There is a story the UK industry tells about IPv6, and it goes like this. The move is hard. The kit is old. The customers do not ask for it. There is no money in it. One day, when the business case turns, we will get to it.
Every part of that is a lie the industry tells itself so it does not have to do any work.
IPv6 was specified in December 1995. I got onto it through the 6bone, the experimental testbed that carried it before the real internet would, and ran both the Linux stack and Microsoft Research’s stack on Windows XP to see how they differed. My access came from Hurricane Electric.
The 6bone was switched off on 6 June 2006, so I moved to 6to4 automatic tunnelling, and later to a Hurricane Electric tunnel — still free, and they will route you a /48 for the asking. Native IPv6 arrived at my house in 2017, when I changed ISP to Zen.
So for the best part of twenty years my IPv6 came from an American transit company giving it away, rather than from any of the British ISPs I was paying. Hurricane Electric handed out routed /48s to anyone who wanted one. My own provider would sell me a static IPv4 for a fiver a month.
The dates say the rest. The IETF killed the 6bone in 2006 and deprecated 6to4’s anycast relays in May 2015, calling the mechanism “unsuitable for widespread deployment and use in the Internet”. I outlived two official transition mechanisms waiting for a British ISP to hand me an address. On the day the 6bone shut down, thirty-seven of the forty UK providers in the chart below had not yet asked the registry for an allocation. Twenty-two of them — more than half — did not ask until 2015 or later, the year the IETF gave up on 6to4 as well.
It has been switched on by default in every operating system anyone runs since Windows Vista in 2007. It costs nothing extra from the registry. The biggest ISP that ever tried it in this country finished the job in three years with a team you could fit in a meeting room, and won an award for it.
Thirty years past the specification. Fourteen years past the day the internet permanently switched it on. And the answer in this country was to break the internet on purpose, wrap the broken bit in more machinery, and bill the customer for the inconvenience.
That is not a cost problem. It is a can’t-be-bothered problem, and it has been going on for twenty years.
What I Measured, and How
Everything below is either somebody else’s work, linked, or a number I produced myself. Where it is mine, the script that counted it is in the download below, run as published. The one exception is the address totals, and I explain how those are worked out in the caveats. Four public sources, all free: the registry delegation files, the RIPE routing table dump, the RIPE database, and the DNS. Where I picked a sample instead of measuring the lot, I say so.
The routing numbers come from two sets of public files.
The first is the delegation files, one per regional registry, which list every address block and AS number that registry has handed out, the country it is registered to, and an opaque identifier for the organisation holding it. RIPE’s covers Europe and the Middle East, and it is the one that matters for the UK — but a few dozen UK-registered AS numbers sit in the ARIN and APNIC files instead, and the comparison further down needs the lot. Mine were generated 26 and 27 August 2026.
The second is the RIPE Routing Information Service’s dump of the global routing table, which lists every prefix in BGP and the AS number announcing it. IPv4 and IPv6 come as separate files. Mine was generated at 18:06 UTC on 27 August 2026.
Put them together and you can answer a question nobody in the UK industry wants asked out loud: of the networks this country registered, how many have actually turned IPv6 on?
The scripts, ready to runTake the AS numbers registered to GB out of the delegation files, take every AS number originating a prefix out of the RIS dumps, and comm the two lists against each other per address family. That gives the first table below. One trap worth naming: sort lexically, not with sort -n. comm compares strings, and numerically sorted input silently gives you the wrong answer rather than an error you would notice.
Swap GB for any other country code and you get that country’s row in the comparison table further down. 05-country-row.sh does exactly that.
The organisation-level numbers use the eighth field, which is the registry’s opaque handle for the account holding each resource. These stay on the RIPE file alone — the handles are local to each registry, so concatenating five of them would count the same company twice rather than merging it. UK organisations are RIPE members, so RIPE is where they are. This is how many hold an AS number and no IPv6 at all:
03-org-no-ipv6.sh counts them. And 04-silent-holders.py is the one that matters most. The organisations that hold IPv6, are live in BGP, and announce none of it.
Four caveats before the numbers, because they matter and I would rather say them than have them thrown at me.
The organisation handles are per registry account, so a company running several accounts counts more than once.
Announcing an IPv6 prefix in BGP is not the same as handing IPv6 to a customer. It is the floor, not the ceiling. A network that announces nothing has certainly not deployed it. A network that announces something might still be sitting on it.
The address totals collapse overlapping prefixes. A network announcing a /16 alongside four /17s out of it is announcing 65,536 addresses, not 196,608, and counting the prefixes naively inflates the big holders by two or three times. I use Python’s ipaddress.collapse_addresses before totalling.
The list of fifty websites later on is a sample I picked by hand, not a measurement of the whole country. A different fifty would give a different fraction. It illustrates a pattern rather than proving a proportion, and I name the ones I am talking about as I go.
The first two of those make the routing numbers kinder to the industry than the truth.
The Count
| AS numbers registered to UK organisations | 3,106 |
| Visible in the global routing table | 2,248 |
| Announcing IPv4 | 2,078 |
| Announcing IPv6 | 1,048 |
| Announcing IPv4 and no IPv6 | 1,200 — 57.7% |
Nearly six in ten live UK networks do not carry IPv6 at all. Not partially. Not behind a flag. Not in a lab. Not one prefix.
Now the part that ends the cost argument for good.
Of the 2,363 UK organisations holding an AS number, 1,113 — 47.1% — hold no IPv6 allocation of any kind. They have never asked the registry for it.
A RIPE NCC membership costs EUR 1,800 a year for 2026, flat, and that fee covers your allocations. An IPv6 /29 gives you 524,288 subnets the size of the entire IPv4 internet. It is free with a membership these organisations are already paying for, and it arrives in a couple of days.
Half of them never filled the form in.
And of the ones who did, 463 UK organisations hold IPv6 space, announce IPv4 to the world every day, and announce no IPv6 whatsoever. That is 44.7% of the UK IPv6 holders that are live in BGP.
Read that again, because it is the whole post in one sentence. They asked for the addresses. They were given the addresses. They put them in a spreadsheet. Then nobody could be bothered to type them into a router.
You cannot explain that with money. Nobody spent anything. There is no invoice, no procurement, no business case, no capital request. There is a free thing sitting in a registry account, and an engineering department that has not opened the ticket in fourteen years.
Who Is On That List
These are the largest UK networks announcing IPv4 and no IPv6, by the amount of address space they actually announce, on 27 August 2026. The names come from the RIPE database, which will tell you who holds any of them:
curl -s https://rest.db.ripe.net/ripe/aut-num/AS15914.json \
| python3 -c 'import sys,json; a=json.load(sys.stdin)["objects"]["object"][0]["attributes"]["attribute"]; print(next(x["value"] for x in a if x["name"]=="org"))'
Look at that list and try to say the words “cost barrier” without laughing.
Four of the clearing banks. A global accountancy firm whose entire product is telling other people how to run their affairs. A defence technology company. A hosting provider whose customers pay it to know this. An internet-of-things connectivity business, selling SIM cards, with no IPv6.
Between them, the UK networks announcing no IPv6 are sitting on 4,232,232 IPv4 addresses. The transfer market averaged $20.04 an address across the first half of 2026, so that is a holding worth somewhere north of eighty million dollars. Which is the actual reason none of them have moved: they are rich in addresses, so the shortage is somebody else’s problem, and the internet’s long-term plumbing is nobody’s job in particular.
That is not a strategy. That is being comfortable.
The delegation file carries the date each block was handed out, so you can see exactly how comfortable:
grep -E '\|ipv4\|(141\.228|155\.131|155\.136|161\.2)\.0\.0\|' \
delegated-ripencc-extended-latest | cut -d'|' -f4,5,6
Barclays has held 141.228.0.0/16 since 6 August 1990. Nationwide and NatWest took theirs in November 1991, four days apart. British Airways got 161.2.0.0/16 in April 1992. These are class B blocks from before the web existed, handed out when addresses were free and nobody counted.
