Try our new research platform with insights from 80,000+ expert users

Bitsight vs RSA Archer comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 1, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Bitsight
Ranking in IT Vendor Risk Management
3rd
Average Rating
8.6
Reviews Sentiment
7.8
Number of Reviews
6
Ranking in other categories
Attack Surface Management (ASM) (10th)
RSA Archer
Ranking in IT Vendor Risk Management
4th
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
42
Ranking in other categories
GRC (1st), IT Governance (1st)
 

Mindshare comparison

As of August 2025, in the IT Vendor Risk Management category, the mindshare of Bitsight is 10.8%, down from 12.1% compared to the previous year. The mindshare of RSA Archer is 11.8%, down from 12.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Vendor Risk Management
 

Featured Reviews

Marc Chapel - PeerSpot reviewer
Stable product with efficient features for listing vulnerabilities
I recommend BitSight because it is very convenient to use. It has become a standard tool used in many companies. It is easy to share a few components of an algorithm for users. It is not ideal as it only reflects some of the reality of Internet-facing applications. However, it is the best solution at the moment. I rate it an eight out of ten.
IMRAN ALMARZOOQI - PeerSpot reviewer
Automates compliance management effectively but needs improved interface and dashboards
The tool basically automates whatever processes you already have, so I cannot specify improvements in that regard. However, my main issue with Archer is the graphics. The graphics have always been lacking. I always need to depend on another tool to read information from Archer to have better dashboards. It is like using Linux, and it has a Linux mindset and interface. I want to use Archer for top management and CEOs, but it looks too technical, and the dashboards are not really friendly. They are bulky, like opening an old Nintendo system from nineteen-ninety. The management agrees that Archer lacks in terms of presentation and dashboarding. It is complex, not user-friendly, and bulky. The interface just looks old.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Its customer service team responds quickly."
"Offers open ports from an external point of view."
"I prefer BitSight due to its patch management capabilities. The score is a valuable feature. I have contacted the customer support through e-mail and their response rate is fast. I rate the solution a nine out of ten."
"The solution is user-friendly."
"The best thing about BitSight is the comprehensive list of risk vectors, covering compromised systems, diligence failures, and behavioral anomalies."
"The product helps us identify the vulnerabilities of internet-facing applications."
"The solution has improved my organization by having everything combined to a single platform."
"Integration is another great aspect of RSA Archer. From the beginning, integration has been a central focus for RSA, and Archer has always integrated well with most tools on the market today."
"It has the best workload management features."
"Archer seamlessly integrates data systems without requiring additional software."
"RSA is a very rich application. I like its adaptive suggestion, where based on your users and the class of data, it can actually recommend you the proper control to choose. For example, we have been using PCI DSS as an NIST. So based on application feedback, it will provide you with a suggestion on which control objective needs to be set. Based on that, you can make a decision—you don't need to take the suggestion, but you can customize that particular provided suggestion. RSA Archer's workflow is also good, in terms of process automation."
"Easy to implement with a high level of automation."
"The part I liked about Archer was the risk assessment for deficiencies and being able to use it there."
"It is a very friendly tool. We can easily understand what is going on inside the tool. I like this tool. We can work with the tool for the ERP platform. We can create automated applications based on the requirements."
 

Cons

"Its factor analysis feature could be better."
"There may be room for improvement in the methodology for identifying findings, as occasional errors occur on the technical side."
"At the moment, when the vulnerability score decreases, it remains the same for quite a while, even though issues are resolved in 24 hours."
"BitSight could improve the classes and lower-level detections of anomalies that compound the information used to compute the rating."
"Data enrichment is the major issue."
"The solution’s benchmarking should be improved."
"If you need to integrate the RSA products with another SEIM solution, then it doesn't work properly."
"While the AI features are emerging and the cost is comparatively low, it's not yet up to the market standard."
"There were so many problems that we had found. One time, the search index was not working. We also faced slowness in Archer, but I resolved this issue."
"Solution could use more inbuilt applications."
"Archer could be improved by having more customization. I'm not sure if the backend processes have API calls and those kinds of seamless integrations, but from the front, some of the solutions are very out-of-the-box. It's not customizable, so that could be a little problematic since you have to use their features. In terms of the backend structure, I'm not too sure because I'm not a developer—I was an end user and product owner of Archer—and I don't quite know the backend and developmental features. But since it's an out-of-the-box solution, sometimes customization was challenging and support was a little problematic because we had to reach out to them all the time."
"It would be useful for customers if COBIT 2019 could be translated into different languages."
"I find the tech support to be inadequately knowledgeable."
"Some areas are not truly automated but are only scheduled."
 

Pricing and Cost Advice

"The product has a reasonable price."
"The solution's price is average."
"The solution's price should be reduced. You only have to pay the license and there are no additional fees."
"Fairly highly-priced, especially for smaller companies."
"At the higher end of the price scale, but provides better, more accessible functionality and customization than cheaper products."
"As I am a developer and responsible for providing production support, I do not have personal knowledge of the pricing. However, my colleagues claim that it is very expensive in comparison with other tools."
"The solution’s pricing is moderate."
"RSA Archer's price is justifiable and not as expensive, compared to ServiceNow. I have heard that the licensing for ServiceNow is much more expensive. I'm unaware whether there are any additional costs after licensing fees."
"The price of the solution is very affordable."
"The initial purchase is cheap. You pay a nominal price to start then renew the license annually. You also must buy a license for each module. I'm not too fond of that aspect of the licensing model. You buy the elephant and then spend more money to feed the elephant."
report
Use our free recommendation engine to learn which IT Vendor Risk Management solutions are best for your needs.
865,295 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Computer Software Company
11%
Manufacturing Company
9%
Insurance Company
8%
Financial Services Firm
23%
Insurance Company
12%
Manufacturing Company
9%
Computer Software Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for BitSight?
The product is a little expensive and very oriented to large companies.
What needs improvement with BitSight?
BitSight could improve the classes and lower-level detections of anomalies that compound the information used to compute the rating. They could evolve to be a more powerful scanner of cyber hygiene...
What do you like most about RSA Archer?
It has various valuable features. For example, showing us if a control aligns with specific standards or frameworks helps us understand it better and verify its compliance.
What needs improvement with RSA Archer?
While it provides benefits in terms of security, the pricing is a bit higher than customers typically expect. It would be helpful if RSA Archer had the capability for two-way integration because, i...
What is your primary use case for RSA Archer?
Regarding the compliance, risk, and governance tools, I am comfortable discussing the tools in the GRC category. The specific module from ServiceNow is the ServiceNow Compliance, Risk, and Governan...
 

Comparisons

 

Also Known As

No data available
Archer
 

Overview

 

Sample Customers

Fannie Mae, Cabela's, BNP Paribas, PWC, AIR Worldwide, Con Edison, The Container Store, OshKosh, Steris, University of South Florida, Emblem Health, Lloyds Bank
T-Systems, Bridge Point, Equifax, First Data, Global Imaging Company, Manulife Financial
Find out what your peers are saying about Bitsight vs. RSA Archer and other solutions. Updated: July 2025.
865,295 professionals have used our research since 2012.