up:: For Policymakers MOC
What isn’t legislated yet?
Eight gaps, and the first one is structural rather than an oversight.
Every breach law in every jurisdiction is built on the same assumption: somebody breaks in, it’s detected, and a duty to disclose follows. Recording encrypted traffic breaks nothing, enters nothing, and leaves no artifact. There’s no intrusion to detect, so no notification duty attaches, and nobody whose data was collected will ever be told.
That gap sits underneath most of the others. Without a triggering event, liability has nothing to attach to, regulators have nothing to enforce against, and the people carrying the loss never learn they’re carrying it.
Not legal advice
This is general education about published instruments and the gaps between them. Whether any obligation exists in a particular case is a legal determination.
The short version:
- No notification duty exists, because breach laws require a detectable event and this harm produces none.
- No jurisdiction requires a private company to inventory or migrate its cryptography. The obligation reaches business through procurement and contracts.
- Liability is unallocated between organizations, vendors, insurers, and the people whose data it was.
- Nothing requires a long-lived product to be updatable, which is why implanted and industrial devices are the hardest category.
- The mandates arrived without funding sized to them.
- The categories with the longest exposure, genetic and biometric data, have the least specific protection.
- No standard of care has been defined, so what counts as reasonable will be decided retrospectively by a court.
- An entire layer of government is uncovered. No post-quantum mandate reaches cities, counties or school districts, which operate the systems residents deal with most.
Why is the notification gap the foundational one?
Because the entire disclosure architecture assumes an incident, and this produces none.
U.S. state breach-notification laws, sector rules, and comparable regimes abroad are triggered by unauthorized acquisition of personal information being discovered. Each element of that fails here. Copying encrypted traffic off a network path is passive, so nothing is accessed in the sense the statutes mean. Nothing is altered, so no system reports a problem. And the decryption, if it ever happens, occurs years later inside an adversary’s own systems where no one can observe it.
Three agencies described the collection as a present concern in August 2023, writing that attackers “could be targeting data today that would still require protection in the future… using a catch now, break later or harvest now, decrypt later operation.” No disclosure obligation followed from that statement, because none of the existing triggers fit.
Source: CISA, NSA, and NIST, “Quantum-Readiness: Migration to Post-Quantum Cryptography,” August 21, 2023, cisa.gov.
The consequences run further than privacy. With no event, there’s no enforcement hook for a regulator, no accrual date for a claim, no discovery date for an insurance policy, and no moment at which a person could act to protect themselves. See Will anyone tell me if it happens.
What are the other 7 gaps?
| The gap | What’s missing | Who it lands on |
|---|---|---|
| No private-sector duty | Nothing requires a bank, hospital, utility, or software vendor to inventory its cryptography or migrate it | Everyone whose data those organizations hold |
| Unallocated liability | No allocation between the organization, its vendors, its insurer, and the people in the data | The people in the data, on the historical record |
| No product update obligation | Nothing requires a manufacturer to ship a device whose cryptography can be changed during its service life | Patients, operators, and drivers of equipment fielded for 15 to 20 years |
| No funding attached | Inventory and migration duties arrived without appropriations sized to them | Small operators with no capacity to comply |
| Weak protection for permanent data | Genetic and biometric data carry lifetime exposure and no specific cryptographic obligation | Individuals, and their relatives in the genetic case |
| No defined standard of care | Nothing states what a reasonable organization was expected to have done by a given year | Whoever ends up in the first case, decided retrospectively |
| An uncovered layer of government | No post-quantum instrument reaches cities, counties, school districts or special authorities, which operate schools, public hospitals, benefits, courts, transit and vital records | Residents of every U.S. municipality, on records the city holds for a lifetime |
The product row deserves emphasis, because it’s the only gap that closes permanently if legislated now and becomes unfixable if legislated later. A device manufactured in 2028 with fixed cryptography and a 20-year service life is a 2048 problem regardless of what any future legislature does.
Why is the uncovered layer of government different from the other gaps?
Because the other 6 describe who is not regulated inside a market. This one describes a layer of government that no instrument regulates at all.
The federal instruments are precise about who they bind. OMB M-26-15 addresses the heads of federal executive departments and agencies. CNSA 2.0 governs national security systems. Neither reaches a city, a county, a school district, or a transit authority. Those entities file no plan, answer to no phase date, and appear in no scope section.
That is checkable rather than interpretive. M-26-15 is addressed “TO THE HEADS OF EXECUTIVE DEPARTMENTS AND AGENCIES” and carries exactly one explicit exclusion, verbatim: “This memorandum does not apply to national security systems.” The words local, tribal, municipal and territorial appear zero times in it. Local government is not carved out of the memo; it was never inside the universe the memo addresses. Verified against the source PDF on 2026-08-10. Source: OMB, M-26-15, June 24, 2026, M-26-15 PDF.
The systems in that layer are not minor ones. Local government operates public hospitals and clinics, schools, benefits administration, courts and corrections, emergency dispatch, vital records, property records, and transit. The records those hold have some of the longest sensitivity horizons anywhere in public administration, and they sit on the thinnest technology budgets in public administration. That combination appears nowhere else.
One federal requirement does reach local government, and it arrives by data type rather than by entity. The FBI’s Criminal Justice Information Services Security Policy binds any entity handling Criminal Justice Information, explicitly including local and state law enforcement. Controls SC-13 and SC-28 require a cryptographic module certified to FIPS 140-3, or a FIPS-validated symmetric algorithm with a 256-bit key, for that information in transit and at rest outside a physically secure location, with the transition off FIPS 140-2 dated September 21, 2026. Source: CJIS Security Policy v6.1, 06/25/2026.
That is a cryptographic requirement, and it is verified to be a classical one
Checked against the policy text on 2026-08-10. The word quantum appears zero times across all 473 pages of version 6.1, as do ML-KEM, FIPS 203 and CNSA. Every cryptographic requirement in it is symmetric, and the policy sets no key-establishment requirement anywhere. The reason this gets misreported is worth knowing. A 256-bit key is a sound answer to Grover’s algorithm, so a vendor calling an AES-256 product quantum-resistant is being accurate about Grover while saying nothing about Shor, which is what breaks the key exchange carrying those keys. At least one secondary source goes further and conflates CJIS with CNSA 2.0, a regime for national security systems. What CJIS demonstrates today is the channel: a federal cryptographic requirement can reach a city through the data it handles rather than through the entity it is.
The result is a split inside a single government. A city’s police systems can carry a federal cryptographic duty while its schools, hospitals and finance offices carry none. Two departments, one jurisdiction, two regimes, one of them empty. That is a structural pattern rather than an oversight, and it is worth naming as one.
This gap is unusual in a useful way: it is the only one on this page that can be closed without any legislature. A city’s purchasing conditions are administrative in most charters, and a state can reach its own municipalities through procurement terms and funding conditions using authority it already exercises. The drafting text is at What can a city actually do, and the state-level route is at What can a state actually do.
Which gap would close the most with the least new law?
Ranked by impact against difficulty.
- A notification duty tied to collection rather than to intrusion. The hardest to draft, because you can’t require disclosure of an undetectable event. The workable version obliges an organization to disclose when data it holds crossed networks under cryptography now known to be retired, which is a records question rather than a detection question.
- An updatability requirement for long-lived products. Straightforward to draft, and it closes a gap that otherwise gets permanently frozen into fielded hardware. Requires that a device with a service life past a stated year support cryptographic update.
- An inventory obligation for regulated entities. Extends to critical-infrastructure operators and regulated sectors the same duty federal agencies have carried since 2023. It creates the visibility everything else depends on, and it can be delegated to existing sector regulators without new institutions.
- A safe harbor tied to completing that inventory. Attaches a benefit to the work rather than only a penalty to failure, which is what moves organizations with thin margins. See How do you make it worth doing.
- Liability allocation. The most consequential and the slowest, because it needs a considered position on where the loss should fall rather than a default of leaving it with the individual.
Why does the private-sector gap matter more than it looks?
Because most of the affected data isn’t held by government.
The federal instruments cover federal systems thoroughly. Medical records, genetic data, financial history, communications archives, and intellectual property sit overwhelmingly in private hands, and no instrument requires those holders to do anything.
The requirement does reach them, through a longer and less reliable route: federal procurement conditions, sector regulators adopting the federal template, product certification, customer contracts at renewal, and insurers and auditors treating published guidance as the reasonable baseline. That route works unevenly. It reaches a defense supplier quickly and a regional hospital slowly, and it reaches a small water utility not at all.
Source: Office of Management and Budget, Memorandum M-23-02, whitehouse.gov.
What happens if none of this is legislated?
Four outcomes, each observable from how comparable gaps have resolved before.
- The standard of care gets set by a court, retrospectively, in the first case that reaches one. That’s a slower and less predictable outcome than legislating it, and it binds everyone afterward.
- The loss stays with individuals. In the documented record, that’s the default. Equifax exposed 147 million people, most of whom were never customers, settled for at least $575 million, and the people in the file received credit monitoring against an exposure that never expires.
- Insurers resolve it through exclusions. Markets price ambiguity out rather than absorbing it, which shifts the loss back to the organization and then to the individual.
- The long-lived hardware gap closes permanently in the wrong direction, because equipment fielded during the gap carries its cryptography for its whole service life.
Source: Federal Trade Commission, “Equifax to Pay $575 Million as Part of Settlement,” July 22, 2019, ftc.gov.
Questions people ask
Isn’t existing breach law enough? It covers intrusion, and this involves none. Each statutory trigger, unauthorized access, discovery, and a detectable event, fails against passive collection.
Could a notification duty even be drafted for something undetectable? Not on a detection model. It’s draftable on a records model: disclose when data you held crossed networks protected by cryptography since retired. That’s answerable from an inventory rather than from an alarm.
Why hasn’t liability been allocated? No case has forced it, because the harm hasn’t crystallized. Allocation usually follows the first large loss, which is the expensive way to do it.
Do other countries close any of these gaps? The EU comes closest on the product side, requiring state-of-the-art confidentiality and multi-year security updates for connected products sold into its market, which functions as an updatability requirement without naming the technology.
Is the genetic-data gap really unaddressed? Genetic privacy is regulated in several respects, and none of those rules speaks to cryptographic lifetime. The specific gap is that data which stays sensitive for a lifetime carries no obligation about the strength of the encryption protecting it.
Which gap should a legislature take first? The updatability requirement for long-lived products, because it’s the only one that becomes permanently unfixable for equipment fielded while the gap remains open.
Does any of this need new agencies? No. Inventory obligations can be delegated to existing sector regulators, and product requirements to existing certification regimes.
Where to go next
- What can a city actually do carries the procurement language for the uncovered layer, which needs no legislature.
- Model legislative language carries draft statutory text for all 3 of these gaps.
- Will anyone tell me if it happens covers the notification gap from the individual’s side.
- Who pays for this covers the funding gap.
- Who is liable when this fails covers the liability gap as it looks to a company.
- What should a government actually do covers the measures available now.
- For Policymakers MOC is the full legislative route.
Go deeper into the technical detail
The technical treatment is The No-Warning Problem and Why Is Quantum Readiness a Governance Problem.
These open the Post-Quantum Field Guide, a separate site written for security professionals.
Last verified 2026-08-10 · Maintained by Addie LaMarr, LaMarr Labs.