Everyone who came after them pays for that. AWS started charging $0.005 an hour for every public IPv4 address on 1 February 2024 — $43.80 a year, each — and said plainly why: the cost of acquiring one “has risen more than 300% over the past 5 years.” The scarcity is real and it has a price. It is just not being paid by the people holding four million addresses they got for nowt in 1991.
How We Look Against Countries Like Us
Two numbers per country. The first is the share of its people who reach Google over native IPv6, which is Google’s measurement on 25 August 2026. The second is the share of its live networks that announce an IPv6 prefix, which is mine, from the same files as above. I have kept it to developed economies. Comparing ourselves with countries that got the internet late tells you nothing about us. Ordered by people.
| Country | Users on IPv6 | Networks with IPv6 | Live networks |
|---|---|---|---|
| France | 85.6% | 48.5% | 1,368 |
| Germany | 76.6% | 63.9% | 2,291 |
| Belgium | 72.8% | 45.8% | 273 |
| United States | 56.6% | 25.9% | 18,453 |
| Japan | 56.1% | 56.4% | 721 |
| United Kingdom | 53.7% | 42.3% | 2,078 |
| Norway | 52.6% | 66.9% | 278 |
| Netherlands | 51.9% | 61.8% | 1,023 |
| Canada | 43.6% | 33.1% | 1,578 |
| Ireland | 38.1% | 41.5% | 195 |
| Australia | 37.2% | 26.3% | 1,652 |
| Sweden | 36.1% | 53.6% | 642 |
| South Korea | 18.1% | 5.3% | 916 |
| Italy | 17.6% | 35.8% | 1,078 |
| Spain | 13.3% | 26.7% | 934 |
Sixth of fifteen. France has two thirds again as many of its people on IPv6 as we do, off the same European supply chain, under the same equipment vendors, with the same customers telling them nobody is asking for it. Germany is twenty-three points ahead of us on users and twenty-two points ahead on networks.
The two percentage columns do not agree with each other, and the disagreement is the story.
A country’s user percentage is set by three or four companies. The network percentage is set by everybody else. When the first is high and the second is low, it means the big access networks did the job and the rest of the country free-rode on them.
The United States is the clearest case: 56.6% of its people are on IPv6 and only 25.9% of its networks are. The cable and mobile carriers carry nearly everyone. The other eighteen thousand American networks did nothing.
Ours is the same trick with smaller numbers — 53.7% of users against 42.3% of networks. That 53.7% is not a national achievement. It is Sky and BT, and a rounding error of everyone else.
Norway and Sweden are the honest counter-shape: fewer users on IPv6 than us, more networks carrying it. More of their industry has actually done the work, and it is the consumer ISPs that are lagging rather than the trade.
And one row deserves a closer look, because it is the one people reach for when they want to feel better about us.
South Korea is the worst country on this list, by a distance. Of 916 live Korean networks, 61 announce IPv6. Sixty-one.
Some of the fastest domestic broadband on earth, a chip industry that prints money, and 94.7% of its networks never turned it on. The three big carriers — KT, SK Broadband and LG U+ — all announce it, which is why 18.1% of Korean users have it. The other eight hundred and fifty networks did nowt.
Whatever the excuse is there, it is not money, it is not capability, and it is not the state of the fibre.
Twenty Years Of Bolting Things On
Here is what the industry built instead of typing in the addresses.
When the addresses started running short, the answer was carrier-grade NAT: put hundreds of customers behind one public IPv4 address and translate between them. Everything below exists to make that survivable, and every one of these documents is a piece of engineering work somebody chose to do rather than deploy IPv6.
| Bolt-on | What it is for |
|---|---|
| RFC 6598 (2012) | Burns an entire /10 — four million addresses — as “shared address space”, so the shortage workaround needs its own addresses |
| RFC 6333 (2011) | DS-Lite: tunnel IPv4 over the IPv6 network you built but did not give the customer |
| RFC 6877 (2013) | 464XLAT: translate IPv4 to IPv6 and back again on the same journey |
| RFC 6888 (2013) | The list of requirements a carrier-grade NAT must meet not to be dangerous |
| RFC 7021 (2013) | A full study of the applications carrier-grade NAT breaks |
| RFC 7422 (2014) | Deterministic address mapping, invented purely to stop the logging volume bankrupting the provider |
| RFC 7597 / 7599 (2015) | MAP-E and MAP-T: two more ways to carry IPv4 over IPv6 without admitting you have IPv6 |
Look at the shape of that. Every item on the list is harder than dual-stack. Tunnelling IPv4 inside IPv6 is strictly more work than routing IPv6, because you have to route the IPv6 anyway to carry the tunnel. Translating between families is more work than not translating. A carrier-grade NAT is a stateful box in the middle of your network, with capacity planning, failover, session tables, port block allocation, application-layer gateways for the protocols it breaks, and a logging pipeline sized for a legal obligation.
Dual-stack is an address family, a routing protocol you already run, and a firewall policy you already wrote.
The industry looked at those two options and picked the expensive one, twenty years running, because the expensive one could be bought and the cheap one had to be understood. Buying a box is a procurement exercise. Turning on IPv6 means somebody in the building has to know how the network works.
What This Actually Breaks
For anyone who thinks this is aesthetics, here is what a shared address costs your users, in the order they will phone you about it.
Nothing can reach in. No port forwarding, so no self-hosted anything, no games console acting as host, no site-to-site VPN without a relay, no security camera without a vendor cloud, no remote access to the thing at the other site. Every one of those gets replaced by a third-party rendezvous service, which is another company holding your data because your provider would not give you an address.
You inherit strangers’ reputations. Share an address with a few hundred people and you share their behaviour. Rate limits, CAPTCHAs, Wikipedia blocks, streaming geo-errors and fraud scoring all land on you for something someone else did.
Ports run out. A carrier-grade NAT has 65,535 ports per public address per protocol, and one modern browser session eats dozens. Oversubscribe and the failure is not a clean error. It is a slow, intermittent, unreproducible fault that looks like everything except what it is, and it burns days of support time per incident.
Every workaround has to be maintained forever, by people who could have spent that time on the fix.
And then there is the one that stopped being an inconvenience and became everybody’s problem. Nobody can tell who did what.
The Bolt-On That Reached Parliament
Once hundreds of customers share one address, an address no longer identifies anybody. So the police cannot resolve an IP address to a person, and the answer to that was not IPv6. It was legislation.
Section 21 of the Counter-Terrorism and Security Act 2015 amended the data retention regime specifically so the Secretary of State could compel providers to retain the extra data needed “to link the unique attributes of a public Internet Protocol (IP) address to the person (or device) using it at any given time.” The explanatory notes are blunt about why it was needed: providers “may share IP addresses between multiple users, and the providers generally have no business purpose for keeping a log of who used each address at a specific point in time.”
Read that as an engineer rather than a lawyer. The industry broke attribution to save itself some work, and Parliament passed a law obliging it to build a logging system to paper over the breakage.
Two years later Europol put it plainly. In October 2017 it published a call for the industry to stop using carrier-grade NAT, with figures: 90% of mobile internet access providers and 50% of fixed-line providers had adopted a technology that stopped them identifying their own subscribers. Europol’s then executive director said CGN “has created a serious online capability gap in law enforcement efforts to investigate and attribute crime”, and noted that it “forces judiciary and law enforcement authorities to investigate many more individuals than would normally be necessary.”
Europol also said the quiet part. Carrier-grade NAT “was supposed to be a temporary solution until the transition to IPv6 was completed”. Instead the industry kept increasing its use of it while the replacement sat there, finished, free and ignored.
So the cost of not deploying IPv6 includes: a piece of primary legislation, a nationwide retention obligation, innocent people pulled into investigations because they shared an address with somebody who was not innocent, and an ongoing capability gap that the police describe as a public safety problem.
Nobody put that on the business case. It never appears in the “IPv6 has no ROI” slide, because it is not paid for by the people who caused it.
