{"id":5736,"date":"2026-06-11T11:10:23","date_gmt":"2026-06-11T11:10:23","guid":{"rendered":"https:\/\/signmycode.com\/blog\/?p=5736"},"modified":"2026-06-11T11:10:28","modified_gmt":"2026-06-11T11:10:28","slug":"nist-announces-third-round-candidates-for-post-quantum-digital-signatures","status":"publish","type":"post","link":"https:\/\/signmycode.com\/blog\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures","title":{"rendered":"NIST Announces Third Round Candidates for Post-Quantum Digital Signatures"},"content":{"rendered":"\n<h2 id=\"h-quick-summary\" class=\"wp-block-heading\">Quick Summary<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Globally, companies are still preparing for a quantum revolution, and the National Institute of Standards and Technology (NIST) has made significant progress on its Post-Quantum Cryptography (PQC) Standardization Program. <\/p>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\">On May 21, 2026, <a href=\"https:\/\/csrc.nist.gov\/Projects\/pqc-dig-sig\">NIST named the 9 digital signature algorithms<\/a> that are moving onto the next round of candidates for their Additional Digital Signature Candidates PQC Standards Process &#8211; these will be the next group of candidates being evaluated as possible post-quantum digital signatures to be used to protect critical systems against future attacks using quantum computing as an attack method.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote has-small-font-size is-layout-flow wp-block-quote-is-layout-flow\"><\/blockquote>\n\n\n\n<h3 id=\"h-here-are-the-candidate-algorithms\" class=\"wp-block-heading\">Here are the Candidate Algorithms:<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>FAEST<\/li>\n\n\n\n<li>HAWK<\/li>\n\n\n\n<li>MAYO<\/li>\n\n\n\n<li>MQOM<\/li>\n\n\n\n<li>QR-UOV<\/li>\n\n\n\n<li>SDitH<\/li>\n\n\n\n<li>SNOVA<\/li>\n\n\n\n<li>SQIsign<\/li>\n\n\n\n<li>UOV<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The most recent announcement from NIST (National Institute of Standards and Technology) is the completion of their 18-month evaluation of all candidate <strong>post-quantum digital signature schemes<\/strong> and the commencement of a new phase that will evaluate some additional digital signature schemes that will help protect our critical systems against potential quantum attacks in the future.<\/p>\n\n\n\n<h2 id=\"h-the-evolution-of-nist-s-pqc-standardization-journey\" class=\"wp-block-heading\">The Evolution of NIST&#8217;s PQC Standardization Journey<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Due to growing concern over large-scale quantum computing&#8217;s ability to break common public-key cryptography, NIST began creating the\u00a0initial\u00a0set of post-quantum standard documents. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This included a PQC competition, which aimed to\u00a0identify\u00a0post-quantum-safe digital signature and key agreement algorithms suitable for government, commercial and critical infrastructure applications.\u00a0\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As part of the certification process for these post-quantum candidates, <strong>NIST has conducted<\/strong>\u00a0several\u00a0peer-reviewed evaluations, each consisting of a series of rounds, and publicly reviewed\u00a0submitted\u00a0algorithms (via cryptanalysis).\u00a0<\/p>\n\n\n\n<h3 id=\"h-the-first-round-of-standards-included\" class=\"wp-block-heading\">The First Round of Standards Included:\u00a0<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>CRYSTALS-Kyber<\/strong> (now standardized as <strong>ML-KEM<\/strong>) for key establishment\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/signmycode.com\/blog\/what-is-ml-dsa-crystals-dilithium-the-future-of-digital-signatures-beyond-rsa-and-ecc\"><strong>CRYSTALS-Dilithium<\/strong><\/a>\u00a0(now standardized as <strong>ML-DSA<\/strong>) for digital signatures\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Falcon for Digital Signatures.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>SPHINCS+<\/strong> (now standardized as <strong>SLH-DSA<\/strong>) for digital signatures\u00a0<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The <strong>NIST agency issued the first set of PQC standards in August of 2024<\/strong>. PQC standards are used as the foundation for organizations to begin their transition to quantum-resilient cryptography. Therefore, PQC provides\u00a0organizations\u00a0with the first legally recognized algorithms of PQC to use for their transition to quantum-resilient cryptography.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The need for long-term security includes having many&nbsp;different types&nbsp;of cryptographic methods (i.e., diversity); therefore, systems that belong to the same mathematical family are likely to share the same vulnerabilities.&nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To support long-term security of all cryptographic systems, <strong>NIST initiated an Independent Digital Signatures (IDS) program in 2022<\/strong> to develop additional digital signature schemes that shared a different mathematical base than those currently in use and also produced differing performance and deployment characteristics than those currently in use.<\/p>\n\n\n\n<h2 id=\"h-why-additional-signature-algorithms-matter\" class=\"wp-block-heading\">Why Additional Signature Algorithms Matter<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The original version of standardized algorithms for post-quantum cryptography offers strong initial building blocks to a sound quantum-safe security model. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Many of these protocols share some of the same underlying mathematical models, and therefore can share vulnerabilities due to the common [or similar] mathematical assumptions of those models \u2014 primarily to their reliance on<strong> lattice-based cryptography<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As a part of the Additional Signatures project, NIST is working to mitigate some of the systemic risk that occurs whenever there is a cryptanalytic breakthrough. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When you have a crypto analysis breakthrough that can be used to compromise an entire class of algorithms that share a particular underlying mathematical structure, then you will have a set of alternative algorithms based on different mathematical structures that will be able to function as inter-technical replacements for the class that has been attacked.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NIST is also interested in finding algorithms that would provide specific advantages over other algorithms when implementing them in diverse deployment scenarios, and, therefore, can be expected to provide value in those instances. <\/p>\n\n\n\n<h3 id=\"h-these-use-cases-may-include-but-will-not-be-limited-to\" class=\"wp-block-heading\">These use cases may include, but will not be limited to:<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Smaller signature sizes<\/li>\n\n\n\n<li>Smaller public-key sizes<\/li>\n\n\n\n<li>Faster verification times<\/li>\n\n\n\n<li>Better performance on constrained devices<\/li>\n\n\n\n<li>Easier implementation and deployment<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">These reasons for diversification become increasingly important as governments, enterprises, cloud service providers, and certificate authorities begin to transition to a large-scale PQC solution.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Recommended:<\/strong> <a href=\"https:\/\/signmycode.com\/blog\/aws-kms-embraces-the-quantum-era-with-ml-dsa-digital-signature-support\">AWS KMS Embraces the Quantum Era with ML-DSA Digital Signature Support<\/a><\/p>\n\n\n\n<h2 id=\"h-from-50-submissions-to-9-finalists\" class=\"wp-block-heading\">From 50 Submissions to 9 Finalists<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The additional digital signature process began with a call for proposals in 2022.<\/p>\n\n\n\n<h3 id=\"h-the-competition-progressed-through-several-stages\" class=\"wp-block-heading\">The competition progressed through several stages:<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>50 submissions received<\/li>\n\n\n\n<li>40 candidates accepted into the first round<\/li>\n\n\n\n<li>14 candidates advanced to the second round<\/li>\n\n\n\n<li>9 candidates selected for the third round<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Throughout the evaluation process, NIST researchers and the broader cryptographic community conducted extensive security reviews, implementation studies, performance testing, and cryptanalysis.<\/p>\n\n\n\n<h3 id=\"h-the-remaining-candidates-represent-a-diverse-collection-of-cryptographic-families\" class=\"wp-block-heading\">The remaining candidates represent a diverse collection of cryptographic families:<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Algorithm<\/strong><\/td><td><strong>Cryptographic Family<\/strong><\/td><\/tr><tr><td>FAEST<\/td><td>Symmetric-key \/ VOLE-in-the-Head<\/td><\/tr><tr><td>HAWK<\/td><td>Lattice-based<\/td><\/tr><tr><td>MAYO<\/td><td>Multivariate<\/td><\/tr><tr><td>MQOM<\/td><td>Multivariate \/ MPC-in-the-Head<\/td><\/tr><tr><td>QR-UOV<\/td><td>Multivariate<\/td><\/tr><tr><td>SDitH<\/td><td>Code-based \/ MPC-in-the-Head<\/td><\/tr><tr><td>SNOVA<\/td><td>Multivariate<\/td><\/tr><tr><td>SQIsign<\/td><td>Isogeny-based<\/td><\/tr><tr><td>UOV<\/td><td>Multivariate<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The selection demonstrates NIST&#8217;s commitment to preserving cryptographic diversity rather than concentrating exclusively on one mathematical approach.