Listen to a Summary of This Article
One American government department told federal auditors that its unclassified computer networks supported more than four million connected devices. Identifying the encryption embedded in those systems would be an enormous undertaking, officials explained. Yet when investigators examined how the department intended to accomplish it, they found no adequate plan.
Across Washington, the picture was scarcely more reassuring. Of 24 major federal agencies examined, only one had completed an inventory of its priority systems requiring protection against future quantum attacks. None had adequately assessed the money needed to replace vulnerable cryptography, and none had tested replacement technology in its own computing environment.
The findings, published by the US Government Accountability Office on 6 October, concern a security threat that may begin years before the technology needed to exploit it becomes available. An intelligence service can intercept encrypted communications it cannot presently read, retain copies and wait for sufficiently powerful quantum computers to decipher them.
Some of that information could remain sensitive for decades.
The investigation was conducted between February 2024 and September 2025. The public report, released after a review of sensitive material, does not establish how much progress departments have made since then. But it documents the scale of the work confronting Washington as federal agencies approach a 22 October deadline to submit plans for replacing vulnerable security technology.
A threat that begins before the machine exists
Modern computer networks depend on several forms of cryptography working together. One protects the contents of communications; another helps computers establish secure connections or verify digital identities.
Some widely used public-key methods rely on mathematical problems that conventional computers cannot solve within any practical period. A sufficiently advanced quantum computer could perform certain calculations far more efficiently, undermining protections used by governments, banks and businesses.
Not all encryption faces the same danger. Symmetric-key methods, commonly used to protect the contents of messages and stored files, are generally expected to remain secure when appropriately implemented. The more immediate concern involves vulnerable public-key systems, particularly those used to establish secure connections and authenticate users.
Under certain conditions, an attacker who has retained encrypted communications could use a future quantum computer to recover the keys needed to decipher them. Cybersecurity specialists call this harvest now, decrypt later.
No publicly known quantum computer can break widely deployed public-key systems at a practical scale. Researchers disagree about when such a machine might become available. Some foresee the necessary advances during the 2030s, while others believe formidable engineering obstacles will take much longer to overcome.
An organisation protecting information that must remain confidential for twenty years cannot afford to assume the machines will arrive late. Diplomatic exchanges, intelligence reports, medical records and industrial designs may retain their value long after the computers that transmitted them have been replaced.
The American National Institute of Standards and Technology anticipated this problem years ago. In August 2024, it approved three principal standards for post-quantum cryptography, covering secure key establishment and digital signatures. The methods rely on mathematical problems believed to withstand attacks from both conventional and quantum computers.
The standards are available. Incorporating them into the complex networks on which governments and businesses depend is another matter.
Washington’s incomplete inventory
The GAO examined 24 federal agencies, including departments responsible for taxation, transport, healthcare, defence administration and public benefits. Its assessment concerned civilian and other non-national-security systems, rather than classified intelligence networks and military command systems, which operate under separate security arrangements.
Even within that scope, investigators found that departments frequently lacked reliable information about their own technology.
One agency had produced no inventory of its priority systems. Another 22 had incomplete inventories, sometimes omitting high-value equipment or systems holding information expected to remain sensitive beyond 2035. Several departments had incorrectly classified certain symmetric-key algorithms as vulnerable to quantum attacks.
At six agencies selected for closer examination, auditors attempted to verify the information recorded about particular systems. None could fully substantiate all the required details.
Nineteen agencies had not used automated tools to identify vulnerable cryptography, while 23 lacked documented procedures for maintaining their inventories. Eighteen reported shortages of cryptography expertise without having developed plans to address them.
The difficulties reflect how government computing has evolved. Encryption is embedded in operating systems, servers, applications and network equipment, much of it acquired over decades. Some departments depend on older products whose manufacturers no longer provide updates, or on specialist software that must remain compatible with other government systems.
Replacing one security method may require changes to several interconnected applications. Equipment that cannot be upgraded must eventually be retired, often while the services it supports continue operating.
The cost is difficult to calculate without knowing precisely what needs replacing.
Twenty-one agencies had prepared funding assessments that they acknowledged were not fully accurate. Three had produced none. Officials described uncertainty over which systems could be upgraded, whether suitable products would become available and what manufacturers might charge.
The auditors concluded that none had satisfactorily completed the required funding assessment.
Their investigation produced 89 recommendations to the Cybersecurity and Infrastructure Security Agency and 23 of the departments examined, addressing inventories, funding and preparations for testing replacement cryptography.
The agencies challenge the auditors
Federal officials disputed parts of the investigation, arguing that they were being asked to prepare for technologies that manufacturers had not yet fully developed.
Eleven agencies reported difficulty estimating costs because suitable products or reliable prices were unavailable. Sixteen considered testing premature while suppliers were still incorporating the new standards into commercial equipment.
