Forescout Finds Post-Quantum Key Exchange on More Than 19 Million of 160 Million SSH Servers, With OT at 16 Percent and Medical Devices at 6 Percent
Quentir Defense Monitor
Evidence-based insights for quantum defense and security. Published by Quentir Systems LLC · September 3, 2026.

The migration to quantum-resistant encryption is moving at two speeds, and the split between them is now measured rather than suspected. Forescout Research, the vendor's Vedere Labs team, published a year-over-year measurement of post-quantum adoption on June 24, 2026, drawn from internet-wide scan data covering more than 160 million SSH hosts. The number of SSH servers that support post-quantum cryptography in their key exchange grew 72 percent in twelve months, from 11.5 million to more than 19 million. As a share of everything reachable, that is a climb from 6.2 percent to 11.8 percent. Nearly nine of every ten SSH servers on the internet still negotiate their session keys with mathematics a future quantum computer is expected to break.
On September 1, Daniel dos Santos, who leads the research team behind those figures, walked German-speaking security professionals through the same data in a guest article for Security-Insider, and the framing he chose is the one that matters for a defense reader. The interesting story is no longer the average. It is the spread. Ordinary IT equipment is picking up quantum-resistant key exchange almost without trying, while operational technology, the equipment that runs plants, grids and hospitals, sits far behind on the same curve. The gap follows a simple rule: wherever an update is cheap, the migration is already happening, and wherever hardware lives for decades, it has barely begun.
That rule should sound familiar to anyone who buys military equipment, because long-lived, hard-to-patch, safety-qualified hardware is what a force runs on. The Forescout numbers are a civilian measurement, and they double as the closest available proxy for how the quantum transition will go anywhere that equipment outlives its cryptography.
How OpenSSH 10.0 Turned a Routine Version Upgrade Into More Than 19 Million Post-Quantum Servers
The growth side of the measurement has a clear mechanical cause. More than 80 percent of the SSH servers Forescout observed run OpenSSH, and the OpenSSH project began shipping quantum-resistant key exchange as standard equipment several releases ago. The project's release notes show the sequence: version 9.9 in September 2024 added a hybrid key exchange combining ML-KEM, the module-lattice standard NIST finalized in 2024, with the classical X25519 exchange, and version 10.0 in April 2025 made that hybrid, mlkem768x25519-sha256, the default for key agreement. An administrator who upgrades OpenSSH for ordinary reasons, a distribution refresh, a vulnerability patch, a new server image, receives post-quantum key exchange without ever deciding to adopt it.
The measured effect is that roughly 40 percent of internet-facing OpenSSH servers now support post-quantum key exchange out of the box, with ML-KEM and the earlier SNTRUP hybrid as the two algorithms doing the work. Forescout attributes most of the growth to OpenSSH upgrades on systems where software hygiene is easy.
The same pattern shows up one layer over, in the web and application traffic protected by TLS. TLS 1.3, the only TLS version being updated to incorporate post-quantum key exchange, now runs on 30 percent of the servers Forescout observed, up from 19 percent a year earlier. TLS 1.2 is frozen. This 30 percent is a proxy for migration readiness, not a finding that 30 percent of observed TLS is quantum-resistant. Ordinary TLS 1.3 does not itself provide post-quantum key exchange. Where upgrading is a package manager command, readiness for the quantum transition is spreading as a side effect of routine maintenance. That is genuinely good news, and it is exactly why the other half of the measurement deserves attention.
The Adoption Ladder Falls From 50 Percent on IT Equipment to 6 Percent on Medical Devices and 3 Percent on Dropbear
Inside enterprise networks, Forescout sorted devices into four classes and checked what fraction runs an OpenSSH version capable of post-quantum key exchange. Ordinary IT equipment came in around 50 percent. Internet-of-things devices, cameras, printers, controllers of every kind, reached 28 percent. Operational technology, the equipment wired into physical processes, stood at 16 percent. Connected medical devices came in at 6 percent.
Below all four sits the embedded world's other SSH implementation. Dropbear, the lightweight server built into routers, gateways and countless industrial and field devices, supports post-quantum key exchange in only 3 percent of observed installations. The devices least likely to ever see an administrator are also the furthest from the new mathematics.
