ID  Algorithm  Requirement  Definition 

TBD (105 for testing)  MLKEM768+X25519  MUST 

TBD (106 for testing)  MLKEM1024+X448  SHOULD 

ID  Algorithm  Requirement  Definition 

TBD (107 for testing)  MLDSA65+Ed25519  MUST 

TBD (108 for testing)  MLDSA87+Ed448  SHOULD 

TBD  SLHDSASHAKE128s  MAY 

TBD  SLHDSASHAKE128f  MAY 

TBD  SLHDSASHAKE256s  MAY 

X25519  X448  

Algorithm ID reference  TBD (105 for testing)  TBD (106 for testing) 
Field size  32 octets  56 octets 
ECDHKEM  x25519Kem ( 
x448Kem ( 
ECDH public key  32 octets 
56 octets 
ECDH secret key  32 octets 
56 octets 
ECDH ephemeral  32 octets 
56 octets 
ECDH share  32 octets 
56 octets 
Key share  32 octets  64 octets 
Hash  SHA3256  SHA3512 
Algorithm ID reference  MLKEM  Public key  Secret key  Ciphertext  Key share 

TBD (105 for testing)  MLKEM768  1184  2400  1088  32 
TBD (106 for testing)  MLKEM1024  1568  3168  1568  32 
Algorithm ID reference  MLKEM  ECDHKEM 

TBD (105 for testing)  MLKEM768  x25519Kem 
TBD (106 for testing)  MLKEM1024  x448Kem 
Algorithm ID reference  Curve  Field size  Public key  Secret key  Signature 

TBD (107 for testing)  Ed25519  32  32  32  64 
TBD (108 for testing)  Ed448  57  57  57  114 
Algorithm ID reference  MLDSA  Public key  Secret key  Signature value 

TBD (107 for testing)  MLDSA65  1952  4032  3293 
TBD (108 for testing)  MLDSA87  2592  4896  4595 
Algorithm ID reference  Hash function  Hash function ID reference 

TBD (107 for testing)  SHA3256  12 
TBD (108 for testing)  SHA3512  14 
Algorithm ID reference  SLHDSASHAKE public key  SLHDSASHAKE secret key  SLHDSASHAKE signature 

TBD (SLHDSASHAKE128s)  32  64  7856 
TBD (SLHDSASHAKE128f)  32  64  17088 
TBD (SLHDSASHAKE256s)  64  128  29792 
Algorithm ID reference  Hash function  Hash function ID reference 

TBD (SLHDSASHAKE128s)  SHA3256  12 
TBD (SLHDSASHAKE128f)  SHA3256  12 
TBD (SLHDSASHAKE256s)  SHA3512  14 
ID  Algorithm  Public Key Format  Secret Key Format  Signature Format  PKESK Format  Reference 

TBD  MLKEM768+X25519  32 octets X25519 public key ( 
32 octets X25519 secret key ( 
N/A  32 octets X25519 ciphertext, 1088 octets MLKEM768 ciphertext [, 1 octet algorithm ID in case of v3 PKESK], 1 octet length field of value n, n octets wrapped session key ( 

TBD  MLKEM1024+X448  56 octets X448 public key ( 
56 octets X448 secret key ( 
N/A  56 octets X448 ciphertext, 1568 octets MLKEM1024 ciphertext [, 1 octet algorithm ID in case of v3 PKESK], 1 octet length field of value n, n octets wrapped session key ( 

TBD  MLDSA65+Ed25519  32 octets Ed25519 public key ( 
32 octets Ed25519 secret key ( 
64 octets Ed25519 signature ( 
N/A 

TBD  MLDSA87+Ed448  57 octets Ed448 public key ( 
57 octets Ed448 secret key ( 
114 octets Ed448 signature ( 
N/A 

TBD  SLHDSASHAKE128s  32 octets public key ( 
64 octets secret key ( 
7856 octets signature ( 
N/A 

TBD  SLHDSASHAKE128f  32 octets public key ( 
64 octets secret key ( 
17088 octets signature ( 
N/A 

TBD  SLHDSASHAKE256s  64 octets public key ( 
128 octets secret key ( 
29792 octets signature ( 
N/A 
