Edition 2026.5 / Evidence-led market research

Which post-quantum discovery tools can prove what they find?

Fourteen products scored across seven functional criteria. Every weight, limitation and source is exposed so the result can be challenged precisely.

Capability index2026.5
Products scored
14
Functional criteria
7
Probes per product
56
Method version
v2026.08.12

Published 15 August 2026
Score-bound build 8b656ac6

01 Finding is largely solved

02 Proving remains rare

03 Remediation separates the field

2026.5 standings

The leading capability band

QScout leads the disclosed instrument. CBOM Secure forms the strong second band. AppViewX, IBM and Keyfactor should be read as an established cluster, not as precise second-decimal ordering.

RankProductScoreBandConfidenceStrongest documented ground
1QScout Pulse GoldQtonic Quantum Corp9.42
LeadingDEEPSigned inventory verifiable by a stranger, published detector accuracy and a published vantage policy. S01S02S03
2CBOM SecureEncryption Consulting8.21
StrongMODThe widest documented discovery surface, continuous policy evaluation and a cryptographically verifiable change log. S04S05S06
3AppViewX Quantum Trust HubAppViewX7.58
EstablishedMODBidirectional ServiceNow control, closed-loop certificate lifecycle automation and remediation inside delivery pipelines. S07S24
4IBM Guardium + Quantum SafeIBM7.39
EstablishedMODIBM authored the CBOM specification, and its open-source toolchain has been benchmarked against external ground truth. S09S10S23
5Keyfactor AgileSec + CommandKeyfactor7.37
EstablishedMODServiceNow applications route cryptographic findings into vulnerability response and automate certificate deployment to endpoint stores. S08S25

The instrument

Seven questions behind every score

Discovery carries the largest weight. Evidence, change detection and risk quantification carry the next-largest shares. Correctness, remediation and reporting complete the instrument.

C121.05%

Discovery

How broadly and deeply does the product find cryptographic assets?

C215.79%

Evidence artifact

Does it produce a portable, verifiable record of what was found?

C510.53%

Correctness

Is detection accuracy measured against named ground truth?

C610.53%

Remediation loop

Can a finding move through ownership, action and verified closure?

C710.53%

Reporting

Can technical and executive readers understand and reuse the result?

Category findings

What the ranking says about the market

F-01

Accuracy is measured in the literature and almost never published by vendors

Across the fourteen scored products, one publishes per-detector figures for its own product and one open-source toolchain has been independently benchmarked. The rest ask buyers to act on inventories without a published error rate. S23S26

F-02

Signing the evidence remains rare

Most products emit a CycloneDX bill of materials. Two are documented as producing a cryptographically verifiable record, and one publishes a key and a procedure a stranger can use without contacting the vendor. S02S05

F-03

Discovery has converged; downstream execution has not

Discovery breadth has the highest field mean. The meaningful separation now appears in evidence integrity, change handling, risk quantification and remediation after an inventory exists.

F-04

The best functional products and the best-assured vendors differ

Capability leadership and certification or deployment assurance rarely sit in the same company, forcing buyers to evaluate technical performance and vendor approval as separate decisions. S11S12S13

F-05

Remediation is the criterion where QScout does not lead

AppViewX and Keyfactor document bidirectional workflow and certificate lifecycle capabilities that QScout does not yet demonstrate against a live ticketing tenant. S24S25

The buyer question

Do not ask only what a scanner finds. Ask what a stranger can verify.

Request measured detection accuracy against a named corpus. Then ask whether the resulting cryptographic bill of materials can be verified as unaltered without relying on the vendor. Most assessed products do not publicly answer both questions.

Use the evaluation framework