C3 / 15.79% of index
Change detection
Can it detect and preserve material changes over time?
What is change detection?
Cryptographic change detection identifies when assets, configurations or dependencies appear, disappear or materially change after the initial inventory.
Post-quantum readiness is not a one-time scan. Buyers need to distinguish pipeline processing latency from the total time between a real target change and its discovery.
Questions to ask a vendor
- What triggers a new observation?
- How often are all authorized surfaces revisited?
- Are change records signed, ordered and protected against deletion or reordering?
What this edition actually supports
Weight 3 of 19. Does the product record a meaningful before and after, with enough history to investigate drift?
A scheduled scan alone is not a verified change history. The edition scores public descriptions of repeated discovery, event history and traceable differences. QScout scores 8. Readers should distinguish vendor-described monitoring, an artifact-tested sequence and continuous customer deployment.
How to investigate this criterion
Ask for two dated inventories of the same scope, stable asset identity and a reviewable change event.
Primary and original inputs: pqc-index.org · pqc-index.org. Review all dated cell source checks and the 1 October per-cell limits.
The 2026.7 cells below are public-evidence scores. A vendor page documents a claim; an artifact check tests only its stated scope. Missing product execution and inaccessible sources remain explicit unknowns. The score snapshot has not been recomputed from later pages.
Change detection scores in edition 2026.7
Equal scores share the same criterion position; the next position skips the tied places. The highest value in this column is a published rubric cell, not a measured product winner. A partial or unverified source anchor remains visible even when its numeric score is high.
| Position on criterion | Product | Change detection score | Overall score | Internal 1 October source review | Evidence |
|---|---|---|---|---|---|
| 1 | QScout Pulse GoldQtonic Quantum Corp | 8 | 8.00 | Partial or qualified supportPublic 500-event hash chain/signatures are inspectable, but 10 unsigned events, before=null and heartbeat labels limit cryptographic drift proof.Exact cell and citations | S27S28S29S30 |
| 1 | CBOM SecureEncryption Consulting | 8 | 7.47 | Partial or qualified supportVendor documents monitoring, alerts and a tamper-proof audit trail, but publishes no log mechanism or independent verification.Exact cell and citations | S04S05S06 |
| 3 | Keyfactor AgileSec + CommandKeyfactor | 6 | 6.53 | Narrow feature documentedVendor documents findings resolved across full scans, a concrete change-state rule.Exact cell and citations | S08S25 |
| 3 | QCecuring CBOMQCecuring | 6 | 6.53 | Narrow feature documentedDocumented comparison lists improved/regressed/unchanged and violation deltas; no signed change history shown.Exact cell and citations | S19 |
| 3 | QuSecure QuProtect R3QuSecure | 6 | 5.21 | Partial or qualified supportContinuous traffic inventory is documented, but explicit cryptographic diff and tamper history are absent.Exact cell and citations | S13 |
| 6 | AppViewX Quantum Trust HubAppViewX | 5 | 6.37 | Claim not verified from accessible evidenceScheduling/drift docs returned 403; archived scheduling quote does not prove diff reporting.Exact cell and citations | S07S24 |
| 6 | SandboxAQ AQtive GuardSandboxAQ | 5 | 6.21 | Partial or qualified supportCloudTrail change observation documented; generic quote does not establish diff/alert completeness.Exact cell and citations | S12 |
| 6 | Fortanix Key Insight / PQC CentralFortanix | 5 | 5.74 | Partial or qualified supportVendor documents manual RESCAN and asset updates; scheduled diff/drift automation needed for higher anchor is absent.Exact cell and citations | S15 |
| 6 | O3 SecurityO3 Security | 5 | 5.47 | Partial or qualified supportVersioned CBOM is documented; scheduled re-scan/diff mechanism is not established.Exact cell and citations | S17 |
| 6 | ISARA AdvanceISARA | 5 | 5.42 | Narrow feature documentedPrimary Azure whitepaper documents continuous monitoring and historical trends; no tamper-evident mechanism shown.Exact cell and citations | S14 |
| 6 | DigiCert Quantum CentralDigiCert | 5 | 5.37 | Partial or qualified supportVendor states imports after stale sync; automatic import is not the same as verified cryptographic diff detection.Exact cell and citations | S18 |
| 6 | CryptoNext COMPASSCryptoNext | 5 | 4.68 | Partial or qualified supportPrimary PDF explicitly describes passive continuous traffic monitoring; no diff/drift reporting or alert timing shown, making midpoint discretionary.Exact cell and citations | S16 |
| 13 | IBM Guardium + Quantum SafeIBM | 4 | 5.58 | Partial or qualified supportVendor alert/policy wording does not establish crypto-level drift history; final point-in-time cap is conservative.Exact cell and citations | S09S10S26 |
| 13 | TYCHON Quantum CommandTYCHON | 4 | 5.16 | Claim not verified from accessible evidenceVendor pages returned 403; archived change-alert wording has no accessible mechanism.Exact cell and citations | S11 |