Ah ha!
Thanks for the feedback. Apparently this problem has uncovered 7 devices that didn’t actually follow the local standard of using xinetd, instead of a systemd managed socket, and do run ntpsec or chrony.
One of the problematic devices started updating the cache file as soon as I switched over to using xinetd.
Now to figure out why /etc/xinetd.d/check-mk-agent was never installed on the 6 other, debian, devices.