PQ Crypto Registry

Algorithms

Post-quantum cryptographic algorithms evaluated for practical deployment.

Primitive
Assumption
Capability

FN-DSA

digital-signature
Security
NTRU lattice problems (Short Integer Solution over NTRU lattices)·EUF-CMA
Standard
FIPS 206
ParamsLevelPKSKSig
FN-DSA-51218971,281666
FN-DSA-102451,7932,3051,280
Risk
Assumption: low
Implementation: high
Side-channel: high

Hash-based Signatures for Bitcoin

digital-signature
Security
Hash function second-preimage resistance (SHA-256)·EUF-CMA
Standard
ePrint 2025/2203
ParamsLevelPKSKSig
hbs-btc-2e40132644,036
hbs-btc-2e30132643,440
hbs-btc-2e20132643,128
Risk
Assumption: low
Implementation: medium
Side-channel: low

HQC

kem
Security
Quasi-Cyclic Syndrome Decoding (QCSD)·IND-CCA2
Standard
NIST IR 8545
ParamsLevelPKSKCTSS
HQC-12812,2412,3214,43332
HQC-19234,5144,6028,97832
HQC-25657,2377,33314,42132
Risk
Assumption: medium
Implementation: medium
Side-channel: medium

leanSig

digital-signature
Security
Hash function second-preimage resistance (Poseidon2 over 31-bit prime fields)·EUF-CMA
Standard
ePrint 2025/055 and ePrint 2025/1332
ParamsLevelPKSKSig
leansig-hashing-optimized132642,688
leansig-size-optimized132642,240
leansig-balanced132642,464
Risk
Assumption: medium
Implementation: high
Side-channel: medium

ML-DSA

digital-signature
Security
Module-LWE & Module-SIS·EUF-CMA
Standard
FIPS 204
ParamsLevelPKSKSig
ML-DSA-4421,3122,5602,420
ML-DSA-6531,9524,0323,309
ML-DSA-8752,5924,8964,627
Risk
Assumption: low
Implementation: high
Side-channel: medium

ML-KEM

kem
Security
Module-LWE·IND-CCA2
Standard
FIPS 203
ParamsLevelPKSKCTSS
ML-KEM-51218001,63276832
ML-KEM-76831,1842,4001,08832
ML-KEM-102451,5683,1681,56832
Risk
Assumption: low
Implementation: low
Side-channel: medium

SLH-DSA

digital-signature
Security
Hash function second-preimage resistance·EUF-CMA
Standard
FIPS 205
ParamsLevelPKSKSig
SLH-DSA-SHA2-128s132647,856
SLH-DSA-SHA2-128f1326417,088
SLH-DSA-SHA2-192s3489616,224
SLH-DSA-SHA2-192f3489635,664
SLH-DSA-SHA2-256s56412829,792
SLH-DSA-SHA2-256f56412849,856
SLH-DSA-SHAKE-128s132647,856
SLH-DSA-SHAKE-128f1326417,088
SLH-DSA-SHAKE-192s3489616,224
SLH-DSA-SHAKE-192f3489635,664
SLH-DSA-SHAKE-256s56412829,792
SLH-DSA-SHAKE-256f56412849,856
Risk
Assumption: low
Implementation: low
Side-channel: low

XMSS

digital-signature
Security
Hash function second-preimage resistance and pseudorandomness·EUF-CMA
Standard
RFC 8391
ParamsLevelPKSKSig
XMSS-SHA2_10_2561681362,498
XMSS-SHA2_16_2561681362,690
XMSS-SHA2_20_2561681362,819
Risk
Assumption: low
Implementation: high
Side-channel: low