Video companion
After Root Causes + Dustin Moody: on-ramp signatures and backup algorithms
Root Causes episode 613 features Dustin Moody on the state of NIST PQC contests — including backup KEMs, on-ramp digital signatures, and evaluation criteria beyond security proofs.
What the episode covers
Moody explains why NIST continues evaluating algorithms after releasing FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA):
- Algorithm diversity — ML-DSA and Falcon both rely on structured lattices; backup families reduce correlated risk.
- HQC — non-lattice KEM backup advancing toward standardization.
- On-ramp signatures — candidates with different mathematical foundations (multivariate, hash-based, MPC-in-the-head).
Listen to the full Root Causes 613 episode for selection criteria: security, performance, and implementation characteristics.
The embedded interview with Moody (PQShield) covers complementary migration strategy guidance. See NIST's PQC project page for official updates.
What it does not cover
Contest updates inform strategy; they do not replace inventory. You cannot prioritize Falcon vs ML-DSA deployment until you know which systems consume which certificate chains.
This quarter
- Read Root Causes 613 and note on-ramp candidates relevant to your PKI constraints (signature size, verification speed).
- Inventory signature algorithms separately from key exchange — authentication migration is harder.
- Plan crypto-agility so algorithm swaps do not require forklift infrastructure changes.
Continue on the Q-Day hub: ML-KEM migration guide
References & further reading
Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.
Last verified 2026-06-21
- Root Causes 613: Status of the NIST PQC Contests (Dustin Moody)Sectigo Root Causes Podcast · 2025Dustin Moody on Falcon, HQC, on-ramp signatures, and ongoing NIST PQC evaluation criteria.
- How to Build Your 12-Month Post-Quantum Strategy (Dustin Moody, NIST)PQShield / Shielded podcast (YouTube) · 2025NIST PQC project lead on 2035 timelines, migration myths, crypto-agility, and practical next steps.
- What Is Post-Quantum Cryptography?NIST · 2024Official overview of NIST's PQC project, finalized standards, and the harvest-now-decrypt-later threat model.
- FIPS 204 — Module-Lattice-Based Digital Signature Standard (ML-DSA)NIST · 2024-08Standardized post-quantum digital signatures (formerly Dilithium).
- FIPS 205 — Stateless Hash-Based Digital Signature Standard (SLH-DSA)NIST · 2024-08Hash-based post-quantum signatures (SPHINCS+ family).
See your exposure with evidence
Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.