https://www.nist.gov/news-events/news/2025/03/nist-selects-hqc-fifth-algorithm-post-quantum-encryption Skip to main content U.S. flag An official website of the United States government Here's how you know Here's how you know [icon-dot-g] Official websites use .gov A .gov website belongs to an official government organization in the United States. [icon-https] Secure .gov websites use HTTPS A lock ( A locked padlock ) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites. https://www.nist.gov/news-events/news/2025/03/ nist-selects-hqc-fifth-algorithm-post-quantum-encryption National Institute of Standards and Technology National Institute of Standards and Technology Search NIST [ ] Search Menu Close * Publications * What We Do + All Topics + Advanced communications + Artificial intelligence + Bioscience + Buildings and construction + Chemistry + Cybersecurity + Electronics + Energy + Environment + Fire + Forensic science + Health + Information technology + Infrastructure + Manufacturing + Materials + Mathematics and statistics + Metrology + Nanotechnology + Neutron research + Performance excellence + Physics + Public safety + Quantum information science + Resilience + Standards + Transportation * Labs & Major Programs + Assoc Director of Laboratory Programs + Laboratories o Communications Technology Laboratory o Engineering Laboratory o Information Technology Laboratory o Material Measurement Laboratory o Physical Measurement Laboratory + User Facilities o NIST Center for Neutron Research o CNST NanoFab + Research Test Beds + Research Projects + Tools & Instruments + Major Programs o Baldrige Performance Excellence Program o CHIPS for America Initiative o Manufacturing Extension Partnership (MEP) o Office of Advanced Manufacturing o Special Programs Office o Technology Partnerships Office * Services & Resources + Standards and Measurements o Calibration Services o Laboratory Accreditation (NVLAP) o Quality System o Standard Reference Materials (SRMs) o Standard Reference Instruments (SRIs) o Standards.gov o Time Services o Office of Weights and Measures + Software + Data o Chemistry WebBook o National Vulnerability Database o Physical Reference Data o Standard Reference Data (SRD) + Storefront + License & Patents + Computer Security Resource Center (CSRC) + NIST Research Library * News & Events + News + Events + Blogs + Feature Stories + Awards + Video Gallery + Image Gallery + Media Contacts * About NIST + About Us o Leadership o Organization Structure o Budget & Planning + Contact Us + Visit + Careers o Student programs + Work with NIST + History o NIST Digital Archives o NIST Museum o NIST and the Nobel + Educational Resources NEWS NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption March 11, 2025 Share Facebook Linkedin X.com Email * NIST has chosen a new algorithm for post-quantum encryption called HQC, which will serve as a backup for ML-KEM, the main algorithm for general encryption. * HQC is based on different math than ML-KEM, which could be important if a weakness were discovered in ML-KEM. * NIST plans to issue a draft standard incorporating the HQC algorithm in about a year, with a finalized standard expected in 2027. Collage illustration of servers, laptops and phones is divided into left "Old Encryption Standards" and right "New Encryption Standards." Credit: J. Wang/NIST and Shutterstock Last year, NIST standardized a set of encryption algorithms that can keep data secure from a cyberattack by a future quantum computer. Now, NIST has selected a backup algorithm that can provide a second line of defense for the task of general encryption, which safeguards internet traffic and stored data alike. Encryption protects sensitive electronic information, including internet traffic and medical and financial records, as well as corporate and national security secrets. But a sufficiently powerful quantum computer, if one is ever built, would be able to break that defense. NIST has been working for more than eight years on encryption algorithms that even a quantum computer cannot break. Last year, NIST published an encryption standard based on a quantum-resistant algorithm called ML-KEM. The new algorithm, called HQC, will serve as a backup defense in case quantum computers are someday able to crack ML-KEM. Both these algorithms are designed to protect stored information as well as data that travels across public networks. What is post-quantum cryptography? Read an explainer. HQC is not intended to take the place of ML-KEM, which will remain the recommended choice for general encryption, said Dustin Moody, a mathematician who heads NIST's Post-Quantum Cryptography project. "Organizations should continue to migrate their encryption systems to the standards we finalized