Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In a May 13, 2022 report, then-NSA Cybersecurity Director Rob Joyce said of the post-quantum standards effort, “There are no backdoors.” That was his assurance about the standards process—not independent proof that every implementation or product using the resulting algorithms is free of vulnerabilities. NIST has since finalized three distinct standards: one for establishing cryptographic keys and two for digital signatures.

What did the NSA’s “no backdoors” statement refer to?

Bloomberg, in a report republished by Data Center Knowledge on May 13, 2022, quoted Joyce saying, “There are no backdoors.” The story concerned NIST’s then-pending effort to standardize post-quantum cryptography. Joyce’s statement was an assurance about that standards effort, not a guarantee about every software implementation, device, or deployed system that might later use a standardized algorithm. Read the May 2022 report.

NIST—not the NSA—is the standards authority identified in the report’s subject. NIST’s process selected and developed standards from submissions to its post-quantum cryptography project. The distinction matters: the standard defines an algorithm and its requirements, while security in practice also depends on how systems implement, configure, and maintain it.

Which standards were ultimately approved?

On August 13, 2024, NIST approved three Federal Information Processing Standards (FIPS) for post-quantum cryptography. They serve different purposes, so it is misleading to call all three “encryption algorithms.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Standard Algorithm What it does
FIPS 203 ML-KEM Key establishment: helps parties establish a shared secret over a public channel. It does not, by itself, encrypt all the application data exchanged afterward.
FIPS 204 ML-DSA Digital signatures: supports signing and verification to authenticate a signer and detect unauthorized changes.
FIPS 205 SLH-DSA Digital signatures: also supports signing and verification for authentication and integrity.

NIST designed these standards to resist attacks by future quantum computers. Their finalization establishes the standards; it does not establish that every organization has adopted them. NIST’s publications listing, updated August 5, 2026, marks FIPS 203, 204, and 205 as final while also showing continuing work, including a 2026 draft covering additional SLH-DSA parameter sets. See NIST’s post-quantum publications listing.

NIST’s approval announcement describes the standards and their separate functions. Read the August 2024 announcement.

Can quantum computers break encryption?

The policy concern is that sufficiently capable quantum computers could threaten some of today’s public-key cryptography. The NSA described that risk in its September 2022 announcement of the Commercial National Security Algorithm Suite 2.0 (CNSA 2.0), which sets future quantum-resistant requirements for National Security Systems (NSS). That announcement provides context for the migration effort; it does not supply a date for when a quantum computer will be capable of breaking current cryptography. Read the NSA’s CNSA 2.0 announcement.

Post-quantum cryptography is cryptography designed to withstand attacks from both conventional and quantum computers. Replacing or adding cryptographic algorithms is a transition for systems and organizations, not a claim that every existing encrypted connection is already broken.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How is NSA’s CNSA 2.0 guidance different from NIST’s standards?

NIST’s FIPS standards define algorithms for broad use. NSA’s CNSA 2.0 guidance is a separate policy context for National Security Systems. NSA says its selected algorithms are detailed in CNSA 2.0 and CNSS Policy 15, released March 4, 2025; those requirements should not be presented as a universal deadline or mandate for every consumer, company, or government system. See NSA’s current post-quantum resources.

That NSA resource page also says the agency favors post-quantum cryptography over quantum key distribution (QKD) for NSS, describing post-quantum cryptography as more cost-effective and easier to maintain in that setting. NSA does not recommend QKD/QC for NSS unless stated limitations are overcome. This is the agency’s recommendation within its NSS remit, not a universal verdict about QKD in every use case.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What does the assurance mean for organizations and users?

Joyce’s reported statement addresses confidence in the standards effort; it should not be treated as a blanket security warranty. A sound assessment separates three layers:

  • The standard: the published algorithm specification and its formal requirements.
  • The implementation: the code, hardware, configuration, and operational controls that put the algorithm to work.
  • The deployed system: the complete service or product, including key handling, updates, and the other components around the cryptography.

For organizations, NIST’s standards are a basis for planning a transition, not evidence that all systems have already migrated. Inventorying where public-key cryptography is used and planning how affected systems can be updated are practical steps; the specific schedule depends on the organization’s systems and applicable policy. NIST’s PQC publications page links to its transition resources alongside the standards.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.