Try our new research platform with insights from 80,000+ expert users

MetricStream vs RSA Archer comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 1, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

MetricStream
Ranking in GRC
10th
Ranking in IT Governance
4th
Ranking in IT Vendor Risk Management
18th
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
3
Ranking in other categories
Continuous Controls Monitoring (9th)
RSA Archer
Ranking in GRC
1st
Ranking in IT Governance
1st
Ranking in IT Vendor Risk Management
4th
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
42
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of March 2026, in the GRC category, the mindshare of MetricStream is 3.1%, down from 4.8% compared to the previous year. The mindshare of RSA Archer is 5.6%, down from 16.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
GRC Mindshare Distribution
ProductMindshare (%)
RSA Archer5.6%
MetricStream3.1%
Other91.3%
GRC
 

Featured Reviews

JQ
Owner at a consultancy with 1-10 employees
Centralized risk libraries have streamlined audits and now highlight clunky workflows and upgrades
MetricStream can be improved in several areas. Sometimes the overall flow of the application can seem a bit clunky, based on feedback from clients. From my understanding and what I have heard from developers within MetricStream during my deeper use of the application, the application seems to have been developed within silos, and the interaction of certain applications internally could definitely be improved in terms of the overall coding that exists between applications within the solution. The only improvement I suggest for MetricStream is to gather a collaborative think tank from several of the largest clients and compile feedback to prioritize suggested enhancements from multiple organizations.
CJ
Information Security Specialist at Dubai Health Authority
Centralized management strengthens compliance with good look and feel
From my perspective as a customer and end user, Archer has an impressive look and feel, but the most adaptive feature is its ease of configuration which helps to enhance our process according to our maturity. It's more about our organization getting centralized with an integrated approach that focuses on risk governance and compliance. When can provide a detailed dashboards to management with the details of risks from top-down or bottom-up prioritizing actions based on its criticality or necessity. This allows us to show end users and management where the issues lie and effectively demonstrate accountability and visibility in compliance.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Key features are usability and ease of configuration. It allows us to have all the information in a single place and provide real-time indicators and information for our executives."
"The interface is mobile-friendly and it is getting a good response from our customers."
"Since implementing MetricStream, audit teams have shaved about two weeks off of annual planning across various teams, allowing audit departments of about 140 auditors across maybe 10 teams to squeeze in 10 extra audits, one audit per each team, if not additional testing."
"The last project was for an investment group that was using Excel. Shifting their records from one position to another took approximately 15 minutes. In Archer, we created a workflow for them to leverage it, and they could send the single record with one click to one person within seconds. The whole process went from 15 minutes to two minutes to get the approval for the records. The main purpose of Archer is to just make it easy."
"From my perspective as a customer and end user, RSA is about the look and feel."
"Enables development of any application, automation of any workflow including the GRC work processes."
"Solution is scalable."
"I like how Archer requires very little programming ability. A person with minimum coding experience can configure the necessary fields in Archer. It's more of a drag-and-drop solution."
"The helpful features of RSA Archer include providing an integrated overview of the landscape in the company, which leads the user to use the same inventory and other components, sharing the same set of references and objects we are working on."
"Integration is another great aspect of RSA Archer. From the beginning, integration has been a central focus for RSA, and Archer has always integrated well with most tools on the market today."
"The part I liked about Archer was the risk assessment for deficiencies and being able to use it there."
 

Cons

"MetricStream's scalability is adaptable, though the biggest issue I have encountered with clients has been around upgrades that require re-implementing customizations to the out-of-box solutions after significant upgrades."
"We would like to have more dashboards and reports, such as geographical and trend reports in the next version. Also, an improvement in the mobile version would be helpful."
"I would like to see out-of-the-box integration with more security, it would be helpful."
"I would like to see real-time data, from vulnerabilities, and threats."
"A remaining area for improvement is integration. There should be built-in integration mechanisms, for example, for organizations switching from platforms like ServiceNow to Archer, instead of custom integrations for each client."
"The management agrees that Archer lacks in terms of presentation and dashboarding. It is complex, not user-friendly, and bulky."
"It would be nice if RSA Archer featured more customization. When customers are updating, they should be notified whether certain updates are optional. The install screen should not proceed to the next page unless we make some selections about which updates we want to install."
"Slow turnaround time from support team."
"If I were to rate RSA technical support on a scale from one to ten, I would give it about four, as there is definitely room for improvement, but support is available."
"If you need to integrate the RSA products with another SEIM solution, then it doesn't work properly."
"Solution could use more inbuilt applications."
 

Pricing and Cost Advice

"They are flexible in terms of customers' needs."
"Fairly highly-priced, especially for smaller companies."
"At the higher end of the price scale, but provides better, more accessible functionality and customization than cheaper products."
"As I am a developer and responsible for providing production support, I do not have personal knowledge of the pricing. However, my colleagues claim that it is very expensive in comparison with other tools."
"The pricing is okay. The licensing costs are very reasonable; it is very affordable to us."
"The solution is not at all a cheap product."
"The initial purchase is cheap. You pay a nominal price to start then renew the license annually. You also must buy a license for each module. I'm not too fond of that aspect of the licensing model. You buy the elephant and then spend more money to feed the elephant."
"The solution's price should be reduced. You only have to pay the license and there are no additional fees."
"The license is costly for the solution, but the remaining set up and maintenance is quite cheaper."
report
Use our free recommendation engine to learn which GRC solutions are best for your needs.
884,873 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
22%
Manufacturing Company
7%
Computer Software Company
6%
Comms Service Provider
6%
Financial Services Firm
19%
Insurance Company
12%
Manufacturing Company
7%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise6
Large Enterprise25
 

Questions from the Community

What are the main differences between RSA Archer, MetricStream and IBM OpenPages?
RSA Archer, IBM OpenPages and MetricStream are the top GRC software solutions in the market today. Out of the 3, IBM OpenPages has a slightly upper hand as IBM has come up with powerful Artificial ...
What needs improvement with RSA Archer?
While it provides benefits in terms of security, the pricing is a bit higher than customers typically expect. It would be helpful if RSA Archer had the capability for two-way integration because, i...
What is your primary use case for RSA Archer?
Regarding the compliance, risk, and governance tools, I am comfortable discussing the tools in the GRC category. The specific module from ServiceNow is the ServiceNow Compliance, Risk, and Governan...
What advice do you have for others considering RSA Archer?
I have been in touch with about three companies who use RSA Archer actively in the compliance area. These companies use RSA Archer for nearly all purposes, including governance, internal risk, and ...
 

Also Known As

No data available
Archer
 

Overview

 

Sample Customers

Federal Home Loan Bank of Chicago, ACCO Brands Corporation, AgFirst Farm Credit Bank, AIB International, Associated Banc-Corp, BAE Systems, Barclaycard, Dell Inc, DIRECTV, Energizer, Fresenius Kabi, Hasbro, Goodyear, HudsonCity Savings Bank, Infigen Energy, Kaydon, Leroy Merlin, Mountry Financial Corp., Nicholas Piramal, Pepco, Pfizer, Societe Generale, Whitney Bank
T-Systems, Bridge Point, Equifax, First Data, Global Imaging Company, Manulife Financial
Find out what your peers are saying about MetricStream vs. RSA Archer and other solutions. Updated: March 2026.
884,873 professionals have used our research since 2012.