NIS2 Quantum Preparedness Monitor Figures rebuilt 00:01 UTC · scans run every 24h

41.0% of 1,488 NIS2 endpoints negotiate post-quantum key exchange. At the current pace, full migration arrives in 2028.

Sector-by-sector cryptographic posture of public endpoints in NIS2 Annex I and II sectors.

PQ key exchange
41.0%
610 of 1,488 endpoints
Full pass (A/B)
25.7%
382 graded A or B; both need PQ key exchange
Pace · last 30 days
+1.9 pts
≈ +23.1 pts / year · IMPROVING

Pace and projection follow the same 1,239 endpoints throughout. The projection carries their 13-week trend forward; the CNSA 2.0 deadline is 2030.

ABCDF
Loading…

LOW N marks fewer than 30 endpoints. Select a sector or country to see its endpoints sorted A to F: one tile each, or one tile per 10 above 300.

Methodology

What we measure, and what we don't.

Scope
Public endpoints of organisations in NIS2 Annex I and II sectors, from a curated target list. Each host takes its sector from a hostname pattern, or else from its target-list category.
Detected
TLS versions, cipher suites, key-exchange groups including X25519MLKEM768, SecP256r1MLKEM768 and SecP384r1MLKEM1024, and the certificate, on HTTPS, mail and SSH endpoints.
Grades
A to F on the same scale as a single probe. Without post-quantum key exchange a host grades C at best, so A or B requires it.
Cadence
The scheduler starts a full scan cycle every 24 hours; each figure uses a host's latest scheduled scan. The 30-day pace and the projection read a fixed set of endpoints: those already scanned when the history window opens. Per-country government cohorts, starting with the Netherlands, are scanned weekly and stay outside these figures: their trend rests on about four scans a month per host, not thirty, so its slope is not comparable with this one.
Not covered
Internal networks, OT, source code and stored keys. Probes submitted by visitors never enter these figures.

Your inventory, not just your edge.

This monitor sees public endpoints. An assessment covers internal networks, code, keys and OT.