Fast, medium-small-ish among PQ, but do you trust the cryptanalysis for now?
Classic McEliece
60 years of cryptanalysis, unbroken; megabyte public keys; ciphertext sizes are nice though. Never getting into Noise or TLS.
CSIDH
Beautiful NIKE, small keys, slow as hell, do you really trust isogenies, also everyone says it’s small because we benchmark CSIDH-512 but does that actually give you real 128-bit PQ?
SIDH/SIKE
This is why we do cryptanalysis.
HQC
Does anyone really understand how it works other than “noisy ElGamal”? Actually, probably, but how much have we studied quasi-cyclic codes? Also slower and larger than ML-KEM.
ML-DSA
3KB signatures where you used to have 64 bytes, and also do you really trust the ring structure, well that’s same for ML-KEM.
Falcon
Nice 600-byte signature and cursed math, good luck implementing it in constant time and make sure no compiler flags or whatever mess up your IEEE 754. Also don’t leak the key. But really, I kinda like it.
SLH-DSA
You trust SHA-256 to work as advertised, yeah? Then bulletproof but your signature sizes are a giant JPEG. Fair for root certs or something like that.
SQIsign
Small signatures, small keys, slow as hell. Probably also appeared in Alice in Wonderland somewhere for the quaternion orders.