Rank 14 / Emerging band / Confidence THIN

CryptoNext COMPASS

CryptoNext / PQC discovery capability record for edition 2026.7.

4.68Index score / 10[1]

A probe-fed CycloneDX cryptographic inventory database. S16

Emerging THIN

Seven criterion scores

C16

Discovery

How broadly and deeply does the product find cryptographic assets?

C50

Correctness

Is detection accuracy measured against named ground truth?

C64

Remediation loop

Can a finding move through ownership, action and verified closure?

C76

Reporting

Can technical and executive readers understand and reuse the result?

Evidence for every cell (JSON): URLs read, verbatim quotes and rationale · Post-review totals

Research record · reviewed 2026-09-26

Evidence behind all seven scores

Edition 2026.7 scores were fixed using the 27 September 2026 method. A 30 September check asked whether archived excerpts could be found in cited sources; a separate 1 October internal review assessed what those sources support. Neither later check changed a score, weight, rank or cohort. Original rationales, adjustments, citations and both separate checks remain visible. Read the method · Download the 1 October claim ledger.

Discovery

6 / 10

Weight 4/19 · 1.26 points of the overall score

Internal 1 October claim review: Partial or qualified support. Primary Network Probe PDF confirms TLS/SSH/ISAKMP and parameters; archived longer protocol list and cross-surface count need further corroboration.

1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Native discovery is the passive network probe: (a) TLS/network, (b) certificates in transit, (i) SSH/IPsec/ISAKMP, (j) OT protocols (dnp3 etc.) = 4 surfaces with 'algorithms, parameters, keys, certificates' extraction. Other sources (CLM, scanners, EDRs) are third-party feeds via API, not COMPASS discovery; PQC/hybrid detection not documented in the URLs searched.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Inspected Protocols TLS/SSL, DTLS, QUIC, SSH, ISAKMP, Kerberos, DNSSec, SMB

Original scoring anchor: 6: 3-4 surfaces

Evidence artifact

6 / 10

Weight 3/19 · 0.95 points of the overall score

Internal 1 October claim review: Narrow feature documented. Primary Network Probe PDF states CBOM files based on OWASP CycloneDX; PDF text extraction splits the standard name.

1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: CycloneDX CBOM output streamed via Kafka is documented; the datasheet's 'code signing' and 'software integrity checks' refer to the appliance, not to the CBOM artifact. CBOM signing/hash chain and a public sample are not documented in the URLs searched.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

The CryptoNext COMPASS Network Probe produces CBOM files, based on the OWASP CycloneDX standard, enabling easy integration with any system that supports this format.

Original scoring anchor: 6: standard-schema export documented, no integrity mechanism

Change detection

5 / 10

Weight 3/19 · 0.79 points of the overall score

Internal 1 October claim review: Partial or qualified support. Primary PDF explicitly describes passive continuous traffic monitoring; no diff/drift reporting or alert timing shown, making midpoint discretionary.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Continuous passive capture is documented (exceeds point-in-time), but diff/drift reporting, change alerts and tamper-evident change history are not documented in the URLs searched; published 8 requires drift alerts AND signed/hash-chained history.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

The CryptoNext COMPASS Network Probe is a hardware appliance designed for passive and continuous network traffic monitoring, enabling the detection and collection of cryptographic assets in transit to build a comprehensive inventory.

Original scoring anchor: midpoint between 4 (point-in-time scans) and 6 (scheduled rescans with documented diff/drift reporting)

Risk quantification

4 / 10

Weight 3/19 · 0.63 points of the overall score

Internal 1 October claim review: Partial or qualified support. Data sensitivity/criticality linkage is vendor-documented; formula and per-asset risk behavior are not verified.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Original assessment: Detection of weak/non-compliant algorithms plus a claimed sensitivity/criticality context for prioritization; no score, categories, formula or HNDL/data-lifetime factor documented, so the claim is capped below the anchor it implies.

Final review: 5 → 4. The only documented output is a weak or non-compliant flag, which is anchor 4. The sensitivity and criticality linkage is a marketing sentence with no categories, score or mechanism. The researcher cited rubric line 19 but put the score above the cap that line sets, so it snaps to 4.

