pqcbench report

Post-quantum vs classical cryptography measured through one OpenSSL EVP path. 70 measured result(s) across 2 run file(s): mac-arm64, mac-arm64-kpqc.

Executive summary

Single machine: Apple M3 Max (macOS/arm64), OpenSSL 3.6.2, 2 run files (2026-07-21, 2026-07-22)

Where PQC is faster

7.6×faster
Key exchange
ML-KEM-768 vs ECDH-P384 · NIST Level 3 · 74.0 µs vs 560.0 µs (keygen + encaps + decaps)
7.0×faster
Signing
ML-DSA-65 vs RSA-4096-PSS · NIST Level 3 · 2,639/s vs 374.9/s at a 1 KiB message
3,062×faster
Keygen
ML-DSA-65 vs RSA-4096-PSS · NIST Level 3 · 93.0 µs vs 284.7 ms

Where PQC costs more

11.7×larger
Wire size
ML-KEM-768 vs ECDH-P384 · NIST Level 3 · 2,272 B vs 194 B (public key + ciphertext)
5.1×larger
Signature + public key
ML-DSA-65 vs RSA-4096-PSS · NIST Level 3 · 5,261 B vs 1,024 B
2.0×slower
Verification
ML-DSA-65 vs RSA-4096-PSS · NIST Level 3 · 11,765/s vs 23,256/s at a 1 KiB message
up to 1,081×slower
PQC-internal spread
Other PQC families vs the ML-KEM/ML-DSA baselines · BIKE-L5 exchange 1,081× slower than ML-KEM-768; SLH-DSA-SHAKE-128s signing 1,023× slower than ML-DSA-65

PQC vs classical at a glance

Every measured aspect, quantified from the PQC algorithm's perspective at each NIST level. Timing uses median ops/s; sizes use bytes. The direction word (faster / slower / larger / smaller) states which side leads.

KEM aspects — ML-KEM vs ECDH

AspectNIST Level 1NIST Level 3NIST Level 5
Keygen1.7× slower3.1× faster2.4× faster
Encaps3.5× faster14.7× faster12.0× faster
Decaps1.9× faster7.0× faster5.2× faster
Public key12.3× larger12.2× larger11.8× larger
Ciphertext11.8× larger11.2× larger11.8× larger
Wire cost12.1× larger11.7× larger11.8× larger

Pairs — NIST Level 1: ML-KEM-512 vs ECDH-P256; NIST Level 3: ML-KEM-768 vs ECDH-P384; NIST Level 5: ML-KEM-1024 vs ECDH-P521.

Signature aspects — ML-DSA vs level-matched classical

AspectNIST Level 1NIST Level 3NIST Level 5
Keygen5.0× slower1.1× slower
Sign14.3× slower3.4× slower
Verify1.4× slower2.8× faster
Public key20.2× larger20.1× larger
Signature33.6× larger31.8× larger
Wire cost27.2× larger26.2× larger

Pairs — NIST Level 1: ML-DSA-44 vs ECDSA-P256; NIST Level 3: ML-DSA-65 vs ECDSA-P384; NIST Level 5: ML-DSA-87 vs no classical baseline in this run.

NIST level
Kind
Provider / tier
Program / origin
Algorithm
Within a row, selections are combined (OR); across rows they narrow (AND). No selection in a row = all.

KEM / key exchange

cross-provider (reference implementation) PQC▲ beats fastest classical baseline in its group
Timing cells show median time (lower is faster) and ops/s in parentheses (higher is faster). Cell shading compares within each NIST level: faster slower. Size cells: fewer bytes is smaller (shaded the same way).

Signatures

Timing cells show median time (lower is faster) and ops/s in parentheses (higher is faster). Cell shading compares within each NIST level: faster slower. Size cells: fewer bytes is smaller (shaded the same way).

Symmetric context

Secondary section: hashes and AEADs measured through the same EVP path, for a Grover-era reference point.

Throughput is MB/s (higher is faster); shading: faster slower.

Appendix: skipped / error results

Records that did not reach status: ok this run (missing provider, build tier not present, or a failed correctness gate).

Standards

Published specification for each algorithm family present in this run. Links open in a new tab.

AESFIPS 197
AIMernot standardized (research / competition candidate)
BIKEnot standardized (research / competition candidate)
CROSSnot standardized (research / competition candidate)
ChaCha20RFC 8439
ECDHFIPS 186-5
ECDSAFIPS 186-5
Ed25519RFC 8032
Ed448RFC 8032
FalconFIPS 206 (draft)
FrodoKEMISO/IEC 18033-2 Amd 2
HAETAEnot standardized (research / competition candidate)
HQCNIST selection (2025)
Hybrid KEMdraft-ietf-tls-ecdhe-mlkem, FIPS 203
MAYOnot standardized (research / competition candidate)
ML-DSAFIPS 204
ML-KEMFIPS 203
NTRU+not standardized (research / competition candidate)
RSAFIPS 186-5
SHA-FIPS 180-4
SHA3FIPS 202
SLH-DSAFIPS 205
SM2ISO/IEC 14888-3, RFC 8998 (TLS)
SM3ISO/IEC 10118-3
SM4ISO/IEC 18033-3, RFC 8998 (TLS)
SMAUG-Tnot standardized (research / competition candidate)
X25519RFC 7748
X448draft-ietf-tls-ecdhe-mlkem, FIPS 203

Run metadata

mac-arm64

Source filemac-arm64-20260722.json
Host slugmac-arm64
CPUApple M3 Max
Archarm64
OSDarwin 25.5.0
Cores (physical)14
Compilerclang 21.0.0 (clang-2100.1.1.101)
OpenSSLOpenSSL 3.6.2 7 Apr 2026
Providersdefault=3.6.2, oqsprovider=0.11.0, kpqc=absent
liboqsunknown
Iterations / warmup1000 / 100
Timermonotonic_wall
Git commitcc3317e
Timestamp2026-07-22T00:36:50Z

mac-arm64-kpqc

Source filemac-arm64-kpqc-20260721.json
Host slugmac-arm64-kpqc
CPUApple M3 Max
Archarm64
OSDarwin 25.5.0
Cores (physical)14
Compilerclang 21.0.0 (clang-2100.1.1.101)
OpenSSLOpenSSL 3.6.2 7 Apr 2026
Providersdefault=3.6.2, oqsprovider=absent, kpqc=0.9.1-dev
liboqsabsent
Iterations / warmup1000 / 100
Timermonotonic_wall
Git commit50b4f63
Timestamp2026-07-21T13:30:45Z