See what PQC readiness looks like across the market.

Quelea measured organisations across nine industries from the public internet, with nothing installed and no credentials used. The result is an aggregate baseline partners can use to make assessment conversations more concrete.

A visible gap between leading and lagging sectors.

The marker shows the median share of observed services that were PQC-capable. The coloured band shows the middle half of each industry cohort, making variation visible without reducing an organisation to one score.

0%25%50%75%100%
BankingMiddle half 2271%
49%
EducationMiddle half 740%
18%
Energy & utilitiesMiddle half 953%
29%
HealthcareMiddle half 1657%
31%
InsuranceMiddle half 1770%
37%
RetailMiddle half 3072%
50%
TechnologyMiddle half 2467%
39%
TelecommunicationsMiddle half 942%
19%
Travel & hospitalityMiddle half 2873%
51%
Middle 50% of cohortMedian: under 30% · 30–49% · 50% or more

Capability is only one part of readiness.

Protocol versions show where post-quantum key exchange can be introduced. Certificate lifetimes show whether the operating model is prepared for faster, repeatable cryptographic change.

Post-quantum key-exchange readiness by industry

Share of publicly observed services by migration state.

Banking48%
Education28%
Energy & utilities35%
Healthcare38%
Insurance43%
Retail51%
Technology45%
Telecommunications28%
Travel & hospitality51%
Hybrid PQC negotiatedTLS 1.3, classical key exchangeTLS 1.2 — protocol upgrade required

Each bar averages the service split within each organisation, then weights every organisation equally. The PQC figure therefore differs from the industry median above.

Public TLS certificate lifetimes by industry

Distribution of observed certificate validity periods. The value at right is the share at 47 days or fewer, shown to one decimal place.

Banking0.0%
Education0.5%
Energy & utilities0.2%
Healthcare0.3%
Insurance0.1%
Retail0.9%
Technology0.3%
Telecommunications0.1%
Travel & hospitality0.1%
47 days or fewer48–90 days91–365 daysMore than 365 days

CA/B Forum schedule200-day maximum from 15 March 2026100 days from 15 March 202747 days from 15 March 2029

The source buckets do not separate certificates above and below the current 200-day maximum, so this is presented as a lifecycle-automation indicator—not a compliance assessment.

The inventory question changes by industry.

The same discovery method reveals different urgency. Data lifetime, infrastructure turnover and regulatory exposure determine how each client should interpret the baseline.

Banking

Banking carries one of the clearest harvest-now, decrypt-later exposures: payment instructions, account data and counterparty records stay sensitive for years after capture, so traffic recorded today can still be worth decrypting when a cryptographically relevant quantum computer arrives. DORA names cryptographic key management and encryption in transit directly, and NIS2 adds an incident and risk-management layer on top. Evidence of which services already negotiate post-quantum key exchange supports evidence toward both.

DORANIS2
Industry PQC-capable median iThe median share of publicly observed services in this industry that negotiated hybrid post-quantum key exchange. NIST and CISA recommend cryptographic discovery and inventory as the basis for migration planning. This is an outside-in readiness signal, not a compliance score.49%
Run fewer than half their services on PQC-capable key exchangeiShows how common low post-quantum adoption is across the cohort. NCSC guidance calls for estate-wide discovery and an initial migration plan by 2028; this cohort-relative band supports prioritisation but is not a mandated threshold. Yellow is 52% or below, orange 53–71%, and red 72% or above.
52%
Still expose TLS 1.2 somewhereiHybrid ML-KEM key agreement is defined for TLS 1.3 by the IETF. TLS 1.2 exposure therefore identifies services that need protocol modernisation before this form of hybrid post-quantum key exchange can be negotiated. Yellow is 85% or below, orange 86–90%, and red 91% or above.
94%
Carry a median certificate lifetime over 100 daysiShorter certificate lifetimes increase rotation frequency and make lifecycle automation operationally important. The CA/B Forum schedule reduces the maximum public TLS certificate lifetime to 100 days in March 2027 and 47 days in March 2029. This is a lifecycle indicator, not a compliance finding. Yellow is 66% or below, orange 67–77%, and red 78% or above.
91%
Managed edgeiThe PQC-capable share observed on CDN, proxy and other managed front-door services. It indicates how quickly provider-managed layers can change; NIST defines crypto agility as the ability to replace and adapt cryptography while preserving security and operations. Red is below 30%, orange is 30–49%, and yellow is 50% or above.
68.6%
Customer-facingiThe PQC-capable share observed on services more directly controlled by the organisation. A gap from the managed edge can reveal deeper ownership, legacy-system or supplier dependencies—the areas CISA and NCSC recommend identifying in migration inventories and roadmaps. Red is below 30%, orange is 30–49%, and yellow is 50% or above.
39%
COHORT COMPOSITION