Review evidence and archived ruling

https://www.cryptonext-security.com/en/solutions-use-case-inventory-your-cryptography/ ('Quickly identify weak, obsolete, or non-compliant cryptographic algorithms'); https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/ ('Connect each cryptographic asset to the data it protects and its business criticality')

Read the review file
Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

COMPASS does more than identify cryptographic assets: it links them to the data they protect, with information on sensitivity and criticality, to enable risk-based prioritization.

Original scoring anchor: midpoint between 4 (vulnerable/not flag) and 6 (categorical risk levels plus context); capped per rubric line 19

Correctness

0 / 10

Weight 2/19 · 0.00 points of the overall score

Internal 1 October claim review: Claim not verified from accessible evidence. Zero is a bounded absence of published accuracy evidence, not measured error rate; archived no-hit search was not reproduced.

1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Throughput ('up to 1 Gbps') and 'no packets lost' are performance claims, not detection-correctness metrics.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

not documented in the URLs listed (no accuracy metric, benchmark, test methodology or false-positive handling found)

Original scoring anchor: 0: not documented

Remediation loop

4 / 10

Weight 2/19 · 0.42 points of the overall score

Internal 1 October claim review: Partial or qualified support. API/CMDB integration is vendor-documented; ticket creation or closure is not demonstrated, consistent with guidance-only cap.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Downstream API export named; ticket creation, automated remediation or closure verification not documented in the URLs searched. CryptoNext 'Remediation' SDK is a separate product and not credited to COMPASS.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Standard APIs for easy upstream (sensors: CLM, scanners, EDRs, etc.) and downstream (platforms: CMDB, CTEM, etc.) integrations

Original scoring anchor: 4: remediation guidance only (downstream export to CMDB/CTEM named; no ticketing documented)

Reporting

6 / 10

Weight 2/19 · 0.63 points of the overall score

Internal 1 October claim review: Partial or qualified support. Compliance reports are named; actual standards-to-finding mapping and report output are not independently examined.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Dashboards, a 'personalized report generation module', REST API and CBOM/Kafka export are documented; compliance reports and DORA/NIS2/ANSSI/NIST references are named but no report content, framework mapping or sample is documented.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Use ready-made compliance reports, customize them, and respond to audits at any time.

Original scoring anchor: 6: dashboards plus exports (compliance reports named without documented mapping, capped per rubric line 19)

Research scope, product-status record and unresolved evidence gaps

Documentation reviewed 2026-09-26: COMPASS (Analytics + Network Probe, GA 1 July 2025) remains marketed under the same name. New since Aug 2026: 'CryptoNext Discovery On Demand', a two-week scoped assessment service announced Paris, 10 Sept 2026 (report prioritizes weak/quantum-vulnerable assets by severity and measures DORA/NIST gaps). It is a service offering, not a COMPASS feature release, and was not credited to COMPASS cells. A brand refresh is listed (undated on page). No rename or acquisition found.

Archived product-status source · Source check: HTTP 200. The archived summary has not been independently revalidated in full.

Primary evidence is thin: one hardware datasheet (PDF, text read directly), one launch press release (PDF on vendor site; used only for concrete capability statements), and two marketing product pages. No public docs portal, GitHub repo or sample CBOM was found. The WebFetch PDF parse failed; both PDFs were downloaded by the fetch tool and read page-by-page, so datasheet quotes are verbatim. Published C3=8 is the largest unsupported cell: nothing fetched documents drift alerts or tamper-evident history. Between-anchor convention: integer midpoint, both anchors named. Third-party descriptions (encryptionconsulting.com, postquantum.com) claiming '100+ protocols' and endpoint/code-scanner correlation are inadmissible and were not credited. The 10 Sept 2026 Discovery On Demand release (read verbatim from the PDF) describes a consulting-style service report with severity prioritization and DORA gap measurement; a reviewer could argue it lifts C4/C7 if the service is treated as part of COMPASS, but the release does not name COMPASS, so it was not credited.

Original product evidence (JSON) · Final matrix and applied review changes · Edition identity and hashes