Search

Search bills, members, committees and pages...

S. 2558

U.S. SenateIn Senate Committee

Summary

S. 2558, the The National Quantum Cybersecurity Migration Strategy Act of 2025, was introduced in the Senate on Jul 30, 2025 by Sen. Gary Peters (D) with 1 co-sponsor. It was referred to Homeland Security And Governmental Affairs, and last saw action on Jul 30, 2025: Read twice and referred to the Committee on Homeland Security and Governmental Affairs.


Record

Text

S. 2558 has 1 co-sponsor.

sb2558/introduced-in-senate.txt
119 S2558 IS: The National Quantum Cybersecurity Migration Strategy Act of 2025.
U.S. Senate
2025-07-30
text/xml
EN
Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.
II
119th CONGRESS
1st Session
S. 2558
IN THE SENATE OF THE UNITED STATES
July 30, 2025
Mr. Peters (for himself and Mrs. Blackburn ) introduced the following bill; which
was read twice and referred to the Committee
on Homeland Security and Governmental Affairs
A BILL
To require the Subcommittee on the Economic and Security Implications of
Quantum Information Science to assess possible migration by Federal agencies to
post-quantum cryptography, and for other purposes.
1.
Short title
This Act may be cited as the The National Quantum Cybersecurity Migration Strategy Act of 2025. .
2.
Definitions
In this Act:
(1)
Cryptography
The term cryptography has the meaning given such term in the National Institute of Standards and Technology Special Publication 1800–21B (relating to mobile device security) and the National Institute of Standards and Technology Special Publication 800–59 (relating to guidelines for identifying an information system as a national security system).
(2)
Classical computer
The term classical computer means a device that accepts digital data and manipulates the data based on a program or sequence of instructions for how such data is to be processed, and that encodes information in binary.
(3)
Quantum computer
The term quantum computer means a computer that uses the collective properties of quantum states, such as superposition, interference, and entanglement, to perform calculations.
(4)
Post-Quantum Cryptography
The term post-quantum cryptography means cryptographic algorithms or methods that are not specifically vulnerable to attacks by either a quantum computer or classical computer.
(5)
Critical Infrastructure
The term critical infrastructure has the meaning given that term in section 1016(e) of the Critical Infrastructures Protection Act of 2001 ( 42 U.S.C. 5195c(e) ).
(6)
High-impact system
The term high-impact system means a Federal information system that holds sensitive information, the loss of which would be categorized as high impact under Federal Information Processing Standards Publication 199 (relating to standards for security categorization of Federal information and information systems), as in effect on the day before the date of the enactment of this Act.
(7)
Sector risk management agency
The term sector risk management agency has the meaning given the term in section 2200 of the Homeland Security Act of 2002 ( 6 U.S.C. 650 ).
3.
Strategy for Federal agency migration to
post-quantum cryptography
(a)
Duties of Subcommittee on the Economic and Security Implications of Quantum
Information Science
Not later than 180 days after the date of the enactment of this Act, the Subcommittee on the Economic and Security Implications of Quantum Information Science, as established by section 105 of the National Quantum Initiative Act ( 15 U.S.C. 8814a ), in coordination with the Director of the National Institute of Standards and Technology and in consultation with the Quantum Economic Development Consortium, shall develop a National Quantum Cybersecurity Migration Strategy that includes the following:
(1)
A definition of a cryptographically relevant quantum computer.
(2)
Recommended standards for Federal agencies to apply to determine whether a quantum computer meets such definition, including—
(A)
the characteristics of such computers; and
(B)
the particular point at which such computers are capable of attacking real world cryptographic systems that classical computers are unable to attack.
(3)
An assessment of the urgency for migration to post-quantum cryptography for each Federal agency relative to—
(A)
the critical functions of each agency; and
(B)
the risk each agency faces should a cryptographically relevant quantum computer attack a system operated by the agency.
(4)
Performance measures for migration to post-quantum cryptography to be used by each Federal agency for each of the following 4 stages of migration:
(A)
Preparation for migration to post-quantum cryptography.
(B)
Establishment of a baseline understanding of the data inventory.
(C)
Planning and execution of post-quantum cryptographic solutions, including ensuring that data at rest and in motion is subject to appropriate protections.
(D)
Monitoring and evaluation of migration success and assessment of cryptographic security.
(5)
A plan for evaluating and monitoring entities that are at high risk of quantum cryptographic attacks, including entities determined to be providers of critical infrastructure.
(b)
Post-Quantum pilot program
Not later than 180 days after the date of the enactment of this Act, the Subcommittee on the Economic and Security Implications of Quantum Information Science shall establish a post-quantum pilot program that requires each sector risk management agency to upgrade not less than one high-impact system to post-quantum cryptography not later than January 1, 2027.
(c)
Duties of the Office of Electronic Government
Not later than 180 days after the date of the enactment of this Act, the Administrator of the Office of Electronic Government, in coordination with the Subcommittee on the Economic and Security Implications of Quantum Information Science, shall—
(1)
survey the heads of Federal agencies for information relating to the cost of migration to post-quantum cryptography by the Federal agencies, including estimates for the personnel, equipment, and time needed to fully implement post-quantum cryptography, in alignment with the National Quantum Cybersecurity Migration Strategy developed pursuant to subsection (a);
(2)
verify that the information provided under paragraph (1) is realistic and fiscally sound;
(3)
identify the funding and resources necessary for Federal agencies to carry out the migration to post-quantum cryptography; and
(4)
advise on how Federal agencies should encourage the adoption of post-quantum cryptography by the private sector.
(d)
Report to Congress
Not later than 1 year after the date of the enactment of this Act, the Director of the Office of Management and Budget and the Subcommittee on the Economic and Security Implications of Quantum Information Science shall jointly submit to Congress a report detailing their findings with respect to the post-quantum migration assessments required under subsection (a)(3), the pilot program established pursuant to subsection (b), and the survey on associated costs of executing the migration required by subsection (c)(1).
(e)
Assessment by Comptroller General
Not later than 1 year after the development of the National Quantum Cybersecurity Migration Strategy under subsection (a), and annually thereafter, the Comptroller General of the United States shall submit to Congress an assessment, using the performance measures described in subsection (a)(4), of the progress made by each Federal agency in migrating to post-quantum cryptography.

