{
  "slug": "digicert-quantum-central",
  "name": "DigiCert Quantum Central",
  "vendor": "DigiCert",
  "researched_at": "2026-09-26",
  "product_status": {
    "summary": "New major release: moved from preview (1 Jul 2026) to General Availability on 24 Sep 2026 as part of DigiCert ONE, launching with the Essentials subscription plan. Interim preview releases added CyberArk/Keyfactor/CSV certificate import (3 Aug), key import from Azure Key Vault/AWS KMS/Google Cloud KMS (10 Aug), and Policies/Violations/Tracking with Jira status sync (9 Sep). Not renamed, acquired or discontinued.",
    "url": "https://docs.digicert.com/en/quantum-central/quantum-central-release-notes.html"
  },
  "cells": {
    "C1": {
      "score": 6,
      "anchor": "6: 3-4 surfaces",
      "urls": [
        "https://docs.digicert.com/en/quantum-central/build-your-inventory/scan-public-endpoints.html",
        "https://docs.digicert.com/en/quantum-central/build-your-inventory/import-certificates.html",
        "https://docs.digicert.com/en/quantum-central/build-your-inventory/import-keys.html",
        "https://docs.digicert.com/en/quantum-central/check-crypto-posture/read-your-dashboard.html",
        "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-your-inventory.html"
      ],
      "quote": "Key agreements using X25519MLKEM768 , SecP256r1MLKEM768 , and SecP384r1MLKEM1024 are considered quantum-safe and count towards your Quantum Readiness % .",
      "rationale": "Documented surfaces: (a) public TLS endpoints, (b) certificates (TLM, CyberArk/Keyfactor/CSV import), (e/f) keys in Azure Key Vault/AWS KMS/Google Cloud KMS via customer-run export script; algorithm + key size/curve + ML-DSA/SLH-DSA and hybrid ML-KEM key-agreement detection documented. Only the public-endpoint scan and TLM sync are product-driven discovery; the rest is ingestion of customer-produced CSV. Applications/libraries: 'Application inventory is on the roadmap'. 3-4 surfaces -> 6.",
      "delta_vs_published": 0
    },
    "C2": {
      "score": 4,
      "anchor": "4: proprietary export only (CSV/PDF/JSON)",
      "urls": [
        "https://docs.digicert.com/en/quantum-central/quantum-central-release-notes.html",
        "https://docs.digicert.com/en/quantum-central/check-crypto-posture/get-ai-powered-insights-about-your-assets.html",
        "https://www.digicert.com/quantum-central",
        "https://www.digicert.com/news/digicert-quantum-central-now-available-to-help-organizations-turn-pqc-plans-into-action"
      ],
      "quote": "Export dashboard and inventory data for offline review or reporting.",
      "rationale": "CBOM export is claimed on the product page ('Export CBOMs for internal and external stakeholders', WebFetch-extracted) and GA press release, but no schema is named and none of the 32 docs pages documents a CBOM export; documented exports are dashboard/inventory data, violation records and AI-Assist CSV/PDF. Claimed anchor 6 capped at the anchor below (rubric line 19). No integrity mechanism documented.",
      "delta_vs_published": -2
    },
    "C3": {
      "score": 5,
      "anchor": "between 4 (point-in-time, manual) and 6 (scheduled rescans with diff/drift reporting)",
      "urls": [
        "https://docs.digicert.com/en/quantum-central/set-up-quantum-central-integrations/integrate-trust-lifecycle-manager.html",
        "https://docs.digicert.com/en/quantum-central/govern-crypto-assets/define-crypto-policies.html",
        "https://docs.digicert.com/en/quantum-central/get-started/licensing-and-plans/essentials-plan.html"
      ],
      "quote": "Quantum Central can automatically import newly discovered certificates and TLS endpoints from Trust Lifecycle Manager when you sign in. This automatic import runs only if asset data was last synced more than 24 hours ago.",
      "rationale": "Re-evaluation against policies on asset change and a violation lifecycle (first-detected time, closed history) exist, but sync is sign-in-triggered, endpoint scans are manual, no scheduled rescan or diff report is documented, no tamper-evident history, and Essentials retains history 1 month.",
      "delta_vs_published": 0
    },
    "C4": {
      "score": 5,
      "anchor": "between 4 (vulnerable/not-vulnerable flag) and 6 (categorical risk levels from algorithm vulnerability plus context)",
      "urls": [
        "https://docs.digicert.com/en/quantum-central/govern-crypto-assets/define-crypto-policies.html",
        "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-policy-violations.html",
        "https://docs.digicert.com/en/quantum-central/check-crypto-posture/read-your-dashboard.html"
      ],
      "quote": "Every violation created by a policy inherits the policy’s severity. Choose the severity based on the risk represented by the condition and the expected urgency of remediation.",
      "rationale": "Built-in assessment is a quantum-safe true/false flag plus a Quantum Readiness %; Critical/High/Medium/Low exists only as user-assigned policy severity (Essentials allows 1 policy). No HNDL/data-lifetime factor or formula documented.",