It Does Not Just Hide Criminals. It Helps Them.
The attribution argument is the one law enforcement makes, and it is about catching people after the event. There is a second argument that gets made far less often and is worse: address sharing actively degrades the defences that stop attacks happening at all.
This is not my analysis. The IETF published the catalogue in RFC 6269, Issues with IP Address Sharing, in June 2011. That was before the UK deployed most of the carrier-grade NAT it now runs. Its plain words: address sharing “creates a vector for attack amplification in numerous ways.”
Here is what it warned would break, and did.
Rate limiting and lockouts stop working. The standard defence against password guessing and credential stuffing is to count failures per address and put the offender in a penalty box. Share that address between hundreds of people and the counter is measuring a crowd. RFC 6269 is blunt about the outcome: “In the presence of widespread large-scale address sharing, penalty box solutions to service abuse simply will not work.” One user’s failed logins lock out everybody else, so operators raise the thresholds, and raising the thresholds is what the attacker wanted.
Blocklisting becomes collateral damage. Block the spammer and you block the road they live on. So the sensible operator stops blocking, and the abuse continues from an address nobody dares touch.
Infected machines stay infected. Abuse feeds and malware notifications arrive as an address and a timestamp. Behind a CGN with no port logging, the provider cannot tell which of its customers is running the bot, so the customer never gets told and the infection stays up. Worse, RFC 6269 notes the reverse problem: “someone else’s worm can interfere with the ability to access the service for other subscribers sharing the same IP address.”
Address-based access control fails. Every allow-list built on source address is now admitting a crowd rather than a customer.
And one defence is measurably weakened rather than merely blunted. Blind TCP attacks depend on guessing the five-tuple, and the industry’s mitigation is randomising the source port (RFC 6056). A carrier-grade NAT hands each subscriber a slice of the port range instead of the whole of it. In RFC 6269’s words, “with shared IPv4 addresses, the port selection space is reduced.” The workaround for the address shortage takes entropy directly out of an anti-attack mechanism.
Then there is the part that ought to worry anybody, regardless of what they think about policing. If the server did not log source ports and the NAT did not log destinations, RFC 6269 spells out what a provider must do when a lawful request arrives: it “would need to disclose the identity of all subscribers who had active sessions on the NAT during the time period in question. This may be a large number of subscribers.”
The alternative to identifying one guilty subscriber is handing over the identities of several hundred innocent ones. That is the actual privacy outcome of address sharing, and it is the opposite of the one its defenders claim for it.
Three Things Have To Line Up, And Nobody Is Required To Provide Any Of Them
People assume the logs exist somewhere and it is a matter of asking. They mostly do not, and the reason is arithmetic rather than ill will.
To turn a shared address back into a household, three separate things must all have gone right:
- The far-end server logged the source port. RFC 6302 asked internet-facing servers to log source port and timestamp alongside the address, in 2011. It is a recommendation. Nobody enforces it, and a great many servers still log the address alone. At which point the trail is dead before it reaches the British end.
- The provider kept the mapping. Every session, for months.
- The clocks agreed. RFC 6269 warns that on a busy CGN “even very small amounts of clock skew between a third party’s server and the CGN operator will result in ambiguity about which customer was using a specific port at a given time.”
Miss any one and you have nothing. And the middle one is where it falls apart, because the standards documents contain the sums.
RFC 7422 put real numbers on it. Operators reported roughly 33,000 connections per household per day. At about 150 bytes per log entry that is 5 MB per subscriber per day, 150 MB a month. For a provider with a million subscribers: 150 terabytes of logs a month, 1.8 petabytes a year — to be kept for the six to twelve months the law expects, and searched on demand.
And it is never one log. NAT444, the case RFC 7422 sizes its entries for, puts one translation in the customer’s router and another at the carrier, and every gate a packet crosses has to write down what it did. Reconstructing a single session means correlating separate tables, kept by separate parties, against the clock problem above. The evidence arrives in pieces from different systems, or it does not arrive.
And the money is only half of it. Capturing session records at that rate, shipping them somewhere, indexing them so a lawful request comes back in hours rather than weeks, and holding the lot for a year is a data engineering project. There is no dashboard for it and no box to buy. It has to be built by somebody who understands what they are building, and that is not point and click, which in this industry is close enough to saying it does not get built.
Nobody was ever going to pay for it either. And the IETF knew it, which is why RFC 6888 tells operators the opposite of what public safety needs: “A CGN’s port allocation scheme SHOULD minimize log volume”, justified because “huge log volumes can be problematic to CGN operators.” RFC 7422 exists for no other purpose than cutting that bill down.
So the design advice to the industry is log less, the economics say 1.8 petabytes a year is unaffordable, and the legal expectation is a complete record. Those cannot all be true at once, and the one that gives is the record.
That is why Europol found the majority of access providers cannot identify a subscriber when served with a legal order. Not because they are obstructive. Because the thing being asked for was never economically possible to keep, and nobody was ever made to.
Two things follow from that, and they are mine rather than anybody’s quote.
First: a large share of British internet connections are unattributable by construction. Mobile is the clearest case, and independent measurement puts it higher than Europol did, at 95%. So the anonymity that used to require Tor, or a VPN somebody had to buy, is now the factory setting on a British mobile connection — issued free with the SIM, to everybody, including the small number of people the whole apparatus is meant to find.
Second, and worse: breaking the cheap targeted method is what produces demand for the expensive untargeted one. When you can serve a warrant on one address and get one household, you need nothing else. When that stops working, the state does not shrug. It reaches for something broader. That is what the 2015 Act was: a retention duty across the whole subscriber base, to answer questions about a handful of people.
None of that exists on the other side. Nothing is translated, so there is no per-connection record to keep at all. The address in the far-end server’s log is already the subscriber’s prefix: one record, written once when the line was provisioned, in one system. Even a provider rotating prefixes daily writes a few hundred a year per customer, against the twelve million that 33,000 connections a day comes to. It is not that IPv6 logs less. There is nothing to log.
The people who wrote the workaround knew it. In the middle of a specification written for no reason but to make CGN affordable to log, they stopped to record that “native IPv6 will offer subscribers a better experience than CGN”.
An industry declined to spend a fortnight per network on a free protocol, and the country got a data retention regime instead.
Would Fixing This Protect Children Better Than The Online Safety Act?
I want to be careful here, because it is easy to make this argument badly and the badly-made version deserves the kicking it would get.
Start with how a child abuse investigation actually runs. A platform detects the material and reports it. The report carries an address and a timestamp. Police serve the access provider to turn that into a subscriber, and the subscriber is an address in the real world with a door on it. That is the whole chain, and every step after it depends on the one before.
Now put a carrier-grade NAT in the middle. The report still arrives. The address still resolves. To several hundred households, and Europol found investigations “dropped or delayed” as a result. Their case examples include a prosecutor unable to identify the members of a forum supporting ISIS, so the prosecution did not happen, and HMRC tracing bulk tax fraud to mobile addresses and finding the leads “frustrated from the outset”.
NCMEC’s CyberTipline took 21.3 million reports in 2025 and referred more than 18.8 million to law enforcement, including over 53,000 involving a child in immediate danger. NCMEC also records that more than 10% of industry reports arrived with information too poor to work out which jurisdiction to send them to. That figure is not CGNAT’s doing and I am not claiming it is — but it tells you where in this pipeline cases die. They die on metadata.
So the honest version of the comparison is this. Carrier-grade NAT breaks the Online Safety Act’s own last mile. Parliament has imposed duties to detect and report, and left the access network unable to resolve what gets reported. You may pass as many reporting duties as you like. If the final step returns a crowd, the report is paper.
And the cost of the two things is not remotely comparable. The Act is the largest piece of internet regulation this country has attempted — thousands of services in scope, a regulator writing codes for years, age assurance running at millions of checks a day, and a circumvention problem large enough that Parliament has debated VPN use in the Lords. IPv6 costs nothing from the registry and takes a competent team a couple of weeks. One of those has been required of the entire industry. The other has never been asked of anyone.
