Skip to main content
Knowledge Oct 26, 2026

We Scanned Every EU Tax Authority. Half Still Accept TLS 1.0

In June 2026, attackers used stolen identities to get into France’s tax administration and left with the tax records of 678,000 people. It was the French finance ministry’s third major incident this year. Nothing in the public reporting points to encryption, and no TLS setting stops someone who logs in as someone else.

It does raise a fair question, though. Tax authorities hold the most complete financial picture any government has of its citizens, and most of what they run is reachable over HTTPS from anywhere in the world. How well do they look after the part anyone can see?

We scanned all 27 on the same day with the same method and ranked them. France came 25th and Denmark came last. We also scanned eight tax authorities outside the EU, from the IRS to Singapore, and on post-quantum readiness Europe is far behind.

The ranking

Each scan starts from Certificate Transparency logs, finds every hostname that has carried a public certificate under the authority’s domain, and tests every reachable HTTPS endpoint: 1,928 across the EU. The score is out of 100, and the methodology is at the end of this post.

Map of all 27 EU countries and their tax authority TLS scores, from Denmark at 38 in red to Luxembourg at 94 in blue, with a complete ranking alongside the map.

TLS score of each EU tax authority by country, from red (lowest) to blue (highest).

RankCountryTax authorityDomainScoreEndpointsHosts on TLS 1.0Post-quantum share
1LuxembourgAdministration des contributions directesimpotsdirects.public.lu94300%
2PortugalAutoridade Tributária e Aduaneiraportaldasfinancas.gov.pt905040%
3SpainAgencia Tributariaagenciatributaria.gob.es881600%
4LatviaValsts ieņēmumu dienestsvid.gov.lv861000%
4MaltaCommissioner for Revenuecfr.gov.mt8640100%
6GermanyELSTERelster.de8337044%
7BelgiumFPS Financeminfin.fgov.be817100%
7BulgariaNational Revenue Agencynra.bg81300%
9PolandKrajowa Administracja Skarbowapodatki.gov.pl7920074%
10CroatiaPorezna upravaporezna-uprava.hr76910%
11AustriaFinanzamt Österreichbmf.gv.at7581084%
12HungaryNemzeti Adó- és Vámhivatalnav.gov.hu741200%
12IrelandRevenuerevenue.ie7430175%
12SloveniaFinančna upravafu.gov.si741410%
15EstoniaMaksu- ja Tolliametemta.ee7345135%
16FinlandVerohallintovero.fi7149018%
16NetherlandsBelastingdienstbelastingdienst.nl7133806%
18GreeceAADEaade.gr68113341%
19RomaniaANAFanaf.ro66420%
20CyprusTax Departmentmof.gov.cy653257%
21SwedenSkatteverketskatteverket.se6213524%
22LithuaniaValstybinė mokesčių inspekcijavmi.lt614320%
23CzechiaFinanční správamfcr.cz60162327%
24ItalyAgenzia delle Entrateagenziaentrate.gov.it56140138%
25FranceDGFiPimpots.gouv.fr5481420%
26SlovakiaFinančná správafinancnasprava.sk51113714%
27DenmarkSkattestyrelsenskat.dk383581111%

Read the endpoint column alongside the score. Every exposed host is one more thing to patch, renew and monitor, so a small footprint is a real strength, and most of the authorities at the top keep theirs tight. Luxembourg’s lead comes with a caveat: its direct tax administration is three endpoints inside the shared public.lu namespace. The scores that impress most are the ones that hold up across dozens or hundreds of endpoints.

Big estates are no excuse

Across this study, scores fall as estates grow, so size is the obvious defence for the bottom of the table. It does not survive a look at the neighbours.

Scatter plot of all 27 EU tax authorities, with public endpoint count on the logarithmic X axis and TLS score on the Y axis. Each point is labeled with its ISO country code. The blue upper envelope connects LU, PT, ES, DE, BE, AT and NL. The red lower envelope connects BG, RO, CY, LT, FR, SK and DK. Denmark scores 38 across 358 endpoints, while the Netherlands scores 71 across 338.

TLS score against public endpoint count for each EU tax authority. Scores fall as estates grow, but authorities of the same size can be more than 30 points apart.

Denmark’s Skattestyrelsen exposes 358 endpoints, more than any other EU tax authority. Another 131 hostnames listed in public Certificate Transparency logs did not answer from the internet at all, most likely because they sit behind a firewall. It has 11 hosts still accepting TLS 1.0, two expired certificates in service, and four more that were due to expire within a week of the scan. Its sub-scores are 33 for protocols, 48 for certificate health and 17 for web hardening.

The Netherlands runs 338 endpoints, scores 71 and has no TLS 1.0 anywhere. A 33-point gap between neighbours with the same problem to solve is about how the estate is managed, not how big it is.

The three authorities just above Denmark tell the same story. France’s DGFiP, 25th with 54, has four hosts accepting TLS 1.0, an expired certificate on one endpoint, a bad OCSP response stapled on another, and a mail server that still offers TLS 1.1. Only 20% of its endpoints negotiate post-quantum key exchange. None of this explains the June breach, but it suggests nobody has reviewed the public surface as a whole for some time.

Slovakia’s Finančná správa scored 51, with seven hosts on TLS 1.0 (only Denmark has more), an expired certificate in service, and no DNSSEC on any of its zones. Italy’s Agenzia delle Entrate scored 56, with two expired certificates in service, TLS 1.0 on a public mail server and a certificate health sub-score of 56. All three run between 81 and 140 endpoints. So does Austria, which scored 75 with no legacy protocols at all.

Who does it well

Spain’s Agencia Tributaria scored 88 across 16 endpoints, with no legacy protocols, a signed DNS zone, and HSTS and a Content Security Policy on every web host. Its one gap is post-quantum key exchange, where it has nothing yet. Portugal scored 90 on a smaller estate and already has post-quantum on 40% of it, and Germany’s ELSTER scored 83 across 37 endpoints.

Belgium’s FPS Finance scored 81 across 71 endpoints with no TLS 1.0, every zone signed and only one web host missing HSTS. Its blind spot is the newest protocol rather than the oldest: TLS 1.3 on a single endpoint, and so no post-quantum key exchange anywhere.

Among large estates, the Netherlands is the benchmark: 338 endpoints, no TLS 1.0, DNSSEC on its main zones, and a score twelve points above the median for estates its size. With post-quantum key exchange switched on, it would be close to the top of this table.

More than half still run TLS 1.0

14 of the 27 still accept TLS 1.0 and TLS 1.1 on at least one public host: Croatia, Cyprus, Czechia, Denmark, Estonia, France, Greece, Ireland, Italy, Lithuania, Romania, Slovakia, Slovenia and Sweden. Browsers dropped both in 2020, and the payment card industry banned TLS 1.0 for card data in 2018.

In most cases the main taxpayer portal is fine. The old protocols live on a few forgotten hosts next to modern ones, which is how they get past audits that only test the homepage. An attacker looking for weak spots doesn’t start at the homepage either.

TLS 1.3 is mostly there, except in Belgium, Bulgaria and Romania

TLS 1.3 has been current since 2018. It is faster, drops every legacy cipher by design, and is the only version that can carry post-quantum key exchange. Across the EU, 985 of the 1,384 endpoints where we could measure it support TLS 1.3, or 71%.

Seven authorities offer it everywhere: Germany, Latvia, Luxembourg, Malta, the Netherlands (all 191 measured endpoints), Poland and Portugal. Austria, Denmark and Estonia are each one to six endpoints short. Bulgaria and Romania support it nowhere, and Belgium on one endpoint out of 68, a surprising gap in an estate that is otherwise one of the cleanest here. Lithuania (24%), Italy (39%) and Czechia (45%) are also well behind.

Denmark shows how averages hide the tail. 97% of its endpoints offer TLS 1.3, and it still has eleven hosts accepting TLS 1.0.

