A government-wide readiness failure, not a breach finding

GAO evaluated all 24 Chief Financial Officer Act agencies against three preparatory practices drawn from federal guidance. None fully addressed all three: inventorying vulnerable cryptography, assessing transition funding and planning tests of post-quantum protections.

The public report says most experts expect a cryptographically relevant quantum computer eventually, possibly as soon as the 2030s. Present-day quantum computers cannot break the relevant federal cryptography.

That distinction matters. GAO found readiness gaps; it did not report that a quantum computer has penetrated a federal system or that every system uses vulnerable encryption.

GAO’s public quantum-readiness record.
MeasureFinding
Major agencies reviewed24
Agencies fully meeting all three practices0
Agencies receiving earlier recommendations23
Recommendations in the sensitive report89

Agency responses were divided

Twelve agencies agreed with GAO’s recommendations, two partially agreed, seven neither agreed nor disagreed, and one disagreed with three of its four recommendations. GAO maintained that all 89 were warranted.

The public version followed a sensitive report issued in September 2025. GAO said it worked with the Office of the National Cyber Director through September 2026 before release, so the public document necessarily omits sensitive system details.

This analysis’s contribution is the denominator: zero of 24 fully met the complete readiness framework, even though agency positions on the remedies differed. Recommendation-closure records and agency inventories—not threat forecasts alone—will show whether readiness improves.

Sources and further reading

GAO-27-108740: Quantum Computing — Federal Actions Needed, October 6, 2026 ↗

Photograph source and CC BY-SA 4.0 license ↗