Discovery
How broadly and deeply does the product find cryptographic assets?
Capability instrument public-evidence re-score
A public-evidence capability instrument for comparing what post-quantum discovery software does - and how convincingly it can show its work.
How broadly and deeply does the product find cryptographic assets?
Does it produce a portable, verifiable record of what was found?
Can it detect and preserve material changes over time?
Does it turn inventory into a defensible migration priority?
Is detection accuracy measured against named ground truth?
Can a finding move through ownership, action and verified closure?
Can technical and executive readers understand and reuse the result?
Each product is scored from 0 to 10 per criterion. For edition 2026.7 the publisher reports that researchers scored every cell with URLs read, an archived source passage and a rationale, then three adversarial reviews could only lower or raise a cell with new evidence. The files are published under /evidence/2026-7/; the total is the weighted sum over 19.
The independent 30 September 2026 source-access screen reproduced an archived excerpt for 71 of 98 cells, found accessible sources without reproducing the excerpt for 20, and could not access cited sources for 7. This screen does not validate each complete rationale or product behavior. Inspect the dated check records.
Admissible evidence includes product pages, technical documentation, release notes and published specifications. Analyst reports, reseller pages and press coverage are excluded from the functional score. No vendor was asked for internal data and none supplied any.
Where a capability was not located in public sources, the index records it as not documented. That is an evidence-bound statement, not proof the capability does not exist.
Certifications, install base, customer counts, deployment scale, procurement vehicles, marketplace listings, analyst placement, funding and company age are excluded. They measure vendor assurance or market presence rather than product capability.
They may still matter in procurement, so the report records them separately instead of hiding them.
When a vendor demonstrates that a cell is wrong, the cell changes, the change is logged with its date and evidence, and the index is republished. Corrections remain visible in later editions whether they help QScout or a competitor.
Edition 2026.7 (27 September 2026): the 2026.5 scores were withdrawn after an audit found that four of QScout's seven cells were asserted by the vendor instrument and that the phrase "56 probes" had no enumeration behind it. Every product was re-scored; the changes are listed under withdrawn claims and in the published evidence files.