An update to this - the scan is still running, but it looks like I'm going to end up with 8 times more vulnerable hosts than @shadowserverThe Shadowserver Foundation are seeing.
I'll update tomorrow and likely publish the full data - a shocking amount of orgs haven't patched. E.g. there's hundreds of .gov* SSL cert names unpatched.