DNSSEC turned off for the NS TTL when transitioning from insecure to secure zone
The current validator mode is that it turns off DNSSEC on insecure delegations, which is fine, but it doesn't turn it back on after the DS is refetched, possibly because it's served from packet cache.
See https://lists.dns-oarc.net/pipermail/dns-operations/2018-August/017869.html