NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205)
NIST's Post-Quantum Cryptography (PQC) standardisation effort culminated in August 2024 with the publication of three Federal Information Processing Standards: FIPS 203 (ML-KEM, based on CRYSTALS-Kyber for key encapsulation), FIPS 204 (ML-DSA, based on CRYSTALS-Dilithium for digital signatures), and FIPS 205 (SLH-DSA, based on SPHINCS+ for hash-based digital signatures). These standards are designed to resist attacks from both classical and quantum computers. NIST recommends organisations begin transitioning to PQC algorithms immediately. A fourth standard (FN-DSA, based on FALCON) expected in 2025.
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) is a compliance framework from United States (NIST) with 8 domains and 8 controls that map to 125 other frameworks. The largest domains are Crypto-Agility (1 controls), FIPS 203 ML-KEM (1 controls), FIPS 204 ML-DSA (1 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (8)
Crypto-Agility
| Code | Title |
|---|---|
| PQC-6 | Crypto-Agility Architecture and Hybrid Composite Mode Strategy |
FIPS 203 ML-KEM
| Code | Title |
|---|---|
| PQC-2 | FIPS 203 ML-KEM Implementation - Module-Lattice Key-Encapsulation Mechanism |
FIPS 204 ML-DSA
| Code | Title |
|---|---|
| PQC-3 | FIPS 204 ML-DSA Implementation - Module-Lattice Digital Signature |
FIPS 205 SLH-DSA
| Code | Title |
|---|---|
| PQC-4 | FIPS 205 SLH-DSA Implementation - Stateless Hash-Based Digital Signature |
Implementation Operations
| Code | Title |
|---|---|
| PQC-8 | Implementation Requirements - RNG, Side-Channel, Key Management, Operations, Incident Response |
Inventory and Migration
| Code | Title |
|---|---|
| PQC-5 | Cryptographic Inventory and PQC Migration Roadmap |
PQC Framework
| Code | Title |
|---|---|
| PQC-1 | PQC Scope, Quantum Resistance Rationale, and Mathematical Foundations |
Validation and HSMs
| Code | Title |
|---|---|
| PQC-7 | FIPS Validated Modules, HSM Readiness, and Algorithm Validation |
Your Compliance Coverage
If you comply with NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205), you already cover:
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
63%
5 controls mapped
Compare →OWASP ASVS
63%
5 controls mapped
Compare →NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems
63%
5 controls mapped
Compare →+ 122 more: CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 (63%), Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023) (63%)
See all 125 mapped frameworks ↓Maps to 125 other frameworks
What is NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) and who does it apply to?
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) is a compliance framework from United States (NIST) with 8 domains and 8 controls. NIST's Post-Quantum Cryptography (PQC) standardisation effort culminated in August 2024 with the publication of three Federal Information Processing Standards: FIPS 203 (ML-KEM, based on CRYSTALS-Kyber for key encapsulation), FIPS 204 (ML-DSA, based on CRYSTALS-Dilithium for digital signatures), and FIPS 205 (SLH-DSA, based on SPHINCS+ for hash-based digital signatures). These standards are designed to resist attacks from both classical and quantum computers. NIST recommends organisations begin transitioning to PQC algorithms immediately. A fourth standard (FN-DSA, based on FALCON) expected in 2025. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) actually require?
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) has 8 controls organised across 8 domains. The largest domains are Crypto-Agility (1 controls), FIPS 203 ML-KEM (1 controls), FIPS 204 ML-DSA (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) do I already cover?
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) maps to 125 other compliance frameworks. The top mapping partners are NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements (63% coverage), OWASP ASVS (63% coverage), NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems (63% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205)?
Start your NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 8 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required