Discovery
How broadly and deeply does the product find cryptographic assets?
Rank 14 / Emerging band / Confidence THIN
CryptoNext / PQC discovery capability record for edition 2026.7.
A probe-fed CycloneDX cryptographic inventory database. S16
Emerging THIN
How broadly and deeply does the product find cryptographic assets?
Does it produce a portable, verifiable record of what was found?
Can it detect and preserve material changes over time?
Does it turn inventory into a defensible migration priority?
Is detection accuracy measured against named ground truth?
Can a finding move through ownership, action and verified closure?
Can technical and executive readers understand and reuse the result?
Evidence for every cell (JSON): URLs read, verbatim quotes and rationale · Post-review totals
Research record · reviewed 2026-09-26
Edition 2026.7 scores were fixed using the 27 September 2026 method. A 30 September check asked whether archived excerpts could be found in cited sources; a separate 1 October internal review assessed what those sources support. Neither later check changed a score, weight, rank or cohort. Original rationales, adjustments, citations and both separate checks remain visible. Read the method · Download the 1 October claim ledger.
Weight 4/19 · 1.26 points of the overall score
Internal 1 October claim review: Partial or qualified support. Primary Network Probe PDF confirms TLS/SSH/ISAKMP and parameters; archived longer protocol list and cross-surface count need further corroboration.
Read the full review record · Cell cryptonext-compass/C1. This status does not independently validate the numeric score.
1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Native discovery is the passive network probe: (a) TLS/network, (b) certificates in transit, (i) SSH/IPsec/ISAKMP, (j) OT protocols (dnp3 etc.) = 4 surfaces with 'algorithms, parameters, keys, certificates' extraction. Other sources (CLM, scanners, EDRs) are third-party feeds via API, not COMPASS discovery; PQC/hybrid detection not documented in the URLs searched.
URL availability labels below reflect the historical 30 September source-access screen.
Inspected Protocols TLS/SSL, DTLS, QUIC, SSH, ISAKMP, Kerberos, DNSSec, SMB
Original scoring anchor: 6: 3-4 surfaces
Weight 3/19 · 0.95 points of the overall score
Internal 1 October claim review: Narrow feature documented. Primary Network Probe PDF states CBOM files based on OWASP CycloneDX; PDF text extraction splits the standard name.
Read the full review record · Cell cryptonext-compass/C2. This status does not independently validate the numeric score.
1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: CycloneDX CBOM output streamed via Kafka is documented; the datasheet's 'code signing' and 'software integrity checks' refer to the appliance, not to the CBOM artifact. CBOM signing/hash chain and a public sample are not documented in the URLs searched.
URL availability labels below reflect the historical 30 September source-access screen.
The CryptoNext COMPASS Network Probe produces CBOM files, based on the OWASP CycloneDX standard, enabling easy integration with any system that supports this format.
Original scoring anchor: 6: standard-schema export documented, no integrity mechanism
Weight 3/19 · 0.79 points of the overall score
Internal 1 October claim review: Partial or qualified support. Primary PDF explicitly describes passive continuous traffic monitoring; no diff/drift reporting or alert timing shown, making midpoint discretionary.
Read the full review record · Cell cryptonext-compass/C3. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Continuous passive capture is documented (exceeds point-in-time), but diff/drift reporting, change alerts and tamper-evident change history are not documented in the URLs searched; published 8 requires drift alerts AND signed/hash-chained history.
URL availability labels below reflect the historical 30 September source-access screen.
The CryptoNext COMPASS Network Probe is a hardware appliance designed for passive and continuous network traffic monitoring, enabling the detection and collection of cryptographic assets in transit to build a comprehensive inventory.
Original scoring anchor: midpoint between 4 (point-in-time scans) and 6 (scheduled rescans with documented diff/drift reporting)
Weight 3/19 · 0.63 points of the overall score
Internal 1 October claim review: Partial or qualified support. Data sensitivity/criticality linkage is vendor-documented; formula and per-asset risk behavior are not verified.
Read the full review record · Cell cryptonext-compass/C4. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Original assessment: Detection of weak/non-compliant algorithms plus a claimed sensitivity/criticality context for prioritization; no score, categories, formula or HNDL/data-lifetime factor documented, so the claim is capped below the anchor it implies.
