{
  "slug": "ibm-guardium-quantum-safe",
  "name": "IBM Guardium + Quantum Safe",
  "vendor": "IBM",
  "researched_at": "2026-09-26",
  "product_status": {
    "summary": "Consolidating, not discontinued. https://www.ibm.com/products/guardium-quantum-safe now returns HTTP 301 to https://www.ibm.com/products/guardium-cryptography-manager (verified with curl on 2026-09-26). Guardium Quantum Safe docs are still live under Guardium Data Security Center 3.x, which says: 'As of 31 July 2025, Guardium Quantum Safe has a standalone installation and delivery path'. Guardium Cryptography Manager (GCM) 2.0 has 'General Availability 26-Nov-2025' (https://www.ibm.com/support/pages/ibm-guardium-cryptography-manager20, curl-verified). The 2.0.1 release (Mar 2026) is known only from web search, and the GCM docs index lists version 2.0.3.0 per WebFetch. GCM ingests IBM Quantum Safe Explorer (QSE) findings and CBOMs. No new major release since Aug 2026 was found.",
    "url": "https://www.ibm.com/products/guardium-cryptography-manager"
  },
  "cells": {
    "C1": {
      "score": 8,
      "anchor": "8: 5-6 surfaces with algorithm depth (10 not reached: hybrid detection not documented)",
      "urls": [
        "https://www.ibm.com/docs/en/SSQQH4_2.0.0/discovery/gcm_discovering_db_and_app.html",
        "https://www.ibm.com/docs/en/SSQQH4_2.0.0/Plug-ins/available-plug-ins.html",
        "https://www.ibm.com/docs/en/SSQQH4_2.0.0/inventory/Inventory_overview/cryptographic-object-overview.html",
        "https://www.ibm.com/docs/en/quantum-safe/quantum-safe-explorer/2.x?topic=quantum-safe-explorer-overview",
        "https://www.ibm.com/docs/en/SSQQH4_2.0.0/post_quantum_cryptography/post_quantum_cryptography.html"
      ],
      "quote": "Quantum Safe™ Explorer supports scanning of source code that is written in Java, C, C++, C#, Python, Dart, Go, Kotlin, JavaScript and Typescript (Node.js).",
      "rationale": "Documented surfaces: (a) network scan of certificates, keys, ciphers and protocols; (b) PKI through Vault PKI and CA plug-ins (ADCS, DigiCert, Sectigo, Venafi); (c) source code through QSE; (e/f) cloud KMS and vaults through AWS, Azure, GCP, Akeyless and HashiCorp plug-ins; (j) mainframe through the IBM zCDI plug-in; plus Kubernetes secrets. The object model records key algorithm, key size and algorithm parameters. The PQC policy names Kyber, Dilithium, FALCON and SPHINCS+. Hybrid-algorithm detection is not documented, and depth is not shown for each plug-in surface, so the score stays at 8.",
      "delta_vs_published": 0
    },
    "C2": {
      "score": 6,
      "anchor": "6: standard-schema export documented, no integrity mechanism",
      "urls": [
        "https://www.ibm.com/docs/en/quantum-safe/quantum-safe-explorer/2.x?topic=quantum-safe-explorer-overview",
        "https://research.ibm.com/blog/quantum-safe-cbomkit",
        "https://github.com/cbomkit/cbomkit"
      ],
      "quote": "Scanning generates cryptographic inventory reports in various formats, including a Cryptography Bill of Materials (CBOM), .CSV files, and Findings.JSON.",
      "rationale": "CBOM export is documented. Signing, hashing or any integrity mechanism for the CBOM is not documented in the QSE overview, the CBOMkit blog, the cbomkit GitHub README or the GCM docs index. IBM authored the CBOM standard, but authorship is not an integrity mechanism. The published 8.5 had no integrity evidence behind it.",
      "delta_vs_published": -2.5
    },
    "C3": {
      "score": 4,
      "anchor": "4: point-in-time scans (scheduled discovery documented; diff/drift reporting not documented)",
      "urls": [
        "https://www.ibm.com/docs/en/SSQQH4_2.0.0/discovery/gcm_managing_discovery.html",
        "https://www.ibm.com/docs/en/gdsc/3.x?topic=guardium-quantum-safe"
      ],
      "quote": "It enables in-depth analysis of associated risks and vulnerabilities, offers robust policy enforcement, and alerting mechanisms to effectively manage cryptographic assets.",
      "rationale": "GCM discovery profiles can be scheduled, and each scan gets a Run ID and a scan timeline. Diff or drift reporting between scans, change alerts and tamper-evident history are not documented in the GCM managing-discovery page, the GQS overview or the GQS getting-started page. The generic 'alerting mechanisms' line has no mechanism behind it. The published 7 had no change-detection evidence.",
      "delta_vs_published": -3
    },
    "C4": {
      "score": 6,
      "anchor": "6: categorical risk levels from algorithm vulnerability plus some context",
      "urls": [
        "https://www.ibm.com/docs/en/SSQQH4_2.0.0/post_quantum_cryptography/post_quantum_cryptography.html",
        "https://www.ibm.com/docs/en/guardium-cm/1.0.0?topic=violations-types-policy-in-guardium-cryptography-manager"
      ],
      "quote": "Built-in policies automatically detect risky assets and generate PQC violations, which include CVSS-style based on CVSS impact scores, to prioritize remediation efforts.",
      "rationale": "Assets are classified PQC Safe or PQC Unsafe, with CVSS-style impact scores and an 'Exploitability Score'. Data lifetime, HNDL or Mosca factors are not documented. The product page mentions 'customized risk metrics', but no formula is given.",
      "delta_vs_published": 0
    },
    "C5": {
      "score": 6,
