(a)
Inventory—
(1)
Establishment— Not later than 180 days after the date of enactment of this Act, the Director of OMB shall establish, by rule or binding guidance, a requirement for each executive agency to establish and maintain an inventory of each cryptographic system in use by the agency.
(2)
Additional content in rule or binding guidance— In the rule or binding guidance established by paragraph (1), the Director of OMB shall include, in addition to the requirement described under that paragraph—
(A)
a description of information technology to be prioritized for migration to post-quantum cryptography;
(B)
a description of the information required to be reported pursuant to subsection (b); and
(C)
a process for evaluating progress on migrating information technology to post-quantum cryptography, which shall be automated to the greatest extent practicable.
(3)
Periodic updates— The Director of OMB shall update the rule or binding guidance established by paragraph (1) as the Director determines necessary.
(b)
Agency reports— Not later than 1 year after the date of enactment of this Act, and on an ongoing basis thereafter, the head of each executive agency shall provide to the Director of OMB, the Director of CISA, and the National Cyber Director an inventory of all information technology in use by the executive agency that is vulnerable to decryption by quantum computers, prioritized pursuant to the guidance issued under subsection (a)(2).
(c)
Migration and assessment—
(1)
Migration to post-quantum cryptography— Not later than 1 year after the date on which the Director of NIST has issued post-quantum cryptography standards, the Director of OMB shall issue guidance requiring each executive agency to develop a plan to migrate information technology of the agency to post-quantum cryptography.
(2)
Designation of systems for migration— Not later than 90 days after the date on which the guidance required by paragraph (1) has been issued, the Director of OMB shall issue guidance for executive agencies to—
(A)
designate information technology to be migrated to post-quantum cryptography; and
(B)
prioritize information technology designated under subparagraph (A), on the basis of the amount of risk posed by decryption by quantum computers to that technology, for migration to post-quantum cryptography.
(d)
Interoperability— The Director of OMB shall ensure that the designations and prioritizations made under subsection (c)(2) are assessed and coordinated to ensure interoperability.
(e)
Report on post-Quantum cryptography— Not later than 15 months after the date of enactment of this Act, the Director of OMB shall submit to Congress a report on the following:
(1)
A strategy to address the risk posed by the vulnerabilities of information technology systems of executive agencies to weakened encryption due to the potential and possible capability of a quantum computer to breach that encryption.
(2)
The amount of funding needed by executive agencies to secure the information technology systems described in paragraph (1) from the risk posed by an adversary of the United States using a quantum computer to breach the encryption of information technology systems.
(3)
A description of Federal civilian executive branch coordination efforts led by the National Institute of Standards and Technology, including timelines, to develop standards for post-quantum cryptography, including any Federal Information Processing Standards developed under chapter 35 of title 44, United States Code, as well as standards developed through voluntary, consensus standards bodies such as the International Organization for Standardization.
(f)
Report on migration to post-Quantum cryptography in information technology systems— Not later than 1 year after the date on which the Director of OMB issues guidance under subsection (c)(2), and annually thereafter until the date that is 5 years after the date on which post-quantum cryptographic standards are issued, the Director of OMB shall submit to Congress, with the report submitted pursuant to section 3553(c) of title 44, United States Code, a report on the progress of executive agencies in adopting post-quantum cryptography standards.