Why hasn't TLS 1.3 been implemented yet?

Such security upgrades are complex in nature. In a multi-vendor internet environment, you need to update both client and servers to support a new security standard. So far, no major browsers have TLS 1.3 enabled by default. It cannot be assumed that by a specific date, every server and end user device will support all new security standards. Furthermore, TLS 1.3 is not an extension but a major change with complete revamping. The way TLS or SSL version negotiation works is that an end user device sends the latest version of a supported protocol to a server, which responds with the latest version and chooses something which is supported by both of them.