Why Germany's BSI Advises Against Classic McEliece for New Systems, Four Months After ISO Standardized It
In 1978 Robert McEliece, an information theorist at the Jet Propulsion Laboratory, published a short progress report describing a public-key cryptosystem built from error-correcting codes, the same mathematics that let deep-space probes send clean pictures through noise. For nearly half a century his scheme outlived most of its contemporaries. It survived because its security rested on an old, well-studied problem: decoding a random-looking linear code is hard, and an attacker who cannot see the hidden structure of the key has nothing better than generic decoding. That longevity made Classic McEliece, the modern version of the scheme, a favorite of cryptographers who wanted conservative protection for data that must stay secret for decades.
In the first week of October 2026, Germany's Federal Office for Information Security (BSI) changed its advice. On the page for its Technical Guideline TR-02102, the agency now writes that it currently recommends not using Classic McEliece for new developments or when planning new cryptographic applications. heise reported the change on 6 October 2026. The question for anyone who buys, builds or certifies encryption is why an agency would step back from a scheme four months after ISO published it as an international standard, and what that sequence means for contracts that rely on the word "standardized".
Practical takeaway. BSI's advice covers new systems only. Existing hybrid deployments that correctly pair Classic McEliece with a classical algorithm such as X25519 keep the protection of the classical part, and BSI says current results are not a practical attack. For new projects BSI points to FrodoKEM, ML-KEM and HQC. Specifications that ask only for "an ISO-standardized post-quantum algorithm" now leave a gap between what the standard allows and what Germany's national guideline recommends.
What did BSI actually say about Classic McEliece, and when?
The German text is short. BSI currently recommends that Classic McEliece not be used for new developments or for the planning of new cryptographic applications. The agency attributes the change to cryptanalytic progress in 2026 and states that the results so far do not yield a practical attack on Classic McEliece with the parameters TR-02102-1 recommended. The guideline itself is still at version 2026-01, published in January, which listed the scheme as suitable; according to heise, the revised TR-02102-1 is planned for early 2027. BSI's page does not give a date for that version, and the agency's own text cites no paper numbers.
Two details matter for anyone already running the scheme. BSI had asked from the start that Classic McEliece be used only in hybrid form, combined with an established classical key exchange. In a correctly designed and implemented hybrid, the combined key is at least as strong as the classical half, although that half offers no long-term protection against a quantum computer. This is why heise reports that existing hybrid deployments are not yet at practical risk. And the alternatives BSI names for new work, FrodoKEM, ML-KEM and HQC, come from three different mathematical families: unstructured lattices, structured lattices and a different family of codes.
Which two preprints, from August and September 2026, cut the cost of attacking it
The first is IACR ePrint 2026/1630, "Quasipolynomial Cryptanalysis of the McEliece Cryptosystem (or: PIR Meets McEliece)", posted on 7 August 2026 and revised on 27 August by Ashrujit Ghoshal (IIT Madras), Yuval Ishai (Technion and AWS), Aayush Jain and Nuozhou Sun (both Carnegie Mellon). It gives a simple classical distinguisher that runs in time nO(log n) and separates McEliece public keys from random matrices, for every Classic McEliece parameter set reviewed in the NIST process. The authors also sketch heuristic decryption and key-recovery algorithms that, by their own account, are not yet practically efficient. The work began as an attempt to build private information retrieval protocols from algebraic codes, a reminder that the sharpest attacks often arrive from a neighboring field.
The second is IACR ePrint 2026/1984, "Improving GIJS Key Recovery for Classic McEliece", posted on 11 September 2026 and revised on 6 October by Stephen A. Weis of Anthropic. It reduces the estimated cost of the attack's core linear-algebra step from roughly 2^114 to 2^124 bit operations to between 2^89 and 2^98 bit operations, or about 2^107 to 2^117 per run once the cost of memory access is counted, and it describes two ways to recover secret keys whose costs depend on the method chosen. The results rest on four heuristic assumptions, tested on small keys, including the recovery of a previously unsolved toy instance from the TII McEliece key-recovery challenges. heise summarizes the effect as a fall in claimed strength from the AES-256 level toward roughly AES-128, a journalistic shorthand that the preprint itself does not use as a formal classification. Even the lowest estimate is still far beyond any computer that exists.
