C4 / 15.79% of index

Risk quantification

Does it turn inventory into a defensible migration priority?

What is risk quantification?

Quantum-risk quantification turns cryptographic inventory into migration priority using algorithm exposure, data sensitivity, confidentiality lifetime, exploitability and dependency context.

A raw inventory does not tell an organization what to migrate first. A useful model exposes the inputs, weighting and uncertainty behind its priorities.

Questions to ask a vendor

  1. Is harvest-now-decrypt-later exposure modeled?
  2. Can a buyer inspect the score inputs and weights?
  3. Does priority account for data lifespan and migration dependency?

What this edition actually supports

Weight 3 of 19. Can an inventory support a defensible migration order?

Useful prioritization ties crypto exposure to algorithm, key/certificate state, reachable use, data lifetime and operational context, and makes assumptions visible. QScout scores 9 in the dated rubric. CBOM Secure's current V1.1 page describes a 0–100 score and its connected-source limits; that current cited page does not silently revise its 2026.7 cell. A risk number is a model output, not a measured breach probability.

How to investigate this criterion

Read the scoring rationale, source date, missing inputs and a case where the priority would change.

The 2026.7 cells below are public-evidence scores. A vendor page documents a claim; an artifact check tests only its stated scope. Missing product execution and inaccessible sources remain explicit unknowns. The score snapshot has not been recomputed from later pages.

Risk quantification scores in edition 2026.7

Equal scores share the same criterion position; the next position skips the tied places. The highest value in this column is a published rubric cell, not a measured product winner. A partial or unverified source anchor remains visible even when its numeric score is high.

Position on criterionProductRisk quantification scoreOverall scoreInternal 1 October source reviewEvidence
1QScout Pulse GoldQtonic Quantum Corp98.00Partial or qualified supportPublished seven-factor model is organization-level while per-asset priority uses different factors; final nine is a contestable interpolation.Exact cell and citationsS27S28S29S30
2CBOM SecureEncryption Consulting77.47Partial or qualified supportAccessible V1.1 page confirms 0-100 score and named factors; exact archived datasheet quote was inaccessible (406), and lifetime/HNDL is absent.Exact cell and citationsS04S05S06
2O3 SecurityO3 Security75.47Partial or qualified supportVendor urgency ranking uses break-year and attack surface; numeric score/data lifetime/weights are not shown.Exact cell and citationsS17
2ISARA AdvanceISARA75.42Partial or qualified supportPrimary whitepaper names algorithm strength, key size and usage context risk scores; no lifetime/HNDL or ranking formula.Exact cell and citationsS14
5Keyfactor AgileSec + CommandKeyfactor66.53Narrow feature documentedVendor documents compliant/high/medium/low classification; no numerical asset model inferred.Exact cell and citationsS08S25
5QCecuring CBOMQCecuring66.53Narrow feature documentedVendor documents risk categories with algorithm examples; no numerical model asserted.Exact cell and citationsS19
5AppViewX Quantum Trust HubAppViewX66.37Claim not verified from accessible evidenceRisk pages returned 403; archived readiness score does not establish the exact asset-risk anchor.Exact cell and citationsS07S24
5SandboxAQ AQtive GuardSandboxAQ66.21Narrow feature documentedPolicy severity categories documented, without numerical calibration.Exact cell and citationsS12
5Fortanix Key Insight / PQC CentralFortanix65.74Partial or qualified supportVendor documents categorical risk counts with context; scoring details and validation are not published.Exact cell and citationsS15
5IBM Guardium + Quantum SafeIBM65.58Partial or qualified supportVerified-TLS IBM product documentation reproduces CVSS-style PQC violation wording, but asset-score calibration and current product-suite attribution remain untested.Exact cell and citationsS09S10S26
5QuSecure QuProtect R3QuSecure65.21Partial or qualified supportExposure-based risk ordering is documented; model and calibration not supplied.Exact cell and citationsS13
5TYCHON Quantum CommandTYCHON65.16Claim not verified from accessible evidenceVendor pages returned 403; exact risk score factors and categories unverified.Exact cell and citationsS11
13DigiCert Quantum CentralDigiCert55.37Partial or qualified supportPolicy severity is documented; exact per-asset contextual risk scoring remains a rubric interpolation.Exact cell and citationsS18
14CryptoNext COMPASSCryptoNext44.68Partial or qualified supportData sensitivity/criticality linkage is vendor-documented; formula and per-asset risk behavior are not verified.Exact cell and citationsS16