58retail and commercial banks

29universal banks

15cooperative and mutual banks

9investment banks

8consumer and card lenders

6state and development banks

3private and wealth banks

2credit unions

REGIONAL SAMPLE
55501510

Education

Education holds records with a long shelf life and a short defence: a student record stays sensitive for a working lifetime, research data is worth capturing years before it is published, and the estate is federated across departments, campuses and vendors in a way that few central teams see whole. Which services already negotiate a post-quantum hybrid is the measurable starting point, and where NIS2 or a national research-security regime applies, the same inventory supports evidence toward its cryptographic controls.

NIS2Research security
Industry PQC-capable median iThe median share of publicly observed services in this industry that negotiated hybrid post-quantum key exchange. NIST and CISA recommend cryptographic discovery and inventory as the basis for migration planning. This is an outside-in readiness signal, not a compliance score.18%
Run fewer than half their services on PQC-capable key exchangeiShows how common low post-quantum adoption is across the cohort. NCSC guidance calls for estate-wide discovery and an initial migration plan by 2028; this cohort-relative band supports prioritisation but is not a mandated threshold. Yellow is 52% or below, orange 53–71%, and red 72% or above.
80%
Still expose TLS 1.2 somewhereiHybrid ML-KEM key agreement is defined for TLS 1.3 by the IETF. TLS 1.2 exposure therefore identifies services that need protocol modernisation before this form of hybrid post-quantum key exchange can be negotiated. Yellow is 85% or below, orange 86–90%, and red 91% or above.
97%
Carry a median certificate lifetime over 100 daysiShorter certificate lifetimes increase rotation frequency and make lifecycle automation operationally important. The CA/B Forum schedule reduces the maximum public TLS certificate lifetime to 100 days in March 2027 and 47 days in March 2029. This is a lifecycle indicator, not a compliance finding. Yellow is 66% or below, orange 67–77%, and red 78% or above.
57%
Managed edgeiThe PQC-capable share observed on CDN, proxy and other managed front-door services. It indicates how quickly provider-managed layers can change; NIST defines crypto agility as the ability to replace and adapt cryptography while preserving security and operations. Red is below 30%, orange is 30–49%, and yellow is 50% or above.
74.5%
Customer-facingiThe PQC-capable share observed on services more directly controlled by the organisation. A gap from the managed edge can reveal deeper ownership, legacy-system or supplier dependencies—the areas CISA and NCSC recommend identifying in migration inventories and roadmaps. Red is below 30%, orange is 30–49%, and yellow is 50% or above.
22.5%
COHORT COMPOSITION

140universities

13school operators

1college or polytechnic

1vocational provider

REGIONAL SAMPLE
55501510205

Energy & utilities

Energy and utilities run equipment with service lives measured in decades, so cryptographic choices made now are likely to outlast several planning cycles. Operational technology tends to lag the public web layer by years, which usually shows up as services still on TLS 1.2 and therefore blocked from a post-quantum hybrid entirely. Operators are essential entities under NIS2, and this inventory supports evidence toward its cryptographic controls.

NIS2
Industry PQC-capable median iThe median share of publicly observed services in this industry that negotiated hybrid post-quantum key exchange. NIST and CISA recommend cryptographic discovery and inventory as the basis for migration planning. This is an outside-in readiness signal, not a compliance score.29%
Run fewer than half their services on PQC-capable key exchangeiShows how common low post-quantum adoption is across the cohort. NCSC guidance calls for estate-wide discovery and an initial migration plan by 2028; this cohort-relative band supports prioritisation but is not a mandated threshold. Yellow is 52% or below, orange 53–71%, and red 72% or above.
72%
Still expose TLS 1.2 somewhereiHybrid ML-KEM key agreement is defined for TLS 1.3 by the IETF. TLS 1.2 exposure therefore identifies services that need protocol modernisation before this form of hybrid post-quantum key exchange can be negotiated. Yellow is 85% or below, orange 86–90%, and red 91% or above.
86%
Carry a median certificate lifetime over 100 daysiShorter certificate lifetimes increase rotation frequency and make lifecycle automation operationally important. The CA/B Forum schedule reduces the maximum public TLS certificate lifetime to 100 days in March 2027 and 47 days in March 2029. This is a lifecycle indicator, not a compliance finding. Yellow is 66% or below, orange 67–77%, and red 78% or above.
77%
Managed edgeiThe PQC-capable share observed on CDN, proxy and other managed front-door services. It indicates how quickly provider-managed layers can change; NIST defines crypto agility as the ability to replace and adapt cryptography while preserving security and operations. Red is below 30%, orange is 30–49%, and yellow is 50% or above.
72.4%
Customer-facingiThe PQC-capable share observed on services more directly controlled by the organisation. A gap from the managed edge can reveal deeper ownership, legacy-system or supplier dependencies—the areas CISA and NCSC recommend identifying in migration inventories and roadmaps. Red is below 30%, orange is 30–49%, and yellow is 50% or above.
33.6%
COHORT COMPOSITION

