S. 5313: Quantum Grid Utility Assurance and Resilient Defense Act of 2026
This bill would direct federal energy regulators and the Department of Energy to address a new cybersecurity issue for the electric grid: the possibility that future quantum computers could break some of today’s encryption and create risks for critical grid systems.
What it changes for federal regulators
When the Federal Energy Regulatory Commission (FERC) reviews or updates electric reliability standards, it would have to specifically consider:
- cybersecurity risks from quantum computers, and
- whether post-quantum cryptography, or PQC, should be used in information technology and operational technology systems to reduce those risks.
FERC could then take whatever action it determines is appropriate based on that review.
What it requires the Department of Energy to do
The bill would require the Secretary of Energy, through the Office of Cybersecurity, Energy Security, and Emergency Response, to set up a PQC sandbox within 1 year. This sandbox would be a test and development program focused on using post-quantum cryptography in electric grid systems.
The sandbox could include:
- briefings and workshops,
- software challenges,
- hardware modeling,
- grid simulations,
- red-team exercises,
- pilot projects, demonstrations, and proof-of-concept testing.
It would bring together stakeholders such as grid operators, vendors, federal agencies, state and local organizations, and distribution utilities. The goal would be to help test and encourage PQC use in both existing systems and systems expected to be deployed within the next 5 years.
What study and report would be required
The bill would also require the Department of Energy, in consultation with the Electric Reliability Organization and other relevant groups, to study quantum-related cybersecurity risks to the bulk-power system. That study would examine:
- risks to IT and OT systems, and
- barriers to moving high-value IT and OT systems to PQC.
The study would also have to make recommendations on actions FERC could take to help keep the bulk-power system reliable. To the extent practical, the study would connect the systems it looks at with reliability categories used by the Electric Reliability Organization, so the results can be applied more easily.
Within 1 year, the Secretary of Energy would have to send Congress a report on the study. The report would be unclassified, though it could include a classified annex. The unclassified portion would have to be made public.
Who it affects
The bill is aimed mainly at federal agencies, electric grid operators, and companies that provide cybersecurity, software, hardware, and related services for power systems. It does not directly impose a broad new requirement on all businesses or consumers, but it could lead to new reliability or cybersecurity expectations for electric utilities and their vendors over time.
Relevant Companies
- NEE — A major electric utility that could be affected if new grid cybersecurity standards or upgrade practices are adopted by regulators.
- DUK — Utility operations could be impacted by any reliability or cybersecurity standards tied to bulk-power systems.
- D — As a large power utility, it could need to adjust systems or compliance practices if FERC standards evolve.
- EXC — Could be affected through electric grid cybersecurity and reliability requirements affecting utilities and grid operators.
- SO — Could face indirect impacts if new post-quantum cybersecurity expectations are applied to utility IT and OT systems.
- CEG — As an operator in the power sector, it could be affected by changes in reliability and cybersecurity compliance expectations.
- IBM — A provider of enterprise IT and cybersecurity products that could see demand related to post-quantum cryptography planning and implementation.
- ACN — A consulting and technology services firm that could be involved in advising utilities on PQC migration and grid cybersecurity.
- CRWD — A cybersecurity company that could be affected if utilities increase spending on quantum-resistant security planning.
- PANW — Could see indirect demand effects from utility cybersecurity upgrades and post-quantum security initiatives.
This is an AI-generated summary of the bill text. There may be mistakes.
Sponsors
2 bill sponsors
Actions
2 actions
| Date | Action |
|---|---|
| Aug. 06, 2026 | Introduced in Senate |
| Aug. 06, 2026 | Read twice and referred to the Committee on Energy and Natural Resources. |
Corporate Lobbying
0 companies lobbying
None found.
* Note that there can be significant delays in lobbying disclosures, and our data may be incomplete.