Post-quantum vs classical cryptography measured through one OpenSSL EVP path. 70 measured result(s) across 2 run file(s): mac-arm64, mac-arm64-kpqc.
Single machine: Apple M3 Max (macOS/arm64), OpenSSL 3.6.2, 2 run files (2026-07-21, 2026-07-22)
Every measured aspect, quantified from the PQC algorithm's perspective at each NIST level. Timing uses median ops/s; sizes use bytes. The direction word (faster / slower / larger / smaller) states which side leads.
| Aspect | NIST Level 1 | NIST Level 3 | NIST Level 5 |
|---|---|---|---|
| Keygen | 1.7× slower | 3.1× faster | 2.4× faster |
| Encaps | 3.5× faster | 14.7× faster | 12.0× faster |
| Decaps | 1.9× faster | 7.0× faster | 5.2× faster |
| Public key | 12.3× larger | 12.2× larger | 11.8× larger |
| Ciphertext | 11.8× larger | 11.2× larger | 11.8× larger |
| Wire cost | 12.1× larger | 11.7× larger | 11.8× larger |
Pairs — NIST Level 1: ML-KEM-512 vs ECDH-P256; NIST Level 3: ML-KEM-768 vs ECDH-P384; NIST Level 5: ML-KEM-1024 vs ECDH-P521.
| Aspect | NIST Level 1 | NIST Level 3 | NIST Level 5 |
|---|---|---|---|
| Keygen | 5.0× slower | 1.1× slower | — |
| Sign | 14.3× slower | 3.4× slower | — |
| Verify | 1.4× slower | 2.8× faster | — |
| Public key | 20.2× larger | 20.1× larger | — |
| Signature | 33.6× larger | 31.8× larger | — |
| Wire cost | 27.2× larger | 26.2× larger | — |
Pairs — NIST Level 1: ML-DSA-44 vs ECDSA-P256; NIST Level 3: ML-DSA-65 vs ECDSA-P384; NIST Level 5: ML-DSA-87 vs no classical baseline in this run.
Secondary section: hashes and AEADs measured through the same EVP path, for a Grover-era reference point.
Records that did not reach status: ok this run (missing provider, build tier not present, or a failed correctness gate).
Published specification for each algorithm family present in this run. Links open in a new tab.
| AES | FIPS 197 |
|---|---|
| AIMer | not standardized (research / competition candidate) |
| BIKE | not standardized (research / competition candidate) |
| CROSS | not standardized (research / competition candidate) |
| ChaCha20 | RFC 8439 |
| ECDH | FIPS 186-5 |
| ECDSA | FIPS 186-5 |
| Ed25519 | RFC 8032 |
| Ed448 | RFC 8032 |
| Falcon | FIPS 206 (draft) |
| FrodoKEM | ISO/IEC 18033-2 Amd 2 |
| HAETAE | not standardized (research / competition candidate) |
| HQC | NIST selection (2025) |
| Hybrid KEM | draft-ietf-tls-ecdhe-mlkem, FIPS 203 |
| MAYO | not standardized (research / competition candidate) |
| ML-DSA | FIPS 204 |
| ML-KEM | FIPS 203 |
| NTRU+ | not standardized (research / competition candidate) |
| RSA | FIPS 186-5 |
| SHA- | FIPS 180-4 |
| SHA3 | FIPS 202 |
| SLH-DSA | FIPS 205 |
| SM2 | ISO/IEC 14888-3, RFC 8998 (TLS) |
| SM3 | ISO/IEC 10118-3 |
| SM4 | ISO/IEC 18033-3, RFC 8998 (TLS) |
| SMAUG-T | not standardized (research / competition candidate) |
| X25519 | RFC 7748 |
| X448 | draft-ietf-tls-ecdhe-mlkem, FIPS 203 |