The author's affiliation will draw attention. The preprint describes mathematics, and it does not claim that an AI system produced the result. Quentir has already argued that AI-assisted cryptanalysis changes how post-quantum assurance must be read; this case shows the more ordinary route by which researchers at AI companies now feed straight into national cryptographic policy.
Why ISO still lists Classic McEliece as an active standard
ISO/IEC 18033-2:2006/Amd 2:2026, prepared by the joint committee JTC 1/SC 27, was published in June 2026. Its catalogue entry still shows the amendment as a published, active international standard, with no withdrawal or revision under way that the catalogue reveals. The same amendment also standardizes FrodoKEM, one of the schemes BSI now prefers.
BSI therefore did not overrule ISO. A standards body defines interoperable options and their exact encodings. A national agency decides which of those options it recommends for systems under its guidance. Profiling of this kind is routine in cryptography, and it explains how both statements can be true on the same day. The United States had already taken a different path: in NIST IR 8545, published in March 2025, NIST selected HQC from its fourth round and did not select Classic McEliece for standardization.
What the gap between ISO and BSI means for procurement and certification
Contracts, tenders and certification schemes often write security requirements as references to standards, because a standard is stable, citable and neutral between vendors. The Classic McEliece episode shows the limit of that habit. A supplier that ships Classic McEliece in a new product in 2027 may conform to ISO/IEC 18033-2, provided its implementation meets the standard's requirements, and still depart from Germany's national recommendation. Where a tender, a certification scheme or an applicable federal requirement incorporates BSI guidance, buyers have to check which version of TR-02102 applies and which algorithms it recommends.
The people affected sit far from the mathematics. Hospitals archiving patient records, courts storing case files and companies holding long-term trade secrets chose conservative schemes precisely to avoid revisiting the decision every few years. Their protection depends on someone following guidance between versions of a standard and translating it into product choices. On 6 October Quentir looked at how the Dutch quantum strategy of 5 October 2026 sets central-government migration deadlines running to 2035; deadlines of that length make mid-course changes in algorithm advice a planning certainty.
How Quentir Reads It
Classic McEliece has now lost a national recommendation within months of a major standards body adopting it. The sequence is instructive because nothing broke. The reported attacks are not currently practical against the recommended parameters, the standard stayed in force, and properly constructed hybrids retain their classical component's protection while the agency changes direction for new systems. The changed recommendation strengthens the case for crypto-agility, the ability to swap an algorithm without rebuilding a system.
The open question is what ISO's subcommittee does next. If the 2027 revision of TR-02102-1 confirms the advice and other agencies follow, the amendment may stand as a published option few guidelines still recommend. If further work restores confidence, BSI's step will read as prudence. Either way, the governance lesson stands: an algorithm choice in a contract is a decision with an expiry date, and the contract should say who watches the clock. Our Signature Brief 2026.4, Crypto-Agility as a Verifiable Duty, covers what this post does not attempt: maturity models with published evaluations, quantified agility metrics and the covenant gap in contracts already signed, within a fixed scope.
Sources: Bundesamt für Sicherheit in der Informationstechnik, Technische Richtlinie TR-02102 (Kryptographische Verfahren), current version 2026-01, page consulted 7 October 2026; Jürgen Schmidt, "Post-Quantum Crypto: BSI Concerned About McEliece", heise online, 6 October 2026; ISO, ISO/IEC 18033-2:2006/Amd 2:2026, published June 2026; Ghoshal, Ishai, Jain and Sun, "Quasipolynomial Cryptanalysis of the McEliece Cryptosystem (or: PIR Meets McEliece)", IACR ePrint 2026/1630, 7 August 2026, revised 27 August 2026; Stephen A. Weis, "Improving GIJS Key Recovery for Classic McEliece", IACR ePrint 2026/1984, 11 September 2026, revised 6 October 2026; NIST, IR 8545, Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process, March 2025; FrodoKEM project site. Robert J. McEliece, "A Public-Key Cryptosystem Based on Algebraic Coding Theory", JPL DSN Progress Report 42-44, 1978.
Published intelligence, built to inform your own decisions. Published: October 7, 2026.