Rank 2 / Strong band / Confidence MOD

CBOM Secure

Encryption Consulting / PQC discovery capability record for edition 2026.7.

7.47Index score / 10[1]

Vendor-documented broad discovery, continuous monitoring, and a claimed tamper-evident change log. S04S05S06

Strong MOD

Seven criterion scores

C110

Discovery

How broadly and deeply does the product find cryptographic assets?

C54

Correctness

Is detection accuracy measured against named ground truth?

C66

Remediation loop

Can a finding move through ownership, action and verified closure?

C78

Reporting

Can technical and executive readers understand and reuse the result?

Evidence for every cell (JSON): URLs read, verbatim quotes and rationale · Post-review totals

Research record · reviewed 2026-09-26

Evidence behind all seven scores

Edition 2026.7 scores were fixed using the 27 September 2026 method. A 30 September check asked whether archived excerpts could be found in cited sources; a separate 1 October internal review assessed what those sources support. Neither later check changed a score, weight, rank or cohort. Original rationales, adjustments, citations and both separate checks remain visible. Read the method · Download the 1 October claim ledger.

Discovery

10 / 10

Weight 4/19 · 2.11 points of the overall score

Internal 1 October claim review: Partial or qualified support. Vendor quote enumerates many surfaces; parameter depth and hybrid detection rely on an inaccessible datasheet and remain documentation-only.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: 8 surfaces are documented: TLS (a), certs/PKI/AD (b), source code in 7 languages (c), PE/ELF binaries (d), HSM/KMIP (e), AWS/Azure/GCP KMS (f), agent for OS trust stores/hosts (g), and database TDE plus keystores (h). Key size is captured, and the datasheet says 'hybrid TLS (X25519MLKEM768) detected in production'.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

20+ production sensors inventory cryptographic assets across cloud platforms, hardware security modules, KMIP servers, TLS endpoints, directory services, databases, file systems, source code, and binaries.

Original scoring anchor: 10: >=7 surfaces documented with algorithm+parameter depth and PQC/hybrid detection

Evidence artifact

7 / 10

Weight 3/19 · 1.11 points of the overall score

Internal 1 October claim review: Narrow feature documented. Accessible vendor page documents CycloneDX 1.6/1.7 export; it does not document a signature on the exported CBOM.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: CycloneDX 1.6/1.7 export is documented. 'Cryptographically verifiable' integrity is claimed only for the audit trail, not the CBOM export, and no mechanism is named. No public sample or signature found.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Audit artifacts generated in CycloneDX 1.6 and 1.7.

Original scoring anchor: between 6 (standard export, no integrity) and 8 (standard export + documented integrity mechanism)

Change detection

8 / 10

Weight 3/19 · 1.26 points of the overall score

Internal 1 October claim review: Partial or qualified support. Vendor documents monitoring, alerts and a tamper-proof audit trail, but publishes no log mechanism or independent verification.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Continuous monitoring that detects configuration changes, email/Teams alerting and a tamper-evident change log are documented. No detection latency is published (needed for 9), and the log's mechanism (hash chain or signature) is not named.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

A tamper-proof audit trail records every asset change in a cryptographically verifiable log: what changed, when, and by whom.

Original scoring anchor: 8: continuous or scheduled monitoring with documented change alerts AND tamper-evident history

Risk quantification

7 / 10

Weight 3/19 · 1.11 points of the overall score

Internal 1 October claim review: Partial or qualified support. Accessible V1.1 page confirms 0-100 score and named factors; exact archived datasheet quote was inaccessible (406), and lifetime/HNDL is absent.

1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: A per-asset 0-100 score and bands are documented, but the listed factors have no data-lifetime or HNDL term. HNDL/TNFL 'enrichment' appears only on the vendor blog page cbom-inventory-to-intelligence, with no mechanism and no stated combination into the numeric score. No weights are published.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Four risk bands: Critical, High, Low, Safe. Scoring weighs algorithm strength, expiry, key reuse, cipher mode, IV/nonce handling, KDF parameters, quantum exposure.

Original scoring anchor: between 6 (categorical levels from algorithm plus context) and 8 (numeric score including HNDL/data lifetime)

Correctness

4 / 10

Weight 2/19 · 0.42 points of the overall score

Internal 1 October claim review: Partial or qualified support. Vendor says false positives are eliminated but gives no method or precision/recall metric; anchor is only a documented claim.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: False-positive reduction through dormant/conditional/active reachability is described. No precision, recall or benchmark is documented in the URLs searched or in a web search for CBOM Secure accuracy metrics. The V1.1 'Testing and Validation Evidence' section gives outcome claims only (70-80% audit time, >90% incident reduction).

