Candidate catalog / 1 October 2026

The field is larger than this edition

Edition 2026.7 scored 14 named products. These additional or historically unassessed products have no score here; absence from the ranking is not a finding of failure.

Eight already listed, still unassessed

The original research listed these eight without assigning scores. Four were found in a search with a disclosed US focus. This is not a complete market census. Sectigo and Entrust identity updates below refer to existing entries and do not add historical products.

  • Arqit Encryption IntelligenceNot scored in edition 2026.7.
  • PQStation QVisionNot scored in edition 2026.7.
  • QryptoCyber platform (QryptoDiscover)Not scored in edition 2026.7.
  • QuintessenceLabs TSF SentryNot scored in edition 2026.7.
  • Venafi TLS Protect PQCNot scored in edition 2026.7.
  • Entrust PKIaaS for PQNot scored in edition 2026.7.
  • Checkmarx CBOMNot scored in edition 2026.7.
  • Sectigo CBOMNot scored in edition 2026.7.

Inspect the historical discovery record · Read the eligibility and scoring method.

Current candidates and identity questions

These are attributed vendor-documentation leads for a future uniform review, not measured product results or additions to the 2026.7 denominator. A product may be eligible, adjacent or overlapping another listed suite after its exact build and scope are resolved. Open-source tools and operator-led products can qualify under the same functional rule; company size and sales do not decide inclusion.

CBOMkit is now hosted under its project organization; IBM Research describes its origin and early toolchain. It is a separate candidate, not evidence for the scored IBM Guardium product.

Unscored candidate catalog, 1 October 2026
ProductCurrent statusVendor-documented scopeEvidence still needed
Entrust Cryptographic Security PlatformIdentity update to historical Entrust entry; do not double countThe current platform page describes inventory, CBOM import/export, policy and lifecycle controls.Confirm current native discovery, exact build and module boundary; do not borrow a 2021 third-party AgileScan sheet as current Entrust execution proof. The current platform page returned AWS HTTP 403 on 1 October, so direct access varies.
Sectigo Quantum ReadyIdentity update to historical Sectigo CBOM entry; do not double countThe vendor documents cryptographic asset and dependency discovery and readiness guidance.Confirm the available build and distinguish this product from Sectigo Certificate Manager's separate lifecycle functions.
Keyfactor CipherInsightsHistorical lead revisited; conditional separate productThe vendor documents passive encrypted-traffic analysis and TLS inventory.Confirm supported version and prevent AgileSec or Command capabilities being transferred to this product.
Qualys Certificate ViewHistorical lead revisited; conditional specialized productThe documentation covers certificate inventory, SSL/TLS assessment and a PQC readiness view.Apply the same eligibility rule to a narrower certificate/TLS scope before scoring.
SafeLogic Cryptographic Posture ManagementFormal review candidateThe vendor describes discovery across code, applications and infrastructure, plus CBOM and remediation views.Confirm the exact available build, export instance and boundary from separate SafeLogic products.
Qinsight AtlasFormal review candidateThe vendor describes code, cloud and endpoint discovery, CBOM and risk guidance.Obtain a named build and artifact; a webpage does not prove correctness or closure.
Interlynk Post-Quantum ReadinessConditional aggregatorThe vendor describes ingesting CycloneDX CBOMs and prioritizing migration.Decide whether CBOM aggregators without native discovery belong in this product cohort.
IBM Z Crypto Discovery & InventoryConditional IBM Z-specific product; separate from Guardium and CBOMkitIBM documents consolidated IBM Z cryptographic inventory, policy and remediation monitoring.Pin a version and inspect a native output artifact; IBM Z scope cannot be generalized to other systems.
CBOMkit (IBM-origin open-source project)Conditional specialized open-source discovery candidate; separate from GuardiumThe current CBOMkit project has IBM Research origins and describes source and container CBOM generation with companion viewer, policy and repository tools.Pin a runnable release and assess its exact discovery scope under the same seven criteria; do not transfer its evidence to the scored Guardium product.
Post Quantum LeapConditional regional candidateThe vendor describes certificate discovery, imported CBOMs and migration planning.Confirm delivery, version and whether imported data is separate from native discovery.

What would make a new score legitimate?

  1. Freeze one eligibility rule, including the treatment of specialized tools, aggregators and bundles.
  2. Name the exact SKU, version and available build for each accepted product; collect C1–C7 primary sources and artifacts in the same window.
  3. Mark inaccessible or untested capabilities unknown, give each vendor the same challenge process, and independently review material disputes.
  4. Publish a new dated edition, raw cell changes and any rank change. Keep this edition's scores and files intact.

Suggest a missing product or challenge an eligibility decision. Sales, headcount and funding have no score weight.