S-5313-119
Read twice and referred to the Committee on Energy and Natural Resources.
Sponsored by Christopher Coons (D-DE)
What it does
This bill would require the Federal Energy Regulatory Commission to consider quantum computing cybersecurity risks and post-quantum cryptography when reviewing electric grid reliability standards. It would also direct the Department of Energy to create a testing program ("sandbox") for post-quantum cryptography and to produce a study and report on quantum-related risks to the bulk power system within one year.
Who benefits
Electric utilities and grid operators who would gain federal guidance and a testing environment for adopting post-quantum cryptography; IT/OT vendors serving the power sector who could participate in the DOE sandbox; and electricity consumers nationwide who would indirectly benefit from a more cyber-resilient grid.
Who is hurt
Utilities and vendors may face future compliance costs if FERC or the Electric Reliability Organization later adopts new reliability standards based on this study, though the bill itself imposes no mandates. Smaller distribution utilities and vendors with fewer resources may find participation in or compliance with eventual PQC requirements more burdensome than larger operators.
Supporters argue
Supporters argue that quantum computers could eventually break current encryption protecting the electric grid's control systems, and that waiting until the technology matures would leave critical infrastructure exposed. They contend this bill takes a measured, low-cost first step—study, sandbox testing, and mandatory consideration by FERC—rather than imposing costly mandates before the technology and risks are fully understood.
Opponents argue
Opponents argue the bill adds another layer of federal study and process without guaranteeing meaningful protection, since FERC is only required to "consider" the risks and take action it deems "appropriate," which could result in no binding standards at all. They contend the one-year study and three-year sandbox report timelines may lag behind fast-moving quantum computing advances, making the requirements more symbolic than protective.
Constitutional context
Congress's authority to regulate the interstate electric grid rests on the Commerce Clause (Art. I, §8, cl. 3), the same basis underlying FERC's existing jurisdiction over bulk-power system reliability under the Federal Power Act. Because the bill directs FERC only to "consider" risks and take action it deems appropriate—rather than imposing a specific mandate—it is unlikely to raise the kind of major questions doctrine concerns at issue in West Virginia v. EPA (2022).
Checks and balances
Congress directs FERC and the Department of Energy (executive branch agencies) to study and consider a new risk category, but leaves the scope of any resulting action to agency discretion, with judicial review available under the Federal Power Act if FERC later issues binding rules.
Historical precedent
This builds on the Quantum Computing Cybersecurity Preparedness Act of 2022, which required federal agencies generally to plan for migration to post-quantum cryptography.