Quantum-GUARD Act directs FERC to harden grid against quantum attacks
FERC gets told to study quantum threats to the grid, but the bill stops short of setting migration deadlines of the kind the executive branch already imposed on federal agencies.
TL;DR
The Quantum-GUARD Act, introduced by Sens. Mike Rounds (R-SD) and Chris Coons (D-DE), directs FERC to review electric-grid reliability standards for quantum-computer threats and to explore post-quantum cryptography for IT and OT systems. The bill authorizes FERC to "take such action the Commission determines to be appropriate." That's language that stops short of mandating migration timelines. For grid operators running quantum-vulnerable SCADA on legacy public-key crypto, Monday looks the same as Friday.
The Quantum-GUARD Act tells FERC to "explore" and "consider" post-quantum cryptography for the electric grid and then take whatever action it "determines to be appropriate." That isn't a mandate. It's an authorization to study the problem: a necessary first step, but not one that changes anyone's Monday.
The bill arrives amid an accelerating federal push on quantum preparedness. NIST finalized its first post-quantum cryptographic algorithms last year. The Biden administration set a 2035 federal migration target. In June, a Trump executive order accelerated that deadline to 2030. A Senate bill that directs FERC to explore the issue, against that backdrop, reads less like urgency and more like due diligence from a sector where reliability is the non-negotiable priority.
The real bottleneck isn't regulatory willpower. It's the OT infrastructure that has to be touched.
Ali Shaikh, CEO of Graphiant, told CyberScoop the "real work is upgrading infrastructure, not applications." Evgeny Gervis, CEO of SafeLogic, identified the core tension: "The highest priority for electric utilities will be preservation of integrity and availability, both services that are widely supported by legacy public key cryptographic controls that are quantum vulnerable." In plainer terms, the crypto protecting SCADA communications and software update integrity is the same crypto quantum computers are expected to break. Replacing it means touching systems where an outage isn't an inconvenience; it's a reliability violation.
Getting quantum threats into FERC's reliability-standard review process is necessary groundwork for eventual mandates. But for the engineers who will have to swap out field-device cryptography without dropping a substation, the clock hasn't started ticking.
Published ·Updated ·Deep Fathom