up:: For Policymakers MOC

Model legislative language

Three gaps recur across every jurisdiction that has published anything on this: nobody is required to tell you your data was collected, nobody is required to ship a device whose encryption can be updated, and no private organization is required to know where its own cryptography lives.

Below is draft language for each, written to be lifted, cut, and argued with. Each provision carries drafting notes explaining what every clause is doing and what it deliberately avoids.

The hardest of the 3 is the notification duty, because you can’t require disclosure of an event nobody can detect. The draft solves that by building the trigger on records an organization already holds rather than on an alarm nobody will ever hear.

Not legal advice

This is drafting material offered as a starting point, and it isn’t legal advice. Any provision below needs review by legislative counsel against the jurisdiction’s own definitions, enforcement architecture, and existing statutes.

The short version:

  • The notification gap can be closed on a records model, since a detection model is impossible by construction.
  • The updatability requirement is the most urgent, because it’s the only gap that becomes permanently unfixable for equipment fielded while it stays open.
  • The inventory obligation needs no new institutions, only a delegation to sector regulators who already supervise these entities.
  • A safe harbor attached to compliance moves organizations that a penalty alone won’t reach.
  • Each provision is drafted to survive the objection it will actually face, which is stated alongside it.
  • None of these require naming an algorithm, which is what keeps them from expiring.

What goes at the top of the bill?

Findings. Legislatures open with the facts the law rests on, and a findings section does 3 jobs at once: it establishes the record, it survives into the press release, and it’s what a court reads when the statute is later challenged as arbitrary.

Every finding below is sourced. That’s unusual for findings and it’s the reason this section is worth lifting whole.

SECTION 1. FINDINGS.

The [legislature] finds the following:

(1) The cryptography protecting substantially all electronic commerce, government communication, and personal data depends on mathematical problems that a sufficiently large quantum computer can solve efficiently, a result published in 1994 and not since overturned.

(2) The United States National Institute of Standards and Technology finalized replacement cryptographic standards on August 13, 2024, and selected an additional algorithm in March 2025, such that replacement standards are now available for deployment.

(3) Encrypted data recorded today may be retained and decrypted at a later date once such a computer exists, a practice the Cybersecurity and Infrastructure Security Agency, the National Security Agency, and the National Institute of Standards and Technology jointly described in August 2023 as attackers “targeting data today that would still require protection in the future.”

(4) The collection described in paragraph (3) alters no system, triggers no alarm, and produces no artifact, and therefore constitutes no event cognizable under existing breach-notification law.

(5) Federal executive agencies have been required to maintain an annual algorithm-level inventory of their cryptographic systems since May 2023, and no comparable obligation reaches the private entities that hold the majority of affected data.

(6) The United States has projected a cost of approximately $7,100,000,000 to migrate priority federal civilian systems between 2025 and 2035, a figure derived by inventory followed by costing.

(7) Products containing digital elements are routinely placed in service with cryptography fixed at manufacture and service lives of 10 to 20 years, such that products sold today will remain in service beyond the date on which their cryptography is scheduled to be withdrawn.

(8) Data whose confidentiality is required by law to persist for a period of years, including health records, financial records, and classified information, is exposed retroactively by the practice described in paragraph (3).

Drafting notes.

  • Paragraph (4) is the legal keystone. It establishes on the record why existing law fails, which is what justifies a new duty rather than an amendment to the old one.
  • Paragraph (7) justifies Section 3 of the draft and is the finding most likely to be challenged by manufacturers. It’s also the most verifiable, since service lives are published in product documentation.
  • Every paragraph is sourced in The primary documents behind every claim, and a staffer should attach those citations as a supporting memorandum rather than into the bill text itself.

Source: Shor, SIAM J. Computing 26(5), 1997, arxiv.org; NIST, August 13, 2024, nist.gov; CISA, NSA, and NIST, August 21, 2023, cisa.gov; OMB M-23-02, whitehouse.gov; OMB, July 2024, OMB PQC Report.

How do you legislate a harm nobody can detect?

By changing what the duty attaches to.

