up:: For Policymakers MOC
Model legislative language
Three gaps recur across every jurisdiction that has published anything on this: nobody is required to tell you your data was collected, nobody is required to ship a device whose encryption can be updated, and no private organization is required to know where its own cryptography lives.
Below is draft language for each, written to be lifted, cut, and argued with. Each provision carries drafting notes explaining what every clause is doing and what it deliberately avoids.
The hardest of the 3 is the notification duty, because you can’t require disclosure of an event nobody can detect. The draft solves that by building the trigger on records an organization already holds rather than on an alarm nobody will ever hear.
Not legal advice
This is drafting material offered as a starting point, and it isn’t legal advice. Any provision below needs review by legislative counsel against the jurisdiction’s own definitions, enforcement architecture, and existing statutes.
The short version:
- The notification gap can be closed on a records model, since a detection model is impossible by construction.
- The updatability requirement is the most urgent, because it’s the only gap that becomes permanently unfixable for equipment fielded while it stays open.
- The inventory obligation needs no new institutions, only a delegation to sector regulators who already supervise these entities.
- A safe harbor attached to compliance moves organizations that a penalty alone won’t reach.
- Each provision is drafted to survive the objection it will actually face, which is stated alongside it.
- None of these require naming an algorithm, which is what keeps them from expiring.
What goes at the top of the bill?
Findings. Legislatures open with the facts the law rests on, and a findings section does 3 jobs at once: it establishes the record, it survives into the press release, and it’s what a court reads when the statute is later challenged as arbitrary.
Every finding below is sourced. That’s unusual for findings and it’s the reason this section is worth lifting whole.
SECTION 1. FINDINGS.
The [legislature] finds the following:
(1) The cryptography protecting substantially all electronic commerce, government communication, and personal data depends on mathematical problems that a sufficiently large quantum computer can solve efficiently, a result published in 1994 and not since overturned.
(2) The United States National Institute of Standards and Technology finalized replacement cryptographic standards on August 13, 2024, and selected an additional algorithm in March 2025, such that replacement standards are now available for deployment.
(3) Encrypted data recorded today may be retained and decrypted at a later date once such a computer exists, a practice the Cybersecurity and Infrastructure Security Agency, the National Security Agency, and the National Institute of Standards and Technology jointly described in August 2023 as attackers “targeting data today that would still require protection in the future.”
(4) The collection described in paragraph (3) alters no system, triggers no alarm, and produces no artifact, and therefore constitutes no event cognizable under existing breach-notification law.
(5) Federal executive agencies have been required to maintain an annual algorithm-level inventory of their cryptographic systems since May 2023, and no comparable obligation reaches the private entities that hold the majority of affected data.
(6) The United States has projected a cost of approximately $7,100,000,000 to migrate priority federal civilian systems between 2025 and 2035, a figure derived by inventory followed by costing.
(7) Products containing digital elements are routinely placed in service with cryptography fixed at manufacture and service lives of 10 to 20 years, such that products sold today will remain in service beyond the date on which their cryptography is scheduled to be withdrawn.
(8) Data whose confidentiality is required by law to persist for a period of years, including health records, financial records, and classified information, is exposed retroactively by the practice described in paragraph (3).
Drafting notes.
- Paragraph (4) is the legal keystone. It establishes on the record why existing law fails, which is what justifies a new duty rather than an amendment to the old one.
- Paragraph (7) justifies Section 3 of the draft and is the finding most likely to be challenged by manufacturers. It’s also the most verifiable, since service lives are published in product documentation.
- Every paragraph is sourced in The primary documents behind every claim, and a staffer should attach those citations as a supporting memorandum rather than into the bill text itself.
Source: Shor, SIAM J. Computing 26(5), 1997, arxiv.org; NIST, August 13, 2024, nist.gov; CISA, NSA, and NIST, August 21, 2023, cisa.gov; OMB M-23-02, whitehouse.gov; OMB, July 2024, OMB PQC Report.
How do you legislate a harm nobody can detect?
By changing what the duty attaches to.
Every breach-notification statute in force triggers on unauthorized acquisition being discovered. Copying encrypted traffic is passive, alters nothing, and produces no artifact on either end, so the trigger never fires. A statute that waits for detection here will never operate.
