptography for Initial Authentication in Kerberos (PKINIT)
Web page · 452 KB · a long read
ISO/IEC 18033-2 specifies asymmetric encryption algorithms including RSA-OAEP and HIME(R); referenced in cross-national cryptographic equivalence analyses for PQC transition.
Web page · 102 KB · a short read
Defines runtime DH group negotiation for SSH-2; the PQC SSH drafts replace this with ML-KEM key exchange while maintaining the group exchange signaling model.
Web page · 23 KB · a quick skim
This document describes a method of verifying Secure Shell (SSH) host keys using Domain Name System Security (DNSSEC). The document defines a new DNS resource record that contains a standard SSH key fingerprint. [STANDARDS-TRACK]
Web page · 158 KB · a long read
Defines the SSH architectural framework covering transport layer, user authentication, and connection multiplexing for secure remote access.
Web page · 89 KB · a short read
Defines the SSH transport layer including key exchange, server authentication, and encryption. The key exchange phase is where QKD-derived pre-shared keys can be injected via the ext-info mechanism or future SSH KEX extensions. Foundational standard for understanding QKD integration into SSH.
Web page · 86 KB · a short read
Amendment 1 to ISO/IEC 18033-2, adding the FACE asymmetric cipher. Classical, NOT post-quantum — the row previously claimed "Post-Quantum KEMs including FrodoKEM alignment" and linked to an unrelated standard (ISO 8144-1 mineral wool insulation). The post-quantum content of ISO/IEC 18033-2 is in Amendment 2:2026 (FrodoKEM, Classic McEliece, ML-KEM).
Web page · 80 KB · a short read
Registry of SSH protocol algorithm names and identifiers; being updated to include ML-KEM and ML-DSA algorithm names for post-quantum SSH key exchange.
Web page · 63 KB · a short read
Defines the SSH-2 user authentication layer; being updated for PQC public-key authentication methods using ML-DSA host keys.
Web page · 43 KB · a short read
Defines the SSH-2 connection multiplexing protocol; the connection layer operates over PQC-secured channels when quantum-resistant key exchange is negotiated.
Web page · 62 KB · a short read
The 2026 amendment adding post-quantum KEMs to the ISO/IEC 18033-2 encryption-algorithms standard.
Web page · 84 KB · a short read
Aviation information-security concepts and process framework — the vocabulary an aircraft programme uses when arguing a cryptographic change is safe.
Web page · 142 KB · a short read
Provides the IPsec architectural framework for security services at the IP layer; foundation for all IKEv2 and ESP PQC migration work.
Web page · 299 KB · a long read
Defines the ESP protocol for confidentiality, data origin authentication, integrity, and anti-replay in IPv4/IPv6; requires PQC-aware encryption updates.
Web page · 131 KB · a short read
Defines the IPsec AH protocol for data origin authentication and integrity; used in IKEv2 tunnels being updated for PQC algorithm negotiation.
Web page · 100 KB · a short read
ANSI standard specifying ECDSA for financial services; defines elliptic curve parameters and signature operations now being superseded by ML-DSA in PQC migration.
Web page · 33 KB · a quick skim
Specifies RSASSA-PSS algorithm identifier for X.509 certificates; relevant for hybrid certificate schemes combining classical RSA with PQC signatures.
Web page · 16 KB · a quick skim
Core SAML 2.0 specification defining XML-based authentication and authorization assertions used in enterprise SSO and identity federation. PQC migration requires replacing RSA/ECDSA XML signatures with ML-DSA equivalents.
PDF · 630 KB · a long read
Base DNSSEC RR formats (DNSKEY, RRSIG, NSEC, DS). Classical-only; PQ adoption pending IANA codepoint assignment.
Web page · 139 KB · a short read
ANSSI cryptographic algorithm rules and recommendations v3.00 — first update since 2020 and first version to explicitly address the quantum threat. Covers symmetric crypto (AES, block/stream ciphers, MAC, hash), asymmetric crypto (factorisation, discrete log, lattice/LWE), key encapsulation, digital signatures, entity authentication, and random number generation. Licensed Licence Ouverte v2.0.
PDF · 1.4 MB · a long read
IEEE 1363a extends IEEE 1363 with additional DL-based schemes; referenced alongside its parent standard in legacy cryptography displacement analysis.
Standards for Security Categorization of Federal Information and Information Systems
Web page · 44 KB · a short read
This document presents a framework to assist the writers of certificate policies or certification practice statements for participants within public key infrastructures, such as certification authorities, policy authorities, and communities of interest that wish to rely on certificates. In particular, the framework provides a comprehensive list of topics that potentially (at the writer's discreti
Web page · 817 KB · a long read
Specifies RSASSA-PSS for CMS SignedData; RSASSA-PSS is the preferred RSA signature scheme in FIPS 186-5 and is referenced in PQC hybrid signature composite RFCs.
Web page · 45 KB · a short read
Defines the AES key wrap algorithm used to protect symmetric keys in CMS and PKCS#11; used in hybrid PQC schemes that wrap classical keys with ML-KEM-derived symmetric keys.
Web page · 119 KB · a short read
Specifies RSA, DSA, DH, and hash algorithm identifiers for CMS; the PQC CMS RFCs (RFC 9629, draft composites) augment this with ML-KEM/ML-DSA identifiers.
Web page · 63 KB · a short read
Web page · 46 KB · a short read
Defines the Time-Stamp Protocol. Timestamps must remain verifiable for decades, which makes them one of the sharpest post-quantum signature problems.
Web page · 55 KB · a short read
IEEE 1363 defines RSA, DL, and EC public-key schemes including ECDH, ECDSA, and ECIES; foundational reference for classical algorithms being superseded in PQC migration.
The original code of practice for information security management, ancestor of ISO/IEC 27002. Cited where legacy control mappings still reference it.
Web page · 76 KB · a short read
Risk management for medical devices. Governs whether a cryptographic change to a device is treated as a design change requiring re-assessment.
Web page · 78 KB · a short read
US Children's Online Privacy Protection Rule — consent and data-handling for services directed to under-13 users.
Web page · 159 KB · a long read
A new URL scheme, "data", is defined. It allows inclusion of small data items as "immediate" data, as if it had been included externally. [STANDARDS-TRACK]
Web page · 107 KB · a short read
US FDA rule for electronic records and signatures in FDA-regulated activities — crypto and audit-trail controls.
Web page · 109 KB · a short read
Defines normative requirement level keywords (MUST, SHOULD, MAY, etc.) used throughout IETF RFCs including all PQC protocol specifications.
Web page · 6 KB · a quick skim
NIAP administers the U.S. implementation of Common Criteria; mandates evaluated cryptographic modules meet CNSA 2.0 algorithm requirements as PQC standards are finalized.
Web page · 84 KB · a short read
US Health Insurance Portability and Accountability Act Security Rule — administrative, physical, and technical safeguards for ePHI.
Web page · 686 KB · a long read
This specification defines a lossless compressed data format. This memo provides information for the Internet community. This memo does not specify an Internet standard of any kind.
Web page · 140 KB · a short read
Defines MIME multipart/signed and multipart/encrypted content types; foundational for S/MIME which is being updated for PQC algorithm identifiers.
Web page · 67 KB · a short read
Privacy Act 1988 (Cth) with Australian Privacy Principles — enforced by the OAIC. APP 11 requires organisations to take reasonable steps to protect personal information, including robust cryptographic controls. Harvest-now-decrypt-later attacks on personal financial data directly implicate long-term cryptographic security. 2024 reforms increased penalties up to AU$50M for serious breaches.