      "anchor": "6: a published benchmark metric, but n<100 (70 Go-invocation occurrences) and ground truth not dual-annotated. Footing: the CBOMkit toolchain is treated as in-row, consistent with the brief's S10 and with the C1 and C2 scoping.",
      "urls": [
        "https://arxiv.org/abs/2608.04857v1",
        "https://arxiv.org/html/2608.04857"
      ],
      "quote": "On the full Go-invocation ground truth Crypsy reaches F1 = 0.92 (P = 0.95, R = 0.89) versus 0.66 for CBOMkit (P = 0.84, R = 0.54)",
      "rationale": "Paper: Näther (XITASO GmbH) and Hirsch (University of Applied Sciences Amberg-Weiden), 'Hidden Ciphers and Where to Find Them', arXiv 2608.04857v1, 5 Aug 2026. The arXiv Comments field says 'accepted at ICICS 2026' (byte-verified). It tests CBOMkit-hyperion (PQCA sonar-cryptography v1.6.1) on 70 Go-invocation occurrences: TP 38, FP 7, FN 32, giving P 0.84, R 0.54, F1 0.66. Ground truth is the synthetic Cryben corpus with a CycloneDX 1.7 CBOM, built by the authors of the competing tool Crypsy. It is independent of CBOMkit, but no dual annotation is stated. Because n<100, anchor 6 is the ceiling.",
      "delta_vs_published": -2
    },
    "C6": {
      "score": 7,
      "anchor": "7: one-way ticket creation plus automated remediation actions",
      "urls": [
        "https://www.ibm.com/docs/en/SSQQH4_2.0.0/remediation/creating_tickets.html",
        "https://www.ibm.com/docs/en/SSQQH4_2.0.0/remediation/gcm_ai_enabled_remediation.html",
        "https://www.ibm.com/products/guardium-cryptography-manager"
      ],
      "quote": "For the tickets that are created in JIRA and ServiceNow, you need to track the ticket status in those particular applications.",
      "rationale": "Tickets go one way to Jira or ServiceNow, and the status is explicitly tracked in the external system. The product page states 'Automate key generation and certificate renewal'. AI-prefilled remediation fields are documented. Bidirectional sync and rescan-verified closure are not documented.",
      "delta_vs_published": 0
    },
    "C7": {
      "score": 6,
      "anchor": "6: dashboards plus exports",
      "urls": [
        "https://www.ibm.com/docs/en/guardium-cm/1.0.0?topic=dashboards-cryptographic-posture-management",
        "https://www.ibm.com/products/guardium-cryptography-manager",
        "https://www.ibm.com/docs/en/guardium-cm/2.0.0"
      ],
      "quote": "Export: You can export the dashboard in PDF format.",
      "rationale": "Documented: a posture dashboard with PDF export, CSV/Excel export of violations, a Swagger API, and 'audit-ready reports'. The only framework referenced is generic NIST quantum-safe alignment. Separate executive and technical reports, and mappings to CNSA 2.0, NIST IR 8547 or OMB, are not documented.",
      "delta_vs_published": -1
    }
  },
  "total": 6.21,
  "published_total": 7.39,
  "urls_that_failed": [
    "curl (from the research host) to every https://www.ibm.com/docs/en/SSQQH4_2.0.0/* page and https://www.ibm.com/docs/en/guardium-cm/2.0.0 returned HTTP 403. The content was read through WebFetch instead.",
    "http://web.archive.org/web/20260819182742id_/https://www.ibm.com/docs/en/guardium-cm/2.0.x?topic=post-quantum-cryptography-readiness loaded (200) but is a JavaScript shell with no body text."
  ],
  "notes": "SCOPE: this row mixes three IBM offerings. Guardium Quantum Safe (GDSC 3.x docs, standalone since 31 Jul 2025), Guardium Cryptography Manager 2.0.x (the destination of the 301 from the GQS product page) and Quantum Safe Explorer 2.x (the source-code scanner that feeds both). The GCM plug-ins (cloud KMS, CAs, zCDI mainframe) are credited to this row because IBM now redirects GQS to GCM. A reviewer who limits the row to GQS 3.x would score C1 lower. QUOTE VERIFICATION: the IBM docs quotes were extracted through WebFetch and are not byte-verified, because IBM docs block curl and the Wayback copy is a JavaScript shell. The GQS 3.x 'alerting mechanisms' quote WAS byte-verified against the Wayback snapshot of 20250809. The C4 quote contains IBM's own grammatical error ('CVSS-style based on CVSS impact scores'). A second WebFetch returned the same text. The arXiv quote and the Table 2 counts were byte-verified from the arXiv HTML fetched on the research host. C5 ORIGIN: the 15 Aug C5=8 rested on this paper. The paper benchmarks CBOMkit-hyperion, not a Guardium product, uses only n=70 for that tool, and is single-sourced for ground truth, so anchor 8 is not supported. FOOTING: C5=6 treats the IBM-originated CBOMkit toolchain as part of this row, as the brief's S10 does and as C1 and C2 do. No IBM doc was found saying GQS, GCM or QSE uses the sonar-cryptography engine. If a reviewer excludes CBOMkit from the row, C5 falls to 0, because no metric or false-positive handling was found in the GQS, GCM or QSE docs, and the total falls to 5.58. A first WebFetch summary of the arXiv abstract wrongly said the paper had no tool comparison; the raw full text corrected that. CBOMkit's recall of 0.54 on this corpus is unflattering, but the anchors score whether a metric exists, not how good it is. The published C2=8.5 and C3=7 had no documented integrity or change-history mechanism behind them. PUBLISHED_TOTAL: the brief gives no total, so 7.39 is recomputed from published_cells with the rubric formula."
}