Three things need saying plainly, because the argument is worthless without them.
One. It is not a substitute, and I am not proposing it as one. IPv6 does nothing to stop a twelve-year-old finding pornography. It does nothing about recommender systems, autoplay or live-streaming. It does nothing about material hosted in another country, which is most of it. Those are the problems the Act was written for and no protocol change touches them.
Two. IPv6 is not an identity layer, and anyone selling it as one is overselling it. Privacy extensions rotate a device’s address by design, so the address of the machine is not the stable thing. What is stable is the prefix delegated to the line — the /56 that Sky has been handing every subscriber since 2016. That resolves to a subscriber, which is exactly the resolution a lawful request needs, and no more than that. It is a restoration of what a single IPv4 address per line used to give, not a new surveillance capability.
Three. The property that frustrates the police also frustrates everyone else who tracks you, and some people value that. Being one of five hundred behind a shared address is genuine crowd cover against commercial profiling. I do not think it is worth what it costs — it is cover bought by making abuse unattributable and rate limiting useless, and it is cover the platforms mostly see through anyway with cookies and fingerprinting. But it is a real argument and it deserves stating rather than ignoring.
So no, this is not IPv6 instead of the Online Safety Act. It is that Britain wrote the most expensive online safety law in its history on top of plumbing it knew was broken, when the fix was free, well documented, and available for the whole time the Bill was being drafted.
What To Actually Ask For
Not a ban. A ban is the wrong instrument and it would backfire.
There is no IPv4 left to hand out — RIPE has been empty since November 2019, and a new provider gets a single /24 from a waiting list. Outlaw address sharing tomorrow and the small operator cannot connect customers at all, while the outfits sitting on class B blocks from 1990 carry on untouched. It would entrench exactly the people this post is about.
The better instrument already exists and somebody has already run the experiment.
In 2012 Belgium’s federal police, its telecoms regulator, its Council of Prosecutors-General and its ISP association signed a two-page voluntary code of conduct. Maximum 16 subscribers behind one IPv4 address. Limit the use of CGN. Start adopting IPv6.
By 2017 most Belgian operators were inside the limit, one had gone down to 8, and Belgian police were seeing an average of four users per mobile address. Europol’s own summary of why is the part worth reading twice: the biggest providers “are quickly moving towards IPv6 because no financial interest to invest in CGN anymore.” Cap the oversubscription and the economics of the workaround collapse, because a NAT that can only stack sixteen people is not cheaper than the protocol that needs none.
That year Belgium had the highest IPv6 adoption in the world at 49%, when Britain and France were on 14% and Spain and Italy were under 1%. Belgium is still third in the country table above, on 72.8%.
That is the ask. Not “you may not share addresses” — you may not sell a connection that is both unattributable and has no IPv6. Shared addressing alongside working IPv6 is fine. That is how every mobile network on earth operates. Shared addressing with no IPv6 is selling a broken service and charging the public for the consequences.
Sky Proved It Could Be Done, Eleven Years Ago
If it were genuinely hard, nobody in the UK would have managed it.
Sky started an internal IPv6 project in early 2013 and finished in 2016, with roughly 90% of its fixed-line base — about five million users — picking up IPv6 and using it. Their engineer wrote the whole thing up on RIPE Labs: 6PE across the MPLS core, dual-stacked peering and transit, RADIUS attributes to enable it per subscriber, firmware work across seven CPE models including five legacy ones, and capacity upgrades on RADIUS and DNS.
Three years, one ISP, and the same Openreach copper everybody else was selling over. ISPreview reported the finish in September 2016, with Sky expecting 95% of its base by the end of that year, and Sky took the Jim Bound IPv6 Award for it.
Their advice was: “Do not underestimate the work required to enable IPv6, and do not leave it to the last minute to begin the journey.”
Eleven years later, most of the industry is still at the last minute, and treating it as a place to live.
Everybody Has Had The Addresses For Years
Sky was the first of the big ISPs. It was nowhere near the first in the country, and not one provider on this list can say it was waiting on the registry.
RIPE stamps the allocation date into the name of the block, so you can check any of them yourself:
whois -h whois.ripe.net 2a01:4b00::/32 | grep -E 'netname|^org:'
# netname: UK-BCUBE-20110225 -> Hyperoptic, allocated 25 February 2011
Every date below came from that lookup against the provider’s own allocation, cross-checked against the delegation file. The big ISPs are in bold, the rest are the full-fibre builders. Whether customers actually get IPv6 is from ISPreview’s survey as updated in March 2025, and from the mobile tracker for the phone networks.
Forty providers. Every one has held IPv6 address space for at least three years, most of them for over a decade — and seventeen of them still do not give it to a customer.
Hyperoptic has held 2a01:4b00::/32 since February 2011. Fifteen years of building fibre into blocks of flats, selling gigabit connections, and putting people behind carrier-grade NAT with an unused IPv6 allocation on the books. Trooli has had theirs thirteen years. Truespeed and Airband ten.
Andrews & Arnold is the one to hold the rest against. A small ISP in Bracknell with a fraction of the customers and engineers of anybody else on that list, giving IPv6 to every line since 2002, and one of the outfits behind 6UK. TalkTalk took its allocation three months earlier and still does not ship it to consumers.
Virgin Media took its block three weeks before Zen took theirs. Zen shipped it, and I have been on the end of one of their /48s ever since. Virgin is still saying “when we are ready”.
And look at the bottom of the table. Squirrel, brsk, Lit Fibre and Octaplus all got their allocations in the last six years and all ship IPv6, while providers holding space since 2011 do not. Starting late is not the obstacle. Starting at all is.
Two names from that survey are not in the chart, and the reason is the same for both. Cuckoo is a retail brand buying wholesale access over Openreach, CityFibre and others, and Freedom Fibre is a wholesale network whose customers come through retail partners. Neither holds its own address space, so IPv6 is somebody else’s decision to make for them. iDNET is marked with an asterisk because theirs is a provider-independent assignment rather than an allocation of their own.
The One That Settles It
If you want the argument reduced to a single company, it is Plusnet.
BT bought Plusnet in January 2007. Plusnet sits under British Telecommunications’ own RIPE account, so it has had access to BT’s IPv6 allocation since June 2010. BT ships IPv6. EE, the other sister company, ships IPv6. ISPreview noted that BT and Plusnet even use nearly identical customer routers, calling the gap “somewhat of a peculiarity”.
Plusnet trialled IPv6 in 2011 and publicly urged the rest of the industry to get on with it. In 2019 it said it would launch in spring 2020. In 2021 it expected “to make good progress over the coming year”. In November 2023 it ran a three-month trial across two sites in Chesterfield and Sheffield, with about twenty staff and friendly customers on it.
In April 2026 its own customer forum was still asking where IPv6 had got to.
One parent company. One address allocation. Near-identical hardware. Engineers who work for the same group and can walk down the corridor to the people who already did it. Three brands, and one of them cannot manage in fifteen years what the other two finished.
Whatever is stopping this, it is not the technology, the money, the kit, or the address space. It is somebody deciding it is not their problem this quarter, fifteen years running.
Virgin Media, Sixteen Years Of “When We Are Ready”
The other end of the scale deserves naming, because the timeline is a matter of public record and it is remarkable.
March 2010: a customer asks on Virgin Media’s own forum when IPv6 is coming. The answer is “when we are ready”.
November 2016: Virgin tells ISPreview it plans to adopt IPv6 by mid-2017. It does not.
June 2018: a consumer trial is reported. December 2018: a third presentation to the UK IPv6 Council, hinting at 2019.
2021: a statement that they are “continuing to plan our IPV6 deployment having tested several solutions and intend to introduce IPV6 for our customers in future.”
February 2024: Virgin Media locks the fourteen-year-old forum thread.
August 2026: still nothing.
