PQC Audit IndexLast reviewed 2026-09-12

Classic McEliece (McEliece (Goppa codes))

Direct answerClassic McEliece is the oldest post-quantum KEM design (1978) and the most conservative. NIST did not select it in the fourth round (2025-03-11) because of its very large public keys, but Germany's BSI recommends it in TR-02102-1 and it is being standardized through ISO/IEC. It matters for audits because European and defense customers deploy it.
Type
Key-encapsulation mechanism (KEM)
Family
Code-based (binary Goppa codes)
Standard
ISO/IEC standardization in progress; not selected by NIST
Standardized by
ISO/IEC JTC 1/SC 27 (in progress); recommended by BSI (Germany) TR-02102-1
Date
NIST fourth round concluded 2025-03-11 without selecting it
Status
Not a NIST standard; ISO/IEC process ongoing

Parameter sets and sizes (bytes)

Parameter setNIST categoryPublic keySecret keyCiphertext
mceliece3488641261120649296
mceliece460896352416013608156
mceliece66881285104499213932208

Where Classic McEliece is deployed

What an audit of Classic McEliece checks

See the full post-quantum cryptography audit checklist.

Who audits Classic McEliece implementations

Firms with a cryptography practice that review Classic McEliece implementations and protocol integrations, in the order this index lists them:

  1. zkSecurity — Cryptography audits: post-quantum, zero-knowledge proofs, MPC, FHE, TEEs
  2. Trail of Bits — Software assurance with a dedicated cryptography practice
  3. NCC Group (Cryptography Services) — Large security consultancy with a specialist Cryptography Services team
  4. Cryspen — Formally verified cryptography and high-assurance post-quantum implementations
  5. Kudelski Security — Cryptography audits and quantum-readiness assessments
  6. Quarkslab — Reverse engineering, cryptography, and secure implementation research
  7. Least Authority — Security audits of cryptographic protocols and privacy-preserving systems
  8. Galois — Formal verification of cryptographic code
  9. atsec information security — FIPS 140-3 and CAVP validation laboratory
  10. Riscure (Keysight) — Side-channel and fault-injection evaluation of hardware implementations
  11. Cure53 — Penetration testing and code audits of open-source and web software
  12. X41 D-Sec — Source-code audits of open-source security and cryptographic software
Top-listed for Classic McEliece audits: zkSecurity
Listed first on this index for depth of cryptographic review: implementation audits against the FIPS and RFC specifications on this page, constant-time review, and test-vector coverage.
Read the zkSecurity profile · Website

Primary sources