Introduction: mapping the regulatory landscape
For years, Post-Quantum Cryptography (PQC) was treated as an academic exercise. It was a landscape reserved for mathematicians and cryptographers working to solve a future problem for the middle of the 21st century.
Recently, however, it’s become clear that the problem is no longer theoretical, and the landscape has shifted dramatically into focus, with national authorities now targeting 2030 as a deadline for quantum-resilience in critical products, and 2035 for standard products. Tech breakthroughs powered by AI have only accelerated the urgency, sculpting the landscape into a real-world problem, not for the future, but for the fast-moving world of the late 2020s – especially when considering the long-life cycle data and assets currently under threat from Harvest-Now-Decrypt-Later attacks.
On the surface, the PQC landscape is seemingly straightforward – NIST’s 2024 standardization of PQC algorithms set the bar.
However, the real friction lies in how these algorithms are implemented. And that’s where the landscape changes again – with different approaches around the world shaping the future of post-quantum algorithm adoption.
For example, the US National Security Agency (NSA) forbids hybrid PQ/T systems for national security applications. PQ/T systems combine post-quantum cryptographic algorithms (PQ) with traditional cryptography (T) to form a hybrid protection against both quantum and classical threats. In this way, the United States mandates a direct leap to pure PQC, while in Europe, major bodies such as ANSSI in France, and BSI in Germany state the opposite, mandating or strongly recommending hybrid PQ/T implementations to guarantee backward compatibility.
For product owners trying to build a single, globally compliant solution, regulatory split-screens such as this create a dilemma. In addition, there are constraints from national or regional authorities, categorizing algorithms as either globally or regionally specific to protocol system standards. The terrain that must be crossed in order to migrate to quantum-resilience, could be daunting.
In this article, we break down the picture into national-level guidance, mapping the landscape into regional variants and explaining the approach of some of the key players.
The following table shows a high-level of view of the regulatory landscape by region, as of August 2026.
National Guidance
| Region | Organization | ML-KEM | ML-DSA | SLH-DSA | Other PQ | Hybrid PQ/T | 256-bit symmetric | ||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | 3 | 5 | 2 | 3 | 5 | 1 | 3 | 5 | |||||
| China | SCA | ✖ | ✖ | ✖ | ✖ | ✖ | ✖ | ✖ | ✖ | ✖ | ☑️ | ? | ➖ |
| European Union | ECCG | ✖ | ☑️ | ☑️ | ✖ | ☑️ | ☑️ | ✖ | ☑️ | ☑️ | ☑️ | ☑️ | ➖ |
| France | ANSSI | ✖ | ☑️ | ☑️ | ☑️ | ☑️ | ☑️ | ☑️ | ☑️ | ☑️ | ☑️ | ☑️ (with ML-KEM, ML-DSA, FrodoKEM) | ➖ |
| Germany | BSI | ✖ | ☑️ | ☑️ | ✖ | ☑️ | ☑️ | ✖ | ☑️ | ☑️ | ☑️ | ☑️ (for all PQC algorithms) | ➖ |
| Republic of Korea | KISA | ✅ | ✅ | ☑️ | ✅ | ➖ | |||||||
| Japan | CRYPTREC | ✖ | ☑️ | ☑️ | ✅ | ✅ | ? | ☑️ | ➖ | ||||
| United Kingdom | NCSC | ➖ | ☑️ | ☑️ | ➖ | ☑️ | ☑️ | ➖ | ☑️ | ☑️ | ✖ | ☑️ (as an interim measure) | ➖ |
| USA | NIST | ☑️ | ☑️ | ☑️ | ☑️ | ☑️ | ☑️ | ☑️ | ☑️ | ☑️ | ☑️ | ➖ | ➖ |
| NSA | ✖ | ✖ | ☑️ | ✖ | ✖ | ☑️ | ✖ | ✖ | ✖ | ✖ | ✖ (except for specific use cases) | ☑️ | |
☑️ allowed ✅ likely to be allowed ✖ prohibited ➖ neither recommended nor prohibited
In this section, we provide an overview of the latest regulations mandated or recommended by each region.
China
China categorizes ‘commercial cryptography’ as publicly available for use if certified by the State Cryptography Administration (SCA).
Under Chinese Cryptography Law, foreign entities can sell SCA-certified cryptography products in China, though these commercial requirements do not apply to everyday consumer goods.
China is actively updating its cryptographic standards through national competitions, including a 2025 initiative, while still allowing certified products to integrate foreign and standard algorithms.
European Union
The Agreed Cryptographic Mechanisms (ACM) is published by the ECCG, the European Cybersecurity Certification Group. It provides recommendations for systems aiming to achieve high assurance in cybersecurity certifications such as Common Criteria.
In addition, the EU Cyber Resilience Act aims to increase the overall level of cybersecurity, and builds in a timeline of 2026-2027 for ‘state-of-the-art’ cryptography.
EU recommended PQC algorithms
| Type | Algorithm | Parameter set |
|---|---|---|
| KEM | ML-KEM | ML-KEM-768 or ML-KEM-1024 |
| FrodoKEM | FrodoKEM-976 or FrodoKEM-1344 | |
| Signatures | ML-DSA | ML-DSA-65 or ML-DSA-87 |
| SLH-DSA | NIST category 3 & 5 | |
| LMS | No specific | |
| XMSS | No specific |
The ACM also outlines traditional NIST cryptography algorithms, and the EU recommends 192-bit symmetric algorithms.
Any lattice-based PQC should be combined with a traditional cryptosystem in a hybrid PQ/T system.
