
Electric utilities operate on 30-50 year asset lifecycles; forcing a cryptographic migration in four years means retrofitting legacy SCADA systems that were never designed for rapid crypto swaps. The real constraint is not the encryption standard itself — NIST already published PQC algorithms — but the operational-technology layer: utilities must upgrade hardware, firmware, and software in systems that cannot tolerate downtime. If utilities prioritize IT cryptography first and defer OT upgrades, SCADA systems remain quantum-vulnerable through 2030, defeating the bill's intent.
FERC now faces a regulatory mandate to force electric utilities off quantum-vulnerable public-key cryptography before 2030 — a constraint that forces capital reallocation away from legacy SCADA and software update controls that utilities have deferred upgrading for decades.
The bill creates enforceable reliability standards, not voluntary guidance, meaning utilities that miss the migration face compliance violations. Watch FERC's Q4 2026 standards review for the first formal quantum-threat assessment language — if FERC hedges or delays, the 2030 deadline collapses into a 2028-2029 compression crunch.
Does the bill specify which cryptographic algorithms FERC must mandate, or does it leave algorithm selection to FERC's discretion? If the latter, utilities will lobby for the cheapest option, not the most robust one.
Strategic intelligence, synthesized daily — with a public track record. Every call graded against what actually happened.