# Mind the Gap: Policy vs Reality in Post-Quantum TLS Deployment > A research companion explaining an Internet-scale study of post-quantum TLS adoption on public HTTPS endpoints. The site is designed for general readers, while the linked ACM IMC paper provides the full technical methods and results. ## Study overview - Population: one million public HTTPS endpoints targeted - Stable panel: 684,494 domains observed successfully from every vantage point in all three rounds - Measurements: more than two billion TLS 1.3 handshakes - Vantage points: 11 globally distributed measurement locations - Period: July 2025 to March 2026 - Scope: post-quantum key exchange on public HTTPS endpoints, not TLS deployment in every application ## Main pages - [Overview](./index.html): Study scope, measurement locations, headline findings, the research paper, and ACM coverage. - [Background](./background.html): Quantum risk, NIST post-quantum cryptography standards, transition roadmaps, and the study design. - [Configuration landscape](./configuration.html): Chosen and explicitly supported key-exchange groups, including the concentration around X25519MLKEM768 and the absence of verified post-quantum authentication in the stable panel. - [Deployment agency](./deployment.html): Infrastructure concentration and likely provider-managed versus owner-managed deployment. - [Sectoral adoption](./adoption/sectoral.html): Hybrid key-exchange adoption across measured sectors, separated by likely management relationship. - [National adoption](./adoption/national.html): Hybrid key-exchange adoption across country and regional domain samples. - [TLS security](./security.html): TLS versions, cipher suites, certificates, and known vulnerability indicators observed alongside post-quantum key exchange. - [Research team](./team.html): Authors and institutional affiliations. ## Primary sources - [Full research paper](./paper.pdf): Complete methodology, results, limitations, and references. - [Communications of the ACM article](https://cacm.acm.org/news/post-quantum-tls-finished-the-easy-half/): Independent coverage featuring perspectives from Google, Cloudflare, Mozilla, and NIST. ## Authors - Nimesha Wickramasinghe, UNSW Sydney - Frank Li, Georgia Institute of Technology - Sanjay Jha, UNSW Sydney - Arash Shaghaghi, UNSW Sydney ## Citation guidance When describing numerical findings, preserve the population and denominator shown on the relevant page or in the paper. Do not generalize the results beyond public HTTPS endpoints measured during the three study rounds. The latency finding concerns hybrid post-quantum key exchange, not post-quantum authentication.