U.S. President Joe Biden signed the Quantum Computing Cybersecurity Preparedness Act into law last month to address the migration of federal agency systems to post-quantum cryptography (PQC) that can better resist attacks from quantum computers.

The legislation required the Office of Management and Budget (OMB) to prioritize the post-quantum cryptography migration within a year after the National Institutes of Standards and Technology (NIST) issues post-quantum cryptography standards, which are expected to publish by 2024. It also asked OMB to submit a strategy to address the security risk posed by the vulnerabilities of agency information technology systems to the potential capability of a quantum computer and report ongoing coordination efforts with international standards development organizations for PQC standards.

The act mentioned that Congress finds cryptography essential for national security and the functioning of the economy and notes the potential risks posed by “harvest now, decrypt later” attacks.

“Quantum computers might one day have the ability to push computational boundaries, allowing us to solve problems that have been intractable thus far, such as integer factorization, which is important for encryption,” the act states.

This legislative move follows a White House memo issued last November to promote U.S. leadership in quantum computing and mitigate risks to vulnerable cryptographic systems. The memo asked federal agencies to submit cryptographic system inventory by May 4, 2023, and for each following year to designate cryptographic inventory and migration lead, and report testing of pre-standardized PQC.

Private Sector Should Also Start the Quantum Security Preparedness

Quantum computing and security vendors are staunchly behind the Quantum Computing Cybersecurity Preparedness Act.

“It's important that the U.S. move as quickly as possible to act against the coming quantum threat since it takes significant effort to upgrade existing systems,” QuSecure co-Founder and COO Skip Sanzeri said in a statement. “Meanwhile, quantum computers are under development globally with some adversarial nation-states putting tens of billions of dollars into programs to create these very powerful machines that will break the encryption we use today.”

“While not here yet, quantum computers will be online in coming years, but it will take more than a few years for our federal agencies and commercial enterprises to upgrade their systems to post-quantum cybersecurity,” Sanzeri added.

The legislation also signals the need for the private sector to prepare for security threats in the quantum computing era, Quantinuum Chief Legal Officer and Chief Compliance Officer Kaniah Konkoly-Thege noted.

“The Quantum Cybersecurity Preparedness Act signals that the U.S. government views post-quantum cryptography as a critical national security threat. This threat is not limited to the federal government. The private sector is also impacted as bad actors look to steal customer data and IP now to decrypt when fault-tolerant quantum computers arrive, also known as 'hack now, decrypt later.' The private sector should take its cue from the direction of the federal government and begin preparing for this massive new cybersecurity challenge,” Konkoly-Thege wrote.