None of 24: The GAO Audit of Federal PQC Readiness

The GAO PQC audit, published on 6 October 2026, tested 24 US federal agencies on inventory, funding and testing for post-quantum cryptography. None had fully addressed all three. This article sets out what the audit found, where its evidence stops, and how a board outside Washington can run the same test.
On 6 October 2026, the US Government Accountability Office (GAO), the audit arm of Congress, published GAO-27-108740, QUANTUM COMPUTING: Federal Actions Needed to Prepare for Emerging Cyber Threat. It reviews how 24 federal agencies have prepared to move their systems to post-quantum cryptography (PQC), the public-key algorithms designed to resist attack by a quantum computer.
GAO tested three preparatory practices that the White House budget office, the Office of Management and Budget (OMB), set out for agencies in November 2022: keep a prioritised inventory of systems that use vulnerable cryptography, work out what the migration will cost, and test the new algorithms in the agency's own environment. None of the 24 had fully addressed all three.
The result sits in one chart on the report's highlights page.
Inventory of systems with vulnerable cryptography: one agency fully addressed the practice, 21 partially, one minimally, and one had produced no inventory.
Funding needed for the transition: 21 agencies partially addressed the practice and three had produced no assessment.
Testing PQC: one agency partially addressed the practice and 23 had not addressed it. No agency had tested a post-quantum algorithm in its own environment.
The 24 are the agencies covered by the Chief Financial Officers Act of 1990. They include all 15 cabinet departments, among them Defense, Treasury, State, Energy and Homeland Security, together with nine agencies such as NASA, the Social Security Administration and the Nuclear Regulatory Commission.
How to read the GAO PQC audit
Four facts about the document govern how far its findings can be taken.
It is the public version of a sensitive report GAO issued on 11 September 2025. Ten agencies judged parts of the original too sensitive to publish, and the public version does not attribute any finding to a named agency.
The audit ran from February 2024 to September 2025. The evidence was more than a year old on the day of publication.
The scope excludes national security systems, which fall under separate authorities.
The sensitive version carried 89 recommendations, addressed to the Cybersecurity and Infrastructure Security Agency (CISA) and 23 of the 24 agencies. Twelve agencies agreed, two partially agreed, seven neither agreed nor disagreed, one disagreed with three of the four recommendations made to it, and the Department of the Interior did not respond. The public version adds no new recommendations.
The findings are a dated baseline. They are not a description of October 2026, and the report does not claim to be one. The baseline matters because of what the same agencies must file later this month, which is covered below.
On the threat itself GAO is measured. It reports a survey of 32 specialists published by the Global Risk Institute in December 2024. They generally expect a quantum computer capable of breaking today's public-key cryptography to be built, with widely varying estimates of when. Its conclusion records expert views that the probability within ten years is low, and states that the effect on unprepared federal systems could be catastrophic. It also records a point that deserves more attention than it gets. Using such a machine to derive a private key from a public key, in GAO's words, is not an event that can be detected by the victim organisation's cybersecurity tools.
What the audit measured
GAO built its test from the OMB instruction of November 2022, a memorandum titled Migrating to Post-Quantum Cryptography, and from its own earlier work on large technology transitions. The test has three practices and eight activities.
Inventory, five activities: a complete list of priority systems; a complete record of the vulnerable algorithms on each; a complete record of each system's other characteristics, such as the type of software package, the operating system and who hosts it; evidence that the algorithm entries are accurate; and evidence that the system entries are accurate.
Funding, one activity: an assessment of the funding needed for every vulnerable system in the inventory, with assurance that it is accurate.
Testing, two activities: work with software suppliers to identify candidate environments, hardware and software for testing, and test PQC in the agency's environment.
Priority systems are those an agency has designated high value assets, those rated high impact, those holding data expected to remain mission-sensitive in 2035, and logical access control systems that rely on public-key cryptography.
