Rank 12 / Developing band / Confidence MOD

QuSecure QuProtect R3

QuSecure / PQC discovery capability record for edition 2026.7.

5.21Index score / 10[1]

Vendor pages document passive live-network sensors, continuous inventory and policy-driven remediation. S13

Developing MOD

Seven criterion scores

C14

Discovery

How broadly and deeply does the product find cryptographic assets?

C50

Correctness

Is detection accuracy measured against named ground truth?

C66.5

Remediation loop

Can a finding move through ownership, action and verified closure?

C78

Reporting

Can technical and executive readers understand and reuse the result?

Evidence for every cell (JSON): URLs read, verbatim quotes and rationale · Post-review totals

Research record · reviewed 2026-09-26

Evidence behind all seven scores

Edition 2026.7 scores were fixed using the 27 September 2026 method. A 30 September check asked whether archived excerpts could be found in cited sources; a separate 1 October internal review assessed what those sources support. Neither later check changed a score, weight, rank or cohort. Original rationales, adjustments, citations and both separate checks remain visible. Read the method · Download the 1 October claim ledger.

Discovery

4 / 10

Weight 4/19 · 0.84 points of the overall score

Internal 1 October claim review: Partial or qualified support. Reconnaissance documents network-negotiated algorithms/certs; exact one-to-two surface boundary is a rubric judgment.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: The documented mechanism is passive sensors on live network traffic. They read TLS versions, key exchange, signatures, ciphers, certificates, key sizes and JA3/JA4 fingerprints, and detect PQC ('Algorithm-level detection (RSA, ECC, PQC) plus key sizes'). That covers surfaces (a) and (b). The older discovery page claims 'Routers, servers, endpoints, applications, cloud, and network infrastructure'. It names no mechanism beyond network observation, and the Recon page contrasts itself with source-code scanning. I found no documented discovery of code, binaries, HSM/KMS, cloud KMS, host configuration, SSH or IPsec. IPsec appears only as an encryptor protocol.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

QuProtect Reconnaissance builds a live inventory of the algorithms, protocols, certificates and key sizes your systems negotiate.

Original scoring anchor: 4: 1-2 surfaces (network/TLS, certificates on the wire), with algorithm, key-size and PQC depth

Evidence artifact

6 / 10

Weight 3/19 · 0.95 points of the overall score

Internal 1 October claim review: Narrow feature documented. Vendor documents CycloneDX 1.6 CBOM export from live inventory; exported bytes were not tested.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: A CycloneDX v1.6 CBOM export is documented. I found no signature, hash chain, public sample or verification procedure on the fetched pages.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

QuProtect Reporting generates a CycloneDX v1.6 cryptographic bill of materials from the live inventory the sensors build, on demand and in machine-readable form.

Original scoring anchor: 6: standard-schema export documented, no integrity mechanism

Change detection

6 / 10

Weight 3/19 · 0.95 points of the overall score

Internal 1 October claim review: Partial or qualified support. Continuous traffic inventory is documented, but explicit cryptographic diff and tamper history are absent.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: The inventory is continuous. Reports show 'What is in and out of policy, and what changed', and the Recon page says configuration drift is found. I found no drift alert mechanism, signed or hash-chained change history, or published detection latency.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Reports generate on demand from the inventory, which updates continuously from live traffic.

Original scoring anchor: 6: continuous inventory with documented change reporting; 8 not met because no tamper-evident history is documented

Risk quantification

6 / 10

Weight 3/19 · 0.95 points of the overall score

Internal 1 October claim review: Partial or qualified support. Exposure-based risk ordering is documented; model and calibration not supplied.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Findings are ranked by exposure. I found no numeric score, no documented data-lifetime or HNDL factor, and no formula. The Resilience page names HNDL only as a finding class to remediate, not as a scoring input.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Find where legacy cryptography is still in use, on live network traffic, ranked by exposure rather than by count.