Ciphers from another era

Nine authorities still offer 3DES on public HTTPS endpoints, on at least 26 endpoints between them: Cyprus, Czechia, Estonia, France, Greece, Ireland, Italy, Lithuania and Slovakia. The Sweet32 attack showed in 2016 that its 64-bit blocks are breakable on long-lived connections, and mainstream TLS libraries have disabled it by default ever since.

Two go further back. Estonia still offers RC4 on one endpoint, a cipher the IETF banned from TLS in 2015. Lithuania offers IDEA, removed from the standard with TLS 1.2 in 2008, and SEED, which OpenSSL stopped enabling by default in 2016. Poland’s web estate is clean of all of these, but the finance ministry mail servers that receive email for podatki.gov.pl still accept both RC4 and 3DES.

Below that sits a larger layer of legacy rather than broken cryptography. 24 authorities accept RSA key exchange, which has no forward secrecy: anyone who records traffic today and obtains the server’s private key later can decrypt all of it. 19 offer finite-field Diffie-Hellman. And 26 accept CBC-mode suites with ECDHE key exchange, the mildest item here and mostly a sign of cipher lists nobody has trimmed in years. Luxembourg, on its three endpoints, is the only authority with no weak suite at all.

Web hardening: a median of 38 out of 100

HSTS tells browsers to use HTTPS for a site from then on, so later visits never start over plain HTTP, where anyone on the network path could intercept them. It matters on public web pages more than on APIs or mail endpoints, and coverage is patchy: Greece is missing it on 64 of its 81 web hosts, Cyprus on 23 of 29, Sweden on 27 of 38. The median web hardening sub-score, which also covers Content Security Policy, frame protection and cookie flags, is 38 out of 100.

Expired certificates, and what they say about monitoring

An expired certificate on a public host is rarely about the certificate. It means nobody is watching that host, renewal is not automated or never reached the server, and anything still connecting to it has either stopped checking certificates or stopped working.

Seven EU tax authorities were serving at least one expired certificate on the day of our scan, nine in all out of the 803 in use across the EU.

CountryExpired certificates / in useShareExpired for
Netherlands1 / 1060.9%1,291 days
Denmark2 / 1131.8%733 and 288 days
Hungary1 / 714.3%608 days
Italy2 / 832.4%410 and 61 days
France1 / 283.6%314 days
Czechia1 / 382.6%260 days
Slovakia1 / 412.4%3 days

The percentages are small, but the ages are not. Only Slovakia’s looks like a renewal that slipped last week. Seven of the nine expired more than eight months ago, so these hosts have run with an invalid certificate for most of a year or longer without anyone noticing. Outside the EU, the UK had one certificate two days past expiry, and South Korea’s HomeTax one that expired 825 days ago.

One of Italy’s, expired for 410 days, came from Let’s Encrypt, so someone once set up automated renewal and it quietly stopped. The Dutch one was never a real certificate: a ten-year certificate issued by “MyCompany”, the placeholder name in default OpenSSL and appliance templates, which no browser has ever trusted. It is still answering on a public address three and a half years after it expired.

Romania’s ANAF has the email version of the same problem. smtp.mfinante.ro, the server that receives its mail, still presents the factory certificate of a Cisco email appliance: self-signed, issued to “Cisco ESA Certificate” rather than to ANAF, and expired 1,396 days before our scan. Most mail servers encrypt with whatever certificate they are offered without checking it, so mail to ANAF is still encrypted, but no sender can verify it is talking to the real server. Email is not part of the score, so this does not affect Romania’s ranking.

This gets harder from here. Since March 2026 a public certificate can be valid for at most 200 days, falling to 100 days in March 2027 and 47 days in March 2029. Short-lived certificates are a good sign that renewal is automated, and on that measure Estonia is ready, with 27 of its 28 certificates valid for 90 days or less. Greece (59%) and Finland (48%) are on the way. Austria, Belgium and Sweden, with 40 to 65 certificates each, have none. Across the EU, 19% of certificates in use are short-lived, against 45% at the IRS and 40% in Singapore. One-year certificates can be automated too, but anyone still renewing by hand will be doing it eight times a year per certificate by 2029.

