The quantum shift is on. Security teams, embedded engineers and hardware vendors are now busy migrating systems to PQC, and top of the integration list is likely to be ML-DSA. Standardized by NIST as FIPS 204, ML-DSA is the cornerstone algorithm for quantum-safe digital signatures. From automotive control systems to aerospace electronics, ML-DSA is likely to be found everywhere, helping digital systems authenticate and prove the integrity of communications and files.
However, benchmarking ML-DSA comes with a major catch. Unlike the classical primitives it replaces, ML-DSA uses a technique called ‘rejection-sampling’, which in turn leads to timing variability. As a result, applying old techniques to benchmark the performance of ML-DSA (for example, minimum, average, or maximum execution times) will not produce reliable results. It’s an important consideration, as safety-critical systems and high-network environments rely on accurate measurements. A signing operation that takes 20 times longer than the average, for example, could easily lead to catastrophe.
In a new plain-english white paper (based on joint research by PQShield and the University of Bundeswehr Munich) we break down the core challenges:
- The 10 Benchmarking Pitfalls – from ambiguous measurement boundaries to misleading derterministic assumptions
- A standardized methodology – how to use dataset-driven testing to accurately evaluate PQC implementations
- Real-world hardware results – featuring the first publicly verifiable worst-case execution time benchmarks on real-world embedded processors
Whether you are an engineer, system architect, or compliance officer, this white paper provides the practical framework you need to make safe, predictable PQC migration decisions for ML-DSA.