42oil and gas producers

39electricity utilities

39multi-segment groups

10gas utilities

REGIONAL SAMPLE
55501510

Healthcare

Healthcare has the longest confidentiality horizon of any sector here: a patient record does not stop being sensitive, so traffic captured today remains worth decrypting for a lifetime. That makes harvest-now, decrypt-later a present concern rather than a future one, even where no regulator has set a post-quantum deadline. NIS2 covers health entities as essential, and cryptographic controls support evidence toward its risk-management obligations.

NIS2
Industry PQC-capable median iThe median share of publicly observed services in this industry that negotiated hybrid post-quantum key exchange. NIST and CISA recommend cryptographic discovery and inventory as the basis for migration planning. This is an outside-in readiness signal, not a compliance score.31%
Run fewer than half their services on PQC-capable key exchangeiShows how common low post-quantum adoption is across the cohort. NCSC guidance calls for estate-wide discovery and an initial migration plan by 2028; this cohort-relative band supports prioritisation but is not a mandated threshold. Yellow is 52% or below, orange 53–71%, and red 72% or above.
71%
Still expose TLS 1.2 somewhereiHybrid ML-KEM key agreement is defined for TLS 1.3 by the IETF. TLS 1.2 exposure therefore identifies services that need protocol modernisation before this form of hybrid post-quantum key exchange can be negotiated. Yellow is 85% or below, orange 86–90%, and red 91% or above.
90%
Carry a median certificate lifetime over 100 daysiShorter certificate lifetimes increase rotation frequency and make lifecycle automation operationally important. The CA/B Forum schedule reduces the maximum public TLS certificate lifetime to 100 days in March 2027 and 47 days in March 2029. This is a lifecycle indicator, not a compliance finding. Yellow is 66% or below, orange 67–77%, and red 78% or above.
70%
Managed edgeiThe PQC-capable share observed on CDN, proxy and other managed front-door services. It indicates how quickly provider-managed layers can change; NIST defines crypto agility as the ability to replace and adapt cryptography while preserving security and operations. Red is below 30%, orange is 30–49%, and yellow is 50% or above.
71.2%
Customer-facingiThe PQC-capable share observed on services more directly controlled by the organisation. A gap from the managed edge can reveal deeper ownership, legacy-system or supplier dependencies—the areas CISA and NCSC recommend identifying in migration inventories and roadmaps. Red is below 30%, orange is 30–49%, and yellow is 50% or above.
26%
COHORT COMPOSITION

44pharmaceutical companies

37providers

21device makers

17payers

11health services groups

REGIONAL SAMPLE
55501510

Insurance

Insurance holds some of the longest-lived personal records in commercial use: underwriting files, medical disclosures and claims histories that remain sensitive for the life of a policy and beyond. That long confidentiality horizon is what makes recorded traffic valuable to an attacker willing to wait. Where DORA applies, encryption in transit and key management are named requirements, and this inventory supports evidence toward them.

