C4 / 15.79% of index
Risk quantification
Does it turn inventory into a defensible migration priority?
What is risk quantification?
Quantum-risk quantification turns cryptographic inventory into migration priority using algorithm exposure, data sensitivity, confidentiality lifetime, exploitability and dependency context.
A raw inventory does not tell an organization what to migrate first. A useful model exposes the inputs, weighting and uncertainty behind its priorities.
Questions to ask a vendor
- Is harvest-now-decrypt-later exposure modeled?
- Can a buyer inspect the score inputs and weights?
- Does priority account for data lifespan and migration dependency?
What this edition actually supports
Weight 3 of 19. Can an inventory support a defensible migration order?
Useful prioritization ties crypto exposure to algorithm, key/certificate state, reachable use, data lifetime and operational context, and makes assumptions visible. QScout scores 9 in the dated rubric. CBOM Secure's current V1.1 page describes a 0–100 score and its connected-source limits; that current cited page does not silently revise its 2026.7 cell. A risk number is a model output, not a measured breach probability.
How to investigate this criterion
Read the scoring rationale, source date, missing inputs and a case where the priority would change.
Primary and original inputs: pqc-index.org · www.encryptionconsulting.com. Review all dated cell source checks and the 1 October per-cell limits.
The 2026.7 cells below are public-evidence scores. A vendor page documents a claim; an artifact check tests only its stated scope. Missing product execution and inaccessible sources remain explicit unknowns. The score snapshot has not been recomputed from later pages.
Risk quantification scores in edition 2026.7
Equal scores share the same criterion position; the next position skips the tied places. The highest value in this column is a published rubric cell, not a measured product winner. A partial or unverified source anchor remains visible even when its numeric score is high.
| Position on criterion | Product | Risk quantification score | Overall score | Internal 1 October source review | Evidence |
|---|---|---|---|---|---|
| 1 | QScout Pulse GoldQtonic Quantum Corp | 9 | 8.00 | Partial or qualified supportPublished seven-factor model is organization-level while per-asset priority uses different factors; final nine is a contestable interpolation.Exact cell and citations | S27S28S29S30 |
| 2 | CBOM SecureEncryption Consulting | 7 | 7.47 | Partial or qualified supportAccessible V1.1 page confirms 0-100 score and named factors; exact archived datasheet quote was inaccessible (406), and lifetime/HNDL is absent.Exact cell and citations | S04S05S06 |
| 2 | O3 SecurityO3 Security | 7 | 5.47 | Partial or qualified supportVendor urgency ranking uses break-year and attack surface; numeric score/data lifetime/weights are not shown.Exact cell and citations | S17 |
| 2 | ISARA AdvanceISARA | 7 | 5.42 | Partial or qualified supportPrimary whitepaper names algorithm strength, key size and usage context risk scores; no lifetime/HNDL or ranking formula.Exact cell and citations | S14 |
| 5 | Keyfactor AgileSec + CommandKeyfactor | 6 | 6.53 | Narrow feature documentedVendor documents compliant/high/medium/low classification; no numerical asset model inferred.Exact cell and citations | S08S25 |
| 5 | QCecuring CBOMQCecuring | 6 | 6.53 | Narrow feature documentedVendor documents risk categories with algorithm examples; no numerical model asserted.Exact cell and citations | S19 |
| 5 | AppViewX Quantum Trust HubAppViewX | 6 | 6.37 | Claim not verified from accessible evidenceRisk pages returned 403; archived readiness score does not establish the exact asset-risk anchor.Exact cell and citations | S07S24 |
| 5 | SandboxAQ AQtive GuardSandboxAQ | 6 | 6.21 | Narrow feature documentedPolicy severity categories documented, without numerical calibration.Exact cell and citations | S12 |
| 5 | Fortanix Key Insight / PQC CentralFortanix | 6 | 5.74 | Partial or qualified supportVendor documents categorical risk counts with context; scoring details and validation are not published.Exact cell and citations | S15 |
| 5 | IBM Guardium + Quantum SafeIBM | 6 | 5.58 | Partial or qualified supportVerified-TLS IBM product documentation reproduces CVSS-style PQC violation wording, but asset-score calibration and current product-suite attribution remain untested.Exact cell and citations | S09S10S26 |
| 5 | QuSecure QuProtect R3QuSecure | 6 | 5.21 | Partial or qualified supportExposure-based risk ordering is documented; model and calibration not supplied.Exact cell and citations | S13 |
| 5 | TYCHON Quantum CommandTYCHON | 6 | 5.16 | Claim not verified from accessible evidenceVendor pages returned 403; exact risk score factors and categories unverified.Exact cell and citations | S11 |
| 13 | DigiCert Quantum CentralDigiCert | 5 | 5.37 | Partial or qualified supportPolicy severity is documented; exact per-asset contextual risk scoring remains a rubric interpolation.Exact cell and citations | S18 |
| 14 | CryptoNext COMPASSCryptoNext | 4 | 4.68 | Partial or qualified supportData sensitivity/criticality linkage is vendor-documented; formula and per-asset risk behavior are not verified.Exact cell and citations | S16 |