Neither federal quantum strategy meets GAO's six-point standard
Summary
GAO uses a standard six-characteristic framework to judge whether a national strategy is built to succeed. In November 2024, it applied that framework to the government's strategy for defending against the quantum-computing threat to cryptography and found every characteristic only partially addressed -- with no single office responsible for coordinating it. In March 2026, it applied the same framework to the strategy for advancing quantum computing itself and found two characteristics fully addressed, four still partial -- even though a lead coordinating office already existed. Both times, the responsible office neither agreed nor disagreed with GAO's recommendation to fix it.
The threat: quantum computers could break the encryption the internet runs on
A sufficiently powerful quantum computer -- what calls a cryptographically relevant quantum computer, or CRQC -- could break the cryptographic methods that currently secure financial transactions, encrypted communications, and infrastructure systems. Some experts predict a CRQC could exist in the next 10 to 20 years. The risk isn't only future-tense: adversaries could copy today's encrypted data and simply wait, decrypting it once a CRQC becomes available.
found that documents developed over the prior eight years had produced an emerging U.S. strategy built around three goals: standardize post-quantum cryptography (PQC) resistant to quantum attacks, migrate federal systems to it, and get the rest of the economy to prepare. Checked against 's six-characteristic framework, the strategy partially addressed all six -- objectives and activities existed for the first two goals but not the third, and none of the three goals had defined performance measures. separately estimated migrating priority federal systems alone would cost $7.1 billion between 2025 and 2035 -- about $710 million a year -- though itself flagged that figure as a rough, high-uncertainty estimate subject to annual revision.
View data as table
| Quantum computing R&D, per year | 200 |
|---|---|
| OMB's PQC migration cost estimate, annualized 2025-2035 | 710 |
's diagnosis: no single federal organization was responsible for coordinating the strategy. It recommended the Office of the National Cyber Director (ONCD) -- created by Congress in January 2021 specifically to provide this kind of cybersecurity leadership -- take on that coordinating role. ONCD did not agree or disagree with the recommendation.
The technology itself: a strategy with a different set of gaps
Sixteen months later, turned the same checklist on a related but separate strategy: the quantum-computing component of the National Quantum Initiative, the 2018 law meant to keep the U.S. ahead in quantum information science. This time the strategy fully addressed two characteristics -- it clearly defined its purpose and methodology, and it identified the problem and assessed risk. But it only partially addressed the other four: it listed goals without subordinate objectives or performance measures, described current but not future budgets, named agencies without defining their specific roles, and linked to other strategies without integrating across them.
View data as table
| 2024 cybersecurity strategy -- fully addressed | 0 |
|---|---|
| 2024 cybersecurity strategy -- partially addressed | 6 |
| 2026 R&D strategy -- fully addressed | 2 |
| 2026 R&D strategy -- partially addressed | 4 |
The federal government has spent about $200 million a year on quantum computing research and development since fiscal year 2020 -- roughly one-fifth of the $1 billion a year it spends on quantum information science overall, a broader field that also includes quantum networking and quantum sensing.
View data as table
| Quantum computing R&D, per year since FY2020 | 200 |
|---|---|
| All quantum information science, per year | 1,000 |
This gap looked different from the cybersecurity report's. There, 's problem was that no office was clearly in charge. Here, said a coordinator already existed: the Office of Science and Technology Policy (OSTP) co-chairs the interagency body behind the strategy and, per 's own conclusion, is already the lead organization coordinating interagency science policy. The gap was in the strategy documents themselves -- missing objectives, resources, and defined roles -- not in who was supposed to be in charge. recommended OSTP update those documents. Like ONCD before it, OSTP neither agreed nor disagreed with the recommendation, though it said it had no concerns about the recommendation's wording.
The workforce side of the strategy showed a similar pattern of partial progress. The interagency body responsible, in its initial assessment, identified two gaps: no comprehensive data on the many occupational fields the quantum workforce spans, and no metrics for judging whether training programs actually work. An -funded study already underway could start closing those gaps, agency officials told , as long as it proceeds and gets the appropriations it needs.
The takeaway
- used the exact same scorecard on two related strategies, 16 months apart, and found two different partial-credit results. Zero of six characteristics fully addressed for the cybersecurity-threat strategy in 2024; two of six for the R&D strategy in 2026.
- The two gaps had different root causes. In 2024, no office was clearly in charge of the cybersecurity strategy at all -- recommended ONCD fill that vacuum. In 2026, OSTP already led the R&D strategy's coordination; the gap was in the strategy documents themselves, which hadn't caught up to fully define objectives, resources, and roles.
- Both recommendations got the same noncommittal response. Neither ONCD nor OSTP agreed or disagreed with 's fix. Whether either office actually takes on the coordinating role is the open question both reports leave behind.
The cybersecurity-strategy findings are from -25-107703, 'Future of Cybersecurity: Leadership Needed to Fully Define Quantum Threat Mitigation Strategy' (November 21, 2024), read directly and in full via an archived copy. The R&D-strategy findings are from -26-107759, 'Quantum Computing: Updating the National Strategy Could Promote U.S. Leadership' (March 18, 2026), also read directly and in full. The two reports examine distinct facets of federal quantum-computing policy -- defending against the technology's cryptographic threat versus advancing the technology itself -- using 's identical six-characteristic framework for evaluating national strategies, about 15.8 months apart.
Sources(2) ▾
- U.S. Government Accountability Office, Future of Cybersecurity: Leadership Needed to Fully Define Quantum Threat Mitigation Strategy (2024-11-21) — -25-107703, a Q&A report to a Senate Homeland Security subcommittee -- the cybersecurity-threat facet, examining the U.S. strategy for migrating to post-quantum cryptography before a cryptographically relevant quantum computer emerges. Distinct from doc-gao26-107759 (the quantum-computing R&D and workforce strategy facet), issued about 16 months later. Both use 's identical six-characteristic framework for evaluating national strategies. Direct gao.gov fetch returned HTTP 403; fetched via an existing Wayback capture. gao.gov · original document
- U.S. Government Accountability Office, Quantum Computing: Updating the National Strategy Could Promote U.S. Leadership (2026-03-18) — -26-107759, a report to the Ranking Member of the Joint Economic Committee -- the R&D and workforce-strategy facet, examining the National Quantum Initiative's quantum-computing strategy and workforce assessment. Distinct from doc-gao25-107703 (the quantum-cybersecurity-threat facet), issued about 16 months earlier. Both use 's identical six-characteristic framework for evaluating national strategies. Fetched directly from files.gao.gov (HTTP 200); no Wayback capture needed since the mirror was directly reachable. gao.gov · original document
Comments
Always open. Logged-in readers can annotate paragraphs in place.
has a standard six-point framework for judging whether a national strategy is built to succeed: does it define its purpose and methodology, assess risk, set objectives and performance measures, specify resources, assign roles, and integrate with other efforts. In November 2024⧉, applied that framework to the U.S. strategy for migrating away from cryptography a future quantum computer could break, and found every one of the six characteristics only partially addressed. In March 2026⧉, applied the same framework to the separate strategy for advancing quantum computing as a technology, and found two characteristics fully addressed and four still partial.