Discovery
How broadly and deeply does the product find cryptographic assets?
Edition 2026.5 / Evidence-led market research
Fourteen products scored across seven functional criteria. Every weight, limitation and source is exposed so the result can be challenged precisely.
Published 15 August 2026
Score-bound build 8b656ac6
01 Finding is largely solved
02 Proving remains rare
03 Remediation separates the field
2026.5 standings
QScout leads the disclosed instrument. CBOM Secure forms the strong second band. AppViewX, IBM and Keyfactor should be read as an established cluster, not as precise second-decimal ordering.
| Rank | Product | Score | Band | Confidence | Strongest documented ground |
|---|---|---|---|---|---|
| 1 | QScout Pulse GoldQtonic Quantum Corp | 9.42 | Leading | DEEP | Signed inventory verifiable by a stranger, published detector accuracy and a published vantage policy. S01S02S03 |
| 2 | CBOM SecureEncryption Consulting | 8.21 | Strong | MOD | The widest documented discovery surface, continuous policy evaluation and a cryptographically verifiable change log. S04S05S06 |
| 3 | AppViewX Quantum Trust HubAppViewX | 7.58 | Established | MOD | Bidirectional ServiceNow control, closed-loop certificate lifecycle automation and remediation inside delivery pipelines. S07S24 |
| 4 | IBM Guardium + Quantum SafeIBM | 7.39 | Established | MOD | IBM authored the CBOM specification, and its open-source toolchain has been benchmarked against external ground truth. S09S10S23 |
| 5 | Keyfactor AgileSec + CommandKeyfactor | 7.37 | Established | MOD | ServiceNow applications route cryptographic findings into vulnerability response and automate certificate deployment to endpoint stores. S08S25 |
The instrument
Discovery carries the largest weight. Evidence, change detection and risk quantification carry the next-largest shares. Correctness, remediation and reporting complete the instrument.
How broadly and deeply does the product find cryptographic assets?
Does it produce a portable, verifiable record of what was found?
Can it detect and preserve material changes over time?
Does it turn inventory into a defensible migration priority?
Is detection accuracy measured against named ground truth?
Can a finding move through ownership, action and verified closure?
Can technical and executive readers understand and reuse the result?
Category findings
Across the fourteen scored products, one publishes per-detector figures for its own product and one open-source toolchain has been independently benchmarked. The rest ask buyers to act on inventories without a published error rate. S23S26
Most products emit a CycloneDX bill of materials. Two are documented as producing a cryptographically verifiable record, and one publishes a key and a procedure a stranger can use without contacting the vendor. S02S05
Discovery breadth has the highest field mean. The meaningful separation now appears in evidence integrity, change handling, risk quantification and remediation after an inventory exists.
Capability leadership and certification or deployment assurance rarely sit in the same company, forcing buyers to evaluate technical performance and vendor approval as separate decisions. S11S12S13
AppViewX and Keyfactor document bidirectional workflow and certificate lifecycle capabilities that QScout does not yet demonstrate against a live ticketing tenant. S24S25
The buyer question
Request measured detection accuracy against a named corpus. Then ask whether the resulting cryptographic bill of materials can be verified as unaltered without relying on the vendor. Most assessed products do not publicly answer both questions.
Use the evaluation framework