Internet X.509 Public Key Infrastructure - Algorithm Identifiers for the Module-Lattice-Based Key-Encapsulation Mechanism
RFC 9935, “Internet X.509 Public Key Infrastructure - Algorithm Identifiers for the Module-Lattice-Based Key-Encapsulation Mechanism”, is a Proposed Standard document published in March 2026 by S. Turner, P. Kampanakis, J. Massimo, B. E. Westerbaan. The canonical text is published by the RFC Editor.
Abstract
The Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) is a quantum-resistant Key Encapsulation Mechanism. This document specifies the conventions for using the ML-KEM in X.509 Public Key Infrastructure. The conventions for the subject public keys and private keys are also specified.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9935 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9934 Privacy-Enhanced Mail File Format for Encrypted ClientHello
- RFC 9936 Use of ML-KEM in the Cryptographic Message Syntax
- RFC 9932 Mutually Authenticating TLS in the Context of Federations
- RFC 9938 A Framework for the Deterministic Networking Controller Plane
- RFC 9931 Security Considerations for Optimistic Protocol Transitions in HTTP/1.1
- RFC 9939 PKCS #8: Private-Key Information Content Types
- RFC 9930 Tunnel Extensible Authentication Protocol Version 1
- RFC 9940 Some Key Terms for Network Fault and Problem Management