What is the 256-bit cryptographic hash function standardized by NIST in 2002?

The story behind the answer

The 256-bit cryptographic hash function standardized by NIST in 2002 is SHA-256.

SHA-256 belongs to the SHA-2 family of cryptographic hash functions. It accepts input of arbitrary length and produces a fixed 256-bit digest, usually written as 64 hexadecimal characters. A tiny change in the input normally produces a substantially different digest, a property called the avalanche effect.

NIST published the SHA-2 family in the Federal Information Processing Standards publication FIPS PUB 180-2 in 2002. SHA-256 is used in integrity checks, digital signatures, certificate systems, and many blockchain implementations. Hashing is not encryption: encryption is designed to be reversible with a key, while a secure cryptographic hash is designed to be computationally infeasible to reverse.

SHA-256 should also be distinguished from SHA-1 and MD5, older algorithms that have serious collision weaknesses. For password storage, a fast general-purpose hash alone is not ideal; purpose-built password-hashing algorithms add salting and computational cost.

Source: Wikipedia · fact-checked Sept. 2026

Add question to a list

Choose a list to keep this question in: