ENISA’s draft of the Agreed Cryptographic Mechanisms shifts EUCC guidance toward post‑quantum cryptography, recommending PQC and removing deprecated mechanisms. The draft also revises the category model and clarifies hybrid deployments.
The Agreed Cryptographic Mechanisms (ACM) are a guideline from the ECCG cryptography subgroup. It names which cryptographic mechanisms are recognized by national certification authorities. The ACM is aimed at developers and evaluators and classifies each mechanism as either Recommended or Admissible, including key lengths and validity periods.
The document is part of the European certification scheme EUCC and is revised every two years. Version 2.0 was adopted in mid‑2025. The current draft of Version 3 is the first major update since then.
What happened?
ENISA published the draft together with a changelog on 2 June 2026. All changes compared to Version 2.0 are marked in red in the document to simplify comparison. The public consultation runs until the end of July 2026; feedback can be submitted via an online survey of the European Commission.
Substantively, the draft contains twelve points of change, ranging from purely editorial updates to structural interventions in the category model. Most substantive changes revolve around one theme: preparing for the quantum threat.
What changes specifically?
The twelve changes can be grouped into a few focal points. Central are the status of post‑quantum mechanisms, the revised category model, and several newly included mechanisms.
Post‑quantum mechanisms become Recommended
The central novelty concerns the status of post‑quantum secure mechanisms. Several mechanisms are assigned the highest status Recommended in the draft:
- ML‑KEM (FIPS 203) and FrodoKEM for key exchange
- ML‑DSA (FIPS 204) and SLH‑DSA (FIPS 205) for digital signatures
- the stateful hash‑based signatures XMSS and LMS (SP 800‑208)
This places standardized PQC mechanisms for the first time on a par with established classical mechanisms. Classical asymmetric schemes such as RSA, FF‑DLOG and EC‑DLOG are consistently classified as Admissible, i.e., allowed but no longer the first choice for new systems.
Hybridization clarified
The draft maintains the recommendation to use PQC schemes not alone but in hybrid operation with a classically secure mechanism. New is that the guideline formulates this point far more precisely and names concrete key combiners (NIST SP 800‑227, CatKDF, CasKDF). The background is the state of standardization, which has progressed for hybrid schemes.
This is also visible in TLS: the draft includes hybrid TLS‑1.3 ciphersuites, such as X25519MLKEM768 and SecP256r1MLKEM768, and classifies them as Recommended. They combine a classical key‑agreement with ML‑KEM so that both components would have to be broken to compromise the connection.
New category model: from Legacy to Admissible
Structurally most significant is the revision of the categories. The previous label “Legacy” is removed and replaced by “Admissible.” Recommended mechanisms provide at least 125 bits of security and reflect the state of the art. Admissible mechanisms provide at least 100 bits, are considered acceptable for the short term, and should be replaced where possible.
A notation for a minimum validity period is added. A[2033] means recognition ends on 31 December 2033. A[2033+] means the mechanism remains admissible at least until then and the timeframe may be extended in future versions. The default value for admissible mechanisms is A[2033+]. This refinement is motivated by the quantum threat, which is not yet practical but must already be considered when choosing mechanisms.
New mechanisms added
Beyond the PQC mechanisms, the draft adds further schemes. EdDSA (RFC 8032) is included as an elliptic signature scheme, with a note on deterministic signature generation and the associated susceptibility to fault attacks. For password hashing, Argon2‑id (RFC 9106) is added as a recommended method; PBKDF2 remains admissible. As a memory‑hard function, Argon2 offers better protections against password guessing than pure iteration schemes. Additionally, the draft introduces Extendable‑Output Functions (XOF) such as SHAKE and cSHAKE as their own category, since they are already used in ML‑KEM and ML‑DSA.
AES clarification and removals
Regarding AES, the draft explicitly clarifies that doubling key length is not required: AES‑128 remains admissible in all contexts, including in PQC environments. However, in contexts where quantum resistance is demanded, AES with at least 192 bits is recommended. At the same time, the draft removes several previously deprecated mechanisms from the guideline, as there is no longer any reason for them to remain.
Defined update process
Finally, the draft defines for the first time in a new Annex C a formal process for how the ACM is updated and how external parties can submit proposals. This is why the current consultation is structured and open.
What does this mean for manufacturers?
The ACM applies directly to products certified under the EUCC‑Schema. Manufacturers who certify, for example, a smart meter gateway under that scheme must validate the cryptographic mechanisms used against the recognized list. The Recommended or Admissible status and the associated timeframes determine how long a product remains recognized on the market.
This direction is particularly relevant for long‑lived industrial products. A machine controller with remote maintenance over TLS often stays in the field for ten years or more. Over such a horizon the “harvest now, decrypt later” scenario applies: today’s intercepted, classically encrypted traffic may be decrypted later once a powerful quantum computer becomes available. The upgrade of PQC mechanisms and the emphasis on hybrid operation specifically target this product class.
Even outside direct EUCC certification, the ACM sets the course. The cryptographic requirements from the RED Delegated Act, EN 18031 and the expectations for secure product development in the context of CRA conformity assessment move in the same direction. Manufacturers who align their crypto strategy with Recommended mechanisms and plan for PQC in hybrid operation are making a decision that is viable beyond the EUCC scheme.
The draft remains in consultation until the end of July 2026 and may still change. For strategic planning, however, the exact wording of individual tables is less important than the clearly visible direction: away from purely classical asymmetry and toward hybrid and post‑quantum‑secure mechanisms.
The elevation of post‑quantum mechanisms and the new category model provide guidance but raise concrete migration questions for existing product landscapes.
Kryptography is part of your product compliance
Whether EUCC, CRA or EN 18031: cryptography requirements run through almost every product regulation. Secuvise supports manufacturers from classifying requirements to implementing them in the product. If this topic becomes relevant for your products, feel free to contact us.