top of page

ISO/IEC 18033-2:2006/Amd 2:2026 has published.

  • Writer: Brian Couzens
    Brian Couzens
  • Jun 16
  • 2 min read

Three post-quantum KEMs now sit inside one of the principal international standards for asymmetric encryption: ML-KEM, Classic McEliece and FrodoKEM.


Read that again. Not one algorithm. Three. From three different mathematical families.


Why this matters before the detail.


A standards body had a choice. It could have ratified the market's preferred answer, ML-KEM, and closed the question. It did not. It standardised a structured lattice scheme, an unstructured lattice scheme and a code-based scheme alongside each other. That is a deliberate governance decision, not an engineering accident. ISO has declined to concentrate the future of public-key encryption in a single algorithm family.


The signal is concentration risk. If a weakness emerges in lattice cryptography, internationally recognised alternatives already exist inside the same standard. Optionality has been preserved at the standards layer, where it is hardest to retrofit later.


š“š”šž šŸšššœš­š¬.


#ML-KEM is the standardised form of CRYSTALS-Kyber, also published by NIST as FIPS 203. It carries the strongest adoption momentum across TLS, VPN, HSM and PKI estates.


Classic #McEliece is code-based, with decades of cryptanalytic scrutiny. NIST has not standardised it. ISO judged it mature enough to include. That divergence is the most instructive part of the amendment.


#FrodoKEM is a conservative lattice design built on unstructured Learning With Errors, a hedge against structure-specific attacks on lattice schemes.


š–š”ššš­ š¢š­ šœš”ššš§š šžš¬.


Procurement is where this lands first. Expect ISO 18033-2 alignment to appear in government tenders, banking RFPs, critical infrastructure requirements and product certification over the next two to four years. The question shifts from "do you support PQC" to "which standardised families, and can you replace one without redesign."


Governance consequence for boards.


Single-algorithm dependency is now a documented structural risk, not a theoretical one. The standard itself contradicts the narrative that PQC equals ML-KEM. Crypto-agility stops being an aspiration and becomes a procurement test you will be asked to pass.


One caveat for precision. This brief addresses the inclusion of the three KEMs. Claims about classical-plus-PQC hybrid constructions within the amendment require sight of the published normative text before assertion.


The future of cryptography will not belong to one algorithm.

It will belong to architectures agile enough to change as the science does.




Ā 
Ā 
Ā 

Recent Posts

See All
An Analysis of ASD's PQC Vendor Approach.

One supplier can destroy five years of post-quantum planning. Not through incompetence. Through dependency. The conversation around post-quantum cryptography still revolves around algorithms, migratio

Ā 
Ā 
Ā 

Comments


bottom of page