Mental model
In M3 and M4 you saw how ML-KEM and ML-DSA work on their own. How you deploy these algorithms in a real production system is a separate architecture decision, and there are three basic approaches: hybrid (using classical and PQC key agreement together in a TLS key exchange, producing a combined secret, as in M3), pure (PQC only, no classical component), and composite (combining a classical and a PQC signature in one object inside an X.509 certificate or signature). These three terms are not interchangeable: hybrid works at the TLS/key exchange level, composite at the certificate/signature level, and pure means the “PQC only” option at both.
BSI and ANSSI: hybrid required, an aligned position
ANSSI’s own 2023 position paper is clear: “ANSSI still strongly emphasizes the necessity of hybridation… This position is aligned with the one of other European cybersecurity agencies like BSI in Germany.” So BSI and ANSSI are on the same side; there is no disagreement between them, the real disagreement is between them and NSA. BSI’s own current TR-02102-1 (23 January 2026) gives concrete dates: using classical key agreement alone is acceptable for general applications until the end of 2031SOURCED; for applications needing high protection the limit is earlier, the end of 2030SOURCED; for classical signatures the limit is 2035SOURCED. Before these dates, in BSI’s own words, “quantum-safe key agreement in hybrid mode with classical mechanisms” is recommended, not PQC alone.
ANSSI’s rationale contains an exception: “any product that includes post-quantum mitigation shall implement hybridation except if the quantum mitigation only relies on hash-based signatures like XMSS, LMS or SPHINCS+ for which hybridation is optional.” So the hash-based signature family you saw in M2 (SLH-DSA/LMS/XMSS) is, in ANSSI’s view, exempt from the hybrid requirement, because its trust model (hash function preimage resistance, not an algebraic assumption) is different and trustworthy enough; there is no such exemption for lattice-based schemes (ML-KEM, ML-DSA).
NSA / CNSA 2.0: pure PQC, a different trust philosophy
NSA’s CNSA 2.0 requirement takes a different position: it considers ML-KEM-1024 and ML-DSA-87 (category 5, the highest security level) sufficient directly, on their own. Hybrid is allowed during the transition (provided the CNSA 2.0 component is present and preferred), but the target state is pure. The commonly cited rationale from NSA’s own public FAQ is that the extra complexity of hybrid (running, testing and standardizing two separate algorithms together) and the second transition needed later to drop the classical component entirely are unnecessary; NSA trusts the math of ML-KEM/ML-DSA enough not to need an extra classical “safety net”. CNSA 2.0’s own schedule requires OS, web and cloud services to move exclusively (with zero classical component) to CNSA 2.0 by 2033SOURCED.
An honest note: neither NSA’s main algorithm announcement PDF nor its own FAQ document (both on media.defense.gov) could be accessed directly for this course; the server blocks automated access to both the same way (Access Denied). The dates and rationale above are passed on with high confidence from many secondary sources that corroborate each other, but no NSA document was verified directly from the primary source. This is an application of the course’s “say what you could not verify” discipline.
Composite: a third layer, not yet mature
Hybrid and pure are mostly discussed at the TLS key exchange level; composite applies the same idea at the certificate/signature level, carrying both an ML-DSA and a classical (RSA/ECDSA/Ed25519/Ed448) signature together in one field of an X.509 certificate. Its standard is the IETF LAMPS working group’s draft-ietf-lamps-pq-composite-sigs; as of September 2026 the draft has DRAFT2026-08-26 status, in editing at the RFC Editor according to the IETF’s own Datatracker (very close to an RFC but not final yet), at version 19SOURCED. Even ANSSI’s own 2023 position paper admits that for certificate-level hybridization the “designs and security proofs… are still currently moving, ANSSI did not yet identify any well-defined design that could be cited.” So even one of the strongest advocates of hybrid openly accepts that composite certificate design is not yet mature; this is a concrete counter-argument against someone telling an architect “composite is already ready, let’s use it”.