H.R. 3259: Post Quantum Cybersecurity Standards Act
Sponsor
Haley Stevens
Democrat · MI-11
NIST gets post-quantum cybersecurity push
Why it matters
Introduced on 2025-05-07, H.R. 3259 pushes the federal government to help critical systems start switching to encryption that can survive future quantum-computer attacks before those attacks become practical.
H.R. 3259, the Post Quantum Cybersecurity Standards Act, is a targeted federal preparation bill rather than a broad new mandate. It does not order private companies to rip out current encryption on a deadline, and it does not set fines or criminal penalties. Instead, it amends existing federal law to give the National Institute of Standards and Technology, or NIST, a clearer job: promote the voluntary adoption and deployment of post-quantum cryptography standards, working with the Department of Homeland Security and sector risk management agencies.
The bill is specific about who needs the most help. NIST must provide guidance and public resources for adoption, and it must provide technical assistance to entities at high risk of quantum cryptoanalytic attacks, specifically including critical infrastructure and digital infrastructure providers. It also writes key definitions into law. “Critical infrastructure” uses the meaning in section 1016(e) of Public Law 107-56, codified at 42 U.S.C. 5195c(e). “Sector risk management agency” uses the meaning in section 2200 of the Homeland Security Act of 2002, codified at 6 U.S.C. 650. “Post-quantum cryptography” is defined as cryptographic algorithms or methods assessed not to be specifically vulnerable to attack by either a quantum computer or a classical computer.
The bill also opens the door to money, but only under conditions. A grant program may be established only if appropriations are available and only after the NIST Director has issued post-quantum cryptography standards. If that happens, grants and technical assistance can go to high-risk entities for adopting those standards and remediating vulnerabilities. The bill does not set a dollar figure for the program, a maximum grant size, or a fixed application timeline. Instead, it says funds may cover “reasonable costs” up to a “specified amount” to be set later by the NIST Director, who may also develop and update rules on eligibility, application disclosures, grant amounts, and grant duration.
Another important piece is research. The bill amends section 4(a)(1)(A) of the Cyber Security Research and Development Act, at 15 U.S.C. 7403, so that National Science Foundation research explicitly includes post-quantum cryptography. That means the legislation is trying to do two things at once: speed near-term deployment help through NIST and support longer-term cryptography research through NSF. The Congressional Budget Office has reportedly scored the bill at minimal cost, but the bill text itself does not include a specific authorization amount.
Bill Progress
Latest Action · Jun 11, 2025
Committee approved bill for floor consideration by the Yeas and Nays: 35 - 0.
H.R. 3259 Bill Summary
What H.R. 3259 actually does.
NIST must lead voluntary adoption effort
The bill directs the Director of NIST to promote voluntary adoption and deployment of post-quantum cryptography standards by consulting with the Secretary of Homeland Security and the heads of sector risk management agencies, starting from amendments made in Section 2 of H.R. 3259, introduced on 2025-05-07.
Technical help for high-risk infrastructure
NIST must disseminate public guidance and resources and provide technical assistance to entities at high risk of quantum cryptoanalytic attacks, specifically naming critical infrastructure and digital infrastructure providers in new subsection 2(c)(1)(A) and 2(c)(1)(B).
Grant program depends on 2 conditions
A grant program can be established only if 2 things happen: appropriations are available and the NIST Director has already issued post-quantum cryptography standards. The grants are meant to help high-risk entities adopt standards and remediate vulnerabilities.
Grant amounts left to NIST, not Congress
The bill does not set a dollar cap in statute. Instead, grant funds may cover “reasonable costs” up to a “specified amount” that will be established later by the NIST Director, who may also set rules on eligibility, application disclosure, grant amounts, and duration under Section 2(c)(2)(C).
Bill adds 3 key legal definitions
The legislation adds definitions for 3 important terms: “critical infrastructure” by cross-reference to 42 U.S.C. 5195c(e), “sector risk management agency” by cross-reference to 6 U.S.C. 650, and “post-quantum cryptography” as algorithms or methods assessed not to be specifically vulnerable to attack by either a quantum computer or a classical computer.
