This bill directs the National Institute of Standards and Technology (NIST) and the Office of Science and Technology Policy (OSTP) to help U.S. information systems prepare for threats from future quantum computers. NIST must, within 180 days of enactment, publish guidance for upgrading systems to post-quantum cryptography. The guidance must include standards and selection criteria for procuring and deploying commercial post-quantum solutions and material tailored for critical infrastructure sectors. NIST must make the guidance available to the private sector and may publish Special Publications. NIST must also offer to collaborate with industry assessments led by members of the Quantum Economic Development Consortium and, if asked, provide technical support, test beds, interoperability frameworks, and coordination.
OSTP must, within 360 days of enactment and in coordination with NIST, produce a National Quantum Cybersecurity Upgrade Strategy. The strategy must define a “cryptographically relevant quantum computer,” recommend standards and characteristics to identify such machines, and give guidelines to assess how urgently each Federal agency should upgrade. The strategy must list recommended performance measures for preparing to upgrade (including hardware and software steps), building a data inventory baseline, planning and executing post-quantum solutions for data at rest and in motion, and monitoring upgrades. The strategy must include an implementation plan and steps to evaluate and monitor entities at high risk of quantum attacks.
OSTP must also create a voluntary post-quantum pilot program within 360 days to provide planning and technical help to participating covered entities (sector risk management agencies, Federal agencies, and mission partners). The pilot must encourage high-risk entities to join. For each participating covered entity, at least one high-impact system must be upgraded to post-quantum cryptography within 18 months of program start, after which the entity head may upgrade additional systems under specified notice rules. OSTP and the covered entity must report to the relevant congressional committees: an initial report within 180 days after the initial upgrade and annual updates thereafter.
The bill includes definitions for terms used in the text, such as post-quantum cryptography (and references to specific NIST FIPS and NIST Special Publication standards), high-impact system (as defined by FIPS 199), and critical infrastructure sectors (as defined in NSM-22).
No publicly available information on costs, funding levels, or appropriations is included in the bill text.
The bill’s text frames the goal as helping Federal agencies, critical infrastructure sectors, and industry prepare for quantum-era threats by providing clear guidance, measurable performance steps, technical support, and a voluntary pilot program to demonstrate upgrades to post-quantum cryptography.
No publicly available information.