Why did the report evaluate ML-DSA-44 specifically?
The biggest reason is practicality.
Compared to higher-security parameter sets like ML-DSA-65 and ML-DSA-87, ML-DSA-44 offers:
• Smaller signatures
• Faster verification
• Lower network overhead
That matters because signature size quickly becomes the dominant scaling constraint in post-quantum systems.
In testing, PQ blocks were already ~18× larger than non-PQ blocks at equivalent TPS.
Read the report 👇