This page organizes documentation related to the NIST First Call for Multi-Party Threshold Schemes [NIST IR 8214C] (2026).
The technical scope is organized across two classes — Class N (NIST-specified primitives) and Class S (Special primitives not specified by NIST) — each with various categories of crypto-systems, as follows:
| Sign | PKE | Symm | KeyGen | FHE | ZKPoK | Gadgets | |
|---|---|---|---|---|---|---|---|
| Class N | N1 | N2 | N3 | N4 | |||
| Class S | S1 | S2 | S3 | S4 | S5 | S6 | S7 |
The NIST Threshold Call considers a Previews phase (including three opportunities/rounds) and a Packages phase. Participation in the Previews phase is a requirement for a subsequent participation in the Packages phase.
Template for Preview Writeups (v0.2.2, 2026-07-11): .zip (with latex code) and .pdf (example). Submitted Preview Writeups may be subject to revision recommendations and their full consideration also depends on a corresponding Preview Talk.
Template for Package Writeups: To appear (expected August 2026), with the structure outlined in the NIST Threshold Call. Will be usable for Technical Specification, Report on Experimental Evaluation, and Notes on Patent Claims.
The first phase of previews gathered 26 Preview Writeups (PW) from 23 distinct teams, as listed in the table below. The union of the teams includes 185 authors. The corresponding Preview Talks (PT) were hosted at MPTS 2026 (NIST Workshop on Multi-Party Threshold Schemes). The Preview Writeups can be updated across time (see date in column "Preview Writeup").
Legend: [PW] = [Preview Writeup (link to file)]; [PT] = [Preview Talk (link to webpage)]. |Team| = Number of team members.
| # | Team |
Categories |
|Team| | Crypto-systems (hint) |
Preview |
Preview |
Patents * |
| 1 | Amber | S2 | 4 | Amber (Threshold Lattice-based KEM) | [PW] | [3b5] | Yes |
| 2 | BBDL | S1 | 4 | tBLS (Threshold BLS Sign) | [PW] | [1b1] | |
| 3 | BDLR | N1 | 4 | Gargos (Threshold Schnorr Sign) | [PW] | [1a4] | |
| 4 | BICYCCLIST | N1 | 7 |
TECLA (2-party Threshold ECDSA) |
[PW] | [2a3] | |
| 5 | N1 | 7 | THE-CLASH (n-party Threshold ECDSA) | [PW] | |||
| 6 | Fireblocks-3MI | N1, N4 | 7 | Classic Schnorr (Threshold Schnorr Sign) | [PW] | [1a3] | |
| 7 | N1, N4 | 7 | BAM (2-party ECDSA) | [PW] | [2a2] | ||
| 8 | N1, N4, S2, S7 | 7 | CCGMP (n-party ECDSA) and gadgets | [PW] | |||
| 9 | FROST | N1 | 12 | FROST (Threshold Schnorr Sign) | [PW] | [1a1] | |
| 10 | Haystack | N1 | 3 | Haystack (Threshold HBS) | [PW] | [3a6] | |
| 11 | Hermine | S1, S4 | 8 | Hermine (Threshold Sign) [Lattice-based] | [PW] | [3b3] | |
| 12 | LEAST | S1, S4 | 9 | LEAST (Threshold Sign) [from code-based group-actions] | [PW] | [4a3] | |
| 13 | Mithril | N1, N4 | 6 | Mithril (Threshold ML-DSA) | [PW] | [3b7] | Yes |
| 14 | MPC MINIons | N3, S3, S7 | 14 | MiniMPC (Threshold AES+SHA+MAC) and gadgets (inc. OT and garbling) | [PW] | [3a2] [3a3] | |
| 15 | PANTHERIA | S5 | 26 | FHE (RLWE-based) and Threshold FHE | [PW] | [2b5] | Yes |
| 16 | PiVer | S7 | 10 | PiVer (Verifiable Secret Sharing) | [PW] | [4b2] | |
| 17 | PQarrots | S1, S2, S4 | 31 | Macaw (Threshold Signature), Kea (Threhold PKE), Kakapo (SKG) (from Isogeny-based Group Actions) | [PW] (Jan-30) | [4a1] | |
| 18 | Quorus | N1, N4 | 5 | Quorus (Threshold ML-DSA) | [PW] | [3b6] | |
| 19 | RedETA | N1, N4 | 6 | RedETA signatures (Threshold ECDLP-based Signatures) | [PW] | [2a4] | Yes |
| 20 | Schmivitz | S6, S7 | 8 | VOLEith-based ZKPoK | [PW] | [4c1] | |
