---
title: "Post-Quantum Cryptography: ML-KEM and ML-DSA | Lattix"
description: Post-quantum cryptography resists quantum attack. Reference guidance on FIPS 203 ML-KEM, FIPS 204 ML-DSA, migration deadlines, and harvest-now-decrypt-later.
source: "https://lattix.io/blog/topics/post-quantum-cryptography/"
content-type: text/markdown
---

# Post-Quantum Cryptography: ML-KEM and ML-DSA | Lattix

[Blog](https://lattix.io/blog/) [Topics](https://lattix.io/blog/topics/) Post-Quantum Cryptography

Topic

# Post-Quantum Cryptography

What the migration to ML-KEM and ML-DSA requires, why the harvest-now-decrypt-later threat starts the clock today, and which deadlines apply.

11posts

Post-quantum cryptography is the set of algorithms that stay secure against an adversary holding a cryptographically relevant quantum computer. NIST standardized the first three in 2024: FIPS 203 (ML-KEM) for post-quantum key encapsulation, FIPS 204 (ML-DSA) for digital signatures, and FIPS 205 (SLH-DSA) as a hash-based signature alternative.

Migration fails on inventory, not on mathematics. Teams cannot list where cryptography runs, which algorithms and key sizes each system negotiates, or how long the protected data must stay confidential, and without that cryptographic bill of materials no schedule survives contact. The second trap is treating parameter sets as interchangeable: CNSA 2.0 requires ML-KEM-1024 and ML-DSA-87 for national security systems, so an ML-KEM-768 deployment does not clear that bar.

Posts under this hub cover the harvest-now-decrypt-later threat model, NIST IR 8547 and the dates it fixes, CNSA 2.0 timelines for national security systems, federal procurement signals, and what cryptographic agility demands of a data architecture. Several examine signature selection and why lineage structures need room to change algorithms.

## Frequently asked questions

### What is harvest now, decrypt later?

Harvest now, decrypt later describes an adversary who copies encrypted traffic or stored ciphertext today and holds it until a quantum computer can break the key exchange that protected it. The threat lands now because the exposure window equals the data's required confidentiality lifetime. Health records, genomic data, intelligence, and long-lived contracts are collectable today and still sensitive in 2040.

### What is the difference between ML-KEM-768 and ML-KEM-1024?

Both are parameter sets of the FIPS 203 key encapsulation mechanism, differing in security category and message size. ML-KEM-768 targets NIST security category 3 and suits most commercial traffic. ML-KEM-1024 targets category 5, carries larger keys and ciphertexts, and is what CNSA 2.0 requires for national security systems. Choose by requirement, not by default.

### When do organizations have to complete post-quantum migration?

NIST IR 8547 sets the federal floor: cryptographic algorithms providing 112 bits of classical security are deprecated after 2030 and disallowed after 2035. CNSA 2.0 moves faster for national security systems, with adoption milestones landing in 2027. Commercial deadlines follow sector regulators, and any data that must stay confidential past 2035 needs the earlier date.

### Which NIST standards define post-quantum algorithms?

Three FIPS publications carry the standardized algorithms. FIPS 203 specifies ML-KEM for key encapsulation, FIPS 204 specifies ML-DSA for digital signatures, and FIPS 205 specifies SLH-DSA, a stateless hash-based signature scheme resting on different assumptions. NIST IR 8547 describes the transition itself, and FIPS 140-3 governs validation of the modules that implement them.

## Reading on post-quantum cryptography

[![Lattix branded cover for the NIST round three additional post-quantum signature schemes analysis. /28 section number, IBM Plex Mono on dark grid background, the May 14 2026 round-three date, nine advancing schemes with HAWK struck out after its July 29 2026 withdrawal, and a lineage strip showing signature agility at the policy enforcement point highlighted in surgical yellow.](https://lattix.io/images/blog/nist-round-3-additional-pqc-signatures-lineage-agility-cover.svg) NIST's Round-Three Signature Field Lost HAWK. Lineage Needs the Agility. August 21, 2026 NIST advanced nine signature candidates to round three on May 14, 2026. One, HAWK, was withdrawn on July 29 after a key-recovery attack. The signature track is the data provenance problem, and agility is now demonstrated rather than theoretical. Read More →](https://lattix.io/blog/nist-round-3-additional-pqc-signatures-lineage-agility/)