DORA
Industry PQC-capable median iThe median share of publicly observed services in this industry that negotiated hybrid post-quantum key exchange. NIST and CISA recommend cryptographic discovery and inventory as the basis for migration planning. This is an outside-in readiness signal, not a compliance score.37%
Run fewer than half their services on PQC-capable key exchangeiShows how common low post-quantum adoption is across the cohort. NCSC guidance calls for estate-wide discovery and an initial migration plan by 2028; this cohort-relative band supports prioritisation but is not a mandated threshold. Yellow is 52% or below, orange 53–71%, and red 72% or above.
59%
Still expose TLS 1.2 somewhereiHybrid ML-KEM key agreement is defined for TLS 1.3 by the IETF. TLS 1.2 exposure therefore identifies services that need protocol modernisation before this form of hybrid post-quantum key exchange can be negotiated. Yellow is 85% or below, orange 86–90%, and red 91% or above.
85%
Carry a median certificate lifetime over 100 daysiShorter certificate lifetimes increase rotation frequency and make lifecycle automation operationally important. The CA/B Forum schedule reduces the maximum public TLS certificate lifetime to 100 days in March 2027 and 47 days in March 2029. This is a lifecycle indicator, not a compliance finding. Yellow is 66% or below, orange 67–77%, and red 78% or above.
85%
Managed edgeiThe PQC-capable share observed on CDN, proxy and other managed front-door services. It indicates how quickly provider-managed layers can change; NIST defines crypto agility as the ability to replace and adapt cryptography while preserving security and operations. Red is below 30%, orange is 30–49%, and yellow is 50% or above.
67.2%
Customer-facingiThe PQC-capable share observed on services more directly controlled by the organisation. A gap from the managed edge can reveal deeper ownership, legacy-system or supplier dependencies—the areas CISA and NCSC recommend identifying in migration inventories and roadmaps. Red is below 30%, orange is 30–49%, and yellow is 50% or above.
39.2%
COHORT COMPOSITION

39life insurers

32non-life insurers

29health insurers

27multiline insurers

3reinsurers

REGIONAL SAMPLE
55501510

Retail

Retail holds the data that harvest-now, decrypt-later was named for: loyalty schemes keep identifiable purchase histories for years, pharmacy counters hold health records, and payment volume is the largest of any sector. The estate is wide and old at its edges, with point-of-sale, supplier and logistics integrations that usually reach TLS 1.3 last, so services still on TLS 1.2 and therefore blocked from a post-quantum hybrid are the expected weakness. Which customer-facing services already negotiate a post-quantum hybrid is the measurable starting point, and PCI DSS 4.0's cryptography requirements give the same inventory a second use: it supports evidence toward them.

PCI DSS 4.0
Industry PQC-capable median iThe median share of publicly observed services in this industry that negotiated hybrid post-quantum key exchange. NIST and CISA recommend cryptographic discovery and inventory as the basis for migration planning. This is an outside-in readiness signal, not a compliance score.50%
Run fewer than half their services on PQC-capable key exchangeiShows how common low post-quantum adoption is across the cohort. NCSC guidance calls for estate-wide discovery and an initial migration plan by 2028; this cohort-relative band supports prioritisation but is not a mandated threshold. Yellow is 52% or below, orange 53–71%, and red 72% or above.
47%
Still expose TLS 1.2 somewhereiHybrid ML-KEM key agreement is defined for TLS 1.3 by the IETF. TLS 1.2 exposure therefore identifies services that need protocol modernisation before this form of hybrid post-quantum key exchange can be negotiated. Yellow is 85% or below, orange 86–90%, and red 91% or above.
83%
Carry a median certificate lifetime over 100 daysiShorter certificate lifetimes increase rotation frequency and make lifecycle automation operationally important. The CA/B Forum schedule reduces the maximum public TLS certificate lifetime to 100 days in March 2027 and 47 days in March 2029. This is a lifecycle indicator, not a compliance finding. Yellow is 66% or below, orange 67–77%, and red 78% or above.
65%
Managed edgeiThe PQC-capable share observed on CDN, proxy and other managed front-door services. It indicates how quickly provider-managed layers can change; NIST defines crypto agility as the ability to replace and adapt cryptography while preserving security and operations. Red is below 30%, orange is 30–49%, and yellow is 50% or above.
55.8%
Customer-facingiThe PQC-capable share observed on services more directly controlled by the organisation. A gap from the managed edge can reveal deeper ownership, legacy-system or supplier dependencies—the areas CISA and NCSC recommend identifying in migration inventories and roadmaps. Red is below 30%, orange is 30–49%, and yellow is 50% or above.
59.1%
COHORT COMPOSITION

38grocers

28specialty retailers

14general merchandisers

12apparel retailers

10auto dealers

8own-retail brands

8convenience and fuel retailers

7online retailers

4multi-segment groups

1pharmacy

REGIONAL SAMPLE
55501510

Technology

Technology companies are assumed to hold the operational advantage here: short certificate lifetimes and automated deployment should make the swap to post-quantum key exchange closer to a configuration change than a project. The estates measured for this page do not yet bear that out. The capability to move fast has not become deployed post-quantum key exchange, so readiness has to be read from what services negotiate today, not from what the tooling could do. The offsetting risk is surface area, since customer data flows through a wide third-party and subprocessor estate that an outside-in scan sees only partly.