<\/p>\n\n\n\n<h2 id=\"h-nist-s-evaluation-criteria\" class=\"wp-block-heading\">NIST&#8217;s Evaluation Criteria<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">NIST evaluated the second-round candidates using three primary categories:<\/p>\n\n\n\n<h3 id=\"h-security\" class=\"wp-block-heading\"><a><\/a>Security<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Security remains the agency&#8217;s highest priority. <strong>Candidate algorithms were assessed for:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Resistance to classical attacks<\/li>\n\n\n\n<li>Resistance to quantum attacks<\/li>\n\n\n\n<li>Strong unforgeability guarantees<\/li>\n\n\n\n<li>Multi-key attack resistance<\/li>\n\n\n\n<li>Side-channel resilience<\/li>\n\n\n\n<li>Fault-injection resistance<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Because these algorithms could eventually protect <a href=\"https:\/\/signmycode.com\/software-publisher-certificate\">digital certificates<\/a>, software updates, government communications, financial systems, and critical infrastructure, long-term security confidence remains paramount.<\/p>\n\n\n\n<h3 id=\"h-performance-and-cost\" class=\"wp-block-heading\"><a><\/a>Performance and Cost<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">NIST also examined:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Signature generation speed<\/li>\n\n\n\n<li>Verification speed<\/li>\n\n\n\n<li>Computational efficiency<\/li>\n\n\n\n<li>Memory requirements<\/li>\n\n\n\n<li>Hardware acceleration potential<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Performance characteristics are especially important for resource-constrained environments such as IoT devices, embedded systems, smart cards, and edge computing platforms.<\/p>\n\n\n\n<h3 id=\"h-implementation-characteristics\" class=\"wp-block-heading\"><a><\/a>Implementation Characteristics<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The agency evaluated:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Ease of implementation<\/li>\n\n\n\n<li>Deployment complexity<\/li>\n\n\n\n<li>Side-channel mitigation requirements<\/li>\n\n\n\n<li>Intellectual property considerations<\/li>\n\n\n\n<li>Long-term maintainability<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Notably, NIST reported that no side-channel findings during the second round were severe enough to eliminate any candidate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Recommended:<\/strong> <a href=\"https:\/\/signmycode.com\/blog\/google-cloud-kms-introduces-quantum-safe-digital-signatures\">Google Cloud KMS Introduces Quantum-Safe Digital Signatures Align with NIST\u2019s PQC Standards<\/a><\/p>\n\n\n\n<h2 id=\"h-standout-candidates\" class=\"wp-block-heading\"><a><\/a>Standout Candidates<\/h2>\n\n\n\n<h3 id=\"h-sqisign\" class=\"wp-block-heading\"><a><\/a>SQIsign<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">SQIsign emerged as one of the most distinctive candidates due to its exceptionally small public-key and signature sizes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>These characteristics make it particularly attractive for:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Digital certificates<\/li>\n\n\n\n<li>Firmware updates<\/li>\n\n\n\n<li>Embedded systems<\/li>\n\n\n\n<li>Constrained devices<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">According to NIST&#8217;s findings, refinements made to the architecture of SQIsign have resulted in significant improvements to the functionality of this signing algorithm, allowing for the signing of SQIsign&#8217;s output approximately 20x faster than before these refinements were applied. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Furthermore, <strong>NIST concluded that <\/strong>the refinements made to SQIsign did not compromise the previous security provided against attacks that had previously exploited SIKE cryptography. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As a result, although SQISign has experienced implementation complexity and side-channel resistance issues, very compact signature size and a mature design aided in its progression to Stage 3 of the competition.<\/p>\n\n\n\n<h3 id=\"h-hawk\" class=\"wp-block-heading\"><a><\/a>HAWK<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">HAWK is a <strong>lattice-based alternative<\/strong> that does not have an inherent need for floating point arithmetic to achieve the same level of security and functionality as Falcon, due to being completely integer-based; this means:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Simpler implementation<\/li>\n\n\n\n<li>Greater portability<\/li>\n\n\n\n<li>Improved suitability for constrained environments<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Because the signature size of HAWK is very small and the speed of signing is efficient, the <strong>NIST recommended<\/strong> that HAWK continue to be evaluated for security-based issues with respect to the original security assumptions.