Try our new research platform with insights from 80,000+ expert users

RSA Archer vs Tenable Lumin comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 1, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

RSA Archer
Ranking in IT Vendor Risk Management
2nd
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
41
Ranking in other categories
GRC (1st), IT Governance (1st)
Tenable Lumin
Ranking in IT Vendor Risk Management
18th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
3
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2025, in the IT Vendor Risk Management category, the mindshare of RSA Archer is 12.5%, up from 11.5% compared to the previous year. The mindshare of Tenable Lumin is 1.8%, down from 2.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Vendor Risk Management
 

Featured Reviews

IMRAN ALMARZOOQI - PeerSpot reviewer
Automates compliance management effectively but needs improved interface and dashboards
The tool basically automates whatever processes you already have, so I cannot specify improvements in that regard. However, my main issue with Archer is the graphics. The graphics have always been lacking. I always need to depend on another tool to read information from Archer to have better dashboards. It is like using Linux, and it has a Linux mindset and interface. I want to use Archer for top management and CEOs, but it looks too technical, and the dashboards are not really friendly. They are bulky, like opening an old Nintendo system from nineteen-ninety. The management agrees that Archer lacks in terms of presentation and dashboarding. It is complex, not user-friendly, and bulky. The interface just looks old.
Yusuf-Hashmi - PeerSpot reviewer
It creates a risk score that helps me develop a remediation plan, so the infrastructure team can move quickly to address risks
Tenable Lumin's dashboard helps me understand my vulnerabilities and which tasks I should prioritize for vulnerability remediation. Tenable creates a risk score that helps me develop a remediation plan, so the infrastructure team can move quickly to address risks. Real-time threat intelligence is also helpful. They get multiple sources of intelligence and correlate the data. Lumin discovers your assets through an agent or a network scan. That's an excellent feature that I'm leveraging now to better understand where all my assets are.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Even non-technical people can be masters of the product."
"The integrated data model of a one-to-many/many-to-one relationship is quite useful."
"One of the useful features is the ability to connect to various systems in order to accommodate data."
"Easy to implement with a high level of automation."
"With RSA Archer, an admin can set permissions for a normal user to go directly to the tool they need to input some data. Admins can then go through that and approve some requests. Also, they can log in based on these kinds of permissions, including ticketing, service patches, or upgrades."
"It is enterprise-wide accessible. So, it is very helpful for all the employees in our bank. They can log in and do their risk management activities. It has a few inbuilt modules that are helpful for doing risk management activities, such as issue management, risk identification, risk assessment, and policy exception management. It also has some inbuilt workflows inside these modules. They are also helpful."
"Integration is another great aspect of RSA Archer. From the beginning, integration has been a central focus for RSA, and Archer has always integrated well with most tools on the market today."
"This solution helped us with the centralization of our governance data, so we could house all of our controls in one place. We could use that central repository of all our controls to build our risk management strategy and our policy and governance. So we could use controls as a central library and build policy, and then build risk management around it."
"Tenable Lumin's dashboard helps me understand my vulnerabilities and which tasks I should prioritize for vulnerability remediation. Tenable creates a risk score that helps me develop a remediation plan, so the infrastructure team can move quickly to address risks. Real-time threat intelligence is also helpful. They get multiple sources of intelligence and correlate the data. Lumin discovers your assets through an agent or a network scan. That's an excellent feature that I'm leveraging now to better understand where all my assets are."
"Tenable Lumin is very good because it helps organizations look for solutions and profit. It also helps organizations save time because it displays market data well."
"The stability of this solution is appropriate. You can sleep well at night, if you have this solution implemented in your environment."
 

Cons

"There is no inbuilt alert in Archer to let us know that a data feed has failed or did not run for different reasons. So, we don't even get to know that a feed has not run until somebody reports it to us. This has been a problem all the time. Data feeds have always been a big headache for us because there is no feature to let us know if a feed has not run or has failed. If Archer had a feature to send us an email notification when a feed has failed, it would've been very helpful. This is the reason why our users are slowly moving away to another platform. Some of the modules that I have been managing are being moved to ServiceNow. Next year, a lot of our modules will be moved from RSA Archer to ServiceNow, and the data feed issue has been one of the main reasons."
"While the AI features are emerging and the cost is comparatively low, it's not yet up to the market standard."
"A remaining area for improvement is integration. There should be built-in integration mechanisms, for example, for organizations switching from platforms like ServiceNow to Archer, instead of custom integrations for each client."
"There should be a way to export and get data from the system in PDF or PowerPoint presentation format. This would be a great addition."
"I would like to have the ability to build and maintain an inventory of personal data processing activities and assets utilizing a purpose-built taxonomy and data structure."
"The product is expensive."
"The solution as a whole could be simplified."
"Some of the error reporting isn't very clear. When you're looking for information on error codes, you got to do a lot of digging."
"The price could be better."
"Tenable Lumin isn't that old and still needs some time to mature."
"The solution's cloud operation has issues Lumin and Tenable are not one product. The integration needs to be worked out better. There is space for improvement there."
 

Pricing and Cost Advice

"I am not 100% familiar with that, especially with their new model. I just know that the way they've licensed per user to scale is good."
"The price of the solution is very affordable."
"The solution is not at all a cheap product."
"The initial purchase is cheap. You pay a nominal price to start then renew the license annually. You also must buy a license for each module. I'm not too fond of that aspect of the licensing model. You buy the elephant and then spend more money to feed the elephant."
"The price of RSA Archer is good. The price isn't too high considering it is a leading tool in the market."
"The license is costly for the solution, but the remaining set up and maintenance is quite cheaper."
"The pricing is okay. The licensing costs are very reasonable; it is very affordable to us."
"I am not sure about other companies, but it's quite expensive."
"The price could be better."
report
Use our free recommendation engine to learn which IT Vendor Risk Management solutions are best for your needs.
851,604 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
43%
Financial Services Firm
14%
Computer Software Company
6%
Manufacturing Company
5%
Financial Services Firm
15%
Computer Software Company
12%
Energy/Utilities Company
10%
University
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about RSA Archer?
It has various valuable features. For example, showing us if a control aligns with specific standards or frameworks helps us understand it better and verify its compliance.
What needs improvement with RSA Archer?
If the user needs to fill data, they need to go to one page and then to the next page if they can reduce the number of clicks to perform some activities and would like RSA to improve in this area. ...
What is your primary use case for RSA Archer?
I perform all of our information security management governance and risk -related activities through Archer. My organization manages all types of audits and Enterprise risk activities using Archer.
Ask a question
Earn 20 points
 

Comparisons

 

Also Known As

Archer
Lumin
 

Overview

 

Sample Customers

T-Systems, Bridge Point, Equifax, First Data, Global Imaging Company, Manulife Financial
Information Not Available
Find out what your peers are saying about RSA Archer vs. Tenable Lumin and other solutions. Updated: April 2025.
851,604 professionals have used our research since 2012.