The ML-KEM implementation in the SunJCE provider in JDK 24 encodes the decapsulation key in its expanded format, as defined in [FIPS 203](https://csrc.nist.gov/pubs/fips/203/final), into its PKCS #8 encoding. This encoding may change as the [related IETF draft](https://datatracker.ietf.org/doc/draft-ietf-lamps-kyber-certificates/) is not yet finalized.