Candidate catalog / 1 October 2026
The field is larger than this edition
Edition 2026.7 scored 14 named products. These additional or historically unassessed products have no score here; absence from the ranking is not a finding of failure.
Eight already listed, still unassessed
The original research listed these eight without assigning scores. Four were found in a search with a disclosed US focus. This is not a complete market census. Sectigo and Entrust identity updates below refer to existing entries and do not add historical products.
- Arqit Encryption IntelligenceNot scored in edition 2026.7.
- PQStation QVisionNot scored in edition 2026.7.
- QryptoCyber platform (QryptoDiscover)Not scored in edition 2026.7.
- QuintessenceLabs TSF SentryNot scored in edition 2026.7.
- Venafi TLS Protect PQCNot scored in edition 2026.7.
- Entrust PKIaaS for PQNot scored in edition 2026.7.
- Checkmarx CBOMNot scored in edition 2026.7.
- Sectigo CBOMNot scored in edition 2026.7.
Inspect the historical discovery record · Read the eligibility and scoring method.
Current candidates and identity questions
These are attributed vendor-documentation leads for a future uniform review, not measured product results or additions to the 2026.7 denominator. A product may be eligible, adjacent or overlapping another listed suite after its exact build and scope are resolved. Open-source tools and operator-led products can qualify under the same functional rule; company size and sales do not decide inclusion.
CBOMkit is now hosted under its project organization; IBM Research describes its origin and early toolchain. It is a separate candidate, not evidence for the scored IBM Guardium product.
| Product | Current status | Vendor-documented scope | Evidence still needed |
|---|---|---|---|
| Entrust Cryptographic Security Platform | Identity update to historical Entrust entry; do not double count | The current platform page describes inventory, CBOM import/export, policy and lifecycle controls. | Confirm current native discovery, exact build and module boundary; do not borrow a 2021 third-party AgileScan sheet as current Entrust execution proof. The current platform page returned AWS HTTP 403 on 1 October, so direct access varies. |
| Sectigo Quantum Ready | Identity update to historical Sectigo CBOM entry; do not double count | The vendor documents cryptographic asset and dependency discovery and readiness guidance. | Confirm the available build and distinguish this product from Sectigo Certificate Manager's separate lifecycle functions. |
| Keyfactor CipherInsights | Historical lead revisited; conditional separate product | The vendor documents passive encrypted-traffic analysis and TLS inventory. | Confirm supported version and prevent AgileSec or Command capabilities being transferred to this product. |
| Qualys Certificate View | Historical lead revisited; conditional specialized product | The documentation covers certificate inventory, SSL/TLS assessment and a PQC readiness view. | Apply the same eligibility rule to a narrower certificate/TLS scope before scoring. |
| SafeLogic Cryptographic Posture Management | Formal review candidate | The vendor describes discovery across code, applications and infrastructure, plus CBOM and remediation views. | Confirm the exact available build, export instance and boundary from separate SafeLogic products. |
| Qinsight Atlas | Formal review candidate | The vendor describes code, cloud and endpoint discovery, CBOM and risk guidance. | Obtain a named build and artifact; a webpage does not prove correctness or closure. |
| Interlynk Post-Quantum Readiness | Conditional aggregator | The vendor describes ingesting CycloneDX CBOMs and prioritizing migration. | Decide whether CBOM aggregators without native discovery belong in this product cohort. |
| IBM Z Crypto Discovery & Inventory | Conditional IBM Z-specific product; separate from Guardium and CBOMkit | IBM documents consolidated IBM Z cryptographic inventory, policy and remediation monitoring. | Pin a version and inspect a native output artifact; IBM Z scope cannot be generalized to other systems. |
| CBOMkit (IBM-origin open-source project) | Conditional specialized open-source discovery candidate; separate from Guardium | The current CBOMkit project has IBM Research origins and describes source and container CBOM generation with companion viewer, policy and repository tools. | Pin a runnable release and assess its exact discovery scope under the same seven criteria; do not transfer its evidence to the scored Guardium product. |
| Post Quantum Leap | Conditional regional candidate | The vendor describes certificate discovery, imported CBOMs and migration planning. | Confirm delivery, version and whether imported data is separate from native discovery. |
What would make a new score legitimate?
- Freeze one eligibility rule, including the treatment of specialized tools, aggregators and bundles.
- Name the exact SKU, version and available build for each accepted product; collect C1–C7 primary sources and artifacts in the same window.
- Mark inaccessible or untested capabilities unknown, give each vendor the same challenge process, and independently review material disputes.
- Publish a new dated edition, raw cell changes and any rank change. Keep this edition's scores and files intact.
Suggest a missing product or challenge an eligibility decision. Sales, headcount and funding have no score weight.