News on 6 October 2026 shows where the move to quantum-safe encryption stands. The US government’s auditor found that none of 24 major federal agencies had fully completed three basic preparation steps [1][2]. The same day, Google’s Chrome 155 began rolling out with post-quantum algorithms that web developers can call directly [3][4], and OpenSSH 10.6 switched on a quantum-resistant signature method for remote logins [9].
Those three are confirmed. A fourth item, from the VPN company Surfshark, is a vendor claim [10]. The audit shows how slow the paperwork is; the releases show tools arriving for those ready to use them.
Why does any of this matter now?
A large enough quantum computer could break the public-key encryption that protects most online traffic and stored data today. No such machine exists yet; GAO notes experts see a low chance of one within ten years, though it could arrive in the 2030s [5][6]. The worry is “harvest now, decrypt later”: data stolen today could be read once one does. So the work of finding and replacing vulnerable encryption has to start years ahead. The replacements are called post-quantum cryptography (PQC).
What did GAO find?
The Government Accountability Office report, Quantum Computing: Federal Actions Needed to Prepare for Emerging Cyber Threat (GAO-27-108740), checked the 24 agencies covered by the Chief Financial Officers Act against three practices drawn from White House budget office (OMB) guidance [1][2]:
- keep a prioritised, annually updated inventory of systems using vulnerable encryption;
- work out the funding needed to switch them;
- test PQC in the agency’s own environment.
None fully addressed all three [1]. Only one agency had a complete inventory of its priority systems; one had no inventory at all, and the other 22 had gaps [2]. By the end of the audit, no agency had tested PQC in its own environment [6]. GAO blames a lack of cryptography expertise, missing processes for inventories and funding estimates, and no plans to guide testing [1].
Two details matter for reading it:
- It is dated. This is the public version of a sensitive report issued in September 2025; GAO says it spent a year with the Office of the National Cyber Director (ONCD) preparing it [1]. The audit itself ran from February 2024 to September 2025 [6]. Agencies may have moved since, and a newer OMB memo requires migration plans by the end of October [5].
- The $7.1 billion figure is not GAO’s. That is an earlier ONCD estimate, given to Congress by OMB, of the cost of moving priority non-security systems to PQC between 2025 and 2035, much of it for replacing old systems that cannot be upgraded [2][6]. GAO found the agency assessments behind it incomplete, so the true cost is uncertain [6].
The sensitive version made 89 recommendations to CISA (the federal cyber agency) and 23 agencies; 12 agencies agreed, and one disagreed with three of its four [5].
What did Chrome 155 add?
Chrome 155 reached the stable channel on 6 October, rolling out to Windows, Mac and Linux over the following days and weeks [3]. Google’s feature tracker lists it as the release that ships new algorithms in the Web Cryptography API, the browser’s built-in toolbox for encryption in web apps [4]:
- ML-KEM (768 and 1024): a NIST-standardised post-quantum method for two parties to agree a secret key;
- ML-DSA (44, 65 and 87): NIST’s post-quantum digital signatures;
- X-Wing: a “hybrid” that pairs ML-KEM-768 with the classical X25519 method [8]; the idea of a hybrid is that an attacker would have to break both;
- ChaCha20-Poly1305: a fast, widely used symmetric encryption method, added alongside them.
Google’s reason: web apps that want PQC today often ship their own code, compiled to run in the browser or written in JavaScript. Now they can use the browser’s own implementation instead [4].
This does not make websites quantum-safe by itself. A developer has to choose to use these functions.
What did OpenSSH and Surfshark add?
OpenSSH, the widely used free software for secure remote logins to servers, released version 10.6 on 6 October [9]. Since version 10.0 it has used a hybrid post-quantum method by default to agree each session’s secret key [9]. That protects recorded traffic against later decryption. It does not stop a future quantum attacker from forging the signatures that prove a server or user is genuine.
Version 10.6 addresses that second step. It enables ssh-mldsa44-ed25519, a hybrid signature that pairs NIST’s ML-DSA-44 with the classical Ed25519 method [9]. Two practical points from the release notes [9]:
- Keys made with OpenSSH’s earlier experimental version of this method (which used an “@openssh.com” suffix) must be regenerated or removed.
- The server now has a WarnWeakCrypto option, on by default, that logs when a client connects using a key-agreement method that is not post-quantum safe. That gives administrators a list of what still needs upgrading, the same inventory step GAO says agencies lack.
