C3 / 15.79% of index

Change detection

Can it detect and preserve material changes over time?

What is change detection?

Cryptographic change detection identifies when assets, configurations or dependencies appear, disappear or materially change after the initial inventory.

Post-quantum readiness is not a one-time scan. Buyers need to distinguish pipeline processing latency from the total time between a real target change and its discovery.

Questions to ask a vendor

  1. What triggers a new observation?
  2. How often are all authorized surfaces revisited?
  3. Are change records signed, ordered and protected against deletion or reordering?

What this edition actually supports

Weight 3 of 19. Does the product record a meaningful before and after, with enough history to investigate drift?

A scheduled scan alone is not a verified change history. The edition scores public descriptions of repeated discovery, event history and traceable differences. QScout scores 8. Readers should distinguish vendor-described monitoring, an artifact-tested sequence and continuous customer deployment.

How to investigate this criterion

Ask for two dated inventories of the same scope, stable asset identity and a reviewable change event.

The 2026.7 cells below are public-evidence scores. A vendor page documents a claim; an artifact check tests only its stated scope. Missing product execution and inaccessible sources remain explicit unknowns. The score snapshot has not been recomputed from later pages.

Change detection scores in edition 2026.7

Equal scores share the same criterion position; the next position skips the tied places. The highest value in this column is a published rubric cell, not a measured product winner. A partial or unverified source anchor remains visible even when its numeric score is high.

Position on criterionProductChange detection scoreOverall scoreInternal 1 October source reviewEvidence
1QScout Pulse GoldQtonic Quantum Corp88.00Partial or qualified supportPublic 500-event hash chain/signatures are inspectable, but 10 unsigned events, before=null and heartbeat labels limit cryptographic drift proof.Exact cell and citationsS27S28S29S30
1CBOM SecureEncryption Consulting87.47Partial or qualified supportVendor documents monitoring, alerts and a tamper-proof audit trail, but publishes no log mechanism or independent verification.Exact cell and citationsS04S05S06
3Keyfactor AgileSec + CommandKeyfactor66.53Narrow feature documentedVendor documents findings resolved across full scans, a concrete change-state rule.Exact cell and citationsS08S25
3QCecuring CBOMQCecuring66.53Narrow feature documentedDocumented comparison lists improved/regressed/unchanged and violation deltas; no signed change history shown.Exact cell and citationsS19
3QuSecure QuProtect R3QuSecure65.21Partial or qualified supportContinuous traffic inventory is documented, but explicit cryptographic diff and tamper history are absent.Exact cell and citationsS13
6AppViewX Quantum Trust HubAppViewX56.37Claim not verified from accessible evidenceScheduling/drift docs returned 403; archived scheduling quote does not prove diff reporting.Exact cell and citationsS07S24
6SandboxAQ AQtive GuardSandboxAQ56.21Partial or qualified supportCloudTrail change observation documented; generic quote does not establish diff/alert completeness.Exact cell and citationsS12
6Fortanix Key Insight / PQC CentralFortanix55.74Partial or qualified supportVendor documents manual RESCAN and asset updates; scheduled diff/drift automation needed for higher anchor is absent.Exact cell and citationsS15
6O3 SecurityO3 Security55.47Partial or qualified supportVersioned CBOM is documented; scheduled re-scan/diff mechanism is not established.Exact cell and citationsS17
6ISARA AdvanceISARA55.42Narrow feature documentedPrimary Azure whitepaper documents continuous monitoring and historical trends; no tamper-evident mechanism shown.Exact cell and citationsS14
6DigiCert Quantum CentralDigiCert55.37Partial or qualified supportVendor states imports after stale sync; automatic import is not the same as verified cryptographic diff detection.Exact cell and citationsS18
6CryptoNext COMPASSCryptoNext54.68Partial or qualified supportPrimary PDF explicitly describes passive continuous traffic monitoring; no diff/drift reporting or alert timing shown, making midpoint discretionary.Exact cell and citationsS16
13IBM Guardium + Quantum SafeIBM45.58Partial or qualified supportVendor alert/policy wording does not establish crypto-level drift history; final point-in-time cap is conservative.Exact cell and citationsS09S10S26
13TYCHON Quantum CommandTYCHON45.16Claim not verified from accessible evidenceVendor pages returned 403; archived change-alert wording has no accessible mechanism.Exact cell and citationsS11