Skip to content

ETSI, BSI, ISO/IEC and the rest: who does what

A one-line orientation to the other standards bodies you will meet in a post-quantum program — the European telecoms group, the German federal office, and the international standards organization — and where each fits.

LeadershipIntro4 min· Updated Jul 22, 2026

NIST, CISA, the IETF, and the FIDO Alliance cover most of what an English-speaking program cites day to day. But three more bodies come up often, especially for organizations operating in Europe or under international frameworks. Here is what each is for in a sentence.

  • **ETSI** — the European Telecommunications Standards Institute. Its Quantum-Safe Cryptography group publishes technical reports and specifications on migration, use cases, and quantum-safe protocol profiles; influential in European telecoms and critical infrastructure.
  • **BSI** — Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik). Its TR-02102 technical guideline gives national cryptographic recommendations and, notably, endorses a conservative PQC posture — recommending schemes such as FrodoKEM and Classic McEliece alongside ML-KEM, and pushing hybrid deployment.
  • **ISO/IEC JTC 1/SC 27** — the joint international committee for IT security techniques. It standardizes cryptography and security management (including the ISO/IEC 27000-series ISMS standards) for global use, and is incorporating the post-quantum algorithms into international standards.
Pitfall

The bodies do not always agree on parameters

BSI and NIST, for example, differ on which algorithms and parameter sets they emphasize (BSI is more cautious about relying on lattices alone). If you operate across jurisdictions, resolve these differences explicitly in policy rather than assuming "NIST-approved" satisfies every regulator.

For most organizations the practical rule is: build to the NIST algorithms and IETF protocols as the baseline, then check whether a regulator or customer contract pulls in ETSI, BSI, or an ISO/IEC requirement that adds constraints on top. The compliance mapping is where those obligations get reconciled.