The state of post-quantum readiness on the web
Each day we measure fixed panels of public hosts for hybrid key exchange (X25519MLKEM768), certificate posture, and whether they offer and honour session resumption, then publish the trend. Read-only handshakes, a restrained probing policy, and an open methodology.
Web panel · hybrid KEX adoption · 2026-09-08
65.7%
46 of 70 reachable hosts negotiated X25519MLKEM768
Updated 2026-09-08
46
Migrated
23
Classical
1
Regressed
0
Unreachable
Session resumption
69of 70
Issues a ticket
Offers resumption at all, after one HEAD request.
41of 70
Without being asked
Sends the ticket on a connection that sends no request.
60of 69
Resumes when offered
Accepts its own ticket back at the same address and SNI.
Each count is shown over the hosts that were actually asked, because the three questions reach three different populations: a host that issues no ticket is never offered one back, so it cannot be said to have refused. Hosts last measured before 28 August 2026 are in none of these counts.
Adoption over time
Adoption by category
Regression detected
1 host regressed: they spoke post-quantum and stopped. Use the “Regressed” filter below.
70 of 70 hosts
| Host | Status | Group | TLS | Cert | Ticket | Resumes | Why |
|---|---|---|---|---|---|---|---|
| cloudflare.comCDN / edge | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | yes | yes | |
| akamai.comCDN / edge | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA384 | yesunasked | yes | |
| fastly.comCDN / edge | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yesunasked | yes | |
| cloudflare-dns.comCDN / edge | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA384 | yes | yes | |
| amazonaws.comCloud / SaaS | Classical | - | TLSv1.3 | sha256WithRSAEncryption | yesunasked | no | |
| cloud.google.comCloud / SaaS | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | yes | yes | |
| azure.microsoft.comCloud / SaaS | Hybrid | X25519MLKEM768 | TLSv1.3 | sha384WithRSAEncryption | yesunasked | yes | |
| digitalocean.comCloud / SaaS | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA384 | yes | yes | |
| heroku.comCloud / SaaS | Classical | - | TLSv1.3 | ecdsa-with-SHA384 | yesunasked | yes | |
| vercel.comCloud / SaaS | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yesunasked | yes | |
| netlify.comCloud / SaaS | Classical | - | TLSv1.3 | sha256WithRSAEncryption | yesunasked | no | |
| wordpress.comCloud / SaaS | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA384 | yesunasked | yes | |
| shopify.comCloud / SaaS | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | yes | yes | |
| salesforce.comCloud / SaaS | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA384 | yesunasked | yes | |
| oracle.comCloud / SaaS | Classical | - | TLSv1.2 | sha256WithRSAEncryption | no | - | |
| ibm.comCloud / SaaS | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA384 | yesunasked | yes | |
| adobe.comCloud / SaaS | Classical | - | TLSv1.3 | ecdsa-with-SHA384 | yesunasked | yes | |
| dropbox.comCloud / SaaS | Classical | - | TLSv1.3 | ecdsa-with-SHA384 | yes | yes | |
| slack.comCloud / SaaS | Classical | - | TLSv1.3 | sha256WithRSAEncryption | yes | yes | |
| zoom.usCloud / SaaS | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yes | yes | |
| letsencrypt.orgSecurity / PKI | Classical | - | TLSv1.3 | ecdsa-with-SHA384 | yesunasked | no | |
| digicert.comSecurity / PKI | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yesunasked | yes | |
| sectigo.comSecurity / PKI | Classical | - | TLSv1.2 | sha256WithRSAEncryption | yesunasked | no | |
| globalsign.comSecurity / PKI | Regressed | - | TLSv1.2 | sha384WithRSAEncryption | yesunasked | yes | |
| okta.comSecurity / PKI | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yesunasked | yes | |
| auth0.comSecurity / PKI | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA384 | yes | yes | |
| crowdstrike.comSecurity / PKI | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | yes | yes | |
| paloaltonetworks.comSecurity / PKI | Classical | - | TLSv1.3 | sha256WithRSAEncryption | yes | yes | |
| fortinet.comSecurity / PKI | Classical | - | TLSv1.3 | sha256WithRSAEncryption | yesunasked | yes | |
| signal.orgMessaging / privacy | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | yes | yes | |
| proton.meMessaging / privacy | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yes | yes | |
| telegram.orgMessaging / privacy | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yesunasked | no | |
| discord.comMessaging / privacy | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | yes | yes | |
| stripe.comPayments | Classical | - | TLSv1.3 | ecdsa-with-SHA384 | yesunasked | no | |