Web page · 299 KB · a long read
US Family Educational Rights and Privacy Act — education records privacy requirements.
Web page · 281 KB · a long read
PDF · 124 KB · a short read
Web page · 82 KB · a short read
Web page · 135 KB · a short read
Web page · 146 KB · a short read
Web page · 158 KB · a long read
Web page · 141 KB · a short read
PDF · 243 KB · a short read
Web page · 47 KB · a short read
Web page · 354 KB · a long read
PDF · 198 KB · a short read
Web page · 75 KB · a short read
Web page · 41 KB · a short read
Web page · 305 KB · a long read
PDF · 2.4 MB · a reference document — dip in, don’t read it through
PDF · 4.5 MB · a reference document — dip in, don’t read it through
PDF · 1.2 MB · a long read
Web page · 59 KB · a short read
Web page · 142 KB · a short read
Official Solana developer documentation for transaction structure. States each signer provides one 64-byte Ed25519 signature per transaction, including validator vote transactions (ordinary transactions in Solana's architecture, not a separate consensus-layer scheme). Also documents the 1,232-byte max transaction size (IPv6 MTU-derived) and 150-slot blockhash expiry.
Web page · 796 KB · a long read
Cardano Improvement Proposal documenting the key-derivation algorithms used across the Cardano wallet ecosystem. Cardano HD wallets use a variation of BIP-32 called ED25519-BIP32 (extended Ed25519): the master key is a 96-byte extended private key (64-byte extended Ed25519 secret key + 32-byte chain code). Documents four historical master-key schemes (Byron, deprecated; Icarus, current recommended; Icarus-Trezor; Ledger/BitBox02).
Web page · 278 KB · a long read
IntersectMBO/cardano-base source file (cardano-crypto-praos/cbits/crypto_vrf.h) pinning Cardano's production VRF choice: 'SUITE = 0x04 /* ECVRF-ED25519-SHA512-ELL2 */', built on the ietfdraft13 primitive — the suite RFC 9381 (Verifiable Random Functions) later standardized as ECVRF-EDWARDS25519-SHA512-ELL2, suite_string 0x04.
Web page · 288 KB · a long read
IOG's Rust implementation of Cardano's Key-Evolving Signature (KES) scheme: the 'sum' composition from Malkin/Micciancio/Miner's forward-secure-signature paper, using Ed25519 (via ed25519_dalek, strict verification) as the depth-zero signature algorithm. Cardano production uses Sum6Kes (2^6 = 64 key evolutions); SumCompact6Kes offers an asymptotically smaller signature.
Web page · 282 KB · a long read
Chainlink Labs research paper specifying OCR3, the off-chain consensus protocol behind Chainlink's price/data-feed oracle network. Digital signatures use standard elliptic-curve schemes: protocol-internal node-to-node signatures are 'typically' EdDSA, while the final on-chain attestation a consuming smart contract verifies is 'typically implemented by ECDSA' — the paper is explicit that the exact scheme depends on context and the target blockchain, not a single fixed algorithm.
PDF · 1.1 MB · a long read
Safe (formerly Gnosis Safe) smart-account contract source. checkNSignatures() enforces an M-of-N owner threshold on-chain: each of the required signatures is verified independently — ECDSA via ecrecover by default, plus EIP-1271 contract signatures, EIP-191, pre-approved hashes, and secp256r1/passkey signatures via the RIP-7212 precompile — with owner addresses required in strict ascending order to prevent duplicate counting. A plain multisig, not an aggregated threshold signature scheme.
Web page · 129 KB · a short read
Official Wormhole documentation for VAAs (Verifiable Action Approvals) — the cross-chain message-attestation format signed by Wormhole's 19-member Guardian network. Each Guardian independently ECDSA-signs a keccak256 double-hash of the message body; once 13 of 19 (two-thirds supermajority) signatures are collected, they are combined with the message into a VAA. A plain M-of-N multisig, not an aggregated threshold signature.
Web page · 172 KB · a long read
Official Polkadot Wiki page on cryptography. Documents three account-signing options — sr25519 (Schnorrkel, primary), Ed25519, and ECDSA/secp256k1 — and states BABE consensus uses sr25519 keys because they support both VRF and digital-signature roles. Notes 'no differences in security between ed25519 and sr25519 for simple signatures.'
Web page · 129 KB · a short read
Official CometBFT documentation for validators. States 'Currently CometBFT uses Ed25519 keys which are widely supported across the security sector and HSMs' for signing consensus votes/precommits — the consensus engine underlying the Cosmos Hub and every Cosmos SDK chain.
Web page · 485 KB · a long read
Official Avalanche developer documentation for cryptographic primitives. States: 'The Avalanche virtual machine uses elliptic curve cryptography, specifically secp256k1, for its signatures on the blockchain.' X-Chain/P-Chain addressing also relies on secp256k1, hashing the ECDSA public key like Bitcoin.
Web page · 675 KB · a long read
Official Avalanche developer documentation for Interchain Messaging (ICM, formerly Avalanche Warp Messaging). 'ICM uses the BLS signature scheme, which allows message recipients to verify the authenticity of these messages... every validator on the Avalanche network holds a BLS key pair.' Signatures from a threshold of the source subnet's stake are aggregated into a single BLS multi-signature — a genuine aggregated threshold signature, unlike the plain N-signature multisig Wormhole and Safe use.
Web page · 603 KB · a long read
Official Arbitrum documentation for the AnyTrust protocol. AnyTrust chains use a Data Availability Committee (DAC, N members, 2-of-N honesty assumption): each member signs (data hash, expiry) with a BLS key; once enough signatures are collected the sequencer aggregates them into 'a BLS aggregated signature (over the BLS12-381 curve)' forming a DACert, posted to the L1 inbox contract. No mention of ECDSA for this specific mechanism — it is BLS end to end.
Web page · 32 KB · a quick skim
ETSI TS 135 216 V17.0.0 (2022-04), 'Specification of the 3GPP Confidentiality and Integrity Algorithms UEA2 & UIA2; Document 2: SNOW 3G specification.' The stream cipher underlying UMTS/LTE's 128-EEA1/128-EIA1 confidentiality and integrity algorithms.
PDF · 81 KB · a short read
ETSI TS 135 222 V17.0.0 (2022-04), 'Specification of the 3GPP Confidentiality and Integrity Algorithms EEA3 & EIA3; Document 2: ZUC specification.' The stream cipher underlying LTE's 128-EEA3/128-EIA3 algorithms, carried forward into 5G.
PDF · 79 KB · a short read
Internet2, with Ciena and Purism, ran a live PQC demonstration on a 1,390-mile Albuquerque-Las Vegas segment of the Internet2 national R&E backbone: 'FIPS 203-compliant solution was used for both quantum-safe encryption and quantum-safe key exchange,' at 10 Gbps line rate.
Web page · 145 KB · a short read
IETF LAMPS WG composite-signature draft, version 19, now in the RFC Editor Queue awaiting publication: 'This document defines combinations of ML-DSA in hybrid with traditional algorithms RSASSA-PKCS1-v1.5, RSASSA-PSS, ECDSA, Ed25519, and Ed448.' Defines composite X.509 certificate signing, not a TLS-handshake profile.