The TLS picture is harsher. Measured on quantum-resistant capability at the transport layer, enterprise IT equipment reaches about 8 percent, and operational technology reaches 0.8 percent. Forescout then laid its risk scoring over the encryption data, and the overlap is the finding a security architect should quote: two thirds of OT devices in the measured networks are simultaneously assigned a critical risk score and incapable of quantum-resistant TLS, and nearly half of IoT devices share that combination. The score combines vulnerabilities, asset criticality and internet exposure. The equipment an organization can least afford to lose is concentrated at the wrong end of the adoption curve.
Quantum pillar: post-quantum cryptography (migration and crypto-agility). Use posture: defensive. Technology readiness: assessed at TRL 9 of 9, pending verification against the governing readiness rubric. The hybrid ML-KEM key exchange ships as the OpenSSH default, but Forescout observed only about 1.9 million servers advertising the listed ML-KEM variants among more than 19 million servers supporting any post-quantum exchange, with most post-quantum observations using SNTRUP, so the open question is how unevenly that protection is distributed across algorithms and device fleets.
The Same Equipment Profile Runs Bases, Ships and Military Hospitals, Which Is Why CISA and MITRE Flagged It
Read as capability, the measurement describes what a defender gains and an intercepting adversary loses, tunnel by tunnel. The threat the migration answers is retrospective: intelligence services already collect encrypted traffic they cannot read, on the expectation that a future quantum computer will open it, the approach known as harvest now, decrypt later. Every SSH or TLS session that negotiates a hybrid ML-KEM exchange today is a session removed from that future archive, because the recorded handshake no longer yields to the anticipated attack. The Forescout data says this protection is already routine for the traffic of office IT, and nearly absent for the traffic that operates physical equipment: the remote-maintenance tunnels into industrial controllers, the management sessions on building automation, the telemetry of connected clinical devices.
The device classes in the study map directly onto military estates. Operational technology in the civilian sense runs power, water, fuel and climate systems on bases and in shipyards; connected medical devices fill the hospitals of every military health system; Dropbear-class embedded SSH stacks sit inside exactly the kind of long-life field equipment that defense programs buy. The U.S. cybersecurity agency CISA runs a dedicated post-quantum initiative that singles out operational technology in critical infrastructure for transition help. Federal policy established by OMB memorandum M-23-02 requires federal agencies to maintain inventories of covered systems vulnerable to quantum decryption and submit them to ONCD and CISA, but explicitly directs them not to include national security systems in those inventories. In his Security-Insider piece, dos Santos points to an April 2026 MITRE analysis of medical devices making the matching argument for the clinical world: lifespans run to decades, regulatory approval slows every change, and for an implanted device a cryptographic upgrade can mean a surgical procedure.
For a force, the capability at stake is the confidentiality of its operational plumbing over the next fifteen years. The offensive side of this ledger needs no new invention; collection against encrypted links is an established practice, and the value of the archive simply grows wherever legacy key exchange persists. The defensive side is what the measurement prices: the protection is standardized, deployed by default in mainstream software, and demonstrably absent from the equipment classes that defense estates share with civilian infrastructure.
What the Scan Does and Does Not Establish for a Program Office Writing 2027 Contracts
The limits of the evidence deserve the same plain statement as the findings. Forescout measured internet-facing services and the enterprise networks its sensors observe; classified and air-gapped military networks are outside the sample, and their refresh cycles are, if anything, slower. Capability is also weaker than enforcement: a server that supports ML-KEM will still fall back to classical exchange with a peer that lacks it, so the 11.8 percent figure is a ceiling on protected sessions, and the measurement says nothing about how often the quantum-resistant option is actually negotiated. A percentage of observed hosts is a fleet statistic, and any single procurement should ask about its own devices.
What the numbers do establish is where crypto-agility language belongs in a contract. The IT fleet demonstrates that when cryptography ships as a software default, migration approaches zero marginal cost; the OT, medical and Dropbear figures show what happens when it is bolted to hardware economics instead. A program office can act on that mechanism today: require post-quantum capable key exchange in any new equipment with a service life past 2030, require a documented cryptographic inventory and upgrade path from vendors of embedded systems, and treat a Dropbear-class SSH stack without a post-quantum roadmap as the procurement risk the 3 percent figure says it is. The measurement will repeat next year, and the useful question for any buyer is which side of the two-speed migration next year's contracts land on.
Sources
Primary source: Forescout Research, Vedere Labs, 'PQC Adoption Gaps,' June 24, 2026, with Daniel dos Santos's September 1, 2026 Security-Insider guest analysis. Other material: OpenSSH release notes on ML-KEM key exchange defaults; CISA's post-quantum cryptography initiative.