US Agencies Had Until May 2023 to Inventory Quantum-Vulnerable Cryptography. Auditors Found One of 24 Inventories Complete.
Table of Contents
October 6, 2026 – The U.S. Government Accountability Office (GAO), the audit agency that reports to Congress, released the public version of its audit of how 24 federal agencies had prepared for the move to post-quantum cryptography (PQC). The audit, Quantum Computing: Federal Actions Needed to Prepare for Emerging Cyber Threat, ran from February 2024 to September 2025. It found that none of the 24 agencies had fully carried out three preparatory practices that GAO drew mainly from guidance the Office of Management and Budget (OMB) issued in November 2022.
Those practices were a prioritized cryptographic inventory of systems that use quantum-vulnerable algorithms, an estimate of the funding needed to migrate them, and tests of PQC in agency environments. One agency’s inventory of its priority systems passed all of GAO’s completeness checks. Of the six agencies GAO examined in depth, none could produce documents supporting the algorithms listed for every system GAO sampled, and by the end of the audit no agency had tested PQC in its own environment.
GAO conducted the review at the request of Senator Maggie Hassan, the ranking member of the Joint Economic Committee. The report, GAO-27-108740, is the public version of a sensitive report GAO issued on September 11, 2025, in which it made 89 recommendations to the Cybersecurity and Infrastructure Security Agency (CISA) and 23 of the 24 agencies. GAO made no new recommendations in the public version.
How GAO Assessed the Agencies
GAO audited the 24 agencies covered by the Chief Financial Officers Act, a group that includes every cabinet department. It built its evaluation framework mainly from OMB Memorandum M-23-02 and supplemented it with its own earlier work on IT transition planning.
M-23-02 directed agencies to send a prioritized inventory of systems containing quantum-vulnerable cryptography, excluding national security systems, to the Office of the National Cyber Director (ONCD) and CISA by May 4, 2023, and every year after that until 2035. The inventory was to cover high value assets, high-impact systems, systems holding data expected to remain mission-sensitive in 2035, and logical access control systems built on public-key cryptography. For each system, agencies were to list every vulnerable cryptographic system in active use, with its algorithm, the service it provides and its key length, along with the software type, operating system and hosting arrangement.
To test completeness, GAO compared each inventory with the high-impact systems and high value assets the agency had listed in its own cybersecurity metrics reports. It also tested the inventories electronically for missing data and reviewed them by hand for obvious errors.
To test accuracy, GAO randomly selected six agencies, two from each third of the 24 agencies ranked by IT budget. From each of their inventories it selected three systems, one from each of three groups: high value assets, high-impact systems, and other systems the agency had judged particularly vulnerable to a quantum attack. It asked officials for documentation, such as reports from automated discovery tools, supporting the algorithms listed for each system. One of the six agencies had no inventory, which left 15 systems at five agencies.
Inventory Completeness and Accuracy
One of the 24 agencies had a complete inventory of its priority systems, 22 had partial inventories and one had none. Most agencies left some of their high value assets out of their inventories, and a majority of them left out some of their high-impact systems. A majority also did not include or consider systems holding data expected to remain sensitive in 2035, or access control systems based on public-key infrastructure.
For the inventory practice as a whole, GAO rated one agency as having fully addressed it, 21 as partially, one as minimally and one as not at all. For funding, GAO rated 21 agencies as having partially addressed the practice and three as not having addressed it. For testing, it rated one agency as having partially addressed the practice and the other 23 as not having addressed it.
GAO counted an inventory as complete on algorithms if it named one or more vulnerable algorithms for each system it listed. Several inventories had no algorithm entry for at least one priority system. Several reported symmetric algorithms as vulnerable to a quantum computer, although OMB had told agencies to report only public-key algorithms.
None of the six agencies GAO sampled fully met its accuracy test. Two agencies provided documents supporting the algorithms for some of the sampled systems. Three provided no documents supporting the algorithms for any sampled system, and the sixth had no inventory.
Four of the six agencies partly supported the software, operating system and hosting details in their sampled entries. The other two supported none of them.
Reasons GAO Gave for the Inventory Gaps
GAO attributed the inventory gaps to a lack of cryptography expertise, documented processes and automated tools. Eighteen agencies reported lacking expertise in cryptography and in building the inventories, and none of the 18 had a plan to close that gap. Twenty-three agencies lacked a documented process for maintaining their inventories.
