Education
FIPS 203, 204, and 205 in plain language
NIST released three post-quantum standards in August 2024. Here is what each does, where it deploys, and how they fit together.

The three standards
| Standard | Algorithm | Replaces | Typical use |
|---|---|---|---|
| FIPS 203 | ML-KEM (Kyber) | RSA/ECDH key exchange | TLS hybrid KEM, VPN, messaging |
| FIPS 204 | ML-DSA (Dilithium) | RSA/ECDSA signatures | Code signing, document signing, certs |
| FIPS 205 | SLH-DSA (SPHINCS+) | RSA/ECDSA signatures | Long-term trust anchors, firmware |
NIST's overview explains the harvest-now-decrypt-later threat driving adoption. NIST IR 8547 sets transition timelines.
Deployment notes
- Start with ML-KEM for confidentiality (HNDL mitigation) via hybrid TLS — classical + PQC key exchange combined.
- ML-DSA signatures are larger and slower than ECDSA — plan certificate chain and CDN impacts.
- SLH-DSA offers hash-based backup signatures when lattice assumptions are a concern.
Watch the embedded algorithms overview, then dive deeper with Menezes' Kyber/Dilithium course.
This quarter
- Download FIPS 203–205 PDFs from NIST CSRC.
- Tag inventory: KEM vs signature vs symmetric findings separately.
- Pilot hybrid ML-KEM-768 per ML-KEM framework guide.
Continue on the Q-Day hub: ML-KEM migration guide
References & further reading
Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.
Last verified 2026-06-21
- FIPS 203 — Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM)NIST · 2024-08Standardized post-quantum key encapsulation (formerly Kyber).
- FIPS 204 — Module-Lattice-Based Digital Signature Standard (ML-DSA)NIST · 2024-08Standardized post-quantum digital signatures (formerly Dilithium).
- FIPS 205 — Stateless Hash-Based Digital Signature Standard (SLH-DSA)NIST · 2024-08Hash-based post-quantum signatures (SPHINCS+ family).
- What Is Post-Quantum Cryptography?NIST · 2024Official overview of NIST's PQC project, finalized standards, and the harvest-now-decrypt-later threat model.
- NIST IR 8547: Transition to Post-Quantum Cryptography StandardsNIST · 2024Federal transition guidance with deprecation timelines for quantum-vulnerable algorithms.
- Q-Day Is Coming: 5 Quantum-Safe Algorithms ExplainedYouTube · 2025Overview of NIST PQC standards including ML-KEM, ML-DSA, and SLH-DSA.
See your exposure with evidence
Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.