Standards explainer

ML-KEM vs Kyber: What Changed in the NIST Standard?

Kyber was the name used during the NIST post-quantum competition. ML-KEM is the final NIST-standardised key encapsulation mechanism derived from Kyber and published as FIPS 203. For real migration planning, ML-KEM is the name that matters.

Kyber

The competition submission name most engineers saw before final standardisation.

ML-KEM

The NIST standard name for the key encapsulation mechanism in FIPS 203.

Migration impact

Use final standard terminology in procurement, architecture, compliance and implementation documents.

Why the Naming Matters

Teams still search for Kyber because that name appeared in research, prototypes and early vendor material. Procurement and compliance documents, however, should now reference FIPS 203 ML-KEM so the implementation target is clear.

The practical risk is ambiguity. A roadmap that says "enable Kyber" may not specify the final parameter set, approved implementation, library version, validation path or protocol integration. A roadmap that says "FIPS 203 ML-KEM" is easier to audit.

Where ML-KEM Fits

ML-KEM is for key establishment: creating shared secrets that can protect a session or wrap another key. It is relevant to TLS, VPNs, APIs, service-to-service encryption and other network protocols.

It is not a digital signature algorithm. Signature migration is handled by standards such as ML-DSA and SLH-DSA, which need a separate workstream for code signing, certificates, documents and identity.

Implementation Checklist

  1. 1. Use final names. Write FIPS 203 ML-KEM in architecture and procurement documents.
  2. 2. Choose the right protocol integration. For web endpoints, this normally means hybrid TLS key exchange.
  3. 3. Test provider support. CDN and load-balancer support can determine what is possible now.
  4. 4. Separate signatures. Do not assume ML-KEM solves RSA or ECDSA signature exposure.
  5. 5. Keep crypto-agility. Build so parameter and library updates can be rolled out without redesigning the application.

Check Your Public TLS Starting Point

The scanner checks whether your endpoint is ready for modern TLS and whether hybrid post-quantum key exchange is observed.

Free readiness account

Keep This Guide Connected to a Real Website Scan

A PQC guide is more useful when it is attached to current evidence. Create a free account, add a public domain now or later, and keep a repeatable baseline for TLS, security headers and visible post-quantum readiness.

No cardStart the free evidence path without a paid plan.
Saved scanKeep the public endpoint result after the browser session.
Rescan laterRerun after TLS, header or provider changes.

Prefer to scan first? Open the free quantum security scanner.

Create Your Free Account

Start with Google, Microsoft or a one-time email code. You can add a domain now if you want the scanner to run after signup, but it is not required.

No cardNo passwordFree saved scan
Add a domain to scan after signup (optional)

Leave this blank to create the account first and scan later.

or use email code

No card or password is needed. The free account can keep scan evidence for rescans and badge qualification when you add a public domain.