What NIST IR 8545 Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process requires
NIST Internal Report 8545, Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process, was published in March 2025 and is available at doi.org/10.6028/NIST.IR.8545. It closes the fourth round and, with it, the standardization process that began with the NIST Call for Proposals in 2016. Four key-encapsulation mechanism candidates were carried into the fourth round for continued evaluation, all based on different security assumptions than ML-KEM: BIKE, Classic McEliece, HQC and SIKE. The report records a single outcome. The only key-establishment algorithm that will be standardized is HQC, and NIST will develop a standard based on HQC to augment its key-establishment portfolio. The reasons for each exclusion are stated. SIKE was removed from consideration after published cryptanalytic results early in the fourth round demonstrated that it was insecure, and its submitters acknowledged its insecurity and recommended against its further use. Classic McEliece drew limited interest despite recognised strengths for use cases where a public key can be transferred once and then used for several encapsulations, such as file encryption and virtual private networks, because of its small ciphertext size and fast encapsulation and decapsulation; it is under consideration for standardization by the International Organization for Standardization, and NIST records that concurrent standardization risks the creation of incompatible standards, so it is no longer under consideration in the current NIST process although NIST may consider developing a standard based on the ISO standard once that process completes. The choice between BIKE and HQC turned on decryption failure rate: submitted KEMs were evaluated on how well they appear to provide IND-CCA2 security, both BIKE and HQC require a sufficiently low decryption failure rate to be IND-CCA2-secure, NIST does not consider the decryption failure rate analysis for BIKE to be as mature as that for HQC, and HQC is not believed to require additional modifications to achieve the desired security properties. The report is explicit that the algorithms not selected are not under consideration for standardization by NIST as part of the current process, that NIST will create a draft standard based on HQC and publish a final version approximately two years after comment adjudication, and that the standardization of HQC will be the second PQC KEM after ML-KEM. It also records that not all NIST PQC standardization is concluded, because NIST is separately evaluating additional digital signatures.
Pillar: Aviation, Defense & Quantum · Authority: National Institute of Standards and Technology (NIST), Information Technology Laboratory · Version: 1.0.0 · Last updated:
Primary source: https://csrc.nist.gov/pubs/ir/8545/final
SHA-256 integrity: f5bdfd93d78f1d577a349ee3e8c577da7d85fc7bad3c9fa8c6067d494c05c9ee
Primary Citations — 10 traced to source
+ 8 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/nist-ir-8545-pqc-fourth-round-status.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/nist-ir-8545-pqc-fourth-round-status.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/nist-ir-8545-pqc-fourth-round-status
- Back to registry: Browse all 10,099 compliance nodes