GAO Audit Finds All 24 CFO Act Federal Agencies Unprepared for Post-Quantum Cryptography Migration
quantumcomputingreport.com Oct 8, 2026

GAO Audit Finds All 24 CFO Act Federal Agencies Unprepared for Post-Quantum Cryptography Migration

AI-summarised brief · reviewed before publication

The U.S. Government Accountability Office released GAO‑27‑108740, auditing all 24 Chief Financial Officers Act agencies for post‑quantum cryptography (PQC) readiness. None had fully implemented the Office of Management and Budget’s core preparatory practices: inventorying quantum‑vulnerable assets, budgeting multi‑year migration funding, and testing PQC algorithms in agency environments. The audit highlights talent shortages, lack of automated cryptographic bill‑of‑materials tools, and a projected $7.1 billion migration cost. It aligns with CNSSP 15 mandates, urging agencies to secure systems before a quantum computer emerges in the 2030s.

💡 Why It Matters

  • · The report exposes a national security blind spot that could leave sensitive data exposed to future quantum attacks, forcing agencies to accelerate costly, urgent upgrades.