Original scoring anchor: 6: categorical/ranked risk from algorithm vulnerability plus exposure context

Correctness

0 / 10

Weight 2/19 · 0.00 points of the overall score

Internal 1 October claim review: Claim not verified from accessible evidence. Vendor says always accurate but provides no benchmark; zero means not documented under rubric, not measured inaccuracy.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: The fetched pages give accuracy only as an adjective. Accuracy metrics, false-positive handling and benchmarks are not documented in the URLs searched. The Recon page gives a design argument that wire observation beats code scanning ('Source code tells you what an application might negotiate.'). That is a rationale, not an accuracy-handling mechanism or a metric. The Army TRL-7 item is third-party news or certification and is inadmissible.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

The inventory is always accurate, and your compliance posture is always current.

Original scoring anchor: 0: not documented

Remediation loop

6.5 / 10

Weight 2/19 · 0.68 points of the overall score

Internal 1 October claim review: Partial or qualified support. Orchestrator action is an adjacent network control and inventory refresh; no cross-product peer run verifies closure.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: Automated remediation is strongly documented: policy-driven algorithm change and automated certificate provisioning and rotation. Closure is recorded in the next export ('The finding, the policy change, the result'). Ticket creation is not documented. The only outbound integration named is 'Integrations: select vulnerability scanners, SIEM and SOAR', so anchor 7's ticket leg is unmet.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

An administrator sets a policy in the Orchestrator. Encryptors carry the connection over post-quantum TLS 1.3 at the network layer, with no application code change, and the inventory records the fix in the next CBOM export.

Original scoring anchor: midpoint between 6 (one-way export plus guidance) and 7 (one-way ticket creation plus automated remediation)

Reporting

8 / 10

Weight 2/19 · 0.84 points of the overall score

Internal 1 October claim review: Partial or qualified support. Human/machine report outputs are documented; compliance mapping detail needs direct report review.

1 October source-text check: Archived excerpt reproduced. Checked 2026-10-01; text access does not independently validate the numeric score or complete rationale.

Historical 30 September source-access check

Archived excerpt reproduced in a cited source. Checked 2026-09-30; this older access state remains separate from the 1 October source-text and claim review.

Assessment: The Reporting page has a mapping table ('Mapped to the instruments you answer to') covering OMB M-26-15, EO 14412, CNSA 2.0, NIST IR 8547, PCI DSS 4.0 12.3.3 and DORA. It names board/executive reporting ('Visibility into cryptographic posture for risk committees and executives') and per-connection technical detail. I found no published sample report, so 10 is not reached.

Cited sources and original archived excerpt

URL availability labels below reflect the historical 30 September source-access screen.

Reports export on demand in machine-readable and human-readable form, covering the cryptography in use, the policy in force and the record of changes

Original scoring anchor: 8: executive and technical reporting with documented compliance mapping

Research scope, product-status record and unresolved evidence gaps

Documentation reviewed 2026-09-26: Still offered. It has not been renamed, acquired or discontinued. QuProtect R3 remains the current product; I found no R4 or successor. The site now presents R3 as three pillars: Recon (discovery), Resilience (policy-driven remediation) and Reporting (CycloneDX CBOM). The Reporting page maps output to mandates issued in June 2026 (EO 14412, OMB M-26-15). The vendor-site footer reads '© 2026 QuSecure, Inc.'

Archived product-status source · Source check: HTTP 200. The archived summary has not been independently revalidated in full.

published_total is not stored in the brief. I computed it from the published cells [6,6,8,6,6,6,8] with the rubric weights. Half-point convention: 6.5 is the midpoint between the named anchors. QuSecure publishes no public docs portal or datasheet that I could find; all evidence is from vendor product pages on qusecure.com, which are unusually specific (algorithms, protocols, CycloneDX version, mandate table). C6: the rubric is ticket-centric. QuSecure documents actual automated remediation with closure recorded in the next export, which is arguably stronger in substance than ticketing, but the rubric's ticket leg is not documented. A reviewer who treats SOAR integration as ticket creation would score 7. C5 was published at 6, but I found no methodology, metric or FP-handling description on any fetched page. C3 dropped for the same reason as for the other products: continuous monitoring is documented, tamper-evident history is not. These C3/C5 drops are rubric-systematic across all three products I scored. All quotes were checked by exact string match against the fetched page text on 2026-09-26.

Original product evidence (JSON) · Final matrix and applied review changes · Edition identity and hashes