Use of ML-KEM in the Cryptographic Message Syntax
RFC 9936, “Use of ML-KEM in the Cryptographic Message Syntax”, is a Proposed Standard document published in March 2026 by J. Prat, M. Ounsworth, D. Van Geest. The canonical text is published by the RFC Editor.
Abstract
Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) is a quantum-resistant Key Encapsulation Mechanism (KEM). Three parameter sets for the ML-KEM algorithm are specified by the US National Institute of Standards and Technology (NIST) in FIPS 203. In order of increasing security strength (and decreasing performance), these parameter sets are ML-KEM-512, ML-KEM-768, and ML-KEM-1024. This document specifies the conventions for using ML-KEM with the Cryptographic Message Syntax (CMS) using the KEMRecipientInfo structure defined in "Using Key Encapsulation Mechanism (KEM) Algorithms in the Cryptographic Message Syntax (CMS)" (RFC 9629).
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9936 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9935 Internet X.509 Public Key Infrastructure - Algorithm Identifiers for the Module-Lattice-Based Key-Encapsulation Mechanism
- RFC 9934 Privacy-Enhanced Mail File Format for Encrypted ClientHello
- RFC 9938 A Framework for the Deterministic Networking Controller Plane
- RFC 9939 PKCS #8: Private-Key Information Content Types
- RFC 9932 Mutually Authenticating TLS in the Context of Federations
- RFC 9940 Some Key Terms for Network Fault and Problem Management
- RFC 9931 Security Considerations for Optimistic Protocol Transitions in HTTP/1.1
- RFC 9941 Secure Shell Key Exchange Method Using Hybrid Streamlined NTRU Prime sntrup761 and X25519 with SHA-512: sntrup761x25519-sha512