Standard hash family. SHA-256 and above remain secure against known quantum attacks.
At a glance
| Quantum risk | Quantum-resistant |
|---|
| Used for | Hash function |
|---|
| Post-quantum algorithm | No |
|---|
Variants and security strength
| Variant | Classical security (bits) |
|---|
| SHA-224 | 112 |
| SHA-256 | 128 |
| SHA-384 | 192 |
| SHA-512 | 256 |
Positions and deadlines by authority
| Authority | Position | Effective | Scope | Details |
|---|
| NIST | Acceptable | in force | all variants | |
| NSA (CNSA 2.0) | Recommended | in force | SHA-384, SHA-512 | CNSA 2.0 requires SHA-384 or SHA-512. |
| NIST | Disallowed | from January 1, 2031 | SHA-224 | 224-bit hashes disallowed for applying protection after 2030 (SP 800-131A Rev. 3 draft). |
Sources
- FIPS 180-4 — Secure Hash Standard (SHS) · NIST
- SP 800-131A Rev. 3 (Initial Public Draft) — Transitioning the Use of Cryptographic Algorithms and Key Lengths · NIST (draft)
- CNSA 2.0 Algorithms (Cybersecurity Advisory) · NSA (guidance)
Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.