Web page · 799 KB · a long read
GSMA official guidance (v1.0, 2024-11-25) on PQC for IoT, including eSIM/Remote SIM Provisioning (RSP): names ML-KEM (FIPS 203), ML-DSA (FIPS 204), SLH-DSA (FIPS 205), LMS and XMSS as the target algorithms, and states 'RSP for IoT is vulnerable to quantum attacks due to the recommended use of TLS, DTLS and recommended cipher suites that include asymmetric cryptography (e.g. in form of ECDHE, ECDSA, etc.)... The GSMA eSIM Group is actively working on a PQC version of RSP.'
PDF · 647 KB · a long read
BFO (PDF software vendor) blog account of the first ML-DSA-signed and SLH-DSA-signed PDF exchanges with Adobe (May 2025), and an agreement at PDF Days 2025 to formally add these algorithms to the PDF specification. Provisional — the formal PDF Association/ISO 32000 specification text had not yet landed as of this fetch; cited here as evidence of real, already-happened vendor interoperability testing, not a ratified standard.
Web page · 29 KB · a quick skim
PCI Security Standards Council's own blog on key-block requirements for POS/PIN key management: 'the PCI SSC recommends that entities... migrate to AES as it is a stronger cryptographic algorithm' than Triple DES (TDES), and 'both AES and TDES keys are required to be managed in key blocks as stipulated by ANSI X9.' Classical-only — no PQC content.
Web page · 85 KB · a short read
Apple's own developer documentation for processing Apple Pay payment tokens: 'Reading, verifying, and processing payment information requires an understanding of several areas of cryptography such as calculating an SHA-1 hash, reading and validating a PKCS #7 signature, and performing elliptic curve Diffie-Hellman key exchange.' Classical-only — no PQC content.
Web page · 14 KB · a quick skim
W3C Secure Payment Confirmation spec — strong customer authentication at online checkout, built on WebAuthn/FIDO2. Names ES256 (ECDSA) and RS256 (RSA) in its normative registration/authentication examples. Classical-only — no PQC content.
Web page · 612 KB · a long read
AWS's own security blog announcing GA: 'AWS Key Management Service (AWS KMS), AWS Certificate Manager (ACM), and AWS Secrets Manager endpoints now support Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) for hybrid post-quantum key agreement... in all AWS Regions,' hybridized with X25519.
Web page · 1.1 MB · a long read
Google Cloud's own product blog announcing GA: 'we are announcing the general availability of our quantum-safe digital signatures (ML-DSA, SLH-DSA) and post-quantum key encapsulation (ML-KEM) in Google Cloud Key Management Service (Cloud KMS),' naming ML-DSA-44/65/87 and SLH-DSA-SHA2-128s parameter sets.
Web page · 282 KB · a long read
Securosys (Swiss HSM manufacturer) product announcement: 'The CyberVault Series implements the HSS-LMS and XMSS algorithms and has already received NIST certification for the recently released ML-KEM, ML-DSA, and SLH-DSA algorithms.' Vendor-stated certification claim, not independently verified against the CMVP database in this pass.
Web page · 244 KB · a long read
ACS ACOSJ-P Java Card smart-card product spec sheet, listing "SM2/SM3/SM4" under Cryptographic Features alongside DES/3DES/RSA/SHA, directly next to "Compliant with PBOC 3.0 Debit/Credit" and "Compliant with PBOC 3.0 QPBOC" certification lines — cited as evidence that Chinas national SM2 signature algorithm is a real, deployed option in PBOC 3.0 payment cards, not a paper standard.
Web page · 93 KB · a short read
Official PCI SSC reporting template restating PCI PIN v3.1 requirements verbatim. Requirement 1-3: "All hardware security modules (HSMs) shall be either: FIPS140-2 or FIPS 140-3 Level 3 or higher certified, or PCI approved." Cited because the PCI PIN standard PDF itself sits behind a click-through agreement gate (excluded per the no-gated-sources rule); this template is the same PCI SSC primary text, freely retrievable.
PDF · 3.0 MB · a reference document — dip in, don’t read it through
The PCI PTS HSM approval program standard. Its own scope statement limits it to payment functions (PIN processing, 3-D Secure, card production, key generation/injection) and states it "does not aim to develop a standard for general-purpose HSMs".
PDF · 819 KB · a long read
Section 7.14(c): "HSMs used for key management or otherwise used for the protection of sensitive data must be approved by PCI or certified to FIPS 140-2 or 140-3 Level 3 or higher certification for physical security." Retrieved from a third-party host because pcisecuritystandards.org gates the document; cover page verified genuine PCI SSC.
PDF · 1.9 MB · a reference document — dip in, don’t read it through
Requirement P2-6.1.2 (ACS and DS roles only): key management performed using an HSM that is either "FIPS 140-2 Level 3 (overall) or higher certified, or PCI PTS HSM approved". Note this document references FIPS 140-2 only — it has not been updated to 140-3, unlike PCI PIN v3.1.
PDF · 1.5 MB · a long read
Requirement 1A-1.1 requires account-data encryption on a PCI PTS POI device approved with SRED. Requirement 4A-1.1 sets the HSM bar at "FIPS 140-2 or 140-3 Level 3 (overall) or higher certified". Its applicability matrix writes "Level 3 or 4" as prose for "or higher" — not a Level 4 mandate. Superseded by P2PE v3.2 (June 2025); v3.2 is not publicly downloadable, so v3.1 is cited as the last public text.
PDF · 2.0 MB · a reference document — dip in, don’t read it through
Section 6.2.11 Cryptographic Module Rating: "The SWIFTNet PKI CA uses an HSM that is compliant with FIPS 140-1 or FIPS 140-2 Level 3. Subscribers use HSMs that comply with minimally FIPS 140-1 or 140-2 level 2." The subscriber floor (Level 2) is lower than the Level 3 asserted in the CSCF; no SWIFT document reconciles the two.
PDF · 232 KB · a short read
Section IV para 5: "All COTS IA and IA-enabled IT products acquired for use to protect information on NSS shall comply with the requirements of the NIAP program in accordance with NSA-approved processes and, where applicable, the requirements of the Federal Information Processing Standard (FIPS) Cryptographic validation program(s)." Scope is National Security Systems only.
PDF · 451 KB · a long read
Section 5.2.4.3: "Cryptographic hardware security modules used in cloud-based KMS must have received FIPS 140-2 or FIPS 140-3 Level 3 accreditation" and "Cloud-based KMS components must have been evaluated against and determined to comply with applicable National Information Assurance Partnership (NIAP) Protection Profiles." This — not FedRAMP — is the real US federal Level 3 mandate for cloud KMS/HSM.
PDF · 2.7 MB · a reference document — dip in, don’t read it through
UnionPay’s own terminal security certification scheme, effective 2025-01-07. Read in full: contains ZERO occurrences of PCI, PTS, POI, FIPS, EAL, ISO 15408 or Common Criteria. Testing basis is UnionPay’s own 《中国银联支付受理终端安全规范》; the only compulsory external certification named is China 3C.
PDF · 253 KB · a short read
Annex I point 1 (adapting ETSI EN 319 411-2 clause 6.5.2, GEN-6.5.2-02): TSP key generation "shall be carried out within a secure cryptographic device which is a trustworthy system certified in accordance with: Common Criteria ... EAL 4 or higher; or the European Common Criteria-based cybersecurity certification scheme (EUCC) ... EAL 4 or higher; or until 31.12.2030, FIPS PUB 140-3 level 3." Three ALTERNATIVE routes, with the FIPS route sunsetting 2030-12-31.
