Growing PQC at the edge belies deeper quantum-readiness challenges
F5 Labs says 54% of top sites offer post-quantum key exchange, but CDN defaults inflate true enterprise readiness.
F5 Labs’ State of PQC on the Web found 54% of the top one million websites support post-quantum key exchange, but the share falls to 22% when Cloudflare-hosted sites are excluded. A June KPMG survey found only 27% of CISOs actively implementing PQC, while 38% rank it a top high-impact emerging threat. Experts say CDN defaults protect only the client-to-edge connection, not origin servers, internal APIs, VPNs, SSH, or enterprise PKI, leaving harvest-now-decrypt-later exposure. More than one in ten sampled sites still lack TLS 1.3, and only 35% of government and telecommunications sites supported post-quantum key exchange.