A government-wide readiness failure, not a breach finding
GAO evaluated all 24 Chief Financial Officer Act agencies against three preparatory practices drawn from federal guidance. None fully addressed all three: inventorying vulnerable cryptography, assessing transition funding and planning tests of post-quantum protections.
The public report says most experts expect a cryptographically relevant quantum computer eventually, possibly as soon as the 2030s. Present-day quantum computers cannot break the relevant federal cryptography.
That distinction matters. GAO found readiness gaps; it did not report that a quantum computer has penetrated a federal system or that every system uses vulnerable encryption.
| Measure | Finding |
|---|---|
| Major agencies reviewed | 24 |
| Agencies fully meeting all three practices | 0 |
| Agencies receiving earlier recommendations | 23 |
| Recommendations in the sensitive report | 89 |
Agency responses were divided
Twelve agencies agreed with GAO’s recommendations, two partially agreed, seven neither agreed nor disagreed, and one disagreed with three of its four recommendations. GAO maintained that all 89 were warranted.
The public version followed a sensitive report issued in September 2025. GAO said it worked with the Office of the National Cyber Director through September 2026 before release, so the public document necessarily omits sensitive system details.
This analysis’s contribution is the denominator: zero of 24 fully met the complete readiness framework, even though agency positions on the remedies differed. Recommendation-closure records and agency inventories—not threat forecasts alone—will show whether readiness improves.
Sources and further reading
GAO-27-108740: Quantum Computing — Federal Actions Needed, October 6, 2026 ↗
