Join our Newsletter — 33% off our NHI Course
Foundations & NHI Taxonomy

Keccak

← Back to Glossary
By NHI Mgmt Group Updated September 29, 2026 Domain: Foundations & NHI Taxonomy

Keccak is the hashing algorithm selected as the basis for SHA-3. It evolved from the RadioGatún primitive and differs materially from the older hash family used in SHA-1 and SHA-2. In practice, Keccak is important because algorithmic diversity can reduce reliance on the same design assumptions across cryptographic deployments.

What Keccak Is and Why It Matters

Keccak is a cryptographic hash function family built around a sponge construction, and it became the basis for SHA-3. Its significance is not just theoretical: it gives systems a modern alternative to older hash families with a different design lineage and security model.

How Keccak Works at a High Level

Keccak absorbs input into a fixed internal state, then squeezes out output of the requested length. That sponge design is what distinguishes it from Merkle-Damgård style hashes such as SHA-1 and SHA-2, and it is part of why SHA-3 was standardized separately rather than as a drop-in replacement.

For practitioners, the important detail is that Keccak is not “just another hash.” The construction changes how padding, domain separation, and output generation behave, which matters when a hash is used for integrity, key derivation, signatures, or protocol design.

Keccak Versus SHA-2 and SHA-1

Keccak was selected after the SHA-3 competition because it offered a distinct cryptographic design rather than reusing the same core structure as SHA-2. That design diversity can reduce correlated failure risk if a weakness is ever found in a particular hash family or style of construction.

In practice, this does not mean Keccak is automatically “better” for every use case. SHA-2 remains widely deployed and well understood, while Keccak is most relevant where a standard SHA-3 family function is required or where protocol authors want the sponge construction’s properties.

Where Keccak Shows Up in Security Design

Keccak matters anywhere a system depends on hashing for trust decisions, tamper detection, or cryptographic binding. It is the kind of primitive that sits beneath many higher-level controls, so correct algorithm selection affects interoperability, auditability, and long-term cryptographic resilience.

Its use is especially relevant in environments that want algorithm agility. Selecting a different hash primitive can help avoid overconcentration on one design assumption, but the real value comes only when the surrounding protocol, key management, and implementation choices are sound.

Risk and Threat Considerations

Hashing algorithms are often treated as interchangeable, but weak substitution choices can create real exposure. Using the wrong hash for the job, or assuming any modern hash is safe in every context, can undermine integrity checks, digital signatures, password handling, or protocol compatibility.

Failure mechanism: Security breaks usually arise from misapplication, legacy compatibility, poor truncation rules, or implementation errors rather than from Keccak itself. Problems also appear when teams preserve outdated assumptions from older hash families and fail to re-evaluate how the construction behaves in the surrounding system.

Impact: The result can be integrity loss, verification failures, interoperability problems, or a false sense of cryptographic safety. In large environments, inconsistent hash choices can also complicate incident response and migration planning.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST SP 800-57 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5SC-13 — Cryptographic ProtectionKeccak is a cryptographic primitive used to protect integrity and related security functions.
Recommendation — Use approved cryptographic hashes consistently and validate that implementations preserve required integrity properties.
NIST SP 800-57Key ManagementHash selection and output use depend on key lifecycle and algorithm-strength decisions in cryptographic systems.
Recommendation — Align hash choices with key sizes, cryptoperiods, and approved cryptographic transitions.
ISO/IEC 27001:2022A.8.24 — Use of cryptographyKeccak is relevant as a cryptographic algorithm selected and governed under cryptography controls.
Recommendation — Specify and approve cryptographic algorithms, then review their use across systems and protocols.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org