The International Organization for Standardization (ISO) has officially included the post-quantum cryptographic algorithm Classic McEliece in the asymmetric encryption standard ISO/IEC 18033-2. This is a landmark event for the entire industry: developers and regulators now have a clear benchmark for implementing protection against the threats posed by quantum computing.
Classic McEliece is a key encapsulation mechanism developed back in 1978 by Robert McEliece. Unlike classic RSA and the Diffie-Hellman protocol, which are based on factoring large numbers and discrete logarithms, this algorithm relies on error-correcting code theory, specifically binary Goppa codes. This makes it fundamentally resistant to attacks from quantum computers, which can break traditional schemes in minutes.
According to the Okinawa Institute of Science and Technology, Classic McEliece is considered one of the most conservative and time-tested designs in post-quantum cryptography. Since its inception, the algorithm has withstood all known cryptanalysis attempts, confirming its exceptional reliability.
The main feature of the algorithm is the significant size of its public keys, ranging from 255 KB to 1.3 MB. However, the ciphertext size remains compact—up to 208 bytes. As experts from the British company Post-Quantum note, this scheme is ideal for scenarios with long-lived static keys, such as protecting VPN connections, encrypting files, or long-term data storage.
The ISO decision takes on particular significance against the backdrop of the stance of the U.S. National Institute of Standards and Technology (NIST), which previously postponed the standardization of Classic McEliece, preferring the HQC algorithm. NIST has acknowledged that it may adopt a standard based on the ISO version in the future. Thus, ISO is ahead of the American regulator, creating a global precedent.
According to Post-Quantum CEO Ricky Hasan, ISO recognition gives the green light to governments and private companies from 177 countries to systematically implement the algorithm. The company previously successfully tested Classic McEliece on combat drones under limited communication conditions, proving its practical viability despite the massive key size.
Classic McEliece is already mentioned in recommendations from regulators in the Netherlands and Germany. Support for the algorithm has been implemented in projects such as Debian, Ubuntu, and the Bouncy Castle cryptographic library.
Expert opinion: The standardization of Classic McEliece by ISO is not just a technical decision but a strategic signal to the market. While NIST hesitates, the international community receives a ready-made and proven tool for protection against the quantum threat. For the crypto industry, where asset security directly depends on the resilience of algorithms, this means that the transition to post-quantum schemes is no longer a matter of the future but a task for the coming years.