ENISA's version 3 draft for Agreed Cryptographic Mechanisms remains under public review, while version 2.0 is still applicable. The proposal elevates selected post-quantum mechanisms and refines how accepted cryptography is categorised.
The current position
ENISA published the working draft of version 3 of the Agreed Cryptographic Mechanisms, or ACM, for public review on 2 June 2026. That review ran until the end of July 2026. As of 16 September 2026, ENISA still presents version 3 as a draft for public review and identifies ACM version 2.0 as the applicable version.
That distinction matters. The proposed classifications and dates in version 3 should inform planning and technical review, but they are not yet the applicable ACM requirements. Teams should continue to assess EUCC work against the current scheme documents and applicable version 2.0 guidance.
What the ACM does
The ACM is cryptography guidance produced by the European Cybersecurity Certification Group Sub-group on Cryptography. It is intended primarily for developers and evaluators working in the EUCC context, identifying cryptographic mechanisms that national cybersecurity certification authorities are intended to accept.
EUCC is the European Common Criteria-based cybersecurity certification scheme for ICT products, established by Commission Implementing Regulation (EU) 2024/482. The Regulation is binding, while the ACM provides state-of-the-art cryptographic guidance within the certification framework.
A proposed recommended and admissible model
A central version 3 proposal is to replace the existing legacy label with admissible. In the draft:
Recommendedmechanisms reflect the state of the art.Admissiblemechanisms remain accepted under the draft's conditions and validity treatment.
This is not a proposal to prohibit classical cryptography overnight. The draft continues to list specified RSA, finite-field and elliptic-curve signature and key-establishment mechanisms as admissible, with notes relating to the quantum threat.
The draft also introduces validity notation for admissible mechanisms:
| Notation | Proposed meaning |
|---|---|
A[2033] |
Acceptance ends on 31 December 2033. |
A[2033+] |
Acceptance continues at least through 2033 and may be extended in a later ACM version. |
The proposed default validity for admissible mechanisms is A[2033+]. These notations concern proposed ACM acceptance. They do not, by themselves, set a product's market lifetime, certificate expiry date or support period.
Post-quantum mechanisms move into focus
The version 3 draft classifies several post-quantum mechanisms as recommended:
- ML-KEM and FrodoKEM for key establishment or encapsulation.
- ML-DSA, XMSS, LMS and SLH-DSA for digital signatures.
This would place these mechanisms among the draft's recommended choices, subject to the parameter and implementation guidance in the document. It does not mean that every parameter set, implementation or deployment pattern is automatically accepted.
The shift is particularly significant for new designs that need to protect confidentiality over a long period. The quantum threat affects how teams weigh the risk that encrypted information collected now could become readable later if sufficiently capable quantum computing becomes available.
Hybrid key establishment needs separate design review
For MLWE-based key establishment, the draft says that the post-quantum mechanism should be combined with a classical mechanism. It also lists the following recommended TLS 1.3 groups:
SecP256r1MLKEM768X25519MLKEM768SecP384r1MLKEM1024
These proposed ACM entries are useful planning signals, but they are not a complete protocol deployment decision. Teams still need to verify the relevant TLS profile, product architecture, library support, implementation constraints and applicable standards.
ENISA's April 2026 report on hybridisation maps the state of standards work, but expressly does not establish an ENISA or ECCG recommendation. It is therefore useful context, not a substitute for checking the applicable ACM and protocol standards.
Other proposed additions and clarifications
The draft also proposes several changes beyond post-quantum key establishment and signatures.
Argon2-id is added as a recommended password-hashing mechanism, while PBKDF2 remains admissible. EdDSA is listed as admissible. The classifications should support technical review, not replace assessment of the parameters, implementation and use case.
Extendable-output functions, including SHAKE and cSHAKE, appear as a separate proposed category. This reflects their use in mechanisms such as ML-KEM and ML-DSA.
For AES, the draft clarifies that AES-128 remains an agreed mechanism. Where quantum security is sought, it recommends AES-192 or AES-256. It does not require every use of AES-128 to be replaced or every symmetric key length to be doubled.
A proposed update process
New Appendix C sets out a proposed process for updating the ACM. It covers submission, completeness review, analysis and update steps. Under the draft, major updates receive a two-month public review, while the subgroup may adopt minor editorial changes directly.
This is a proposed document-maintenance process, not a statutory appeal route or certification procedure.
A practical review list for product teams
The draft is a useful prompt to organise evidence and options before its status changes. A proportionate review should include:
- Inventory the cryptographic mechanisms used across products, services and supporting components.
- Map each mechanism to its parameters, key sizes, protocol profiles and implementation dependencies.
- Record the current version 2.0 classification alongside the proposed version 3 classification.
- Identify information with long-lived confidentiality requirements and assess where hybrid key establishment may need investigation.
- Defer final implementation decisions until the applicable ACM version and relevant protocol standards are confirmed.
What to monitor next
The key status remains unchanged on the access date: version 3 is still presented by ENISA as a draft for public review, and version 2.0 remains applicable. Teams should monitor whether ENISA publishes an adopted version, whether classifications or validity treatments change, and how the final document aligns with relevant protocol and implementation standards.
The version 3 working draft nevertheless gives a clear indication of the direction under consideration: greater prominence for selected post-quantum mechanisms, continued conditional acceptance of many classical mechanisms, and closer attention to hybrid deployment choices.