PQC (Post-Quantum Cryptography) 08-11-2026

How composite signatures fit into PQC migration

Larry Seltzer
Composite blog hero

Migrating to post-quantum cryptography (PQC) will take time. During that transition, some organizations expect to use conventional and post-quantum algorithms together.

One way to do that is with composite digital signatures and certificates, which contain key material for both conventional cryptography and PQC. DigiCert plans to support four of the 18 composite signature standards expected to emerge from the Internet Engineering Task Force (IETF).

Some organizations may be contractually required, or directed by a standards body, to use composite signatures. For those organizations, composite options will be available.

However, DigiCert doesn’t believe composite signatures are ever necessary for security purposes. If they’re not required for regulatory or business purposes, we recommend using pure ML-DSA instead.

World Quantum Readiness Day graphic

How composite digital signatures work

The IETF LAMPS working group is drafting standards for composite signatures.

Creating a composite signature requires a new type of private key that contains keying material for both a conventional algorithm and a post-quantum algorithm. A corresponding composite X.509 certificate contains a new type of public key with material from both algorithms.

For some organizations, the appeal is that relying parties can validate a single certification path anchored in a multi-algorithm trust anchor. This avoids the need to maintain parallel certificate chains.

The CA/Browser Forum Baseline Requirements will also be relevant in this area, although participants appear willing to let other standards bodies take the lead. 

Which composite signatures will DigiCert support?

DigiCert has selected four options from the emerging standard:

  • MLDSA44-Ed25519
  • MLDSA44-RSA2048-PSS
  • MLDSA65-Ed25519
  • MLDSA87-Ed448

DigiCert intends to release support for these options at a later date.

Why composite signatures may not provide an advantage

DigiCert believes composite signatures are unnecessary unless stringent regulations or other requirements mandate their use. They don’t solve a problem that pure ML-DSA can't address, and they don’t provide a tangible security benefit.

If relying parties already support ML-DSA, there’s no need to pair it with a compromised classical algorithm. Composite certificates also don’t provide backward compatibility because they’re newer than ML-DSA itself.

There are other reasons to avoid composites when they aren’t required.

Larger keys and signatures add overhead

Size matters. Every additional kilobyte can introduce performance overhead.

Cloudflare has studied the effect of larger keys and signatures, providing useful context for teams evaluating the performance implications of PQC.

Ecosystem support remains limited

Announced ecosystem support for composite signatures is minimal.

Anyone that supports composite signatures will necessarily support pure ML-DSA. As a result, technology providers may feel little urgency to add support for composites.

How should you evaluate composite signatures?

If your requirements call for composite signatures, DigiCert recommends starting with MLDSA44-Ed25519 because it has the smallest keys and signatures among the four supported options.

You may also want to experiment with all four. Conduct testing in an isolated lab using a configuration that represents the production systems where the certificates would eventually run.

Testing can help you evaluate:

  • Compatibility with your applications and infrastructure
  • Key and signature size
  • Performance overhead
  • Certificate issuance and validation behavior
  • Support across relying parties

To get hands-on experience with composite certificates and see how they differ from conventional and post-quantum certificate types, create test certificates with the DigiCert Labs certificate generation tool.

Generate post-quantum certificates graphic


Click here to generate your post-quantum certificate.

When composite signatures are required

Composite signatures won’t be the default choice for most PQC migrations. But when a regulation, contract, or standards body requires them, testing is essential. Start with MLDSA44-Ed25519, evaluate it in an isolated lab that reflects your production environment, and confirm compatibility before moving forward.

For questions about using composite signatures, contact pqclabs@digicert.com.

Subscribe to the blog