GAO finds federal agencies unprepared for quantum-computing cryptography risk
The September 2025 GAO report says all 24 CFO Act agencies lack key practices to transition to post-quantum cryptography, a gap that could matter by the 2030s.

GAO issued a public version of its September 2025 report on quantum computing and federal cryptography on September 2026 after collaborating with the Office of the National Cyber Director from September 2025 through September 2026. The study evaluated the 24 Chief Financial Officer Act agencies against an Office of Management and Budget-based framework of three preparatory practices.
The report found that none of the 24 agencies fully addressed the three practices, which include developing inventories of vulnerable cryptography, assessing funding needs for post-quantum cryptography, and establishing plans for testing quantum-resistant algorithms. GAO attributes the shortfall to a lack of cryptography expertise, absent inventory processes, and missing testing plans.
Industry experts anticipate a cryptographically relevant quantum computer could be developed as soon as the 2030s. Such a machine could break current encryption, allowing malicious actors to compromise system authentication and decrypt data that had been collected before the quantum breakthrough.
GAO issued 89 recommendations to 23 agencies to establish and implement the missing processes. Twelve agencies agreed with the recommendations, two partially agreed, seven neither agreed nor disagreed, and one agency disagreed with three of its four recommendations. The public version of the report does not add further recommendations.
The findings signal that federal agencies must create comprehensive cryptography inventories, secure funding for post-quantum transitions, and conduct testing of quantum-resistant algorithms to mitigate the emerging quantum-computing threat.
Further reading