One feature of the test should be stated plainly, because it changes how the scores read. On a plain reading of the framework, the inventory GAO examined is a list of priority systems with the vulnerable algorithm and a handful of attributes recorded against each. It is not a discovery of the cryptographic estate: the keys, certificates, libraries and protocols in use, wherever they sit. An agency could pass the GAO test without a view of every key, certificate and library inside the systems it lists, including those embedded in its suppliers' products and its own code. The difference between the record and the work of establishing it is set out in Discovery Is Table Stakes for PQC. A CBOM Is Not Discovery. In that sense the agencies were tested against the lower of the two standards.
The inventory finding
One agency of the 24 had a complete inventory of priority systems. One had none. The remaining 22 had inventories that left priority systems out. At a majority of agencies the inventory did not identify all high impact systems, did not identify all high value assets, and did not consider systems holding long-lived data or providing access control through public-key infrastructure.
Three details go beyond the headline numbers.
The first is an error of substance. Several agencies listed symmetric-key algorithms as vulnerable to a quantum computer. Symmetric cryptography is not currently projected to be vulnerable in that way, and the OMB instruction asked only for public-key algorithms. An inventory that makes that error suggests it was compiled without the knowledge needed to compile it.
The second is the evidence test. GAO selected six agencies, drew three systems at random from the inventories of five of them, and asked for documentation supporting what the inventory said about each system. The sixth agency had no inventory to draw from. None of the six could fully support its algorithm entries. Two supported some of them. Three supplied nothing that supported the algorithms recorded. The result for system characteristics was the same in kind: none fully supported, four partly, two not at all. Where the auditor asked for proof, no agency could prove all of what it had written down. The standard an inventory has to meet is set out in What Evidence Actually Proves a PQC Migration Is Good.
The third is scale. One department told GAO it had not built an inventory because of the size of its environment: its unclassified systems support more than 4 million endpoints. GAO found it had no plan for producing one. Officials said a plan would appear in a forthcoming PQC strategy document.
GAO attributes the inventory failures, in part, to four causes.
Expertise. Eighteen agencies reported a lack of expertise in cryptography and in building the related inventories, and none of the 18 had a plan to fill the gap. They cited the cost of training and limited resources.
Process. Twenty-three agencies had no documented process for maintaining the inventory.
Tools. Nineteen agencies used no automated tools. Officials at 15 said it was too early in the migration to use them or that they were waiting for CISA to identify suitable ones. CISA told GAO it had not told agencies to wait.
Planning. The department with 4 million endpoints had no plan for the task.
Two official comments recorded in the report are worth keeping. The Office of the National Cyber Director (ONCD), the White House office that coordinates national cyber policy, said automated tools can assist with a cryptographic inventory but cannot be relied on to complete one. CISA said manual inventory work is a necessary part of the migration. Both are right, and the reasons are set out in Shadow Cryptography: The Estate Nobody Signed For.
The funding finding
No agency had fully identified the funding it needs. Twenty-one had produced an assessment, and three had not.
Only one of the 21 assessments rested on a complete inventory of priority systems.
All 21 agencies told GAO their figures were not fully accurate.
Only one agency of the 24 had a documented process for assessing the funding needed.
Fourteen agencies said it was too early to document funding assessments.
Eleven said an assessment was difficult to produce while no supplier had products or prices to base it on.
These assessments have already been used. In July 2024, OMB gave Congress a government-wide estimate, developed by ONCD, of approximately USD 7.1 billion to migrate priority systems, or replace those that cannot support PQC, between 2025 and 2035. OMB told GAO the figure was a rough order of magnitude. ONCD said the assessments were never intended as budget information and that agencies had been told to project forward from the cost of past programmes.
A rough order of magnitude is a legitimate thing to give a legislature. It is not a budget. GAO found that 23 of the 24 agencies had no documented process for assessing funding, and that 20 of the 21 assessments rested on incomplete inventories. Its stated consequence is that agencies will be unable to prepare complete and accurate assessments and risk unexpected migration costs. Without a documented method, there is no route from the estimate to a budget.
The testing finding
One agency had carried out market research to identify supplier implementations of PQC that it could test. It had not tested them. The other 23 had done neither. Sixteen agencies said it was too early, because suppliers were still at an early stage of building the algorithms into their products.
On this finding the auditor and the executive branch disagree, and the disagreement is instructive.
