A CDN or cloud provider can support post-quantum cryptography while a specific customer workload still negotiates only classical key exchange. The gap can come from TLS version policy, FIPS mode, client capability, SDK version, origin routing, regional support or product-specific limitations.
The practical question is not "does our provider have a PQC blog post?" It is "which of our real user journeys and machine-to-machine calls negotiate a NIST-standardised hybrid key exchange, and where do they fall back?"
Treat provider documentation as supplier evidence, then pair it with live scans and application tests. That gives you a defensible cryptographic inventory rather than a general assumption.