Tracker

The tracker indicates the progress of this legislation as it moves through the legislative process.

  1. Introduced2025-07-30
  2. Passed Senate
  3. Passed House
  4. Conference
  5. To President
  6. Became Law

A bill to require the Subcommittee on the Economic and Security Implications of Quantum Information Science to assess possible migration by Federal agencies to post-quantum cryptography, and for other purposes.

Sponsors

Sen. Gary Peters (D) sponsors S. 2558, and 1 member has co-sponsored it from the day it was introduced.

Committees

S. 2558 went before 1 committee: Homeland Security and Governmental Affairs.

Homeland Security and Governmental Affairs
Homeland Security and Governmental Affairs
Referred To · Jul 30, 2025 · 444 Bills

Actions

S. 2558 has taken 2 actions since Jul 30, 2025.

ChamberAction
Jul 30, 2025
Senate
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.Homeland Security and Governmental Affairs Committee
Jul 30, 2025
Introduced in Senate

Votes

S. 2558 has not gone to a roll call.

Titles

S. 2558 goes by 3 titles, 1 of them short titles.

  • The National Quantum Cybersecurity Migration Strategy Act of 2025. — Display Title
  • The National Quantum Cybersecurity Migration Strategy Act of 2025. — Short Title(s) as Introduced
  • A bill to require the Subcommittee on the Economic and Security Implications of Quantum Information Science to assess possible migration by Federal agencies to post-quantum cryptography, and for other purposes. — Official Title as Introduced

Lobbying

3 clients hired 3 firms and 15 registered lobbyists who named S. 2558 in 8 quarterly filings, 2025 to 2026. Reported under the Lobbying Disclosure Act; a filing’s income covers everything its registrant worked that quarter, so the amounts below are the filings’, not this bill’s.

