
ETSI's Two Quantum Streams
The European Telecommunications Standards Institute (ETSI) runs two related but distinct quantum-cryptography workstreams:
- TC CYBER Quantum-Safe Cryptography (QSC): covers algorithmic Post Quantum Cryptography (ML-KEM, ML-DSA, hybrid).
- ISG QKD: covers quantum key distribution protocols (physics-based key exchange over dedicated channels).
These are complementary. PQC protects classical application-layer channels; QKD protects specific physical links.
TS 103 744 (Hybrid Key Exchange)
The headline standard from TC CYBER QSC is TS 103 744, "Cyber; Quantum-safe Hybrid Key Exchanges". Versions:
- V1.1.1: December 2020.
- V1.2.1: March 2025 (updated for NIST FIPS 203 ML-KEM).
TS 103 744 specifies how to construct a hybrid key exchange combining a classical primitive (ECDH, X25519) with a PQ KEM (ML-KEM, HQC). It does not mandate specific algorithms; it provides the framework.
Note: TS 103 744 is about hybrid KEX. It is NOT a QKD interoperability standard. That lives in ETSI ISG QKD (GS QKD 004 for protocol stack, GS QKD 014 for REST API).
Other TC CYBER Outputs
- TR 103 619: migration to quantum-safe cryptography (report).
- TS 103 898: quantum-safe VPN signalling.
- Various QSC-related technical reports.
Relation to NIST
ETSI TS 103 744 references and aligns with NIST FIPS 203/204/205. European adoption of NIST algorithms via ETSI standards enables regulated-industry compliance in the EU.
Participation
TC CYBER QSC membership includes European telecom operators, national security agencies, universities, and vendors. Non-European stakeholders participate via membership agreements.
Frequently Asked Questions
Is TS 103 744 a QKD standard?
No. TS 103 744 is hybrid PQC key exchange (algorithmic). QKD standards live in ETSI ISG QKD (GS QKD 004, 014).
Are ETSI standards mandatory in Europe?
Not by default. ETSI produces industry standards, not laws. Compliance typically follows regulatory or contractual adoption.
What does TS 103 744 V1.2.1 add?
Updates for NIST FIPS 203 ML-KEM (August 2024). Reflects the standardized PQC algorithm list.
Does ETSI develop its own PQC algorithms?
No. ETSI standards reference external algorithm specifications (NIST FIPS, ISO/IEC). ETSI's contribution is the hybrid protocol and deployment framework.
Sources
Related Articles
Protect Your Data Before Q-Day Arrives
QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.
Try QNSQYOriginally published at quantumsequrity.com/blog/etsi-quantum-safe-standards.