      "delta_vs_published": 0
    },
    "C5": {
      "score": 4,
      "anchor": "4: accuracy or false-positive handling described, no metric",
      "urls": [
        "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-policy-violations.html",
        "https://docs.digicert.com/en/quantum-central/check-crypto-posture/read-your-dashboard.html"
      ],
      "quote": "Use manual resolution for situations such as an accepted risk, a false positive, a nonessential asset, or an asset approaching retirement.",
      "rationale": "False-positive handling and the exact quantum-safe classification rules (subjectPublicKeyInfo, signatureAlgorithm, named key-agreement groups) are documented; no accuracy metric, benchmark or ground truth found in the 32 docs pages.",
      "delta_vs_published": 0
    },
    "C6": {
      "score": 8,
      "anchor": "8: bidirectional integration or inbound state machine implemented and documented, but no live demonstration",
      "urls": [
        "https://docs.digicert.com/en/quantum-central/track-and-prioritize-crypto-remediation-tasks/track-crypto-remediation-tasks.html",
        "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-policy-violations.html",
        "https://docs.digicert.com/en/quantum-central/get-started/licensing-and-plans/essentials-plan.html"
      ],
      "quote": "Quantum Central retrieves the current status and maps it to a standardized state. The connected system remains the source of truth, and Quantum Central does not change the task’s status.",
      "rationale": "Outbound Jira task creation plus inbound status sync mapped to Open/In Progress/Done/Cancelled (shipped 9 Sep 2026, after the 2026.5 review), and verified closure: 'Automated indicates that Quantum Central verified that the asset passes the policy.' Caveat: 'Completing the task in the connected system does not close the violation.' Jira only; ServiceNow/GitHub 'planned'. TLM PQC certificate upgrade is a one-line Essentials-plan claim with no workflow page, not relied on.",
      "delta_vs_published": 1
    },
    "C7": {
      "score": 6,
      "anchor": "6: dashboards plus exports",
      "urls": [
        "https://docs.digicert.com/en/quantum-central/check-crypto-posture/read-your-dashboard.html",
        "https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-policy-violations.html",
        "https://docs.digicert.com/en/quantum-central/get-started/licensing-and-plans/essentials-plan.html",
        "https://docs.digicert.com/en/quantum-central/frequently-asked-questions/what-are-the-pqc-dates-and-milestones-for-my-country-or-the-standards-body-that-i-work-with-.html"
      ],
      "quote": "Export the filtered records for audit or compliance review.",
      "rationale": "Dashboard, violation export, AI-Assist PDF/CSV reports documented. No role-specific executive/technical report, no mapping of assets to frameworks (NIST IR 8547 appears only as a timeline table and the FAQ is a resource list), and the Essentials REST API is 'Import only', so no export API.",
      "delta_vs_published": 1
    }
  },
  "total": 5.37,
  "published_total": 5.47,
  "published_total_note": "Published total not in the brief; computed from published cells with the rubric formula: (4*6+3*6+3*5+3*5+2*4+2*7+2*5)/19 = 104/19 = 5.47.",
  "urls_that_failed": [
    "https://www.digicert.com/quantum-central (curl from the research host blocked by Incapsula; read via WebFetch only, so product-page quotes are WebFetch-extracted)",
    "https://www.digicert.com/news/digicert-quantum-central-now-available-to-help-organizations-turn-pqc-plans-into-action (same Incapsula block for curl; read via WebFetch only)"
  ],
  "notes": "Docs portal (docs.digicert.com/en/quantum-central, 32 pages enumerated from the site's toc.js) read in full as raw text on 2026-09-26; all docs quotes are verbatim from that raw text. Product-page/press-release quotes (e.g. 'Export CBOMs for internal and external stakeholders', 'Ingest and normalize data from DigiCert ONE, network scans, key vaults, SBOMs, CBOMS, and other sources') came through WebFetch, not raw HTML. The 2026.6 staging note says current docs confirm 'full PQC certificate lifecycle (issue/revoke/suspend/escrow)'; that text was not found in the current Quantum Central intro page, get-started page or release notes. Docs inconsistency: build-your-inventory says import of 'keys, endpoints, and applications is coming soon' while import-keys exists and release notes date it 10 Aug 2026. SBOM/CBOM upload is claimed on the product page and review-inventory page, but no import page for it exists in the docs TOC. Essentials plan limits: 1 policy, REST API import only, 1-month history retention. Net change: -2 on C2 (CBOM export claimed but not documented), +1 C6 (Jira status sync added 9 Sep), +1 C7. Quotes were checked against text extracted from the HTML. The extractor changed the whitespace around inline code elements, so spacing before punctuation (e.g. 'X25519MLKEM768 ,') may differ from the rendered page."
}
