Glossary

What is ML-KEM?

ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism) is the NIST standard for agreeing on a secret key over the internet in a way quantum computers can’t break. Published as FIPS 203 in August 2024, it grew out of an algorithm called CRYSTALS-Kyber and comes in three strengths: ML-KEM-512, ML-KEM-768 and ML-KEM-1024.1

Also called: Kyber, CRYSTALS-Kyber, FIPS 203, Module-Lattice-Based Key-Encapsulation Mechanism

Updated September 2026. Sources are numbered and listed at the end.

How ML-KEM works

Encrypting data is the easy part. Fast ciphers like AES-256 do it well, and they hold up against quantum computers. The hard part is getting the same secret key to both sides without anyone in the middle learning it. That job is called key establishment, and it’s the only thing ML-KEM does.

  1. The recipient makes a key pair: a public encapsulation key they can hand to anyone, and a private decapsulation key they keep.
  2. The sender encapsulates: using the public key, it creates a fresh 32-byte shared secret plus a ciphertext that wraps it.
  3. The recipient decapsulates: the private key opens the ciphertext and yields the same 32-byte secret. Both sides now encrypt with a fast cipher using that secret.

Its security rests on a math problem called Module Learning With Errors: recovering hidden values from equations that have had small random errors mixed in. No known algorithm, classical or quantum, solves it efficiently at these sizes. RSA and elliptic-curve keys rest on factoring and discrete logarithms, which a large quantum computer running Shor’s algorithm could solve.

Sizes and security categories from FIPS 203.1 For comparison, an X25519 public key is 32 bytes.
Parameter setNIST categoryAbout as hard to break asPublic keyCiphertext
ML-KEM-5121AES-128800 bytes768 bytes
ML-KEM-7683AES-1921,184 bytes1,088 bytes
ML-KEM-10245AES-2561,568 bytes1,568 bytes

The main cost is size: keys and ciphertexts are tens of times larger than elliptic-curve ones. The math itself is fast.

Why ML-KEM matters

Anything protected by today’s key exchange can be recorded now and opened later, once a large enough quantum computer exists. That is the harvest now, decrypt later threat. Switching the key exchange to ML-KEM closes it for everything sent after the switch.

Deadlines are already set. NIST’s draft transition plan proposes deprecating quantum-vulnerable algorithms like RSA and elliptic-curve key exchange after 2030 and disallowing them after 2035, with ML-KEM as the replacement for key establishment.2 Most real deployments run ML-KEM next to a classical algorithm such as X25519, a setup called hybrid encryption, so a flaw in either one alone isn’t enough to break the connection.

Where you’ll see ML-KEM

  • Your browser. Chrome moved to the hybrid X25519MLKEM768 key exchange by default in Chrome 131, released in November 2024.3 The IETF standardized that hybrid for TLS 1.3 in RFC 10024.4 Cloudflare reported in April 2026 that over 65% of human traffic to its network was post-quantum encrypted.5
  • SSH. OpenSSH 10.0 made mlkem768x25519-sha256 its default key exchange in April 2025.6
  • Messaging. Apple’s iMessage PQ3 protocol uses Kyber,7 and Signal added ML-KEM-768 to its protocol with the Sparse Post-Quantum Ratchet in October 2025.8

ML-KEM in Secria

Secria uses the strongest of the three sets, ML-KEM-1024, paired with X25519. Secria Mail seals every message in your mailbox with it on every plan, free included, with nothing to turn on. Secria VPN mixes an ML-KEM-1024 protected key into every WireGuard session. More on post-quantum email and the post-quantum VPN.

Sources

  1. NIST, FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard (August 2024).
  2. NIST, IR 8547 (initial public draft): Transition to Post-Quantum Cryptography Standards (November 2024).
  3. Google Security Blog, A new path for Kyber on the web (September 2024).
  4. IETF, RFC 10024: Post-quantum traditional hybrid key agreement for TLS 1.3.
  5. Cloudflare, Cloudflare targets 2029 for full post-quantum security (April 2026).
  6. OpenSSH, Post-quantum cryptography.
  7. Apple Security Research, iMessage with PQ3 (February 2024).
  8. Signal, Signal protocol and post-quantum ratchets (October 2025).

Checked September 2026. Secria facts are from our Mail and VPN pages and the whitepaper.

Questions about ML-KEM

Is ML-KEM the same as Kyber?+

Almost. ML-KEM is the standardized version of CRYSTALS-Kyber. NIST made small changes while standardizing it, so ML-KEM and early Kyber drafts don’t interoperate, but the design is the same.

What is ML-KEM used for?+

Setting up a shared secret key between two parties, such as a browser and a website, or an email sender and recipient. That key then encrypts the actual data with a fast cipher like AES-256.

What is the difference between ML-KEM-768 and ML-KEM-1024?+

Security margin and size. ML-KEM-768 targets NIST category 3, about as hard to break as AES-192. ML-KEM-1024 targets category 5, about as hard as AES-256, with slightly larger keys. For data that must stay private for decades, the larger margin is the conservative choice.

Is ML-KEM quantum-proof?+

No one can promise that about any algorithm. ML-KEM rests on a problem with no known efficient quantum attack, and it went through years of public review in NIST’s competition, which began in 2016. That is also why most products pair it with a classical algorithm.

Email that’s ready for what comes next. Post-quantum encryption on every plan, free included.