The move is to attach the duty to a fact the organization can look up: what cryptography protected this data, and has that cryptography since been withdrawn from the approved list? That’s a records question with a determinate answer, and it converts an undetectable event into an auditable one.
Draft: retroactive cryptographic exposure notice
SECTION 2. RETROACTIVE CRYPTOGRAPHIC EXPOSURE NOTICE.
(a) Definitions. As used in this section: (1) “Covered data” means personal information as defined in [existing breach-notification statute]. (2) “Withdrawn cryptography” means a cryptographic algorithm or parameter set that, after the effective date of this section, is designated as disallowed for the protection of covered data by [the national standards authority]. (3) “Transmission period” means the period during which a covered entity transmitted or stored covered data protected solely by cryptography that has since become withdrawn cryptography.
(b) Duty. Not later than [180] days after an algorithm is designated as withdrawn cryptography, a covered entity shall determine whether it transmitted or stored covered data protected solely by that cryptography, and shall notify each affected individual and [the supervising authority] of: (1) the categories of covered data so protected; (2) the transmission period; and (3) whether the entity has since re-protected that data under approved cryptography.
(c) Limitation. A notice under this section is not a representation that any covered data was accessed, acquired, or decrypted, and shall not by itself establish liability under [existing statute].
(d) Safe harbor. A covered entity that completed a cryptographic inventory under Section 4 and migrated the affected systems before the designation date is exempt from subsection (b) as to that data.
Drafting notes.
- Subsection (a)(2) is the engine. By pegging to a standards body’s own designation, the statute updates itself as algorithms retire, and never names an algorithm that could expire.
- “Protected solely by” in (a)(3) matters: data that also travelled under a layer of surviving encryption is excluded, which keeps the duty proportionate.
- Subsection (c) is what makes this passable. Without it, every notice reads as an admission of breach and industry opposition becomes total. It converts the notice from an incident report into a disclosure of fact.
- Subsection (d) is the incentive. An organization that did the work is exempt, which turns the whole provision into a reason to migrate early.
- The objection it will face: notice fatigue. The honest answer is that the trigger fires rarely, on the order of once per algorithm retirement, rather than per incident.
What’s the most urgent provision to pass?
The updatability requirement, because it’s the only one whose window closes permanently.
A device manufactured in 2028 with cryptography fixed in silicon and a 20-year service life is a 2048 problem no future legislature can reach. Every year this gap stays open, more of that equipment enters service. The other 2 gaps can be closed late and still work. This one cannot.
Draft: cryptographic updatability for long-lived products
SECTION 3. CRYPTOGRAPHIC UPDATABILITY.
(a) Application. This section applies to a product with digital elements that is [placed on the market / sold or offered for sale] after [date], and whose manufacturer states, or reasonably anticipates, a service life of [10] years or more.
(b) Requirement. A product subject to this section shall be capable of receiving and applying updates to its cryptographic algorithms and parameters throughout its stated support period, without physical replacement of the product.
(c) Disclosure. The manufacturer shall disclose at the point of sale: (1) the stated support period during which cryptographic updates will be provided; and (2) the cryptographic algorithms the product relies on as shipped.
(d) Exception. Where subsection (b) is not achievable for reasons of safety certification, power, or physical constraint, the manufacturer shall instead disclose that the product’s cryptography is fixed, together with the expected service life.
(e) Enforcement. A violation is [an unfair or deceptive practice / a product-safety non-conformity] enforceable by [authority].
Drafting notes.
- Subsection (d) is doing the heavy lifting politically. Implanted medical devices, some industrial controllers, and some space hardware genuinely can’t take field updates. Banning them is not the goal, and forcing the constraint to be disclosed is. A buyer who knows a device carries fixed cryptography for 20 years can plan around it. A buyer who is never told cannot.
- Subsection (c)(2) is the sleeper. A disclosed algorithm list at point of sale is a cryptographic inventory that assembles itself, at no cost to the purchaser.
- The objection it will face: cost to manufacturers. The counter is that the EU’s product-security regime already requires security updates across a support period, so the compliance pattern exists and much of the industry is building to it.
How do you require an inventory without new institutions?
By delegating it to the regulators who already supervise these entities, which is how the federal government reached its own agencies.