Who is allowed to issue a certificate for the taxman?

Certificate authorities

The 794 valid certificates we found across the EU come from 17 issuers, one of them a private CA. DigiCert signs 35% of them for 15 authorities, Let’s Encrypt 17% for 14, and Sectigo 16% for 12. GlobalSign’s 14% is almost entirely Denmark, and HARICA, the Greek academic CA, issues all 65 of Belgium’s certificates. National CAs still have a foothold: D-Trust in Germany, Microsec in Hungary, Certum in Poland, FNMT in Spain and První certifikační autorita in Czechia.

Belgium, Ireland and Slovenia each depend on a single CA for their whole estate. That is simple until the CA has a problem, as Entrust’s customers found out when browsers withdrew trust from its certificates in 2024. Denmark and HMRC in the UK serve certificates from their own private CAs on public hosts, which no outside client can validate without special configuration.

CAA records

A CAA record is one line in DNS that tells every certificate authority which of them may issue for a domain. It applies from parent domains down, so a record on gouv.fr would cover impots.gouv.fr, and we checked every level up to the top-level domain. Only 7 of the 27 EU authorities are covered: Austria, France, Germany, Lithuania, the Netherlands and Sweden through their own record, and Malta through the government-wide one on gov.mt. None of the other national government domains, from gouv.fr to gov.it, publishes one.

Sweden’s record is the tightest: DigiCert only, no wildcard certificates, no email or logo certificates, and a security contact to notify about any attempt. For the other 20, any CA that can be convinced they control the domain may issue. Outside the EU only Switzerland is covered, through the federal admin.ch record, and the IRS, Japan, Singapore and South Korea have no CAA anywhere.

DNSSEC

Certificate authorities mostly check domain control through DNS, so whoever can forge DNS answers for a domain can, in principle, get a certificate for it. DNSSEC closes that gap, and since March 2026 CAs must check signatures when they are present. 12 of the 27 EU authorities sign their main zone: Belgium, Bulgaria, Czechia, Denmark, Estonia, Germany, Luxembourg, the Netherlands, Portugal, Slovenia, Spain and Sweden. The other 15, including France, Italy, Greece, Austria, Ireland and Poland, do not.

Several signed zones still use 1024-bit RSA keys, which have not been considered safe for years: Denmark (both keys), Germany’s ELSTER, Estonia, Portugal, the e-filing zone of Czechia’s finance ministry, and the shared gov.si zone that holds Slovenia’s tax site. Belgium, Bulgaria, Czechia and Spain sign with modern ECDSA, and outside the EU Norway uses Ed25519, the most modern setup in either group.

Denmark also has the only EU zone that can be walked. skat.dk uses plain NSEC records, which let anyone list every hostname in the zone with a few queries, and a single lookup of ours returned a hostname we had never asked for. Every other signed zone uses NSEC3 or minimal answers that do not leak names. Outside the EU, irs.gov and eight of its subzones have the same problem.

Post-quantum: Malta, Austria, Ireland and Poland lead, the rest barely start

Hybrid post-quantum key exchange (X25519 combined with ML-KEM-768) protects today’s traffic against anyone who records it now and decrypts it once a large quantum computer exists. Tax records stay sensitive for decades, which makes them exactly the kind of data this threat is about.

Hybrid ML-KEM key exchange only exists in TLS 1.3, so Belgium, Bulgaria and Romania, with almost no TLS 1.3 between them, all show 0% post-quantum coverage. Upgrading is only the first step, though. Of the 985 TLS 1.3 endpoints, just 270 negotiate hybrid key exchange, and eight authorities run TLS 1.3 without it anywhere, including Latvia and Luxembourg, where every endpoint is already on TLS 1.3. Italy is the reverse: 51 of its 53 TLS 1.3 endpoints already use post-quantum key exchange, and what holds it back is the 61% of its estate still on TLS 1.2.

