...

FortifyIQ Announces CAVP‑Validated ML‑DSA Verification Library for Post‑Quantum Secure Boot

webinars and news on cybersecurity
Newsroom hexa-yellow icon

FIQ-PQC03-SW, ML-DSA compact signature verification is an ultra-compact verification‑only ML‑DSA implementation with ultra-small code size and stack usage, for verification-only, as used in secure boot in highly memory- and power-constrained embedded devices.

Hod HaSharon, Israel and Salem, Massachusetts, USA. September 3, 2026.

FortifyIQ today announced that its PQC signature verification library has successfully completed its NIST CAVP validation, confirming alignment with NIST’s FIPS 204 standard for post‑quantum digital signatures. ML‑DSA verify‑only is the NIST‑designated post‑quantum digital signature algorithm for secure boot and authenticated firmware updates. FortifyIQ’s technology enables ultra-small code size and stack usage (ROM/RAM), providing a practical path to post-quantum secure boot for constrained platforms and other devices that need to support post quantum secure boot today.

Post‑quantum migration is becoming an essential requirement across embedded systems, including constrained IoT devices and long‑life infrastructure already deployed in the field. ML‑DSA, standardized in FIPS 204, is the post‑quantum digital signature algorithm designated for secure boot and authenticated firmware updates.

FortifyIQ’s compact, pure‑software, verify‑only ML‑DSA module is designed to fit inside the mask ROM of new, cost‑sensitive MCUs/SoCs that have no dedicated crypto hardware, so every unit can ship with PQC secure boot from the factory.

The same implementation can also be integrated into bootloaders and OTA update agents on existing devices, enabling quantum‑safe secure boot and signed firmware updates without hardware changes.

This verification-only library complements FortifyIQ’s portfolio of physically hardened (SCA/FIA-resistant) NIST CAVP-validated post-quantum cryptography, extending high‑assurance protection to resource‑constrained embedded environments such as industrial control and SCADA systems, automotive ECUs, and medical devices.

“Our customers have been clear: they need a practical path to post‑quantum secure boot.” said Alex Kesler, CEO of FortifyIQ. “We engineered this implementation for resource‑constrained embedded systems, where memory budgets are tight and bootloaders must remain small.”

Availability
The ML‑DSA verification library is available now.

About FortifyIQ

FortifyIQ engineers high-assurance, security-certifiable cryptographic IP cores and cryptographic software libraries with classical and post-quantum algorithms, all algorithmically hardened against side-channel and fault injection attacks, while maintaining performance, area, and energy efficiency. Our solutions are foundry- and platform-agnostic, for a wide spectrum, from smart cards and IoT devices to AI accelerators and cloud systems.

Backed by a strong portfolio of granted and pending patents, deep cryptographic research, and formal and practical security proofs, FortifyIQ’s IP is developed and validated using pre- and post-silicon EDA tools, enabling systematic evaluation of physical attack resilience, and by independent evaluations.

FortifyIQ delivers advanced cryptography that is all quantum-safe, certifiable, reliable, and built to meet the security regulatory requirements of today and of the future, and the challenges of real-world applications.

For more information contact: info@fortifyiq.com

SGS certification logo
FortifyIQ AES Algorithm
AVA_VAN.5 Evaluation & Validation Summary
SGS Brightsight Common Criteria Laboratory
Summary. The leakage analysis (Welch t-test) on over 30 million traces did not show statistically significant first- and second-order differences between trace sets with fixed and random inputs. The template-based DPA analysis, on the pseudo-random trace set for the profiling phase (15 million traces) and on a sub-set of 300k fix input traces for matching phase targeting the first-round S-box output, and template attack on ciphertext, did not indicate any potential information leakage.”
“The results for the soft IP presented in the report were obtained on the TOE which is the basic hardware implementation of the soft IP without additional levels of security (e.g. that are present in a secure silicon layout). Therefore the internal strength of the soft IP itself was evaluated. This indicates that the investigated features and parameters of the soft IP implementation should be robust against SCA and fault injection attacks in different implementations including ASIC. Nevertheless, according to the Common Criteria rules, the strength of the final composite product must be evaluated on its own
Request Technical Details