Netherlands PQC Migration Handbook (AIVD, CWI, TNO, 2nd Edition 2024)
Step 3: execution – Netherlands PQC Migration Handbook (AIVD, CWI, TNO, 2nd Edition 2024)

Netherlands PQC Migration Handbook (AIVD, CWI, TNO, 2nd Edition 2024) PRIMITIVES: Choose the recommended post-quantum and symmetric primitives and parameters

The handbook's tables set the choices. Key exchange or encapsulation: ML-KEM recommended, deployed together with ECDH; FrodoKEM and Classic McEliece acceptable as more conservative but not yet standardised, at level 5 or 3 parameters; ECDH and RSA deprecated except as the classical half of a hybrid. Stateless signatures: ML-DSA recommended with ECDSA or EdDSA alongside, SLH-DSA recommended and acceptable without a classical partner and even at level 1; FN-DSA listed only as acceptable, its standard not yet final and its floating-point arithmetic hard to protect against side channels. Stateful hash-based signatures (XMSS, LMS, HSS) only where the signing state can be managed reliably, following NIST guidance. Parameters: ML-KEM-1024 and ML-DSA-87 (level 5) preferred, ML-KEM-768 and ML-DSA-65 acceptable. Symmetric: AES-256 recommended with AES-128 acceptable, SHA-2 and SHA-3 families, AES-GCM, AES-OCB or ChaCha20-Poly1305 for authenticated encryption and CMAC-AES, HMAC-SHA-2 or KMAC for message authentication; MD5, SHA-1, (T)DES, IDEA, Blowfish, RC4 and CBC-MAC deprecated. The tables are not exhaustive (password hashing needs special functions such as Argon2).

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 7 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ALG-DSA ALG-DSA ML-DSA-87 (FIPS 204) for digital signatures in any use case; HashML-DSA, FN-DSA and SLH-DSA are not approved
  • ALG-HBS ALG-HBS LMS or XMSS (SP 800-208) for software and firmware signing, with state managed and signing in hardware; HSS and XMSS-MT not allowed
  • ALG-KEM ALG-KEM ML-KEM-1024 (FIPS 203) for key establishment; Kyber variants that do not follow FIPS 203 are not compliant
  • PQC-2 FIPS 203 ML-KEM Implementation - Module-Lattice Key-Encapsulation Mechanism
  • PQC-3 FIPS 204 ML-DSA Implementation - Module-Lattice Digital Signature
  • PQC-4 FIPS 205 SLH-DSA Implementation - Stateless Hash-Based Digital Signature

ISO 27002:2022 · 1 control

  • 8.24 Use of cryptography

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Step 3: execution – Netherlands PQC Migration Handbook (AIVD, CWI, TNO, 2nd Edition 2024)

Query this from an agent

The graph holds this control, the 7 it maps to, and the evidence behind each claim, over MCP and REST.