Nineteen agencies used no automated tools to find or verify the data in their inventories. Officials at 15 agencies said it was too early to use such tools or that they were waiting for CISA to identify suitable ones. CISA officials told GAO they had not told agencies to wait.
CISA said it had worked with the National Institute of Standards and Technology’s National Cybersecurity Center of Excellence since 2024 on use cases for vendor discovery tools, and that it expected to release its assessment of those tools by December 2025. ONCD officials told GAO that automated tools had never been a policy requirement and could not complete an inventory on their own.
One department did not address the inventory activities at all. Its officials told GAO that the department’s unclassified systems support more than 4 million endpoints and that identifying the cryptography embedded in their applications is very challenging. GAO found the department had no plan for the task, and its officials said a forthcoming PQC strategy would describe their approach.
Funding Assessments and the $7.1 Billion Estimate
M-23-02 required each agency to send ONCD and OMB an assessment of its migration funding needs within 30 days of each inventory. Twenty-one of the 24 agencies produced partial assessments that fell short of GAO’s test, and the other three had none.
Only one assessment was based on a complete inventory of priority systems. All 21 agencies with assessments acknowledged that their figures were not fully accurate, after which GAO did no further testing of the assessments. Eleven agencies said it was difficult to estimate costs when vendors offered no PQC products, and ONCD officials said agencies had been instructed to project historical program costs forward to build a rough baseline.
OMB used the assessments to give Congress an ONCD-developed estimate, in its July 2024 Report on Post-Quantum Cryptography, that migrating prioritized systems other than national security systems from 2025 to 2035 would cost about $7.1 billion in 2024 dollars. OMB and ONCD representatives told GAO the assessments were reliable for that rough-order purpose.
PQC Testing in Agency Environments
M-23-02 encouraged agencies to work with software vendors to find candidate environments for testing PQC. One agency did market research on vendor implementations it could test, but none of the 24 had tested PQC in its own environment by the end of the audit. Sixteen agencies said it was too early because vendors were still adding the new algorithms to their products.
ONCD officials told GAO that testing was voluntary and that most agencies lacked the expertise or resources for it. They added that open-source libraries alone are insufficient for government systems, because they offer no compliance tracking, are often research-grade and lack external audits. GAO disagreed on the first point, writing that OMB’s guidance did not describe testing as voluntary and that open-source tools such as Open Quantum Safe had been available for at least four years.
What OMB, ONCD and CISA Told GAO
OMB officials told GAO they had held technical assistance meetings with some agencies on missing items and data errors, and that they intended to issue guidance addressing the weaknesses GAO found. ONCD officials said the inventory had been designed as an annual, iterative process that would gain detail over several years. CISA officials said manual inventories are a necessary part of the migration and that automated tools would show what manual work misses.
OMB did not respond to GAO’s request for comments on its preliminary results. OMB and the Department of the Interior were the only agencies that did not respond to the sensitive report. ONCD officials told GAO during the audit that OMB expected to issue PQC migration guidance around summer 2025.
Recommendations and Agency Responses
Of the 23 agencies that received recommendations in the sensitive report, 12 agreed in full, two in part and seven neither agreed nor disagreed. One agency disagreed with three of its four recommendations, and the Department of the Interior did not respond. GAO said all of its recommendations remain warranted.
In a letter dated December 17, 2025, reprinted in the report, the Social Security Administration said it agreed with the recommendations and had updated its process to collect cryptographic information through its governance, risk and compliance tool. It added that a review of its inventory of information systems “revealed that none currently use vulnerable cryptographic algorithms,” and that it would develop transition plans “once Post-Quantum Cryptography resistant algorithms become widely available for our information systems.” NIST published its first three PQC standards in August 2024.
The Department of Homeland Security wrote that it had responded to five recommendations in the sensitive report and remained committed to quantum readiness for its systems, including high value assets and high-impact systems. GAO worked with most of the agencies on the public version until January 2026 and with ONCD until September 2026.
Policy Changes Since the Audit
President Trump signed Executive Order 14412 on June 22, 2026. The order directed OMB to require agencies to move their high value assets and high-impact systems, other than national security systems, to PQC by December 31, 2030, for key establishment and by December 31, 2031, for digital signatures. It gave the Department of Homeland Security, through CISA and in coordination with NIST, 270 days, until March 19, 2027, to publish guidance on the minimum elements of a cryptographic bill of materials (CBOM).
