Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

GAO finds none of 24 federal agencies has done all three post-quantum basics

None of 24 federal agencies reviewed by the US GAO has fully completed all three post-quantum basics of inventory, funding and testing. Europol's guidance a day later puts the risk on data harvested now and decrypted whenever a capable quantum computer appears.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying GAO finds none of 24 federal agencies has done all three post-quantum basics
Generated illustration

What happened

  • The GAO has already issued 89 recommendations to 23 agencies, covering inventories of vulnerable cryptography and funding for the post-quantum move, among other steps.
  • The October 6 public report is a redacted version of findings the GAO first sent to the agencies in September 2025.
  • Europol published two reports on October 7, the second of them on the quantum threat to cryptocurrency wallets.
  • Europol wants blockchain projects to build post-quantum algorithms into core protocols and wallet providers to test and deploy PQC-enabled wallets.

Why it matters

  • decision Budget and roadmap owners can fund Europol's first tier of work now, because protocol upgrades and data deletion do not depend on when a quantum computer arrives.
  • exposure Europol ties harvest exposure to protocols, configurations and key management, so the risk an organization carries today sits in settings it already controls.
  • constraint A budget line alone will not close the federal gap, because the causes the GAO lists are missing cryptography expertise, missing processes and missing testing plans.

Collection is the step an attacker can take today [11]. Europol's first report looks at how encrypted communications and stored files could be exposed to harvest-now-decrypt-later attacks. Infosecurity Magazine reported that some governments are rumored to be conducting such attacks already [11][12]. That claim is unconfirmed. The GAO audit and the Europol reports are published documents [1].

The date is a forecast. Consensus on when a cryptographically relevant quantum computer will emerge is divided, and Google predicted in March that it could be as soon as 2029 [2][3].

Europol's guidance starts with protocol work. It tells organizations to move to TLS 1.3 and SSH2, disable legacy protocols and enforce forward secrecy as soon as possible [15]. It also asks them to find and delete sensitive data they do not need, to limit long-term storage [16]. Post-quantum algorithms, including hybrid approaches, come later, to be explored as they become available [17][21].

For anyone outside blockchain projects and wallet providers, the cryptocurrency report is background reading [18]. The report itself is measured. "Cryptocurrencies will not collapse due to quantum computing, but their long-term security requires proactive defence," it said [14].

The GAO blames people and process for the shortfall on its three practices [6][8]. "The incomplete implementation of these practices is due in part to a lack of (1) cryptography expertise, (2) processes for developing cryptography inventories and identifying funding needed to transition to post-quantum cryptography, and (3) plans to guide post-quantum cryptography testing," the GAO wrote [8]. It concluded: "Until the selected agencies address these weaknesses, they will not be well-positioned to address the threat of CRQCs to cryptography that agencies rely on to protect sensitive information." [9]

Across the 23 agencies that received them, the 89 recommendations average about 3.9 each [19]. The report cites 24 agencies, and the coverage does not say why the recommendations went to 23 [7][4].

What to watch

  • GAO status reporting on whether the 23 agencies close the 89 recommendations they have held since September 2025.
  • A documented, attributed case of government harvest-now-decrypt-later collection would move that threat from rumor to the public record.
  • A revision to Google's 2029 estimate, or a competing forecast, would change how much time agencies have to finish post-quantum testing.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence58
Adoption15
Hype gap+10
Incentives
Insufficient
Confidence52
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Europol and the US GAO both released reports this week urging organizations to accelerate their post-quantum cryptography push.

    ReportedSupportedView cited source
  2. [2]

    Consensus on when cryptographically relevant quantum computers (CRQCs) will emerge is divided; when Q-day happens, these machines will be able to crack the crypto on which most government and corporate cybersecurity depend.

    ReportedSupportedView cited source
  3. [3]

    In March, Google predicted that Q-day could come as soon as 2029.

    ReportedSupportedSource: Google, as reported by Infosecurity MagazineView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. infosecurity-magazine.com

    1 article · October 8, 2026

    Europol and US GAO Sound the Alarm Over Quantum Threats

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories