Discovery
How broadly and deeply does the product find cryptographic assets?
Rank 9 / Developing band / Confidence MOD
O3 Security / PQC discovery capability record for edition 2026.7.
Product pages describe a QBOM inventory, an algorithm-based HNDL flag and ranked migration paths. S17
Developing MOD
How broadly and deeply does the product find cryptographic assets?
Does it produce a portable, verifiable record of what was found?
Can it detect and preserve material changes over time?
Does it turn inventory into a defensible migration priority?
Is detection accuracy measured against named ground truth?
Can a finding move through ownership, action and verified closure?
Can technical and executive readers understand and reuse the result?
Evidence for every cell (JSON): URLs read, verbatim quotes and rationale · Post-review totals
Research record · reviewed 2026-09-26
Edition 2026.7 scores were fixed using the 27 September 2026 method. A 30 September check asked whether archived excerpts could be found in cited sources; a separate 1 October internal review assessed what those sources support. Neither later check changed a score, weight, rank or cohort. Original rationales, adjustments, citations and both separate checks remain visible. Read the method · Download the 1 October claim ledger.
Weight 4/19 · 1.47 points of the overall score
Internal 1 October claim review: Partial or qualified support. Vendor lists code/libraries/binaries/configurations; 5-6 surfaces and algorithm depth are not independently enumerated.
Read the full review record · Cell o3-security/C1. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: QBOM page documents code, libraries, binaries and configurations; the CBOM page's 'Complete infrastructure coverage' section adds card labels for Container Images, Live Databases, Cloud Infrastructure, Hardware Security Modules, Web Servers & Network and TLS Certificates (with illustrative counts), plus example parameter output (RSA-2048, ECC-P256, ML-KEM). No per-surface mechanism documented (docs portal login-gated); hybrid detection not documented. 10 implied, capped per rubric line 19.
URL availability labels below reflect the historical 30 September source-access screen.
Discovers every cryptographic algorithm across your source code, libraries, binaries, and configurations — then scores each one against Grover's and Shor's algorithms to determine quantum exposure.
Original scoring anchor: midpoint between 6 (3-4 surfaces) and 8 (5-6 surfaces with algorithm depth); 10 claimed but capped per rubric line 19
Weight 3/19 · 0.95 points of the overall score
Internal 1 October claim review: Claim not verified from accessible evidence. Archived generic industry-format quote does not name CycloneDX; exact standard-schema export support unverified.
Read the full review record · Cell o3-security/C2. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Sentence sits under a Standards heading followed by 'SPDX' and 'CycloneDX' labels; the CERT-In page states O3 'generates a CycloneDX CBOM'. 'Every CBOM, versioned' is versioning, not signing or hash-chaining. Signing and a public sample are not documented in the URLs searched.
URL availability labels below reflect the historical 30 September source-access screen.
Industry-standard formats accepted by regulators and supply-chain partners.
Original scoring anchor: 6: standard-schema export documented, no integrity mechanism
Weight 3/19 · 0.79 points of the overall score
Internal 1 October claim review: Partial or qualified support. Versioned CBOM is documented; scheduled re-scan/diff mechanism is not established.
Read the full review record · Cell o3-security/C3. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Per-push CI re-generation ('Automatic on every push') and versioned history are stated, exceeding manual point-in-time scans; no diff/drift report mechanism, change alerts or tamper-evident history is documented in the URLs searched.
URL availability labels below reflect the historical 30 September source-access screen.
Every CBOM, versioned. Full history of how your cryptographic posture has changed over time
Original scoring anchor: midpoint between 4 (point-in-time scans) and 6 (scheduled rescans with documented diff/drift reporting)
Weight 3/19 · 1.11 points of the overall score
Internal 1 October claim review: Partial or qualified support. Vendor urgency ranking uses break-year and attack surface; numeric score/data lifetime/weights are not shown.
Read the full review record · Cell o3-security/C4. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Break-year estimate, attack surface and an HNDL flag feed a ranked migration priority, with Critical labels and per-asset migration paths; the HNDL flag is algorithm-based and data sensitivity/lifespan appears only in a generic educational guide, not as a documented product factor. No formula published.
