No more typing reviews! Try our Samantha, our new voice AI agent.

Amazon Inspector vs RSA Archer comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 1, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Amazon Inspector
Ranking in IT Vendor Risk Management
7th
Average Rating
8.2
Reviews Sentiment
6.3
Number of Reviews
9
Ranking in other categories
Vulnerability Management (26th)
RSA Archer
Ranking in IT Vendor Risk Management
5th
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
42
Ranking in other categories
GRC (1st), IT Governance (1st)
 

Mindshare comparison

As of August 2026, in the IT Vendor Risk Management category, the mindshare of Amazon Inspector is 1.4%, up from 0.9% compared to the previous year. The mindshare of RSA Archer is 7.8%, down from 11.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Vendor Risk Management Mindshare Distribution
ProductMindshare (%)
RSA Archer7.8%
Amazon Inspector1.4%
Other90.8%
IT Vendor Risk Management
 

Featured Reviews

Abdalla Kenawy - PeerSpot reviewer
AWS DevOps SRE/Infrastructure Engineer at Capgemini
Automated insights streamline data security assessment
For Amazon Inspector, we have many EC2 or virtual machines deployed inside our AWS environment, and the problem is that the existing package deployed inside this EC2 instance has already outdated packages. As we progress with time, this package needs to be updated for security enhancement, which requires us to uninstall the package, install the new version, and then we should be fine. However, the challenge comes with how to scan all our EC2 instances for security vulnerabilities, which is currently managed by Amazon Inspector. Amazon Inspector can scan EC2 instances or ECR, which is the ECR registry where we can save artifacts Docker images. Amazon Inspector can also scan Docker images uploaded to ECR for Elastic Registry service, and it can scan databases and S3 based on the latest updates. I noticed this from a couple of months ago, and it provides huge benefits for security. Regarding the best features of Amazon Inspector, it gives us a list of all existing outdated packages as part of a deployed package on EC2 instances or specific Python packages that are part of the Docker file and the Docker image itself, which are causing security concerns. Amazon Inspector can list these security concerns and offer guidance on how we can remediate it by updating the package to a specific upper version or something similar.
CJ
Information Security Specialist at Dubai Health Authority
Centralized management strengthens compliance with good look and feel
From my perspective as a customer and end user, Archer has an impressive look and feel, but the most adaptive feature is its ease of configuration which helps to enhance our process according to our maturity. It's more about our organization getting centralized with an integrated approach that focuses on risk governance and compliance. When can provide a detailed dashboards to management with the details of risks from top-down or bottom-up prioritizing actions based on its criticality or necessity. This allows us to show end users and management where the issues lie and effectively demonstrate accountability and visibility in compliance.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The findings dashboards are neat and easy to understand, offering clear demarcations for different types of findings and detailed insights into specific vulnerabilities and their associated instances. It is not a place where everything is dumped together. It offers an easy-to-understand layout."
"I recommend Amazon Inspector because it allows the automation of processes and requires less manual monitoring."
"The integration of Amazon Inspector with other AWS services has enhanced our security. Security Hub is a major asset because it allows us to centralize data from various AWS services. We can integrate third-party tools as well. It is just a single-click option."
"The scalability of the solution itself is unparalleled."
"My experience with AWS technical support is very good, I didn't face any specific challenges, and even the documentation of AWS is good for both Microsoft, which is Azure, and AWS."
"The automated vulnerability detection aspect is most valuable."
"The vulnerability discovery is valuable, and they also rank those vulnerabilities for you. So, you could rapidly attack some of the higher, severe vulnerabilities as they pop up, if they do pop up."
"It is scanning the whole repository for any sort of vulnerabilities, so it allows us to be more confident in our DevSecOps and not put a lot of folks or attention to it."
"It's an increasingly mature and very secure tool in the market."
"This solution helped us with the centralization of our governance data, so we could house all of our controls in one place. We could use that central repository of all our controls to build our risk management strategy and our policy and governance. So we could use controls as a central library and build policy, and then build risk management around it."
"This is a good solution compared to others in the market because it is more secure."
"RSA is a very rich application. I like its adaptive suggestion, where based on your users and the class of data, it can actually recommend you the proper control to choose. For example, we have been using PCI DSS as an NIST. So based on application feedback, it will provide you with a suggestion on which control objective needs to be set. Based on that, you can make a decision—you don't need to take the suggestion, but you can customize that particular provided suggestion. RSA Archer's workflow is also good, in terms of process automation."
"The part I liked about Archer was the risk assessment for deficiencies and being able to use it there."
"RSA Archer's best features are advanced workflow, reports, dashboards, and notifications."
"One of the useful features is the ability to connect to various systems in order to accommodate data."
"Archer seamlessly integrates data systems without requiring additional software."
 

