Rank 9 / Developing band / Confidence MOD

O3 Security

O3 Security / PQC discovery capability record for edition 2026.7.

5.47Index score / 10[1]

Product pages describe a QBOM inventory, an algorithm-based HNDL flag and ranked migration paths. S17

Developing MOD

Seven criterion scores

C17

Discovery

How broadly and deeply does the product find cryptographic assets?

C50

Correctness

Is detection accuracy measured against named ground truth?

C64

Remediation loop

Can a finding move through ownership, action and verified closure?

C77

Reporting

Can technical and executive readers understand and reuse the result?

Evidence for every cell (JSON): URLs read, verbatim quotes and rationale · Post-review totals

Research record · reviewed 2026-09-26

Evidence behind all seven scores

Edition 2026.7 scores were fixed using the 27 September 2026 method. A 30 September check asked whether archived excerpts could be found in cited sources; a separate 1 October internal review assessed what those sources support. Neither later check changed a score, weight, rank or cohort. Original rationales, adjustments, citations and both separate checks remain visible. Read the method · Download the 1 October claim ledger.

Discovery

7 / 10

Weight 4/19 · 1.47 points of the overall score

Internal 1 October claim review: Partial or qualified support. Vendor lists code/libraries/binaries/configurations; 5-6 surfaces and algorithm depth are not independently enumerated.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: QBOM page documents code, libraries, binaries and configurations; the CBOM page's 'Complete infrastructure coverage' section adds card labels for Container Images, Live Databases, Cloud Infrastructure, Hardware Security Modules, Web Servers & Network and TLS Certificates (with illustrative counts), plus example parameter output (RSA-2048, ECC-P256, ML-KEM). No per-surface mechanism documented (docs portal login-gated); hybrid detection not documented. 10 implied, capped per rubric line 19.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Discovers every cryptographic algorithm across your source code, libraries, binaries, and configurations — then scores each one against Grover's and Shor's algorithms to determine quantum exposure.

Original scoring anchor: midpoint between 6 (3-4 surfaces) and 8 (5-6 surfaces with algorithm depth); 10 claimed but capped per rubric line 19

Evidence artifact

6 / 10

Weight 3/19 · 0.95 points of the overall score

Internal 1 October claim review: Claim not verified from accessible evidence. Archived generic industry-format quote does not name CycloneDX; exact standard-schema export support unverified.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Sentence sits under a Standards heading followed by 'SPDX' and 'CycloneDX' labels; the CERT-In page states O3 'generates a CycloneDX CBOM'. 'Every CBOM, versioned' is versioning, not signing or hash-chaining. Signing and a public sample are not documented in the URLs searched.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Industry-standard formats accepted by regulators and supply-chain partners.

Original scoring anchor: 6: standard-schema export documented, no integrity mechanism

Change detection

5 / 10

Weight 3/19 · 0.79 points of the overall score

Internal 1 October claim review: Partial or qualified support. Versioned CBOM is documented; scheduled re-scan/diff mechanism is not established.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Per-push CI re-generation ('Automatic on every push') and versioned history are stated, exceeding manual point-in-time scans; no diff/drift report mechanism, change alerts or tamper-evident history is documented in the URLs searched.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Every CBOM, versioned. Full history of how your cryptographic posture has changed over time

Original scoring anchor: midpoint between 4 (point-in-time scans) and 6 (scheduled rescans with documented diff/drift reporting)

Risk quantification

7 / 10

Weight 3/19 · 1.11 points of the overall score

Internal 1 October claim review: Partial or qualified support. Vendor urgency ranking uses break-year and attack surface; numeric score/data lifetime/weights are not shown.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Break-year estimate, attack surface and an HNDL flag feed a ranked migration priority, with Critical labels and per-asset migration paths; the HNDL flag is algorithm-based and data sensitivity/lifespan appears only in a generic educational guide, not as a documented product factor. No formula published.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Ranks cryptographic assets by urgency — algorithms closest to their break-year with the widest attack surface get the highest migration priority

Original scoring anchor: midpoint between 6 (categorical risk levels plus context) and 8 (numeric score, >=2 factors incl. data lifetime/HNDL, ranked priority, formula not fully published)

Correctness

0 / 10

Weight 2/19 · 0.00 points of the overall score

Internal 1 October claim review: Claim not verified from accessible evidence. Zero is a bounded no-metric finding; docs portal access limits prevent complete correctness review.

1 October source-text check: Cited page accessible; excerpt not reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Source accessible; archived excerpt not reproduced. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: No correctness evidence found; public GitHub repos contain no CBOM/QBOM/PQC tooling.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

not documented in the URLs listed (no accuracy metric, benchmark, test methodology or false-positive handling found; docs portal login-gated)

Original scoring anchor: 0: not documented

Remediation loop

4 / 10

Weight 2/19 · 0.42 points of the overall score

Internal 1 October claim review: Partial or qualified support. Migration report is named, but concrete remedial step quality is not checked.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Per-asset migration paths (e.g. RSA-2048 -> ML-DSA-65, 3DES -> AES-256-GCM) are guidance; Jira appears only in the platform-wide integrations list on the homepage, with no crypto-finding ticketing, automated remediation or closure mechanism documented.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

produces a CBOM and migration report in one pass

Original scoring anchor: 4: remediation guidance only

Reporting

7 / 10

Weight 2/19 · 0.74 points of the overall score

Internal 1 October claim review: Partial or qualified support. CNSA gaps are named; actual framework-to-evidence mapping and executive report unavailable for review.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: CNSA 2.0 gap mapping and CERT-In parameters named, migration report plus JSON/CSV/CycloneDX/SPDX exports; separate executive vs technical reports, API documentation and a public sample report are not documented in the URLs searched.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Compares your current cryptographic posture against NSA's Commercial National Security Algorithm Suite 2.0 requirements and surfaces every gap

Original scoring anchor: midpoint between 6 (dashboards plus exports) and 8 (executive and technical reports with documented compliance mapping)

Research scope, product-status record and unresolved evidence gaps

Documentation reviewed 2026-09-26: Active; CBOM/QBOM sit inside a broader software-supply-chain platform (SAST, SCA, secrets, SBOM/AIBOM/HBOM/QBOM). The CBOM page is currently positioned for India BFSI/CERT-In with 'Three sovereign data centres' (Mumbai, Chennai). No rename, acquisition or dated major release found. Docs portal (docs.o3.security) redirects to a login page.

Archived product-status source · Source check: HTTP 200. The archived summary has not been independently revalidated in full.

All O3 evidence is from vendor product/marketing pages; no public technical docs, GitHub CBOM tooling or sample artifact was found, so every cell is capped by rubric line 19 (named capability without mechanism earns at most the anchor below). The academy QBOM guide describes a generic three-layer QBOM (inventory, vulnerability class, sensitivity/lifespan) and was not credited as a product capability. The brief's S17 summary (sensitivity and data lifespan in migration priority) is not supported by the current product pages. The CBOM page quotes include UI mock rows (e.g. 'RSA-2048 auth-svc / jwt Critical Deprecated YES ML-DSA-65'), which are illustrative, not customer data. Quotes were extracted via a fetch tool and requested verbatim. Between-anchor convention: integer midpoint, both anchors named. O3 C1/C2 quotes were re-checked: the CBOM page presents surfaces and formats as card/badge labels, so the cited quotes are single contiguous sentences and the labels are described in the rationale.

Original product evidence (JSON) · Final matrix and applied review changes · Edition identity and hashes