Those objections cannot simply be dismissed. Departments cannot reliably price equipment that has yet to reach the market, nor guarantee that new cryptographic systems will operate successfully alongside ageing applications.
Officials from the Office of the National Cyber Director challenged the auditors’ interpretation of testing requirements. They argued that testing by individual agencies was voluntary and should depend on available resources and operational needs. Federal budget officials also maintained that preliminary funding estimates had been intended to provide broad indications of cost, rather than precise procurement budgets.
The GAO regarded those explanations as insufficient. Experimental implementations of quantum-resistant cryptography had been available for several years, allowing departments to investigate compatibility problems without waiting for finished commercial products.
Although manufacturers would ultimately determine what equipment could be purchased, departments could already examine existing systems, train specialists, identify likely replacements and establish where older technology might present difficulties.
Much of that preparatory work remained unfinished.
There had been some progress. The Social Security Administration reported improvements to its procedures for collecting information about encryption, while the Department of Homeland Security reaffirmed its commitment to preparing its systems. Federal technology officials described efforts to provide guidance and assistance to agencies undertaking the transition.
Twelve agencies agreed with the GAO’s recommendations, two agreed in part, while others disputed particular findings or expressed no position.
The report records the weaknesses identified during the original audit, rather than providing a complete assessment of federal readiness in October 2026. That limitation matters, especially where agencies have since undertaken remedial work. It does not diminish the scale of the deficiencies the investigators established.
A deadline for replacing the digital locks
On 22 June, President Donald Trump signed an executive order intended to accelerate preparations against advanced cryptographic threats. Two days later, the Office of Management and Budget issued instructions requiring federal agencies to submit detailed migration plans within 120 days.
That deadline falls on 22 October.
Departments must identify priority systems, assess risks and explain how they intend to introduce quantum-resistant methods. They are not expected to complete the transition this month. The government has established a programme extending into the next decade, with high-priority systems scheduled to adopt quantum-resistant methods for establishing secure connections by the end of 2030.
The following year is designated for migrating priority digital signature systems, which allow computers to authenticate users and verify that software or electronic documents come from trusted sources. Defeating a vulnerable signature method could allow an attacker to impersonate an authorised party or make malicious software appear legitimate.
The broader federal transition is intended to reach completion by 2035, subject to risk assessments and the availability of suitable products.
America’s national security systems are being addressed separately. On 1 October, the National Security Agency announced that new commercial national security systems must be capable of supporting quantum-resistant algorithms from 2027, with incompatible older systems to be phased out by 2030.
These programmes depend heavily on technology suppliers. Software developers, cloud computing companies and equipment manufacturers must introduce compatible products, after which organisations will need to test and install them without interrupting essential services.
Governments elsewhere face similar constraints. American companies provide much of the software and computing infrastructure used internationally, and the pace at which they adopt the new standards will influence the transition in other countries.
Britain’s National Cyber Security Centre has advised large organisations to complete their initial assessments and migration planning by 2028, undertake their highest-priority changes by 2031 and aim to finish the wider transition by 2035.
For organisations running extensive networks, the work will compete with ordinary maintenance, software upgrades and the replacement of ageing equipment. Some systems may remain in service because removing them would be expensive or disruptive.
Washington’s October deadline will provide an opportunity to judge how far federal departments have progressed since the auditors examined their preparations. The government now has approved technical standards, an implementation timetable and a clearer account of the weaknesses that must be addressed.
The GAO investigation does not establish that particular American government secrets have already been collected for future quantum decryption. Nor can it establish when a computer capable of defeating vulnerable public-key cryptography will become operational.
For an intelligence organisation retaining encrypted communications, however, the precise arrival date may be less important than the possibility that the information will eventually become readable. Material collected without immediate access to its contents may still prove valuable many years later.
The United States could complete its transition by 2035, replacing vulnerable software and equipment throughout its government networks. Stronger encryption would protect future communications, but it could not retrospectively secure an earlier exchange if an adversary had already retained a copy containing the information needed to decrypt it.
A confidential message intercepted in 2026 might remain unreadable for another fifteen years. If its protection is defeated in 2040, the security improvements made in the intervening years will have come too late for that copy.
Principal sources
- US Government Accountability Office, Quantum Computing: Federal Actions Needed to Prepare for Emerging Cyber Threat, 6 October 2026
- White House Office of Management and Budget, Memorandum M-26-15, 24 June 2026
- National Institute of Standards and Technology, Post-Quantum Cryptography Standards, August 2024
- National Security Agency, Post-Quantum Cryptography Measures, 1 October 2026
- UK National Cyber Security Centre, Post-Quantum Cryptography Migration Timelines