pqcstatus

Post-quantum adoption observatory

How many major websites already protect their visitors with hybrid post-quantum key exchange? Measured monthly, published as aggregates only.

French retail banks and insurers (customer websites)

Measured in September 2026 · 20 of 20 websites reachable

Hybrid post-quantum key exchange60%12/20
Hybrid PQ, excluding sites behind a CDN12.5%1/8
TLS 1.3 enabled85%17/20
Legacy TLS 1.0/1.1 still enabled0%0/20
HSTS enabled85%17/20
Served through a CDN60%12/20
Certificate with RSA-2048 or weaker65%13/20

Certificate keys

  • RSA 2048: 13
  • ECDSA p-256: 4
  • RSA 4096: 3

Large French listed companies (CAC 40 members and recent members)

Measured in September 2026 · 40 of 41 websites reachable

Hybrid post-quantum key exchange77.5%31/40
Hybrid PQ, excluding sites behind a CDN55.6%10/18
TLS 1.3 enabled95%38/40
Legacy TLS 1.0/1.1 still enabled0%0/40
HSTS enabled80%32/40
Served through a CDN55%22/40
Certificate with RSA-2048 or weaker55%22/40

Certificate keys

  • RSA 2048: 22
  • ECDSA p-256: 14
  • RSA 4096: 3

French public services (major government websites)

Measured in September 2026 · 20 of 20 websites reachable

Hybrid post-quantum key exchange65%13/20
Hybrid PQ, excluding sites behind a CDN36.4%4/11
TLS 1.3 enabled100%20/20
Legacy TLS 1.0/1.1 still enabled5%1/20
HSTS enabled50%10/20
Served through a CDN45%9/20
Certificate with RSA-2048 or weaker40%8/20

Certificate keys

  • RSA 2048: 8
  • RSA 4096: 5
  • RSA 3072: 3
  • ECDSA p-256: 2
  • ECDSA p-384: 2

Method: standard TLS handshakes with our open methodology, at most two sites at a time. Only aggregated figures are published, never per-site results. Site owners can opt out. Read the methodology · opt-out