Web page · 40 KB · a quick skim
Annex point 1(6) (adapting ETSI EN 319 421 clause 7.6.2, TIS-7.6.2-03): TSU key generation must occur in a secure cryptographic device certified to Common Criteria EAL 4+, or EUCC EAL 4+, or until 31.12.2030 FIPS PUB 140-3 level 3. eIDAS Article 42 itself imposes no cryptographic-module requirement; it enters solely via this implementing act.
Web page · 25 KB · a quick skim
Requires the wallet secure cryptographic device to be evaluated at EAL4 with AVA_VAN.5 under EUCC. Contains ZERO occurrences of FIPS — unlike the qualified-trust-service track, the wallet route has no FIPS alternative.
Web page · 135 KB · a short read
Establishes EUCC, built on the SOG-IS MRA. Article 49 ends the effects of national CC schemes covered by EUCC 12 months after entry into force; Article 50 applies it from 27 February 2025. Annex II lists EN 419241-2:2019 and EN 419221-5:2018 as protection profiles certified at AVA_VAN level 4 or 5 for remote qualified signature creation devices.
Web page · 125 KB · a short read
Authoritative CMVP transition schedule: "September 22, 2021 — CMVP no longer accepts FIPS 140-2 submissions for new validation certificates" and "September 21, 2026 — FIPS 140-2 active modules can be used until this date for new systems. After this date, FIPS 140-2 validation certificates will be moved to the Historical List." Note the page contradicts itself on the submission cut-off (table says 2021-09-22, prose says 2022-04-01); both are recorded here unreconciled.
Web page · 48 KB · a short read
Article 25 makes commercial cryptography certification VOLUNTARY by default ("鼓励商用密码从业单位自愿接受商用密码检测认证"). Article 26 makes it compulsory for products listed in the Network Critical Equipment and Network Security Special Products Catalogue, and for commercial cryptography services using such products. Verified identically on OSCCA and NPC.
Web page · 15 KB · a quick skim
SS6.2.7: "The CA SHALL protect its Private Key in a system or device that has been validated as meeting at least FIPS 140-2 level 3, FIPS 140-3 level 3, or an appropriate Common Criteria Protection Profile or Security Target, EAL 4 (or higher)." Binds the CA key only, not subscriber TLS server keys.
PDF · 2.2 MB · a reference document — dip in, don’t read it through
SS6.2.7, same FIPS140-2/140-3 L3 or CC EAL4+ any-of requirement as the TLS BRs, applied to S/MIME-issuing CA keys.
PDF · 314 KB · a short read
SS6.2.7.3: Signing Services shall protect Subscriber Private Keys in a Hardware Crypto Module conforming to at least FIPS 140-2 level 3 or Common Criteria EAL 4+ — the one BR that also reaches the SUBSCRIBER key, not just the CA.
PDF · 360 KB · a short read
SS5.2.1: "HSMs shall meet either FIPS 140-2 or FIPS 140-3, at level 3 or higher" for RZ KSK generation and storage — the DNS root zone KSK operator only, not general DNSSEC.
Web page · 260 KB · a long read
S3.2.12 (2.3.2 in some numbering): FIPS 140 module validation is required only of GOVERNMENT verifiers/authenticators, at Level 1 or higher for AAL3 — a downgrade from SP 800-63B-3 which required Level 2 overall / Level 3 physical.
PDF · 994 KB · a long read
Chrome's root-store policy incorporates the CA/Browser Forum Baseline Requirements by reference rather than restating an independent HSM-certification requirement.
Web page · 65 KB · a short read
SS6.1.5.2: "The cryptographic module for the End-Entities shall be certified against one of the CPA approved protection profiles (PPs), with at least an assurance level EAL4 augmented with AVA_VAN.4." Governs European V2X (vehicle-to-everything) certificate issuance.
PDF · 1.8 MB · a reference document — dip in, don’t read it through
The Car 2 Car Communication Consortium-sponsored Common Criteria Protection Profile named by the C-ITS Certificate Policy as an approved route for V2X HSM certification.
PDF · 1.1 MB · a long read
US V2X Security Credential Management System requirements: back-end/TMC systems require a FIPS 140-2 Level 3 validated HSM; end-entity (in-vehicle) devices explicitly do NOT require a FIPS validation certificate.
PDF · 1.0 MB · a long read
Binding UN vehicle type-approval regulation for software-update security. Requires software authenticity/integrity protection but names no cryptographic-module certification scheme.
PDF · 623 KB · a long read
Annex 1C Appendix 10, SEC_001: "The following components of the smart tachograph system shall be security certified according to the Common Criteria scheme: vehicle unit, tachograph card, motion sensor, external GNSS facility." Scoped to digital-tachograph components only, not general in-vehicle key storage.
PDF · 18.9 MB · a reference document — dip in, don’t read it through
EASA information-security management regulation for aviation. Contains no cryptographic requirement of any kind, and names no certification scheme.
PDF · 748 KB · a long read
ERTMS/ETCS off-line key-management functional interface specification. Names no cryptographic-module certification scheme for key-management-centre HSMs.
PDF · 1.2 MB · a long read
Notes CMVP/FIPS 140 as something organizations "should be aware of" when selecting cryptographic modules for IoT devices — an advisory footnote, not a requirement.
PDF · 2.4 MB · a reference document — dip in, don’t read it through
Baseline cybersecurity capabilities for IoT devices. Names no cryptographic-module certification requirement.
PDF · 978 KB · a long read
SS4.2: "The IC/hardware platform on which the eUICC is based shall be certified to either PP-0084 or PP-0035." Governs eSIM/eUICC hardware Common Criteria certification.
PDF · 447 KB · a long read
The eUICC-functional-level Common Criteria Protection Profile (EAL4 augmented ALC_DVS.2 + AVA_VAN.5) referenced by GSMA SGP.24/25 for eSIM certification.
PDF · 3.4 MB · a reference document — dip in, don’t read it through
ENISA public-consultation specification extending the EUCC Common Criteria scheme to cover eUICC certification, aligning with the existing BSI Protection Profiles.
PDF · 1.5 MB · a long read
DORA implementing technical standard on ICT risk management. Sets encryption and key-management policy requirements but names no cryptographic-module certification scheme.
PDF · 1.1 MB · a long read
Studio-consortium content-protection specification. Its certification clause requires third-party/trusted-implementer review but names no external certification scheme (FIPS/CC/PCI).
PDF · 303 KB · a short read
SS10.8(a): "Where practicable, seeds and private keys should be generated offline and kept in a secure environment, such as a HSM, with appropriate certification." Hong Kong VATP custody requirement — names no specific scheme, "appropriate certification" only.
PDF · 666 KB · a long read
Dubai virtual-asset custody rulebook. Checked directly: zero occurrences of FIPS/140/Common Criteria — the widely-repeated claim that VARA requires FIPS 140-2 Level 3 HSMs traces to vendor blogs, not this regulation.
PDF · 367 KB · a short read
Dubai virtual-asset technology rulebook. Checked directly: zero occurrences of FIPS/140/Common Criteria.
PDF · 379 KB · a short read
Requires encrypted remote-access sessions (R2.2) but names no algorithm, certification level, or validation scheme.
PDF · 326 KB · a short read
System security management requirements for BES Cyber Systems; no cryptographic-module certification named.
PDF · 638 KB · a long read
BES Cyber System information-protection requirements; no cryptographic-module certification named.