Sixteen years. In that time the company was bought, merged with O2, rebuilt its core twice and replaced its entire router estate. At no point did anyone add an address family. Locking the thread is the most honest thing in that list. It is the moment they stopped pretending and started managing the complaint instead of the problem.
The Altnets Had No Excuse At All
The full-fibre builders were the chance to start clean. New networks, new kit, no legacy, engineers hired this decade. Look at where they sit in the allocation table and most of them took the address space and stopped.
So a company that raised institutional money to build a brand-new fibre network dug up the roads, blew fibre to a hundred thousand homes, bought new routers, wrote a new provisioning stack. And put its customers behind a shared address on a network with no IPv6, in 2026, with the address space already sat in its own registry account.
And then several of them charge £5 a month for a static public IPv4.
They took away the working thing, declined to ship the free replacement, and turned the resulting breakage into a line item on your bill. There is a word for a business model that manufactures a fault and then sells the fix, and it is not “innovation”.
The Websites Give The Game Away
The routing table shows what networks do. The DNS shows what everybody else does. So on 27 August 2026 I put fifty of the UK’s best-known sites in a file — central government, the banks, the big retailers, the telcos, transport and a few universities — and asked each one whether it answers on IPv6:
while read -r d; do
n=$(dig +short AAAA "$d" | grep -c ':')
printf '%-46s %s\n' "$d" "$([ "$n" -gt 0 ] && echo AAAA || echo none)"
done < sites.txt | sort -k2
Then I checked every answer against a second resolver, because one recursive server having a bad day is not a finding:
dig @1.1.1.1 +short AAAA www.tesco.com | grep -c ':'
Seventeen out of fifty had an AAAA record. Thirty-three did not, and both resolvers agreed on every one.
The ones with no IPv6 include www.bbc.co.uk, www.nhs.uk, www.hmrc.gov.uk, www.hsbc.co.uk, www.barclays.co.uk, www.lloydsbank.com, www.santander.co.uk, www.tesco.com, www.johnlewis.com, www.marksandspencer.com, www.britishairways.com, tfl.gov.uk, monzo.com — a bank founded in 2015, with no legacy anything — and, my favourite, www.sky.com.
Sky. The company that put five million customers on IPv6 and won a prize for it. Its own website does not answer on IPv6.
Now the bit that proves the thesis beyond argument.
Fifteen of the seventeen that do have IPv6 got it from a supplier, not from themselves. I resolved each one and looked up who owns the address that answered:
whois -h whois.radb.net -- "$(dig +short AAAA www.sainsburys.co.uk | grep ':' | head -1)" | grep -i descr
www.gov.uk and www.cam.ac.uk answer from Fastly. ico.org.uk, www.parliament.uk, www.ofcom.org.uk, www.asda.com, www.autotrader.co.uk, www.nationalrail.co.uk and www.jisc.ac.uk answer from Cloudflare, which turns IPv6 on for everyone by default. natwest.com and nationwide.co.uk answer from Azure Front Door. www.legalandgeneral.com and www.screwfix.com answer from CloudFront. www.sainsburys.co.uk and www.next.co.uk answer from Akamai.
Two did it themselves: Imperial College London, answering from its own address space, and the UK IPv6 Council’s own website. A university and the people whose entire purpose is IPv6. That is the list.
And www.tesco.com, www.sky.com and www.nhs.uk also sit on Akamai — the same CDN, the same product — and have no IPv6 at all.
Akamai has been explicit about this since June 2022: “Akamai has enabled IPv4+IPv6 dual-stack as the default for our CDN delivery products for many years, meaning that customers have needed to opt-out for content to be IPv4-only.” They added that they made it easy to switch, including through the API.
Same vendor. Same platform. Default on. One organisation left it alone and one went in and turned it off, or kept an ancient config nobody has read since. Sainsbury’s has IPv6 and Tesco does not, and the difference between them is a single configuration flag and somebody’s attention.
After that there is no cost argument and no complexity argument left standing. There is only whether anyone was paying attention.
Across the whole sample the rule holds: where IPv6 arrives as a supplier’s default, Britain has it. Where a British organisation would have had to decide something, it does not. Two sites out of fifty, and one of those was the IPv6 Council.
Which Brings Us To The Managed Service Industry
The consumer ISPs get the blame for CGNAT, and they have earned it. But the layer doing the most damage is the one that sells expertise: the managed service providers, the integrators, the outsourced network teams, the consultancies who write the low-level design.
Go back to the list of the biggest UK networks with no IPv6 — the banks, British Airways, PwC, QinetiQ. Those are not scrappy startups. They are outfits that pay a great deal of money for somebody else to run their network, or employ a large team to run it themselves. Every one of those AS numbers has a design document behind it, a change process, an architecture review board, and a supplier with “network” in its name. Not one of them produced an IPv6 plan.
The pattern is the same everywhere you look at it:
The template is IPv4. The build standard, the firewall ruleset, the monitoring checks, the IPAM, the runbook, the DR plan, the customer handover pack — all IPv4, written once, cloned for a decade. Adding an address family means editing all of it, and nobody is paid to edit it.
Nobody asked for it. This is the sentence that ends every IPv6 conversation in this industry, and it is a confession. Nobody asked for TLS 1.3 either. Nobody asked you to stop using SMBv1. Customers buy the outcome and pay you to know what the outcome requires. “The customer did not ask” means “I do not want to learn it and they cannot tell”.
RFC 1918 feels infinite. Ten-dot is 16.7 million addresses, so an internal network never feels short, so there is never a forcing event. Then the merger arrives, both estates are on 10.0.0.0/8, and the answer is another decade of overlapping-subnet NAT and a document explaining which fake address means which real one — more machinery, again, to avoid the address family that would have made it a non-problem.
IPv6 exposes competence. This is the real one. Dual-stack does not let you hide.
You have to know what your firewall policy actually is, because you have to write it twice. You have to know what your DNS looks like. You have to understand neighbour discovery, prefix delegation, and what your CPE does with a /56.
An engineer who has been getting by on NAT as an accidental security control finds out, in front of people, that it never was one. There are twenty-year careers in this industry built on that single confusion.
So it does not get proposed. Not because it costs money — it does not — but because proposing it means owning it, and owning it means learning it.
That is what I mean by bone idle. Not lazy in the sense of not working hard. This industry works extremely hard. It works hard at carrier-grade NAT, and at explaining to a customer why their CCTV will not connect from outside any more. It will do any amount of work, as long as the work is the kind you can buy rather than the kind you have to understand.
And that is about to stop being a matter of taste. The Cyber Security and Resilience Bill now going through Parliament would amend the NIS Regulations to pull in, among others, “managed service providers (organisations that provide third-party IT services to other businesses)”. It is not law yet. When it is, detection, logging and incident reporting stop being product lines this layer sells and become duties it has to discharge.
Sit that next to the chain further up. Resolving any abuse report starts with a far-end server having logged a source port, and the far-end server is very often one of these outfits’ boxes. The people who will shortly have to prove they can detect and report an incident are the same people who cannot presently be got to enable an address family, or to read a packet capture when a tunnel will not come up.
The Three Excuses
You will hear the same three every time, and none of them lasts a minute.
“Dual-stack is two of everything.” I ran it in production at Nominet, on F5 load balancers in front of the .uk registry, so I know what the objection is worth. So is the NAT tier you bought instead, and that one sits in the traffic path with a session table, a capacity model, a failover story and a logging obligation attached to it. You were never choosing between complexity and simplicity. You picked the complexity that came with an invoice.
“The kit does not support it.” In 2006, fair enough. In 2026 it means your kit is out of support, which is a worse thing to admit than the one you were trying to avoid saying.
“There is no revenue in it.” There is no revenue in backups either.
The Things People Post
The excuses above are what you hear in a meeting. Underneath them sits a layer of technical claims that get repeated in forum threads, comment sections and LinkedIn replies every single time IPv6 comes up, and most of them have been wrong for over a decade.