[![Lattix branded cover for What Is Crypto Agility. Dark grid background, surgical yellow accent, IBM Plex Mono typography, with a reference box showing an algorithm identifier being swapped beneath an unchanged application interface while the protected object stays in place.](https://lattix.io/images/blog/what-is-crypto-agility-cover.svg) What Is Crypto Agility August 14, 2026 Crypto agility is the capability to replace cryptographic algorithms in systems already running, without rewriting the applications that depend on them. It is the property that makes post-quantum migration a configuration change rather than a rebuild. Read More →](https://lattix.io/blog/what-is-crypto-agility/)

[![Lattix branded cover for The Harvest-Now-Decrypt-Later Threat Is Already Here. /12 section number, capture-now decrypt-later timeline metadata, IBM Plex Mono on dark grid background, surgical yellow accent.](https://lattix.io/images/blog/harvest-now-decrypt-later-quantum-threat-cover.svg) The Harvest-Now-Decrypt-Later Threat Is Already Here July 30, 2026 Adversaries do not need a working quantum computer today to compromise tomorrow's cryptography. They need storage, patience, and a sufficiently long-lived secret. The act that matters has already happened by the time the cryptanalysis is feasible. Read More →](https://lattix.io/blog/harvest-now-decrypt-later-quantum-threat/)

[![Lattix branded cover for the Executive Order 14409 post-quantum analysis. /42 section number, IBM Plex Mono on a dark grid background, the order named and dated June 22 2026, the December 31 2030 key-establishment deadline, and a crypto-inventory strip with the object-level enforcement point highlighted in surgical yellow.](https://lattix.io/images/blog/eo-14409-post-quantum-mandate-cryptographic-bill-of-materials-cover.svg) EO 14409 Sets Federal Post-Quantum Deadlines. The Cryptographic Bill of Materials Is the Test. July 3, 2026 Executive Order 14409 sets December 2030 and 2031 deadlines for federal post-quantum migration and orders a cryptographic bill of materials. The binding requirement is naming which algorithm protects which data object, not swapping a transport cipher. Read More →](https://lattix.io/blog/eo-14409-post-quantum-mandate-cryptographic-bill-of-materials/)

[![Lattix branded cover for PCI DSS 4.0.1 Requires Cryptographic Agility. /27 section number, March 2025 binding date, twelve future-dated requirements statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the PCI requirement in a control flow strip.](https://lattix.io/images/blog/pci-dss-4-0-1-cryptographic-agility-cardholder-data-cover.svg) PCI DSS 4.0.1 Requires Cryptographic Agility. Cardholder Data Architectures Have to Move. June 11, 2026 PCI DSS 4.0.1 effective April 2024 introduced future-dated cryptographic requirements that bite in 2025 and 2026. Cardholder Data Environments tightly coupling crypto to application code cannot migrate inside the PCI assessment window. Data-centric encryption is the architectural path. Read More →](https://lattix.io/blog/pci-dss-4-0-1-cryptographic-agility-cardholder-data/)

[![Lattix branded cover for NIST IR 8547 Sets the PQC Migration Floor. /26 section number, 2027 binding window date, federal civilian migration cohort statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the migration milestone in a timeline strip.](https://lattix.io/images/blog/nist-ir-8547-pqc-migration-mid-2026-status-cover.svg) NIST IR 8547 Sets the PQC Migration Floor. The Calendar Bites in 2027. June 9, 2026 NIST IR 8547 establishes the federal post-quantum migration timeline. Mid-2026 progress data shows the schedule is tighter than most program offices have modeled. FIPS 140-3 module validation backlog compounds the risk. Cryptographic agility patterns are the schedule mitigation. Read More →](https://lattix.io/blog/nist-ir-8547-pqc-migration-mid-2026-status/)