Malta is the only authority with full coverage, on all four of its endpoints. Among larger estates, Austria leads with 84%, followed by Ireland at 75% and Poland at 74%. No one else reaches 50%, and 10 authorities offer it nowhere, including Spain and Belgium, two of the best-run estates in the ranking. Across the EU, 270 of 1,304 probed endpoints are protected, about one in five.

269 of those 270 use X25519 with ML-KEM-768. The remaining one, in Austria, uses P-256 with ML-KEM-768, and nobody runs the stronger ML-KEM-1024 variants. That is the combination browsers, CDNs and current TLS libraries turn on by default, and where post-quantum shows up it usually arrived with a CDN or load balancer that enabled it. That makes the laggards harder to excuse, because for most of them it is a configuration change, not a project. The Netherlands (6%) and Sweden (4%) stand out for the wrong reason: large, modern estates still in single digits.

How the EU compares with the rest of the world

For context, we ran the same scan on the same day against eight tax authorities outside the EU: the United States, the United Kingdom, Switzerland, Norway, Japan, South Korea, Singapore and Australia.

CountryTax authorityDomainScoreEndpointsHosts on TLS 1.0Post-quantum share
SingaporeIRASiras.gov.sg85860100%
AustraliaAustralian Taxation Officeato.gov.au78596096%
NorwaySkatteetatenskatteetaten.no76179050%
SwitzerlandFederal Tax Administrationestv.admin.ch6510600%
United KingdomHMRChmrc.gov.uk59457386%
United StatesIRSirs.gov58787287%
JapanNational Tax Agencynta.go.jp571,3464499.9%
South KoreaNational Tax Service (HomeTax)hometax.go.kr43116430%

On the overall score, the gap is smaller than it looks. The median for these eight is 62 against 74 for the EU, but their estates are far larger, with a median of 318 endpoints against 37. At the same scale the two groups are level: authorities with 100 or more endpoints have a median score of 60 in the EU and 59 outside it.

Post-quantum key exchange is where the gap opens up. Across the eight, 2,521 of 2,840 probed endpoints (89%) negotiate hybrid ML-KEM, against 21% in the EU. Singapore covers all 59 of its probed endpoints, Japan 1,120 of 1,121, Australia 96%, and the IRS and HMRC 86 to 87%. Much of that traffic runs through large CDN and cloud platforms that enable it by default, the shortcut most EU tax authorities have not taken. TLS 1.3 follows the same pattern, at 88% of endpoints outside the EU against 71% inside it.

Singapore is the standout. IRAS scored 85 across 86 endpoints, with TLS 1.3 and post-quantum key exchange on every one and no legacy protocols. That would put it sixth in the EU ranking, ahead of every European authority with more than 20 endpoints.

South Korea is the cautionary tale. HomeTax, the national filing portal, scored 43, below every EU authority except Denmark. It accepts TLS 1.0 on 43 hosts, offers RC4, IDEA, SEED and 3DES, supports TLS 1.3 on one endpoint and has no post-quantum key exchange. Japan has modern and legacy side by side: all but one of its probed endpoints negotiate post-quantum key exchange, while 44 hosts still accept TLS 1.0. Switzerland’s federal tax administration, like South Korea, has no post-quantum key exchange anywhere, and still offers the obsolete SEED cipher.

What this says about public-sector security

Every authority in this study has a competent team running its main portal. What separates the top of the table from the bottom is whether anyone owns the rest: the hosts set up for a project, a partner or a migration and then left running on whatever was standard at the time. Nobody decided to keep TLS 1.0 alive on Denmark’s eleven hosts, and nobody decided to switch it off either.

Tax administrations are in scope of NIS2 as central government entities, and “we did not know that host existed” is getting harder to say to a supervisor. You only find those hosts by looking at everything the organization has ever put a certificate on, which is what Certificate Transparency logs make possible.