Supply-chain assurance
Industry PQC-capable median iThe median share of publicly observed services in this industry that negotiated hybrid post-quantum key exchange. NIST and CISA recommend cryptographic discovery and inventory as the basis for migration planning. This is an outside-in readiness signal, not a compliance score.39%
Run fewer than half their services on PQC-capable key exchangeiShows how common low post-quantum adoption is across the cohort. NCSC guidance calls for estate-wide discovery and an initial migration plan by 2028; this cohort-relative band supports prioritisation but is not a mandated threshold. Yellow is 52% or below, orange 53–71%, and red 72% or above.
60%
Still expose TLS 1.2 somewhereiHybrid ML-KEM key agreement is defined for TLS 1.3 by the IETF. TLS 1.2 exposure therefore identifies services that need protocol modernisation before this form of hybrid post-quantum key exchange can be negotiated. Yellow is 85% or below, orange 86–90%, and red 91% or above.
94%
Carry a median certificate lifetime over 100 daysiShorter certificate lifetimes increase rotation frequency and make lifecycle automation operationally important. The CA/B Forum schedule reduces the maximum public TLS certificate lifetime to 100 days in March 2027 and 47 days in March 2029. This is a lifecycle indicator, not a compliance finding. Yellow is 66% or below, orange 67–77%, and red 78% or above.
79%
Managed edgeiThe PQC-capable share observed on CDN, proxy and other managed front-door services. It indicates how quickly provider-managed layers can change; NIST defines crypto agility as the ability to replace and adapt cryptography while preserving security and operations. Red is below 30%, orange is 30–49%, and yellow is 50% or above.
62.3%
Customer-facingiThe PQC-capable share observed on services more directly controlled by the organisation. A gap from the managed edge can reveal deeper ownership, legacy-system or supplier dependencies—the areas CISA and NCSC recommend identifying in migration inventories and roadmaps. Red is below 30%, orange is 30–49%, and yellow is 50% or above.
47.9%
COHORT COMPOSITION

34IT services groups

29software companies

19internet platforms

18hardware makers

17semiconductor companies

12payment companies

1multi-segment group

REGIONAL SAMPLE
55501510

Telecommunications

Telecommunications carries bulk transit plus long-lived subscriber identifiers, so a single recorded capture can retain value long after the session ends. Operators are classed as essential entities under NIS2, which puts cryptographic risk management in scope. Interconnect and management interfaces are often the slowest part of the estate to reach TLS 1.3, and nothing can negotiate a post-quantum hybrid until it does.

NIS2
Industry PQC-capable median iThe median share of publicly observed services in this industry that negotiated hybrid post-quantum key exchange. NIST and CISA recommend cryptographic discovery and inventory as the basis for migration planning. This is an outside-in readiness signal, not a compliance score.19%
Run fewer than half their services on PQC-capable key exchangeiShows how common low post-quantum adoption is across the cohort. NCSC guidance calls for estate-wide discovery and an initial migration plan by 2028; this cohort-relative band supports prioritisation but is not a mandated threshold. Yellow is 52% or below, orange 53–71%, and red 72% or above.
78%
Still expose TLS 1.2 somewhereiHybrid ML-KEM key agreement is defined for TLS 1.3 by the IETF. TLS 1.2 exposure therefore identifies services that need protocol modernisation before this form of hybrid post-quantum key exchange can be negotiated. Yellow is 85% or below, orange 86–90%, and red 91% or above.
88%
Carry a median certificate lifetime over 100 daysiShorter certificate lifetimes increase rotation frequency and make lifecycle automation operationally important. The CA/B Forum schedule reduces the maximum public TLS certificate lifetime to 100 days in March 2027 and 47 days in March 2029. This is a lifecycle indicator, not a compliance finding. Yellow is 66% or below, orange 67–77%, and red 78% or above.
66%
Managed edgeiThe PQC-capable share observed on CDN, proxy and other managed front-door services. It indicates how quickly provider-managed layers can change; NIST defines crypto agility as the ability to replace and adapt cryptography while preserving security and operations. Red is below 30%, orange is 30–49%, and yellow is 50% or above.
61.7%
Customer-facingiThe PQC-capable share observed on services more directly controlled by the organisation. A gap from the managed edge can reveal deeper ownership, legacy-system or supplier dependencies—the areas CISA and NCSC recommend identifying in migration inventories and roadmaps. Red is below 30%, orange is 30–49%, and yellow is 50% or above.
26.6%
COHORT COMPOSITION