OMB issued Memorandum M-26-15 two days after the order. Each agency must submit a PQC migration plan to OMB and ONCD within 120 days, by October 22, 2026, including the methods and automated tools used for its cryptographic inventory and an estimate of the funding and personnel it needs.
On January 23, 2026, CISA published a list of product categories in which PQC-capable products are widely available. It said organizations should acquire only PQC-capable products in those categories. Executive Order 14306 of June 2025 had required the list by December 1, 2025.
GAO’s Assessment of the Quantum Threat
GAO’s first objective was to describe the threat a cryptographically relevant quantum computer (CRQC) poses to federal systems. GAO wrote that such a machine could be used to forge authentication credentials and to decrypt data that adversaries collect and store today, the harvest-now, decrypt-later risk.
GAO cited a December 2024 Global Risk Institute survey of 32 experts, 21 of whom put the probability of a CRQC by 2040 at 50 percent or higher, and it said a CRQC could arrive as soon as the 2030s. In GAO’s reproduction of the survey, 22 of the 32 experts put the chance of a CRQC within 10 years below 30 percent, while the other 10 put it at 50 percent or higher. A GAO footnote put the number of physical qubits needed to derive a private key from a public key at about 10 million, citing a 2019 National Academies report and a 2023 RAND working paper. In its conclusions, GAO wrote that experts consider the probability of a CRQC within the next 10 years low.
My Analysis
For years I have said at conferences, and written here since 2022, that barely any agency, company or regulator asking for a comprehensive cryptographic inventory understands the size of what it is asking for. In my 2022 article on manual cryptographic inventories, I argued that asking asset owners, developers and IT staff to report every use of cryptography rarely produces a complete picture at enterprise scale. In 2024 I wrote that a truly complete inventory may take years of effort in a big organization. GAO has now checked the result at 24 federal agencies, and the office that set the requirement had called that result comprehensive. I know of no other published audit that tested mandated PQC inventories against the submitting organizations’ own records and then asked for the evidence behind sampled entries.
I care more about GAO’s method than its scores. US agencies must submit their PQC migration plans to OMB by October 22, and the Saudi Central Bank (SAMA) expects the banks it supervises to have accurate and comprehensive inventory procedures by December 31. Both supervisors could run GAO’s checks on records the submitting organizations already hold, without commissioning a new discovery scan.
Disclosure: Applied Quantum sells cryptographic discovery and PQC migration services and publishes the PQC Migration Framework and the CBOM Profile mentioned below. I founded and teach at Quantum Academy, whose discovery course is also mentioned below.
How GAO Tested the Inventories
I count four checks in GAO’s method.
- An independent denominator. GAO compared each inventory with the high value assets and high-impact systems the agency had already listed in its cybersecurity metrics reports, a list compiled for another purpose.
- Empty fields. GAO tested electronically for priority systems with no algorithm, software type, operating system or hosting entry.
- Obvious errors. GAO reviewed the entries by hand and found symmetric algorithms reported as quantum-vulnerable, against OMB’s instructions.
- Evidence behind a random sample. At each sampled agency, GAO picked one system from each of three groups, high value assets, high-impact systems and other systems the agency considered particularly exposed, and asked for the documents behind each entry, such as discovery-tool reports.
None of the four checks requires access to a production system. Most inventories failed the first, leaving out some of the high value assets their own agencies had already reported. At three of the five sampled agencies that had inventories, officials supplied no documents supporting the algorithms reported for any sampled system.
Because none of the six sampled agencies passed the accuracy test, GAO’s ratings, read together, place the one inventory that passed all of its completeness checks outside the sample. That inventory’s rating says nothing about whether the algorithms it lists match the systems. GAO’s completeness checks also stop at the system level: an inventory passed if it named the right systems and entered at least one vulnerable algorithm against each.
OMB Called the Inventory Comprehensive in 2023
In December 2023, Nick Polk, then a senior adviser to the federal chief information security officer at OMB, said the civilian government had for the first time “a comprehensive inventory of our asymmetric cryptography” across its agencies and their critical systems. He acknowledged that the first submissions were imperfect and said the process would improve each year.
GAO began its audit two months later and found that most inventories left out some of the high value assets the same agencies had reported elsewhere. GAO’s first check needed nothing more than those lists, which agencies already report as part of their cybersecurity metrics. GAO’s report describes no such reconciliation by OMB, ONCD or CISA before GAO ran its own. OMB told GAO it had held technical assistance meetings with some agencies on missing items and data errors, so OMB knew the submissions had problems.
