executive-ordertrade-pressNewsThe Broadside2 min read

Quantum-GUARD Act tasks FERC, DOE with grid PQC migration

Trump's PQC executive order gets its first legislative codification, narrowed to electric utilities, with FERC reliability standards as the enforcement mechanism that guidance alone can't provide.


TL;DR

Sens. Chris Coons (D-DE) and Mike Rounds (R-SD) introduced the Quantum-GUARD Act on Aug. 14, directing FERC to factor quantum-computing risks into bulk-power reliability standards and requiring DOE to establish a collaborative PQC testing environment within one year. Electric utilities and grid operators would face potential mandatory PQC migration; FERC-approved reliability standards carry enforcement teeth that guidance doesn't. This is the first legislative codification of Trump's June 2025 PQC executive order, and it narrows the field from government-wide to a single critical-infrastructure sector.

Quantum-GUARD Act tasks FERC, DOE with grid PQC migration
Editorial illustration · drawn by The Broadside

The Quantum-GUARD Act, introduced by Sens. Chris Coons (D-DE) and Mike Rounds (R-SD) on August 14, takes one piece of President Trump's June 2025 post-quantum cryptography executive order and writes it into statute, but only for the electric grid. The bill directs the Federal Energy Regulatory Commission to factor quantum-computing risks into its review of bulk-power reliability standards proposed by the North American Electric Reliability Corporation, and requires the Department of Energy's CESER office to stand up a collaborative PQC testing environment for utilities within one year.

The FERC provision is where the bill does something guidance alone can't. Under the executive order, sector risk management agencies are directed to assist critical infrastructure owners with PQC migration planning, a coordination role, as reflected in CISA's January 2026 product-categories list. The Quantum-GUARD Act puts FERC in a position to embed quantum-risk assessment into mandatory reliability standards. Once a standard is approved by FERC, noncompliance can trigger enforcement action. That's a different category of incentive from technical assistance or procurement guidance.

The three-year question

DOE gets one year to establish its testing environment and three years to publish a public report recommending how FERC should encourage PQC adoption in "high-value" IT and OT systems in bulk electric systems. The bill doesn't define "high-value," and it doesn't specify whether FERC's eventual actions would be mandatory or guidance-based. That ambiguity is the operational question for utility CISOs and compliance directors: whether this lands as a reliability standard with enforcement teeth or as a recommendation dressed in statutory language. CISA has separately warned that OT and ICS environments face unique PQC migration challenges (long equipment lifecycles, real-time constraints, and limited crypto-agility) that make the DOE testing environment practically necessary, not just politically expedient.

Where it fits

The bill arrives as House and Senate committees advance separate versions of the National Quantum Initiative Reauthorization Act, each containing provisions for NIST to provide technical assistance to critical-infrastructure operators at high risk of quantum attack. The Quantum-GUARD Act is narrower and more prescriptive, it picks one sector and names the regulator. Rounds, who chairs the Senate Armed Services cyber subcommittee, framed it explicitly as codifying pieces of Trump's EO. For electric utilities still parsing what the June 2025 executive order means for them, the bill provides an early answer: FERC will be the one asking.


Published ·Deep Fathom