Final review: 5 → 4. The only documented output is a weak or non-compliant flag, which is anchor 4. The sensitivity and criticality linkage is a marketing sentence with no categories, score or mechanism. The researcher cited rubric line 19 but put the score above the cap that line sets, so it snaps to 4.
https://www.cryptonext-security.com/en/solutions-use-case-inventory-your-cryptography/ ('Quickly identify weak, obsolete, or non-compliant cryptographic algorithms'); https://www.cryptonext-security.com/en/products-cryptography-discovery-and-inventory/ ('Connect each cryptographic asset to the data it protects and its business criticality')
Read the review fileURL availability labels below reflect the historical 30 September source-access screen.
COMPASS does more than identify cryptographic assets: it links them to the data they protect, with information on sensitivity and criticality, to enable risk-based prioritization.
Original scoring anchor: midpoint between 4 (vulnerable/not flag) and 6 (categorical risk levels plus context); capped per rubric line 19
Weight 2/19 · 0.00 points of the overall score
Internal 1 October claim review: Claim not verified from accessible evidence. Zero is a bounded absence of published accuracy evidence, not measured error rate; archived no-hit search was not reproduced.
Read the full review record · Cell cryptonext-compass/C5. This status does not independently validate the numeric score.
1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Throughput ('up to 1 Gbps') and 'no packets lost' are performance claims, not detection-correctness metrics.
URL availability labels below reflect the historical 30 September source-access screen.
not documented in the URLs listed (no accuracy metric, benchmark, test methodology or false-positive handling found)
Original scoring anchor: 0: not documented
Archived search note: web search 2026-09-26: site:cryptonext-security.com COMPASS "false positive" OR accuracy OR precision OR benchmark (no vendor hits). This is not a source URL or a reproducible capability test.
Weight 2/19 · 0.42 points of the overall score
Internal 1 October claim review: Partial or qualified support. API/CMDB integration is vendor-documented; ticket creation or closure is not demonstrated, consistent with guidance-only cap.
Read the full review record · Cell cryptonext-compass/C6. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Downstream API export named; ticket creation, automated remediation or closure verification not documented in the URLs searched. CryptoNext 'Remediation' SDK is a separate product and not credited to COMPASS.
URL availability labels below reflect the historical 30 September source-access screen.
Standard APIs for easy upstream (sensors: CLM, scanners, EDRs, etc.) and downstream (platforms: CMDB, CTEM, etc.) integrations
Original scoring anchor: 4: remediation guidance only (downstream export to CMDB/CTEM named; no ticketing documented)
Weight 2/19 · 0.63 points of the overall score
Internal 1 October claim review: Partial or qualified support. Compliance reports are named; actual standards-to-finding mapping and report output are not independently examined.
Read the full review record · Cell cryptonext-compass/C7. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Dashboards, a 'personalized report generation module', REST API and CBOM/Kafka export are documented; compliance reports and DORA/NIS2/ANSSI/NIST references are named but no report content, framework mapping or sample is documented.
URL availability labels below reflect the historical 30 September source-access screen.
Use ready-made compliance reports, customize them, and respond to audits at any time.
Original scoring anchor: 6: dashboards plus exports (compliance reports named without documented mapping, capped per rubric line 19)
Documentation reviewed 2026-09-26: COMPASS (Analytics + Network Probe, GA 1 July 2025) remains marketed under the same name. New since Aug 2026: 'CryptoNext Discovery On Demand', a two-week scoped assessment service announced Paris, 10 Sept 2026 (report prioritizes weak/quantum-vulnerable assets by severity and measures DORA/NIST gaps). It is a service offering, not a COMPASS feature release, and was not credited to COMPASS cells. A brand refresh is listed (undated on page). No rename or acquisition found.
Archived product-status source · Source check: HTTP 200. The archived summary has not been independently revalidated in full.
Primary evidence is thin: one hardware datasheet (PDF, text read directly), one launch press release (PDF on vendor site; used only for concrete capability statements), and two marketing product pages. No public docs portal, GitHub repo or sample CBOM was found. The WebFetch PDF parse failed; both PDFs were downloaded by the fetch tool and read page-by-page, so datasheet quotes are verbatim. Published C3=8 is the largest unsupported cell: nothing fetched documents drift alerts or tamper-evident history. Between-anchor convention: integer midpoint, both anchors named. Third-party descriptions (encryptionconsulting.com, postquantum.com) claiming '100+ protocols' and endpoint/code-scanner correlation are inadmissible and were not credited. The 10 Sept 2026 Discovery On Demand release (read verbatim from the PDF) describes a consulting-style service report with severity prioritization and DORA gap measurement; a reviewer could argue it lifts C4/C7 if the service is treated as part of COMPASS, but the release does not name COMPASS, so it was not credited.
Original product evidence (JSON) · Final matrix and applied review changes · Edition identity and hashes