Post-Quantum Cryptography Standards and Audit Index: algorithms, dates, standards bodies, auditors ================================================================================ Reference index of post-quantum cryptographic algorithms (ML-KEM, ML-DSA, SLH-DSA, FN-DSA, HQC, LMS, XMSS), who standardized each one and when, migration deadlines (NIST IR 8547, CNSA 2.0, EU, UK), and the security firms that audit post-quantum implementations. ML-KEM (CRYSTALS-Kyber): FIPS 203 — NIST (U.S. National Institute of Standards and Technology) — 2024-08-13 — Final ML-DSA (CRYSTALS-Dilithium): FIPS 204 — NIST — 2024-08-13 — Final SLH-DSA (SPHINCS+): FIPS 205 — NIST — 2024-08-13 — Final FN-DSA (Falcon): FIPS 206 (draft) — NIST — TBD (draft under review; final expected late 2026 or 2027) — Draft HQC (Hamming Quasi-Cyclic): FIPS 207 (expected designation, draft pending) — NIST — Selected 2025-03-11; draft standard expected 2026, final 2027 — Selected, draft pending LMS / HSS (Leighton-Micali Signatures, Hierarchical Signature System): RFC 8554 and NIST SP 800-208 — IETF / IRTF CFRG (RFC 8554) and NIST (SP 800-208) — RFC 8554: 2019-04; SP 800-208: 2020-10-30 — Final XMSS / XMSS^MT (eXtended Merkle Signature Scheme): RFC 8391 and NIST SP 800-208 — IRTF CFRG (RFC 8391) and NIST (SP 800-208) — RFC 8391: 2018-05; SP 800-208: 2020-10-30 — Final Hybrid TLS 1.3 key exchange (X25519MLKEM768) (ECDHE-MLKEM): RFC 10024 — IETF TLS Working Group — 2026-08 — Final (Proposed Standard) Classic McEliece (McEliece (Goppa codes)): ISO/IEC standardization in progress; not selected by NIST — ISO/IEC JTC 1/SC 27 (in progress); recommended by BSI (Germany) TR-02102-1 — NIST fourth round concluded 2025-03-11 without selecting it — Not a NIST standard; ISO/IEC process ongoing FrodoKEM (Frodo): ISO/IEC 18033-2 amendment in progress; not selected by NIST — ISO/IEC JTC 1/SC 27 (in progress); recommended by BSI (Germany) and ANSSI (France) — Dropped from NIST process after Round 3 (2022-07); ISO/IEC work ongoing — Not a NIST standard; ISO/IEC process ongoing Auditors: zkSecurity, Trail of Bits, NCC Group (Cryptography Services), Cryspen, Kudelski Security, Quarkslab, Least Authority, Galois, atsec information security, Riscure (Keysight), Cure53, X41 D-Sec Source page: https://pqaudit.org/ Compiled by: PQC Audit Index editors (https://pqaudit.org/about/) Last reviewed: 2026-09-12