ONCD's position is that testing was never a requirement. The 2022 instruction encouraged it, the majority of agencies are not resourced for it, and those that wanted to test were pointed to a centre run by the National Institute of Standards and Technology (NIST). ONCD also argued that open-source libraries are often research-grade, provide no compliance tracking, often lack external audit, and cannot on their own carry a government migration.
GAO's position is that the instruction does not describe testing as voluntary, that it was issued before the standards were final and stresses testing in agency environments before commercial implementations are finalised, and that open-source tools for prototyping have been available for at least four years. It cites the Open Quantum Safe project as an example.
Each side is right about a different thing. ONCD is right that a research library is not a production answer. GAO is right about what early testing is for. Its stated purpose is to identify systems, such as legacy systems and custom software, that may not support PQC, so that plans can be made to replace them. That knowledge does not depend on a validated commercial product, and an agency that has not tested does not have it. A bounded way to obtain it is set out in Beyond the Hype: A Vendor-Neutral Framework for Your First PQC Hybrid Pilot.
The same answer three times
One answer recurs across the three findings.
Fifteen agencies said it was too early to use automated inventory tools, or that they were waiting for CISA to name them.
Fourteen said it was too early to document funding assessments.
Sixteen said it was too early to test.
The OMB instruction dates from November 2022. NIST published the first three post-quantum standards in August 2024. The audit closed in September 2025.
Each answer points to something outside the agency: a central agency to recommend tools, standards that had only recently been finalised, suppliers still building products. In each case the preparatory work GAO was looking for did not depend on it. A documented process for maintaining an inventory needs no supplier. Nor does a plan for acquiring expertise, a written method for estimating cost, or a test plan that names where in the network testing will happen. The recommendations GAO describes in the public version include establishing and implementing processes for building inventories and for identifying funding. The sequencing argument is set out in Why PQC Vendors Are Not the Starting Point for Your Post-Quantum Transition. Two of the mistakes in The PQC Baker's Dozen describe the pattern directly: waiting for Q-day, the day a quantum computer breaks today's encryption, and mistaking a supplier's roadmap for your own.
One letter reprinted in the report shows the pattern on a single page. On 17 December 2025 the Social Security Administration wrote to GAO agreeing with its recommendations. The letter states that a review of the agency's inventory of information systems, as defined by the Federal Information Security Modernization Act, found that none currently use vulnerable cryptographic algorithms, and that transition plans will be developed once post-quantum algorithms become widely available for its systems. NIST had published the standards sixteen months earlier. Read literally, the first statement means that none of those systems relies on RSA or elliptic curve cryptography. GAO reprints the letter and summarises it without challenge, and the public report offers no means of testing the claim.
What has changed since the audit closed
Two instruments have been issued since September 2025, and both bear on how the baseline should be read.
Executive Order 14412 of 22 June 2026 directs OMB to require agencies to move their high value assets and high impact systems to PQC by 31 December 2030 for key establishment and 31 December 2031 for digital signatures. It required each agency head to identify a PQC migration lead within 30 days. It also directs a proposed procurement rule that would require covered federal contractors to comply by 31 December 2030 with NIST's Federal Information Processing Standards, including those that specify post-quantum algorithms.
OMB memorandum M-26-15 of 24 June 2026 implements the order. It tells agencies to mitigate as much quantum risk as feasible by 31 December 2030 and to submit a PQC Migration Plan to OMB and ONCD within 120 days. Counted from the date of the memorandum, that falls on 22 October 2026. The plan must contain, at a minimum, a system prioritisation strategy with a risk-based justification, timelines and milestones for the migration phases, timelines and milestones for meeting the deadline to support Transport Layer Security (TLS) 1.3, the methodologies and automated tools used for the cryptographic inventory, a plan for implementing a cryptographically agile architecture, a third-party coordination plan, an estimate of the funding and personnel required, a risk management strategy for the migration period and a definition of governance roles. The agility requirement is the one that outlasts this migration, because it decides whether the next change of algorithm is a configuration change or a rebuild. That is the practical meaning of cryptographic agility. The memorandum also states that manual approaches to discovery are often insufficient at federal scale.
