Post-quantum cryptography has mostly been a story about browsers, VPNs and enterprise IT stacks migrating their encryption. This month it reached the electric grid. Senators Chris Coons (D-Del.) and Mike Rounds (R-S.D.) introduced the Quantum Grid Utility Assurance and Resilient Defense Act, which would direct the Federal Energy Regulatory Commission to fold quantum computing threats and post-quantum cryptography into the reliability standards that electricity owners and operators must meet, and to stand up a technical sandbox for studying how quantum technology affects both information and operational technology systems.

“As the technology races forward and our adversaries continue to seek vulnerabilities in our critical systems, we need to pass the Quantum-GUARD Act to ensure our government is using every available tool to meet this threat,” Coons said in the bill’s announcement. Patrick Miller, president and CEO of Ampyx Cyber, put the practical stakes in operational terms: “The hardest part of getting ahead of it is not the cryptography itself but migrating the equipment already in the field. This bill gets the approach right.”

That framing matters more than the bill’s text alone conveys. SCADA systems that control physical grid equipment were never designed with cryptographic agility in mind. The signatures behind a trusted firmware update reaching a substation controller depend on cryptography a sufficiently capable quantum computer could eventually forge, letting an attacker push malicious firmware disguised as legitimate. Migrating that infrastructure is not a software update; it is a hardware and protocol replacement cycle measured in years, on equipment with service lives measured in decades.

For a CISO or OT security lead at a utility or vendor serving one, the actionable step now, well ahead of any FERC rulemaking, is to start the inventory: which SCADA components, update mechanisms and protocols rely on cryptography with no post-quantum successor path yet. That inventory is the same work recent nation-state activity against critical infrastructure has made urgent, and the UK’s guidance on identity in critical systems points at the same gap: legacy infrastructure was not built for the threat model it now faces.

Source: Senator Chris Coons, “Senators Coons, Rounds Introduce Bipartisan Legislation to Fortify Our Electric Grid Against Emerging Quantum Cyber Threats”