up:: For Policymakers MOC

What a state legislator needs to know

You own the only law in the country that could close the foundational gap, and you own it because your legislature wrote it.

What can a state actually do covers the state’s full toolkit, most of which belongs to the governor. This page covers what needs a statute, which is the part only you can do.

Not legal advice

This is general education about available authority rather than legal advice. What a particular state may do is a determination for its own counsel.

What is the situation in 5 sentences?

Encryption protecting data in transit today can be recorded now and decrypted years later, once a sufficiently capable quantum computer exists, so records with long confidentiality lives are exposed the day they travel rather than the day the machine arrives. Federal agencies carry a dated migration mandate. Nothing requires a private company to inventory or migrate its cryptography, and nobody whose data was collected will ever be told. Your state operates health exchanges, Medicaid, retirement systems, universities, corrections and vital records, none of which any federal instrument covers. Neither does it cover a single city, county or school district in your state.

Why is the notification gap yours specifically?

Because every US state wrote its own breach-notification statute, and the federal government never wrote a general one.

Every one of those statutes is built on the same assumption: somebody breaks in, it is detected, and a duty to disclose follows. Recording encrypted traffic breaks nothing, enters nothing, and leaves no artifact. There is no intrusion to detect, so no notification duty attaches, and nobody whose data was collected learns that it was.

That gap sits underneath most of the others. With no triggering event, liability has nothing to attach to, regulators have nothing to enforce against, no claim has an accrual date, no insurance policy has a discovery date, and the people carrying the loss never learn they are carrying it.

Three federal agencies described this collection as a present concern in August 2023, writing that attackers “could be targeting data today that would still require protection in the future… using a catch now, break later or harvest now, decrypt later operation.” No disclosure obligation followed, because none of the existing triggers fit.

Source: CISA, NSA and NIST, “Quantum-Readiness: Migration to Post-Quantum Cryptography,” August 21, 2023, cisa.gov.

Your statute is the most natural home for the fix anywhere in American law, because it is the only instrument already built to compel disclosure of harm to individuals, and because amending an existing statute is a materially smaller lift than creating a duty from nothing.

What actually needs a statute?

Four things. Everything else on the state toolkit belongs to the governor and needs no legislature at all, which is worth knowing so a bill does not spend its capital on ground already covered.

1. Amending the breach-notification statute. The workable version obliges an organization to disclose when data it held crossed networks under cryptography now known to be retired. That is a records question rather than a detection question, which is the whole drafting insight: you cannot require disclosure of an undetectable event, but you can require disclosure of a documented one.

2. An inventory obligation for regulated entities. Delegated to the sector regulators your state already operates, with reduced requirements for small entities. This extends to insurers, state-chartered banks, hospitals and utilities the same duty federal agencies have carried since 2023, and it creates the visibility everything else depends on.

3. A safe harbor tied to completing that inventory. Attaching a benefit to the work rather than only a penalty to failure is what moves organizations with thin margins. See How do you make it worth doing.

4. Reaching local government, if the governor will not. No federal instrument reaches a city, county or school district. A state can reach them, and a statute conditioning state technology funding on vendor disclosure does it permanently rather than for one administration.

The federal .gov registry lists 12,716 local government domains nationally, comprising 8,928 city, 2,623 county, 1,100 special district and 65 school district. Every one of them is in that uncovered space.

Source: CISA .gov registry, cisagov/dotgov-data, retrieved August 10, 2026.

Drafting text for all 4 is at Model legislative language.

What is the one drafting trap?

A product mandate.

Requiring that connected products sold in the state be capable of cryptographic updates is the single most valuable provision in this field, and at state level it invites an interstate-commerce challenge that can consume the entire effort.

The version that works is a purchase condition. The state buys only products meeting the requirement. That reaches the same manufacturers, needs no commerce-clause argument, and has a long track record in state vehicle, appliance and building standards. It moves more slowly than a sales prohibition and it survives.

Why does this pay off for you?

Because there is a documented precedent for a state legislator going first on exactly this category of harm, and it is the reason your statute exists at all.

Breach notification began in a state legislature and the rest of the country followed. No federal general statute was written, one state wrote one, and over the following two decades every other state enacted its own. The entire architecture of data-breach disclosure in the United States exists because a state legislator wrote it first. That is the precedent for this amendment, and it is worth checking against your own state’s legislative history, which will show your statute descending from that same wave.

The bill is short and amends rather than creates. A definitional amendment plus a records-based trigger is a fraction of the drafting, hearing time and floor time of a standalone measure, and it lands in a statute your chamber already understands.

Nobody is defending the gap. There is no organized opposition to a disclosure duty of this shape, which is unusual on anything touching technology regulation.

The first-mover position is unclaimed. As far as this Guide can establish, no state has amended its breach-notification statute to reach this, and no state has conditioned local technology funding on vendor disclosure. First at something checkable, in one session.

And the asymmetry runs against waiting. If long-lived records held by entities in your state surface later as having traveled under retired cryptography, the question asked will be what was known and when. The federal agency statement above is dated August 2023 and is on the public record. A legislator with a filed bill has an answer. One without has a news cycle.

Claim the provision, never the outcome

“First state to require disclosure when data crossed networks under retired cryptography” is checkable and defensible. A claim about making the state quantum-safe is neither, and it will be tested by the first competent reporter who asks what actually changed.

What should I ask in committee?

Five questions with documented premises, where a deflection is audible.

  1. Under our current breach statute, what event triggers a duty to notify when encrypted data was copied rather than accessed?
  2. Which of our state agencies can produce an algorithm-level inventory of where cryptography is used in their systems?
  3. Which entities that this state supervises, insurers, state-chartered banks, hospitals, have ever been asked that question in an examination?
  4. How much technology funding do we pass through to local governments, and does any condition travel with it?
  5. Which state systems or equipment cannot receive a cryptographic update at all?

Question 1 is the one with no good answer, and it is the premise of the amendment. A fuller version is at What should I ask in a hearing.

Which state systems are worst exposed?

SystemWhy it’s the worst case
Health exchanges and MedicaidClinical data with lifetime sensitivity, at population scale
State retirement systemsFinancial and identity records spanning whole careers and beyond
UniversitiesResearch data, health systems and student records held for decades
Vital recordsBirth, death, marriage. Permanent by definition
Corrections and courtsSealed records, juvenile records, protected identities
DMV and identityBiometric and identity data that cannot be reissued

The pattern across all 6 is long-lived personal data on thin technology budgets.

Questions people ask

Is this urgent or is it a 2035 problem? The exposure that matters is records with long confidentiality lives, and those are traveling now. See Harvest Now Decrypt Later.

Won’t this conflict with federal law? The federal instruments bind federal systems. A state acting on its own statute, its own systems and the entities it supervises is in its own lane, and a supplementary-rather-than-preemptive clause makes that explicit.

Isn’t this the governor’s job? Procurement, agency directives and instructing regulators are executive actions needing no legislature. The statute is not, and neither is a durable condition on local funding that survives a change of administration.

Is this partisan? Nothing here has an organized opposition, and the published federal instruments span administrations of both parties.

What is the smallest useful bill? The definitional amendment to the breach statute, on a records trigger rather than a detection trigger. Everything else can follow it.

Is any state doing this already? This Guide does not track state legislative activity comprehensively. If a state has filed or enacted something not reflected here, that is a correction worth sending. See Corrections and verification.

Where to go next


Last verified 2026-08-10 · Maintained by Addie LaMarr, LaMarr Labs.