<\/p>\n\n\n\n<h3 id=\"h-faest\" class=\"wp-block-heading\"><a><\/a>FAEST<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">FAEST is a conservative design philosophy that uses existing symmetric cryptographic techniques (including AES) and has achieved significantly greater performance, not to mention it produces increased quantum security proofs, than the previous version.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While researchers have identified potential vulnerabilities associated with some types of implementations (e.g., fault attacks and side-channel attacks), the National Institute of Standards and Technology has concluded that such vulnerabilities can be managed, and therefore allowed FAEST to progress to the third round of research and testing.<\/p>\n\n\n\n<h3 id=\"h-mqom-and-sdith\" class=\"wp-block-heading\"><a><\/a>MQOM and SDitH<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Among the other MPC candidates and those already classified as MPC candidates that were reviewed, MQOM and SDitH stood out as very good submissions. MQOM produced a performance level that matched that of existing methods (for example, RSA) for an equivalent level of security and produced signatures with smaller key sizes\/signatures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SDitH has the advantage of a long history of research into syndrome decoding and has historically employed conservative security assumptions in its theories of security. <strong>Therefore, both MQOM and SDitH will be viewed by NIST as good candidates<\/strong> for providing a larger cryptographic diversity than the traditional and non-traditional methods of cryptography to date.<\/p>\n\n\n\n<h2 id=\"h-the-multivariate-cryptography-story\" class=\"wp-block-heading\"><a><\/a>The Multivariate Cryptography Story<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Perhaps the most interesting aspect of the third-round selections is the continued presence of four multivariate candidates:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>UOV<\/li>\n\n\n\n<li>MAYO<\/li>\n\n\n\n<li>QR-UOV<\/li>\n\n\n\n<li>SNOVA<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Researchers found several ways of &#8216;attacking&#8217; UOV, MAYO, and SNOVA in the second round of development of these algorithms, specifically in regard to their multiple parameters. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ultimately, NIST has determined that the attacks affected only some of the possible parameters for each of the algorithms, and therefore did not significantly undermine UOV, MAYO, and SNOVA.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>NIST has reaffirmed that secure settings exist for each of the four algorithms and also for all proposed parameters for these algorithms,<\/strong> including QR-UOV.<\/p>\n\n\n\n<h3 id=\"h-uov\" class=\"wp-block-heading\"><a><\/a>UOV<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">UOV continues to be attractive due to its small signature sizes and quick verification times. <strong>NIST continues to view UOV as a very valid contributor<\/strong> to algorithmic diversity, even though it suffers from some large publication sizes.<\/p>\n\n\n\n<h3 id=\"h-mayo\" class=\"wp-block-heading\"><a><\/a>MAYO<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">MAYO will provide a smaller public key than UOV while keeping the same signature size and verification time as UOV. <strong>NIST determined that<\/strong> some parameter settings of MAYO were negatively impacted by wedge attacks; however, the overall system architecture was not at fault for the loss from these wedge attacks.<\/p>\n\n\n\n<h3 id=\"h-qr-uov\" class=\"wp-block-heading\"><a><\/a>QR-UOV<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The QR-UOV algorithm has avoided the problems associated with wedge attacks on other multivariate schemes. This algorithm has achieved a significant reduction in the amount of public key data by using quotient ring techniques and by utilizing odd characteristic fields. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The result is that QR-UOV provides excellent security margins along with significant performance increases (compared to other schemes).<\/p>\n\n\n\n<h3 id=\"h-snova\" class=\"wp-block-heading\"><a><\/a>SNOVA<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">SNOVA continues to be a candidate for the NIST post-quantum cryptographic standard even after being attacked cryptographically\/during the competition. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Its most recent parameter sets indicate that SNOVA has very competitive efficiencies compared to other schemes and has created smaller public key sizes and signatures than Falcon in several instances. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Although NIST stated<\/strong> that they view the scheme as immature compared to some other competing schemes, they kept SNOVA as a candidate due to its potential for long-term usage.<\/p>\n\n\n\n<h2 id=\"h-candidates-eliminated-in-round-two\" class=\"wp-block-heading\">Candidates Eliminated in Round Two<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Several notable candidates were eliminated after the second round.<\/p>\n\n\n\n<h3 id=\"h-cross\" class=\"wp-block-heading\"><a><\/a>CROSS<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">After completing an additional security evaluation and refining their parameters, <strong>NIST concluded<\/strong> that the performance profile was still too similar to that of SPHINCS+ and did not offer enough of an advantage over SPHINCS+, as well as having very large signatures (relative to other submitted candidates).<\/p>\n\n\n\n<h3 id=\"h-less\" class=\"wp-block-heading\"><a><\/a>LESS<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">By optimising, LESS has achieved significantly lower signature sizes. However, this candidate had very large public keys and did not deliver acceptable performance relative to other candidates; therefore, <strong>NIST eliminated LESS <\/strong>due to concerns about the widespread use of attack methods against this candidate&#8217;s security margins.<\/p>\n\n\n\n<h3 id=\"h-mirath-perk-and-ryde\" class=\"wp-block-heading\"><a><\/a>Mirath, PERK, and RYDE<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Despite significant improvements shown by all 3 solutions in round 2 of this process, NIST found that their better combinations of security, maturity, &amp; performance from competing systems meant those 3 will no longer advance in this process.<\/p>\n\n\n\n<h2 id=\"h-what-happens-next\" class=\"wp-block-heading\">What Happens Next?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">NIST anticipates a duration of roughly 2 years before this 3rd phase of evaluations ends. Companies that submitted entries can make limited changes to address identified weaknesses or inconsistencies and\/or to resolve implementation issues, until revised packages must be submitted by August 14, 2026.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While <strong>NIST expects revisions only in minor ways, <\/strong>submission redesigns may suggest a less than ready state regarding new patterns of standardization; however, where the technology submitted is completely new, other than limitations outlined in the evaluation guidelines, NIST may accept prior designs that have not been submitted from this process due to late entry into the competition.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Throughout this time, <strong>NIST urges the global cryptography community<\/strong> to continue its review of the systems still being evaluated via these methods by:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Cryptanalysis<\/li>\n\n\n\n<li>Optimized software implementations<\/li>\n\n\n\n<li>Hardware acceleration studies<\/li>\n\n\n\n<li>Constrained-device testing<\/li>\n\n\n\n<li>Side-channel assessments<\/li>\n\n\n\n<li>Performance benchmarking<\/li>\n<\/ul>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\">NIST also plans to host the 7th NIST PQC Standardization Conference in 2027, likely in or near Gaithersburg, Maryland.<\/p>\n\n\n\n<h2 id=\"h-broader-post-quantum-transition\" class=\"wp-block-heading\">Broader Post-Quantum Transition<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The announcement arrives amid growing efforts to prepare for the eventual arrival of practical quantum computing.<\/p>\n\n\n\n<h3 id=\"h-recent-initiatives-include\" class=\"wp-block-heading\">Recent Initiatives include:<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Publication of NIST&#8217;s first PQC standards<\/li>\n\n\n\n<li>Release of NIST&#8217;s draft PQC transition strategy<\/li>\n\n\n\n<li>Federal guidance encouraging cryptographic inventory assessments<\/li>\n\n\n\n<li>CISA&#8217;s publication of hardware and software categories supporting PQC standards<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Cybersecurity professionals are warning against threats involving the &#8220;going in the barn,&#8221; where an opponent will harvest data through encrypted methods today, with the intention of decrypting that data with new quantum computers at a later date.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Therefore, organizations are being asked to begin planning for <a href=\"https:\/\/signmycode.com\/blog\/pqc-code-signing-in-a-cnsa-2-0-world-preparing-for-the-quantum-leap\">PQC migration<\/a> sooner rather than take their chances and wait until quantum computers are operational.