Advertisement

Work needed to fortify systems against quantum threats, watchdog says

None of the 24 agencies the Government Accountability Office audited had fully addressed selected post-quantum cryptography practices.
Listen to this article
0:00
Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.
(Getty Images)

Federal agencies have struggled to implement practices designed to keep their information protected in the face of an attack from a future quantum computer, a congressional watchdog found.

In findings made public Tuesday, the Government Accountability Office said that overwhelmingly federal agencies had either not addressed or only partially addressed three practices it reviewed related to shoring up their systems against anticipated quantum threats — commonly known as post-quantum cryptography or PQC. Just one agency fully addressed one of those practices, per the report. 

“Until agencies develop and implement plans and processes to ensure that the federal government expeditiously transitions priority systems to PQC, data currently protected by cryptography will be at risk of exposure,” the report said.

The report published Tuesday is a public version of a sensitive report it completed a year ago, per the GAO. While it’s more limited, the public report addresses the same themes and is based on the same auditing as the sensitive report, GAO said. The agencies audited were the roughly two dozen Chief Financial Officers Act agencies, which provides a wide cross section of large Cabinet-level agencies and smaller independent agencies.

Advertisement

According to GAO, the three practices it surveyed were agency progress on developing and updating an annual inventory of agency systems with vulnerable cryptography, identifying funding needed to transition that cryptography, and testing PQC at the agency level to ensure the algorithms work.

GAO said it developed those categories based on relevant Office of Management and Budget guidance, linking specifically to a 2022 memo.

The report comes as some experts estimate that a quantum computer with the ability to break traditional methods of encryption — known as a cryptographically relevant quantum computer (CRQC) — could be fully realized as soon as the 2030s. Though the probability that the technology will be developed that quickly is low, the result would leave encrypted information at risk. Meanwhile, there are also concerns that adversaries are harvesting data to decrypt once the cryptographic relevance is achieved. 

In an effort to address that threat, the U.S. government has published algorithms aimed at thwarting attacks from future quantum computers and developed requirements for agencies to identify their vulnerable systems and update them with PQC on a priority basis. GAO’s report, which captures a period from February 2024 to September 2025, aimed to evaluate the extent to which agencies are planning a migration. 

Specifically, GAO’s review found that a majority of agency inventories didn’t identify all of their high-impact systems or high-value assets. It also found missing data for things like the operating system used and piecemeal inclusion of vulnerable algorithms for priority systems. 

Advertisement

Among the reasons that contributed to the incomplete inventories was lack of expertise in the area of cryptography, inventory maintenance processes, and automated tools. One unidentified department also had difficulty developing an inventory process for its complex environment. Officials at that department, according to the GAO, said that its unclassified systems support more than 4 million endpoints — in other words, physical or virtual devices on its network. 

GAO said it made 89 recommendations to 23 agencies in the sensitive report, including developing inventory processes and identifying funding to support PQC. GAO disclosed that 12 agencies agreed, two agreed in part, seven did not agree or disagree, and one disagreed with three of four recommendations. The Department of Interior, meanwhile, did not provide a response to GAO. And there were no additional recommendations made in the public version. 

Both OMB and Office of the National Cyber Director officials said they assisted agencies with meetings and guidance. ONCD said the inventory was intended to be iterative, increasing in the level of detail as the process matures each year. OMB said it expected to develop future guidance to address weaknesses. 

Notably, since the watchdog conducted the audit, agencies received new guidance on quantum readiness efforts that requires them to draw up plans for PQC migration by the end of October. In a June memo, OMB required agencies to make their plans on a priority basis, with the most critical, or high-impact, systems slated for migration first. 

GAO said it worked with agencies to prepare the public version of the report from its publication in September of last year to early this year — in addition to work with ONCD until September of this year — but the report does not mention the new guidance.

Advertisement

The watchdog agency also stated that it sent a copy of the report to Sen. Maggie Hassan, D-N.H., who is the ranking member of the Joint Economic Committee and requested the audit. Representatives for Hassan didn’t immediately respond to FedScoop’s request for comment.

Latest Podcasts