Cons

"There is room for improvement in the scanning capabilities. I'd like to see broader coverage in terms of the vulnerabilities detected."
"One major area for improvement is remediation. My team works on remediating findings over time, likely using available patches. However, easier integration with Amazon's patching services would be very helpful."
"There isn't too much to improve right now. Scanning on demand or as a part of the pipeline versus a post pipeline solution would be good, but it is not a deal breaker by any means."
"It has a limited scope. So, AWS Inspector primarily focuses on the security of the EC2 instance. So, if your architecture includes other AWS services, then you may need to use additional tools for your comprehensive security assessment. So that is one con. Another is, like, we have a dependency on agents."
"It has automated vulnerability assessment, yet I seek more flexibility in defining custom vulnerability checks tailored to my needs, which is more difficult."
"There are challenges associated with the interdependencies in AWS services, like requiring an Active Directory for other services, resulting in additional charges."
"The most challenging aspect I faced with Amazon Inspector during integration was automating the remediation process."
"The false positive rate of Amazon Inspector is a little high, and it is not covering all different applications and scanning."
"RSA Archer's technical support is a little disappointing because the first level is always manned by junior members who don't have much technical expertise."
"A remaining area for improvement is integration. There should be built-in integration mechanisms, for example, for organizations switching from platforms like ServiceNow to Archer, instead of custom integrations for each client."
"If I were to rate RSA technical support on a scale from one to ten, I would give it about four, as there is definitely room for improvement, but support is available."
"Solution could use more inbuilt applications."
"GUI could be improved."
"The tech support team's turnaround time is often slow."
"Because I have not upgraded, the graphical user interface is not the current one. It is not very modern and as user-friendly as it could be."
"We evaluated Archer but at the time its poor support for Basel (e.g. cap allocation) was a deal stopper for us."
 

Pricing and Cost Advice

"The lowest cost would be around $10 for a few small accounts, however, for thousands of accounts, it could be around $5000 to $6000 dollars per month."
"The pricing is very transparent and clear."
"It is scaled as you go. There are probably a certain number of scans per month, and there are tiers. If you're under a certain tier, it is free. The second level is pennies, and then all the way up to like a million. So, it has a tiered pricing program. They're pretty good with your initial scanning, and there is room to scale based on being affordable, but it is fairly cheap. There are no additional costs. They pretty much think about it as a pay-per-scan type model."
"It's priced according to market standards for its services."
"As I am a developer and responsible for providing production support, I do not have personal knowledge of the pricing. However, my colleagues claim that it is very expensive in comparison with other tools."
"The price of RSA Archer is good. The price isn't too high considering it is a leading tool in the market."
"Fairly highly-priced, especially for smaller companies."
"I am not 100% familiar with that, especially with their new model. I just know that the way they've licensed per user to scale is good."
"The solution's price should be reduced. You only have to pay the license and there are no additional fees."
"At the higher end of the price scale, but provides better, more accessible functionality and customization than cheaper products."
"The license is costly for the solution, but the remaining set up and maintenance is quite cheaper."
"The price of the solution is very affordable."
report
Use our free recommendation engine to learn which IT Vendor Risk Management solutions are best for your needs.
908,800 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Computer Software Company
7%
Comms Service Provider
7%
Government
7%
Financial Services Firm
18%
Insurance Company
10%
Manufacturing Company
7%
Construction Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise2
Large Enterprise6
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise6
Large Enterprise25
 

Questions from the Community

What is your experience regarding pricing and costs for Amazon Inspector?
I am not honestly sure about the pricing side of Amazon Inspector, but that is taken care of by a separate team. I believe it's cheaper than the other third-party solutions.
What needs improvement with Amazon Inspector?
They might launch support for third-party environments in the next version regarding the best features in Amazon Inspector from my perspective. The false positive rate of Amazon Inspector is a litt...
What is your primary use case for Amazon Inspector?
I mostly use Amazon Inspector for vulnerability scanning on AWS native applications. For hybrid applications, we have different security scanners.
What needs improvement with RSA Archer?
While it provides benefits in terms of security, the pricing is a bit higher than customers typically expect. It would be helpful if RSA Archer had the capability for two-way integration because, i...
What is your primary use case for RSA Archer?
Regarding the compliance, risk, and governance tools, I am comfortable discussing the tools in the GRC category. The specific module from ServiceNow is the ServiceNow Compliance, Risk, and Governan...
What advice do you have for others considering RSA Archer?
I have been in touch with about three companies who use RSA Archer actively in the compliance area. These companies use RSA Archer for nearly all purposes, including governance, internal risk, and ...
 

Also Known As

No data available
Archer
 

Overview

 

Sample Customers

betterment, caplinked, flatiron, university of nutri dame
T-Systems, Bridge Point, Equifax, First Data, Global Imaging Company, Manulife Financial
Find out what your peers are saying about Amazon Inspector vs. RSA Archer and other solutions. Updated: June 2026.
908,800 professionals have used our research since 2012.