Fund the reauthorized National Quantum Initiative at Congress's own proposed level, and extend post-quantum cryptography migration support beyond federal systems to critical infrastructure facing the "harvest now, decrypt later" threat.
Verification Status
AI-researched, unverifiedLast Reviewed
Jul 4, 2026
Cited Sources
5
A position worth holding should survive its strongest good-faith objection and name who bears the burden.
The best good-faith case against this position, followed by why the party still lands where it does.
The strongest good-faith objection: federal agencies are a fundamentally different regulatory subject than privately-owned critical infrastructure, and a critic could argue mandating and resourcing post-quantum migration for private utilities and hospitals raises questions this issue's "just extend the same deadline" framing understates: who pays for it (a new federal spending obligation), and whether the federal government should be setting technical security mandates for private industry generally. But the federal government already sets mandatory security standards for privately-owned critical infrastructure in exactly this category — NERC reliability standards for the power grid, HIPAA security requirements for hospitals — precisely because the consequences of a critical-infrastructure breach extend far beyond the company that got breached. Post-quantum migration is the same category of mandate, not a novel expansion of federal authority, and the funding question is a design detail (cost-share, phased timelines, small-operator subsidies) to work out, not a reason to leave the underlying gap unaddressed.
The people, institutions, and tradeoffs most likely to bear the burden of this choice.
Private critical-infrastructure operators bear compliance costs if a mandate is imposed without full federal funding attached. Taxpayers bear the cost if the federal government does fund this migration for private companies. If the mandate isn't extended at all, then the customers, patients, and ratepayers of vulnerable private infrastructure bear the "harvest now, decrypt later" risk that goes unaddressed. This issue's position is that this last cost is the least acceptable of the three, not that the other two are costless.
Turn frustration into useful pressure.
If this position misses evidence or a lived consequence, challenge it. If it holds up, help test it locally and connect it to the issues around it.