[![Lattix branded cover for CNSA 2.0 and the January 2027 Deadline for National Security Systems. /18 section number, twenty months remaining statistic, ML-KEM-1024 / ML-DSA-87 algorithm metadata, IBM Plex Mono on dark grid background, surgical yellow accent on the January 2027 milestone in a transition timeline strip.](https://lattix.io/images/blog/cnsa-2-january-2027-national-security-systems-cover.svg) CNSA 2.0 and the January 2027 Deadline for National Security Systems May 15, 2026 CNSA 2.0 binds new National Security System acquisitions to ML-KEM-1024 and ML-DSA-87 effective January 1, 2027. Twenty months remain on the clock. The target is not the hard part. The transition pattern is. Read More →](https://lattix.io/blog/cnsa-2-january-2027-national-security-systems/)

[![Lattix branded cover for CISA's PQC product categories and federal acquisition. /11 section number, January 23 2026 publication date, two-tier procurement category map, IBM Plex Mono on dark grid background, surgical yellow accent.](https://lattix.io/images/blog/cisa-pqc-product-categories-federal-acquisition-cover.svg) CISA's PQC Product Categories Move Quantum-Safe From Roadmap to Procurement May 12, 2026 CISA's January 23, 2026 product categories list, issued under Executive Order 14306, defines where federal buyers should acquire only PQC-capable products. The list is advisory. The procurement language built on it will not be. Read More →](https://lattix.io/blog/cisa-pqc-product-categories-federal-acquisition/)

[![Lattix branded cover for CNSA 2.0 Just Narrowed the PQC Field. /04 section number, ML-KEM-1024 and ML-DSA-87 metadata strip, IBM Plex Mono on dark grid background.](https://lattix.io/images/blog/cnsa-2-0-ml-kem-1024-ml-dsa-87-exclusive-clarification-cover.svg) CNSA 2.0 Just Narrowed the PQC Field. ML-KEM-768 Will Not Clear NSS. May 5, 2026 NSA's April 2026 clarification narrowed the post-quantum field for National Security Systems to ML-KEM-1024 and ML-DSA-87. ML-KEM-768 will not clear NSS. Vendors that staked PQC-ready claims on the smaller parameter set need new statements. Read More →](https://lattix.io/blog/cnsa-2-0-ml-kem-1024-ml-dsa-87-exclusive-clarification/)

[![Lattix branded cover for Post-Quantum Cryptography: Why the Transition Has to Happen Now. /03 section number, FIPS 140-2 sunset date, IBM Plex Mono on dark grid background, surgical yellow accent.](https://lattix.io/images/blog/post-quantum-cryptography-why-transition-now-cover.svg) Post-Quantum Cryptography: Why the Transition Has to Happen Now May 4, 2026 Two PQC deadlines are already running. September 21, 2026 sunsets FIPS 140-2 for federal procurement. January 2027 binds CNSA 2.0 for National Security Systems. The migration that matters is not the algorithm. It is the cryptographic agility to swap one. Read More →](https://lattix.io/blog/post-quantum-cryptography-why-transition-now/)

[![Lattix diagram showing an MCP-connected AI agent with injected prompts denied at policy enforcement points, ABAC-compliant accesses allowed with ML-KEM-768 unwrap, and every decision committed to a Merkle-tree lineage.](https://lattix.io/images/blog/mcp-blast-radius-cryptographic-data-enforcement-cover.svg) How Cryptographic Data Enforcement Contains the MCP Blast Radius April 24, 2026 AI agents acting on injected instructions are now the dominant exfiltration vector. Two April 2026 incidents show why ABAC enforcement at the data object, not the network or the identity plane, is the control that actually contains MCP. Read More →](https://lattix.io/blog/mcp-blast-radius-cryptographic-data-enforcement/)

## Related topics

- [Zero Trust Architecture](https://lattix.io/blog/topics/zero-trust/)
- [Data Security](https://lattix.io/blog/topics/data-security/)
- [Zero Trust Data Format](https://lattix.io/blog/topics/ztdf/)
- [Access Control](https://lattix.io/blog/topics/access-control/)
- [AI Security](https://lattix.io/blog/topics/ai-security/)
- [Cryptography and Key Management](https://lattix.io/blog/topics/cryptography/)

[All topics →](https://lattix.io/blog/topics/)
