NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205)
NIST's Post-Quantum Cryptography (PQC) standardisation effort culminated in August 2024 with the publication of three Federal Information Processing Standards: FIPS 203 (ML-KEM, based on CRYSTALS-Kyber for key encapsulation), FIPS 204 (ML-DSA, based on CRYSTALS-Dilithium for digital signatures), and FIPS 205 (SLH-DSA, based on SPHINCS+ for hash-based digital signatures). These standards are designed to resist attacks from both classical and quantum computers. NIST recommends organisations begin transitioning to PQC algorithms immediately. A fourth standard (FN-DSA, based on FALCON) expected in 2025.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
FIPS 203 — ML-KEM Key Encapsulation
| Code | Title |
|---|---|
| FIPS 203 Sec. 4 | ML-KEM Parameter Sets |
| FIPS 203 Sec. 5.1 | Key Generation (KeyGen) |
| FIPS 203 Sec. 5.2 | Encapsulation (Encaps) |
| FIPS 203 Sec. 5.3 | Decapsulation (Decaps) |
| FIPS 203 Sec. 6 | ML-KEM Implementation Requirements |
FIPS 204 — ML-DSA Digital Signatures
| Code | Title |
|---|---|
| FIPS 204 Sec. 4 | ML-DSA Parameter Sets |
| FIPS 204 Sec. 5.1 | Key Generation (KeyGen) |
| FIPS 204 Sec. 5.2 | Signature Generation (Sign) |
| FIPS 204 Sec. 5.3 | Signature Verification (Verify) |
| FIPS 204 Sec. 6 | Pre-Hashing and Domain Separation |
FIPS 205 — SLH-DSA Hash-Based Signatures
| Code | Title |
|---|---|
| FIPS 205 Sec. 4 | SLH-DSA Parameter Sets |
| FIPS 205 Sec. 5.1 | SLH-DSA Key Generation |
| FIPS 205 Sec. 5.2 | SLH-DSA Signature Generation |
| FIPS 205 Sec. 5.3 | SLH-DSA Signature Verification |
| FIPS 205 Sec. 6 | Hash Function Instantiations |
General Requirements and Compliance
| Code | Title |
|---|---|
| FIPS 203/204/205 Sec. 1 | Scope and Applicability |
| FIPS 203/204/205 Sec. 2 | Quantum Resistance Rationale |
| FIPS 203/204/205 Sec. 3 | Mathematical Foundations |
Implementation and Security Considerations
| Code | Title |
|---|---|
| Impl. Req. 1 | Random Number Generation |
| Impl. Req. 2 | Side-Channel Attack Resistance |
| Impl. Req. 3 | Key Management and Storage |
| Impl. Req. 4 | Algorithm Validation |
| Impl. Req. 5 | Migration Planning |
Migration Planning
Transitioning to post-quantum cryptography
Maps to 499 other frameworks
Frequently Asked Questions
What is NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205)?
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) is a compliance framework from United States (NIST) with 6 domains and 23 controls. NIST's Post-Quantum Cryptography (PQC) standardisation effort culminated in August 2024 with the publication of three Federal Information Processing Standards: FIPS 203 (ML-KEM, based on CRYSTALS-Kyber for key encapsulation), FIPS 204 (ML-DSA, based on CRYSTALS-Dilithium for digital signatures), and FIPS 205 (SLH-DSA, based on SPHINCS+ for hash-based digital signatures). These standards are designed to resist attacks from both classical and quantum computers. NIST recommends organisations begin transitioning to PQC algorithms immediately. A fourth standard (FN-DSA, based on FALCON) expected in 2025. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) have?
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) has 23 controls organised across 6 domains. The largest domains are FIPS 203 — ML-KEM Key Encapsulation (5 controls), FIPS 204 — ML-DSA Digital Signatures (5 controls), FIPS 205 — SLH-DSA Hash-Based Signatures (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) map to?
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) maps to 499 other compliance frameworks. The top mapping partners are 3GPP Security (26% coverage), 3GPP Security Architecture (TS 33.501 — 5G Security) (26% coverage), NIST SP 800-171A Rev 3 — Assessing CUI Security Requirements (26% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) compliance?
Start your NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 23 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required