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Also Read:<\/strong> <a href=\"https:\/\/signmycode.com\/blog\/what-is-trust-now-forge-later-tnfl-vs-hndl-attacks-explained\">What Is Trust Now, Forge Later (TNFL)? TNFL vs HNDL Attacks Explained<\/a><\/p>\n\n\n\n<h2 id=\"h-conclusion\" class=\"wp-block-heading\"><a><\/a>Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Post-Quantum Cryptography (PQC) is changing from just being an academic project to being one of the Significant building Blocks of future Cyber Security Strategy. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The emergence of quantum computing requires that organizations prepare for a major shift in their cryptographic infrastructure to assure the protection of all sensitive data (e.g., user identities), communication, and vital infrastructure against new threats.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Quick Summary Globally, companies are still preparing for a quantum revolution, and the National Institute of Standards and Technology (NIST) has made significant progress on its Post-Quantum Cryptography (PQC) Standardization Program. On May 21, 2026, NIST named the 9 digital signature algorithms that are moving onto the next round of candidates for their Additional Digital&hellip; <a class=\"more-link\" href=\"https:\/\/signmycode.com\/blog\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures\">Read More <span class=\"screen-reader-text\">NIST Announces Third Round Candidates for Post-Quantum Digital Signatures<\/span><\/a> <\/p>\n","protected":false},"author":1,"featured_media":5739,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[458],"tags":[932,930,931,929],"class_list":["post-5736","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-security","tag-digital-signature-algorithms-pqc","tag-nist-post-quantum-cryptography-standardization-process","tag-post-quantum-digital-signature","tag-post-quantum-cryptography","entry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v24.6 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>NIST Announces 9 Advanced Candidates for Post Quantum Digital Signatures<\/title>\n<meta name=\"description\" content=\"The NIST PQC program has advanced nine digital signature algorithms for continued evaluation, helping shape the future of quantum resistant cybersecurity.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/signmycode.com\/blog\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NIST Announces Third Round Candidates for Post-Quantum Digital Signatures\" \/>\n<meta property=\"og:description\" content=\"The NIST PQC program has advanced nine digital signature algorithms for continued evaluation, helping shape the future of quantum resistant cybersecurity.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/signmycode.com\/blog\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures\" \/>\n<meta property=\"og:site_name\" content=\"SignMyCode - Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-11T11:10:23+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-06-11T11:10:28+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2026\/06\/nist-pqc-digital-signature-algorithms.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"912\" \/>\n\t<meta property=\"og:image:height\" content=\"453\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Janki Mehta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Janki Mehta\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures\",\"url\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures\",\"name\":\"NIST Announces 9 Advanced Candidates for Post Quantum Digital Signatures\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/nist-pqc-digital-signature-algorithms.webp\",\"datePublished\":\"2026-06-11T11:10:23+00:00\",\"dateModified\":\"2026-06-11T11:10:28+00:00\",\"description\":\"The NIST PQC program has advanced nine digital signature algorithms for continued evaluation, helping shape the future of quantum resistant cybersecurity.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/signmycode.com\\\/blog\\\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures#primaryimage\",\"url\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/nist-pqc-digital-signature-algorithms.webp\",\"contentUrl\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/nist-pqc-digital-signature-algorithms.webp\",\"width\":912,\"height\":453,\"caption\":\"Quantum Safe Digital Signature\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"NIST Announces Third Round Candidates for Post-Quantum Digital Signatures\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/\",\"name\":\"SignMyCode - Blog\",\"description\":\"Code Signing News, Updates\",\"publisher\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#organization\",\"name\":\"SignMyCode.com\",\"url\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/logo1.png\",\"contentUrl\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/logo1.png\",\"width\":135,\"height\":86,\"caption\":\"SignMyCode.com\"},\"image\":{\"@id\":\"https:\\\/\\\/signmycode.