Rank 10 / Developing band / Confidence MOD

ISARA Advance

ISARA / PQC discovery capability record for edition 2026.7.

5.42Index score / 10[1]

Vendor material describes passive network discovery, endpoint and key-vault inputs, and posture scoring. S14

Developing MOD

Seven criterion scores

C18

Discovery

How broadly and deeply does the product find cryptographic assets?

C50

Correctness

Is detection accuracy measured against named ground truth?

C66

Remediation loop

Can a finding move through ownership, action and verified closure?

C77

Reporting

Can technical and executive readers understand and reuse the result?

Evidence for every cell (JSON): URLs read, verbatim quotes and rationale · Post-review totals

Research record · reviewed 2026-09-26

Evidence behind all seven scores

Edition 2026.7 scores were fixed using the 27 September 2026 method. A 30 September check asked whether archived excerpts could be found in cited sources; a separate 1 October internal review assessed what those sources support. Neither later check changed a score, weight, rank or cohort. Original rationales, adjustments, citations and both separate checks remain visible. Read the method · Download the 1 October claim ledger.

Discovery

8 / 10

Weight 4/19 · 1.68 points of the overall score

Internal 1 October claim review: Partial or qualified support. Vendor lists many surfaces broadly; independently checked detail is insufficient for exact 5-6-surface depth anchor.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: The Azure whitepaper (§5–6) documents mechanisms for passive network monitoring of TLS and SSH via vTAP and the ISARA Network Analyzer, which covers surfaces (a) and (i). It also documents Azure Key Vault (e/f), endpoint scans (g) and database encryption queries (h). Certificates (b) are covered across pages. Depth: 'Inventory algorithms, protocols, primitives, key lengths, and device information.' That is 6 surfaces. Code (c) and OT/SCADA (j) are claimed without a mechanism. PQC/hybrid detection by the product is not documented in the URLs searched; only a vendor blog checklist mentions PQC validators.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Agentless-first discovery across networks, servers, databases, code, CMDBs, KMSs, and more to map your complete cryptographic posture

Original scoring anchor: 8: 5-6 surfaces with algorithm depth; 10 not met because PQC/hybrid detection is not documented for the product

Evidence artifact

3 / 10

Weight 3/19 · 0.47 points of the overall score

Internal 1 October claim review: Partial or qualified support. Primary Azure whitepaper documents dashboards/APIs but no explicit standard/proprietary export; midpoint three is discretionary.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Dashboards, APIs and webhook integrations are documented, but no export format (CSV/PDF/JSON/CBOM) is documented in the URLs searched. I found no integrity mechanism or public sample. The vendor's own blog argues CBOMs are not essential, and I found no CBOM export claim. The 'Cryptography Validator Report' is form-gated and I did not fetch it.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Provides dashboards and APIs for remediation prioritization

Original scoring anchor: midpoint between 2 (dashboard-only) and 4 (proprietary export)

Change detection

5 / 10

Weight 3/19 · 0.79 points of the overall score

Internal 1 October claim review: Narrow feature documented. Primary Azure whitepaper documents continuous monitoring and historical trends; no tamper-evident mechanism shown.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Original assessment: Continuous monitoring, historical trend analysis and 'snapshots, trend views, and burn-down reporting' are documented. I found no drift alert mechanism, signed or hash-chained change history, or published latency. Drift detection appears only in a generic best-practice guide, not as a product mechanism.

Final review: 6 → 5. The researcher's 6 depended on change tracking. On the fetched whitepaper, the 'track changes' line sits in a generic principles list, not in the ISARA Advance capability list. What ISARA Advance itself documents is continuous monitoring plus trend and history views, with no diff or drift output. Under the rule applied to O3 and Fortanix, that is 5. The published 8 was carried_thin, and nothing restores it.

Review evidence and archived ruling

https://www.isara.com/assets/LTS/assets/partnership/ISARA-Cryptographic-Posture-Management-for-Azure-Environments-(Whitepaper).pdf (product section: 'Supports continuous monitoring and historical analysis of cryptographic trends'; 'Continuously track changes' appears only under generic 'Key Principles'); https://www.isara.com/partner-msazure.html ('snapshots, trend views, and burn-down reporting')

Read the review file
Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Supports continuous monitoring and historical analysis of cryptographic trends

Original scoring anchor: 6: continuous monitoring with documented trend/historical reporting; 8 not met because no tamper-evident history is documented