URL availability labels below reflect the historical 30 September source-access screen.
Ranks cryptographic assets by urgency — algorithms closest to their break-year with the widest attack surface get the highest migration priority
Original scoring anchor: midpoint between 6 (categorical risk levels plus context) and 8 (numeric score, >=2 factors incl. data lifetime/HNDL, ranked priority, formula not fully published)
Weight 2/19 · 0.00 points of the overall score
Internal 1 October claim review: Claim not verified from accessible evidence. Zero is a bounded no-metric finding; docs portal access limits prevent complete correctness review.
Read the full review record · Cell o3-security/C5. This status does not independently validate the numeric score.
1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: No correctness evidence found; public GitHub repos contain no CBOM/QBOM/PQC tooling.
URL availability labels below reflect the historical 30 September source-access screen.
not documented in the URLs listed (no accuracy metric, benchmark, test methodology or false-positive handling found; docs portal login-gated)
Original scoring anchor: 0: not documented
Archived search note: web search 2026-09-26: site:o3.security CBOM OR QBOM "false positive" OR accuracy OR precision (no hits on correctness). This is not a source URL or a reproducible capability test.
Weight 2/19 · 0.42 points of the overall score
Internal 1 October claim review: Partial or qualified support. Migration report is named, but concrete remedial step quality is not checked.
Read the full review record · Cell o3-security/C6. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: Per-asset migration paths (e.g. RSA-2048 -> ML-DSA-65, 3DES -> AES-256-GCM) are guidance; Jira appears only in the platform-wide integrations list on the homepage, with no crypto-finding ticketing, automated remediation or closure mechanism documented.
URL availability labels below reflect the historical 30 September source-access screen.
produces a CBOM and migration report in one pass
Original scoring anchor: 4: remediation guidance only
Weight 2/19 · 0.74 points of the overall score
Internal 1 October claim review: Partial or qualified support. CNSA gaps are named; actual framework-to-evidence mapping and executive report unavailable for review.
Read the full review record · Cell o3-security/C7. This status does not independently validate the numeric score.
1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.
Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.
Assessment: CNSA 2.0 gap mapping and CERT-In parameters named, migration report plus JSON/CSV/CycloneDX/SPDX exports; separate executive vs technical reports, API documentation and a public sample report are not documented in the URLs searched.
URL availability labels below reflect the historical 30 September source-access screen.
Compares your current cryptographic posture against NSA's Commercial National Security Algorithm Suite 2.0 requirements and surfaces every gap
Original scoring anchor: midpoint between 6 (dashboards plus exports) and 8 (executive and technical reports with documented compliance mapping)
Documentation reviewed 2026-09-26: Active; CBOM/QBOM sit inside a broader software-supply-chain platform (SAST, SCA, secrets, SBOM/AIBOM/HBOM/QBOM). The CBOM page is currently positioned for India BFSI/CERT-In with 'Three sovereign data centres' (Mumbai, Chennai). No rename, acquisition or dated major release found. Docs portal (docs.o3.security) redirects to a login page.
Archived product-status source · Source check: HTTP 200. The archived summary has not been independently revalidated in full.
All O3 evidence is from vendor product/marketing pages; no public technical docs, GitHub CBOM tooling or sample artifact was found, so every cell is capped by rubric line 19 (named capability without mechanism earns at most the anchor below). The academy QBOM guide describes a generic three-layer QBOM (inventory, vulnerability class, sensitivity/lifespan) and was not credited as a product capability. The brief's S17 summary (sensitivity and data lifespan in migration priority) is not supported by the current product pages. The CBOM page quotes include UI mock rows (e.g. 'RSA-2048 auth-svc / jwt Critical Deprecated YES ML-DSA-65'), which are illustrative, not customer data. Quotes were extracted via a fetch tool and requested verbatim. Between-anchor convention: integer midpoint, both anchors named. O3 C1/C2 quotes were re-checked: the CBOM page presents surfaces and formats as card/badge labels, so the cited quotes are single contiguous sentences and the labels are described in the rationale.
Original product evidence (JSON) · Final matrix and applied review changes · Edition identity and hashes