Quantum Readiness and Innovation Act of 2025
Analysis under review: This bill has generated analysis that may be too generic or incomplete. Clause-level evidence remains available below.
Summary
What This Bill Does
The bill defines key terms used throughout the Quantum Readiness and Innovation Act, including post-quantum cryptography, critical infrastructure sectors, high-impact systems, and covered entities for the pilot program, mandates NIST to develop guidance within 180 days for upgrading information systems to post-quantum cryptography, including procurement standards for commercial solutions, and requires the Office of Science and Technology Policy to develop a National Quantum Cybersecurity Upgrade Strategy within 360 days, defining cryptographically relevant quantum computers and establishing guidelines. It relies on reporting requirements, definition changes, product standards, and compliance mandates. The main policy areas are Cybersecurity, Technology, Finance, and Trade.
Who Benefits and How
Post-quantum cryptography solution vendors could gain revenue opportunities, Post-quantum cryptography vendors and solution providers could gain revenue opportunities, and Federal IT modernization contractors could gain revenue opportunities.
Who Bears the Burden and How
Office of Science and Technology Policy would take on compliance duties, National Institute of Standards and Technology would take on compliance duties, and Federal agencies with high-impact information systems would take on compliance duties.
Key Provisions
- Defines key terms used throughout the Quantum Readiness and Innovation Act, including post-quantum cryptography, critical infrastructure sectors, high-impact systems, and covered entities for the pilot program.
- Mandates NIST to develop guidance within 180 days for upgrading information systems to post-quantum cryptography, including procurement standards for commercial solutions.
- Requires the Office of Science and Technology Policy to develop a National Quantum Cybersecurity Upgrade Strategy within 360 days, defining cryptographically relevant quantum computers and establishing guidelines...
Evidence Chain:
This summary is generated from the full bill text using AI analysis. Expand "Detailed Analysis" below for identified beneficiaries/burden bearers with clause-level evidence links.
At a Glance
What This Bill Does
The bill defines key terms used throughout the Quantum Readiness and Innovation Act, including post-quantum cryptography, critical infrastructure sectors, high-impact systems, and covered entities for the pilot program, mandates NIST to develop guidance within 180 days for upgrading information systems to post-quantum cryptography, including procurement standards for commercial solutions, and requires the Office of Science and Technology Policy to develop a National Quantum Cybersecurity Upgrade Strategy within 360 days, defining cryptographically relevant quantum computers and establishing guidelines.
Key Policy Areas
Cybersecurity, Technology, Finance, Trade
Primary Purpose
The bill defines key terms used throughout the Quantum Readiness and Innovation Act, including post-quantum cryptography, critical infrastructure sectors, high-impact systems, and covered entities for the pilot program, mandates NIST to develop guidance within 180 days for upgrading information systems to post-quantum cryptography, including procurement standards for commercial solutions, and requires the Office of Science and Technology Policy to develop a National Quantum Cybersecurity Upgrade Strategy within 360 days, defining cryptographically relevant quantum computers and establishing guidelines.
Policy Domains
Quantum Readiness and Innovation Act of 2025
Identified Gains
- Post-quantum cryptography solution vendors
- Post-quantum cryptography vendors and solution providers
- Federal IT modernization contractors
- Quantum-resistant hardware manufacturers
- Quantum Economic Development Consortium members
Identified Costs
- Office of Science and Technology Policy
- National Institute of Standards and Technology
- Federal agencies with high-impact information systems
- Sector risk management agencies
Sponsors
Legislative Progress
In CommitteeMr. Peters (for himself and Mrs. Blackburn) introduced the following …
Read twice and referred to the Committee on Commerce, Science, …
Introduced in Senate
Stakeholder Effects
cui bono?How this legislation distributes effects. Mention counts reflect frequency, not effect magnitude.
Post-quantum cryptography solution providers, Post-quantum cryptography solution vendors, Post-quantum cryptography vendors and solution providers
Federal agencies with high-impact information systems, National Institute of Standards and Technology, Office of Science and Technology Policy
Federal IT modernization contractors, IT systems integrators and federal contractors
Critical infrastructure operators (energy, finance, healthcare, etc.)
Bill Structure & Actor Mappings
Who is "The Secretary" in each section?
- "qedc"
- → Quantum Economic Development Consortium
- "the_director_nist"
- → Director of the National Institute of Standards and Technology
- "the_director_ostp"
- → Director of the Office of Science and Technology Policy
Key Definitions
Terms defined in this bill
The Committee on Commerce, Science, and Transportation of the Senate; and the Committee on Energy and Commerce of the House of Representatives.
Have the meanings given in section 3 of the Quantum Computing Cybersecurity Preparedness Act (Public Law 117-260).
Critical infrastructure sectors defined in the National Security Memorandum on Critical Infrastructure Security and Resilience (NSM-22), dated April 30, 2024.
A Federal information system that holds sensitive information, the loss of which would be categorized as high impact under Federal Information Processing Standards Publication 199.
Cryptographic algorithms or methods assessed not to be specifically vulnerable to attack by either a quantum computer or classical computer, including NIST FIPS 203, 204, and 140-3 compliant methods operating within zero trust architecture.
Has the meaning given in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).
A sector risk management agency; a Federal agency; or a mission partner of a Federal agency.
We use a combination of our own taxonomy and classification in addition to large language models to assess meaning and potential beneficiaries. High confidence means strong textual evidence. Always verify with the original bill text.
Learn more about our methodology