Risk quantification

7 / 10

Weight 3/19 · 1.11 points of the overall score

Internal 1 October claim review: Partial or qualified support. Primary whitepaper names algorithm strength, key size and usage context risk scores; no lifetime/HNDL or ranking formula.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: The posture score combines several factors and drives prioritized remediation. The Solutions page adds 'Risk scoring aligned to data sensitivity and exposure'. Data lifetime or HNDL is not documented as a scoring input; HNDL appears only as risk framing. No formula is published.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Assigns risk-based posture scores based on algorithm strength, key size, and usage context

Original scoring anchor: midpoint between 6 (categorical plus context) and 8 (numeric multi-factor score including data lifetime/HNDL)

Correctness

0 / 10

Weight 2/19 · 0.00 points of the overall score

Internal 1 October claim review: Claim not verified from accessible evidence. Zero is a bounded lack of public accuracy metric; source marketing claim is not a benchmark.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: This text describes the analysis method only. Accuracy metrics, false-positive handling and benchmarks are not documented in the URLs searched.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

ISARA Advance uses automated agentless scanning to discover cryptographic assets across your environment, then analyzes each asset against current standards and best practices to identify risks, misconfigurations, and vulnerabilities.

Original scoring anchor: 0: not documented

Remediation loop

6 / 10

Weight 2/19 · 0.63 points of the overall score

Internal 1 October claim review: Narrow feature documented. Vendor documents ticket workflows and CMDB integration, without closure test.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Ticketing and CMDB integration are documented ('connects with CMDBs, cloud-based KMSs, databases, and ticketing systems through built-in or webhook integrations'), along with prioritized remediation actions. I found no documented automated remediation action by the product itself. The key-rotation text in the Azure guide is generic advice. Bidirectional sync and verified closure are not documented.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Remediate vulnerabilities through ticket-based workflows and CMDB integrations.

Original scoring anchor: 6: one-way ticket/export plus guidance

Reporting

7 / 10

Weight 2/19 · 0.74 points of the overall score

Internal 1 October claim review: Partial or qualified support. Vendor executive/trend views are documented; exact framework mapping and report artifact not tested.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Separate stakeholder views are documented: executive and board, GRC and application owners, and engineers. Compliance support is claimed ('Meet cryptographic inventory and reporting requirements under NSM-10 and OMB M-23-02'; PCI-DSS, DORA, NERC CIP), but no mapping mechanism, export or sample report is documented.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Gain visibility into enterprise cryptographic risk through snapshots, trend views, and burn-down reporting that support executive decision-making.

Original scoring anchor: midpoint between 6 (dashboards plus exports) and 8 (exec and technical reports with documented compliance mapping)

Research scope, product-status record and unresolved evidence gaps

Documentation reviewed 2026-09-26: Still offered. ISARA is operating and has not wound down or been acquired. On 2026-06-30 ISARA posted a vendor press release (BusinessWire newsitemid 20260630023670) announcing an award for ISARA Advance, now positioned as the 'Autonomous Crypto Posture Management (ACPM) platform'. The product page is live, and an 'ISARA Advance on Microsoft Azure' offering now exists (partner-msazure.html). I found no vendor-documented major release after Aug 2026. A web search found no acquisition or wind-down news.

Archived product-status source · Source check: HTTP 200. The archived summary has not been independently revalidated in full.

The brief says the 2026.6 row was 'Not re-fetched this refresh; carried from 2026.4'. This is the first re-fetch. published_total is not stored in the brief. I computed it from the published cells [7,5,8,7,5,6,7] with the rubric weights. Half-point convention: a non-anchor score means the midpoint between the two named anchors. ISARA publishes no public docs portal, datasheet or release notes for Advance. The resources page lists only 2019–2020 datasheets, for Radiate and Catalyst. The most specific admissible evidence is three short (2–4 page) Azure partnership PDFs. They are largely generic best-practice text; only Whitepaper §6 and the Integration Brief §3 describe Advance specifically, and I did not credit generic advice (for example automated key rotation or drift detection) as product capability. The vendor's quantum-readiness blog maps its modules (Network Discovery, Validators, Application Discovery, Risk Prioritization, Actionability, Company-Wide Reporting) to a checklist. That mapping is a vendor self-assessment and was not used as evidence. The 2026 award is third-party recognition and inadmissible. C3 and C5 drops are rubric-systematic across all three products I scored. All quotes were checked by exact string match against fetched page or PDF text on 2026-09-26.

Original product evidence (JSON) · Final matrix and applied review changes · Edition identity and hashes