NIST's standard post-quantum key encapsulation mechanism (FIPS 203), derived from CRYSTALS-Kyber.
At a glance
| Quantum risk | Quantum-resistant |
|---|
| Used for | Key establishment |
|---|
| Post-quantum algorithm | Yes |
|---|
Variants and security strength
| Variant | Classical security (bits) |
|---|
| ML-KEM-512 | 128 |
| ML-KEM-768 | 192 |
| ML-KEM-1024 | 256 |
Positions and deadlines by authority
| Authority | Position | Effective | Scope | Details |
|---|
| NIST | Recommended | in force | all variants | |
| ANSSI | Recommended | in force | ML-KEM-1024 | ANSSI prefers the highest security level (5), in hybrid mode. |
| ANSSI | Acceptable | in force | ML-KEM-768 | Level 3 accepted by ANSSI, in hybrid mode. |
| BSI | Recommended | in force | ML-KEM-768, ML-KEM-1024 | BSI recommends ML-KEM-768/1024 in hybrid combination with a classical scheme; ML-KEM-512 is not recommended. |
| NSA (CNSA 2.0) | Recommended | in force | ML-KEM-1024 | CNSA 2.0 requires ML-KEM-1024. |
Sources
- FIPS 203 — Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM) · NIST
- ANSSI views on the Post-Quantum Cryptography transition (2023 follow-up) · ANSSI (guidance)
- FAQ — Cryptographie post-quantique · ANSSI (guidance)
- BSI TR-02102-1 — Cryptographic Mechanisms: Recommendations and Key Lengths (Version 2026-01) · BSI
- CNSA 2.0 Algorithms (Cybersecurity Advisory) · NSA (guidance)
Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.