up:: For Policymakers MOC
What can a state actually do?
Almost every analysis of this treats it as a federal question. That’s where the published instruments are, and it leaves out the level of government that moves fastest and already regulates most of the affected parties directly.
States hold four things the federal government does not use here: they buy enormous quantities of technology, they supervise insurers and state-chartered financial institutions, they wrote every breach-notification law in the country, and they operate systems holding lifetime-sensitive records on nearly every resident.
A state can act on all four without waiting for Congress, and 3 of them need no new legislation at all.
Not legal advice
This is general education about available authority rather than legal advice. What a particular state may do is a determination for its own counsel.
The short version:
- Procurement is the fastest lever and needs no legislation. A state buying only from suppliers with dated commitments moves the market for everyone.
- States already hold the breach-notification authority, since every U.S. state wrote its own.
- State agencies hold lifetime-sensitive records: health exchanges, retirement systems, universities, corrections, vital records.
- Insurance and state-chartered banks are supervised at state level, which reaches the private sector directly.
- The one thing to avoid is a product mandate, which invites an interstate-commerce fight. Use a purchase condition instead.
- Drafting text for the substantive provisions is at Model legislative language.
What about cities and counties, and who covers them?
Nobody, and it is the largest uncovered layer in the U.S. picture.
No federal post-quantum mandate reaches local government. OMB M-26-15 binds federal civilian executive branch agencies and addresses the heads of executive departments and agencies. A city or county files no migration plan under it, answers to no phase date in it, and appears nowhere in its scope. The same is true of every phase deadline that gets quoted in coverage of the federal transition.
That leaves out the level of government residents actually touch. Schools, public hospitals, benefits administration, courts, transit, emergency dispatch, vital records, property records, and municipal payroll are operated locally. Many of those systems hold records with lifetime sensitivity, which is exactly the profile that makes recorded traffic a problem decades later.
One federal requirement does reach local government, and it arrives by data type rather than by entity. The FBI’s Criminal Justice Information Services Security Policy binds any entity handling Criminal Justice Information, explicitly including local and state law enforcement. Controls SC-13 and SC-28 require a cryptographic module certified to FIPS 140-3, or a FIPS-validated symmetric algorithm with a 256-bit key, for that information in transit and at rest outside a physically secure location, with the move off FIPS 140-2 dated September 21, 2026. Source: CJIS Security Policy v6.1, 06/25/2026.
Verified: CJIS carries no post-quantum requirement, whatever anyone tells you
Checked against the policy text on 2026-08-10. The word quantum appears zero times across all 473 pages of version 6.1, as do ML-KEM, FIPS 203 and CNSA. Every cryptographic requirement in it is symmetric, and the policy sets no key-establishment requirement anywhere. This is how the confusion starts. A 256-bit key is a sound answer to Grover’s algorithm, so a vendor calling an AES-256 product quantum-resistant is being accurate about Grover while saying nothing about Shor, which is what actually breaks the key exchange. At least one secondary source goes further and conflates CJIS with CNSA 2.0, a regime for national security systems. What CJIS establishes today is the channel: a federal cryptographic requirement that reaches a city through the data it handles.
The practical consequence is a split inside one jurisdiction. A city’s police systems can carry a federal cryptographic obligation while its schools, hospitals and finance offices carry none. Two departments of the same government, two different regimes, one of them empty.
What this means for a state. The uncovered layer is inside state authority. A state already sets procurement terms, supervises many local entities, and in most states conditions a substantial share of local funding. A state acting on procurement reaches its own municipalities in a way no federal instrument currently does, which makes the lever described above larger than it first appears.
Why does the state level matter here?
Three reasons, and the third is the one usually missed.
States move faster. A state legislature can pass a procurement requirement or amend a breach statute in a session. The federal instruments in this field took years and most of the private-sector gaps remain unaddressed.
States already regulate the affected parties. Insurers, state-chartered banks, hospitals, universities, utilities, and licensed professionals are supervised at state level. The federal government reaches them indirectly through funding conditions and sector rules; a state supervises them directly.
States are themselves large holders of the worst-case data. A state operates health exchanges, Medicaid systems, retirement funds, universities, corrections systems, vital records, DMV databases, and often election infrastructure. Those hold exactly the categories with lifetime confidentiality horizons, on budgets that rarely include a migration program.
What needs no new legislation?
Three levers, available to most states through existing authority.
1. Procurement. A state’s technology purchasing is large enough to move suppliers, and adding a post-quantum readiness requirement to solicitations is typically an administrative act rather than a statutory one. The requirement can be graduated: ask for a dated roadmap now, require support at a stated date later.