Filed under Defense, Computer Industry, Copyright/Patent/Trademark, Education, Intelligence, Law Enforcement/Crime/Criminal Justice, Trade (domestic/foreign), Homeland Security.

Clients

Who paid to be heard, by how many filings named the bill.

ClientBusinessStateFirmsFilingsReported
BUSINESS SOFTWARE ALLIANCEDistrict of Columbia14
BSA THE SOFTWARE ALLIANCE (FORMERLY BSA BUSINESS SOFTWARE ALLIANCE INC)Technology AssociationDistrict of Columbia13$90K
SB TECHNOLOGY, INC. D/B/A SANDBOXAQComputer software companyCalifornia11$60K

Firms

Registrants who filed on the bill, by filings.

RegistrantClientsFilingsReported
BUSINESS SOFTWARE ALLIANCE14
CGCN GROUP, LLC13$90K
MICHAEL BEST STRATEGIES LLC11$60K

Lobbyists

Named on the filings that cite the bill.

Filings

The documents themselves, on the Senate’s Lobbying Disclosure site, largest reported first.

ClientRegistrantPeriodReportedDocument
BUSINESS SOFTWARE ALLIANCEBUSINESS SOFTWARE ALLIANCE2025 fourth_quarter$530K4th Quarter - Report
BUSINESS SOFTWARE ALLIANCEBUSINESS SOFTWARE ALLIANCE2025 third_quarter$490K3rd Quarter - Report
BUSINESS SOFTWARE ALLIANCEBUSINESS SOFTWARE ALLIANCE2026 first_quarter$470K1st Quarter - Report
BUSINESS SOFTWARE ALLIANCEBUSINESS SOFTWARE ALLIANCE2026 second_quarter$320K2nd Quarter - Report
SB TECHNOLOGY, INC. D/B/A SANDBOXAQMICHAEL BEST STRATEGIES LLC2025 third_quarter$60K3rd Quarter - Report
BSA THE SOFTWARE ALLIANCE (FORMERLY BSA BUSINESS SOFTWARE ALLIANCE INC)CGCN GROUP, LLC2026 first_quarter$30K1st Quarter - Termina…
BSA THE SOFTWARE ALLIANCE (FORMERLY BSA BUSINESS SOFTWARE ALLIANCE INC)CGCN GROUP, LLC2025 fourth_quarter$30K4th Quarter - Report
BSA THE SOFTWARE ALLIANCE (FORMERLY BSA BUSINESS SOFTWARE ALLIANCE INC)CGCN GROUP, LLC2025 third_quarter$30K3rd Quarter - Report

Classification

The Congressional Research Service files S. 2558 under Science, Technology, Communications, one of its 31 policy areas.

CRS Subjects

CRS assigns every bill one policy area from its 31; S. 2558’s is Science, Technology, Communications.

s2558/policy-areas.txt
Science, Technology, CommunicationsAgriculture and FoodAnimalsArmed Forces and National SecurityArts, Culture, ReligionCivil Rights and Liberties, Minority IssuesCommerceCongressCrime and Law EnforcementEconomics and Public FinanceEducationEmergency ManagementEnergyEnvironmental ProtectionFamiliesFinance and Financial SectorForeign Trade and International FinanceGovernment Operations and PoliticsHealthHousing and Community DevelopmentImmigrationInternational AffairsLabor and EmploymentLawNative AmericansPublic Lands and Natural ResourcesSocial WelfareSports and RecreationTaxationTransportation and Public WorksWater Resources Development

Source: congress.gov · legiscan.com