Independently measured performance
What does the implementation actually cost to run, measured by someone with no stake in the answer?
Requirements, evidence source, and references
This page is the citable form of this dimension — a finding elsewhere can link straight to the bar it was judged against.
Independently measured performance
6 requirementsWhat does the implementation actually cost to run, measured by someone with no stake in the answer?
Keygen / encapsulate / decapsulate and keygen / sign / verify timings, measured rather than quoted.
Reported with a distribution, not a single mean — median, p95 and p99 at a stated iteration count.
Measured on named hardware, at a stated liboqs or library version, traceable to a reproducible public run.
Measured on more than one architecture (x86-64 and ARM) so the numbers travel to the reader's estate.
Handshake-level cost measured in situ, not inferred by adding primitive timings together.
TLS / networkPKI / CAKey, ciphertext and signature sizes checked against the standard rather than taken from the datasheet.
- NIST FIPS 203 — Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM)confirmed2026-08-13Published 2024-08-13. Parameter sets ML-KEM-512 / 768 / 1024.
- NIST FIPS 204 — Module-Lattice-Based Digital Signature Standard (ML-DSA)confirmed2026-08-13Published 2024-08-13.
- NIST FIPS 205 — Stateless Hash-Based Digital Signature Standard (SLH-DSA)confirmed2026-08-13Published 2024-08-13. Based on SPHINCS+.
Operations per second under sustained load, and the point at which the device saturates.
HSMWhere an implementation is not independently testable, that is recorded as not assessed — never inferred from the vendor's own published figures, and never scored as zero.