Surfshark said on 7 October that its version of the WireGuard VPN protocol now uses ML-DSA for authentication as well as ML-KEM for key exchange, on iOS and macOS first, with other platforms to follow [10]. The company calls the result “fully post-quantum secure” [10]. That is Surfshark’s own claim: its announcement cites no independent audit or published design.
What about website certificates?
That is a separate job. The certificates that prove a site is genuine also rely on vulnerable signatures. In February Google said Chrome has no immediate plan to accept post-quantum versions of today’s certificates, because they are too large. Instead it is developing smaller Merkle Tree Certificates, with wider testing planned for the first quarter of 2027 and a new quantum-resistant root store from the third quarter of 2027 [7]. Those are plans, not delivered features.
What this does not prove
- How ready agencies are today. GAO’s findings reflect an audit that ended in September 2025 [1][6].
- What migration will cost. The $7.1 billion estimate rests on assessments GAO found incomplete [6].
- That Chrome users are now protected. The new tools only help when sites use them [4].
- That Surfshark’s design is sound. “Fully post-quantum secure” is the company’s wording; no independent review is cited [10]. OpenSSH’s new signature method also only helps once keys are generated and servers configured to use it [9].
- When a quantum computer could break today’s encryption. GAO cites expert surveys, not a date [6].
The Bottom Line
The US government is behind on the basics. Its biggest agencies had not finished listing which systems use vulnerable encryption, let alone testing replacements, when GAO audited them [1][2]. Software is moving faster: Chrome 155 gives every web developer built-in post-quantum tools [4], OpenSSH now offers quantum-resistant login signatures and flags connections that are not post-quantum safe [9], while quantum-safe certificates are still planned for 2027 [7]. The lesson for any organisation is GAO’s first step: find out where your vulnerable encryption is.
Related on TSN: Project Eleven Strongpoint: post-quantum custody with Zcash Foundation as partner · Quantum and wallet keys: Europol says the risk is exposed keys, and Ethereum researchers urge a careful move
Sources
- US Government Accountability Office, “Quantum Computing: Federal Actions Needed to Prepare for Emerging Cyber Threat,” GAO-27-108740, 6 October 2026 (product page summary as shown in search index; see source note). https://www.gao.gov/products/gao-27-108740
- “GAO: Federal Agencies Haven’t Fully Prepared for PQC Transition,” MeriTalk, 6 October 2026. https://www.meritalk.com/articles/gao-federal-agencies-havent-fully-prepared-for-pqc-transition/
- Google, “Stable Channel Update for Desktop,” Chrome Releases blog, 6 October 2026. https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html
- Google, “Algorithm Updates in WebCrypto,” Chrome Platform Status (feature 5198951632470016; shipping milestone 155 on desktop and Android), read 8 October 2026. https://chromestatus.com/feature/5198951632470016
- Madison Alder, “Work needed to fortify systems against quantum threats, watchdog says,” FedScoop, 7 October 2026. https://fedscoop.com/agencies-behind-fortifying-systems-against-quantum-threats-watchdog-says/
- “US Cryptographic Inventory Audit: One of 24 Complete,” PostQuantum.com, 6 October 2026. https://postquantum.com/security-pqc/us-cryptographic-inventory-audit/
- Chrome Secure Web Networking Team, “Cultivating a robust and efficient quantum-safe HTTPS,” Google blog, 27 February 2026. https://blog.google/security/cultivating-a-robust-and-efficient-quantum-safe-https/
- WICG, “Implementation Status,” issue #25 on the Modern Algorithms in the Web Cryptography API repository (Chromium entry lists X-Wing as MLKEM768-X25519), read 8 October 2026. https://github.com/WICG/webcrypto-modern-algos/issues/25
- OpenSSH, “OpenSSH Release Notes” (OpenSSH 10.6, released 6 October 2026; OpenSSH 10.0 entry for the default key-agreement change), read 8 October 2026. https://www.openssh.com/releasenotes.html
- Surfshark (edited by Sonia Wilkoszewska), “Surfshark’s WireGuard is now fully post-quantum secure,” Surfshark blog, 7 October 2026. https://surfshark.com/blog/post-quantum-secure-wireguard
Source note: gao.gov returned “Access Denied” to both our fetch tool and a direct request for the product page and report PDF, so GAO’s own summary was read via a search-index copy of the product page, and details were checked against MeriTalk, FedScoop and PostQuantum.com (labelled secondary sources). PostQuantum.com’s author discloses that his firm sells PQC migration services; only its factual summary of the report is used here, not its analysis. The Chrome Releases post (the brief’s link) lists only version numbers and security fixes; the WebCrypto feature and its milestone come from Google’s Chrome Platform Status entry, read via its public API.

