GovTech · 8 October 2026
GAO: No US federal agency fully post-quantum crypto ready
A GAO audit of 24 US federal agencies found none had fully implemented recommended post-quantum cryptography practices, highlighting a government-wide gap in preparing for future quantum computing threats.
What happened
The US Government Accountability Office has found that none of the 24 federal agencies it reviewed had fully implemented a set of recommended practices for preparing their IT systems against future quantum computing threats. The watchdog's audit assessed how agencies are progressing on post-quantum cryptography (PQC) readiness, the process of migrating systems to encryption standards designed to withstand attacks from sufficiently powerful quantum computers.
According to the report, every agency examined had gaps against the selected PQC practices, pointing to a government-wide shortfall in preparing critical systems for a threat that cybersecurity experts expect to materialise as quantum computing matures.
Why it matters
Post-quantum cryptography migration is one of the more consequential, if under-the-radar, digital transformation challenges facing large organisations. Quantum computers capable of breaking current encryption standards are not yet operational at scale, but the transition work — inventorying systems, prioritising sensitive data, and swapping in quantum-resistant algorithms — takes years. Agencies and enterprises that delay risk being caught exposed once the technology arrives, particularly for data that needs to stay protected for long periods, such as health, financial or national security records.
For technology and transformation leaders more broadly, the finding underscores a recurring pattern: emerging-risk readiness tends to lag behind awareness. Knowing a threat is coming is not the same as having a funded, sequenced plan to address it, and the GAO's findings suggest many organisations have yet to close that gap.
By the numbers
- 24 federal agencies were audited by the GAO on post-quantum cryptography readiness.
- Zero of those agencies had fully addressed the selected PQC practices assessed in the review.
The Renascence take
It is tempting to read this as a story about cryptography. It is really a story about how organisations sequence long-horizon risk against short-term delivery pressure — a service-design and operating-model problem as much as a technical one.
Quantum-readiness is the ultimate test of whether an institution can act on a threat it cannot yet see or feel. The lesson here is not "encrypt faster" — it's that organisations consistently under-invest in risks with long lead times and no immediate customer complaint attached to them. The agencies and enterprises that get ahead of this will be the ones that treat PQC migration as a standing transformation workstream with its own governance and budget line, not a future problem to revisit once the threat becomes tangible. By then, for anything requiring long-term data confidentiality, it will already be too late to matter.
Sources
This briefing was written by our Newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.
FAQ
Questions we get on this topic
More in GovTech
Stay ahead of CX
Get the signal, not the noise.
The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.
