Rank 8 / Developing band / Confidence MOD

IBM Guardium + Quantum Safe

IBM / PQC discovery capability record for edition 2026.7.

5.58Index score / 10[1]

IBM Research contributed to CycloneDX CBOM; its separate Cryptoscope study reports measured accuracy, not validation of this scored Guardium + Quantum Safe product. S09S10S26

Developing MOD

Seven criterion scores

C18

Discovery

How broadly and deeply does the product find cryptographic assets?

C50

Correctness

Is detection accuracy measured against named ground truth?

C67

Remediation loop

Can a finding move through ownership, action and verified closure?

C76

Reporting

Can technical and executive readers understand and reuse the result?

Evidence for every cell (JSON): URLs read, verbatim quotes and rationale · Post-review totals

Research record · reviewed 2026-09-26

Evidence behind all seven scores

Edition 2026.7 scores were fixed using the 27 September 2026 method. A 30 September check asked whether archived excerpts could be found in cited sources; a separate 1 October internal review assessed what those sources support. Neither later check changed a score, weight, rank or cohort. Original rationales, adjustments, citations and both separate checks remain visible. Read the method · Download the 1 October claim ledger.

Discovery

8 / 10

Weight 4/19 · 1.68 points of the overall score

Internal 1 October claim review: Partial or qualified support. IBM lists source-code languages; the 5-6-surface count relies on additional product documents and no common runtime test.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Documented surfaces: (a) network scan of certificates, keys, ciphers and protocols; (b) PKI through Vault PKI and CA plug-ins (ADCS, DigiCert, Sectigo, Venafi); (c) source code through QSE; (e/f) cloud KMS and vaults through AWS, Azure, GCP, Akeyless and HashiCorp plug-ins; (j) mainframe through the IBM zCDI plug-in; plus Kubernetes secrets. The object model records key algorithm, key size and algorithm parameters. The PQC policy names Kyber, Dilithium, FALCON and SPHINCS+. Hybrid-algorithm detection is not documented, and depth is not shown for each plug-in surface, so the score stays at 8.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Quantum Safe™ Explorer supports scanning of source code that is written in Java, C, C++, C#, Python, Dart, Go, Kotlin, JavaScript and Typescript (Node.js).

Original scoring anchor: 8: 5-6 surfaces with algorithm depth (10 not reached: hybrid detection not documented)

Evidence artifact

6 / 10

Weight 3/19 · 0.95 points of the overall score

Internal 1 October claim review: Narrow feature documented. IBM documentation describes CBOM/CSV/Findings.JSON output; no signature/integrity method cited.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: CBOM export is documented. Signing, hashing or any integrity mechanism for the CBOM is not documented in the QSE overview, the CBOMkit blog, the cbomkit GitHub README or the GCM docs index. IBM authored the CBOM standard, but authorship is not an integrity mechanism. The published 8.5 had no integrity evidence behind it.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Scanning generates cryptographic inventory reports in various formats, including a Cryptography Bill of Materials (CBOM), .CSV files, and Findings.JSON.

Original scoring anchor: 6: standard-schema export documented, no integrity mechanism

Change detection

4 / 10

Weight 3/19 · 0.63 points of the overall score

Internal 1 October claim review: Partial or qualified support. Vendor alert/policy wording does not establish crypto-level drift history; final point-in-time cap is conservative.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: GCM discovery profiles can be scheduled, and each scan gets a Run ID and a scan timeline. Diff or drift reporting between scans, change alerts and tamper-evident history are not documented in the GCM managing-discovery page, the GQS overview or the GQS getting-started page. The generic 'alerting mechanisms' line has no mechanism behind it. The published 7 had no change-detection evidence.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

It enables in-depth analysis of associated risks and vulnerabilities, offers robust policy enforcement, and alerting mechanisms to effectively manage cryptographic assets.

Original scoring anchor: 4: point-in-time scans (scheduled discovery documented; diff/drift reporting not documented)

Risk quantification

6 / 10

Weight 3/19 · 0.95 points of the overall score

Internal 1 October claim review: Partial or qualified support. Verified-TLS IBM product documentation reproduces CVSS-style PQC violation wording, but asset-score calibration and current product-suite attribution remain untested.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Assets are classified PQC Safe or PQC Unsafe, with CVSS-style impact scores and an 'Exploitability Score'. Data lifetime, HNDL or Mosca factors are not documented. The product page mentions 'customized risk metrics', but no formula is given.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Built-in policies automatically detect risky assets and generate PQC violations, which include CVSS-style based on CVSS impact scores, to prioritize remediation efforts.

