Skip to content
Observatory

The state of post-quantum readiness on the web

Each day we measure fixed panels of public hosts for hybrid key exchange (X25519MLKEM768), certificate posture, and whether they offer and honour session resumption, then publish the trend. Read-only handshakes, a restrained probing policy, and an open methodology.

Web panel · hybrid KEX adoption · 2026-09-08

65.7%

46 of 70 reachable hosts negotiated X25519MLKEM768

Updated 2026-09-08

46

Migrated

23

Classical

1

Regressed

0

Unreachable

Session resumption

69of 70

Issues a ticket

Offers resumption at all, after one HEAD request.

41of 70

Without being asked

Sends the ticket on a connection that sends no request.

60of 69

Resumes when offered

Accepts its own ticket back at the same address and SNI.

Each count is shown over the hosts that were actually asked, because the three questions reach three different populations: a host that issues no ticket is never offered one back, so it cannot be said to have refused. Hosts last measured before 28 August 2026 are in none of these counts.

Adoption over time

07-25
07-26
07-27
07-28
07-29
07-30
07-31
08-01
08-02
08-03
08-04
08-05
08-06
08-07
08-08
08-09
08-10
08-11
08-12
08-13
08-14
08-15
08-16
08-17
08-18
08-19
08-20
08-21
08-22
08-23
08-24
08-25
08-26
08-27
08-28
08-29
08-30
08-31
09-01
09-02
09-03
09-04
09-05
09-06
09-07
09-08

Adoption by category

CDN / edge
100% · 4/4
Messaging / privacy
100% · 4/4
News / media
100% · 4/4
Consumer web
67% · 12/18
Measurement / research
67% · 2/3
Developer platform
60% · 6/10
Cloud / SaaS
56% · 9/16
Payments
50% · 1/2
Security / PKI
44% · 4/9

Regression detected

1 host regressed: they spoke post-quantum and stopped. Use the “Regressed” filter below.

70 of 70 hosts

HostStatusGroupTLSCertTicketResumesWhy
cloudflare.comCDN / edgeHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA256yesyes
akamai.comCDN / edgeHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA384yesunaskedyes
fastly.comCDN / edgeHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesunaskedyes
cloudflare-dns.comCDN / edgeHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA384yesyes
amazonaws.comCloud / SaaSClassical-TLSv1.3sha256WithRSAEncryptionyesunaskedno
cloud.google.comCloud / SaaSHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA256yesyes
azure.microsoft.comCloud / SaaSHybridX25519MLKEM768TLSv1.3sha384WithRSAEncryptionyesunaskedyes
digitalocean.comCloud / SaaSHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA384yesyes
heroku.comCloud / SaaSClassical-TLSv1.3ecdsa-with-SHA384yesunaskedyes
vercel.comCloud / SaaSHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesunaskedyes
netlify.comCloud / SaaSClassical-TLSv1.3sha256WithRSAEncryptionyesunaskedno
wordpress.comCloud / SaaSHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA384yesunaskedyes
shopify.comCloud / SaaSHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA256yesyes
salesforce.comCloud / SaaSHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA384yesunaskedyes
oracle.comCloud / SaaSClassical-TLSv1.2sha256WithRSAEncryptionno-
ibm.comCloud / SaaSHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA384yesunaskedyes
adobe.comCloud / SaaSClassical-TLSv1.3ecdsa-with-SHA384yesunaskedyes
dropbox.comCloud / SaaSClassical-TLSv1.3ecdsa-with-SHA384yesyes
slack.comCloud / SaaSClassical-TLSv1.3sha256WithRSAEncryptionyesyes
zoom.usCloud / SaaSHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesyes
letsencrypt.orgSecurity / PKIClassical-TLSv1.3ecdsa-with-SHA384yesunaskedno
digicert.comSecurity / PKIHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesunaskedyes
sectigo.comSecurity / PKIClassical-TLSv1.2sha256WithRSAEncryptionyesunaskedno
globalsign.comSecurity / PKIRegressed-TLSv1.2sha384WithRSAEncryptionyesunaskedyes
okta.comSecurity / PKIHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesunaskedyes
auth0.comSecurity / PKIHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA384yesyes
crowdstrike.comSecurity / PKIHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA256yesyes
paloaltonetworks.comSecurity / PKIClassical-TLSv1.3sha256WithRSAEncryptionyesyes
fortinet.comSecurity / PKIClassical-TLSv1.3sha256WithRSAEncryptionyesunaskedyes
signal.orgMessaging / privacyHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA256yesyes
proton.meMessaging / privacyHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesyes
telegram.orgMessaging / privacyHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesunaskedno
discord.comMessaging / privacyHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA256yesyes
stripe.comPaymentsClassical-TLSv1.3ecdsa-with-SHA384yesunaskedno
paypal.comPaymentsHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesunaskedyes
github.comDeveloper platformClassical-TLSv1.3ecdsa-with-SHA256yesunaskedno
gitlab.comDeveloper platformHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesyes
stackoverflow.comDeveloper platformHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA384yesyes
npmjs.comDeveloper platformHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA256yesyes
nodejs.orgDeveloper platformHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesyes
python.orgDeveloper platformHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesunaskedyes
kernel.orgDeveloper platformClassical-TLSv1.3ecdsa-with-SHA384yesunaskedyes
debian.orgDeveloper platformHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesunaskedyes
ubuntu.comDeveloper platformClassical-TLSv1.3sha256WithRSAEncryptionyesunaskedyes
mozilla.orgDeveloper platformClassical-TLSv1.3sha256WithRSAEncryptionyesyes
censys.ioMeasurement / researchHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA384yesyes
shodan.ioMeasurement / researchHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA256yesyes
ssllabs.comMeasurement / researchClassical-TLSv1.3sha256WithRSAEncryptionyesunaskedyes
google.comConsumer webHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA256yesyes
youtube.comConsumer webHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA256yesyes
facebook.comConsumer webHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesunaskedyes
instagram.comConsumer webHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesunaskedyes
x.comConsumer webHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesyes
linkedin.comConsumer webClassical-TLSv1.3sha256WithRSAEncryptionyesyes
wikipedia.orgConsumer webHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA384yesunaskedyes
reddit.comConsumer webHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesunaskedyes
amazon.comConsumer webClassical-TLSv1.3sha256WithRSAEncryptionyesunaskedyes
apple.comConsumer webHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA256yesyes
microsoft.comConsumer webHybridX25519MLKEM768TLSv1.3sha384WithRSAEncryptionyesunaskedyes
netflix.comConsumer webClassical-TLSv1.3ecdsa-with-SHA384yesyes
ebay.comConsumer webHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesunaskedyes
yahoo.comConsumer webClassical-TLSv1.3sha256WithRSAEncryptionyesunaskedyes
bing.comConsumer webClassical-TLSv1.3sha384WithRSAEncryptionyesunaskedno
duckduckgo.comConsumer webHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesunaskedno
spotify.comConsumer webClassical-TLSv1.3sha256WithRSAEncryptionyesyes
twitch.tvConsumer webHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesunaskedyes
cnn.comNews / mediaHybridX25519MLKEM768TLSv1.3ecdsa-with-SHA384yesunaskedyes
bbc.comNews / mediaHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesunaskedyes
nytimes.comNews / mediaHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesunaskedyes
theguardian.comNews / mediaHybridX25519MLKEM768TLSv1.3sha256WithRSAEncryptionyesunaskedyes

Methodology

Once a day we open two or three read-only TLS connections to each host in a fixed public panel. The first sends nothing at all, and records whether the server selects the hybrid group X25519MLKEM768, the negotiated TLS version, the leaf certificate’s signature algorithm and expiry, and whether it volunteers a session ticket. Hosts that volunteer none get a second connection carrying a single HEAD /, because many servers withhold a ticket until a request arrives. The last connection offers that ticket back, to the same address and the same server name that issued it, and records whether the server resumes. We send no credentials, we never offer a ticket to a host that did not issue it, we honor connection refusals, and we do not attempt any exploitation. This is the same class of measurement public scanners such as SSL Labs and Censys perform.

The panel and the probing policy live in the open-source pqc-observatory repository, where anyone can propose a host. To have a host removed from the panel, open a pull request or contact [email protected] and we will drop it within one measurement cycle.

Full methodology, and what this number is not →