RFC 9794: a new standard for post-quantum terminology

RFC 9794: a new standard for post-quantum terminology

Summary

The UK National Cyber Security Centre (NCSC) has co-authored RFC 9794, published by the IETF in June 2025, which defines standard terminology for Post-Quantum/Traditional (PQ/T) hybrid cryptographic schemes. The RFC, produced with Dr Britta Hale, lays out foundational definitions from algorithms to protocol-level artefacts to ensure consistent, unambiguous language across standards and protocol work in the IETF’s PQUIP working group.

Consistent terminology is presented as a security enabler: reducing misunderstandings that can undermine protocol security analyses. The RFC does not give migration timelines or protocol-specific guidance, but provides the lexical groundwork that other draft RFCs, academic papers and standards bodies are already referencing.

Key Points

  • RFC 9794 specifies terminology for PQ/T hybrid schemes to ensure consistent discussion and analysis across IETF protocols.
  • The document was authored by the NCSC with Dr Britta Hale and published in June 2025.
  • Clear terminology reduces the risk of ambiguous security assumptions during standards development.
  • The RFC complements NIST’s PQC algorithm standards (e.g. ML-KEM, ML-DSA, SLH-DSA) and NCSC guidance on migration.
  • The IETF PQUIP Working Group provides a cross-protocol venue for PQC discussions; RFC 9794 supplies a shared vocabulary for that work.
  • The RFC is already referenced by 20+ technical drafts and by academic and standards documents, signalling broad uptake.

Why should I read this?

Short version: if you care about getting post-quantum cryptography into real protocols without accidental security holes, this matters. RFC 9794 fixes the language everyone will use when designing and assessing hybrid PQ/T schemes — so reading it saves you time and helps you avoid costly misunderstandings later. If you deal with TLS, SSH, IPSec or any protocol updates for PQC, skim this first.

Author

Punchy take: this isn’t sexy, but it’s foundational. Good terminology = fewer mistakes. The NCSC’s RFC is the sort of boring-but-critical work that makes secure protocol migration possible; treat it as required reading if you touch PQC standards or implementations.

Source

Source: https://www.ncsc.gov.uk/blog-post/new-standard-for-post-quantum-terminology

Leave a Reply

Your email address will not be published. Required fields are marked *