M4 / Signatures

HQC status and the additional signature candidates in IR 8610

FoundationsPractitionerAdvisor

After this lesson you can

  • State HQC's current standardization status (recalled from M2) and the current, live-verified number of IR 8610's round 3 additional signature candidates
  • Summarize, with correct status language, why and how HAWK's withdrawal took the field from 9 candidates to 8 (linked to M14)

Before thisSLH-DSA and FN-DSA

Mental model

In M2 you saw HQC as an independent backup KEM to ML-KEM. This lesson brings two things together: a short reminder of HQC’s current status, and the current state of NIST’s separate “Additional Digital Signatures” program. These are different processes and should not be confused.

HQC: a short reminder

As you saw in M2, HQC is SELECTED2025-03-11 today (September 2026), with no draft FIPS yet. This lesson does not repeat that status; it only makes clear that HQC is a separate process that must not be confused with the next topic (round 3 additional signatures): HQC is a backup KEM to ML-KEM (an existing, final standard), while the round 3 candidates below are part of an entirely separate evaluation that adds to ML-DSA, SLH-DSA and FN-DSA on the signature side.

IR 8610: why there is a second process on the signature side

The “don’t put all your eggs in one basket” principle you learned in M2 applies on the signature side too: alongside ML-DSA, SLH-DSA and FN-DSA (all three already selected), NIST is evaluating additional signature candidates from even more varied mathematical families through a separate process called Additional Digital Signatures. IR 8610 (14 May 2026, final) reports this process moving from round 2 to round 3: 9SOURCED candidates advanced to round 3: FAEST, HAWK, MAYO, MQOM, QR-UOV, SDitH, SNOVA, SQIsign, UOV. According to IR 8610’s own Table 3, these candidates come from four different mathematical families (isogeny, lattice, MPC-in-the-Head, multivariate): a search for even broader diversity than the lattice, hash-based and code-based trio you saw in M2. (Live verification note: CSRC’s round 3 project page today lists FAEST under a separate fifth “symmetric-based” heading; NIST’s own taxonomy has been updated since IR 8610 was published, an example of how the “check the live source” discipline makes a difference even here.)

HAWK’s withdrawal: from 9 to 8

If you check round 3’s live project page today (September 2026), one of the nine candidates, HAWK, is marked “withdrawn”; the number of active candidates has dropped to 8SOURCED. The reason is not a procedural problem but a real cryptanalysis finding; you will see the full case (who found it, how, how quickly) in M14 (the-hawk-case). The important point here: this withdrawal is not a failure of the process but the opposite, the process working as designed. A candidate being found weak and eliminated during broad public review, before becoming a final standard, is exactly the purpose of the round structure; in M13 (cost model) and M14 you will see the economic and operational consequences of this “find early, fix cheaply” principle in more depth.

Round 3 itself is an evaluation, not yet a selection. IR 8610 itself gives no duration; it only says the 7th PQC Standardization Conference is planned for the first half of 2027 (the common secondary-source summary that “round 3 will take about two years” is an inference from that, ESTIMATED, not stated directly in IR 8610’s text). Presenting any of these candidates to an architect as “ready to use” would be the same kind of overclaim as presenting HQC as final while it is still pre-draft.

Numbers to know

  • IR 8610 (14 May 2026) advanced 9 candidates to round 3 of the Additional Digital Signatures process: FAEST, HAWK, MAYO, MQOM, QR-UOV, SDitH, SNOVA, SQIsign, UOV, from four mathematical families according to IR 8610's own Table 3 (isogeny, lattice, MPC-in-the-Head, multivariate); the live CSRC page today lists FAEST under a separate fifth 'symmetric-based' heading, so the taxonomy has been updated since IR 8610
  • With HAWK's withdrawal in July 2026 (the full case is in M14), the number of active round 3 candidates today (September 2026) is 8; evidence that the 'don't trust a single basket' principle from M2 works inside the process itself

Lab: Check the round 3 additional signatures page live

[not run] This is a live verification exercise, not a runnable command

Requires: internet access. Check your setup

shell
# Open csrc.nist.gov/projects/pqc-dig-sig/round-3-additional-signatures
Recorded output
9 candidates are listed, with the HAWK row marked 'withdrawn'; the total number of active candidates is 8

At the table

How to say this in a bank meeting.

To an executive
NIST's additional signature standardization process is still running (round 3 will run into 2027), and one candidate (HAWK) was withdrawn because of a cryptanalysis finding before the process ended. That is a sign the process itself is healthy: it eliminates problematic candidates before they reach the finish.
To an architect
None of these round 3 candidates (except HQC, which was selected separately as ML-KEM's backup) is mature enough to consider for production decisions today; round 3 is an evaluation running into 2027, not a selection yet.
Objection
“"IR 8610 had 9 candidates and now I hear HAWK was withdrawn. Is this process reliable?"”
Answer
The opposite: a candidate being withdrawn before becoming a standard, because of an independent cryptanalysis finding, is evidence the process works. NIST's multi-candidate, long-round structure exists exactly so that a weak design surfaces during broad review before it reaches production. In M14 you will see the full detail of this case (who found it, how, how quickly it was handled).

Sources

Checkpoint

Answer first, then compare with the model answer and score yourself against the rubric. Saved in this browser only.

  1. 01Recall

    How many candidates did IR 8610 advance to round 3, and how many are active today?

  2. 02Recall

    What is HQC's status today (recall M2)?

  3. 03Scenario

    A colleague who has not checked recent information says 'NIST's additional signature process has 9 candidates.' What do you tell them, and how do you verify it?

  4. 04Hostile

    An auditor asks: 'Doesn't the withdrawal of a NIST candidate shake confidence in PQC standards?' How do you answer, citing the design of the process?

Project linkContributes to the crypto-diversity section of Project 4 (capstone) as the right frame for the current maturity of ongoing standardization processes (round 3 additional signatures).