NSF research mandate explicitly expanded
Section 2(b) amends section 4(a)(1)(A) of the Cyber Security Research and Development Act, codified at 15 U.S.C. 7403, to explicitly include post-quantum cryptography as a National Science Foundation research focus.
Who benefits from H.R. 3259?
Critical infrastructure operators
Operators covered by the definition in 42 U.S.C. 5195c(e) could receive NIST technical assistance and, if appropriations are available, grants to cover reasonable costs up to a specified amount set by the NIST Director for adopting post-quantum standards and fixing vulnerabilities.
Digital infrastructure providers
These providers are specifically identified as entities at high risk of quantum cryptoanalytic attacks, making them eligible for targeted guidance, public resources, technical assistance, and potentially grants if the 2 grant conditions are met.
National Institute of Standards and Technology
NIST gets a clearer statutory role under new subsection 2(c): it must promote voluntary deployment, publish guidance, assist high-risk entities, and potentially run a grant program in consultation with DHS, CISA, and sector risk management agencies.
Academic and scientific researchers
Researchers funded through the National Science Foundation benefit because Section 2(b) explicitly adds post-quantum cryptography to NSF’s research scope under 15 U.S.C. 7403, making the topic a named federal research priority.
Who is affected by H.R. 3259?
Department of Homeland Security
DHS is directly involved because NIST must consult the Secretary of Homeland Security when promoting voluntary adoption and deployment of post-quantum cryptography standards.
Cybersecurity and Infrastructure Security Agency
If the grant program is established, the NIST Director must consult the Director of CISA on program design, alongside other sector-specific and risk management agencies and private-sector representatives.
Sector risk management agencies
Agencies defined by reference to 6 U.S.C. 650 are pulled into both the deployment effort and the grant consultation process, giving them a role in identifying needs across high-risk sectors.
Private-sector entities and nonprofit organizations
These groups are not hit with a mandate or penalty, but they are affected because they may be consulted if the grant program is created and some may qualify as high-risk entities needing help with post-quantum adoption.
HR3259 Legislative Journey
House: Vote: 35-0
Jun 11, 2025
Ordered to be Reported by the Yeas and Nays: 35 - 0.
House: Committee Action
May 7, 2025
Referred to the House Committee on Science, Space, and Technology.
About the Sponsor
Haley Stevens
Democrat, Michigan's 11th congressional district · 7 years in Congress
Committees: Science, Space, and Technology, House Select Committee on the Strategic Competition Between the United States and the Chinese Communist Party, Education and Workforce
View full profile →
Cosponsors (3)
All 3 cosponsors are Republicans. Cosponsors represent 3 states: Iowa, New York, Pennsylvania.
Committee Sponsors
Science, Space, and Technology Committee
1 of 40 committee members cosponsored
18 Democrats across this committee haven't cosponsored yet. Mobilize their constituents
What laws does H.R. 3259 change?
1 changes
Sections Amended
Section 4 of Cyber Security Research and Development Act (15 U.S.C. 7403)
inserting ``, including post-quantum cryptography'' before the semicolon
H.R. 3259 Quick Facts
- Committee
- Science, Space, and Technology
- Chamber
- House
- Policy
- Science, Technology, Communications
- Introduced
- May 7, 2025
Committee approved bill for floor consideration by the Yeas and Nays: 35 - 0.
Jun 11, 2025
Who is lobbying on H.R. 3259?
3 organizations lobbying on this bill
QUANTUM INDUSTRY COALITION | 5 |
SB TECHNOLOGY, INC. D/B/A SANDBOXAQ | 2 |
MERLIN INTERNATIONAL, INC. | 1 |
Showing 1-3 of 3 organizations
H.R. 3259 Common Questions
How much money can organizations get under the Post Quantum Cybersecurity Standards Act?
H.R. 3259 does not set a dollar amount in the statute. Grants may cover "reasonable costs" up to a later "specified amount" set by the NIST Director under the Post Quantum Cybersecurity Standards Act (SEC. 2(a)(2)).
Can critical infrastructure companies get federal grants for post-quantum cybersecurity upgrades?
Yes, but only if Congress provides appropriations and NIST has already issued post-quantum cryptography standards, according to H.R. 3259 SEC. 2(a)(2). The grants are for high-risk entities adopting standards and fixing quantum-related vulnerabilities.