Original scoring anchor: 6: categorical risk levels from algorithm vulnerability plus some context

Correctness

0 / 10

Weight 2/19 · 0.00 points of the overall score

Internal 1 October claim review: Partial or qualified support. Final zero correctly excludes a CBOMkit benchmark not tied to Guardium/Quantum Safe; absence of IBM-specific metric is bounded.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Original assessment: Paper: Näther (XITASO GmbH) and Hirsch (University of Applied Sciences Amberg-Weiden), 'Hidden Ciphers and Where to Find Them', arXiv 2608.04857v1, 5 Aug 2026. The arXiv Comments field says 'accepted at ICICS 2026' (byte-verified). It tests CBOMkit-hyperion (PQCA sonar-cryptography v1.6.1) on 70 Go-invocation occurrences: TP 38, FP 7, FN 32, giving P 0.84, R 0.54, F1 0.66. Ground truth is the synthetic Cryben corpus with a CycloneDX 1.7 CBOM, built by the authors of the competing tool Crypsy. It is independent of CBOMkit, but no dual annotation is stated. Because n<100, anchor 6 is the ceiling.

Final review: 6 → 0. The re-score says the CBOMkit footing is 'consistent with C1 and C2', but that does not hold: the C1 rationale uses no CBOMkit evidence, and the C2 quote comes from the QSE overview (the cbomkit README adds nothing). CBOMkit therefore carries weight in C5 only. The metric measures an Apache-2.0 community tool that the paper credits to PQCA and that is now governed outside IBM. No IBM product doc (GQS 3.x, GCM 2.0.x, QSE 2.x) says it uses that engine. No metric or false-positive handling was found in the Guardium/QSE docs searched, so anchor 0 applies. What would restore 6 (and only 6, because n=70 < 100 and there is no dual annotation): an IBM doc stating that GQS, GCM or QSE uses the sonar-cryptography/CBOMkit-hyperion engine. Row total falls 6.21 -> 5.58 (106/19). Anchor 8, which the published 15 Aug correction used, fails on every axis whatever the scope.

Review evidence and archived ruling

arXiv 2608.04857v1 HTML: 'we ran CBOMkit-hyperion (the PQCA sonar-cryptography plugin, v1.6.1) on the Go-invocation subset of Cryben'; Table 2 'All Go CBOMkit 70 38 7 32 0.84 0.54 0.66'. The paper contains zero occurrences of 'IBM' or 'Guardium'. github.com/IBM/sonar-cryptography and github.com/IBM/cbomkit return 301 to github.com/cbomkit/*; GitHub API: cbomkit/cbomkit license Apache-2.0, owner 'cbomkit'. research.ibm.com/blog/quantum-safe-cbomkit: 'IBM Research has developed and open-sourced CBOMkit' and 'IBM is donating its CBOM toolset to the Linux Foundation'; the blog links CBOMkit to no Guardium, GCM or QSE product. The QSE 2.x overview (WebFetch) mentions no sonar-cryptography, CBOMkit, hyperion or SonarQube, and has no accuracy, precision, recall or false-positive statement. A web search for Guardium Cryptography Manager / Guardium Quantum Safe together with CBOMkit / sonar-cryptography returned no link. A third party, QCecuring's import docs (docs.qcecuring.com/cbom/platform/import-export), lists 'cbomkit-theia — IBM's open-source CBOM scanner' and 'IBM Quantum Safe Explorer' as SEPARATE sources.

Read the review file
Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

On the full Go-invocation ground truth Crypsy reaches F1 = 0.92 (P = 0.95, R = 0.89) versus 0.66 for CBOMkit (P = 0.84, R = 0.54)

Original scoring anchor: 6: a published benchmark metric, but n<100 (70 Go-invocation occurrences) and ground truth not dual-annotated. Footing: the CBOMkit toolchain is treated as in-row, consistent with the brief's S10 and with the C1 and C2 scoping.