Some of this is honest confusion and some of it is a person who has decided not to learn something reaching for a reason. Either way it is worth going through, because these claims are doing real work. They are what an engineer repeats to a manager who cannot check them.
“NAT is my firewall. IPv6 puts every device straight on the internet.”
This is the big one and it is the wrong way round. The protection people credit to NAT comes from there being no mapping until something inside asks for one — which is a stateful firewall, and it is the firewall doing the work, not the translation. The IETF said so in RFC 4864 in 2007: that role, “often marketed as a firewall, is really an arbitrary artifact”, where a real firewall gives you “explicit and more comprehensive management controls.”
Every consumer IPv6 router ships with default-deny inbound. You get the same posture, from a policy somebody wrote down, rather than from a side effect of running out of addresses. And you can then permit exactly the one thing you meant to permit, instead of the port-forwarding séance.
If your entire security model is “attackers cannot find my devices”, you did not have a security model. You had NAT.
“IPv6 is slower.”
This one deserves an honest answer rather than a dismissal, because the truth is mixed and the people making it are not simply wrong.
Content providers who have optimised for it measure gains: Facebook reported page loads around 15% faster over IPv6, Akamai around 5% on mobile. APNIC’s broader measurement of the whole internet is less flattering and has IPv6 round-trip times running marginally higher on average — of the order of a millisecond or so, and improving over time.
So: broadly a wash, better where somebody has done the work, occasionally a hair worse where nobody has.
It is worth knowing where the cost actually sits, because the header is the thing people picture and the header is not the problem.
Start with what IPv6 took off the router. IPv4 carries a header checksum. The Time to Live changes every hop, so the checksum has to change with it, and RFC 6583 lists “verifying and updating the checksum” as a step in the forwarding process itself. IPv6 has none. That step just goes.
Then the length. An IPv4 header is variable, which is what IHL is for: a router reads a length before it knows where the payload starts. An IPv6 header is 40 bytes. Always. Every field sits at a fixed offset and nothing has to be worked out first.
Then fragmentation. IPv4 routers can fragment in flight, which is why Identification, Flags and Fragment Offset are sat in the header at all. RFC 8200 is flat about it: “fragmentation in IPv6 is performed only by source nodes, not by routers along a packet’s delivery path”. So that path goes as well.
On header handling alone IPv6 is the cheaper protocol to forward. It was built to be.
The one place it does cost more is per route, and that turns out not to matter. The lookup key went from 32 bits to 128, so an IPv6 forwarding entry is wider and on a lot of kit takes two hardware slots where an IPv4 route takes one. Everybody stops the argument there. It is worth going one step further, because the full table is four times smaller.
On the RIS dump generated at 02:03 UTC on 28 August 2026 there were 1,229,166 IPv4 prefixes in the global routing table and 300,470 IPv6 ones. Four times as many IPv4 routes, each a quarter of the width. So the raw key storage comes out a dead heat: 4.92 MB against 4.81 MB. Now apply the two-slots-per-IPv6-route rule people worry about. A full IPv6 table still needs about half the hardware entries of a full IPv4 one.
And the reason the IPv4 table is that big is the shortage itself. 767,543 of those 1.2 million routes are /24s — 62% of the entire IPv4 internet sitting at the longest prefix anybody will accept, because blocks got chopped up, sold off and announced in pieces by whoever bought them. Every one of those is a router somewhere holding an entry it would not need if the space had not run out.
So the memory argument runs the other way round from how it gets told in meetings. Carrying IPv6 is cheaper on your FIB than carrying IPv4, and it gets cheaper every year the transfer market slices another /16 into sixteen /24s.
And the CPU spikes people actually hit are neither of those. A modern router forwards both families in silicon at line rate. What hurts is anything that shoves a packet off that path into the control plane, which RFC 6583 calls “a ‘slower’ software process running on a general purpose processor”. That processor was sized for routing protocols. Never for traffic.
Two things shove packets at it. The first is extension headers. They are a chain rather than a fixed block, so a box wanting the layer-4 ports for an ACL or an ECMP hash has to walk a variable-length list to find them, and a Hop-by-Hop Options header “may be examined or processed by any node along a packet’s delivery path”. On plenty of kit that means punted.
The second is Neighbour Discovery. A /64 covers trillions of addresses that will never be assigned, so scanning one sets a router resolving addresses that do not exist. RFC 6583 exists for that, and calls it a denial of service.
Both have known answers. Filter Hop-by-Hop at the edge, rate-limit ND, cap the neighbour cache. Neither is a reason the protocol is slow. They are reasons an unconfigured router is slow, and that points where the rest of this post points.
Now weigh a millisecond against the alternative you actually deployed — a stateful translation box in the path of every connection, holding a session table, that breaks some of them outright. Nobody stalled for twenty years over a millisecond.
“There is plenty of IPv4 about, you can just buy it.”
You can. That is what a shortage looks like. Blocks handed out for nothing in 1990 now change hands at around $20 an address, and AWS bills $43.80 a year for every one you use.
A market in a thing does not prove there is plenty of it. It proves somebody worked out how to charge you for the shortage.
Nobody Was Ever Going To Make Them
The UK has no policy on this at all, and it never has.
There was an attempt. 6UK was set up in 2010 with £20,000 of seed money from the Department for Business, Innovation and Skills, backed by Vint Cerf, with LINX, AAISP, Timico and Easynet behind it. In December 2012 its volunteer directors resigned at the AGM, nobody stood for the board, and it was wound up. Its parting verdict: free-market incentives are insufficient, “one factor appears to dominate IPv6 adoption rates, namely government support,” and “countries with hands-off governments fall behind.”
Fourteen years on, that is exactly what happened. The UK IPv6 Council is still going, but a forum is not a lever.
Compare the United States, where OMB memorandum M-21-07 required 80% of federal IP-enabled assets to be IPv6-only by the end of the 2025 financial year. Agencies missed it. They still had a number to miss, a date to miss it by, and somebody who has to stand up and explain the miss. Here there is nothing to miss, so nobody has ever had to explain anything.
The UK government does not require IPv6 in its own procurement in any meaningful way. Ofcom does not measure it. No regulator asks about it. And so, predictably, www.nhs.uk and www.hmrc.gov.uk do not have it, while www.gov.uk does. And www.gov.uk only has it because it is served through Fastly, which turned IPv6 on years ago on somebody else’s behalf.
I have written before about what happens when nobody holds a contract over an industry — the mechanisms that work turn out to be the ones somebody with resources chooses to operate, and if nobody does, nothing happens for a decade. IPv6 in the UK is that pattern again, without even a members’ vote at the end of it.
And It Is Not That Nobody Noticed
The absence of a requirement would be disappointing if this had gone unspotted. It did not.
The state worked out what carrier-grade NAT does and legislated about it. Parliament looked straight at the problem, understood it well enough to write law about it, and wrote the law that accommodates the breakage. “Require them to deploy the protocol that removes it” was either never raised or was raised and dropped.
So we are a country whose declared position is that IP attribution matters enough for counter-terrorism legislation, and which asks not one provider to do the free thing that restores it. Fraud, account takeover, harassment, threats to kill, child abuse referrals and terrorism all arrive at the access network asking the same question, and for a lot of British connections the honest answer is “one of these several hundred households”.
The National Cyber Security Centre is part of GCHQ and publishes guidance on a great many things. It does not require IPv6 of anybody. Nobody in Britain does.
www.ncsc.gov.uk and www.gchq.gov.uk do both answer on IPv6, mind. So does the Internet Watch Foundation. All three because they sit behind Cloudflare, which turned it on for everyone by default. www.police.uk has none.
And What That Means For The Seventeen
Seventeen of the forty providers in this post sell connections with no IPv6, and about half the full-fibre builders put customers behind carrier-grade NAT.
I am not accusing any of them of a crime, and nobody in those buildings is hoping for one.
But a connection behind carrier-grade NAT with no IPv6 cannot be resolved to a subscriber. That is not contested. The IETF wrote it down in 2011, Europol in 2016 and 2017, Parliament in 2015 — all of it published before most of this equipment was bought. The alternative was free, and available the whole time.
That is what “we will get to IPv6 eventually” means, once you follow it down.
What To Do About It, Concretely
Short, because none of it is hard. That is the point of the whole post.
If you buy connectivity: put IPv6 in the tender as a pass/fail requirement, not a nice-to-have. Ask for native dual-stack and a delegated prefix, in writing, and ask what size.
If the answer is a single /64, keep asking. RFC 6177 killed that one in 2011: handing a home site one /64 “precludes the expectation that even home sites will grow to support multiple subnets”, and it is “strongly intended that even home sites be given multiple subnets worth of space, by default”.
What it did not do is name a size. It withdrew the old blanket /48, said the choice “is an issue for the operational community”, and dropped one worked example on the way past: a home default “of less than /48, such as a /56”.
The operators answered it themselves. RIPE-690 is their own practice document and it is blunt. A /48 each if you want a simple plan. A /48 for business and a /56 for residential if you want a pragmatic one. Anything longer than a /56 is “strongly discouraged”, and a /64 does not conform to IPv6 standards and will break customer LANs.
So the floor is a /56, and it is the IETF’s own number rather than anybody’s preference. Sky has handed every subscriber one since 2016. Zen hands out a /48, which is 65,536. A business should not accept less than a /48.
If a provider tells you a /48 to a house is extravagant, a British ISP has been doing it for years while they were still working out their position.
If you run an AS number: you probably already hold a /29 you have never announced. Check.
AS=AS20712 # your AS number
ORG=$(whois -h whois.ripe.net "$AS" | awk '/^org:/{print $2; exit}')
# what IPv6 the registry has already given you
whois -h whois.ripe.net -- "-i org $ORG" | grep -i '^inet6num'
# what you are actually announcing of it
whois -h whois.ripe.net -- "-i origin $AS" | grep -i '^route6'
If the first command prints a prefix and the second prints nothing, you are one of the 463.
Announce it, dual-stack your border and one internal VLAN, and put a AAAA on one public service. That is a fortnight’s work for one engineer and it turns your organisation from a statistic in the table above into one that has started.
If you run a website: check for an AAAA record. If you are behind a CDN, it is probably a toggle you can turn on this afternoon at no cost. If it is off, somebody turned it off.
If you sell managed services: write IPv6 into the build standard and the low-level design template, once, and every customer after that gets it by default. Nobody has to ask for it, because nobody asks for TLS either.
If you are an engineer who has never done it: build a lab tonight. About 90% of my own traffic runs over native IPv6 and it is the least eventful thing about my network. Get a tunnel or a VPS with a /64, put addresses on things, break it, fix it. It takes an evening to stop being frightening and it is the single cheapest thing you can do to your career this year.
The Questions I Cannot Settle
Everything above I can show you. This part is the bit I keep turning over, and I do not have a clean answer to any of it.
Why can some and not others?
This is the one that matters, and the data makes it stranger rather than clearer.
Sky and Virgin Media sold broadband to the same country, over the same regulator, at the same time. One finished in 2016. The other has been saying “when we are ready” since 2010. Sainsbury’s and Tesco sit on the same CDN, on a product where dual-stack is the default, and one has IPv6 and one does not. Norway and Britain buy from the same vendors and 66.9% of Norwegian networks carry IPv6 against 42.3% of ours.
Every external factor you might blame is held constant in those pairs. Same country, same suppliers, same kit, same customers, same decade, same regulator, same money. And the outcomes are opposite.
So the cause is not in the circumstances. It is inside the building. Somewhere in Sky there was a person who made this their business and kept making it their business for three years. In the other places there was not, or there was and nobody above them cared. That is the whole variable, and it is not a technical one.
Which is an uncomfortable answer, because you cannot procure it, and you cannot put it in a strategy document.
Is it training?
Partly, and less than you would think.
Look again at the 463 outfits holding IPv6 they have never announced. Somebody in each of those buildings knew enough to know they needed it, knew who to ask, filled the form in, and got it issued. The knowledge was there and the follow-through was not.
Training gets an engineer to the point of being able. It does not get them to the point of being made to. Nobody has ever had a bad appraisal for not deploying IPv6. Nobody has ever lost a contract over it. Until one of those is true, the training goes on the pile with everything else somebody learned on a course and never used.
How long until we are all on it?
I can put a number on this one, and it is worse than I expected.
Google has measured the share of its own visitors arriving over IPv6 since 2008. Taking mid-August each year, so it is like for like:
We are not accelerating towards the finish. We are decelerating short of halfway. This year added 1.1 points, the smallest gain in a decade, against 6.6 points in the year to August 2017.
Straight-line it from the last three years and the world reaches 100% in 2049. Straight-line it from this year alone and it is 2073. Neither is a forecast. A curve that is flattening does not reach the top by drift at all. It stalls somewhere in the sixties and the remainder never moves, because the networks that have not done it by then are the ones nothing was ever going to move.
I would love to be wrong about that. The number has got smaller every year I have looked at it.
Do we need a law?
This is the one I have gone back and forth on most, and I have landed on “not the law people reach for”.
Against a mandate: the Americans passed the strongest one anybody has, and missed it. A deadline is not a deployment.
For one: 6UK’s parting verdict in 2012 was that free-market incentives are insufficient and that the countries which fall behind are the ones with hands-off governments. Fourteen years of British data agrees with them.
And here is the part that settles it. This country has already legislated about this problem — it just legislated in the wrong direction. We were willing to legislate to accommodate address sharing. We have never been willing to legislate to remove it.
What I would ask for is not a ban and not a target, but the Belgian instrument described earlier: a hard limit on how many subscribers may share one address. It needs no new addresses, it does not shut anybody out of the market, and it works on the economics rather than on anybody’s good intentions.
A mandate on its own produces one useful thing, and it is not deployment. It is a named person who has to explain the miss. We have never had one of those.
How did we move to IPv4 so quickly, then?
Because somebody could switch the old one off.
The comparison is exact, and almost nobody makes it. The ARPANET ran the Network Control Program, which addressed hosts in 8 bits — 6 for the node and 2 for the host, so 64 nodes of 4 machines, 256 hosts in total. By the late 1970s that was obviously not enough, and the answer was a new protocol with a bigger address. Same problem we have now, forty-odd years earlier.
Jon Postel published the transition plan in November 1981. In March 1982 the US Department of Defense declared TCP/IP its official standard. Both protocols ran side by side, and on 1 January 1983 NCP was turned off. Hosts that had not converted lost access to the network. Vint Cerf remembers “I survived the TCP/IP switchover” pins being worn afterwards by the people who got through it.
Fourteen months from plan to flag day.
Now count what made that possible. Roughly a couple of hundred hosts, not four billion. One network, not every network. One funder who owned every machine on it and paid the wages of everyone touching them. A single organisation able to set a date, and — this is the bit that matters — able to make the old protocol stop working on that date.
None of those things exist now, and that is the whole answer. IPv4 did not win because the migration was easy. It won because there was somebody in a position to end the argument.
Nobody is in that position today. There is no authority that can switch IPv4 off, and there never will be. Which means this transition cannot be finished the way the last one was — it can only be finished by several thousand outfits each deciding, on their own, to bother.
On this year’s numbers, that lands in 2073. Ninety years after the flag day.
We Used To Make Things Properly
A standard is something you keep when nobody is checking. That is the whole of it. There is no inspector for this, no certificate, no auditor who turns up and asks to see your routing table, and twenty years have now shown exactly what this country does with an obligation nobody enforces.
We drop it, and then we buy something to cover the gap.
None of that is a technical failure and I will not pretend it is. Britain can do this work. The skills are here, the kit is here, the address space is issued and sat waiting in accounts we are already paying for. What has gone is the instinct to do a job properly because it is the job — without being paid extra for it, and without somebody stood over you making you.
