Skip to content
Hugin
A large dark reel of magnetic tape standing on a steel shelf beside a second flat reel, both unlabelled, in a dim storage rack.

Hugin News

None of 24 major federal agencies has fully met the three preparation practices GAO drew from federal guidance for a future quantum computer able to break some of today's encryption.

3 min read

Original editorial artwork generated for Hugin.

The Government Accountability Office reported October 6 that none of the 24 agencies covered by the Chief Financial Officers Act has fully built the cryptography inventories, funding assessments and testing federal guidance calls for before a quantum computer able to break some of today's encryption exists. In a sensitive September 2025 report, GAO made 89 recommendations to CISA and 23 of those agencies: 12 agreed, two partially agreed, one disagreed with three of its four, seven neither agreed nor disagreed, and Interior did not respond.

cybersecurityquantum-computingencryptionpost-quantum-cryptographyfederal-agencies
2source receipts1source hosts3 minread timelinkedprimary source

The Government Accountability Office reported October 6 that none of the 24 agencies covered by the Chief Financial Officers Act -- the largest federal departments and agencies, Defense among them -- has fully taken the steps federal guidance says they should take before a computer able to break some of today's encryption exists. Using White House budget guidance, GAO built a framework of three practices: a prioritized inventory of vulnerable cryptography, an assessment of the funding needed, and testing of quantum-resistant algorithms. Passing meant fully addressing all three. No agency did.

The threat, and the timing experts give

GAO describes two dangers from a "cryptographically relevant quantum computer," or CRQC: an attacker could forge the certificates that verify users, machines and software, and could later decrypt data copied and stored today -- what GAO calls "harvest now, decrypt later." Today's quantum computers cannot yet break this cryptography, GAO says. On timing it reports other people's estimates, not its own. Its letter cites "some experts" predicting a CRQC in the next 10 to 20 years. It also summarises the Global Risk Institute's December 2024 report, in which most of 32 surveyed industry experts put the probability of a CRQC being developed by 2040, anywhere in the world, above 50 percent -- a survey of expert opinion, not a date and not a GAO finding. GAO's own conclusions call the probability within 10 years low, while the impact on unprepared federal systems "could be catastrophic to the nation's economy and security."

What was already required

The requirement traces to a November 18, 2022, OMB memo, M-23-02, directing agencies to inventory vulnerable systems, assess transition funding, and test post-quantum cryptography. Agencies were directed to finish the funding assessments in June 2024; NIST finalized the core standards in August 2024. A GAO footnote says OMB used those assessments to give congressional committees an estimate, developed by the Office of the National Cyber Director, that migrating priority systems to post-quantum cryptography or replacing legacy systems that cannot support it would cost about $7.1 billion government-wide. The figure is from OMB's July 2024 report under the Quantum Computing Cybersecurity Preparedness Act, which GAO says noted that a significant portion of it reflects legacy systems.

Where the 24 agencies stand

Only one of the 24 agencies fully built a prioritized inventory; a majority of the inventories missed high-impact systems and most missed high-value assets. None fully completed a funding assessment -- 21 built partial ones the agencies themselves said were not fully accurate, three developed none. One researched candidate vendors for testing; none tested post-quantum cryptography in its own environment. GAO attributes the gaps partly to a lack of cryptography expertise and of automated discovery tools; 16 agencies said testing was too early, with vendors still incorporating the new algorithms into products.

The recommendations, and what is withheld

In the sensitive report it issued in September 2025, GAO made 89 recommendations to CISA and 23 of the 24 agencies. Of those 23: 12 agreed, two partially agreed, one disagreed with three of its four while agreeing with the fourth, seven neither agreed nor disagreed, and the Department of the Interior did not respond. GAO says it continues to believe all the recommendations are warranted. On this public version Homeland Security said it remained committed to quantum readiness, and the Social Security Administration said it agreed and had updated how it collects cryptographic information. Ten agencies determined that certain information in the original was sensitive; GAO omitted the original comment letters, does not say which agencies besides Interior fell into each response group, and makes no new recommendations here.

Source links