PDF · 268 KB · a short read
The RPKI CP requires each CA's Certification Practice Statement to describe its cryptographic-module standards, but sets no floor itself — the floor (e.g. ARIN's FIPS 140-2 Level 4) is set per-CA in the CPS, not by this policy.
Web page · 78 KB · a short read
PCI SSC's own announcement (18 May 2026): v5.0 adds "support for post-quantum cryptography considerations" and new definitions covering PQC — terminology/guidance, not a mandated PQC algorithm or parameter set. Also adds EC-SDSA (a classical ECC scheme, unrelated to PQC) as a separate, unrelated change.
Web page · 82 KB · a short read
PTS HSM v4 remains usable for NEW device-security approvals until 2027-06-30 despite v5.0's publication; v4 device-approval expiry extended April 2032 -> April 2033; v3 device-approval expiry extended to April 2028. No v5.0-specific PQC deadline exists.
PDF · 110 KB · a short read
Web page · 149 KB · a short read
Web page · 77 KB · a short read
Web page · 299 KB · a long read
Web page · 15 KB · a quick skim
Web page · 15 KB · a quick skim
Web page · 895 KB · a long read
Web page · 189 KB · a long read
Web page · 1.5 MB · a long read
Web page · 16 KB · a quick skim
Web page · 16 KB · a quick skim
Web page · 74 KB · a short read
PDF · 524 KB · a long read
Web page · 110 KB · a short read
This memo represents a republication of PKCS #10 v1.7 from RSA Laboratories' Public-Key Cryptography Standards (PKCS) series, and change control is retained within the PKCS process.
Web page · 69 KB · a short read
This document defines new Modular Exponential (MODP) Groups for the Internet Key Exchange (IKE) protocol.
Web page · 24 KB · a quick skim
This document describes the Certificate Request Message Format (CRMF) syntax and semantics.
Web page · 102 KB · a short read
This document updates RFC 3161 . It allows the use of ESSCertIDv2, as defined in RFC 5035 , to specify the hash of a signer certificate when the hash is calculated with a function other than the Secure Hash Algorithm (SHA-1).
Web page · 15 KB · a quick skim
This document provides specifications for existing TLS extensions.
Web page · 67 KB · a short read
This memo specifies a PKCS #11 Uniform Resource Identifier (URI) Scheme for identifying PKCS #11 objects stored in PKCS #11 tokens and also for identifying PKCS #11 tokens, slots, or libraries.
Web page · 59 KB · a short read
Web page · 84 KB · a short read
PDF · 253 KB · a short read
PDF · 289 KB · a short read
PDF · 378 KB · a short read
PDF · 1.4 MB · a long read
Entities participating in the generation or verification of digital signatures depend on the authenticity of the process.
PDF · 226 KB · a short read
PDF · 338 KB · a short read
PDF · 1.5 MB · a reference document — dip in, don’t read it through
PDF · 219 KB · a short read
PDF · 3.5 MB · a reference document — dip in, don’t read it through
Web page · 87 KB · a short read
Web page · 84 KB · a short read
Web page · 86 KB · a short read
Web page · 104 KB · a short read
Web page · 88 KB · a short read
Web page · 86 KB · a short read
Web page · 262 KB · a long read
Peer-reviewed IJACSA paper (2023) applying ISO/IEC 27005:2018's risk assessment methodology (asset/threat/vulnerability identification, likelihood x consequence scoring, treatment selection) combined with NIST SP 800-30 guidance to an insurance-sector case study. Cited as the open, reachable source for ISO 27005's actual methodology since the standard itself is sold and not held.
Web page · 109 KB · a short read
IACR ePrint 2024/667. Integrates a post-quantum-secure HPKE variant (ML-KEM/ML-DSA alongside classical ciphers) into an ARINC 653 avionics software partition. Covers DO-178C's certification process in depth (module/application/system acceptance, Reusable Software Components for certification-credit reuse) and how partitioning contains the recertification blast radius of a crypto change.
Web page · 18 KB · a quick skim
AFuzion (a DO-178C certification consultancy) technical whitepaper on DO-178C cost/schedule by Design Assurance Level. Discusses per-DAL cost and schedule delta qualitatively (a referenced chart, not machine-readable); does not itself state a specific re-certification dollar figure or year range.
Web page · 211 KB · a long read
arXiv:2408.16714. Builds a hardware-in-the-loop ARINC 429 simulator and demonstrates a real denial-of-service attack via a compromised bus. States ARINC 429's actual technical characteristics -- 32-bit words, 12.5/100 Kbits/s slow/fast rates -- and discusses why adding message encryption or authentication to the protocol is impractical.
PDF · 3.1 MB · a reference document — dip in, don’t read it through
Industry trade article covering a University of Tennessee PUF-based post-quantum CAN-FD security framework. States that standard CAN's payload size is too small for PQC and that CAN-FD's increased payload capacity is what makes PQC on the bus feasible.
Web page · 866 KB · a long read
TI technical whitepaper (SNLA462) on MACsec (IEEE 802.1AE) securing 100BASE-T1 Automotive Ethernet backbone links, contrasted with software-layer TLS/SSL. Grounds why Automotive Ethernet backbones (not CAN/LIN) are the automotive PQC migration target.
PDF · 390 KB · a short read
Nature 631, 755-759 (2024), CC-BY 4.0. Demonstrates that generative models trained recursively on their own synthetic output degenerate ("model collapse") -- the tails of the real data distribution disappear.
Web page · 367 KB · a long read
CSA security analysis of Google's Agent Payments Protocol (AP2) for agent-to-agent commerce -- cryptographically signed Mandates (ECDSA), identified quantum-threat weaknesses, and a hybrid-scheme roadmap.
Web page · 1.2 MB · a long read
Official Let's Encrypt announcement (2026-06-03) of its post-quantum roadmap: Merkle Tree Certificates, targeting late-2026 staging and 2027 production, chosen because ML-DSA-44 signatures alone would push TLS handshakes well past 10KB.
Web page · 39 KB · a quick skim
Official Docker blog (2026-06-16): Docker Content Trust and the Notary v1 service are being fully retired, first announced July 2025. Confirms DCT/Notary v1 has no PQC roadmap and points to Sigstore/Notation as modern replacements.
Web page · 252 KB · a long read
Technical analysis of the April 2021 Codecov Bash Uploader supply chain compromise -- an unsigned CI script was modified to exfiltrate CI environment secrets (AWS IAM keys, deploy keys, tokens) from over 23,000 affected customers.
Web page · 431 KB · a long read
IACR ePrint 2025/1577. Profiled (template) and unprofiled (CPA) side-channel attacks on ML-KEM's NTT-domain pair-pointwise multiplication during decapsulation, yielding full key recovery.
Web page · 16 KB · a quick skim
IACR ePrint 2025/2025. Covers migration of ECDSA-dependent security features -- secure boot, remote attestation -- to ML-DSA, motivated by Shor's algorithm breaking discrete-log/ECDSA.
Web page · 15 KB · a quick skim
Original 1984 BB84 protocol paper (arXiv reprint of the 1984 IEEE conference paper). Defines the rectilinear and diagonal conjugate photon-polarization bases and the sifting/eavesdropper-detection procedure that underlies quantum key distribution.
PDF · 1.2 MB · a long read
Comprehensive review of the Micius satellite's quantum experiments: satellite-based entanglement distribution over 1200km (2017) and entanglement-based QKD over 1120km (2020), the latter generating no key material aboard the satellite itself.
Web page · 44 KB · a short read
Physical Review Letters 85, 441 (2000). Proves BB84's security via an entanglement-purification-based protocol, extending the tolerable bit/phase error rate to just under 11% (the QBER eavesdropper-detection threshold).
