← Migration news
Standards· 11 Mar 2025· United States· 3 min read

NIST selects HQC as a backup key encapsulation standard

HQC gives the standards portfolio a non-lattice fallback to ML-KEM, with a draft standard in 2026 and a final standard expected in 2027.

On 11 March 2025 NIST selected HQC at the end of the fourth round of its post-quantum standardisation process, as a key encapsulation mechanism based on error-correcting codes rather than structured lattices.

The point of HQC is diversification. ML-KEM (FIPS 203) remains the primary recommendation; HQC exists so that a future breakthrough against lattice assumptions would not leave deployers without a standardised alternative.

NIST said it planned a draft standard about a year later, with a finalised standard expected in 2027. The draft is being prepared as FIPS 207.

What it means for your migration
  • Do not wait for HQC. ML-KEM is the algorithm to deploy now; HQC is insurance, not a replacement plan.
  • Design for crypto-agility so a second KEM can be introduced without re-architecting protocols and key management.
  • Procurement questions can reasonably ask vendors about algorithm agility rather than HQC support dates.

HQC is selected but not yet a published standard; implementation guidance can still change before FIPS 207 is final.

Chronology

Timeline of events

Every step in this story with its date, authority and evidence class.

  1. 13 Aug 2024A1

    First three PQC standards finalised

    FIPS 203, 204 and 205 published.

    NIST

  2. 11 Mar 2025A1

    HQC selected for standardisation

    NIST announces HQC as the fourth-round selection and fifth algorithm overall.

    NIST

  3. 31 Dec 2027A2

    Final HQC standard expected

    NIST expects the finalised standard in 2027.

    NIST