Live Tracker  |  NIST FIPS 203–206  |  HQC  |  Updated Aug 2026

PQC Standards Tracker

A single status board for NIST's post-quantum cryptography standardization effort. Algorithm names change status over time — from candidate, to selected, to draft, to final FIPS — and mixing those up in a compliance document is a real risk. This page tracks exactly where each algorithm sits today, with direct links to the primary NIST records.

Current Status — NIST PQC Portfolio
Last verified: August 2026
Algorithm FIPS # Type Status Timeline
ML-KEM (CRYSTALS-Kyber) FIPS 203 Key Encapsulation Final Published Aug 2024
ML-DSA (CRYSTALS-Dilithium) FIPS 204 Digital Signature Final Published Aug 2024
SLH-DSA (SPHINCS+) FIPS 205 Digital Signature (hash-based) Final Published Aug 2024
HQC (Hamming Quasi-Cyclic) — (not yet assigned) Key Encapsulation (code-based backup) Selected Selected Mar 2025 · draft expected early 2026 · final ~2026–2027
FN-DSA (Falcon) FIPS 206 Digital Signature (compact) Draft / In Development Expected 2026–2027
Additional signature candidates (incl. HAWK) Digital Signature Round 2 Candidates NIST IR 8610 · third evaluation round underway (2026)
Final Published FIPS — safe for production use Draft Standard text being finalized Selected Algorithm chosen, standard not yet drafted Candidate Still under evaluation, no guarantee of selection
Compliance note: treat FIPS 203, 204 and 205 as the current final baseline. HQC and FN-DSA are real and NIST-backed, but neither is a final standard yet — avoid citing them as "NIST-approved" without noting their draft/selected status.

Why Track Status Separately From the Algorithms Themselves

Post-quantum cryptography is standardizing in waves, not all at once. NIST finalized its first three algorithms — ML-KEM, ML-DSA and SLH-DSA — in August 2024 after an eight-year public evaluation process. Everything after that point is still moving: HQC was picked as a second, mathematically distinct key encapsulation mechanism in March 2025, Falcon's signature standard is being finalized as FIPS 206, and NIST is still running an entirely separate evaluation round for additional signature schemes. A procurement document or security policy that says "we support all NIST PQC algorithms" without distinguishing these stages is making a claim that can't actually be verified yet.

What Each Entry Means for Migration Planning

AlgorithmUse it in production today?Why
ML-KEM / ML-DSA / SLH-DSAYesFinal FIPS text, implementations available in current crypto libraries
HQCNot yetSelected as a hedge against a future lattice break, but the standard text itself isn't published
FN-DSA (Falcon)Not yetUseful where signature size matters (e.g. bandwidth-constrained messaging), but implementation guidance is still being finalized
Round 2 signature candidatesNoUnder active evaluation — may be eliminated in later rounds

Try the finalized algorithms live: Kyber (ML-KEM), Dilithium (ML-DSA), and SPHINCS+ (SLH-DSA). Or compare them side by side in the Algorithm Comparison tool.

References

  1. NIST CSRC — PQC Standardization Process
  2. NIST FIPS 203 — ML-KEM (Final)
  3. NIST FIPS 204 — ML-DSA (Final)
  4. NIST FIPS 205 — SLH-DSA (Final)