Federal agencies must upgrade to quantum-proof encryption by 2027
S. 2558 — The National Quantum Cybersecurity Migration Strategy Act of 2025. · Filed by Gary Peters (D-MI) · 1 cosponsor · Introduced Jul 30, 2025 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill directs federal agencies to develop and execute a strategy for migrating their computer systems from current encryption methods to quantum-resistant encryption before quantum computers become powerful enough to break existing security. It requires the creation of standards, a pilot program upgrading at least one critical system per agency by 2027, cost assessments, and annual progress reports to Congress.
Why we flagged it
The bill's core function is mandating federal agencies upgrade encryption systems to defend against future quantum computing threats. It is a public-sector cybersecurity and infrastructure modernization measure, not a private-sector subsidy or deregulation.
What the text implies
- The bill does not mandate private-sector adoption of post-quantum cryptography, only federal systems and critical infrastructure providers—leaving non-critical private companies potentially vulnerable to quantum attacks for years longer.
- Cost estimates are not yet known; the bill requires a survey and report, meaning Congress will not know the full fiscal impact before passage. Implementation could require billions in IT spending across agencies.
The full analysis lists 4 implications of this text.
Who stands to gain
cybersecurity software vendors; IT infrastructure companies; quantum-resistant cryptography developers