Set the two documents side by side. The memorandum says: "Through their inventories, agencies have already identified legacy systems for which migration would be too difficult or costly." GAO, examining those inventories as they stood up to September 2025, found one complete inventory among 24, none of the six agencies selected for closer review able to evidence all of the entries checked, and no agency that had tested PQC to find out which systems cannot support it. The plans due on 22 October must state an inventory method and a funding estimate, which are two of the three practices the audit found incomplete.
Thirteen months separate the end of the audit from that deadline, and agencies may have closed some of the gap. Whether they have is not on the public record. The memorandum requires the plans to be sent to OMB and ONCD and contains no requirement to publish them, and GAO's public version reports the position at the close of the audit. A reader is left with a baseline from 2025 and a filing in 2026 that cannot be compared with it.
Earlier warnings went the same way. In November 2024 GAO recommended that the National Cyber Director take the lead in coordinating the national strategy for the quantum threat to cryptography, and ensure that it fully addresses the characteristics of a national strategy. The office neither agreed nor disagreed, and the new report records that as of March 2025 the recommendation had not been addressed. ONCD also told GAO that OMB was expected to issue a memorandum instructing agencies to plan their migration around the summer of 2025. Memorandum M-26-15 is dated 24 June 2026.
Why the GAO PQC audit matters outside Washington
A reader in a bank in Frankfurt, a telecommunications operator in Kuala Lumpur or an energy company in London has four reasons to read a US federal audit.
The first is the conditions. These agencies had a written instruction from the centre of government from November 2022, a statute behind it in the Quantum Computing Cybersecurity Preparedness Act of December 2022, a government-wide cost estimate, the body that wrote the standards inside the same government, and a central office running working groups and office hours. After close to three years none had fully addressed three preparatory practices. An organisation without those advantages has no basis for assuming it would score better. The only way to know is to run the test.
The second is the supply chain. The procurement rule directed by the executive order would carry the 2030 date to federal contractors, and the OMB memorandum tells agencies to make sure their requirements for products in the categories CISA has listed include PQC. A company that sells technology to the US government, or to a company that does, is inside the scope of this migration whether or not its own regulator has spoken. Where other regulators have spoken, their timetables are mapped in The State of Post-Quantum Cryptography in 2026. For cryptographic modules, compliance with those standards is shown through validation under FIPS 140-3. The gap between dated demand and validated supply is examined in Demand has a date. Supply has a register. The readiness work before a module goes to a testing laboratory is the subject of a FIPS 140-3 gap analysis. The procurement side is covered in Stop Buying Cryptographic Debt for PQC.
The third is the exposure that is already running. GAO describes an urgent need to fix the inventories because of harvest now, decrypt later: data protected by today's public-key cryptography can be copied now and decrypted when a capable machine exists. The systems an inventory fails to list are the systems whose data nobody has assessed for that exposure. The arithmetic is in Mosca's Theorem: The Equation That Tells You When to Start Post-Quantum Migration.
The fourth is ownership. The causes GAO identifies sit in different functions: workforce planning, asset records, financial planning, engineering test and supplier management. No security team controls all five. The OMB memorandum says as much. It states that the migration is not only the responsibility of the agency's Chief Information Officer and Chief Information Security Officer, although its sample allocation of roles still makes those two officers accountable for prioritisation, risk acceptance and resource allocation. In a company, risk acceptance and the allocation of resources across functions belong to the executive who owns enterprise risk. PQC transformation is an enterprise risk programme, and its accountable owner should be the Chief Risk Officer.
Remediation, part one: run the GAO test on your own organisation
The value of the GAO framework is that it is short, it is based on stated criteria and it asks for evidence. It is the kind of exercise a thematic review performs: one risk theme, tested the same way across a whole organisation. Any audit committee can commission it. Adapted for an organisation outside government, the eight activities become eight questions.
Is there a complete list of priority systems: those supporting critical functions, those holding data that must stay confidential into the 2030s and beyond, and those that control access through public-key infrastructure?
Does the list record the vulnerable public-key algorithms on each system?
Does it record each system's software type, operating system and hosting arrangement?