Every number in this article comes from the same scan anyone can run at sslboard.com. The free summary gives you the score and main findings in a few minutes. The full report adds every affected hostname and IP:port, the certificate inventory and CSV exports, so whoever has to fix the problem knows where to start. It costs $20 for an estate of this size, and retests are free for 30 days so you can check the fixes landed.

Methodology

Cohort. One domain per EU member state: the official website of the national tax administration, checked by hand on 5 October 2026. Where an authority’s site is a subdomain of a wider government zone, as in Malta, Slovenia, Hungary and Luxembourg, the scan covers that subdomain only. Older and secondary domains were not scored, so every country is represented by one comparable domain. Some countries needed a judgment call:

  • Germany: the Länder collect tax, so we used elster.de, the national online filing portal.
  • Austria and Belgium: tax is run inside the finance ministry, so the ministry’s domain is the tax authority’s (bmf.gv.at and minfin.fgov.be).
  • Cyprus: there is no separate tax domain, so we scanned the finance ministry’s mof.gov.cy, where the Tax Department sits.
  • Luxembourg: tax is split between two administrations on public.lu, and we scanned impotsdirects.public.lu, the direct tax administration.
  • Croatia: the tax website is a page on the central gov.hr platform, run by another ministry. The tax administration’s own systems, including the ePorezna filing portal, run on porezna-uprava.hr, so we scored that.
  • Czechia: financnisprava.gov.cz is a single host, but electronic filing runs on the finance ministry’s domain, so we scored mfcr.cz, which also covers the rest of the ministry.

Comparison group. For the international comparison we scanned the domain of each authority’s own estate: irs.gov, hmrc.gov.uk (HMRC’s public pages live on the shared GOV.UK site, which we did not scan), estv.admin.ch (a subdomain of the shared Swiss federal domain; most Swiss tax is collected by the cantons), skatteetaten.no, nta.go.jp (including the e-Tax system), hometax.go.kr (South Korea’s national filing portal), iras.gov.sg and ato.gov.au. These eight are not part of the EU ranking.

Dates. 26 EU scans and all eight comparison scans ran on 5 October 2026. Belgium’s figures come from a scan of minfin.fgov.be taken on 25 September 2026.

What was tested. Hostnames were discovered from Certificate Transparency logs, then every reachable HTTPS endpoint (IP and port) was tested for accepted TLS versions and cipher suites, the certificate chain served (validity, expiry, key type and size, revocation), forward secrecy, hybrid post-quantum key exchange, OCSP stapling, HTTP to HTTPS redirects, HSTS and other security headers. DNSSEC was checked for every zone involved, and mail servers were checked for transport security. Everything was observed from the public internet, as any visitor would see it, without credentials and without testing anything beyond a normal handshake and HTTP request. “Post-quantum share” is the percentage of endpoints where our probe got a definite answer that negotiated hybrid ML-KEM key exchange.

Scoring. SSLBoard scoring model, version 2. The score combines seven weighted categories: certificate health (30%), confidentiality and agility (20%), protocols (15%), ciphers (15%), web hardening (10%), reliability (5%) and future readiness (5%). Penalties scale with the share of affected hosts or endpoints, so one bad host in a large estate costs less than one bad host out of three.

Size. Scores fall as estates grow: the median is 83.5 for authorities with fewer than 20 endpoints, 73.5 for 20 to 99, and 60 for 100 or more (Spearman rank correlation of -0.73). Part of that is fair: a larger attack surface is harder to defend, and we treat keeping it small as a strength. We show endpoint counts next to every score so readers can see both.

Certificates and DNS. Certificate counts cover the distinct certificates served on reachable endpoints; CA counts use the valid ones. “Short-lived” means a validity period of 100 days or less. CAA was read for every scanned hostname and checked by hand up the DNS tree to the top-level domain, as a CA would. For impots.gouv.fr and nta.go.jp our DNSSEC check returned an error, so we verified both by hand: impots.gouv.fr has no DS record and is unsigned, nta.go.jp is signed and validates.

Sources for the French incident. BleepingComputer; The Register, 14 August 2026; France 24, 19 August 2026.