Try our new research platform with insights from 80,000+ expert users

MetricStream vs RSA Archer comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 1, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

MetricStream
Ranking in GRC
9th
Ranking in IT Governance
3rd
Ranking in IT Vendor Risk Management
12th
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
2
Ranking in other categories
Continuous Controls Monitoring (12th)
RSA Archer
Ranking in GRC
1st
Ranking in IT Governance
1st
Ranking in IT Vendor Risk Management
2nd
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
41
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of April 2025, in the GRC category, the mindshare of MetricStream is 5.0%, up from 3.9% compared to the previous year. The mindshare of RSA Archer is 17.2%, down from 17.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
GRC
 

Featured Reviews

AP
Reasonably priced, stable, with out of the box deployment, and has good local support
They have now reworked it. The interface is mobile-friendly and it is getting a good response from our customers. It's a very good feature that the product offers. It is also available as a cloud option, which is getting a lot of interest from customers who are looking into the GRCC. It is very useful, especially in the solution platform. It has good features and good functionality, and our customers feel there is a lot of merit in that. I think that the portal is constantly improving. They do their own enhancements very often. They keep doing those enhancements from their site itself.
IMRAN ALMARZOOQI - PeerSpot reviewer
Automates compliance management effectively but needs improved interface and dashboards
The tool basically automates whatever processes you already have, so I cannot specify improvements in that regard. However, my main issue with Archer is the graphics. The graphics have always been lacking. I always need to depend on another tool to read information from Archer to have better dashboards. It is like using Linux, and it has a Linux mindset and interface. I want to use Archer for top management and CEOs, but it looks too technical, and the dashboards are not really friendly. They are bulky, like opening an old Nintendo system from nineteen-ninety. The management agrees that Archer lacks in terms of presentation and dashboarding. It is complex, not user-friendly, and bulky. The interface just looks old.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The interface is mobile-friendly and it is getting a good response from our customers."
"Key features are usability and ease of configuration. It allows us to have all the information in a single place and provide real-time indicators and information for our executives."
"RSA Archer's best features are advanced workflow, reports, dashboards, and notifications."
"The Advance Workflow feature simplifies things."
"The tool has stability, and it allows me to automate whatever process I have."
"Easy to implement with a high level of automation."
"The part I liked about Archer was the risk assessment for deficiencies and being able to use it there."
"Flexible record permissions and data import features."
"RSA is a very rich application. I like its adaptive suggestion, where based on your users and the class of data, it can actually recommend you the proper control to choose. For example, we have been using PCI DSS as an NIST. So based on application feedback, it will provide you with a suggestion on which control objective needs to be set. Based on that, you can make a decision—you don't need to take the suggestion, but you can customize that particular provided suggestion. RSA Archer's workflow is also good, in terms of process automation."
"First of all, its access control feature where it provides application level access, solution level access, and even recall access, as well."
 

Cons

"I would like to see out-of-the-box integration with more security, it would be helpful."
"We would like to have more dashboards and reports, such as geographical and trend reports in the next version. Also, an improvement in the mobile version would be helpful."
"Recently, we made a suggestion for cross references, like for one application to another. There were limitations there, so we're hoping that will be included in the next upgrade."
"I would like to see real-time data, from vulnerabilities, and threats."
"The technology's a little outdated."
"It would be useful for customers if COBIT 2019 could be translated into different languages."
"The solution as a whole could be simplified."
"The first improvement I would suggest for RSA Archer is a better search feature. The search criteria needs to be improved. Sometimes I do a search and the search doesn't return the exact item I'm looking for. RSA Archer could also be improved by being more user-friendly. Maybe I have been using a limited version of RSA Archer, but I'm not sure whether it has ESG, environmental and social governance. In the next couple of years, ESG is the next feature that will be integrated into GRC tools. I would recommend RSA Archer adds ESG."
"If you need to integrate the RSA products with another SEIM solution, then it doesn't work properly."
"The bullet chart is the best graph for my purposes, and it should be available for inclusion in the dashboards."
 

Pricing and Cost Advice

"They are flexible in terms of customers' needs."
"RSA Archer's price is justifiable and not as expensive, compared to ServiceNow. I have heard that the licensing for ServiceNow is much more expensive. I'm unaware whether there are any additional costs after licensing fees."
"The pricing is okay. The licensing costs are very reasonable; it is very affordable to us."
"The initial purchase is cheap. You pay a nominal price to start then renew the license annually. You also must buy a license for each module. I'm not too fond of that aspect of the licensing model. You buy the elephant and then spend more money to feed the elephant."
"The price of the solution is very affordable."
"I am not 100% familiar with that, especially with their new model. I just know that the way they've licensed per user to scale is good."
"Fairly highly-priced, especially for smaller companies."
"At the higher end of the price scale, but provides better, more accessible functionality and customization than cheaper products."
"As I am a developer and responsible for providing production support, I do not have personal knowledge of the pricing. However, my colleagues claim that it is very expensive in comparison with other tools."
report
Use our free recommendation engine to learn which GRC solutions are best for your needs.
845,406 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
27%
Financial Services Firm
20%
Computer Software Company
8%
Non Profit
5%
Educational Organization
51%
Financial Services Firm
12%
Computer Software Company
5%
Manufacturing Company
4%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What are the main differences between RSA Archer, MetricStream and IBM OpenPages?
RSA Archer, IBM OpenPages and MetricStream are the top GRC software solutions in the market today. Out of the 3, IBM OpenPages has a slightly upper hand as IBM has come up with powerful Artificial ...
What do you like most about RSA Archer?
It has various valuable features. For example, showing us if a control aligns with specific standards or frameworks helps us understand it better and verify its compliance.
What needs improvement with RSA Archer?
If the user needs to fill data, they need to go to one page and then to the next page if they can reduce the number of clicks to perform some activities and would like RSA to improve in this area. ...
What is your primary use case for RSA Archer?
I perform all of our information security management governance and risk -related activities through Archer. My organization manages all types of audits and Enterprise risk activities using Archer.
 

Also Known As

No data available
Archer
 

Overview

 

Sample Customers

Federal Home Loan Bank of Chicago, ACCO Brands Corporation, AgFirst Farm Credit Bank, AIB International, Associated Banc-Corp, BAE Systems, Barclaycard, Dell Inc, DIRECTV, Energizer, Fresenius Kabi, Hasbro, Goodyear, HudsonCity Savings Bank, Infigen Energy, Kaydon, Leroy Merlin, Mountry Financial Corp., Nicholas Piramal, Pepco, Pfizer, Societe Generale, Whitney Bank
T-Systems, Bridge Point, Equifax, First Data, Global Imaging Company, Manulife Financial
Find out what your peers are saying about MetricStream vs. RSA Archer and other solutions. Updated: February 2025.
845,406 professionals have used our research since 2012.