Key length and PQC transition

Key length

The minimum key sizes each source publishes for protecting data until a given year. The rules that apply to you come first, and every figure links to the document it comes from. New to this? Start with why key length matters and which year to enter.

Rules that apply to you

No rules selected, so every source is listed as comparison.

Data encrypted today with RSA or elliptic-curve key exchange and needing secrecy until 2035 can be recorded now and decrypted later if a large quantum computer arrives first.

NIST12031 to open
Symmetric
128
Factoring modulus
3,072
Discrete log
3,072 / 256
Elliptic curve
256
Hash
256
ML-KEM (FIPS 203)
Signatures: ML-DSA, SLH-DSA
BSI42026 to 2032
Symmetric
128
Factoring modulus
Hybrid only
Discrete log
Hybrid only
Elliptic curve
Hybrid only
Hash
256
Hybrid with a classical scheme: ML-KEM-768 or -1024, FrodoKEM-976 or -1344, or Classic McEliece
Signatures: ML-DSA-65 or -87, SLH-DSA (192 or 256), LMS or XMSS; classical signatures until end of 2035
ANSSI52031 to open
Symmetric
128
Factoring modulus
3,072
Discrete log
3,072 / 250
Elliptic curve
250
Hash
256
Hybrid with a classical scheme: ML-KEM-768 preferred (512 allowed), FrodoKEM-976 preferred; post-quantum recommended for use beyond 2030
Signatures: ML-DSA hybrid with a classical signature; SLH-DSA may be used alone
NSA CNSA 2.062025 to open
Symmetric
256
Factoring modulus
Transition only
Discrete log
Transition only
Elliptic curve
Transition only
Hash
384
ML-KEM-1024
Signatures: ML-DSA-87; LMS or XMSS for firmware
Symmetric
not imported
Factoring modulus
Retired
Discrete log
Retired
Elliptic curve
Retired
Hash
not imported
ASD-approved PQC (ISM)
Source Window Symmetric ? Factoring modulus ? DL key / group ? Elliptic curve ? Hash ? Post-quantum ?
NIST12031 to open1283,0723,072 / 256256256ML-KEM (FIPS 203)
Sig: ML-DSA, SLH-DSA
BSI42026 to 2032128Hybrid onlyHybrid onlyHybrid only256Hybrid with a classical scheme: ML-KEM-768 or -1024, FrodoKEM-976 or -1344, or Classic McEliece
Sig: ML-DSA-65 or -87, SLH-DSA (192 or 256), LMS or XMSS; classical signatures until end of 2035
ANSSI52031 to open1283,0723,072 / 250250256Hybrid with a classical scheme: ML-KEM-768 preferred (512 allowed), FrodoKEM-976 preferred; post-quantum recommended for use beyond 2030
Sig: ML-DSA hybrid with a classical signature; SLH-DSA may be used alone
NSA CNSA 2.062025 to open256Transition onlyTransition onlyTransition only384ML-KEM-1024
Sig: ML-DSA-87; LMS or XMSS for firmware
ASD7not importedRetiredRetiredRetirednot importedASD-approved PQC (ISM)

All sizes in bits and all are minimums. Grey italic values fall outside the source's own window and show where it last stood. D draft, S superseded edition, 2nd not yet checked against the primary document. The Lenstra and Verheul, Lenstra 2004 and RFC 3766 models are not yet implemented.

References

  1. NIST SP 800-57 Pt 1 Rev 5, NIST, 2020-05.
  2. NIST SP 800-57 Pt 1 Rev 6 initial public draft, NIST, 2025-12-05, draft.
  3. NIST IR 8547 initial public draft, NIST, 2024-11-12, draft.
  4. BSI TR-02102-1, Cryptographic Mechanisms: Recommendations and Key Lengths, version 2026-01, BSI, 2026-01-23.
  5. ANSSI-PG-083, Règles et recommandations concernant le choix et le dimensionnement des mécanismes cryptographiques, v3.00, ANSSI, 2026-03-20.
  6. NSA CNSA 2.0 algorithms advisory, NSA, 2025-05-30.
  7. ASD, Planning for post-quantum cryptography, ASD, 2025-09-22.

How your rules compare

Each line is one source's minimum over the years it covers, with your rules in colour. The shaded band spans the least and most demanding sources and the dashed line is the median.

RetiringQuantum-vulnerablealgorithms retired1,5362,0482,5603,0723,58420202022202420262028203020322034203620382040NISTANSSIBSI2035
Range across sourcesMedianYour rules, in colourOther sourcesClassical retirement