NIST finalizes its first PQC standards: start with a cryptographic inventory
FIPS 203, 204 and 205 provide finalized standards for post-quantum key establishment and digital signatures.
Contents of this article
What happened
On August 13, 2024, NIST released its first three finalized post-quantum cryptography standards: FIPS 203 for ML-KEM, FIPS 204 for ML-DSA and FIPS 205 for SLH-DSA. They address key establishment and digital signatures, not a simple renaming of existing HTTPS certificates.
Implications for website operations
Encryption spans browsers, CDNs, load balancers, origins and internal services. Standards still require implementations, interoperability checks and performance testing. Prioritize long-lived sensitive data and key usage; support for one algorithm does not prove that the entire delivery chain has migrated.
Operational next steps
Record TLS libraries, versions and certificate workflows at every endpoint, and ask vendors about their migration plans. Test handshake compatibility, setup latency and fallback behavior in a limited environment before production changes.
