Home icon

How to create post-quantum signatures using AWS KMS and ML-DSA

Security Blog



AWS has announced the integration of Module-Lattice-Based Digital Signature Standard (ML-DSA) into AWS Key Management Service (AWS KMS), providing post-quantum cryptographic signature capabilities.

  • Offers three new key specifications: ML_DSA_44, ML_DSA_65, and ML_DSA_87
  • Provides quantum-resistant digital signatures with different security levels
  • Supports signing and verifying messages up to 4096 bytes using RAW or EXTERNAL_MU message types
  • Available in select AWS Regions with plans to expand
  • Enables secure long-term signing for firmware, operating systems, and applications

The new feature allows organizations to prepare for potential future quantum computing threats by implementing post-quantum cryptographic signatures within a FIPS-140-3 Level 3 certified environment.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Jun 13
2025
AWS KMS adds support for post-quantum ML-DSA digital signatures
Nov 17
2025
Post-quantum (ML-DSA) code signing with AWS Private CA and AWS KMS
Apr 7
2025
ML-KEM post-quantum TLS now supported in AWS KMS, ACM, and Secrets Manager
May 14
2026
Automating post-quantum cryptography readiness using AWS Config

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.