News

GAO Audit Finds All 24 CFO Act Federal Agencies Unprepared for Post-Quantum Cryptography Migration

The U.S. Government Accountability Office (GAO) has released a public audit report (GAO-27-108740) evaluating the post-quantum cryptography (PQC) readiness of all 24 Chief Financial Officers (CFO) Act federal agencies. The findings reveal that zero out of the 24 reviewed agencies have fully implemented the core preparatory practices required by the Office of Management and Budget (OMB) to secure unclassified federal IT systems against future quantum decryption threats.

The public report is an unclassified release of a sensitive audit originally issued in September 2025. Over the past year, GAO collaborated with the Office of the National Cyber Director (ONCD) to redact classified operational details while preserving structural policy evaluations. The audit measures agency progress against three mandatory practice pillars: establishing prioritized inventories of quantum-vulnerable cryptographic assets, developing multi-year migration funding assessments, and conducting operational PQC algorithm testing within agency environments.

[ GAO Federal Agency PQC Readiness Audit Metrics (GAO-27-108740) ]
Evaluation PillarIdentified Agency Deficit & Operational GapsSystemic Root Causes
• Cryptographic Asset Inventory• 23 of 24 agencies lack documented processes to maintain cryptographic inventories
• 19 of 24 agencies fail to use automated discovery tools
• Omission of High-Value Assets (HVAs), Public Key Infrastructure (PKI) systems, and data sensitive past 2035; misclassification of symmetric algorithms as quantum-vulnerable
• Migration Funding Assessments• 21 of 24 agencies submitted incomplete cost projections
• 3 agencies submitted no funding data
• Absence of vendor price quotes for PQC-integrated commercial products; reliance on unrefined baseline projections
• Operational PQC Testing• 23 of 24 agencies have executed no operational PQC software or hardware testing• 18 of 24 agencies report severe shortages in internal technical cryptography expertise and lack documented workforce training plans

A primary driver for immediate action is the threat of “harvest now, decrypt later” tactics, where hostile nation-states like China capture encrypted traffic today via Border Gateway Protocol (BGP) rerouting or subsea cable interception to decrypt once a Cryptographically Relevant Quantum Computer (CRQC) emerges. Survey data cited by GAO indicates a majority of quantum experts predict a CRQC could arrive as soon as the 2030s. Despite OMB’s government-wide rough-order estimate of $7.1 billion required to migrate priority systems and replace non-upgradeable legacy infrastructure, agencies continue to face severe technical talent shortages and lack standardized Cryptographic Bill of Materials (CBOM) automation tools, leaving critical federal data exposed to future quantum attacks.

The audit aligns with critical enforcement timelines across the federal government, including Committee on National Security Systems Policy (CNSSP) 15, which mandates PQC support for all new commercial National Security Systems starting in 2027 and complete phase-out of legacy non-compliant hardware by 2030. In the underlying sensitive report, GAO issued 89 targeted recommendations across 23 agencies to enforce automated CBOM inventories and establish dedicated migration budgets.

Review the full public report via the GAO Official Portal here and inspect executive summaries on ExecutiveGov here.

In GQI Portal

The players behind the news

The team that writes QCR tracks every company, deal and technology in the GQI Factory, GQI's verified database of the quantum industry. Next up: every story linked to its players, coming to QCR's paid plans.

Leave a comment

All fields are required. Your email address will not be published.