C6 / 10.53% of index
Remediation loop
Can a finding move through ownership, action and verified closure?
What is remediation loop?
The remediation loop moves a cryptographic finding from detection through ownership, change execution, verification and durable closure.
The assessed field clusters on discovery. The largest practical separation often appears after a finding exists: ticket state, certificate deployment, exception handling and closure verification.
Questions to ask a vendor
- Is integration one-way or bidirectional?
- Has the complete loop run against a live tenant?
- Can the system reopen a closed item when the underlying exposure remains?
What this edition actually supports
Weight 2 of 19. Can a finding reach an owner, a controlled change and a verified closure?
Recommendations, ticket creation, human action and confirmed closure are different steps. QScout scores 6 here; DigiCert Quantum Central scores 8 in the frozen record. QScout's owned loopback lab demonstrated one verified closed ticket and four nonclosed controls with harness-supplied rescan flags; it was not a customer ticketing tenant or autonomous remediation. NIST describes crypto agility as changing algorithms while preserving security and operations.
How to investigate this criterion
Trace the exact finding, owner, approval, action, rescan and reopened-state rule; ask who performed each step.
Primary and original inputs: pqc-index.org · pqc-index.org · csrc.nist.gov. Review all dated cell source checks and the 1 October per-cell limits.
The 2026.7 cells below are public-evidence scores. A vendor page documents a claim; an artifact check tests only its stated scope. Missing product execution and inaccessible sources remain explicit unknowns. The score snapshot has not been recomputed from later pages.
Remediation loop scores in edition 2026.7
Equal scores share the same criterion position; the next position skips the tied places. The highest value in this column is a published rubric cell, not a measured product winner. A partial or unverified source anchor remains visible even when its numeric score is high.
| Position on criterion | Product | Remediation loop score | Overall score | Internal 1 October source review | Evidence |
|---|---|---|---|---|---|
| 1 | DigiCert Quantum CentralDigiCert | 8 | 5.37 | Partial or qualified supportVendor describes external task status readback, but a comparative live workflow test is absent.Exact cell and citations | S18 |
| 2 | Keyfactor AgileSec + CommandKeyfactor | 7 | 6.53 | Partial or qualified supportConnector API query is documented; ticket creation/automated remediation attribution requires closer source binding.Exact cell and citations | S08S25 |
| 2 | AppViewX Quantum Trust HubAppViewX | 7 | 6.37 | Claim not verified from accessible evidenceVendor pages returned 403; archived CLM action may be adjacent-platform rather than Quantum Trust Hub behavior.Exact cell and citations | S07S24 |
| 2 | IBM Guardium + Quantum SafeIBM | 7 | 5.58 | Partial or qualified supportJira/ServiceNow ticket creation is documented; automated remediation action beyond a ticket is not tested.Exact cell and citations | S09S10S26 |
| 5 | SandboxAQ AQtive GuardSandboxAQ | 6.5 | 6.21 | Partial or qualified supportCertificate rotation is documented; attribution to the scored AQG product scope and closure needs checking.Exact cell and citations | S12 |
| 5 | QuSecure QuProtect R3QuSecure | 6.5 | 5.21 | Partial or qualified supportOrchestrator action is an adjacent network control and inventory refresh; no cross-product peer run verifies closure.Exact cell and citations | S13 |
| 7 | QScout Pulse GoldQtonic Quantum Corp | 6 | 8.00 | Partial or qualified supportInbound closure rule is documented/fixture-tested; public harness is not a live tenant and outbound integration defaults dry-run.Exact cell and citations | S27S28S29S30 |
| 7 | CBOM SecureEncryption Consulting | 6 | 7.47 | Narrow feature documentedCycloneDX export and remediation guidance support final six; named Jira/ServiceNow integration belongs to CertSecure Manager, not this product.Exact cell and citations | S04S05S06 |
| 7 | QCecuring CBOMQCecuring | 6 | 6.53 | Narrow feature documentedJSON export and Action Required guidance satisfy final six; no named ticket integration inferred.Exact cell and citations | S19 |
| 7 | ISARA AdvanceISARA | 6 | 5.42 | Narrow feature documentedVendor documents ticket workflows and CMDB integration, without closure test.Exact cell and citations | S14 |
| 7 | TYCHON Quantum CommandTYCHON | 6 | 5.16 | Claim not verified from accessible evidenceVendor pages returned 403; archived response-action claim cannot verify automation/product scope.Exact cell and citations | S11 |
| 12 | Fortanix Key Insight / PQC CentralFortanix | 4 | 5.74 | Partial or qualified supportVendor says corrective actions can occur in platform but gives no reproducible ticket/action mechanism.Exact cell and citations | S15 |
| 12 | O3 SecurityO3 Security | 4 | 5.47 | Partial or qualified supportMigration report is named, but concrete remedial step quality is not checked.Exact cell and citations | S17 |
| 12 | CryptoNext COMPASSCryptoNext | 4 | 4.68 | Partial or qualified supportAPI/CMDB integration is vendor-documented; ticket creation or closure is not demonstrated, consistent with guidance-only cap.Exact cell and citations | S16 |