| 21 | SmallWood | S6 | 2 | SmallWood (hash-based ZKPoK) | [PW] | [4c2] | |
| 22 | SplitForge | N1, S2, N4 | 10 | SplitKey (Server-assisted threshold signatures and PKE) | [PW] | [2a5] | |
| 23 | Symphony | N3, S7 | 4 | Maestro (T-AES), SHArp (T-SHA), MACnifico (T-MAC) and gadgets (inc one-hot vectors) | [PW] | [3a5] | |
| 24 | Tanuki | S1 | 12 | Tanuki (Threshold Lattice-based Signature) | [PW] | [3b2] | Yes |
| 25 | Vinaigrette | S1, S4 | 9 | Threshold UOV+MAYO Signatures (Multivariate-based) | [PW] | [4a4] | |
| 26 | Zama | S4, S5, S6 | 13 | TFHE (Torus), ZHEnith (ZKP), Nexus (Threshold FHE) | [PW] | [2b3] | Yes |
* The column "Patents" shows "Yes" for the "Preview Writeups" that indicated there are patents whose claims may apply to the proposed crypto-systems. The upcoming package submission requires a "Notes on Patent Claims" document with more detail.
The second phase of previews gathered 10 Preview Writeups (PW) from 10 distinct teams, as listed in the table below. The union of the teams includes 35 authors. The corresponding Preview Talks (PT) were hosted at TCPT2 (Threshold Call Preview Talks #2 on July 07–08, 2026). The Preview Writeups may be updated across time (see date in column "Preview Writeup").
Legend: [PW] = [Preview Writeup (link to file)]; [PT] = [Preview Talk (link to webpage)]. |Team| = Number of team members.
| # | Team | Categories | |Team| | Crypto-systems (hint) | Preview Writeup | Preview Talk | Patents * |
| 27 | Dfns-Coord | S7 | 3 | Coordinated Messaging | [PW] | [1b1] | |
| 28 | Dfns-KU | N1 | 4 | KU (Threshold ECDSA) | [PW] (Jul-27) | [1a3] | Yes |
| 29 | FaFROST | N1 | 6 | FaFROST (Threshold Schnorr) | [PW] (Jul-24) | [1b2] | |
| 30 | LaZer | S6 | 4 | LaZer (Lattice-based ZKP) | [PW] | [2b1] | |
| 31 | Lemur | S1 | 5 | Lemur (Lattice-based Signature) | [PW] | [2a2] | |
| 32 | LoTRS | S1 | 6 | LoTRS (Lattice-based Signature) | [PW] | [2a3] | |
| 33 | TALUS | N1, N4 | 2 | TALUS (Threshold ML-DSA) | [PW] | [2a1] | Yes |
| 34 | Threshcon | N3 | 2 | Threshcon (Threshold Ascon) | [PW] | [2b2] | |
| 35 | Trout | N1 | 3 | Trout++ (Threshold ECDSA) | [PW] | [1a1] | |
| 36 | Twig | N1 | 7 | Twig (Threshold ECDSA) | [PW] (Jul-22) | [1a2] | Yes |
* The column "Patents" shows "Yes" for the "Preview writeups" that indicated there are patents whose claims may apply to the proposed crypto-systems. The upcoming package submission requires a "Notes on Patent Claims" document with more detail.
Before an actual package submission, each prospective team needs to submit a "Preview Writeup" (plan of upcoming package submission) and (if accepted) present a "Preview Talk". For consideration within the 3rd round of previews, teams should submit their preview writeup by 2026-Aug-07.
[To appear: Each package will include Technical Specification, Open-Source Reference Implementation, Report on Experimental Evaluation, Notes in Patent Claims]
The submission of packages will be handled after the phase of previews. The deadline for packages submission is expected to be set to 2026-Nov-30 (postponed from 2026-Oct-19). The deadline will be confirmed after the third preview phase.
The latex template for Technical Specification, Report on Experimental Evaluation, and Notes in Patent Claims is expected to be made available in August 2026, following the structure outlined in the NIST Threshold Call.
Security and Privacy: digital signatures, encryption, key management, message authentication, post-quantum cryptography, secure hashing
Activities and Products: standards development