← Latest papers
💻 computer science

Measuring Post-Quantum TLS Deployment Across UK Internet Sectors

This study of 4,665 UK organizations reveals that observable post-quantum cryptography deployment is highly uneven and fragmented, driven primarily by infrastructure provider decisions rather than organizational sector, with significantly higher adoption in HTTPS compared to SMTP and a notable absence of post-quantum certificate signatures.

Original authors: Konstantinos Loizou, Essam Ghadafi

Published 2026-08-04
📖 4 min read☕ Coffee break read

Original authors: Konstantinos Loizou, Essam Ghadafi

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine the internet as a giant, bustling city where every building is a website, an email server, or a cloud service. To keep the doors locked and the secrets safe, these buildings use special digital keys called cryptography. For decades, these keys have been incredibly strong, but scientists have been worried about a future "super-key" that could break them all. This super-key comes from a new kind of computer called a quantum computer, which is still being built but is expected to be powerful enough to crack today's locks. To get ready, experts are designing new, quantum-proof locks called Post-Quantum Cryptography (PQC). The big question for governments and companies is: "Are we actually putting these new locks on our doors yet, or are we just talking about it?" This paper is like a massive, city-wide inspection to see exactly how many buildings in the UK have actually installed these new, futuristic locks on their front doors.

The authors, Konstantinos Loizou and Essam Ghadafi from Newcastle University, decided to take a very specific and clever look at this problem. Instead of just scanning the most popular websites (like checking only the skyscrapers in the city center), they created a balanced map of 4,665 different organizations across ten different sectors, from banks and hospitals to universities and government offices. They checked two main types of "doors": the web (HTTPS, which is the lock you see when you visit a website) and email (SMTP, which is the lock used to send and receive messages). They wanted to see if these organizations were actually using the new quantum-proof key-exchange methods.

Here is what they found, and it's a bit of a mixed bag. First, they discovered that the new locks are showing up, but mostly on the web. About 44% of the reachable websites they checked had at least one of these new quantum-proof keys installed. However, when they looked at email servers, the picture was much gloomier: only about 6.4% of email services had the new keys. It turns out that if an organization has the new lock on its website, it is roughly 17 times more likely to have it on its email server than if it didn't, but even then, most email servers are still using the old, potentially breakable locks.

The most surprising twist in the story is who is actually putting these locks on. You might think that a bank would be very different from a tech company in how fast they upgrade, but the study found that the organization's industry didn't matter as much as who was running the building. It's like realizing that whether a house has a new security system depends entirely on the landlord, not the family living inside. The researchers found that a tiny handful of big infrastructure providers (companies like Cloudflare, Google, and Amazon) were responsible for almost all the new locks they saw. For example, 95% of the websites hosted by Cloudflare had the new keys, while Microsoft-hosted email servers had none. In fact, for email, Google was the only major provider with the new keys, accounting for nearly all the adoption they saw.

The paper also checked the "signatures" on the certificates (the digital ID cards that prove a building is who it says it is). They found that while the keys for the doors were starting to become quantum-proof, the ID cards were still using the old, classical signatures. No one had switched to the new quantum-proof ID cards yet. This suggests that while the front door is getting stronger, the way we verify who is standing there hasn't changed.

In short, the study suggests that when we see a website with a quantum-proof lock, it's often because the big tech company hosting it decided to upgrade, not because the specific organization running the site made a special plan to do so. This means that simply looking at a website and seeing a new lock doesn't necessarily mean the whole organization is ready for the quantum future; it might just mean their landlord is ahead of the curve. The researchers conclude that we need to be careful not to mistake these visible upgrades for a complete, organization-wide migration, as the email systems and the digital ID cards are still waiting in the wings.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →