Large enterprises (5000+ employees) with deep legacy investment in Archer wanting to extend existing deployment.
New buyers; modern alternatives (Hyperproof, LogicGate, Vanta + Drata at scale) deliver faster time-to-value with cleaner UX.
Is RSA Archer (Archer) a trustworthy vendor?
- 2020-09-01STG acquired Archer from RSA + Dell; product-investment trajectory uncertain
- 2022-09-15STG spun Archer out as independent company; rebranded from RSA Archer to Archer
- 2023-06-10IBM Cloud platform shift announced creating migration friction for legacy customers
- 2025-09-12Customer-support complaints persisted; named-resource access reduced under STG ownership
What 780 reviews actually say
Synthesized from G2, Capterra, Reddit, Trustpilot. Patterns >15% prevalence shown.
Praise patterns
- Platform depth is the genuine strength for existing customers71% →
- Heavy customization for regulated-industry use cases51% →
Complaint patterns
- UX-and-workflow modernization visibly slow78% →
- IBM Cloud migration friction is real64% ↓
- Implementation timelines and complexity heavy51% →
- Customer-support quality declined under STG ownership47% ↑
- Renewal pricing pressure persists41% ↑
What buyers actually pay
18 anonymized deal disclosures · last updated 2026-05-01
| Company size | Median annual |
|---|---|
| 5000+ employees | $850,000 |
Auto-verified certifications
Editorial: Strengths
- Deep enterprise IRM platform with 20+ year heritage and Fortune-500 customer base
- Mature audit workflow, risk management, vendor risk, business continuity, policy management
- Heavy customization capabilities for regulated-industry use cases (banking, energy, telecom)
- Strong installed base of certified professionals and implementation partners
- Multi-entity, multi-region, multi-subsidiary support at enterprise scale
- Framework coverage breadth across global regulatory requirements
Editorial: Weaknesses
- UX-and-workflow modernization slow; 10+ year legacy-feel in core flows
- IBM Cloud platform shift created migration friction; some customers stuck on legacy infrastructure
- Implementation timelines often 6-18 months for enterprise rollouts
- Pricing opaque; six-to-seven-figure annual contracts standard
- New-buyer addressable market shrinking as modern alternatives mature
- Customer-support quality uneven post-STG ownership; named-resource access reduced
Key features & integrations
- +Mature IRM platform: audit + risk + vendor + policy + business continuity
- +Multi-entity, multi-region, multi-subsidiary support
- +Framework coverage across global regulatory requirements
- +Heavy customization for regulated-industry use cases
- +Risk register with quantitative scoring
- +Vendor risk management with deep questionnaire library
- +Policy lifecycle with versioning + attestation
- +Business continuity + crisis management workflows
Read our full ranking of GRC / Compliance Automation
RSA Archer (Archer) ranks #9 in our editorial review of 10 grc / compliance automation platforms. The deep-dive covers methodology, comparison tables, decision matrix, migration scoring, and FAQs.
Read the full rankingClosest alternatives in GRC / Compliance Automation
Contribute your verified deal price
Pricing in B2B software is opaque because vendors want it that way. Verified buyer prices fix that, anonymously. Share what you actually paid for RSA Archer (Archer); we’ll add it to the verified pricing dataset on this page (with company size band only, no identifying details).
Submit anonymously