GAO's 2024-2025 Post-Quantum Audit of 24 Federal Agencies, Released 6 October 2026, Finds None Met All Inventory, Funding and Testing Practices Ahead of OMB's 22 October Migration Plans
What GAO-27-108740 found at 24 federal agencies in 2024 and 2025
On 6 October 2026 the U.S. Government Accountability Office released the public version of its audit, conducted from February 2024 to September 2025, of how the 24 Chief Financial Officers Act agencies are preparing to move vulnerable systems to post-quantum cryptography. GAO measured three practices drawn from OMB's November 2022 memo M-23-02: a prioritized inventory of systems with vulnerable cryptography, the funding needed to migrate them, and testing in agency environments. None of the 24 agencies fully addressed all three. One agency had a complete inventory of priority systems, 19 used no automated discovery tools, and no agency had tested post-quantum algorithms in its own environment. Agencies may have moved since; the public report does not say.
Why the $7.1 billion figure needs a second look
OMB gave Congress an estimate of about $7.1 billion to migrate priority federal systems or replace legacy systems that cannot support the new algorithms. GAO reports that 21 agencies acknowledged their funding assessments were not fully accurate and that only one assessment rested on a complete inventory.
Why the timing matters in October 2026
The audit work ended in September 2025, and the public version does not discuss OMB's June 2026 memo M-26-15, whose agency migration plans fall due on 22 October 2026. Unless agencies have closed the gaps since 2025, those plans will rest on inventories GAO found incomplete.