Does the Post Quantum Cybersecurity Standards Act require private companies to adopt post-quantum encryption?
No. Under the Post Quantum Cybersecurity Standards Act, NIST is directed to promote voluntary adoption and deployment of post-quantum cryptography standards, not mandate them (SEC. 2(a)(2)).
Which organizations are considered high risk for quantum cryptoanalytic attacks in H.R. 3259?
The bill specifically names critical infrastructure and digital infrastructure providers as high-risk entities for technical assistance under H.R. 3259 SEC. 2(a)(2).
What are the conditions before NIST can start a post-quantum grant program?
Under the Post Quantum Cybersecurity Standards Act, two things must happen first: appropriations must be available and the NIST Director must have issued post-quantum cryptography standards (SEC. 2(a)(2)).
Can nonprofits be consulted on post-quantum cybersecurity grants under H.R. 3259?
Yes. If the grant program is created, the NIST Director must consult private sector representatives, including nonprofits, under H.R. 3259 SEC. 2(a)(2).
Does H.R. 3259 make NIST publish public guidance on post-quantum cryptography?
Yes. Under the Post Quantum Cybersecurity Standards Act, NIST must disseminate or make publicly available guidance and resources for post-quantum cryptography adoption (SEC. 2(a)(2)).
What does post-quantum cryptography mean in the Post Quantum Cybersecurity Standards Act?
It means cryptographic algorithms or methods assessed not to be specifically vulnerable to attack by either a quantum computer or a classical computer under H.R. 3259 SEC. 2(a)(1).
Does the bill expand NSF research into post-quantum cryptography?
Yes. H.R. 3259 explicitly adds post-quantum cryptography to NSF research by amending 15 U.S.C. 7403 under SEC. 2(b).
Which federal agencies must NIST work with on post-quantum cybersecurity under H.R. 3259?
NIST must consult with the Secretary of Homeland Security and the heads of sector risk management agencies under the Post Quantum Cybersecurity Standards Act (SEC. 2(a)(2)).
Based on H.R. 3259 bill text
Full Bill Text
Get notified when H.R. 3259 moves
Committee votes, floor action, cosponsor changes — straight to your inbox.
Bill alerts + Legisletter's monthly briefing. Unsubscribe anytime.
Science, Technology, Communications Bills
9 related bills we're tracking
AM Radio for Every Vehicle Act of 2025
Placed on the Union Calendar, Calendar No. 330.
Nov 12, 2025
Scientific Integrity Act
Referred to the House Committee on Science, Space, and Technology.
Feb 6, 2025
Kids Online Safety Act
Read twice and referred to the Committee on Commerce, Science, and Transportation. (Sponsor introductory remarks on measure: CR S2929-2930)
May 14, 2025
GUARDRAILS Act
Referred to the Committee on Energy and Commerce, and in addition to the Committee on the Judiciary, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
Mar 20, 2026
Artificial Intelligence Civil Rights Act of 2025
Referred to the Committee on Energy and Commerce, and in addition to the Committee on Oversight and Government Reform, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
Dec 2, 2025
TAKE IT DOWN Act
Became Public Law No: 119-12.
May 19, 2025
States' Right to Regulate AI Act
Read twice and referred to the Committee on Commerce, Science, and Transportation.
Dec 17, 2025
ACERO Act
Received in the Senate and Read twice and referred to the Committee on Commerce, Science, and Transportation.
Feb 24, 2026
ASCEND Act
Received in the Senate. Read twice. Placed on Senate Legislative Calendar under General Orders. Calendar No. 344.
Feb 24, 2026
Trending Right Now
Bills gaining momentum across Congress
Great American Outdoors Act 250
Ordered to be Reported in the Nature of a Substitute (Amended) by Voice Vote.
Jun 24, 2026
Humane Cosmetics Act of 2025
Referred to the House Committee on Energy and Commerce.
Feb 27, 2025
Therapeutic Fraud Prevention Act of 2025
Referred to the House Committee on Energy and Commerce.
May 7, 2025
Tracking Science, Technology, Communications in Congress? Monitor bills, track cosponsor momentum, and launch advocacy campaigns — all from one advocacy platform.