56integrated operators

19fixed-line operators

12mobile operators

9satellite operators

8cable operators

REGIONAL SAMPLE
29501510

Travel & hospitality

Travel and hospitality hold two records that outlive the trip: the booking, with its payment card and passport details, and the loyalty account, which keeps years of movements. Estates here are federated by design, with airline, hotel, agency and payment partners exchanging data through integrations that predate the modern web, and those partner edges are where older protocols tend to persist. Which customer-facing services already negotiate a post-quantum hybrid is the measurable starting point, and PCI DSS 4.0's cryptography requirements give the same inventory a second use: it supports evidence toward them.

PCI DSS 4.0
Industry PQC-capable median iThe median share of publicly observed services in this industry that negotiated hybrid post-quantum key exchange. NIST and CISA recommend cryptographic discovery and inventory as the basis for migration planning. This is an outside-in readiness signal, not a compliance score.51%
Run fewer than half their services on PQC-capable key exchangeiShows how common low post-quantum adoption is across the cohort. NCSC guidance calls for estate-wide discovery and an initial migration plan by 2028; this cohort-relative band supports prioritisation but is not a mandated threshold. Yellow is 52% or below, orange 53–71%, and red 72% or above.
47%
Still expose TLS 1.2 somewhereiHybrid ML-KEM key agreement is defined for TLS 1.3 by the IETF. TLS 1.2 exposure therefore identifies services that need protocol modernisation before this form of hybrid post-quantum key exchange can be negotiated. Yellow is 85% or below, orange 86–90%, and red 91% or above.
83%
Carry a median certificate lifetime over 100 daysiShorter certificate lifetimes increase rotation frequency and make lifecycle automation operationally important. The CA/B Forum schedule reduces the maximum public TLS certificate lifetime to 100 days in March 2027 and 47 days in March 2029. This is a lifecycle indicator, not a compliance finding. Yellow is 66% or below, orange 67–77%, and red 78% or above.
71%
Managed edgeiThe PQC-capable share observed on CDN, proxy and other managed front-door services. It indicates how quickly provider-managed layers can change; NIST defines crypto agility as the ability to replace and adapt cryptography while preserving security and operations. Red is below 30%, orange is 30–49%, and yellow is 50% or above.
56.5%
Customer-facingiThe PQC-capable share observed on services more directly controlled by the organisation. A gap from the managed edge can reveal deeper ownership, legacy-system or supplier dependencies—the areas CISA and NCSC recommend identifying in migration inventories and roadmaps. Red is below 30%, orange is 30–49%, and yellow is 50% or above.
50%
COHORT COMPOSITION

30airlines

20restaurant groups

18resorts and gaming

14hotel groups

13airports

11rail and coach operators

8contract caterers

7ground transport operators

5booking sites

3multi-segment groups

1cruise line

REGIONAL SAMPLE
55501510

The benchmark, ready for the working session.

Use this as context, not a diagnosis. A client-specific view still requires an agreed scope, connected evidence and expert interpretation.

IndustryRegulatory / assurance contextPQC-capable medianTLS 1.3 medianMedian certificate lifetime
Banking
DORANIS2
49%87%198 days
Education
NIS2Research security
18%86%197 days
Energy & utilities
NIS2
29%85.4%198 days
Healthcare
NIS2
31%83.3%198 days
Insurance
DORA
37%91.3%198 days
Retail
PCI DSS 4.0
50%88.9%198 days
Technology
Supply-chain assurance
39%87.2%198 days
Telecommunications
NIS2
19%80%198 days
Travel & hospitality
PCI DSS 4.0
51%90.7%198 days

A consistent outside-in view across every industry.

01

Defined sample

Organisations were selected across Europe, the UK and North America using published revenue and stated regional quotas. The Education cohort also includes Oceania.

02

Identical observation window

Every organisation received the same 200-second discovery cap because service count is partly a function of how long the scanner looks.

03

Aggregate publication

No organisation is named on this page and no published figure is attached to a single organisation. Each industry metric treats each organisation equally.

Turn market context into a defensible client baseline.

Bring industry evidence into a repeatable discovery and review workflow, while your team owns the judgement, recommendations and client relationship.