Every breach-notification statute in force triggers on unauthorized acquisition being discovered. Copying encrypted traffic is passive, alters nothing, and produces no artifact on either end, so the trigger never fires. A statute that waits for detection here will never operate.

The move is to attach the duty to a fact the organization can look up: what cryptography protected this data, and has that cryptography since been withdrawn from the approved list? That’s a records question with a determinate answer, and it converts an undetectable event into an auditable one.

Draft: retroactive cryptographic exposure notice

SECTION 2. RETROACTIVE CRYPTOGRAPHIC EXPOSURE NOTICE.

(a) Definitions. As used in this section: (1) “Covered data” means personal information as defined in [existing breach-notification statute]. (2) “Withdrawn cryptography” means a cryptographic algorithm or parameter set that, after the effective date of this section, is designated as disallowed for the protection of covered data by [the national standards authority]. (3) “Transmission period” means the period during which a covered entity transmitted or stored covered data protected solely by cryptography that has since become withdrawn cryptography.

(b) Duty. Not later than [180] days after an algorithm is designated as withdrawn cryptography, a covered entity shall determine whether it transmitted or stored covered data protected solely by that cryptography, and shall notify each affected individual and [the supervising authority] of: (1) the categories of covered data so protected; (2) the transmission period; and (3) whether the entity has since re-protected that data under approved cryptography.

(c) Limitation. A notice under this section is not a representation that any covered data was accessed, acquired, or decrypted, and shall not by itself establish liability under [existing statute].

(d) Safe harbor. A covered entity that completed a cryptographic inventory under Section 4 and migrated the affected systems before the designation date is exempt from subsection (b) as to that data.

Drafting notes.

  • Subsection (a)(2) is the engine. By pegging to a standards body’s own designation, the statute updates itself as algorithms retire, and never names an algorithm that could expire.
  • “Protected solely by” in (a)(3) matters: data that also travelled under a layer of surviving encryption is excluded, which keeps the duty proportionate.
  • Subsection (c) is what makes this passable. Without it, every notice reads as an admission of breach and industry opposition becomes total. It converts the notice from an incident report into a disclosure of fact.
  • Subsection (d) is the incentive. An organization that did the work is exempt, which turns the whole provision into a reason to migrate early.
  • The objection it will face: notice fatigue. The honest answer is that the trigger fires rarely, on the order of once per algorithm retirement, rather than per incident.

What’s the most urgent provision to pass?

The updatability requirement, because it’s the only one whose window closes permanently.

A device manufactured in 2028 with cryptography fixed in silicon and a 20-year service life is a 2048 problem no future legislature can reach. Every year this gap stays open, more of that equipment enters service. The other 2 gaps can be closed late and still work. This one cannot.

Draft: cryptographic updatability for long-lived products

SECTION 3. CRYPTOGRAPHIC UPDATABILITY.

(a) Application. This section applies to a product with digital elements that is [placed on the market / sold or offered for sale] after [date], and whose manufacturer states, or reasonably anticipates, a service life of [10] years or more.

(b) Requirement. A product subject to this section shall be capable of receiving and applying updates to its cryptographic algorithms and parameters throughout its stated support period, without physical replacement of the product.

(c) Disclosure. The manufacturer shall disclose at the point of sale: (1) the stated support period during which cryptographic updates will be provided; and (2) the cryptographic algorithms the product relies on as shipped.

(d) Exception. Where subsection (b) is not achievable for reasons of safety certification, power, or physical constraint, the manufacturer shall instead disclose that the product’s cryptography is fixed, together with the expected service life.

(e) Enforcement. A violation is [an unfair or deceptive practice / a product-safety non-conformity] enforceable by [authority].

Drafting notes.

  • Subsection (d) is doing the heavy lifting politically. Implanted medical devices, some industrial controllers, and some space hardware genuinely can’t take field updates. Banning them is not the goal, and forcing the constraint to be disclosed is. A buyer who knows a device carries fixed cryptography for 20 years can plan around it. A buyer who is never told cannot.
  • Subsection (c)(2) is the sleeper. A disclosed algorithm list at point of sale is a cryptographic inventory that assembles itself, at no cost to the purchaser.
  • The objection it will face: cost to manufacturers. The counter is that the EU’s product-security regime already requires security updates across a support period, so the compliance pattern exists and much of the industry is building to it.

