{
  "slug": "qcecuring-cbom",
  "name": "QCecuring CBOM",
  "vendor": "QCecuring (QCecuring Technologies)",
  "researched_at": "2026-09-26",
  "product_status": {
    "summary": "No rename, acquisition, discontinuation or dated major release found. A public technical docs portal for CBOM (docs.qcecuring.com/cbom, 22 pages: architecture, deployment, 11 scanner types, CycloneDX v1.6 import/export, compliance, API) is live; it was not read for 2026.5 (brief says 'carried_thin'). Docs pages carry no version or date, so when they appeared is not established.",
    "url": "https://docs.qcecuring.com/cbom"
  },
  "cells": {
    "C1": {
      "score": 9,
      "anchor": "between 8 (5-6 surfaces with algorithm depth) and 10 (>=7 surfaces, algorithm+parameter depth, PQC/hybrid detection)",
      "urls": [
        "https://docs.qcecuring.com/cbom",
        "https://docs.qcecuring.com/cbom/getting-started/first-scan",
        "https://docs.qcecuring.com/cbom/scanners/network",
        "https://docs.qcecuring.com/cbom/scanners/source-code",
        "https://docs.qcecuring.com/cbom/scanners/binary",
        "https://docs.qcecuring.com/cbom/scanners/cloud",
        "https://docs.qcecuring.com/cbom/scanners/filesystem",
        "https://docs.qcecuring.com/cbom/scanners/directory-services",
        "https://docs.qcecuring.com/cbom/scanners/certstore-windows"
      ],
      "quote": "Algorithm, key size, and quantum risk level",
      "rationale": "Docs scanner reference documents (a) TLS endpoints, (b) certificates/ADCS/Windows store, (c) source code in 6 languages, (d) binaries/linked libraries, (e/f) AWS ACM/KMS and Azure Key Vault, (g) agent filesystem keys/keystores, (i) SSH endpoints, with algorithm and key-size depth; ML-KEM/ML-DSA appear in the risk table, but TLS key_share/named-group (hybrid X25519MLKEM768) detection is not documented, so not 10.",
      "delta_vs_published": 2
    },
    "C2": {
      "score": 6,
      "anchor": "6: standard-schema export documented, no integrity mechanism",
      "urls": [
        "https://docs.qcecuring.com/cbom/platform/import-export",
        "https://docs.qcecuring.com/cbom/platform/inventory"
      ],
      "quote": "Exports your full cryptographic inventory as a CycloneDX v1.6 JSON document. The export includes: bomFormat: \"CycloneDX\" , specVersion: \"1.6\" Unique serial number (URN UUID)",
      "rationale": "CycloneDX v1.6 CBOM export thoroughly documented (algorithmProperties incl. NIST quantum security level, certificateProperties, dependencies, BOM-Link). No signature or hash chain on the exported CBOM is documented (only the license file is Ed25519-signed), and no public sample found; github.com/qcecuring has no public repositories.",
      "delta_vs_published": 0
    },
    "C3": {
      "score": 7,
      "anchor": "between 6 (scheduled rescans with diff/drift reporting) and 8 (scheduled monitoring with drift alerts AND tamper-evident history)",
      "urls": [
        "https://docs.qcecuring.com/cbom/architecture",
        "https://docs.qcecuring.com/cbom/platform/compliance",
        "https://docs.qcecuring.com/cbom/platform/sensors",
        "https://docs.qcecuring.com/cbom/administration/licensing"
      ],
      "quote": "Delta vs. the previous assessment for the same standard Direction indicator: IMPROVED, REGRESSED, or UNCHANGED Per-category changes (violations added/resolved)",
      "rationale": "Sensors run scans on hourly/6h/12h/daily/weekly schedules; compliance assessments report deltas vs the previous run; architecture lists 'Email notifications for policy violations and certificate expiry'. No tamper-evident history documented. Caveats: trend delta comes from on-demand 'Run Assessment', and email alerts are Standard/Enterprise only.",
      "delta_vs_published": 4
    },
    "C4": {
      "score": 6,
      "anchor": "6: categorical risk levels from algorithm vulnerability plus some context",
      "urls": [
        "https://docs.qcecuring.com/cbom",
        "https://docs.qcecuring.com/cbom/platform/compliance",
        "https://www.qcecuring.com/blog/quantum-risk-scoring-methodology"
      ],
      "quote": "Every asset is classified automatically: Risk Level Meaning Examples CRITICAL Broken or deprecated MD5, SHA-1, DES, RC4, TLS 1.0/1.1 HIGH Quantum-vulnerable RSA, ECDSA, ECDH, DH, DSA",
      "rationale": "Docs document 5-level categorical risk (CRITICAL..NONE) by algorithm plus per-standard rules with key-size constraints, deadlines and actions. A 6-factor weighted formula with HNDL/retention exists only in a vendor blog; it is not corroborated in the technical docs (exported properties list has no score fields), so it is not credited.",
      "delta_vs_published": 1
    },
    "C5": {
      "score": 4,
      "anchor": "4: accuracy or false-positive handling described, no metric",
      "urls": [
        "https://docs.qcecuring.com/cbom/scanners/filesystem",
        "https://docs.qcecuring.com/cbom/platform/sensors"
      ],
      "quote": "Encrypted PEM keys are detected but cannot be parsed without the passphrase (they still appear as assets with algorithm info) Keystores with individual entry passwords different from the store password may not fully parse",
      "rationale": "Parse limitations and partial/failed scan status with error lists are documented; no precision/recall, benchmark or ground truth found in the 22 docs pages or product page.",
      "delta_vs_published": 1
    },
    "C6": {
      "score": 6,
      "anchor": "6: one-way ticket/export plus guidance",
      "urls": [
        "https://docs.qcecuring.com/cbom/platform/compliance",
        "https://www.qcecuring.com/integrations"
      ],
      "quote": "Action Required remediation (e.g., “Migrate to ML-KEM”)",
      "rationale": "Per-violation required action and migration deadline plus 'Export the full assessment as JSON' = export plus guidance. No Jira/ServiceNow/ticketing integration documented in docs.qcecuring.com/cbom or on the integrations page; no automated remediation documented for CBOM.",
      "delta_vs_published": 3
    },
    "C7": {
      "score": 7,
      "anchor": "between 6 (dashboards plus exports) and 8 (executive and technical reports with documented compliance mapping)",
      "urls": [
        "https://docs.qcecuring.com/cbom/platform/dashboard",
        "https://docs.qcecuring.com/cbom/platform/compliance",
        "https://docs.qcecuring.com/cbom/api-reference"
      ],
      "quote": "CNSA 2.0 — NSA Commercial National Security Algorithm Suite NIST PQC — Post-Quantum Cryptography transition requirements FIPS 140-3 — Approved algorithms and minimum key sizes",
      "rationale": "Compliance mapping to CNSA 2.0/NIST PQC/FIPS 140-3 with per-standard reports, CycloneDX/JSON export and REST API are documented; the executive artifact is a dashboard ('executive summary' cards), and the 'Reports' page has no docs entry, so short of 8. No public sample report.",
      "delta_vs_published": 1
    }
  },
  "total": 6.68,
  "published_total": 4.95,
  "published_total_note": "Published total not in the brief; computed from published cells with the rubric formula: (4*7+3*6+3*3+3*5+2*3+2*3+2*6)/19 = 94/19 = 4.95.",
  "urls_that_failed": [
    "https://github.com/qcecuring/cbom (HTTP 404; the deployment doc says 'git clone https://github.com/qcecuring/cbom.git'; Wayback availability API returned no snapshots; GitHub org page states 'This organization has no public repositories')",
    "https://docs.qcecuring.com/sitemap.xml (HTTP 404; page list taken instead from links on docs.qcecuring.com/cbom)"
  ],
  "notes": "The large upward movement (+1.73 total) comes from reading the vendor's public technical docs portal docs.qcecuring.com/cbom (22 pages, raw text fetched 2026-09-26), which the 2026.5 index did not read (2026.6 brief: 'Not re-fetched; carried, provisional'). It is not a judgment that the product changed. Only docs-documented scanners were counted for C1: the product page (qcecuring.com/product/cbom) also claims HSMs (Thales Luna, Entrust nShield, CloudHSM), Kubernetes/containers, email (S/MIME, PGP) and network devices, but no scanner page exists for these, so they were not counted. The vendor blog at qcecuring.com/blog/quantum-risk-scoring-methodology publishes weights (AV 0.25, DS 0.20, RP 0.20, HE 0.15, SC 0.10, RC 0.10) and claims 'QCecuring CBOM integrates quantum risk scoring directly into the CBOM generation process'; the docs' exhaustive export-property list and asset detail panel show no numeric score, so C4 stays at 6 until the docs corroborate it. Nothing was run against a live instance; all scores rest on documentation. The product is self-hosted (Docker Compose + MongoDB + Java sensors) and requires a vendor license file, so claims cannot be independently exercised without a license. Quotes are verbatim from HTML-to-text extraction; table cells run together without separators, and whitespace may differ from the rendered page."
}