# Does the Quantum-GUARD Act Finally Force Grid Operators to Take PQC Seriously?

Two U.S. senators introduced the Quantum-GUARD Act on August 18, 2026 — a bipartisan bill that would mandate FERC consideration of quantum cybersecurity risks, fund a DOE testing environment for [post-quantum cryptography](https://quantumintel.tech/glossary/fault-tolerant-quantum-computing) adoption, and require a formal vulnerability study of the bulk electric power system. The legislation, sponsored by Senator Chris Coons (D-Del.) and Senator Mike Rounds (R-S.D.), represents the most targeted federal push yet to move critical infrastructure off encryption standards that a sufficiently capable quantum computer could break.

The bill's core premise is straightforward: NIST finalized its post-quantum cryptography standards in 2024, but the electric utility sector has been slow to migrate — not because the cryptography is inadequate, but because replacing embedded IT and operational technology across thousands of deployed grid assets is a logistical and financial challenge of a different order than updating enterprise software. The Quantum-GUARD Act attempts to supply both the regulatory pressure and the institutional infrastructure to accelerate that transition.

If enacted, this legislation would directly affect every entity operating under FERC's bulk electric system reliability authority, and every vendor supplying IT and OT systems to that sector.

---

## What the Quantum-GUARD Act Would Actually Do

The bill's three operative provisions are specific and worth parsing carefully:

**1. FERC quantum risk mandate.** The legislation directs the Federal Energy Regulatory Commission to consider cybersecurity risks posed by quantum computers within its existing authority over grid reliability standards. This stops short of mandating specific PQC deployment timelines — FERC retains its standard-setting discretion — but it formally puts quantum threat modeling inside the reliability rulemaking process. That matters: FERC reliability standards carry enforcement teeth that voluntary guidance does not.

**2. DOE CESER testing sandbox.** The bill establishes a collaborative testing environment through the Department of Energy's Office of Cybersecurity, Energy Security, and Emergency Response (DOE CESER). The intent is to allow utilities and vendors to work through the practical problems of PQC adoption — interoperability conflicts, latency impacts on control system communications, firmware update logistics — before committing to full field deployment. This is the provision industry organizations are most enthusiastic about, because it acknowledges that PQC migration on live grid infrastructure is operationally risky without prior validation.

**3. Bulk electric system vulnerability study.** DOE CESER would be required to study quantum cybersecurity risks across both information technology and operational technology layers of the bulk electric power system. OT systems — SCADA platforms, substation automation, protection relays — are the harder problem: many run on hardware with multi-decade field lifespans, and their cryptographic libraries are often not patchable without physical replacement.

---

## Industry Voices: Supportive, But With a Clear Subtext

The Quantum Economic Development Consortium (QED-C), managed by SRI International, explicitly backed the bill. Celia Merzbacher, QED-C's executive director, referenced the consortium's *QuEnergy Resilience* report, describing PQC for grid monitoring and control communications as "one of the most feasible and highest-impact actions to secure grid operations" — language that carries weight because QED-C's membership spans hardware vendors, national labs, and utilities.

Michael Daniel, president and CEO of the Cyber Threat Alliance, offered the most candid technical framing: "Quantum computing may seem like science fiction, but it's only a matter of time before an operationally relevant quantum computer arrives. The cybersecurity impacts of quantum computing will be immense."

Paul Stimers, executive director of the Quantum Industry Coalition, offered straightforward support. The most pointed industry comment came from Patrick C. Miller, president and CEO of Ampyx Cyber: "The hardest part of getting ahead of it is not the cryptography itself but migrating the equipment already in the field." Miller specifically praised the bill's focus on "real-world adoption, not just research" — an implicit critique of prior federal quantum cybersecurity efforts that produced studies without implementation infrastructure.

That framing is accurate. The NIST PQC standards exist. The threat model is well understood. What has been missing is a mechanism to push utilities and their OT vendors through the expensive, operationally delicate process of field migration. Whether a FERC directive and a DOE sandbox are sufficient mechanisms is the legitimate policy question this bill raises.

---

## The Skeptical Read

**The bill does not set deadlines.** Directing FERC to "consider" quantum risks is meaningfully different from requiring FERC to issue a reliability standard with a compliance timeline. Utilities could remain on pre-quantum cryptography indefinitely if FERC's rulemaking process is slow or if the commission determines other reliability priorities take precedence. The history of FERC cybersecurity standard development — CIP standards have been in development and revision for well over a decade — suggests this process moves slowly relative to the threat.