OMB’s June 2026 memo assumes the inventories. M-26-15 states that agencies “have already identified legacy systems” through them for which migration would be too difficult or costly. That may be true of the systems the inventories contain. GAO’s finding concerns the systems they left out, and GAO had issued its sensitive report, after sending OMB a draft for comment, nine months before the memo.
What GAO Did Not Measure
M-23-02 told agencies that an information system often contains several cryptographic systems and asked them to list every vulnerable one in active use. It never asked how much of each system’s cryptography an inventory had covered, and GAO had no way to measure that from the submissions. An inventory counted as complete on algorithms when each listed system had at least one vulnerable algorithm entered against it.
Comparing an inventory with the documents an agency supplies, as GAO did in its accuracy test, can expose unsupported entries and some omissions, when a configuration export or a discovery report names an algorithm the inventory left out. It cannot establish that every cryptographic use inside a system has been found. A library compiled into a custom application, a key exchange inside appliance firmware or a protocol a cloud provider runs on the agency’s behalf appears in the evidence only if someone looked for it.
For software, operating system and hosting details, GAO compared the inventories with documents such as system security plans, so the evidence was one agency record checked against another. A separately collected configuration export supports an entry. An architecture description copied from the same source as the inventory does not.
An auditor can establish from paperwork whether an inventory names the right systems, as GAO did. Establishing whether it names the cryptography inside those systems takes discovery. In my PQC Migration Framework, discovery runs in five layers: network traffic analysis, scans of source code, configuration and certificate scanning, analysis of running processes and binaries, and manual investigation for what the tools miss.
I think the department that told GAO it could not identify the cryptography embedded across more than 4 million endpoints gave the most accurate description of the problem anywhere in the report. GAO faulted it for having no plan, and on that point GAO is right.
SSA Told GAO That None of Its Systems Use Vulnerable Cryptography
The Social Security Administration’s letter, dated December 17, 2025 and reprinted as Appendix V, is the most revealing page in the report. SSA agreed with GAO’s recommendations and said it now collects cryptographic information through its governance, risk and compliance tool. It then wrote that a review of its FISMA system inventory “revealed that none currently use vulnerable cryptographic algorithms,” and that it would develop transition plans “once Post-Quantum Cryptography resistant algorithms become widely available.”
OMB’s list of quantum-vulnerable algorithms, in M-23-02 and again in M-26-15, names RSA, ECDSA and Diffie-Hellman in both its classic and elliptic-curve forms. Every TLS connection to an internet-facing website today uses at least one of them, because the publicly trusted certificate authorities issue RSA and ECDSA certificates and, as of today, no post-quantum ones. SSA’s own website, where Americans file benefit claims, runs over TLS. I can think of three readings of SSA’s sentence: its review excluded the systems that terminate TLS, its reviewers read “vulnerable” as broken today rather than breakable by a CRQC, or its GRC tool records what system owners type in. Each describes an agency that did not understand the question, 16 months after NIST standardized the algorithms SSA says it is waiting for. CISA published its list of categories with widely available PQC products five weeks after SSA signed the letter.
GAO reprinted the letter without comment and summarized it in the body of the report as an update to SSA’s collection process and a promise of plans once the algorithms become available. GAO’s fieldwork had ended in September 2025, so the claim arrived too late to be audited. It is now in a public GAO report, and SSA’s migration plan is due at OMB on October 22.
Why Agencies Submitted Inventories They Could Not Support
GAO doesn’t say any agency gamed the exercise, and I won’t either. GAO attributes the gaps to missing expertise, process and tools, and I agree with that reading. Eighteen agencies said they lacked cryptographic expertise, and several reported symmetric algorithms as quantum-vulnerable, a mistake few cryptographers would make.
OMB designed the exercise in a way that made GAO’s findings likely. M-23-02 specified what agencies had to inventory and listed the fields each entry needed. The published memo did not say what evidence agencies should keep or submit to substantiate an entry, and ONCD later told GAO that automated tools had never been a requirement. Meeting the May 4 deadline and showing that the inventory met the requirements were two different things.
