• 7 mins read
  • Published

Post-Quantum Readiness Claim Lacks Public Verification

Daisy Shearer Physics and quantum technology editor Science.Report

Post by Daisy Shearer

Post-Quantum Readiness Claim Lacks Public Verification Science.Report © science.report
Post-Quantum Readiness Claim Lacks Public Verification © science.report

A reported GAO assessment says 24 CFO Act agencies had not completed key post-quantum preparation tasks, but the audit and subsequent federal response could not be independently verified in the available public record.

A reported assessment by the U.S. Government Accountability Office has been described as finding that none of the 24 federal agencies covered by the Chief Financial Officers Act had fully completed the basic work required to prepare unclassified IT systems for post-quantum cryptography. However, the available search record does not independently confirm GAO-27-108740 or provide an official update on the agencies' status. The claim should therefore be treated as unverified rather than as an established government-wide finding.

  • Three reported preparation pillars The account attributed to the audit describes three expected practices: building a prioritized inventory of cryptographic assets vulnerable to future quantum attacks, developing a multiyear assessment of migration funding, and testing post-quantum algorithms in operational environments. These are sensible engineering prerequisites, but the available record does not provide agency-level scores, sample definitions, confidence intervals, statistical tests, or independently reviewable audit methodology.

    The reported assessment does not imply that a Cryptographically Relevant Quantum Computer already exists or that federal encryption has already been broken. Post-quantum cryptography is designed to run on conventional computing systems while resisting attacks from future quantum machines. The practical challenge is dependency discovery: cryptographic algorithms may be embedded in software libraries, certificates, protocols, network devices, hardware modules, and legacy equipment that cannot be upgraded without replacement.

    The article's underlying account identifies the public report as GAO-27-108740 and describes it as an unclassified version of a sensitive audit issued after a review process involving the Office of the National Cyber Director. Because the primary GAO document was not present in the available search results, those publication details and the claimed finding involving all 24 agencies cannot be independently confirmed here.

  • The long-dated threat The security concern is commonly summarized as "harvest now, decrypt later." An adversary could collect encrypted traffic today and attempt to decrypt it after acquiring sufficiently capable quantum hardware. The risk is especially relevant to information whose confidentiality must last for many years, even though the arrival date and capabilities of a cryptographically relevant quantum computer remain uncertain.

    Post-quantum cryptography is not quantum communication and does not require quantum hardware. The distinction is important across technical communities associated with NIST, MIT, CERN, and NASA, where classical and quantum computing are studied as different engineering domains. In this context, migration means replacing or supplementing vulnerable public-key mechanisms in conventional systems, then validating performance, interoperability, certificate handling, and operational reliability.

    NIST continues to update materials on cryptographic standards and procedures, including technical material available through its cryptography standards notes. The available October 2026 results, however, do not provide metrics for federal-agency migration to post-quantum algorithms. Technical presentations on threshold cryptographic schemes likewise do not establish that federal agencies are ready or unready for migration.

  • Inventory and cost claims The original account reports a government-wide rough-order estimate of $7.1 billion for migrating priority systems and replacing legacy infrastructure that cannot be upgraded. It also describes shortages of technical personnel and limited automation for producing a Cryptographic Bill of Materials, or CBOM. Neither the stated estimate, the number of inventoried assets, nor the completion of agency pilots could be confirmed from the available official results.

    A CBOM records where cryptographic components are used and helps organizations identify systems that depend on algorithms potentially vulnerable to quantum attacks. Without an accurate inventory, agencies cannot reliably rank exposure, estimate replacement work, or determine which systems require laboratory and production testing. This logic is an engineering rationale for CBOMs, not evidence that any particular federal agency has completed or failed such an inventory.

    The account presents a stark numerical picture: 24 CFO Act agencies were reviewed, none reportedly implemented all three practices, and a sensitive version of the assessment allegedly contained 89 targeted recommendations across 23 agencies. Because the underlying GAO report and agency responses were not available in the search record, these figures remain attributed claims rather than independently verified statistics.

    The article also associates the transition with deadlines under Committee on National Security Systems Policy 15, including reported requirements for new commercial National Security Systems beginning in 2027 and phaseout of noncompliant legacy hardware by 2030. The available results did not confirm official federal deadlines, funding levels, or subsequent changes. They therefore cannot establish whether those milestones remain applicable in the form described.

  • Security before the computer Migration is already a systems-engineering and procurement problem even without a quantum computer. Organizations must locate cryptographic dependencies, test replacement algorithms against performance and compatibility requirements, update certificates and protocols, and account for equipment that cannot be patched. Work discussed in peer-reviewed venues such as Nature may illuminate cryptographic and quantum-technology advances, but it cannot substitute for an agency-specific inventory or implementation record.

    The private-sector response shows why inventories matter. DigiCert's quantum migration platform was described as offering cryptographic inventories, CBOM generation, policy checks, certificate issuance, and remediation workflows. Such tooling may address an operational bottleneck, but its existence does not demonstrate that federal agencies have completed discovery, testing, budgeting, or deployment.

    The available White House statement on National Cybersecurity Awareness Month contains no specific decision, comment, or directive concerning GAO-27-108740 or federal post-quantum migration; the White House cybersecurity message therefore cannot be used to validate the reported audit outcome. No official OMB documents or agency responses in the available results establish corrective actions, migration plans, revised deadlines, or completed pilots.

    The evidence supports a narrower conclusion than the original headline. Post-quantum migration is a credible long-term cybersecurity planning problem, and cryptographic inventories, funding models, and testing programs are rational prerequisites. But the available public record does not allow a reliable determination that all 24 agencies failed the practices described, nor whether corrective measures have since changed that position.

    For policymakers, the key lesson is methodological as well as technical: a government-wide readiness claim requires a primary audit, clearly defined assessment criteria, agency-level evidence, and dated follow-up reporting. Until those materials are available, the reported numbers should remain clearly attributed and separated from verified facts about NIST's continuing standards work and the general engineering requirements of post-quantum cryptography.

  • Related articles