EdDSA
For EdDSA, purpose is digital signature; current status is Approved; planned status is deprecated after 2030 and disallowed after 2035; replacement is ML-DSA (FIPS 204); source document is IR 8547, recorded from its source on 2026-08-16; source re-checked 2026-09-28.
- Algorithm
- EdDSA verified
- Purpose
- digital signature our reading
- Current status
- Approved our reading
- Planned status
- deprecated after 2030 and disallowed after 2035 our reading
- Replacement
- ML-DSA (FIPS 204) our reading
- Source document
- IR 8547 our reading
Values marked our reading are our classification of what the source says — the source does not print them in those words. The quote below is the evidence for each one; judge it yourself.
What the source says
The IR 8547 Transition Timeline IR 8547 proposes a two-stage retirement for quantum-vulnerable public-key algorithms. Understanding the difference between the two stages is the whole point of the document. Stage | Date | What it means | Deprecated | After 2030 | The algorithm is still permitted but its use is discouraged. In practice, no longer acceptable for new deployments on federal systems. | Disallowed | After 2035 | The algorithm may no longer be used for the stated purpose. A disallowed signature scheme is treated as forgeable; a disallowed key-establishment scheme is treated as vulnerable to key recovery. | The algorithms on this schedule are the public-key workhorses of today’s internet: RSA and elliptic-curve signatures ( ECDSA , EdDSA,
— encryptionconsulting.com, retrieved 2026-08-16
Source
- encryptionconsulting.comhttps://www.encryptionconsulting.com/education-center/nist-ir-8547-sp-800-131a-algorithm-transitions/