Classic McEliece Joins an ISO Standard for Quantum-Safe Encryption
Classic McEliece, a code-based encryption algorithm designed to resist attacks from future quantum computers, has been added to an international cryptography standard. The ISO/IEC 18033-2 standard for asymmetric ciphers now includes it, which its developer, UK company Post-Quantum, says will help governments and enterprises adopt it consistently. The step is important, but it comes with context the announcement leaves out.
Why Classic McEliece earned an ISO standard
Classic McEliece builds on a cryptosystem the mathematician Robert McEliece devised in 1978, and cryptographers have tried and failed to break that underlying scheme for decades, which gives it a strong security reputation. It focuses on the “harvest now, decrypt later” threat, where attackers store encrypted data today to crack once quantum computers are capable enough.
The algorithm is open source and recommended by Germany’s federal security office, the BSI, and its Dutch counterpart. According to the July 15 press release, Post-Quantum lists uses including quantum-safe VPNs, protecting long-lived sensitive data, and securing connected devices. With the Czech defense firm STV Group, it recently demonstrated the algorithm on drones.
Why ISO recognition doesn’t replace NIST’s standards
The release frames this as a milestone, and it is one, but a few claims need care. Post-Quantum calls Classic McEliece the most secure post-quantum algorithm available, which is the company’s own assessment. The letter’s suggestion that current encryption could fall within three years is an aggressive estimate from unnamed experts and sits well ahead of most mainstream forecasts.
The bigger missing piece is NIST. The US standards body did not select Classic McEliece for its main post-quantum standards, choosing ML-KEM for key exchange and, later, HQC, mainly because McEliece’s public keys are very large, which makes it impractical for many applications. NIST actually deferred McEliece and said it might build a standard on the ISO version once that process finished. So this ISO inclusion is part of that path, not a competing endorsement, and McEliece remains a specialized option rather than the default.