[Congressional Bills 119th Congress]
[From the U.S. Government Publishing Office]
[S. 5313 Introduced in Senate (IS)]
<DOC>
119th CONGRESS
2d Session
S. 5313
To require the Federal Energy Regulatory Commission to consider
cybersecurity risks from quantum computers, and for other purposes.
_______________________________________________________________________
IN THE SENATE OF THE UNITED STATES
August 6, 2026
Mr. Coons (for himself and Mr. Rounds) introduced the following bill;
which was read twice and referred to the Committee on Energy and
Natural Resources
_______________________________________________________________________
A BILL
To require the Federal Energy Regulatory Commission to consider
cybersecurity risks from quantum computers, and for other purposes.
Be it enacted by the Senate and House of Representatives of the
United States of America in Congress assembled,
SECTION 1. SHORT TITLE.
This Act may be cited as the ``Quantum Grid Utility Assurance and
Resilient Defense Act of 2026'' or the ``Quantum-GUARD Act of 2026''.
SEC. 2. DEFINITIONS.
In this Act:
(1) Bulk-power system.--The term ``bulk-power system'' has
the meaning given the term in section 215(a) of the Federal
Power Act (16 U.S.C. 824o(a)).
(2) Commission.--The term ``Commission'' means the Federal
Energy Regulatory Commission.
(3) Electric reliability organization.--The term ``Electric
Reliability Organization'' has the meaning given the term in
section 215(a) of the Federal Power Act (16 U.S.C. 824o(a)).
(4) High-value.--The term ``high-value'', with respect to
an IT or OT system, means that the system is so critical to an
organization that the loss or corruption of information within
the system or loss of access to the system would have serious
impacts on the ability of the organization to perform its
mission or conduct business.
(5) Information technology; it.--
(A) In general.--The term ``information
technology'' or ``IT'' means any equipment or
interconnected system or subsystem of equipment used in
the automatic acquisition, storage, analysis,
evaluation, manipulation, management, movement,
control, display, switching, interchange, transmission,
or reception of data or information.
(B) Inclusions.--The term ``information
technology'' or ``IT'' includes, at a minimum,
computers, ancillary equipment (including imaging
peripherals, input, output, and storage devices
necessary for security and surveillance), peripheral
equipment designed to be controlled by the central
processing unit of a computer, software, firmware and
similar procedures, services (including support
services), and related resources.
(6) Operational technology; ot.--
(A) In general.--The term ``operational
technology'' or ``OT'' means any programmable system or
device that--
(i) interacts with the physical environment
(or manages devices that interact with the
physical environment); and
(ii) detects or causes a direct change
through the monitoring or control of devices,
processes, or events.
(B) Inclusions.--The term ``operational
technology'' or ``OT'' includes, at a minimum,
industrial control systems, building management
systems, fire control systems, and physical access
control mechanisms.
(7) Post-quantum cryptography; pqc.--The term ``post-
quantum cryptography'' or ``PQC'' means cryptographic
algorithms or methods that are assessed not to be specifically
vulnerable to attack by any of--
(A) a quantum computer (as defined in section 3 of
the Quantum Computing Cybersecurity Preparedness Act (6
U.S.C. 1526 note; Public Law 117-260)); or
(B) a classical computer (as defined in that
section).
(8) PQC sandbox.--The term ``PQC sandbox'' means a program
for innovation and development with respect to the use of post-
quantum cryptography in IT and OT applications for the electric
grid that--
(A) assembles relevant stakeholders, which may
include operators of the bulk-power system, IT and OT
vendors, relevant Federal agencies, relevant State and
local organizations, and distribution utilities (as
defined in section 217(a) of the Federal Power Act (16
U.S.C. 824q(a)));
(B) addresses challenges in PQC cybersecurity
development and adoption;
(C) prioritizes activities that support, encourage,
or enable PQC integration into--
(i) existing systems; and
(ii) during the 5-year period beginning on
the date of enactment of this Act, systems that
are expected to be deployed within that 5-year
period;
(D) may include briefings, workshops, software
challenges, hardware modeling, grid simulations, or
red-teaming exercises; and
(E) may be used to develop and test demonstrations,
proofs of concept, interoperability between IT and OT
systems, and pilot applications.
(9) Reliability standard.--The term ``reliability
standard'' has the meaning given the term in section 215(a) of
the Federal Power Act (16 U.S.C. 824o(a)).
(10) Secretary.--The term ``Secretary'' means the Secretary
of Energy, acting through the Office of Cybersecurity, Energy
Security, and Emergency Response.
SEC. 3. FERC CONSIDERATION OF CYBERSECURITY RISKS FROM QUANTUM
COMPUTERS.
Beginning on the date of enactment of this Act, in reviewing a
proposed reliability standard, or a proposed modification to a
reliability standard, under section 215 of the Federal Power Act (16
U.S.C. 824o) or issuing an order under subsection (d)(5) of that
section, the Commission shall--
(1) consider--
(A) cybersecurity risks from quantum computers; and
(B) potential uses of post-quantum cryptography in
IT and OT systems to protect against those risks; and
(2) take such action the Commission determines to be
appropriate based on that consideration.
SEC. 4. DOE PQC SANDBOX.
(a) In General.--Not later than 1 year after the date of enactment
of this Act, the Secretary shall establish a PQC sandbox.
(b) Collaboration.--In establishing and maintaining the PQC sandbox
under subsection (a), the Secretary may collaborate, as appropriate,
with appropriate officials at other Federal agencies.
(c) Outreach.--Not later than 3 years after the date of enactment
of this Act, the Secretary shall publish a report describing the
outcomes of, and recommendations arising from, PQC sandbox activities,
to encourage PQC adoption by operators of the bulk-power system.
SEC. 5. PQC REPORT.
(a) Study.--The Secretary, in consultation with the Electric
Reliability Organization and other appropriate organizations, shall
conduct a study of cybersecurity risks to the bulk-power system from
quantum computers, including, at minimum--
(1) risks to IT and OT systems; and
(2) obstacles to transitioning high-value IT and OT systems
to PQC.
(b) Requirements.--In conducting the study under subsection (a),
the Secretary shall--
(1) develop recommendations for actions that the Commission
could take to ensure reliable operations of the bulk-power
system; and
(2) to the extent practicable, correlate the high-value IT
and OT systems considered in the study with appropriate
categories based on reliability standards, such as impact
categories relating to the Bulk Electric System (as defined by
the Electric Reliability Organization), so the results of the
study may be readily applied by the Electric Reliability
Organization.
(c) Report.--
(1) In general.--Not later than 1 year after the date of
enactment of this Act, the Secretary shall submit to the
Committee on Energy and Natural Resources of the Senate and the
Committee on Energy and Commerce of the House of
Representatives a report on the study required under subsection
(a).
(2) Form.--The report required under paragraph (1) shall be
in unclassified form, but may include a classified annex.
(3) Public availability.--The Secretary shall make
available to the public the unclassified portion of the report
required under paragraph (1).
<all>