The NIST PQC Competition: Process and Criteria
Review the six-year NIST competition — submission criteria, evaluation rounds, and the final selection rationale.
The NIST PQC Competition: Process and Criteria is a free Cryptology Academy lesson on CoddyKit — lesson 1 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Cryptology Academy learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.
Why NIST Launched PQC
NIST launched the Post-Quantum Cryptography (PQC) standardization project in 2016 in direct response to the threat posed by quantum computers. Shor's algorithm can break RSA and elliptic curve cryptography in polynomial time on a sufficiently large quantum computer. NIST recognized that transitioning cryptographic infrastructure takes decades and began the process well before quantum computers pose an immediate threat.
The Initial Call for Submissions
NIST issued a call for submissions in December 2016, receiving 82 complete submissions by November 2017. After initial review, 69 were accepted as first-round candidates. The submissions spanned a wide range of mathematical assumptions: lattice problems, hash functions, code-based cryptography, isogeny-based cryptography, and multivariate polynomials. Diversity of assumptions was a key goal to avoid putting all eggs in one basket.
Round 1 Evaluation (2017-2019)
During Round 1, NIST and the broader cryptographic community performed intense analysis of all 69 candidates. Criteria included security (resistance to classical and quantum attacks), performance (key and ciphertext sizes, computation speed), flexibility (parameter sets for different security levels), and implementation simplicity. By January 2019, 26 candidates advanced to Round 2.
Round 2 Evaluation (2019-2020)
The 26 Round 2 candidates underwent deeper cryptanalysis and performance benchmarking. Several schemes were broken or weakened during this round, including Rainbow (multivariate) and SIKE (isogeny-based, though SIKE was broken only in Round 3). By July 2020, 15 candidates advanced to Round 3, organized into 7 finalists and 8 alternates.
Round 3 Finalists and Selection
The 7 Round 3 finalists were Kyber, NTRU, SABER (KEMs) and Dilithium, FALCON, Rainbow, SPHINCS+ (signatures). SIKE was an alternate but was spectacularly broken in 2022. NIST selected Kyber for KEM standardization based on its clean design, strong security proofs, and excellent performance. Dilithium, FALCON, and SPHINCS+ were selected for signatures.
Algorithm Diversity Rationale
NIST deliberately selected algorithms based on different mathematical problems to hedge against future breakthroughs. ML-KEM and ML-DSA rely on Module-LWE (lattices). FALCON relies on NTRU lattices and Gaussian sampling. SLH-DSA relies only on hash function security. If a breakthrough against lattices occurred, SLH-DSA would remain secure, providing algorithmic diversity in the standardized suite.
Round 4 and Additional Signature Candidates
In 2022, NIST opened a fourth round specifically soliciting additional signature candidates, motivated by a desire for more signature diversity beyond lattice-based schemes. Candidates included MAYO, CROSS, UOV, and others based on multivariate and code-based assumptions. This process ran in parallel with finalizing the three initial standards (FIPS 203, 204, 205).
FIPS 203, 204, 205 Published 2024
NIST published the final PQC standards in August 2024: FIPS 203 (ML-KEM, based on Kyber), FIPS 204 (ML-DSA, based on Dilithium), and FIPS 205 (SLH-DSA, based on SPHINCS+). FIPS 206 (FN-DSA, based on FALCON) is expected to follow. These are now mandatory considerations for US federal agencies and are influencing standards globally through ISO, ETSI, and IETF.
IETF and Industry Adoption
The IETF rapidly incorporated PQC into protocols. RFC drafts for ML-KEM in TLS 1.3, SSH, and X.509 certificates were in progress by 2024. Cloudflare, Google, and Amazon announced plans to deploy ML-KEM in their TLS stacks. Apple announced PQ3 for iMessage using ML-KEM for ratchet-based post-quantum forward secrecy, deployed to over a billion devices.
Lessons from the Competition
The NIST PQC competition demonstrated that open, collaborative cryptographic standardization works effectively. Multiple highly regarded schemes were broken during the process (GeMSS, SIKE, Rainbow), validating the importance of broad public cryptanalysis. The competition also spurred development of efficient hardware implementations and open-source libraries (liboqs, PQClean) that accelerated adoption.
Ongoing Standardization Work
Post-quantum standardization is not complete. NIST continues evaluating additional signature schemes for diversity. The X9 financial standards body is developing PQC standards for banking. ETSI and ISO are aligning with NIST FIPS. Migration guidance is being developed for specific sectors: healthcare (HIPAA implications), defense (NSA CNSA 2.0 suite), and telecommunications (3GPP for 5G/6G).
NIST PQC Rounds Quiz
How many candidates advanced from the initial submissions to Round 2 of the NIST PQC competition?
NIST PQC Competition Recap
NIST launched the PQC standardization project in 2016, receiving 69 complete submissions. Three evaluation rounds narrowed the field based on security, performance, and diversity. Final selections were Kyber (ML-KEM, FIPS 203), Dilithium (ML-DSA, FIPS 204), SPHINCS+ (SLH-DSA, FIPS 205), and FALCON (FN-DSA, FIPS 206). The competition validated open cryptanalysis and resulted in widely adopted standards now being integrated into TLS, SSH, and messaging protocols.
Frequently asked questions
Is the “The NIST PQC Competition: Process and Criteria” lesson free?
Yes — the full text of “The NIST PQC Competition: Process and Criteria” is free to read here on the web, and the Cryptology Academy course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Cryptology Academy course, upgrade to CoddyKit PRO.
What will I learn in “The NIST PQC Competition: Process and Criteria”?
Review the six-year NIST competition — submission criteria, evaluation rounds, and the final selection rationale. You practise Cryptology Academy with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start Cryptology Academy?
No prior experience is required. Cryptology Academy on CoddyKit is structured for beginners through advanced learners; this is — lesson 1 of 4, so you can start here or from the beginning and move at your own pace.
How long does the “The NIST PQC Competition: Process and Criteria” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this Cryptology Academy lesson?
Yes. Every Cryptology Academy lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- The NIST PQC Competition: Process and Criteria
- ML-KEM (FIPS 203): CRYSTALS-Kyber Standardized
- ML-DSA (FIPS 204) and SLH-DSA (FIPS 205)
- Planning Your Migration to Post-Quantum Standards