Travel and hospitality hold two records that outlive the trip: the booking, with its payment card and passport details, and the loyalty account, which keeps years of movements. Estates here are federated by design, with airline, hotel, agency and payment partners exchanging data through integrations that predate the modern web, and those partner edges are where older protocols tend to persist. Which customer-facing services already negotiate a post-quantum hybrid is the measurable starting point, and PCI DSS 4.0's cryptography requirements give the same inventory a second use: it supports evidence toward them.
PCI DSS 4.0
Industry PQC-capable median iThe median share of publicly observed services in this industry that negotiated hybrid post-quantum key exchange. NIST and CISA recommend cryptographic discovery and inventory as the basis for migration planning. This is an outside-in readiness signal, not a compliance score.51%
Run fewer than half their services on PQC-capable key exchangeiShows how common low post-quantum adoption is across the cohort. NCSC guidance calls for estate-wide discovery and an initial migration plan by 2028; this cohort-relative band supports prioritisation but is not a mandated threshold. Yellow is 52% or below, orange 53–71%, and red 72% or above.
47%
Still expose TLS 1.2 somewhereiHybrid ML-KEM key agreement is defined for TLS 1.3 by the IETF. TLS 1.2 exposure therefore identifies services that need protocol modernisation before this form of hybrid post-quantum key exchange can be negotiated. Yellow is 85% or below, orange 86–90%, and red 91% or above.
83%
Carry a median certificate lifetime over 100 daysiShorter certificate lifetimes increase rotation frequency and make lifecycle automation operationally important. The CA/B Forum schedule reduces the maximum public TLS certificate lifetime to 100 days in March 2027 and 47 days in March 2029. This is a lifecycle indicator, not a compliance finding. Yellow is 66% or below, orange 67–77%, and red 78% or above.
71%
Managed edgeiThe PQC-capable share observed on CDN, proxy and other managed front-door services. It indicates how quickly provider-managed layers can change; NIST defines crypto agility as the ability to replace and adapt cryptography while preserving security and operations. Red is below 30%, orange is 30–49%, and yellow is 50% or above.
56.5%
Customer-facingiThe PQC-capable share observed on services more directly controlled by the organisation. A gap from the managed edge can reveal deeper ownership, legacy-system or supplier dependencies—the areas CISA and NCSC recommend identifying in migration inventories and roadmaps. Red is below 30%, orange is 30–49%, and yellow is 50% or above.
50%