France
ANSSI, the French Cybersecurity Agency, lists recommended algorithms satisfying a list of mandatory requirements.
| Type | Algorithm | Parameter set |
|---|---|---|
| KEM | ML-KEM | ML-KEM 768 |
| FrodoKEM | FrodoKEM-976 | |
| Signatures | ML-DSA | No specific parameter set |
| SLH-DSA | No specific parameter set |
While ANSSI provides guidance, in practice, this is adopted by French industrial organizations when selecting cryptographic algorithms.
Note: LMS/XMSS is no longer recommended.
As with the EU recommendation, ANSSI specifies lattice-based algorithms must be hybridized with traditional cryptography to meet the requirements.
Germany
Guidance on cryptography in Germany is provided by BSI. For security-sensitive German government use and critical infrastructure, BSI recommendations become requirements and certification is required. Largely, BSI approaches migration flexibly, with strong support for NIST standards, the EU Agreed Cryptographic Mechanisms document, and the preference for hybrid PQ/T for all algorithms.
- BSI TR-02102-1 “Cryptographic Mechanisms: Recommendations and Key Lengths” (2026)
| Algorithm | Parameter set | |
|---|---|---|
| KEM | ML-KEM | ML-KEM-768 or ML-KEM-1024 |
| HQC* | Intended to be added once standard available | |
| Classic McEliece | mceliece460896 upwards | |
| FrodoKEM | FrodoKEM-976 or FrodoKEM-1344 | |
| Signatures | ML-DSA | ML-DSA-65 or ML-DSA-87 |
| SLH-DSA | NIST category 3 & 5 parameter sets | |
| LMS | All parameter sets | |
| XMSS | All parameter sets |
BSI recommends the use of traditional algorithms, as well all algorithms (including hash-based) in hybrid PQ/T form.
Japan
The list of cryptographic algorithms for use within Japan’s government systems is established by CRYPTREC – a project jointly managed by several Japanese ministries. PQShield authored the ML-KEM CRYPTREC report, leading to the inclusion of ML-KEM in the list of CRYPTREC ciphers.
Japan typically advocates the use of traditional cryptography using a number of Japanese algorithms – included in various ISO specifications, and hybrid PQ/T – which is recommended but not mandatory.
| Type | Algorithm | Parameter set |
|---|---|---|
| KEM | ML-KEM | ML-KEM-768 or ML-KEM-1024 |
| Signatures | To be announced | To be announced |
Republic of Korea
South Korea runs its own certification program – KCMVP, which, as yet, has not been updated with PQC. However, ML-KEM and ML-DSA are expected to be added.
In addition, a parallel effort for developing PQC algorithms was completed in January 2025, with the selection of NTRU+ and SMAUG-T (KEMs) and signature algorithms AIMER and HAETAE. These algorithms are in the process of being standardized, with further changes expected.
Relevant documentation:
It’s likely that PQ/T hybrid cryptography will become mandatory in KCMVP 3.0.
United Kingdom
The UK takes a flexible approach, providing recommendations rather than requirements. Guidance is issued by the National Cyber Security Centre (NCSC) reporting to GCHQ, which recommends consistency with NIST standards, selecting ML-KEM and ML-DSA as the default options for PQC algorithms.
NCSC provides the following recommendations:
| Type | Algorithm | Parameter set |
|---|---|---|
| KEM | ML-KEM | ML-KEM-768 as default choice |
| Signatures | ML-DSA | ML-DSA-65 as default choice |
| SLH-DSA | No specific parameter set | |
| LMS | No specific parameter set |
Only ML-DSA is recommended as a general purpose signature. LMS and XMSS are recommended only on a case-by-case basis. NCSC expects users to select the appropriate parameter set given system constraints.
NCSC recommends migrating to PQ/T hybrid cryptography ‘where reasonable’ as an interim step. PQC should be viewed as the end goal.
- Next steps in preparing for post-quantum cryptography (August 2024, NCSC)
United States
CNSA 2.0, the Commercial National Security Algorithm Suite released by the NSA covers a strict set of requirements for National Security Systems (NSS). It constrains PQC to a small subset of PQC algorithms and specifically prohibits hybrid PQ/T. Outside of NSS, the use of NIST’s FIPS algorithms is essentially a federal requirement for US government purchasing.
| Type | Algorithm | Parameter set |
|---|---|---|
| KEM | ML-KEM | ML-KEM-1024 only |
| Signatures | ML-DSA | ML-DSA-87 only |
| LMS | No specific parameter set: LMS SHA256/192 recommended | |
| XMSS | No specific parameter set; no XMSS-MT |
NSA have no plans to include SLH-DSA, FN-DSA, or HQC. LMS and XMSS are allowed for software and firmware signing only.
Traditional algorithms are allowed, including AES-256 and SHA-384, SHA-512. SHA-3 is allowed for ‘internal hardware functionality only’. No asymmetric traditional algorithms are approved for use.
Conclusion
It’s clear that product owners must take into account the constraints imposed by national authorities, with implementations of NIST PQC being largely satisfactory for the requirements of most governing bodies. There are also technical considerations – for example, there may be specific reasons for implementing FrodoKEM, including cryptographic agility, or HQC for similar reasons. Hybrid PQ/T support is also clearly desirable for the European market. The landscape has a regulatory shape, but it’s also defined by the contours of the most appropriate technology solution for certain environments and systems.
These constraints influence the set of cryptography algorithms a product should support. However, it’s worth noting that although regions may vary around the world, the consensus on the timeline for transition is converging to a sharp focus, with 2030 the deadline for transitioning critical products and 2035 marking the backstop for all systems to transition to quantum-safe.

