Edition 2026.7 / Evidence-led market research

Which post-quantum discovery tools can prove what they find?

QScout Pulse Gold has the highest score among 14 assessed products in the dated 2026.7 public-evidence index: 8.00 versus CBOM Secure at 7.47. [1] This editorial score is not a uniform test of product code or field accuracy.

Fourteen products scored across seven functional criteria. Every weight, limitation and source is exposed so the result can be challenged precisely.

Capability index2026.7
Products scored
14
Functional criteria
7
QScout cited excerpts reproduced
7 of 7
Method version
v2026.09.27

Published 27 September 2026
Publisher-reported: 5 researchers / 3 adversarial reviews
All 98 source checks
Score-bound build at edition verification 9497e709

Three different records

Follow the proof behind each number

These records answer different questions. A documented product score, a bounded artifact check and a public HTTPS handshake are not interchangeable. [1]

Frozen editorial index · 27 September 2026

8.00 among 14 assessed products

QScout Pulse Gold has the highest published public-evidence score; CBOM Secure follows at 7.47. Seven weights and all 98 cells are public. The 1 October internal review qualifies some anchors and does not validate every numeric score.

Frozen matrix · Method · 98-cell review

Bounded product artifacts

Tested scope, visible limits

Inspect QScout's signed own-API CBOM sample, synthetic one-file scan and rescan, and harness-controlled workflow. Each record distinguishes what ran from what remains unproved. No same-corpus peer performance result is published.

Product proof and adverse results · Comparable-test protocol

Separate HTTPS snapshot · 26 September 2026

5/8 hostnames; 0/2 by IP

Five of eight measured Qtonic Quantum Corp public HTTPS hostnames met a four-handshake rule; selected peers had zero of 2,877. Grouping by resolved IP gives Qtonic Quantum Corp zero of two. This does not measure QScout, internal systems or customer deployments.

Surface edition · Hostname data · Proof hashes

2026.7 / the result in context

QScout Pulse Gold has the highest score among 14 assessed products in this dated public-evidence index

Published 27 September 2026. This is a seven-criterion assessment of accessible product claims and artifacts, not a same-build performance test or a census of every available product. [1]

Published index score8.00 / 10

Seven frozen criterion cells. Read all seven rationales.

Closest assessed product7.47 / 10

CBOM Secure. Read its evidence.

Reproduce or challenge the result

The published difference is 0.53 points under weights 4/3/3/3/2/2/2 over 19. Download the frozen cell matrix, inspect source-access checks, and recalculate the method.

A corrected cell, an eligible unassessed product, or an unsupported citation could change a later rank. Submit reproducible counterevidence. No equal-build peer performance results have been published. The 1 October internal source review reproduced 77 archived quotations but did not validate every numeric score: 24 narrow features were documented, 53 anchors qualified or partial, 20 unverified and one own-API sample narrowly tested. Inspect all 98 cell limits. If QScout's numerator fell by 10 weighted points while CBOM Secure's stayed fixed, the two published scores would tie; 11 points would reverse the order. This is sensitivity, not a new score.

01 14 assessed products

02 7 functional criteria

03 8 historical unassessed products; new candidates under review

2026.7 standings

The leading capability band

QScout leads at 8.00 in the dated public-evidence rubric.[1] CBOM Secure forms the strong second band at 7.47. Keyfactor, QCecuring, AppViewX and SandboxAQ form an established cluster between 6.2 and 6.5 and should not be read as a precise ordering.

RankProductScoreBandConfidenceStrongest documented ground
1QScout Pulse GoldQtonic Quantum Corp8.00LeadingDEEPA publicly verifiable signed sample CBOM for its own API, public trust endpoints, and a vendor-labeled accuracy corpus with stated limits. S27S28S29S30
2CBOM SecureEncryption Consulting7.47StrongMODVendor-documented broad discovery, continuous monitoring, and a claimed tamper-evident change log. S04S05S06
3Keyfactor AgileSec + CommandKeyfactor6.53EstablishedMODAgileSec’s scheduled ServiceNow connector imports cryptographic vulnerabilities and detections for investigation. S08S25
3QCecuring CBOMQCecuring6.53EstablishedMODDocumented scanners for TLS, certificates, source code, binaries, cloud key stores, filesystems and SSH, with CycloneDX 1.6 CBOM export. S19
5AppViewX Quantum Trust HubAppViewX6.37EstablishedMODReviewed Quantum Trust Hub documentation covers PQC discovery, readiness scoring and CBOM export; its guide describes PQC remediation as manual. S07S24

Inspect the inputs

Every product. Every criterion.

Select a score to read its source evidence, rationale and final review adjustment. Search and filter all 98 cells, or download the typed claim ledger.

The instrument

Seven questions behind every score

Discovery carries the largest weight. Evidence, change detection and risk quantification carry the next-largest shares. Correctness, remediation and reporting complete the instrument.

C121.05%

Discovery

How broadly and deeply does the product find cryptographic assets?

C215.79%

Evidence artifact

Does it produce a portable, verifiable record of what was found?

C510.53%

Correctness

Is detection accuracy measured against named ground truth?

C610.53%

Remediation loop

Can a finding move through ownership, action and verified closure?

C710.53%

Reporting

Can technical and executive readers understand and reuse the result?

Category findings

What the ranking says about the market

F-01

Published accuracy measures were uncommon in the reviewed sources

In the public sources reviewed for this edition, QScout publishes its own per-detector figures. Separate research measures open-source toolchains, but those results do not establish accuracy for the scored vendor products. We did not locate comparable published product error rates for the other scored products in this source set. S23S26S28

F-02

Verifiable evidence was uncommon in the reviewed sources

In the reviewed sources, CBOM Secure claims a tamper-evident asset-change log without a specified verification mechanism; QScout publishes a signed sample CBOM for its own API, a public key and a verification procedure. Neither statement establishes signed customer-estate output for both products. S02S05

F-03

Discovery scores require mechanism and scope limits

A documented discovery surface does not establish measured detection accuracy. The final criterion matrix separates discovery breadth from evidence, correctness, risk and remediation; read each product's sources and scope before comparing scores.

F-04

Assurance and certification are outside this ranking

Certification and deployment assurance are not among the seven scored criteria. This index does not rank vendor assurance; buyers should assess those requirements separately. S11S12S13

F-05

Remediation is the criterion where QScout does not lead

The reviewed records distinguish DigiCert's Jira task/status exchange, Keyfactor's scheduled one-way ServiceNow imports, IBM's one-way ticket export and QTH's manual PQC remediation. QScout scores 6, but its published loopback proof does not demonstrate a live ticketing tenant. The frozen scores should not be read as proof of equivalent closed-loop deployment. S24S25

F-06

Re-scoring from public evidence moved every product

The publisher reports that five researchers re-read the public record for all fourteen products on 26 September 2026 and that three adversarial reviews ruled on 52 of the 98 cells, touching every product. Thirteen scores fell and one rose; the order at the top is unchanged (QScout 8.00, CBOM Secure 7.47) and the field now spans 4.68 to 8.00. S31

The buyer question

Do not ask only what a scanner finds. Ask what a stranger can verify.

Request measured detection accuracy against a named corpus. Then ask whether the resulting cryptographic bill of materials can be verified as unaltered without relying on the vendor. Most assessed products do not publicly answer both questions.

Open the buyer brief Inspect product proof