**The "harvest now, decrypt later" window is already open.** Nation-state adversaries with sufficient resources are presumed to be collecting encrypted grid-related communications today, with the intent to decrypt them once cryptographically relevant quantum computers are available. The Quantum-GUARD Act addresses future quantum decryption capability, but the data collection phase is not addressed by any provision in this legislation.

**OT vendor readiness is the binding constraint.** The DOE CESER sandbox is only useful if the vendors who supply SCADA systems, protection relays, and energy management systems actively participate and ship PQC-compatible firmware updates. The bill does not appear to include procurement requirements or vendor certification mandates that would create that incentive.

**No funding figures appear in the source material.** The bill's text as reported does not specify appropriations. A testing environment without dedicated funding is an aspiration, not an infrastructure commitment.

---

## Why This Bill's Timing Is Significant

Senator Rounds explicitly noted the bill would "codify parts of President Trump's executive order regarding advanced cryptographic attacks" — meaning the Quantum-GUARD Act has a plausible path to executive branch support that bipartisan quantum legislation has not always enjoyed. That alignment matters for both the bill's legislative prospects and for how FERC and DOE would interpret their mandates if it passes.

The broader industry trajectory is clear: [post-quantum cryptography](https://quantumintel.tech/glossary/fault-tolerant-quantum-computing) migration is no longer a theoretical future concern for critical infrastructure sectors. NIST's 2024 standard finalization set the technical baseline. The policy and procurement apparatus is now catching up. The Quantum-GUARD Act is one node in a larger federal effort that also includes CISA guidance, NSA advisory timelines for national security systems, and OMB mandates for civilian agencies.

For grid operators and their OT vendors, the signal from this legislation is directional even before it passes: FERC engagement on quantum risk is coming, and the utilities that begin cryptographic inventory and migration planning now will face a less disruptive compliance transition than those who wait for enforceable standards.

---

## Key Takeaways

- **Senators Chris Coons (D-Del.) and Mike Rounds (R-S.D.)** introduced the Quantum-GUARD Act on August 18, 2026.
- The bill has **three core mechanisms**: a FERC quantum risk mandate, a DOE CESER PQC testing sandbox, and a bulk electric system vulnerability study.
- **NIST finalized PQC standards in 2024**; the legislative gap has been adoption infrastructure, not cryptographic standards.
- Industry support is broad — QED-C, Cyber Threat Alliance, Quantum Industry Coalition, and Ampyx Cyber all endorsed the bill.
- **Critical gaps**: no compliance deadlines, no funding figures disclosed in source material, no OT vendor mandates.
- The bill aligns with existing executive branch direction, improving its legislative prospects.
- The hardest migration challenge is **OT systems with long field lifespans**, not enterprise IT.

---

## Frequently Asked Questions

**What is the Quantum-GUARD Act?**
The Quantum Grid Utility Assurance and Resilient Defense Act of 2026 is a bipartisan U.S. Senate bill introduced by Senators Chris Coons and Mike Rounds. It directs FERC to consider quantum cybersecurity risks in grid reliability rulemaking, establishes a DOE testing environment for post-quantum cryptography adoption, and requires a federal study of quantum vulnerabilities in the bulk electric power system.

**Why does quantum computing threaten the electric grid?**
Most grid control systems and communications infrastructure rely on public-key cryptography that a sufficiently powerful quantum computer could break using algorithms such as Shor's. Operational technology systems — SCADA, protection relays, energy management platforms — are particularly exposed because they often run on hardware that cannot be easily patched and may remain in the field for decades.

**What are NIST's post-quantum cryptography standards?**
NIST finalized a set of post-quantum cryptography standards in 2024. These algorithms are designed to be resistant to attacks from both classical and quantum computers. The standards provide the cryptographic baseline for PQC migration, but finalization does not automatically translate to deployment across critical infrastructure.

**What is DOE CESER?**
DOE CESER is the Department of Energy's Office of Cybersecurity, Energy Security, and Emergency Response. Under the Quantum-GUARD Act, CESER would establish a collaborative testing environment to help utilities and vendors identify and resolve practical challenges in adopting post-quantum cryptography for grid systems.

**Does the Quantum-GUARD Act require utilities to adopt PQC by a specific date?**
Based on the bill's provisions as reported, no. The legislation directs FERC to consider quantum risks within its existing authority and establishes a DOE testing infrastructure, but does not set mandatory PQC deployment deadlines for utilities. Enforceable timelines would require subsequent FERC rulemaking.