Congress quietly empowers private consortium to set federal cybersecurity standards
S. 3312 — Quantum Readiness and Innovation Act of 2025 · Filed by Gary Peters (D-MI) · 1 cosponsor · Introduced Dec 2, 2025 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill directs the National Institute of Standards and Technology (NIST) and the Office of Science and Technology Policy to develop guidance and a national strategy for upgrading federal and critical infrastructure computer systems to use post-quantum cryptography—encryption methods designed to resist attacks from future quantum computers. The bill establishes a voluntary pilot program to help federal agencies and critical infrastructure operators test and deploy these new cryptographic systems, with NIST providing technical support and test beds. The primary beneficiaries are federal agencies, critical infrastructure operators, and the technology vendors supplying post-quantum cryptographic solutions.
Why we flagged it
The bill establishes federal guidance and pilot programs for upgrading critical infrastructure and federal systems to post-quantum cryptography standards. It is primarily a technical modernization and cybersecurity readiness measure, not a commemorative or appropriations vehicle.
What the text implies
- The bill's reliance on NIST standards and the Quantum Economic Development Consortium creates a de facto private-sector standard-setting role, potentially favoring consortium members in procurement decisions without explicit competitive bidding language.
- Federal agencies upgrading systems under the pilot program may face vendor lock-in if early post-quantum cryptography solutions are proprietary, as the bill does not mandate open-source or interoperable alternatives.
The full analysis lists 4 implications of this text.
Who stands to gain
quantum computing hardware manufacturers; cryptography software vendors; cybersecurity consulting firms