The Senate’s Quantum Grid Bill Directs FERC to ‘Consider’ Q-Day. Considering Is All It Requires.
The Verb Doing All the Work Is “Consider”
Senator Chris Coons (D-Del.) introduced S.5313 on August 14, 2026. It carries exactly one cosponsor, Senator Mike Rounds (R-S.D.), and it now sits with the Senate Committee on Energy and Natural Resources. The Quantum Grid Utility Assurance and Resilient Defense Act — Quantum-GUARD — is being described as an effort to armor the power grid against quantum computers. Read the text and it is something more modest, and in one respect more useful.
The bill does three things. It directs the Federal Energy Regulatory Commission to consider cyber threats from quantum computers, and potential uses of post-quantum cryptography, when it reviews reliability standards under the Federal Power Act. It establishes a collaborative testing environment inside the Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER) to work out what breaks when utilities try to adopt post-quantum algorithms. And it tells CESER to study quantum vulnerabilities across the bulk electric power system — information technology and operational technology alike — and report back to Congress.
Nothing in there compels a single utility to replace a single certificate. FERC is instructed to think about the problem and take appropriate action — which is less a criticism of the drafting than a description of where the policy actually is.
The Cryptography Is Finished. The Deployment Isn’t.
A common framing of this issue — including in most coverage of this bill — is that post-quantum standards are still being worked out. They aren’t. NIST finalized three of them on August 13, 2024: FIPS 203 (ML-KEM) for key establishment, FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for signatures. In March 2025 it selected HQC as a backup key-encapsulation mechanism built on different math, so that a break in lattice assumptions does not take everything down at once. The algorithms exist, and vendors ship them. What does not exist is any obligation for the private, decades-deep world of grid operational technology to use them. That gap is the entire story.
The Threat Estimate Keeps Getting Cheaper
The honest case for acting now is not that a cryptographically relevant quantum computer exists. It is that the resource estimate for building one keeps falling without anyone building anything.
In 2019, Craig Gidney and Martin Ekerå estimated that factoring a 2,048-bit RSA key would take a quantum computer with 20 million noisy qubits about eight hours. In May 2025, Gidney published a revised analysis putting it at fewer than one million noisy qubits in under a week — a roughly twentyfold reduction in six years, achieved through better arithmetic and cheaper magic-state distillation rather than better hardware. Both assume the same machine: a square grid of qubits with nearest-neighbor connections, a 0.1% gate error rate, and a one-microsecond surface-code cycle. No such machine is close. But the target has been moving toward the attacker at a steady clip.
That is what makes “harvest now, decrypt later” more than a slogan for grid operators specifically: substation and control-system equipment is bought to sit in place for decades, and traffic captured today can be opened whenever the hardware arrives.
What NERC Already Requires — and What It Doesn’t Say
The grid is not unregulated on this point. NERC’s CIP-012-2 took effect on July 1, 2026, requiring balancing authorities, reliability coordinators, transmission operators and owners, and generator operators and owners to document plans that prevent unauthorized disclosure and modification of real-time assessment and monitoring data moving between control centers.
It does not name a cipher. It is, sensibly, algorithm-agnostic — which means an entity can satisfy it today with classical public-key cryptography and remain compliant on the day that cryptography stops working. NERC’s own CIP roadmap, published in January 2026, lists quantum computing under emerging security risks without attaching a requirement to it. Quantum-GUARD’s FERC clause tries to push that from a roadmap heading into a standards proceeding.
Nobody Has Priced the Utility Bill
The federal government has at least priced its own migration. OMB, the Office of the National Cyber Director, CISA, and NIST put the cost for federal civilian agencies at roughly $7.1 billion between 2025 and 2035, in 2024 dollars. That estimate explicitly excludes national security systems, and it excludes the commercial sector entirely — which is to say it excludes almost the whole electric grid.
The deadline has since tightened. Where agencies had been planning against a 2035 horizon, an executive order now requires high-value assets and high-impact systems to move to post-quantum keys by December 31, 2030, and to post-quantum digital signatures by the end of 2031. Those dates bind federal agencies. They do not bind investor-owned utilities, municipal systems, or cooperatives, and the $7.1 billion never covered them.
Quantum-GUARD does not fix that either. What it does fix, potentially, is the information problem: a CESER testbed and a study would produce the first federal accounting of what post-quantum migration actually costs and breaks in operational technology — the number nobody currently has.
Read the Endorsement List
The bill is backed by the Quantum Economic Development Consortium, the Cyber Threat Alliance, the Quantum Industry Coalition, Ampyx Cyber, TPO.group, American Binary, and IonQ — a list worth reading twice. A quantum hardware company and a quantum trade group endorsing legislation premised on quantum computers becoming dangerous is not a contradiction, but it is an alignment of interest, and it belongs in the frame.
The threat is real, the algorithms are ready, and the sector with the longest equipment lifetimes has the weakest mandate. A bill directing a regulator to consider the problem, and a department to measure it, is a reasonable first move. It is a first move.
Get the weekly briefing
One email a week on AI, infrastructure, policy and the supply chains underneath them. Free, and you can unsubscribe any time.