A curated list of resources about post-quantum cryptography.
To contribute, please file a PR. Please list items alphabetically.
If you notice errors or obsolete content, please file PR or an Issue.
Standardization projects:
- NIST Post-Quantum Cryptography
- PQC Additional Digital Signature Schemes (in progress, round 3)
KEMs (encryption, key agreement):
- HQC - Selected in 2025, code-based
- ML-KEM (Kyber) - Selected in 2022, lattice-based
Signature schemes:
- FN-DSA (Falcon) - Selected in 2022, lattice-based
- Presentation FIPS 206 Status Update
- Presentation Falcon, Towards FN-DSA
- Falcon official software
- ML-DSA (Dilithium) - Selected in 2022, lattice-based
- SLH-DSA (SPHINCS+) - Selected in 2022, hash-based
- CISA Quantum-Readiness: Migration to Post-Quantum Cryptography
- CISA Strategy for Migrating to Automated Post-Quantum Cryptography Discovery and Inventory Tools
- DHS PQC approach and roadmap
- NIST and NCCoE's Migration to PQC
- NIST Migration to Post-Quantum Cryptography
- NSA PQC FAQ
- Quantum Computing Cybersecurity Preparedness Act
- GSMA: Post Quantum Government Initiatives by Country and Region
- ISO/IEC JTC 1/SC 27 Working Group on PQC Standardization
Australia:
Canada:
- Communications Security Establishment (CSE) Quantum Threat Assessments
- Migrating the Government of Canada to Post-Quantum Cryptography: Security Policy Implementation Notice
- Roadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001)
China:
Czech Republic:
EU:
- A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography
- ENISA Post-Quantum Cryptography Reports
- ETSI Quantum-Safe Cryptography Specification Group
- Europe's Post-Quantum Readiness 2026 An Empirical Assessment of the EU-27
France:
- ANSSI initiatives and publications
- ANSSI views on the Post-Quantum Cryptography transition
G7:
- G7 Cyber Expert Group Statement on Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector
- G7 Cybersecurity Working Group Statement on preparing for a post-quantum cryptography migration
Germany:
- BSI TR-02102 Cryptographic Mechanisms
- BSI TR-02102-1 "Cryptographic Mechanisms: Recommendations and Key Lengths"
Hong Kong:
India:
Israel:
Japan:
- Guidelines (including PQC) by CRYPTREC
Malaysia:
Netherlands:
Russia:
- TC26 standards committee announces potential standards:
- Codiaeum/Кодиеум - KEM, code-based
- Hypericum - Signature, hash-based
- Shipovnik/Шиповник - Signature, code-based
- Zemlyanika/Земляника - KEM, lattice-based
Singapore:
- MAS Advisory on Addressing the Cybersecurity Risks Associated with Quantum
- CSA Quantum-Safe Hanbook and Quantum Readiness Index
South Korea:
- KpqC Competitions and Algorithms
- Standardized algorithms:
Spain:
Sweden:
- Nationella rekommendationer för övergången till kvantsäker kryptografi (Translation: National recommendations for the transition to quantum secure cryptography.)
Switzerland:
United Kingdom:
- NCSC's Timelines for migration to post-quantum cryptography
- NCSC's Next steps in preparing for post-quantum cryptography
RFCs:
- RFC 8391: XMSS: eXtended Merkle Signature Scheme
- RFC 8554: Leighton-Micali Hash-Based Signatures
- RFC 8784: Mixing Preshared Keys in the Internet Key Exchange Protocol Version 2 (IKEv2) for Post-quantum Security
- RFC 9370 Multiple Key Exchanges in the Internet Key Exchange Protocol Version 2 (IKEv2)
- RFC 9881: Internet X.509 Public Key Infrastructure -- Algorithm Identifiers for the Module-Lattice-Based Digital Signature Algorithm (ML-DSA)
- RFC 9935: Internet X.509 Public Key Infrastructure - Algorithm Identifiers for the Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM)
- RFC 9794: Terminology for Post-Quantum Traditional Hybrid Schemes
- RFC 9941: Secure Shell (SSH) Key Exchange Method Using Hybrid Streamlined NTRU Prime sntrup761 and X25519 with SHA-512: sntrup761x25519-sha512
- RFC 9958: Post-Quantum Cryptography for Engineers
Internet-Drafts:
- I-D Commercial National Security Algorithm (CNSA) Suite 2.0 Profile for Secure/Multipurpose Internet Mail Extensions (S/MIME)
- I-D Composite ML-DSA for use in X.509 Public Key Infrastructure
- I-D Downgrade Prevention for the Internet Key Exchange Protocol Version 2 (IKEv2)
- I-D Framework to Integrate Post-quantum Key Exchanges into Internet Key Exchange Protocol Version 2 (IKEv2)
- I-D Hybrid key exchange in TLS 1.3
- I-D Hybrid Post-Quantum Key Encapsulation Methods (PQ KEM) for Transport Layer Security 1.2 (TLS)
- I-D Merkle Tree Certificates
- I-D ML-KEM Post-Quantum Key Agreement for TLS 1.3
- I-D Post-Quantum and Post-Quantum/Traditional Hybrid Algorithms for HPKE
- I-D Post-quantum hybrid ECDHE-MLKEM Key Agreement for TLSv1.3
- I-D Post-quantum Key Exchange with ML-KEM in the Internet Key Exchange Protocol Version 2 (IKEv2)
- I-D PQ/T Hybrid Key Exchange with ML-KEM in SSH
- I-D Use of Composite ML-DSA in TLS 1.3
- I-D Use of ML-DSA in TLS 1.3