Federal civilian agencies have submitted an algorithm-level cryptographic inventory annually since May 2023. That obligation produced the data behind the government’s own cost projection. No equivalent duty reaches the private sector, where most of the affected data actually sits.
Source: Office of Management and Budget, “Migrating to Post-Quantum Cryptography,” Memorandum M-23-02, November 18, 2022, OMB M-23-02.
Draft: cryptographic inventory for regulated entities
SECTION 4. CRYPTOGRAPHIC INVENTORY.
(a) Application. This section applies to an entity that is [designated critical infrastructure / supervised by a sector regulator listed in subsection (e)].
(b) Inventory. Not later than [24] months after the effective date, and [annually / biennially] thereafter, a covered entity shall maintain an inventory identifying, for each system it operates or procures: (1) the cryptographic algorithms and parameter sets in use; (2) the categories of data those algorithms protect, and the period for which each category must remain confidential; and (3) for cryptography the entity cannot itself modify, the vendor responsible and any dated commitment obtained from that vendor.
(c) Submission. A covered entity shall make the inventory available to its sector regulator on request. The inventory is exempt from public disclosure under [FOIA analogue].
(d) Scaling. A sector regulator shall establish reduced requirements for entities below [threshold], which may be satisfied by an inventory of vendors and their stated commitments.
(e) Delegation. [List existing sector regulators.] No new authority is established by this section.
Drafting notes.
- Subsection (b)(2) is the part that makes the inventory useful rather than a compliance artifact. An algorithm list alone doesn’t set priority; an algorithm list paired with confidentiality lifetimes does.
- Subsection (b)(3) captures the vendor-controlled majority, which is most of a typical estate and the part no internal audit sees.
- Subsection (c)‘s disclosure exemption is essential. A public cryptographic inventory is a target map. Without this clause the provision is actively harmful and will be opposed by every security professional who reads it.
- Subsection (d) is what keeps this from crushing small operators. A rural water utility satisfying the duty with a vendor list and their answers is the intended outcome. See What if we are a small business.
- The objection it will face: burden. The counter is subsection (d) plus the fact that no entity can price or plan a migration it hasn’t inventoried, so the work is required regardless of whether it’s legislated.
What else does a complete bill need?
The provisions above are the substance. A bill that can actually move needs the scaffolding around them, and these are the clauses whose absence gets a draft sent back.
| Clause | What it does | The decision it forces |
|---|---|---|
| Effective dates and phase-in | Staggers the duties so they don’t all land at once | Inventory first, then notification, then updatability on new products only. Retroactive product requirements sink bills |
| Enforcement authority | Names who acts on a violation | Sector regulator, attorney general, or a product-safety body. Pick the one that already supervises the entity |
| Private right of action | Whether individuals can sue | The single biggest political fight in the bill. Including one draws organized opposition; omitting one draws consumer-advocate opposition. Decide deliberately rather than by default |
| Preemption | Whether this displaces or supplements other law | At state level, say explicitly that it supplements existing breach law rather than replacing it |
| Interaction with existing statutes | Prevents double or conflicting duties | Name the health, financial, and breach statutes in your jurisdiction and state which controls |
| Appropriations | Funds the grants and the regulator’s capacity | Without this, the inventory duty is an unfunded mandate on entities that can’t absorb it |
| Severability | One provision falling doesn’t take the rest | Standard, and it matters here because the inventory section is the most likely to be challenged |
| Sunset or review | Forces a look back | A [5]-year review against the standards authority’s designations keeps the statute current |
On the federal-versus-state question. These provisions are drafted jurisdiction-neutral, and they behave differently depending on where they’re introduced. A state can readily pass the notice and inventory sections, since breach notification and sector supervision are established state competencies. The updatability section sits closer to interstate commerce and product regulation, so at state level it’s better framed as a procurement condition, meaning the state buys only products meeting the updatability requirement, rather than as a sales prohibition. That version needs no commerce-clause argument and moves the market anyway.
What needs a lawyer, not a cryptographer. The enforcement architecture, the private-right-of-action decision, preemption, and the interaction with existing statutes are all determinations for legislative counsel in the jurisdiction. What’s offered here is the substantive core and the technical definitions, which is the part that usually stalls a draft because nobody in the room can write it.
What does the member’s office need on one page?
