NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205)
NIST's Post-Quantum Cryptography (PQC) standardisation effort culminated in August 2024 with the publication of three Federal Information Processing Standards: FIPS 203 (ML-KEM, based on CRYSTALS-Kyber for key encapsulation), FIPS 204 (ML-DSA, based on CRYSTALS-Dilithium for digital signatures), and FIPS 205 (SLH-DSA, based on SPHINCS+ for hash-based digital signatures). These standards are designed to resist attacks from both classical and quantum computers. NIST recommends organisations begin transitioning to PQC algorithms immediately. A fourth standard (FN-DSA, based on FALCON) expected in 2025.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (13)
Digital Signatures
| Code | Title |
|---|---|
| FIPS-204-DSA-01 | ML-DSA Digital Signature Implementation |
| FIPS-204-DSA-02 | Signature Context and Domain Separation |
FIPS 203 - ML-KEM Key Encapsulation
| Code | Title |
|---|---|
| FIPS 203 Sec. 4 | ML-KEM Parameter Sets |
| FIPS 203 Sec. 5.1 | Key Generation (KeyGen) |
| FIPS 203 Sec. 5.2 | Encapsulation (Encaps) |
| FIPS 203 Sec. 5.3 | Decapsulation (Decaps) |
| FIPS 203 Sec. 6 | ML-KEM Implementation Requirements |
FIPS 204 - ML-DSA Digital Signatures
| Code | Title |
|---|---|
| FIPS 204 Sec. 4 | ML-DSA Parameter Sets |
| FIPS 204 Sec. 5.1 | Key Generation (KeyGen) |
| FIPS 204 Sec. 5.2 | Signature Generation (Sign) |
| FIPS 204 Sec. 5.3 | Signature Verification (Verify) |
| FIPS 204 Sec. 6 | Pre-Hashing and Domain Separation |
FIPS 205 - SLH-DSA Hash-Based Signatures
| Code | Title |
|---|---|
| FIPS 205 Sec. 4 | SLH-DSA Parameter Sets |
| FIPS 205 Sec. 5.1 | SLH-DSA Key Generation |
| FIPS 205 Sec. 5.2 | SLH-DSA Signature Generation |
| FIPS 205 Sec. 5.3 | SLH-DSA Signature Verification |
| FIPS 205 Sec. 6 | Hash Function Instantiations |
General Requirements and Compliance
| Code | Title |
|---|---|
| FIPS 203/204/205 Sec. 1 | Scope and Applicability |
| FIPS 203/204/205 Sec. 2 | Quantum Resistance Rationale |
| FIPS 203/204/205 Sec. 3 | Mathematical Foundations |
Governance
| Code | Title |
|---|---|
| PQC-GOV-01 | Cryptographic Governance and Policy |
| PQC-GOV-02 | Vendor and Supply Chain Engagement |
| PQC-GOV-03 | Training and Awareness |
Hash-Based Signatures
| Code | Title |
|---|---|
| FIPS-205-SLH-01 | SLH-DSA Hash-Based Signature Implementation |
| FIPS-205-SLH-02 | Long-Term Signature Use Case Mapping |
Implementation
| Code | Title |
|---|---|
| PQC-IMP-01 | FIPS Validated Module Deployment |
| PQC-IMP-02 | Protocol Integration Testing |
| PQC-IMP-03 | Hardware Security Module Readiness |
Implementation and Security Considerations
| Code | Title |
|---|---|
| Impl. Req. 1 | Random Number Generation |
| Impl. Req. 2 | Side-Channel Attack Resistance |
| Impl. Req. 3 | Key Management and Storage |
| Impl. Req. 4 | Algorithm Validation |
| Impl. Req. 5 | Migration Planning |
Key Encapsulation
| Code | Title |
|---|---|
| FIPS-203-KEM-01 | ML-KEM Algorithm Implementation |
| FIPS-203-KEM-02 | Key Generation and Encapsulation Procedures |
Migration Planning
| Code | Title |
|---|---|
| PQC-MIG-01 | Cryptographic Inventory Establishment |
| PQC-MIG-02 | Migration Roadmap and Prioritization |
| PQC-MIG-03 | Crypto-Agility Architecture |
| PQC-MIG-04 | Hybrid and Composite Mode Strategy |
Migration Planning
Transitioning to post-quantum cryptography
| Code | Title |
|---|---|
| PQC-MIG-01 | Cryptographic Inventory Establishment |
| PQC-MIG-02 | Migration Roadmap and Prioritization |
| PQC-MIG-03 | Crypto-Agility Architecture |
| PQC-MIG-04 | Hybrid and Composite Mode Strategy |
Operations
| Code | Title |
|---|---|
| PQC-OPS-01 | Performance and Bandwidth Monitoring |
| PQC-OPS-02 | Incident Response for Cryptographic Failures |
Your Compliance Coverage
If you comply with NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205), you already cover:
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
15%
6 controls mapped
Compare →FedRAMP Rev 5
15%
6 controls mapped
Compare →AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association)
15%
6 controls mapped
Compare →+ 432 more: FFIEC IT Examination Handbook (15%), OWASP ASVS (15%)
See all 435 mapped frameworks ↓Maps to 435 other frameworks
Frequently Asked Questions
What is NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205)?
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) is a compliance framework from United States (NIST) with 13 domains and 41 controls. NIST's Post-Quantum Cryptography (PQC) standardisation effort culminated in August 2024 with the publication of three Federal Information Processing Standards: FIPS 203 (ML-KEM, based on CRYSTALS-Kyber for key encapsulation), FIPS 204 (ML-DSA, based on CRYSTALS-Dilithium for digital signatures), and FIPS 205 (SLH-DSA, based on SPHINCS+ for hash-based digital signatures). These standards are designed to resist attacks from both classical and quantum computers. NIST recommends organisations begin transitioning to PQC algorithms immediately. A fourth standard (FN-DSA, based on FALCON) expected in 2025. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) have?
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) has 41 controls organised across 13 domains. The largest domains are FIPS 203 - ML-KEM Key Encapsulation (5 controls), FIPS 204 - ML-DSA Digital Signatures (5 controls), FIPS 205 - SLH-DSA Hash-Based Signatures (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) map to?
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) maps to 435 other compliance frameworks. The top mapping partners are NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements (15% coverage), FedRAMP Rev 5 (15% coverage), AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) (15% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) compliance?
Start your NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 41 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required