The Government Accountability Office (GAO) said Oct. 6 that none of the major federal agencies have fully completed key preparations for transitioning vulnerable federal systems to post-quantum cryptography (PQC), leaving agencies at risk as quantum computing capabilities advance.
In a new report, GAO said it evaluated agency efforts against three practices drawn largely from Office of Management and Budget (OMB) guidance: developing and annually updating inventories of systems with vulnerable cryptography, identifying funding needed for the PQC transition, and testing PQC in agency environments. None of the 24 Chief Financial Officers Act agencies fully addressed all three practices.
GAO warned that although the chances of a cryptographically relevant quantum computer (CRQC) emerging within the next decade remain uncertain, “the impact of such a computer on unprepared federal systems could be catastrophic to the nation’s economy and security.”
A CRQC would be powerful enough to break certain forms of public-key cryptography that agencies use to protect sensitive information and authenticate users, systems, and software. GAO said most industry experts believe such a machine will eventually be developed, potentially as soon as the 2030s, though estimates vary widely.
The threat is not limited to data generated after a CRQC becomes available.
“There is also a risk that threat actors could harvest large amounts of data now and decrypt it later once a CRQC becomes available,” the watchdog said. “The loss of even a small amount of important sensitive information could have a severe effect on federal operations.”
That risk makes identifying vulnerable systems an immediate concern. Yet GAO found only one of the 24 agencies fully addressed the applicable activities for developing a prioritized inventory of systems using vulnerable cryptography. One agency had not developed an inventory at all, while the remaining 22 did not fully account for all priority systems.
GAO found significant workforce and process gaps behind those shortcomings. Eighteen agencies “reported a lack of expertise in cryptography and developing related inventories.” Those agencies had not developed plans to close those skills gaps.
Additionally, 23 agencies lacked a documented process for maintaining their cryptographic inventories.
Automation was also limited. Five agencies used automated tools to identify and verify cryptographic inventory information, while 19 did not. Officials from 15 agencies told GAO that it was “too early in the migration process to use automated tools” or that they were waiting for the Cybersecurity and Infrastructure Security Agency (CISA) to identify appropriate tools.
In addition, agencies have not fully determined how much the transition to PQC will cost, GAO said.
“None of the 24 agencies fully addressed the one activity under the preparatory practice to identify the funding needed to transition vulnerable cryptography on priority systems to PQC,” GAO said.
Twenty-one agencies developed funding assessments but acknowledged that their figures were not fully accurate, while three agencies had not developed funding assessments.
OMB previously used agency assessments to provide congressional committees with an Office of the National Cyber Director-developed estimate of about $7.1 billion to migrate priority federal systems to PQC or replace legacy systems that cannot support the new cryptography. GAO noted that a significant portion of that estimate reflects legacy-system replacement costs.
Testing is also a challenge, GAO noted. Only one agency fully addressed one of GAO’s two PQC testing activities by conducting market research to identify candidate vendor implementations for testing. That agency had not actually tested PQC in its environment, and the other 23 agencies did not address either testing activity.
The findings are based on a sensitive report GAO issued in September 2025. The watchdog worked with the 24 CFO Act agencies and other federal organizations through September 2026 to prepare the public version released on Tuesday.
In the sensitive report, GAO made 89 recommendations to CISA and 23 of the 24 CFO Act agencies, including recommendations to establish processes for developing inventories of vulnerable cryptography and identifying PQC transition funding.
Twelve agencies agreed with GAO’s recommendations, two partially agreed, seven neither agreed nor disagreed, and one disagreed with three of its four recommendations.
GAO made no additional recommendations in the public report.