Hybrid TLS 1.3 key exchange combining X25519 and ML-KEM-768. Default in major browsers and CDNs; the IANA-recommended PQ group.
At a glance
| Quantum risk | Quantum-resistant |
|---|---|
| Used for | Key establishment |
| Post-quantum algorithm | Yes |
| Hybrid of | ECDH + ML-KEM |
Positions and deadlines by authority
| Authority | Position | Effective | Scope | Details |
|---|---|---|---|---|
| IETF | Recommended | in force | all variants | |
| ANSSI | Acceptable | in force | all variants | Hybrid as required by ANSSI; ANSSI prefers level-5 parameters (e.g. SecP384r1MLKEM1024) where possible. |
Sources
- RFC 10024 — Post-Quantum Traditional (PQ/T) Hybrid Key Agreement Mechanisms for TLS 1.3 · IETF
- IANA — Transport Layer Security (TLS) Parameters (Supported Groups, SignatureScheme) · IANA
- ANSSI views on the Post-Quantum Cryptography transition (2023 follow-up) · ANSSI (guidance)
- FAQ — Cryptographie post-quantique · ANSSI (guidance)
Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.