PDF · 268 KB · a short read
SIAM J. Comput. 26, 1484-1509 (1997); arXiv preprint quant-ph/9508027. Shor's original paper describing polynomial-time quantum algorithms for integer factoring and discrete logarithms -- the basis for the quantum break of RSA and elliptic-curve cryptography.
Web page · 42 KB · a short read
STOC '96 / arXiv quant-ph/9605043. Grover's original quadratic-speedup quantum search algorithm -- the basis for halving symmetric-key effective security levels under a quantum attacker.
PDF · 67 KB · a short read
FDA final guidance (Federal Register, 2023-09-27), effective under FD&C Act section 524B: mandates premarket cybersecurity submissions -- a cybersecurity plan, SBOM, and vulnerability management -- for internet-connected 'cyber devices.' Supersedes the 2014 guidance.
Web page · 84 KB · a short read
TCG DICE specification (Family 2.0, Rev 78, 2018). Defines minimal hardware requirements for deriving a Compound Device Identifier from a Unique Device Secret and first mutable code -- a lightweight hardware root of trust suitable for constrained MCUs.
PDF · 938 KB · a long read
Official 2008 Debian Security Advisory (DSA-1571-1) for CVE-2008-0166: an incorrect Debian-specific OpenSSL patch left only the process ID as entropy input, limiting keys to ~32,767 possible outcomes.
Web page · 26 KB · a quick skim
IEEE Security & Privacy 16(5), 2018; IACR ePrint 2015/1075. Introduces the quantum-risk inequality (shelf-life + migration time > time-to-CRQC means a serious problem today) used across the corpus as "Mosca's Theorem" for migration prioritization.
PDF · 65 KB · a short read
arXiv:2509.24623. Engineering inventory of cryptographic dependencies across TLS/QUIC/PKI, distinguishing HNDL (confidentiality break via harvested ciphertext) from certificate/signature forgery (integrity break once Shor's algorithm can forge RSA/ECDSA signatures).
PDF · 306 KB · a short read
arXiv:1801.05863. Describes Intel SGX's remote attestation architecture -- the enclave's Quoting Enclave signs an attestation report using the platform's Attestation Key, producing a verifiable quote.
Web page · 41 KB · a short read
Costan & Devadas (MIT). Definitive academic explainer of Intel SGX architecture: threat model (all privileged software including kernel/hypervisor treated as potentially malicious), Memory Encryption Engine for DRAM confidentiality, and EGETKEY-derived Seal Keys tied to enclave measurement (MRENCLAVE/MRSIGNER).
Web page · 14 KB · a quick skim
Schneider et al. Systematization-of-knowledge survey of hardware-supported TEE architectures including Intel SGX/TDX, ARM TrustZone/CCA, AMD SEV, and RISC-V Keystone, comparing isolation, sealing, and attestation mechanisms.
Web page · 41 KB · a short read
Official AWS whitepaper describing the Nitro System's hardware-isolation architecture (Nitro Cards, Nitro Security Chip, Nitro Hypervisor) underlying AWS Nitro Enclaves, including how it removes administrator/operator access to customer workload memory.
PDF · 602 KB · a long read
Technical blog explaining why post-quantum/hybrid TLS key exchange (larger ML-KEM key shares, ClientHello split across packets) breaks MTU assumptions baked into deep SSL/TLS inspection appliances (WAF, NGFW), citing Meta's and Google's own documented Kyber768/ML-KEM rollout data.
Web page · 275 KB · a long read
Official Cloudflare docs describing post-quantum key agreement (X25519MLKEM768) and post-quantum signatures (ML-DSA) on the edge-to-origin TLS connection, distinct from the client-to-edge connection -- the architecture underlying origin shielding and per-leg PQC configuration at CDN scale.
Web page · 163 KB · a long read
Technical explainer of the three standard load-balancer TLS handling patterns -- SSL Passthrough (no intermediate decryption), SSL Termination/Offloading, and SSL Bridging/Re-Encryption (proxy terminates then re-encrypts to backend, enabling inspection while preserving backend encryption).
Web page · 80 KB · a short read
Demonstrates that a single bit-flip fault (e.g. via Rowhammer, the same fault class as a radiation-induced Single Event Upset) in a lattice-based Dilithium/ML-DSA secret key vector corrupts subsequent signing operations and enables recovery of most of the secret key from the resulting faulty signatures.
Web page · 43 KB · a short read
Reference on the RAD750 radiation-hardened PowerPC processor widely used in spacecraft, confirming its 110-200 MHz clock rate, SEU/latch-up radiation hardening, and use of FPGA/ASIC coprocessors for cryptographic acceleration.
Web page · 137 KB · a short read
Survey of aeronautical/UAS datalink technologies, covering legacy VHF ACARS alongside newer candidate links.
Web page · 44 KB · a short read
Confirms VHF ACARS avionics data rate of 2400 bps and discusses physical-layer bandwidth constraints of legacy aeronautical VHF datalinks.
PDF · 955 KB · a long read
Official eCFR text of the EAR's encryption export control section, defining ECCN 5E002 (encryption technology) and licensing requirements for cryptographic items and technology.
Academic paper on in-orbit PKI/trust services for space communications, with a baseline latency analysis computing LEO/GEO round-trip latencies at various altitudes and discussing key/certificate management under limited communication windows and orbital handoffs.
PDF · 3.9 MB · a reference document — dip in, don’t read it through
Empirical study of Starlink LEO constellation dynamics, finding satellites have an operational lifespan of 4-6 years against a nominal five-year design life.
PDF · 3.3 MB · a reference document — dip in, don’t read it through
Academic paper on GEO communication satellite system architecture, confirming the industry-standard 15-year design lifetime baseline for GEO satellites.
PDF · 1.6 MB · a reference document — dip in, don’t read it through
Sectigo explainer on timing/side-channel attacks against post-quantum cryptographic implementations, identifying constant-time algorithms as one of the most important countermeasures.
Web page · 588 KB · a long read
Common Criteria Protection Profile for the V2X Hardware Security Module used in Cooperative Intelligent Transport Systems, covering online/offline private key import and HSM security requirements for vehicle-to-vehicle/infrastructure communication.
PDF · 1.4 MB · a long read
Primary-source release changelog for cosign, the Sigstore project's container-signing CLI. As of the cached snapshot, contains no ML-DSA/post-quantum entries -- confirms PQC support has not yet shipped.
Official cert-manager documentation describing its built-in Prometheus metrics exporter for monitoring certificate issuance, renewal, and expiry in Kubernetes clusters.
Web page · 181 KB · a long read
Official repository for x509-certificate-exporter, a Prometheus exporter purpose-built for monitoring X.509 certificate expiry across Kubernetes TLS secrets, ConfigMaps, and on-disk files.
Web page · 366 KB · a long read
Official FAIR Institute overview of the FAIR (Factor Analysis of Information Risk) model -- the only internationally recognized quantitative model for measuring and expressing cyber/information risk in financial terms.
Web page · 104 KB · a short read
Official Open Group standard page for Open FAIR (O-RT Risk Taxonomy Standard and O-RA Risk Analysis Standard), the formal standardization of the FAIR quantitative risk model.
Web page · 87 KB · a short read
Layered latency-decomposition study of TLS 1.3 handshakes across classical, hybrid PQC, and pure PQC key-exchange configurations, measuring per-protocol-layer latency and connection throughput under realistic network conditions.
