QuorumCivic. Hidden in plain sight Get the app
Bill intelligence

Congress funds quantum-proof encryption upgrade for critical infrastructure

H.R. 3259 — Post Quantum Cybersecurity Standards Act · Filed by Haley Stevens (D-MI) · 3 cosponsors · Introduced May 7, 2025 · Reported out

72%
Transparency
Typical bill: 82%
15/100
Hidden-provision risk
Typical bill: 15/100
Cybersecurity Infrastructure Upgrade

Your members of Congress

Enter a ZIP to see where your representative and both senators stood on this bill.

Looked up on this device — your ZIP is never stored on our servers.

What it does

This bill amends two existing laws to accelerate adoption of post-quantum cryptography—encryption methods designed to resist attacks from quantum computers—across U.S. critical infrastructure and digital systems. It directs NIST to issue post-quantum cryptography standards and provide technical guidance to organizations, establishes a voluntary grant program to help high-risk entities (especially critical infrastructure) pay for upgrading their systems, and expands NSF funding for cryptography research. The bill does not mandate adoption; it funds and facilitates voluntary transition.

Why we flagged it

The bill's core function is to fund and facilitate voluntary adoption of post-quantum cryptography standards across critical infrastructure. It is a public-investment measure in national cybersecurity resilience, not a deregulation, tax carve-out, or private subsidy.

What the text implies

  • Grant program eligibility and award amounts are left to NIST discretion ('specified amount established by the Director'), creating potential for uneven distribution of federal funds across sectors and regions depending on how NIST interprets 'high risk' and 'critical infrastructure.'
  • The bill does not establish a timeline for NIST to issue post-quantum cryptography standards, meaning the grant program cannot launch until standards are published—implementation delay risk exists if NIST prioritization shifts.

The full analysis lists 4 implications of this text.

Who stands to gain

cybersecurity software and hardware vendors (cryptography implementation tools); critical infrastructure operators (utilities, telecommunications, financial services); digital infrastructure providers

Correlative observation from public records — not evidence of coordination or wrongdoing, and not financial advice.
This page is the record as of today. The app tells you when it changes.
Quorum analysis of the full bill text · 119th Congress · public record