Many agencies told GAO it was too early. Fifteen said it was too early for automated tools or that they were waiting for CISA, which says it never told them to wait. Fourteen said it was too early to document how they would estimate costs, and 16 said the same about testing PQC.
Banks have no CISA tool assessment to wait for, and I see the same pattern there. In Saudi Arabia, as I wrote last month, some banks facing SAMA’s December 31 deadline have commissioned interview-based inventories that, from what I hear, they expect to be inaccurate. OMB set a date without saying what evidence it would accept and received inventories that, where GAO checked, mostly could not be traced to evidence. SAMA’s circular demands accuracy and comprehensiveness, and it too says nothing about the evidence its examiners will accept.
Why My Framework Starts With a Minimum Viable Inventory
The requirement that produced these inventories asked for everything at once. M-23-02 gave agencies five and a half months to list every vulnerable cryptographic system in active use on their priority systems. M-26-15 asks for “a dynamic, continuously updated inventory of all cryptographic assets.” SAMA gave Saudi banks four months for procedures covering all of theirs. An estate of any size changes faster than a census of it can finish: certificates renew, libraries change with every release, cloud providers alter cipher suites without telling their customers. An organization that sets out to complete the inventory before it acts either stalls, as the department with 4 million endpoints did, or submits what its system owners can type into a spreadsheet, which is what GAO could not trace to evidence.
My PQC Migration Framework asks first for a minimum viable inventory, built architecture-first in four layers, instead of a comprehensive one. Infrastructure cryptography (TLS, SSH and IPsec on load balancers, proxies, VPN concentrators and network devices) and platform cryptography (cloud key services, HSMs, certificate authorities, identity providers) come first, because they carry most of the harvest-now, decrypt-later exposure and can be discovered from the network and from configuration in weeks to months. Application code is scanned next, for the high-risk systems. Embedded and vendor cryptography, where there is no source code and little configuration control, is recorded as incomplete and handled through vendor governance. The framework requires a denominator for every coverage figure and an evidence grade for every finding. A 70 percent inventory with its gaps named is then usable on the day it is produced, and nobody waits for a complete one that cannot be finished. When I wrote that into the framework, I had not seen another migration framework propose it. OMB’s own July 2024 report later called the federal inventory an iterative and ongoing process, which is the same conclusion reached from the other side of the requirement.
It is also why Quantum Academy runs a dedicated course, Cryptographic Discovery, Inventory, and CBOM, because the people are the constraint. Eighteen of the 24 agencies told GAO they lacked cryptographic expertise, and none of the 18 had a plan to acquire it.
OMB’s $7.1 Billion Estimate Came From These Inventories
OMB told Congress in July 2024 that migrating prioritized systems would cost about $7.1 billion from 2025 to 2035. OMB described the figure in that report as a rough order of magnitude with a high but expected level of uncertainty, and said replacing legacy systems that cannot support PQC accounts for a significant portion of it.
GAO found where the uncertainty came from. Only one agency’s funding assessment was based on a complete inventory. All 21 agencies with funding assessments told GAO their figures were not fully accurate, and GAO took them at their word and did no further testing. Agencies had been instructed, according to ONCD, to project historical program costs forward because vendors had no PQC products to price.
Since CISA’s January list of categories in which PQC-capable products are widely available, agencies can no longer cite missing products across the board, though availability in a category does not settle whether a suitable product exists for a given system. In May I wrote about why nobody can tell you what PQC migration costs, and the federal estimate has the same problem at the scale of a government.
I wouldn’t use the $7.1 billion figure as a budget without rebuilding its inputs. OMB presented it as a planning estimate, and the audit does not say how far off the total is, or in which direction. ONCD built it from the agencies’ funding assessments, and GAO found that none of the 24 had a complete and accurate one. M-26-15 has since widened the scope, counting systems whose data must stay sensitive until 2030 where M-23-02 used 2035, and each plan due October 22 must carry a new estimate of funding and personnel.
The New Inventory Requirements in M-26-15 and EO 14412
OMB replaced the request after GAO finished its audit. In M-26-15, OMB asked for a “dynamic, continuously updated inventory of all cryptographic assets,” built with automated tools wherever possible, including software composition analysis of SBOMs, static and dynamic code testing and network scanners, and fed into a central CBOM. Each agency must describe, in the plan due October 22, the methods and automated tools behind its inventory. OMB scheduled inventory work, including high value assets and high-impact systems, for the first phase of the migration in 2026 and 2027.
