At least 64.5% of the post-quantum results in our European scan cohort belong to a CDN edge rather than to the organization being measured. That is 309 of 479 post-quantum-positive targets, across 1,244 classified hosts in eighteen sectors. The number is a floor.
This measures attribution, not posture. A scan finds ML-KEM on a bank’s hostname. That hostname terminates at Akamai. The bank’s own serving stack was never in the handshake. What runs between the edge and the origin is not reachable from outside, so its cryptography is unobservable rather than absent. Every row we publish says so: an edge-attributed target carries no claim about its origin.
Cloudflare hit the same limit from inside, which we covered in February and March. Radar now shows roughly 10% of Cloudflare-customer origins supporting post-quantum key agreement against more than 60% of client-side requests, and Cloudflare can measure both legs because it sits in the path. Nobody outside can.
Three passes, three numbers
We classified each target by whether a recognized edge vendor terminates the observed handshake. The signals are delegation into a vendor’s DNS zone, an address inside a vendor’s published range, a vendor name on the presented certificate, reverse records on the resolved addresses, and registry attribution of the address block. Two agreeing signals count as confirmed. One counts as probable. Signals naming different vendors count as undecided.
The method was revised twice. Each revision raised the number.
| Method | Signals | Attributable to edge |
|---|---|---|
| First pass | DNS delegation, published ranges, certificate | 42.4% |
| Second pass | plus reverse DNS | 55.7% |
| Third pass | plus registry attribution | 64.5% |
An apex domain cannot carry a CNAME record. 1,026 of our 1,363 targets are apex domains, and none of them returned one. Delegation could not see three quarters of the cohort, and that absence looked the same as evidence of no edge. Reverse DNS covered those targets, and Akamai went from 5 to 60.
Twenty-four post-quantum-positive targets resolved into a single address block, and all twenty-four counted as the organization’s own infrastructure. The block is registered as THALES-IMPERVA-NA4-AGG. Imperva publishes no address-range list and sets no reverse records there, so neither earlier method could see it. Registry data moved Imperva from 10 targets to 44 across three registered blocks, Link11 from 0 to 7, Myra from 1 to 5, and Akamai from 60 to 64.
All three passes ran against one scan snapshot. Running the second pass against a snapshot taken a week earlier gives 56.1% rather than 55.7%, entirely in the denominator, so the movement is 8.8 points of new detection against 0.4 points of drift. High-confidence attributions rose from 48 to 267, because registry data gives a second signal to vendors that had only one.
Why the floor keeps rising
Three method steps, each one finding vendors that were there and had been missed. The figure is at least 64.5%, not 64.5% exactly.
The method misses in one direction only, for three reasons. It covers CDN and edge-delivery products, so a cloud load balancer in front of an organization’s own workload is excluded. A vendor outside our table is not counted. And registry attribution misses a vendor that serves customers from address space registered to those customers. Nothing in the method can push the number down.
Every improvement in detection has raised the share that belongs to somebody else’s infrastructure. The third pass is unlikely to be the last.
The sector cut
85.9% of post-quantum-positive finance targets are edge-attributed, 61 of 71. These are DORA-regulated entities whose measured post-quantum posture terminates at a supplier.
Forty-nine of those 61 sit with US-headquartered vendors: Akamai 27, Cloudflare 15, Fastly 4, CloudFront 3. Eleven are with Imperva, which is US-based and French-owned through Thales. One is with German Myra.
Public-sector targets are edge-attributed at 55.0%, 33 of 60. The vendor mix inverts: Cloudflare 22, Myra 3, Akamai 3, Fastly 2, CloudFront 2, Imperva 1. European public administration serves its own stack more often than European finance does, by thirty-one points, measured the same week by the same method.
What the largest vendor cannot see
Cloudflare was detected at 138 targets by the first pass and at 138 by the third. Reverse DNS added nothing. Registry data added nothing. Published address ranges and certificate evidence had already found every one of them.
The vendors the later passes found are Imperva, Link11, Myra, and Akamai. Those are the ones that publish no range list, and the ones Cloudflare cannot see, because Cloudflare observes only traffic crossing Cloudflare. An industry-wide edge metric built on the largest vendor’s own data is most reliable for that vendor’s own customers and least reliable for everyone else, including the European providers a sovereignty assessment needs to see.
Of 33 edge-attributed public-sector targets, 22 are Cloudflare and 3 are Myra. A measurement taken from Cloudflare’s vantage would show the 22 and would not know the German provider exists.
The supplier question
None of this argues against using a CDN. Edge termination is a reasonable architecture and often the fastest route to post-quantum key agreement for external traffic. For an edge-fronted service, the cryptography between the edge and the origin cannot be established from outside by anyone, including your auditor and including us. That leg is answerable through contract, attestation, or configuration evidence from the supplier.
The practical step is knowing which of your services are in that position. A scan tells you which hostnames terminate at a supplier and which terminate on infrastructure you control. [PQ]probe reports both, per host, with the origin leg marked unobservable rather than counted as compliant.
The trajectory is what to plan around. The figure has risen every time the measurement improved, and the next improvement will very likely raise it again.
Method: 1,363 published targets across eighteen sectors, scanned from a fixed European vantage. 1,244 had a current visible scan. Classification uses DNS delegation, published vendor address ranges, leaf certificate names, reverse DNS, and RDAP registry attribution, with two agreeing independent signals required for high confidence. Registry owner names are matched token-exact against a reviewed per-vendor alias list, so an embedded vendor name such as THALES-IMPERVA matches Imperva while PALMYRA does not match Myra. Edge attribution carries no claim about origin posture in either direction.
Sources:
- The Edge Is a False Floor: What PQC Adoption Numbers Actually Measure
- Cloudflare Can’t Fix the False Floor
- Cloudflare Radar origin post-quantum tracking
- Cloudflare published IP ranges, Fastly public IP list, AWS IP ranges (CLOUDFRONT service tag)
- IANA RDAP bootstrap and the regional registry RDAP endpoints