Rank 11 / Developing band / Confidence MOD

DigiCert Quantum Central

DigiCert / PQC discovery capability record for edition 2026.7.

5.37Index score / 10[1]

Quantum Central documentation describes Jira task/status exchange and policy-based verification of remediation. S18

Developing MOD

Seven criterion scores

C16

Discovery

How broadly and deeply does the product find cryptographic assets?

C54

Correctness

Is detection accuracy measured against named ground truth?

C68

Remediation loop

Can a finding move through ownership, action and verified closure?

C76

Reporting

Can technical and executive readers understand and reuse the result?

Evidence for every cell (JSON): URLs read, verbatim quotes and rationale · Post-review totals

Research record · reviewed 2026-09-26

Evidence behind all seven scores

Edition 2026.7 scores were fixed using the 27 September 2026 method. A 30 September check asked whether archived excerpts could be found in cited sources; a separate 1 October internal review assessed what those sources support. Neither later check changed a score, weight, rank or cohort. Original rationales, adjustments, citations and both separate checks remain visible. Read the method · Download the 1 October claim ledger.

Discovery

6 / 10

Weight 4/19 · 1.26 points of the overall score

Internal 1 October claim review: Partial or qualified support. Hybrid group support is documented; the single quote does not itself prove the scored number of discovery surfaces.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Documented surfaces: (a) public TLS endpoints, (b) certificates (TLM, CyberArk/Keyfactor/CSV import), (e/f) keys in Azure Key Vault/AWS KMS/Google Cloud KMS via customer-run export script; algorithm + key size/curve + ML-DSA/SLH-DSA and hybrid ML-KEM key-agreement detection documented. Only the public-endpoint scan and TLM sync are product-driven discovery; the rest is ingestion of customer-produced CSV. Applications/libraries: 'Application inventory is on the roadmap'. 3-4 surfaces -> 6.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Key agreements using X25519MLKEM768 , SecP256r1MLKEM768 , and SecP384r1MLKEM1024 are considered quantum-safe and count towards your Quantum Readiness % .

Original scoring anchor: 6: 3-4 surfaces

Evidence artifact

4 / 10

Weight 3/19 · 0.63 points of the overall score

Internal 1 October claim review: Narrow feature documented. Vendor documents export for offline use, without a standard-schema CBOM or integrity mechanism in cited material.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: CBOM export is claimed on the product page ('Export CBOMs for internal and external stakeholders', WebFetch-extracted) and GA press release, but no schema is named and none of the 32 docs pages documents a CBOM export; documented exports are dashboard/inventory data, violation records and AI-Assist CSV/PDF. Claimed anchor 6 capped at the anchor below (rubric line 19). No integrity mechanism documented.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Export dashboard and inventory data for offline review or reporting.

Original scoring anchor: 4: proprietary export only (CSV/PDF/JSON)

Change detection

5 / 10

Weight 3/19 · 0.79 points of the overall score

Internal 1 October claim review: Partial or qualified support. Vendor states imports after stale sync; automatic import is not the same as verified cryptographic diff detection.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Re-evaluation against policies on asset change and a violation lifecycle (first-detected time, closed history) exist, but sync is sign-in-triggered, endpoint scans are manual, no scheduled rescan or diff report is documented, no tamper-evident history, and Essentials retains history 1 month.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Quantum Central can automatically import newly discovered certificates and TLS endpoints from Trust Lifecycle Manager when you sign in. This automatic import runs only if asset data was last synced more than 24 hours ago.

Original scoring anchor: between 4 (point-in-time, manual) and 6 (scheduled rescans with diff/drift reporting)

Risk quantification

5 / 10

Weight 3/19 · 0.79 points of the overall score

Internal 1 October claim review: Partial or qualified support. Policy severity is documented; exact per-asset contextual risk scoring remains a rubric interpolation.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Built-in assessment is a quantum-safe true/false flag plus a Quantum Readiness %; Critical/High/Medium/Low exists only as user-assigned policy severity (Essentials allows 1 policy). No HNDL/data-lifetime factor or formula documented.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Every violation created by a policy inherits the policy’s severity. Choose the severity based on the risk represented by the condition and the expected urgency of remediation.

Original scoring anchor: between 4 (vulnerable/not-vulnerable flag) and 6 (categorical risk levels from algorithm vulnerability plus context)

Correctness

4 / 10

Weight 2/19 · 0.42 points of the overall score

Internal 1 October claim review: Narrow feature documented. Vendor documents manual handling for false positives, without a published accuracy metric.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: False-positive handling and the exact quantum-safe classification rules (subjectPublicKeyInfo, signatureAlgorithm, named key-agreement groups) are documented; no accuracy metric, benchmark or ground truth found in the 32 docs pages.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Use manual resolution for situations such as an accepted risk, a false positive, a nonessential asset, or an asset approaching retirement.

Original scoring anchor: 4: accuracy or false-positive handling described, no metric

Remediation loop

8 / 10

Weight 2/19 · 0.84 points of the overall score

Internal 1 October claim review: Partial or qualified support. Vendor describes external task status readback, but a comparative live workflow test is absent.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Outbound Jira task creation plus inbound status sync mapped to Open/In Progress/Done/Cancelled (shipped 9 Sep 2026, after the 2026.5 review), and verified closure: 'Automated indicates that Quantum Central verified that the asset passes the policy.' Caveat: 'Completing the task in the connected system does not close the violation.' Jira only; ServiceNow/GitHub 'planned'. TLM PQC certificate upgrade is a one-line Essentials-plan claim with no workflow page, not relied on.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Quantum Central retrieves the current status and maps it to a standardized state. The connected system remains the source of truth, and Quantum Central does not change the task’s status.

Original scoring anchor: 8: bidirectional integration or inbound state machine implemented and documented, but no live demonstration

Reporting

6 / 10

Weight 2/19 · 0.63 points of the overall score

Internal 1 October claim review: Narrow feature documented. Vendor documents filtered dashboard/inventory export; no stronger report behavior is inferred.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Dashboard, violation export, AI-Assist PDF/CSV reports documented. No role-specific executive/technical report, no mapping of assets to frameworks (NIST IR 8547 appears only as a timeline table and the FAQ is a resource list), and the Essentials REST API is 'Import only', so no export API.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Export the filtered records for audit or compliance review.

Original scoring anchor: 6: dashboards plus exports

Research scope, product-status record and unresolved evidence gaps

Documentation reviewed 2026-09-26: New major release: moved from preview (1 Jul 2026) to General Availability on 24 Sep 2026 as part of DigiCert ONE, launching with the Essentials subscription plan. Interim preview releases added CyberArk/Keyfactor/CSV certificate import (3 Aug), key import from Azure Key Vault/AWS KMS/Google Cloud KMS (10 Aug), and Policies/Violations/Tracking with Jira status sync (9 Sep). Not renamed, acquired or discontinued.

Archived product-status source · Source check: HTTP 200. The archived summary has not been independently revalidated in full.

Docs portal (docs.digicert.com/en/quantum-central, 32 pages enumerated from the site's toc.js) read in full as raw text on 2026-09-26; all docs quotes are verbatim from that raw text. Product-page/press-release quotes (e.g. 'Export CBOMs for internal and external stakeholders', 'Ingest and normalize data from DigiCert ONE, network scans, key vaults, SBOMs, CBOMS, and other sources') came through WebFetch, not raw HTML. The 2026.6 staging note says current docs confirm 'full PQC certificate lifecycle (issue/revoke/suspend/escrow)'; that text was not found in the current Quantum Central intro page, get-started page or release notes. Docs inconsistency: build-your-inventory says import of 'keys, endpoints, and applications is coming soon' while import-keys exists and release notes date it 10 Aug 2026. SBOM/CBOM upload is claimed on the product page and review-inventory page, but no import page for it exists in the docs TOC. Essentials plan limits: 1 policy, REST API import only, 1-month history retention. Net change: -2 on C2 (CBOM export claimed but not documented), +1 C6 (Jira status sync added 9 Sep), +1 C7. Quotes were checked against text extracted from the HTML. The extractor changed the whitespace around inline code elements, so spacing before punctuation (e.g. 'X25519MLKEM768 ,') may differ from the rendered page.

Original product evidence (JSON) · Final matrix and applied review changes · Edition identity and hashes