| paypal.comPayments | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yesunasked | yes | |
| github.comDeveloper platform | Classical | - | TLSv1.3 | ecdsa-with-SHA256 | yesunasked | no | |
| gitlab.comDeveloper platform | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yes | yes | |
| stackoverflow.comDeveloper platform | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA384 | yes | yes | |
| npmjs.comDeveloper platform | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | yes | yes | |
| nodejs.orgDeveloper platform | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yes | yes | |
| python.orgDeveloper platform | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yesunasked | yes | |
| kernel.orgDeveloper platform | Classical | - | TLSv1.3 | ecdsa-with-SHA384 | yesunasked | yes | |
| debian.orgDeveloper platform | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yesunasked | yes | |
| ubuntu.comDeveloper platform | Classical | - | TLSv1.3 | sha256WithRSAEncryption | yesunasked | yes | |
| mozilla.orgDeveloper platform | Classical | - | TLSv1.3 | sha256WithRSAEncryption | yes | yes | |
| censys.ioMeasurement / research | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA384 | yes | yes | |
| shodan.ioMeasurement / research | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | yes | yes | |
| ssllabs.comMeasurement / research | Classical | - | TLSv1.3 | sha256WithRSAEncryption | yesunasked | yes | |
| google.comConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | yes | yes | |
| youtube.comConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | yes | yes | |
| facebook.comConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yesunasked | yes | |
| instagram.comConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yesunasked | yes | |
| x.comConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yes | yes | |
| linkedin.comConsumer web | Classical | - | TLSv1.3 | sha256WithRSAEncryption | yes | yes | |
| wikipedia.orgConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA384 | yesunasked | yes | |
| reddit.comConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yesunasked | yes | |
| amazon.comConsumer web | Classical | - | TLSv1.3 | sha256WithRSAEncryption | yesunasked | yes | |
| apple.comConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA256 | yes | yes | |
| microsoft.comConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | sha384WithRSAEncryption | yesunasked | yes | |
| netflix.comConsumer web | Classical | - | TLSv1.3 | ecdsa-with-SHA384 | yes | yes | |
| ebay.comConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yesunasked | yes | |
| yahoo.comConsumer web | Classical | - | TLSv1.3 | sha256WithRSAEncryption | yesunasked | yes | |
| bing.comConsumer web | Classical | - | TLSv1.3 | sha384WithRSAEncryption | yesunasked | no | |
| duckduckgo.comConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yesunasked | no | |
| spotify.comConsumer web | Classical | - | TLSv1.3 | sha256WithRSAEncryption | yes | yes | |
| twitch.tvConsumer web | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yesunasked | yes | |
| cnn.comNews / media | Hybrid | X25519MLKEM768 | TLSv1.3 | ecdsa-with-SHA384 | yesunasked | yes | |
| bbc.comNews / media | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yesunasked | yes | |
| nytimes.comNews / media | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yesunasked | yes | |
| theguardian.comNews / media | Hybrid | X25519MLKEM768 | TLSv1.3 | sha256WithRSAEncryption | yesunasked | yes |
Methodology
Once a day we open two or three read-only TLS connections to each host in a fixed public panel. The first sends nothing at all, and records whether the server selects the hybrid group X25519MLKEM768, the negotiated TLS version, the leaf certificate’s signature algorithm and expiry, and whether it volunteers a session ticket. Hosts that volunteer none get a second connection carrying a single HEAD /, because many servers withhold a ticket until a request arrives. The last connection offers that ticket back, to the same address and the same server name that issued it, and records whether the server resumes. We send no credentials, we never offer a ticket to a host that did not issue it, we honor connection refusals, and we do not attempt any exploitation. This is the same class of measurement public scanners such as SSL Labs and Censys perform.
The panel and the probing policy live in the open-source pqc-observatory repository, where anyone can propose a host. To have a host removed from the panel, open a pull request or contact [email protected] and we will drop it within one measurement cycle.