PDF · 619 KB · a long read
Official HL7 FHIR SMART App Launch specification, describing OAuth 2.0-based authorization patterns for FHIR API client applications, including token issuance and required client-authentication signature algorithms.
Proposes a framework where deep-CNN face matchers inherently support revocable biometric templates (via non-linear model transformations), contrasted against fingerprint/iris templates which are traditionally considered permanently irreplaceable once compromised.
PDF · 5.0 MB · a reference document — dip in, don’t read it through
Official OpenSSH project FAQ on post-quantum cryptography status. Confirms hybrid post-quantum KEY EXCHANGE (mlkem768x25519-sha256, default since OpenSSH 10.0) is shipped, but as of this page OpenSSH does NOT yet support any post-quantum host-key or user-key SIGNATURE algorithm -- ML-DSA SSH keys do not exist yet ('OpenSSH will add support for post-quantum signature algorithms in the future').
Web page · 8 KB · a quick skim
Official ETSI page explaining its deliverable types -- confirms Technical Specification (TS) contains technical requirements for rapid implementation, while Technical Report (TR) contains explanatory/informative material.
Web page · 151 KB · a long read
Official IETF charter page for the PQUIP (Post-Quantum Use In Protocols) working group, which coordinates PQC transition guidance across other IETF working groups (LAMPS, TLS, IPSECME, COSE).
Web page · 39 KB · a quick skim
Official IETF 'about' page. Confirms the IETF has no formal membership -- anyone can participate in an open, non-governmental standards process.
Web page · 86 KB · a short read
Academic evaluation of IEC 61850 substation network time-critical communications, confirming GOOSE Type 1-A mission-critical messages require less than four milliseconds end-to-end delay.
Web page · 43 KB · a short read
OT security technical explainer on IEC 62351-6 GOOSE message security, confirming HMAC-based (symmetric-key) message authentication rather than asymmetric digital signatures, driven by GOOSE's strict sub-4ms timing requirements.
Web page · 66 KB · a short read
Official PMI article defining a program as "a group of related projects managed in a coordinated way to obtain benefits and control not available from managing them individually" -- the basis for classifying multi-year, multi-system PQC migrations as programs rather than single projects.
Web page · 455 KB · a long read
Official Thales Luna HSM documentation describing the standard firmware-update practice: ship with the current FIPS-validated firmware installed while holding a candidate update as a ready-but-not-installed standby version, with rollback to the prior version, allowing safe migration without losing FIPS compliance mid-transition.
Web page · 27 KB · a quick skim
Official Open Quantum Safe GitHub repository for oqsprovider, the OpenSSL 3 provider that adds post-quantum algorithms as a dynamically-loadable plug-in independent of OpenSSL's core logic, as an alternative to static library integration.
Web page · 432 KB · a long read
MDN Web APIs reference for Crypto.getRandomValues(), confirming implementations use a PRNG seeded from a platform-specific entropy source (e.g. /dev/urandom) rather than a raw hardware RNG directly.
Web page · 156 KB · a long read
Official Microsoft Learn Transact-SQL reference for ALTER DATABASE ENCRYPTION KEY, confirming the REGENERATE WITH ALGORITHM syntax for online TDE key re-encryption.
Web page · 53 KB · a short read
Official Microsoft Learn documentation for the sys.dm_database_encryption_keys dynamic management view, used to enumerate SQL Server TDE-encrypted databases.
Web page · 57 KB · a short read
Cloud Security Alliance article distinguishing key-responsibility models -- confirms Hold Your Own Key (HYOK): "The customer maintains control of keys in their own KMS," giving high assurance the cloud provider cannot decrypt data, contrasted with BYOK's provider-boundary key handling.
Web page · 138 KB · a short read
Official eCFR text for 21 CFR 312.62, the FDA regulation specifying investigator record retention: 2 years following marketing-application approval (or 2 years after investigation discontinuation if no application is approved).
Official Visa product page for Visa Token Service (VTS), confirming it substitutes card numbers (PANs) with tokens for digital and mobile wallet payments (Apple Pay, Google Pay, Samsung Pay).
Cryptomathic white paper on the EMV card personalization and key-management workflow. Confirms the general personalization process but not the specific 'KIF injection'/5-7 year migration timeline claim; kept as a legitimate reference on EMV key management, not force-cited to that specific claim.
PDF · 2.8 MB · a reference document — dip in, don’t read it through
Secrets-management glossary article defining the 'Secret Zero' problem: the chicken-and-egg dilemma of securely providing the initial secret needed to unlock a secrets vault or bootstrap further secure access.
Web page · 206 KB · a long read
Experimental evaluation of post-quantum cryptography (ML-KEM) performance overhead for 6G control-plane and TLS communications, including WAN-emulated network conditions. Checked for pqc-testing-validation's specific IKEv2 WAN-latency claims (no exact match found there); kept as a legitimate PQC performance reference.
PDF · 1.1 MB · a long read
Official LoRa Alliance specification defining region-specific radio parameters, confirming the 222-byte maximum application payload for EU863-870 at SF7/SF8, 125 kHz data rates.
Web page · 104 KB · a short read
Thales's official Luna HSM documentation confirming ML-KEM (CKM_ML_KEM) and ML-DSA (CKM_ML_DSA) algorithm support requires Luna HSM Firmware 7.9.0 or newer (LMS-HSS separately available since 7.8.9).
Web page · 47 KB · a short read
Peer-reviewed (WWW '24) longitudinal measurement study of Starlink LEO latency (~19.2M samples); finds terminal-to-ground-station 'bent-pipe' latency ~40ms and median RTT ~39-40ms globally within the dense 53-degree shell, consistent with ~20ms one-way delay.
PDF · 2.9 MB · a reference document — dip in, don’t read it through
Web page · 329 KB · a long read
PDF · 4.7 MB · a reference document — dip in, don’t read it through
Web page · 1.2 MB · a long read
Defines a protocol composing independently-issued post-quantum ZKP credentials (Falcon-1024/ML-DSA-65 signed) from different issuers into one federation token for agentic payment networks.
Web page · 46 KB · a short read
Web page · 369 KB · a long read
Specifies three hybrid key exchange mechanisms for TLS 1.3 combining ECDHE with the SCloud+ post-quantum KEM (X25519SCloud+128, SecP256r1SCloud+192, SecP384r1SCloud+256).
Web page · 68 KB · a short read
Defines Falcon-1024/ML-DSA-65 credential binding, envelope format, and session-token issuance for x402 agentic payment authorization.
Web page · 43 KB · a short read
Quick update to the to-be RFC for ECDHE-MLKEM, recommending three hybrid key agreement mechanisms in TLS 1.3.
