Use of the ML-DSA Signature Algorithm in the Cryptographic Message Syntax
RFC 9882, “Use of the ML-DSA Signature Algorithm in the Cryptographic Message Syntax”, is a Proposed Standard document published in October 2025 by B. Salter, A. Raine, D. Van Geest. The canonical text is published by the RFC Editor.
Abstract
The Module-Lattice-Based Digital Signature Algorithm (ML-DSA), as defined by NIST in FIPS 204, is a post-quantum digital signature scheme that aims to be secure against an adversary in possession of a Cryptographically Relevant Quantum Computer (CRQC). This document specifies the conventions for using the ML-DSA signature algorithm with the Cryptographic Message Syntax (CMS). In addition, the algorithm identifier syntax is provided.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9882 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9881 Internet X.509 Public Key Infrastructure -- Algorithm Identifiers for the Module-Lattice-Based Digital Signature Algorithm
- RFC 9883 An Attribute for Statement of Possession of a Private Key
- RFC 9884 Label Switched Path Ping for Segment Routing Path Segment Identifier with MPLS Data Plane
- RFC 9879 Use of Password-Based Message Authentication Code 1 in PKCS #12 Syntax
- RFC 9885 Multi-Part TLVs in IS-IS
- RFC 9878 Updates to Private Header Extension Usage in Session Initiation Protocol Requests and Responses
- RFC 9886 DRIP Entity Tags in the Domain Name System
- RFC 9877 Registration Data Access Protocol Extension for Geofeed Data