Skip to content

Education

FIPS 203, 204, and 205 in plain language

NIST released three post-quantum standards in August 2024. Here is what each does, where it deploys, and how they fit together.

FIPS 203 204 205 algorithm primer diagram.
Q-Day Is Coming: 5 Quantum-Safe Algorithms Explained Watch on YouTube

The three standards

StandardAlgorithmReplacesTypical use
FIPS 203ML-KEM (Kyber)RSA/ECDH key exchangeTLS hybrid KEM, VPN, messaging
FIPS 204ML-DSA (Dilithium)RSA/ECDSA signaturesCode signing, document signing, certs
FIPS 205SLH-DSA (SPHINCS+)RSA/ECDSA signaturesLong-term trust anchors, firmware

NIST's overview explains the harvest-now-decrypt-later threat driving adoption. NIST IR 8547 sets transition timelines.

Deployment notes

  • Start with ML-KEM for confidentiality (HNDL mitigation) via hybrid TLS — classical + PQC key exchange combined.
  • ML-DSA signatures are larger and slower than ECDSA — plan certificate chain and CDN impacts.
  • SLH-DSA offers hash-based backup signatures when lattice assumptions are a concern.

Watch the embedded algorithms overview, then dive deeper with Menezes' Kyber/Dilithium course.

This quarter

  1. Download FIPS 203–205 PDFs from NIST CSRC.
  2. Tag inventory: KEM vs signature vs symmetric findings separately.
  3. Pilot hybrid ML-KEM-768 per ML-KEM framework guide.

Continue on the Q-Day hub: ML-KEM migration guide

References & further reading

Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.

Last verified 2026-06-21

See your exposure with evidence

Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.