Can the algorithm entries be supported with evidence on request?
Can the system entries be supported with evidence on request?
Is there a funding assessment covering every system on the list, with its basis stated?
Have candidate environments, hardware and software for testing been identified with suppliers?
Has a post-quantum algorithm been tested in the organisation's own environment?
Score each as fully addressed, partially addressed or not addressed, as GAO did. Then apply the step that separated the agencies' assertions from their evidence: pick three systems, one from each priority category, and ask for the documents behind each entry.
Two cautions apply. A pass on this test is a floor. It establishes a system-level list and does not amount to discovery of the cryptographic estate. The person who compiled the inventory should also not be the person who scores it. A structured, independent version of this test forms part of a PQC Readiness Assessment.
Remediation, part two: fix the causes GAO identified
GAO's conclusion names three gaps: no plan for obtaining cryptography expertise, no process for inventories and funding assessments, and no plan to guide testing. Each has a direct remedy, and none depends on a supplier.
Write the expertise plan. Name the skills the programme needs, state which will be trained, hired or contracted, and give the plan an owner and a date. The symmetric-algorithm error is consistent with that gap, although GAO does not draw the link.
Document the inventory process. State who collects the data, from which sources, how a change to a system reaches the record and who answers for its completeness. Attach evidence to each entry at the time it is made. Use automated tools as one source, and plan manual survey work for the parts of the estate that tools cannot reach. Keep a statement of what was not examined. A PQC Discovery Sprint is a bounded way to establish that baseline.
Document the funding method. Begin with a range built from the cost of past programmes, as the agencies were told to do, and state the assumptions. Separate systems that can be upgraded from those that must be replaced, because the second group drives the total. Refresh the estimate each year and as supplier prices arrive. Put it through the finance function so that it reaches the budget.
Write the test plan. Name where in the network testing will happen and which systems are candidates. Use open implementations in a laboratory to measure key and signature sizes, handshake behaviour and performance. Record each system that fails as a replacement candidate. Ask each supplier for a dated statement of when a testable implementation will exist.
Put a date on every wait. For each activity that is on hold, record which party is being waited for, whether that party has been asked, and the date on which the organisation will proceed without it.
Questions for the board
Seven questions test whether an organisation would do better than the agencies did.
If the GAO test were run on us tomorrow, what would we score on inventory, funding and testing, and who would sign the answer?
Who decided that our inventory is complete enough to plan on, and what evidence sits behind three entries picked at random?
What is our migration cost estimate, which inventory is it built on, and where is the method written down?
Have we tested a post-quantum algorithm in our own environment? If not, which party are we waiting for, and did that party ask us to wait?
Which of our systems cannot support PQC and will have to be replaced, and how do we know?
Do we have a written plan for acquiring cryptographic expertise, with an owner?
Which executive is accountable for all six answers?
The position
GAO did not find agencies that were unaware of the problem. Its conclusion is that they recognise the threat and have taken some action. What it found is that the preparatory work had not been finished close to three years after it was asked for, and that one reason given, in three separate places, was that it was too early.
The standards have been final since August 2024. The dates in the executive order are 2030 and 2031. GAO's stated consequence is that the gaps increase the risk that the transition will occur too late. The test that would tell an organisation whether the same is true of itself is eight questions long, needs no product and no supplier, and can be commissioned by an audit committee this quarter.
About the author
Brian Couzens is CEO of SITG-Consulting, an independent consulting and advisory firm working on post-quantum cryptography governance and transformation, cryptographic risk and quantum risk management. The PQC Discovery Sprint is SITG-Consulting's structured engagement for establishing cryptographic visibility across an estate, and the PQC Readiness Assessment reviews a programme's preparation before implementation begins.
Sources
GAO-27-108740, product page with highlights and recommendations
Quantum Computing Cybersecurity Preparedness Act, Public Law 117-260, 21 December 2022
Office of Management and Budget, "Report on Post-Quantum Cryptography", July 2024
NIST, Federal Information Processing Standards 203, 204 and 205, August 2024
Global Risk Institute, "Quantum Threat Timeline Report 2024", December 2024




Comments