Staff read a page. This is the leave-behind that travels with the draft.
[BILL NAME], one page
The problem. Encrypted data is being collected today and stored to be read once quantum computers can break the encryption protecting it. Three federal agencies described this jointly in 2023. No law requires anyone to tell the people whose data it was, because nothing is broken into and no alarm is triggered.
What the bill does. Three things. It requires notice when data was protected by cryptography that has since been formally withdrawn. It requires that long-lived connected products be capable of cryptographic updates, or disclose that they aren’t. And it requires regulated entities to know where their own cryptography is, a duty federal agencies have carried since 2023.
What it does not do. It names no algorithm, sets no deadline for the arrival of quantum computers, requires no public disclosure of security information, and creates no new agency.
Who it reaches. Entities already supervised by [sector regulators], and manufacturers of long-lived connected products. Small entities satisfy the inventory duty with a vendor list.
Cost. The inventory is the only material cost, and it falls on entities that need the inventory to plan or price any migration regardless. The federal government’s own migration is projected at $7.1 billion, a figure produced by exactly this sequence.
Why now. Products sold this year with fixed cryptography will still be in service after the date that cryptography is scheduled to be withdrawn. That window closes permanently, and every year of delay puts more of that equipment into the field.
What should a drafter deliberately avoid?
Five things, each of which has sunk technology legislation before.
| Avoid | Why | Do instead |
|---|---|---|
| Naming specific algorithms | The statute expires when the algorithm does | Peg to a standards authority’s current designation |
| Setting a date for the quantum computer | Nobody credible has one, and the statute dies with the prediction | Trigger on data lifetime and on standards designations |
| Requiring public disclosure of an inventory | It’s a target map | Regulator access on request, with a disclosure exemption |
| A flat duty with no scaling | Crushes small operators and produces documented non-compliance | Thresholds and a reduced vendor-list form |
| Penalty without safe harbor | Punishes without moving anyone | Pair every duty with an exemption for entities that did the work |
What does this cost, and who pays?
The inventory obligation is the only provision with material cost, and it lands on entities that would need the inventory anyway to plan or price anything.
The U.S. projected approximately $7.1 billion to migrate its own priority civilian systems between 2025 and 2035, a figure produced by exactly the inventory-then-cost sequence Section 3 requires. For a legislature, the useful read is that inventory is the cheap step and the prerequisite for costing everything after it.
Source: Office of Management and Budget, “Report on Post-Quantum Cryptography,” July 2024, OMB PQC Report.
Funding mechanisms, including grants for operators without capacity, are covered at Who pays for this, and the incentive design at How do you make it worth doing.
Questions people ask
Can a notification duty really work if nothing is detectable? Yes, on a records model. The trigger is an algorithm’s change of status on an approved list, which is public and dated, combined with the entity’s own records of what it protected with that algorithm.
Won’t Section 1 generate constant notices? No. It fires when an algorithm is formally withdrawn, which happens on the order of once per algorithm across a decade, rather than per incident.
Why is Section 2 the urgent one? Because equipment fielded during the gap carries fixed cryptography for its whole service life. It’s the only provision whose window closes permanently.
Does any of this exist anywhere already? Partially. The EU’s product-security regime requires security updates across a support period, which is Section 2 without naming cryptography. The U.S. federal inventory duty is Section 3 applied only to government.
Do these need a new agency? No. Section 3 delegates to existing sector regulators explicitly, and Sections 1 and 2 attach to existing breach-notification and product-safety enforcement.
What if the standards authority never designates an algorithm as withdrawn? Then Section 1 never fires, which is the correct behavior. The duty tracks the technical consensus rather than getting ahead of it.
Is 24 months realistic for an inventory? For a large regulated entity, it’s tight and achievable. For small entities, subsection (d) is what makes it realistic, and the reduced form is a vendor list rather than a technical audit.
Where to go next
- What can a state actually do covers the levers available at state level, including the 3 needing no legislation.
- What is not legislated yet covers the gaps these provisions close.
- What should a government actually do covers the 12 measures available, including the ones needing no legislation.
- How do you make it worth doing covers incentive design.
- Who pays for this covers the funding question.
- For Policymakers MOC is the full legislative route.
Last verified 2026-07-31 · Maintained by Addie LaMarr, LaMarr Labs.