HR 3259 Introduced Re-checks Congress.gov for new actions and updates the bill's status, and fills in any sponsors, committees, or related bills that are missing. It does not re-pull sponsors/cosponsors/committees/related — those rarely change — and it skips all work if nothing has changed upstream, so it's cheap to click.
Post Quantum Cybersecurity Standards Act
To amend the National Quantum Initiative Act and the Cyber Security Research and Development Act to advance the rapid deployment of post quantum cybersecurity standards across the United States economy, support United States cryptography research, and for other purposes.
Summary
This bill amends federal law to promote the adoption of post-quantum cryptography standards—encryption methods resistant to attacks by quantum computers. It directs the National Institute of Standards and Technology to disseminate guidance, provide technical assistance to high-risk entities, and potentially establish a grant program to help critical infrastructure and digital infrastructure providers adopt post-quantum cryptographic standards. The bill also adds post-quantum cryptography to the National Science Foundation's cybersecurity research programs.
AI-generated plain-language summary of the bill text — neutral, and may be imperfect. See the full text below for the exact wording.
Sponsor (1)
3 cosponsors
Actions (4)
- Jun 11, 2025 Ordered to be Reported by the Yeas and Nays: 35 - 0. · house
- Jun 11, 2025 Committee Consideration and Mark-up Session Held · house
- May 7, 2025 Referred to the House Committee on Science, Space, and Technology. · house
- May 7, 2025 Introduced in House
More bills on these subjects (8)
Other bills that carry the most legislative subjects in common with this one (topical discovery — distinct from the procedural related bills above).
Similar bills (6)
Bills with similar text or summary — includes reintroductions across Congresses. Ranked by semantic similarity of the bill text (computed locally); a neutral discovery aid, not a claim the bills are duplicates.
Text versions (1)
Bills are re-published as they move (Introduced → Reported → Engrossed → Enrolled …). Each stage below is a separate text; pick two to see what changed. Data from Congress.gov.
Full text
IN THE HOUSE OF REPRESENTATIVES
May 7, 2025
Ms. Stevens (for herself and Ms. Tenney) introduced the following bill; which was referred to the Committee on Science, Space, and Technology
A BILL
To amend the National Quantum Initiative Act and the Cyber Security Research and Development Act to advance the rapid deployment of post quantum cybersecurity standards across the United States economy, support United States cryptography research, and for other purposes.
Be it enacted by the Senate and House of Representatives of the United States of America in Congress assembled,
SECTION 1. SHORT TITLE.
This Act may be cited as the “Post Quantum Cybersecurity Standards Act”.
SEC. 2. NIST CRYPTOGRAPHY PROGRAMS AND NSF CRYPTOGRAPHY RESEARCH.
(a) National Institute of Standards and Technology Cryptography Programs.—The National Quantum Initiative Act is amended—
(1) in section 2 (15 U.S.C. 8801)—
(A) by redesignating paragraphs (4), (5), (6), (7), the first paragraph (8) (relating to the definition of “Subcommittee on Economic and Security Implications”), and the second paragraph (8) (relating to the definition of “Subcommittee on Quantum Information Science”) as paragraphs (5), (7), (8),
(9), (11), and (12), respectively;
(B) by inserting after paragraph (3) the following new paragraph:
“(4) Critical infrastructure.—The term ‘critical infrastructure’ has the meaning given such term in section 1016(e) of Public Law 107-56 (42 U.S.C. 5195c(e))”;
(C) by inserting after paragraph (5), as so redesignated, the following new paragraph:
“(6) Post-quantum cryptography.—The term ‘post-quantum cryptography’ means those cryptographic algorithms or methods that are assessed not to be specifically vulnerable to attack by either a quantum computer or classical computer.”; and
(D) by inserting after paragraph (9), as so redesignated, the following new paragraph:
“(10) Sector risk management agency.—The term ‘sector risk management agency’ has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C.
650).”; and
(2) in section 201 (15 U.S.C. 8831), by—
(A) redesignating subsection (c) as subsection (d); and
(B) inserting after subsection (b) the following new subsection:
“(c) Post Quantum Cryptography Deployment.—
“(1) In general.—The Director of the National Institute of Standards and Technology, in consultation with the Secretary of Homeland Security and the heads of sector risk management agencies, as appropriate, shall promote the voluntary adoption and deployment of post-quantum cryptography standards, including by—
“(A) disseminating and making publicly available guidance and resources to help organizations adopt and deploy post-quantum cryptography standards;
“(B) providing technical assistance, as practicable, to entities that are high risk of quantum cryptoanalytic attacks, such as entities determined to be critical infrastructure or digital infrastructure providers; and
“(C) conducting such other activities as determined necessary by the Director to promote the adoption and deployment of post-quantum cryptography standards across the United States.
“(2) Grant program.—
“(A) In general.—Subject to the availability of appropriations and after the date on which the Director of National Institute of Standards and Technology has issued post-quantum cryptography standards under paragraph (1), the Director may establish a program to identify and provide technical assistance through the award of grants to entities that are at high risk of quantum cryptoanalytic attacks, including by granting funds, in adopting such post-quantum cryptographic standards and remediating quantum-related vulnerabilities.
“(B) Use of funds.—Grants awarded to entities under this subsection may be used to cover reasonable costs, up to a specified amount established by the Director of the National Institute of Standards and Technology, of activities to adopt post-quantum cryptographic standards and remediate quantum-related vulnerabilities.
“(C) Guidance.—The Director of the National Institute of Standards and Technology may develop, and periodically update, guidance, including eligibility, application disclosure requirements, grant amount and duration, and any additional requirements regarding the award of grants under this paragraph.
“(D) Consultation.—If the program described in this paragraph is established, the Director of the National Institute of Standards and Technology shall consult with the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, the heads of other Sector Specific Agencies and risk management agencies, and appropriate representatives of private sector entities, including nonprofit organizations, to share information regarding the program and guidance developed under subparagraph
(C).”.
(b) National Science Foundation Cryptography Research.—Subsection
(a)(1)(A) of section 4 of the Cyber Security Research and Development Act (15 U.S.C. 7403) is amended by inserting “, including post-quantum cryptography” before the semicolon. <all>
Comments