Web page · 55 KB · a short read
Web page · 211 KB · a long read
Web page · 40 KB · a short read
Web page · 568 KB · a long read
Web page · 66 KB · a short read
Web page · 17 KB · a quick skim
Web page · 1.6 MB · a long read
Web page · 235 KB · a long read
Web page · 2.5 MB · a long read
Web page · 46 KB · a short read
Web page · 313 KB · a long read
Web page · 278 KB · a long read
Web page · 22 KB · a quick skim
Web page · 63 KB · a short read
Web page · 712 KB · a long read
Web page · 192 KB · a long read
Web page · 44 KB · a short read
PDF · 165 KB · a short read
PDF · 268 KB · a short read
Web page · 103 KB · a short read
Web page · 240 KB · a long read
Web page · 62 KB · a short read
Web page · 61 KB · a short read
Web page · 78 KB · a short read
Web page · 73 KB · a short read
Web page · 176 KB · a long read
Web page · 25 KB · a quick skim
Web page · 24 KB · a quick skim
Web page · 198 KB · a long read
Web page · 94 KB · a short read
Web page · 35 KB · a quick skim
Web page · 374 KB · a long read
Web page · 119 KB · a short read
Web page · 35 KB · a quick skim
Web page · 272 KB · a long read
Web page · 55 KB · a short read
Web page · 404 KB · a long read
Web page · 278 KB · a long read
Web page · 145 KB · a short read
Web page · 177 KB · a long read
Web page · 22 KB · a quick skim
Web page · 779 KB · a long read
Web page · 1.6 MB · a long read
Web page · 1.5 MB · a long read
Web page · 85 KB · a short read
Web page · 73 KB · a short read
PDF · 432 KB · a long read
Web page · 151 KB · a long read
Web page · 90 KB · a short read
Web page · 50 KB · a short read
Web page · 66 KB · a short read
Web page · 166 KB · a long read
Web page · 3 KB · a quick skim
Web page · 35 KB · a quick skim
Web page · 413 KB · a long read
Web page · 41 KB · a short read
Web page · 45 KB · a short read
Web page · 128 KB · a short read
Web page · 536 KB · a long read
Web page · 48 KB · a short read
Web page · 273 KB · a long read
Web page · 60 KB · a short read
Web page · 87 KB · a short read
Web page · 228 KB · a long read
Web page · 228 KB · a long read
Web page · 46 KB · a short read
Web page · 52 KB · a short read
Web page · 61 KB · a short read
Web page · 54 KB · a short read
PDF · 2.4 MB · a reference document — dip in, don’t read it through
PDF · 866 KB · a long read
Web page · 307 KB · a long read
Web page · 51 KB · a short read
PDF · 10.8 MB · a reference document — dip in, don’t read it through
Web page · 124 KB · a short read
PCI PTS approved-device listing detail page. Its header defines the listing fields (approval number, version, expiry, restricted or unrestricted HSM use, remote-managed HSM, ISO PIN block format 4, and a Post-Quantum Cryptography notation).
Web page · 30 KB · a quick skim
NIST GitHub hub for the Entropy Source Validation Test System (ESVTS). It holds the protocol documentation, issue tracker and a Python client for submitting entropy sources and random bit generators for assessment against SP 800-90B and SP 800-90C.
Web page · 274 KB · a long read
Web page · 62 KB · a short read
Web page · 84 KB · a short read
Web page · 75 KB · a short read
Web page · 30 KB · a quick skim
Web page · 356 KB · a long read
Web page · 172 KB · a long read
Web page · 333 KB · a long read
Web page · 96 KB · a short read
PDF · 1.5 MB · a long read
PDF · 126 KB · a short read
PDF · 402 KB · a long read
PDF · 880 KB · a long read
PDF · 410 KB · a long read
PDF · 1.4 MB · a long read
usnistgov/ACVP GitHub repository: the algorithm-neutral ACVP JSON protocol core specification plus per-algorithm test-type and registration-capability sub-specifications (ML-DSA, SLH-DSA, SHA, at this commit). ACVP is the wire protocol NIST's ACVTS speaks — it is not itself a certifying program; CAVP issues the algorithm validation certificate. Pinned at commit 892fd147.
Web page · 485 KB · a long read
usnistgov/ACVP-Server GitHub repository (Gen/Vals): NIST's reference implementation that generates and verifies ACVP test vector sets — the source of every pinned public NIST ACVP-Server reference-sample vector file this program cites. Distinct from ACVTS (the hosted Demo/Prod services) and from CAVP (the certifying program); this repository is code, not a certificate.
Web page · 370 KB · a long read
Web page · 79 KB · a short read
Web page · 163 KB · a long read
Web page · 104 KB · a short read
Web page · 8 KB · a quick skim
Web page · 33 KB · a quick skim
LAKE WG draft defining quantum-resistant cipher suites for the LAKE protocol (formerly EDHOC, RFC 9528) using ML-KEM-512/1024 for key exchange and ML-DSA-44/87 for signatures, and renaming EDHOC to LAKE with registry columns marking DH/NIKE dependence. Directly PQC: KEM-based exchange cannot use the DH-based methods 0-3, and PQ/T hybrid KEMs are discussed for transition.
Web page · 30 KB · a quick skim
COSE WG draft defining C509, a CBOR encoding of X.509 certificates (invertible re-encoding or natively signed CBOR) plus CBOR certification requests, COSE headers and a TLS certificate type, cutting RFC 7925-profiled IoT certificate size by over 50%. PQC-relevant: it is extensible to PQ algorithms, but its own size tables show only marginal savings for ML-DSA-65 and FN-DSA-512 chains because PQ keys and signatures dominate.
Web page · 249 KB · a long read
UTA WG draft defining TLS/DTLS 1.3 profiles for constrained IoT devices and updating RFC 7925's X.509 certificate profile and ciphersuite requirements. It says plainly that its profile is classical and not quantum-resistant, points to draft-ietf-uta-pqc-app for PQC guidance, and notes RFC 9973 external-PSK mixing as a transitional measure against harvest-now-decrypt-later.
Web page · 106 KB · a short read
SUIT WG draft defining the CBOR-based SUIT manifest format: an envelope of COSE-authenticated metadata and command sequences describing where to fetch firmware/code, which devices it applies to and how to install and invoke it, meeting the RFC 9124 requirements. Not a PQC spec, but its envelope design explicitly accommodates large post-quantum signatures for constrained devices.
Web page · 229 KB · a long read
IOTOPS WG draft that revises and will obsolete RFC 7228, giving terminology for constrained-node networks, including device classes (now with narrative for Class 3 and 4 devices beyond Class 2), M-group/J-group device groups, energy and physical-layer bitrate classes. Not PQC-specific; its device classes are the common yardstick for judging whether a device can run PQC (draft-ietf-lake-pqsuites and the TLS 1.3 IoT profile both cite it).
Web page · 80 KB · a short read
OPC UA Part 2 (v1.05.06) describes the OPC UA security model: threats to industrial deployments, security objectives, SecureChannel and session architecture, SecurityPolicies, application/user authentication with X.509 certificates, and a mapping to IEC 62443-4-2, with an annex comparing RSA and ECC. Not PQC-specific; relevant to PQC migration because all OPC UA SecurityPolicies currently rely on RSA or ECC for certificates, signatures and key establishment.
Web page · 407 KB · a long read
OPC UA Part 7 (v1.05.02) specifies the structure of OPC UA Profiles, Facets and Conformance Units used to group features for tool-based and lab-based certification testing; the profiles themselves, including security policy profiles, are maintained in the OPC Foundation online profiles database. Not PQC-specific; relevant to PQC migration because new quantum-safe SecurityPolicies would enter OPC UA via these profiles (current changes add ECC-curve25519 and ECC-nist256 policies).
Web page · 57 KB · a short read
UK HSE regulator guidance page on functional safety of safety instrumented systems, alarm systems and BPCS in the process industries. States that BS EN 61508 is the general benchmark of good practice and BS EN 61511 (edition 2) is the benchmark standard for managing functional safety in the process industries, summarising its safety-lifecycle principles and Functional Safety Assessment.
Web page · 43 KB · a short read
Related content
Next step
See what changedThe revisions page lists the corrections made to the documents and data in the library.