FIPS 203/204/205
FIPS 203, 204, and 205 are the first three finalized federal standards from NIST for post-quantum cryptography, designed to protect data against future attacks by powerful quantum computers. FIPS 203 covers a method for securely establishing shared encryption keys, while FIPS 204 and 205 each specify digital signature schemes used to authenticate data and detect unauthorized changes. NIST published these standards in August 2024, with an effective date of August 14, 2024.
FIPS 203, 204, and 205 are Federal Information Processing Standards issued by NIST specifying quantum-resistant cryptographic algorithms, effective August 14, 2024. FIPS 203 specifies the Module-Lattice-based Key-Encapsulation Mechanism (ML-KEM), a key-establishment mechanism used to securely negotiate a shared secret key between parties, it is a key-encapsulation mechanism, not a general-purpose or symmetric encryption standard. FIPS 204 specifies the Module-Lattice-based Digital Signature Algorithm (ML-DSA), and FIPS 205 specifies the Stateless Hash-based Digital Signature Algorithm (SLH-DSA); both provide digital signature schemes used to detect unauthorized modifications to data and to authenticate the originator. These standards are maintained by NIST; practitioners should note that this entry does not cover implementation validation, migration timelines, or agency-specific adoption requirements, which must be confirmed against the current authoritative NIST publications and any applicable transition guidance.
Why it matters
FIPS 203, 204, and 205 represent NIST's first finalized federal standards for post-quantum cryptography, addressing a threat that most current public-key cryptography was not designed to withstand: the eventual arrival of cryptographically relevant quantum computers capable of breaking widely used key-establishment and digital signature schemes. For defense and public sector organizations, these standards matter because sensitive data with long confidentiality lifespans may be vulnerable to "harvest now, decrypt later" strategies, in which an adversary collects encrypted traffic today with the intent of decrypting it once quantum capability matures. Finalizing these standards gives agencies and contractors an authoritative, NIST-issued foundation on which to plan cryptographic transitions.
Who it's relevant to
Inside FIPS 203/204/205
Common questions
Answers to the questions practitioners most commonly ask about FIPS 203/204/205.