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Rather than treating every discovered asset as an equal risk, this level of precision ensures your team focuses remediation efforts on real-world exposure, eliminating false positives

Original scoring anchor: 4: accuracy or false-positive handling described, no metric

Remediation loop

6 / 10

Weight 2/19 · 0.63 points of the overall score

Internal 1 October claim review: Narrow feature documented. CycloneDX export and remediation guidance support final six; named Jira/ServiceNow integration belongs to CertSecure Manager, not this product.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Original assessment: Ticketing integration is named once, with no named system (no Jira/ServiceNow) and no mechanism; the datasheet does not mention ticketing. Remediation guidance and CertSecure Manager integration are documented. No automated remediation or verified closure is documented.

Final review: 5 → 6. The 6 anchor reads 'one-way ticket/EXPORT plus guidance'. A CycloneDX export plus concrete remediation guidance meets it on its face. The researcher gave QCecuring 6 on exactly this pattern (JSON export plus an 'Action Required' field), so leaving CBOM Secure at 5 was an inconsistency against the #2 product. The raise stops at 6 because the named Jira/ServiceNow ticketing belongs to a different product (CertSecure Manager) and no automated remediation is documented for CBOM Secure. Row total rises 7.37 -> 7.47 (142/19).

Review evidence and archived ruling

/cryptographic-discovery-inventory/: 'Audit artifacts generated in CycloneDX 1.6 and 1.7.' and 'Drive phased remediation across mapped dependencies.' Functionalities page: 'Integrate with SIEM, GRC, and ticketing platforms to streamline remediation workflows.' and 'Plan migration with crypto agility scoring and dependency analysis. Replace weak, deprecated, and quantum vulnerable cryptography first.' V1.1 page: 'so analysts know what to fix'. On /integration/, the ServiceNow ('Automate Certificate Issue Tracking...') and Jira ('Raises and syncs Jira tickets...') entries are tagged 'Certsecure Manager', not CBOM Secure.

Read the review file
Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Integrate with SIEM, GRC, and ticketing platforms to streamline remediation workflows.

Original scoring anchor: between 4 (guidance only) and 6 (one-way ticket/export plus guidance)

Reporting

8 / 10

Weight 2/19 · 0.84 points of the overall score

Internal 1 October claim review: Partial or qualified support. Vendor lists dashboards, KPIs and framework mapping, but no public sample report or assessed mapping accuracy.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: A per-framework mapping table is published (SP 800-131A, FIPS 140-3, CNSA 2.0, CMMC, PCI DSS 4.0, NIST IR 8547, FedRAMP). The datasheet lists role-based dashboards and a REST API with OpenAPI for every widget/KPI. No sample report was found, so 10 is not met.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Reporting includes dashboards built from 29 widgets and 52 built-in KPIs, on-demand compliance evidence, alerting via email and Microsoft Teams, and full inventory export in CycloneDX.

Original scoring anchor: 8: executive and technical reports with documented compliance mapping

Research scope, product-status record and unresolved evidence gaps

Documentation reviewed 2026-09-26: Active. CBOM Secure V1.1 was released in June 2026 and the release page was updated in August 2026. V1.1 added AWS discovery, CrowdStrike Falcon host sync, a Source Code Visualizer, a PQC chart, an AI/MCP module, Docker deployment and in-app docs. No rename, acquisition or discontinuation found. No major release after August 2026 found.

Archived product-status source · Source check: HTTP 200. The archived summary has not been independently revalidated in full.

Evidence is vendor product pages, vendor knowledge-base/blog articles on the vendor's own domain, and the datasheet PDF (created 2026-01-12, modified 2026-06-12). Press-wire copies (PRNewswire/StreetInsider) were not cited; the same statements appear on /cbom-secure-v1-1/. The brief's S06 source (/cbom-secure-deployment-models/) does not contain the CycloneDX 1.6/1.7 statement; that statement is on /cryptographic-discovery-inventory/. The brief's S04 figures ('seventy libraries, eight hundred patterns') are confirmed as '70+ libraries' and '880+ function patterns' on the vendor site. Inconsistencies across vendor pages: 29 widgets/52 KPIs vs 30+/50+; 'Eighteen production sensors' vs '20+'; four bands 'Critical, High, Low, Safe' (datasheet) vs 'Critical, High, Medium, Low, and Safe' (posture page); the datasheet body says CycloneDX 1.6 while its output section says 1.6 and 1.7. The per-asset HNDL scoring claim rests only on a vendor blog article with no mechanism. No public sample CBOM, report or accuracy data exists in the pages fetched. Pages were fetched with curl from the research host and quoted from the extracted text.

Original product evidence (JSON) · Final matrix and applied review changes · Edition identity and hashes