This is the highest-value action on this page. A supplier fielding the requirement from several states changes its roadmap, and every private customer of that supplier benefits without any of them asking.
2. Directing state agencies to inventory. The federal executive branch has required its own agencies to maintain an algorithm-level cryptographic inventory annually since May 2023. A governor or a state CIO can direct the equivalent for state systems under existing authority in most states.
Source: Office of Management and Budget, Memorandum M-23-02, November 18, 2022, OMB M-23-02.
3. Asking through existing supervisors. State insurance departments, banking regulators, and health agencies already send examination questions to the entities they supervise. Adding a cryptographic inventory question to an existing examination cycle costs almost nothing and produces the first real visibility any state would have into private-sector readiness.
What needs legislation?
Two things, and the drafting text for both is at Model legislative language.
Amending the breach-notification statute. Every U.S. state has one, and every one of them triggers on unauthorized acquisition being discovered. That trigger never fires for encrypted data that was copied rather than broken into. A state amending its own statute to add a records-based disclosure duty is working entirely within authority it already exercises, and it’s the most natural home for that provision anywhere in U.S. law.
An inventory obligation for regulated entities. Delegated to the sector regulators the state already operates, with reduced requirements for small entities. This creates the visibility everything else depends on.
What should a state avoid attempting?
A product mandate.
Requiring that connected products sold in the state be capable of cryptographic updates is the single most valuable provision in this field, and at state level it invites an interstate-commerce challenge that can consume the whole effort.
The version that works is a purchase condition. The state buys only products meeting the requirement. That reaches the same manufacturers, needs no commerce-clause argument, and has a long track record in state vehicle, appliance, and building standards. It moves more slowly than a sales prohibition and it survives.
What state systems are most exposed?
Worth naming, because a legislature asking about its own house asks better questions about everyone else’s.
| System | Why it’s the worst case |
|---|---|
| Health exchanges and Medicaid | Clinical data with lifetime sensitivity, at population scale |
| State retirement systems | Financial and identity records spanning entire careers and beyond |
| Universities | Research data, health systems, and student records held for decades |
| Vital records | Birth, death, marriage. Permanent by definition |
| Corrections and courts | Sealed records, juvenile records, protected identities |
| DMV and identity | Biometric and identity data that cannot be reissued |
| Utilities and transport | Operational technology with 20-year service lives |
The pattern across all 7 is the same: long-lived personal data, thin technology budgets, and equipment nobody plans to replace soon.
What are the 5 questions for a state agency head?
The same shape as the federal versions, and answerable without technical background.
- Can you produce an algorithm-level inventory of where cryptography is used in your systems, and when was it last updated?
- Which categories of resident data do you hold that stay sensitive for more than 10 years?
- What proportion of your cryptography sits in vendor products, and what dated commitments do you hold in writing?
- Which of your systems or equipment cannot receive cryptographic updates at all?
- Does your next procurement carry a post-quantum requirement?
A fuller version, with what a substantive answer and a deflection each sound like, is at What should I ask in a hearing.
Questions people ask
Can a state really move the market? Collectively, yes. State and local technology purchasing is a large share of the U.S. public technology market, and suppliers respond to requirements that appear in multiple solicitations.
Is there a model state bill? The provisions at Model legislative language are drafted jurisdiction-neutral, with a note on which adapt cleanly to state level and which need reframing as procurement conditions.
Won’t this conflict with federal rules? The federal instruments bind federal systems. A state acting on its own systems, its own procurement, and the entities it supervises is working in its own lane, and a supplementary-rather-than-preemptive clause makes that explicit.
What about small municipalities? They hold exposed systems with no capacity to act, which is the same problem the federal analysis identifies for small water utilities and rural hospitals. Grants or shared state services are the realistic answers. See Who pays for this.
Should a state wait for federal action? The private-sector gaps have been open since the federal instruments were written, and nothing indicates they close soon. States hold direct authority over insurers, banks, hospitals, and their own systems that the federal government reaches only indirectly.
Is any state doing this already? This resource doesn’t track state-level activity comprehensively, and if a state has adopted a post-quantum procurement requirement or inventory directive that isn’t reflected here, that’s a correction worth sending. See Corrections and verification.
Where to go next
- Model legislative language carries draft statutory text for the substantive provisions.
- The one-page briefing is the printable version for a member or staffer.
- What should a government actually do covers the 12 measures at any level.
- Who pays for this covers funding the entities that cannot fund themselves.
- For Policymakers MOC is the full legislative route.
Last verified 2026-07-31 · Maintained by Addie LaMarr, LaMarr Labs.