in 2024," he said. "We are announcing the selection of HQC because we want to have a backup standard that is based on a different math approach than ML-KEM. As we advance our understanding of future quantum computers and adapt to emerging cryptanalysis techniques, it's essential to have a fallback in case ML-KEM proves to be vulnerable." Encryption Based on Two Math Problems Encryption systems rely on complex math problems that conventional computers find difficult or impossible to solve. A sufficiently capable quantum computer, though, would be able to sift through a vast number of potential solutions to these problems very quickly, thereby defeating current encryption. While the ML-KEM algorithm is built around a mathematical idea called structured lattices, the HQC algorithm is built around another concept called error-correcting codes, which have been used in information security for decades. Moody said that HQC is a lengthier algorithm than ML-KEM and therefore demands more computing resources. However its clean and secure operation convinced reviewers that it would make a worthy backup choice. "Organizations should continue to migrate their encryption systems to the standards NIST finalized in 2024. We are announcing the selection of HQC because we want to have a backup standard that is based on a different math approach than ML-KEM." --Dustin Moody, NIST mathematician and project head Present and Future Standards HQC is the latest algorithm chosen by NIST's Post-Quantum Cryptography project, which has overseen efforts since 2016 to head off potential threats from quantum computers. HQC will take its place alongside the four algorithms NIST selected previously. Three of those algorithms have been incorporated into finished standards, including ML-KEM, which forms the core of the standard called FIPS 203. The other two finished standards, FIPS 204 and FIPS 205, contain digital signature algorithms, a kind of "electronic fingerprint" that authenticates the identity of a sender, such as when remotely signing documents. The three finished standards are ready for use, and organizations have already started integrating them into their information systems to future-proof them. A draft of the fourth standard, built around the FALCON algorithm, also concerns digital signatures and will be released shortly as FIPS 206. HQC is the only algorithm to be standardized from NIST's fourth round of candidates, which initially included four algorithms meriting further study. NIST has released a report summarizing each of these four candidate algorithms and detailing why HQC was selected. NIST plans to release a draft standard built around HQC for public comment in about a year. Following a 90-day comment period, NIST will address the comments and finalize the standard for release in 2027. Draft Guidance for KEM Algorithms One thing HQC has in common with ML-KEM is that they are both what experts call "key encapsulation mechanisms," or KEMs. A KEM is used over a public network as a sort of first handshake between two parties that want to exchange confidential information. NIST has recently published draft guidance for implementing KEM algorithms. This guidance, Recommendations for Key Encapsulation Mechanisms (NIST Special Publication 800-227), describes the basic definitions, properties and applications of KEMs. It also provides recommendations for implementing and using KEMs in a secure manner. NIST hosted a virtual Workshop on Guidance for KEMs in February, and the draft was open for public comment until March 7, 2025. Information technology, Cybersecurity and Cryptography Media Contact * Chad Boutin charles.boutin@nist.gov (301) 975-4261 Organizations * NIST Headquarters * + Laboratory Programs + o Information Technology Laboratory o # Computer Security Division # @ Cryptographic Technology Group Related News NIST Releases First 3 Finalized Post-Quantum Encryption Standards Related Links What Is Post-Quantum Cryptography? NIST IR 8545: Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process NIST SP 800-227 (Initial Public Draft): Recommendations for Key-Encapsulation Mechanisms Post-Quantum Cryptography at NIST Sign up for updates from NIST Enter Email Address [ ] [Sign up] Released March 11, 2025 National Institute of Standards and Technology logo HEADQUARTERS 100 Bureau Drive Gaithersburg, MD 20899 301-975-2000 Webmaster | Contact Us | Our Other Offices X.com Facebook LinkedIn Instagram YouTube Giphy RSS Feed Mailing List How are we doing? Feedback * Site Privacy * Accessibility * Privacy Program * Copyrights * Vulnerability Disclosure * No Fear Act Policy * FOIA * Environmental Policy * Scientific Integrity * Information Quality Standards * Commerce.gov * Science.gov * USA.gov * Vote.gov