Remediation loop

7 / 10

Weight 2/19 · 0.74 points of the overall score

Internal 1 October claim review: Partial or qualified support. Jira/ServiceNow ticket creation is documented; automated remediation action beyond a ticket is not tested.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Tickets go one way to Jira or ServiceNow, and the status is explicitly tracked in the external system. The product page states 'Automate key generation and certificate renewal'. AI-prefilled remediation fields are documented. Bidirectional sync and rescan-verified closure are not documented.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

For the tickets that are created in JIRA and ServiceNow, you need to track the ticket status in those particular applications.

Original scoring anchor: 7: one-way ticket creation plus automated remediation actions

Reporting

6 / 10

Weight 2/19 · 0.63 points of the overall score

Internal 1 October claim review: Narrow feature documented. IBM documents PDF dashboard export, no stronger report claim inferred.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Documented: a posture dashboard with PDF export, CSV/Excel export of violations, a Swagger API, and 'audit-ready reports'. The only framework referenced is generic NIST quantum-safe alignment. Separate executive and technical reports, and mappings to CNSA 2.0, NIST IR 8547 or OMB, are not documented.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Export: You can export the dashboard in PDF format.

Original scoring anchor: 6: dashboards plus exports

Research scope, product-status record and unresolved evidence gaps

Documentation reviewed 2026-09-26: Consolidating, not discontinued. https://www.ibm.com/products/guardium-quantum-safe now returns HTTP 301 to https://www.ibm.com/products/guardium-cryptography-manager (verified with curl on 2026-09-26). Guardium Quantum Safe docs are still live under Guardium Data Security Center 3.x, which says: 'As of 31 July 2025, Guardium Quantum Safe has a standalone installation and delivery path'. Guardium Cryptography Manager (GCM) 2.0 has 'General Availability 26-Nov-2025' (https://www.ibm.com/support/pages/ibm-guardium-cryptography-manager20, curl-verified). The 2.0.1 release (Mar 2026) is known only from web search, and the GCM docs index lists version 2.0.3.0 per WebFetch. GCM ingests IBM Quantum Safe Explorer (QSE) findings and CBOMs. No new major release since Aug 2026 was found.

Archived product-status source · Source check: HTTP 200. The archived summary has not been independently revalidated in full.

SCOPE: this row mixes three IBM offerings. Guardium Quantum Safe (GDSC 3.x docs, standalone since 31 Jul 2025), Guardium Cryptography Manager 2.0.x (the destination of the 301 from the GQS product page) and Quantum Safe Explorer 2.x (the source-code scanner that feeds both). The GCM plug-ins (cloud KMS, CAs, zCDI mainframe) are credited to this row because IBM now redirects GQS to GCM. A reviewer who limits the row to GQS 3.x would score C1 lower. QUOTE VERIFICATION: the IBM docs quotes were extracted through WebFetch and are not byte-verified, because IBM docs block curl and the Wayback copy is a JavaScript shell. The GQS 3.x 'alerting mechanisms' quote WAS byte-verified against the Wayback snapshot of 20250809. The C4 quote contains IBM's own grammatical error ('CVSS-style based on CVSS impact scores'). A second WebFetch returned the same text. The arXiv quote and the Table 2 counts were byte-verified from the arXiv HTML fetched on the research host. C5 ORIGIN: the 15 Aug C5=8 rested on this paper. The paper benchmarks CBOMkit-hyperion, not a Guardium product, uses only n=70 for that tool, and is single-sourced for ground truth, so anchor 8 is not supported. FOOTING: C5=6 treats the IBM-originated CBOMkit toolchain as part of this row, as the brief's S10 does and as C1 and C2 do. No IBM doc was found saying GQS, GCM or QSE uses the sonar-cryptography engine. If a reviewer excludes CBOMkit from the row, C5 falls to 0, because no metric or false-positive handling was found in the GQS, GCM or QSE docs, and the total falls to 5.58. A first WebFetch summary of the arXiv abstract wrongly said the paper had no tool comparison; the raw full text corrected that. CBOMkit's recall of 0.54 on this corpus is unflattering, but the anchors score whether a metric exists, not how good it is. The published C2=8.5 and C3=7 had no documented integrity or change-history mechanism behind them. PUBLISHED_TOTAL: the brief gives no total, so 7.39 is recomputed from published_cells with the rubric formula.

Original product evidence (JSON) · Final matrix and applied review changes · Edition identity and hashes