Why Germany's BSI Advises Against Classic McEliece for New Systems, Four Months After ISO Standardized It
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

Why Germany's BSI Advises Against Classic McEliece for New Systems, Four Months After ISO Standardized It

What BSI changed in its TR-02102 guidance in October 2026

Germany's Federal Office for Information Security (BSI) now advises against using Classic McEliece for new developments and when planning new cryptographic applications. The change appears on the agency's page for Technical Guideline TR-02102 and was reported by heise on 6 October 2026. BSI states that the 2026 results do not amount to a practical attack on the parameter sets it had recommended; heise adds that correctly built hybrid deployments keep the protection of their classical component. For new post-quantum cryptography projects, BSI points to FrodoKEM, ML-KEM and HQC.

Why two preprints from August and September 2026 moved a national guideline

In August, Ghoshal, Ishai, Jain and Sun posted a quasipolynomial-time method that tells Classic McEliece public keys apart from random ones, covering every parameter set reviewed in the NIST process. In September, Stephen A. Weis of Anthropic cut the cost of the attack's core linear-algebra step to between 2^89 and 2^98 bit operations and described two key-recovery methods. Neither paper breaks a deployed key.

Why a standard and a guideline can now point in different directions

ISO published Classic McEliece in June 2026 in amendment 2 to ISO/IEC 18033-2, the same amendment that standardizes FrodoKEM. A national guideline chooses among standardized options, so a procurement clause that only asks for an ISO-standardized algorithm no longer settles which scheme a supplier may ship.

Read More