Migrating to post-quantum cryptography (PQC) will take time. During that transition, some organizations expect to use conventional and post-quantum algorithms together.
One way to do that is with composite digital signatures and certificates, which contain key material for both conventional cryptography and PQC. DigiCert plans to support four of the 18 composite signature standards expected to emerge from the Internet Engineering Task Force (IETF).
Some organizations may be contractually required, or directed by a standards body, to use composite signatures. For those organizations, composite options will be available.
However, DigiCert doesn’t believe composite signatures are ever necessary for security purposes. If they’re not required for regulatory or business purposes, we recommend using pure ML-DSA instead.
The IETF LAMPS working group is drafting standards for composite signatures.
Creating a composite signature requires a new type of private key that contains keying material for both a conventional algorithm and a post-quantum algorithm. A corresponding composite X.509 certificate contains a new type of public key with material from both algorithms.
For some organizations, the appeal is that relying parties can validate a single certification path anchored in a multi-algorithm trust anchor. This avoids the need to maintain parallel certificate chains.
The CA/Browser Forum Baseline Requirements will also be relevant in this area, although participants appear willing to let other standards bodies take the lead.
DigiCert has selected four options from the emerging standard:
DigiCert intends to release support for these options at a later date.
DigiCert believes composite signatures are unnecessary unless stringent regulations or other requirements mandate their use. They don’t solve a problem that pure ML-DSA can't address, and they don’t provide a tangible security benefit.
If relying parties already support ML-DSA, there’s no need to pair it with a compromised classical algorithm. Composite certificates also don’t provide backward compatibility because they’re newer than ML-DSA itself.
There are other reasons to avoid composites when they aren’t required.
Size matters. Every additional kilobyte can introduce performance overhead.
Cloudflare has studied the effect of larger keys and signatures, providing useful context for teams evaluating the performance implications of PQC.
Announced ecosystem support for composite signatures is minimal.
Anyone that supports composite signatures will necessarily support pure ML-DSA. As a result, technology providers may feel little urgency to add support for composites.
If your requirements call for composite signatures, DigiCert recommends starting with MLDSA44-Ed25519 because it has the smallest keys and signatures among the four supported options.
You may also want to experiment with all four. Conduct testing in an isolated lab using a configuration that represents the production systems where the certificates would eventually run.
Testing can help you evaluate:
To get hands-on experience with composite certificates and see how they differ from conventional and post-quantum certificate types, create test certificates with the DigiCert Labs certificate generation tool.

Click here to generate your post-quantum certificate.
Composite signatures won’t be the default choice for most PQC migrations. But when a regulation, contract, or standards body requires them, testing is essential. Start with MLDSA44-Ed25519, evaluate it in an isolated lab that reflects your production environment, and confirm compatibility before moving forward.
For questions about using composite signatures, contact pqclabs@digicert.com.