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"NIST Announces 9 Advanced Candidates for Post Quantum Digital Signatures","description":"The NIST PQC program has advanced nine digital signature algorithms for continued evaluation, helping shape the future of quantum resistant cybersecurity.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/signmycode.com\/blog\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures","og_locale":"en_US","og_type":"article","og_title":"NIST Announces Third Round Candidates for Post-Quantum Digital Signatures","og_description":"The NIST PQC program has advanced nine digital signature algorithms for continued evaluation, helping shape the future of quantum resistant cybersecurity.","og_url":"https:\/\/signmycode.com\/blog\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures","og_site_name":"SignMyCode - Blog","article_published_time":"2026-06-11T11:10:23+00:00","article_modified_time":"2026-06-11T11:10:28+00:00","og_image":[{"width":912,"height":453,"url":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2026\/06\/nist-pqc-digital-signature-algorithms.webp","type":"image\/jpeg"}],"author":"Janki Mehta","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Janki Mehta","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/signmycode.com\/blog\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures","url":"https:\/\/signmycode.com\/blog\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures","name":"NIST Announces 9 Advanced Candidates for Post Quantum Digital Signatures","isPartOf":{"@id":"https:\/\/signmycode.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/signmycode.com\/blog\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures#primaryimage"},"image":{"@id":"https:\/\/signmycode.com\/blog\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures#primaryimage"},"thumbnailUrl":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2026\/06\/nist-pqc-digital-signature-algorithms.webp","datePublished":"2026-06-11T11:10:23+00:00","dateModified":"2026-06-11T11:10:28+00:00","description":"The NIST PQC program has advanced nine digital signature algorithms for continued evaluation, helping shape the future of quantum resistant cybersecurity.","breadcrumb":{"@id":"https:\/\/signmycode.com\/blog\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/signmycode.com\/blog\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/signmycode.com\/blog\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures#primaryimage","url":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2026\/06\/nist-pqc-digital-signature-algorithms.webp","contentUrl":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2026\/06\/nist-pqc-digital-signature-algorithms.webp","width":912,"height":453,"caption":"Quantum Safe Digital Signature"},{"@type":"BreadcrumbList","@id":"https:\/\/signmycode.com\/blog\/nist-announces-third-round-candidates-for-post-quantum-digital-signatures#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/signmycode.com\/blog\/"},{"@type":"ListItem","position":2,"name":"NIST Announces Third Round Candidates for Post-Quantum Digital Signatures"}]},{"@type":"WebSite","@id":"https:\/\/signmycode.com\/blog\/#website","url":"https:\/\/signmycode.com\/blog\/","name":"SignMyCode - Blog","description":"Code Signing News, Updates","publisher":{"@id":"https:\/\/signmycode.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/signmycode.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/signmycode.com\/blog\/#organization","name":"SignMyCode.com","url":"https:\/\/signmycode.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/signmycode.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2021\/10\/logo1.png","contentUrl":"https:\/\/signmycode.com\/blog\/wp-content\/uploads\/2021\/10\/logo1.png","width":135,"height":86,"caption":"SignMyCode.com"},"image":{"@id":"https:\/\/signmycode.com\/blog\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/posts\/5736","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/comments?post=5736"}],"version-history":[{"count":7,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/posts\/5736\/revisions"}],"predecessor-version":[{"id":5748,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/posts\/5736\/revisions\/5748"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/media\/5739"}],"wp:attachment":[{"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/media?parent=5736"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/categories?post=5736"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/signmycode.com\/blog\/wp-json\/wp\/v2\/tags?post=5736"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}