Under EO 14412, high value assets and high-impact systems outside national security systems must use PQC by December 31, 2030, for key establishment and by December 31, 2031, for digital signatures. Most of the inventories GAO examined left out some of those same systems. The Department of Homeland Security, through CISA and with NIST, has until March 19, 2027, to publish minimum elements for a CBOM, so that the cryptographic assets in hardware and software can be assessed automatically.
OMB hasn’t said in M-26-15 how it and ONCD will check what agencies send. The memo says OMB will assess agency-wide progress with ONCD and issue more guidance as needed. It sets no evidence standard for inventory entries and no coverage measure, and it does not mention sampling. The plans are due about five months before the deadline for the federal CBOM minimum elements, so agencies will write them before a common federal baseline for CBOM content exists.
Congress asked for automated evaluation in 2022. The Quantum Computing Cybersecurity Preparedness Act required OMB’s guidance to include a process for evaluating agencies’ migration progress, “automated to the greatest extent practicable,” and in its 2024 strategy for automated discovery and inventory tools, CISA planned to feed them into its Continuous Diagnostics and Mitigation program (my coverage). The same act gave OMB one year after NIST published its PQC standards in August 2024 to issue migration guidance. ONCD told GAO to expect it around summer 2025, and OMB issued M-26-15 in June 2026.
Outdated Threat Estimates in GAO’s Public Version
GAO worked on the public version for a year after the sensitive report and carried the 2025 audit’s threat analysis forward. GAO took its footnote estimate of about 10 million physical qubits from sources published in 2019 and 2023. Craig Gidney’s May 2025 preprint, which GAO cited only for NIST officials’ view that RAND’s energy estimate could fall tenfold, estimated that a 2048-bit RSA integer could be factored in under a week with fewer than a million noisy physical qubits under the paper’s hardware assumptions (my analysis).
In its conclusions, GAO wrote that experts consider the probability of a CRQC within 10 years low. Its Figure 3 shows the basis: 22 of the 32 experts in the December 2024 survey put the chance within 10 years below 30 percent. The same survey’s averaged 10-year likelihood is 19–34%, depending on how the experts’ answers are read. The Global Risk Institute’s 2025 survey, published in March 2026, gives 28–49% (my coverage). Those are expert estimates, not forecasts, and a probability below even odds can still be far too large to accept. A reader deciding when to start migrating needs those ranges, not the word “low” from GAO’s conclusions.
What Supervisors Can Copy From GAO’s Method
US agencies must submit their migration plans by October 22, and SAMA’s examiners will ask Saudi banks for their inventories after December 31. OMB could run GAO’s checks on the plans and the inventories behind them, and SAMA could run them on what its examiners collect.
- Reconcile against a list compiled for another purpose. For agencies, their own lists of high value assets and high-impact systems. For Saudi banks, the asset register SAMA has required since 2017.
- Test for empty fields and out-of-scope entries, such as the symmetric algorithms several agencies reported as quantum-vulnerable in a return meant for public-key algorithms.
- Ask for evidence behind a random sample, and add systems to it where the first answers are thin. GAO’s three systems per agency were enough to show which agencies could produce evidence at all.
I would add two checks GAO did not run. The first is coverage below the system level, stated against a denominator enumerated before discovery ran and with the unit named, since systems, endpoints, repositories and individual cryptographic uses are different measures. In that coverage figure, the asset classes the discovery method cannot observe are reported as unknown rather than zero. The second is an evidence grade on every finding, showing whether it was observed at runtime, confirmed in a binary, declared in a register, attested by a vendor or inferred from documents. The grade belongs to the claim, because runtime evidence of a negotiated algorithm says nothing about where the code that implements it came from.
Applied Quantum’s CBOM Profile, open for public comment until October 31, records discovery coverage for each service along with the method used to enumerate the estate, and I’d like CISA’s minimum elements to require fields of that kind by March 2027.
Under the 2022 act, OMB owes Congress its first report on agencies’ progress by June 24, 2027, a year after M-26-15, alongside its annual FISMA report. I’ll read it for one thing: whether OMB tested the October plans against evidence before reporting progress on them.
CISOs outside government can rehearse GAO’s evidence check now. If an examiner chose three of your priority systems at random and asked where each inventory entry came from, could you produce dated scanner output or configuration evidence for all three, and say what it does not cover? Three of the five sampled agencies that had an inventory could not.