How do you require an inventory without new institutions?

By delegating it to the regulators who already supervise these entities, which is how the federal government reached its own agencies.

Federal civilian agencies have submitted an algorithm-level cryptographic inventory annually since May 2023. That obligation produced the data behind the government’s own cost projection. No equivalent duty reaches the private sector, where most of the affected data actually sits.

Source: Office of Management and Budget, “Migrating to Post-Quantum Cryptography,” Memorandum M-23-02, November 18, 2022, OMB M-23-02.

Draft: cryptographic inventory for regulated entities

SECTION 4. CRYPTOGRAPHIC INVENTORY.

(a) Application. This section applies to an entity that is [designated critical infrastructure / supervised by a sector regulator listed in subsection (e)].

(b) Inventory. Not later than [24] months after the effective date, and [annually / biennially] thereafter, a covered entity shall maintain an inventory identifying, for each system it operates or procures: (1) the cryptographic algorithms and parameter sets in use; (2) the categories of data those algorithms protect, and the period for which each category must remain confidential; and (3) for cryptography the entity cannot itself modify, the vendor responsible and any dated commitment obtained from that vendor.

(c) Submission. A covered entity shall make the inventory available to its sector regulator on request. The inventory is exempt from public disclosure under [FOIA analogue].

(d) Scaling. A sector regulator shall establish reduced requirements for entities below [threshold], which may be satisfied by an inventory of vendors and their stated commitments.

(e) Delegation. [List existing sector regulators.] No new authority is established by this section.

Drafting notes.

  • Subsection (b)(2) is the part that makes the inventory useful rather than a compliance artifact. An algorithm list alone doesn’t set priority; an algorithm list paired with confidentiality lifetimes does.
  • Subsection (b)(3) captures the vendor-controlled majority, which is most of a typical estate and the part no internal audit sees.
  • Subsection (c)‘s disclosure exemption is essential. A public cryptographic inventory is a target map. Without this clause the provision is actively harmful and will be opposed by every security professional who reads it.
  • Subsection (d) is what keeps this from crushing small operators. A rural water utility satisfying the duty with a vendor list and their answers is the intended outcome. See What if we are a small business.
  • The objection it will face: burden. The counter is subsection (d) plus the fact that no entity can price or plan a migration it hasn’t inventoried, so the work is required regardless of whether it’s legislated.

What else does a complete bill need?

The provisions above are the substance. A bill that can actually move needs the scaffolding around them, and these are the clauses whose absence gets a draft sent back.

ClauseWhat it doesThe decision it forces
Effective dates and phase-inStaggers the duties so they don’t all land at onceInventory first, then notification, then updatability on new products only. Retroactive product requirements sink bills
Enforcement authorityNames who acts on a violationSector regulator, attorney general, or a product-safety body. Pick the one that already supervises the entity
Private right of actionWhether individuals can sueThe single biggest political fight in the bill. Including one draws organized opposition; omitting one draws consumer-advocate opposition. Decide deliberately rather than by default
PreemptionWhether this displaces or supplements other lawAt state level, say explicitly that it supplements existing breach law rather than replacing it
Interaction with existing statutesPrevents double or conflicting dutiesName the health, financial, and breach statutes in your jurisdiction and state which controls
AppropriationsFunds the grants and the regulator’s capacityWithout this, the inventory duty is an unfunded mandate on entities that can’t absorb it
SeverabilityOne provision falling doesn’t take the restStandard, and it matters here because the inventory section is the most likely to be challenged
Sunset or reviewForces a look backA [5]-year review against the standards authority’s designations keeps the statute current

On the federal-versus-state question. These provisions are drafted jurisdiction-neutral, and they behave differently depending on where they’re introduced. A state can readily pass the notice and inventory sections, since breach notification and sector supervision are established state competencies. The updatability section sits closer to interstate commerce and product regulation, so at state level it’s better framed as a procurement condition, meaning the state buys only products meeting the updatability requirement, rather than as a sales prohibition. That version needs no commerce-clause argument and moves the market anyway.

What needs a lawyer, not a cryptographer. The enforcement architecture, the private-right-of-action decision, preemption, and the interaction with existing statutes are all determinations for legislative counsel in the jurisdiction. What’s offered here is the substantive core and the technical definitions, which is the part that usually stalls a draft because nobody in the room can write it.

What does the member’s office need on one page?

Staff read a page. This is the leave-behind that travels with the draft.

[BILL NAME], one page

The problem. Encrypted data is being collected today and stored to be read once quantum computers can break the encryption protecting it. Three federal agencies described this jointly in 2023. No law requires anyone to tell the people whose data it was, because nothing is broken into and no alarm is triggered.

What the bill does. Three things. It requires notice when data was protected by cryptography that has since been formally withdrawn. It requires that long-lived connected products be capable of cryptographic updates, or disclose that they aren’t. And it requires regulated entities to know where their own cryptography is, a duty federal agencies have carried since 2023.

What it does not do. It names no algorithm, sets no deadline for the arrival of quantum computers, requires no public disclosure of security information, and creates no new agency.

Who it reaches. Entities already supervised by [sector regulators], and manufacturers of long-lived connected products. Small entities satisfy the inventory duty with a vendor list.

Cost. The inventory is the only material cost, and it falls on entities that need the inventory to plan or price any migration regardless. The federal government’s own migration is projected at $7.1 billion, a figure produced by exactly this sequence.

Why now. Products sold this year with fixed cryptography will still be in service after the date that cryptography is scheduled to be withdrawn. That window closes permanently, and every year of delay puts more of that equipment into the field.

What should a drafter deliberately avoid?

Five things, each of which has sunk technology legislation before.

AvoidWhyDo instead
Naming specific algorithmsThe statute expires when the algorithm doesPeg to a standards authority’s current designation
Setting a date for the quantum computerNobody credible has one, and the statute dies with the predictionTrigger on data lifetime and on standards designations
Requiring public disclosure of an inventoryIt’s a target mapRegulator access on request, with a disclosure exemption
A flat duty with no scalingCrushes small operators and produces documented non-complianceThresholds and a reduced vendor-list form
Penalty without safe harborPunishes without moving anyonePair every duty with an exemption for entities that did the work

What does this cost, and who pays?

The inventory obligation is the only provision with material cost, and it lands on entities that would need the inventory anyway to plan or price anything.

The U.S. projected approximately $7.1 billion to migrate its own priority civilian systems between 2025 and 2035, a figure produced by exactly the inventory-then-cost sequence Section 3 requires. For a legislature, the useful read is that inventory is the cheap step and the prerequisite for costing everything after it.

Source: Office of Management and Budget, “Report on Post-Quantum Cryptography,” July 2024, OMB PQC Report.

Funding mechanisms, including grants for operators without capacity, are covered at Who pays for this, and the incentive design at How do you make it worth doing.

Questions people ask

Can a notification duty really work if nothing is detectable? Yes, on a records model. The trigger is an algorithm’s change of status on an approved list, which is public and dated, combined with the entity’s own records of what it protected with that algorithm.

Won’t Section 1 generate constant notices? No. It fires when an algorithm is formally withdrawn, which happens on the order of once per algorithm across a decade, rather than per incident.

Why is Section 2 the urgent one? Because equipment fielded during the gap carries fixed cryptography for its whole service life. It’s the only provision whose window closes permanently.

Does any of this exist anywhere already? Partially. The EU’s product-security regime requires security updates across a support period, which is Section 2 without naming cryptography. The U.S. federal inventory duty is Section 3 applied only to government.

Do these need a new agency? No. Section 3 delegates to existing sector regulators explicitly, and Sections 1 and 2 attach to existing breach-notification and product-safety enforcement.

What if the standards authority never designates an algorithm as withdrawn? Then Section 1 never fires, which is the correct behavior. The duty tracks the technical consensus rather than getting ahead of it.

Is 24 months realistic for an inventory? For a large regulated entity, it’s tight and achievable. For small entities, subsection (d) is what makes it realistic, and the reduced form is a vendor list rather than a technical audit.

Where to go next


Last verified 2026-07-31 · Maintained by Addie LaMarr, LaMarr Labs.