- I-D Use of the FN-DSA Signature Algorithm in the Cryptographic Message Syntax (CMS)
Alibaba:
Apple:
AWS:
- AWS KMS post-quantum TLS
- AWS PQC Initiative
- AWS post-quantum cryptography migration plan
- s2n-tls PQC implementation
- Verifying and optimizing post-quantum cryptography at Amazon
Cloudflare:
- A look at the latest post-quantum signature standardization candidates
- Cloudflare targets 2029 for full post-quantum security
- Keeping the Internet fast and secure: introducing Merkle Tree Certificates
- PQC solutions overview
- State of the post-quantum Internet in 2025
- Why we cannot wait for better post-quantum signature algorithms
- You don’t need quantum hardware for post-quantum security
Google:
- Roadmap: PQC in Plaintext: Google Cloud’s post-quantum cryptography roadmap
- Announcing quantum-safe digital signatures in Cloud KMS
- Building superconducting and neutral atom quantum computers
- FIDO2/WebAuthn post-quantum security keys
- Google Cloud Post-Quantum Cryptography (PQC)
- Post-quantum cryptography in Chrome
- Quantum frontiers may be closer than they appear
Hashicorp:
IBM:
Kubernetes:
Meta:
- Post-Quantum Cryptography Migration at Meta: Framework, Lessons, and Takeaways
- Post-quantum readiness for TLS at Meta
Microsoft:
Palo Alto Networks:
Red Hat:
- Post-quantum cryptography in Red Hat Enterprise Linux 10
- What’s new in post-quantum cryptography in RHEL 10.1
Signal:
Tencent:
Does not include TLS implementations listed later:
- AWS-LC - Rust bindings in aws-lc-rs
- Botan - C++
- Bouncy Castle - Java/C#
- CIRCL (Cloudflare Interoperable, Reusable Cryptographic Library) - Go
- Google Tink - Multi-language (C++, Go, Java, Obj-C, Python)
C:
- algorand/falcon - Deterministic FALCON implementation
- liboqs - From Open Quantum Safe
- mupq/pqm4 - PQC library for the ARM Cortex-M4
- PQ Code Package - A Linux Foundation PQCA project building high-assurance implementations of standards-track algorithms
Go:
- Go crypto/mlkem - Official Go implementation of Kyber/ML-KEM
JavaScript:
- paulmillr/noble-post-quantum - ML-KEM, ML-DSA, SLH-DSA, Falcon, and hybrids
.NET:
Rust:
- libcrux - Formally verified code
- RustCrypto/KEMs - ML-KEM, FrodoKem
- RustCrypto/signatures - ML-DSA, SLH-DSA, LMS
- orion-rs/orion - ML-KEM, ML-DSA
Zig:
- std.crypto - ML-DSA and ML-KEM in the standard library
Official documentation, plan, proposals, and specifications:
Algorand:
- Algorand Post-Quantum Roadmap
- Technical Brief: Quantum-resistant transactions on Algorand with Falcon signatures
- Algorand Post-Quantum Ledger: Securing the ledger, one account type at a time
- Deterministic Falcon Signatures
Bitcoin:
- BIP-?: SHRINCS: A Compact Hash-Based Signature Scheme
- BIP-360: Pay-to-Merkle-Root (P2MR)
- BIP-361: Post Quantum Migration and Legacy Signature Sunset
- Lattice-based Signature Schemes for Bitcoin
- OP_CHECKSHRINCS: A Hash-Based Signature Opcode for Post-Quantum Bitcoin
Circle/Arc:
- Circle’s Post-Quantum Security Roadmap: "Arc will deploy a precompiled post-quantum signature verifier on mainnet (SLH-DSA-SHA2-128s) so smart accounts can validate post-quantum signatures on-chain."
Ethereum:
NEAR:
- Preparing NEAR for the Quantum Computing Era: "The Near One team (...) decided to start with FIPS-204 (ML-DSA, prev. Dilithium)"
Polkadot:
- Post Quantum Cryptography Roadmap for Polkadot and JAM: "We use both [Falcon and Dilithium] in different parts of the Polkadot protocol to replace all signature schemes."
Ripple:
Solana:
- Quantumglow: Will Solana’s Performance Survive Quantum Computing?: "we propose a hash-based (XMSS-style) signature scheme tailored specifically to Quantumglow"
- Securing Solana Against a Powerful Quantum Adversary
- Solana’s Quantum Readiness: "The alignment around Falcon reflects extensive research around Solana’s quantum resiliency. "
Sui:
- Making Sui Quantum Ready: "Sui is adding [...] ML-DSA-65 as a native protocol signature scheme for everyday accounts, and hash-based SLH-DSA-SHA2-128s inside Move smart contracts for high-value vaults."
Zcash:
- A Decade of Lattice-Based Cryptography by Chris Peikert
- A Survey on Code-Based Cryptography by Violetta Weger, Niklas Gassner and Joachim Rosenthal
- Mathematics of Isogeny-Based Cryptography by Luca de Feo
- Post-Quantum Cryptography by Daniel J. Bernstein, Johannes Buchmann and Erik Dahmen
- Post-quantum cryptography—dealing with the fallout of physics success by Daniel J. Bernstein and Tanja Lange
- Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations by Google Quantum AI
- The Learning with Errors Problem by Oded Regev
- A Gentle Introduction to Lattice-Based Cryptography by Alfred Menezes
- [PQ]probe
- awesome-quantum-software
- PQC Crypto Registry - By Project Eleven
- PQCrypto Usage & Deployment
- PQC Forum - NIST's discussion list
- PQ-SORT: Post-Quantum Signatures On-Ramp Tests
- Quantum Algorithm Zoo