Ask what actually stops it and you land on the money, but not in the way people mean.
A carrier-grade NAT has a purchase order. It has a vendor, a quote, a discount, a support contract and a renewal date. It goes in the capital plan, it depreciates over five years, and somebody’s name sits on the business case. Delivering it is a visible thing a manager can point at in an appraisal.
IPv6 has none of that. No invoice, no supplier, no renewal, nothing to put in a budget and nothing anybody can be seen to have bought. It is just work, done properly, by people who know what they are doing, for no return this quarter. Nobody in this industry has ever been promoted for a thing that never appeared in a budget.
As such the cheaper option loses, every year, for twenty years. Not because anyone weighed it up and chose wrong, but because a management culture has grown up here that can only see the parts of engineering that arrive with a price on them. Cheap was never the obstacle. Unbillable was. That is what it looks like when a business stops caring about standards and starts caring only about what it can put on an invoice, and it is a choice being made by people paid well enough to know better.
Then there is what they sold us instead of an address, which ought to make people angrier than it does.
The internet was built so that any machine could reach any other machine directly. Not a detail of the design. The design. It is why anybody with a connection and an idea could put something up that the whole world could reach. Put a customer behind a shared address and that is gone. You can ask, but you can never answer. You are a consumer of other people’s services, permanently, and never a provider of your own.
That is not an unfortunate side effect of a shortage. It is a re-architecture, and it suits everybody selling it. The camera that now needs the manufacturer’s cloud. The remote access that now needs somebody’s relay. The thing people used to run at home that is now a monthly subscription. Every one of those is somebody who owned a thing being converted into somebody who rents it, and a connection quietly downgraded from a place on the internet to a window onto somebody else’s.
We gave the middle of the internet away to a handful of companies on another continent, then stood about looking surprised that it ended up centralised. You cannot be self-reliant on a connection that will not let you host owt.
Self-reliance is the part I keep coming back to, because this country has stopped expecting it of itself. The instinct now is to wait. For a vendor, a regulator, a grant, a mandate, a customer who rings up and asks. None of those are coming. There is no market signal on its way, no policy in drafting, no deadline anybody will have to explain missing.
Which leaves it where it has been the whole time. A free allocation, sat in a registry account with your company’s name on it, and a fortnight between you and having done the job right.
Nobody is coming to make you. That is exactly why it counts.
You can check whether it is your building. The script is in the download at the top of the post.
Sources
Everything below was retrieved on 27 August 2026.
The data I measured from. Every number of mine comes from these. They are free, they are public, and you can repeat the whole thing in an afternoon.
- Registry delegation files, one per regional registry: RIPE NCC, APNIC, ARIN, LACNIC, AFRINIC. RIPE’s was generated 26 August 2026, the rest 27 August 2026.
- RIPE RIS routing table dumps,
riswhoisdump.IPv4.gzandriswhoisdump.IPv6.gz, generated 18:06 UTC on 27 August 2026. - RIPE database REST interface, for the organisation behind each AS number.
- The public DNS, for the AAAA sweep, cross-checked against a second resolver.
Other people’s measurements.
- Google IPv6 statistics — per-country native IPv6 among Google’s own visitors, figures as of 25 August 2026.
- APNIC on IPv6 performance and on IPv6 security misconceptions — the measured picture rather than the forum one.
- IPv4 transfer market prices, first half of 2026, summarising CircleID’s analysis of publicly priced transactions.
Standards. The bolt-ons, in the order they were published.
- RFC 3056 — 6to4 automatic tunnelling, February 2001.
- RFC 3701 — the 6bone phaseout plan, setting its shutdown for 6 June 2006.
- RFC 7526 — deprecating the 6to4 anycast relays and moving them to Historic, May 2015.
- RFC 4864 — what NAT does and does not give you, and why the firewall people think they have is “an arbitrary artifact”, 2007.
- RFC 4941, RFC 7217 and RFC 8981 — temporary and opaque addresses, which is why a device’s IPv6 address is not a stable identifier.
- RFC 801 — Jon Postel’s NCP/TCP transition plan, November 1981, setting the 1 January 1983 flag day.
- RFC 1883 — the original IPv6 specification, December 1995.
- RFC 6333 — DS-Lite, 2011.
- RFC 6056 — source port randomisation, the defence CGN weakens, 2011.
- RFC 6269 — Issues with IP Address Sharing, June 2011. The IETF’s own catalogue of what CGN breaks, including abuse logging, penalty boxes, blacklisting, port randomisation and traceability.
- RFC 791 and RFC 8200 — the two header formats, and why IPv6 dropped the checksum, the variable length and in-flight fragmentation.
- RFC 6583 — Neighbour Discovery cache exhaustion on a /64, and the forwarding-plane versus control-plane split that decides what costs a router CPU.
- RFC 6177 — how much address space an end site should get, 2011. Obsoletes RFC 3177’s blanket /48, rules out the single /64, and hands the actual number to the operational community.
- RIPE-690 — the European operators’ own answer to that question, October 2017: /48 or /56 to an end user, never a /64.
- RFC 6302 — log the source port, timestamp and protocol, 2011.
- RFC 6598 — shared address space, 2012.
- RFC 6877 — 464XLAT, 2013.
- RFC 6888 — carrier-grade NAT requirements, 2013.
- RFC 7021 — the impact of carrier-grade NAT on applications, 2013.
- RFC 7422 — deterministic mapping to cut CGN logging, 2014.
- RFC 7597 and RFC 7599 — MAP-E and MAP-T, 2015.
- World IPv6 Launch, 6 June 2012.
- Hurricane Electric’s free tunnel broker — where a lot of us got IPv6 while our own ISPs had none.
Law and policy.
- Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 — House of Commons Library briefing on the bill that would bring managed service providers inside the NIS Regulations.
- Counter-Terrorism and Security Act 2015, section 21 — retention of relevant internet data, and its explanatory notes.
- Europol, October 2017 — law enforcement calling for the end of carrier-grade NAT, with the 90% mobile and 50% fixed figures.
- OMB memorandum M-21-07 — the US federal IPv6-only requirement, November 2020.
- Online Safety Act 2023.
- Europol EC3, Carrier Grade NAT and crime attribution online — Gregory Mounier’s presentation to RIPE 74, with the August 2016 survey of EU law enforcement, the case examples, and the Belgian code of conduct and its results.
- NCMEC CyberTipline data — 2025 report volumes and referrals.
- A Multi-perspective Analysis of Carrier-Grade NAT Deployment, ACM IMC 2016 — the independent measurement of CGN use by mobile and fixed providers.
- RIPE NCC charging scheme 2026 — EUR 1,800 per LIR account, flat.
Vendors, in their own words.
- Akamai, June 2022 — dual-stack is the default and customers have to opt out of it.
- AWS, 2023 — the public IPv4 charge, and why.
Reporting and the record.
- Sky’s own write-up on RIPE Labs — how five million users were moved.
- ISPreview, September 2016 — Sky completing the rollout.
- CircleID, September 2016 — the Jim Bound IPv6 Award.
- ISPreview, December 2012 — 6UK winding itself up.
- ISPreview altnet IPv6 and CGNAT survey — April 2024, updated to March 2025.
- ISPreview on Plusnet’s IPv6 trial, November 2023 — the 2011 trial, the missed 2020 launch, and the note that BT and Plusnet ship near-identical routers.
- A community-maintained tracker of UK mobile networks and IPv6 — user-reported rather than official, and the source for which mobile networks hand out IPv6 today.
- havevirginmediaenabledipv6yet.co.uk — the Virgin Media timeline, 2010 to now.
- Internet Society, September 2016 — Sky at 90% of its base, each subscriber getting a /56.
- Internet Society, September 2016 — Ron Broersma’s account of the 1983 NCP to TCP/IP migration, including the 256-host limit and what happened to anyone who missed the deadline.
- The Register, January 2013 — thirty years on from the flag day, and the pins people wore afterwards.
- UK IPv6 Council.