Reference Source

EdDSA

For EdDSA, purpose is digital signature; current status is Approved; planned status is deprecated after 2030 and disallowed after 2035; replacement is ML-DSA (FIPS 204); source document is IR 8547, recorded from its source on 2026-08-16; source re-checked 2026-09-28.

Algorithm
EdDSA verified
Purpose
digital signature our reading
Current status
Approved our reading
Planned status
deprecated after 2030 and disallowed after 2035 our reading
Replacement
ML-DSA (FIPS 204) our reading
Source document
IR 8547 our reading
Sourceencryptionconsulting.com
Verified
Review by
DatasetNIST cryptographic algorithm deprecation schedule: what is approved, deprecated, and disallowed, and when

Values marked our reading are our classification of what the source says — the source does not print them in those words. The quote below is the evidence for each one; judge it yourself.

What the source says

The IR 8547 Transition Timeline IR 8547 proposes a two-stage retirement for quantum-vulnerable public-key algorithms. Understanding the difference between the two stages is the whole point of the document. Stage | Date | What it means | Deprecated | After 2030 | The algorithm is still permitted but its use is discouraged. In practice, no longer acceptable for new deployments on federal systems. | Disallowed | After 2035 | The algorithm may no longer be used for the stated purpose. A disallowed signature scheme is treated as forgeable; a disallowed key-establishment scheme is treated as vulnerable to key recovery. | The algorithms on this schedule are the public-key workhorses of today’s internet: RSA and elliptic-curve signatures ( ECDSA , EdDSA,

— encryptionconsulting.com, retrieved 2026-08-16

Source

Last verified against source: . Due for re-check by . This page as Markdown · OKF bundle · full dataset as JSON.