No more typing reviews! Try our Samantha, our new voice AI agent.

ACF2 vs Idira Privileged Access Manager comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 2, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

ACF2
Ranking in Mainframe Security
4th
Average Rating
9.0
Reviews Sentiment
7.8
Number of Reviews
6
Ranking in other categories
Database Security (13th)
Idira Privileged Access Man...
Ranking in Mainframe Security
1st
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
230
Ranking in other categories
User Activity Monitoring (1st), Enterprise Password Managers (2nd), Privileged Access Management (PAM) (1st), Operational Technology (OT) Security (3rd)
 

Mindshare comparison

As of August 2026, in the Mainframe Security category, the mindshare of ACF2 is 12.2%, up from 12.1% compared to the previous year. The mindshare of Idira Privileged Access Manager is 5.7%, up from 2.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Mainframe Security Mindshare Distribution
ProductMindshare (%)
Idira Privileged Access Manager5.7%
ACF212.2%
Other82.1%
Mainframe Security
 

Featured Reviews

reviewer1077621 - PeerSpot reviewer
IT Examiner at a financial services firm with 10,001+ employees
A reliable, scalable product for security and auditing of our mainframe environment
It is a good product. It has been used for years. As long as it is configured correctly, it is a very stable product. It depends on how an institution or a company configures it. It depends on an institution's risk appetite. You need to make sure it is configured as per the concept of least privilege, and the logging features, detection and control mechanism, and other things like that are enabled. If you configure it to give access to the public, then there could be compromises. You should also have someone who independently checks it to make sure that it is configured keeping security in mind. If it has been configured for a while, when there are enhancements to the product or when you enhance it, you need to make sure that security is also looked at, and it is configured according to an institution's security policies. I would rate it a nine out of 10.
Atul-Gujar - PeerSpot reviewer
CyberArk manager at a comms service provider with 10,001+ employees
Secures critical infrastructures with essential user session audit records
A potential area for improvement is enhancing support for cluster environments and distributed Vaults. Clients in multiple countries that need central access have different challenges that require better solutions from CyberArk. For financial services, CyberArk can improve incident response by ensuring fast support for critical priority tickets to meet compliance requirements. Providing more documentation on CyberArk is recommended for new team members to enhance their troubleshooting capabilities. I understand it's up to the client, but 99% fail to change the demo key, so it's crucial for CyberArk to emphasize changing the key and documenting it as part of the installation process.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We use this tool to quickly assign privileges to different users as soon as they come in."
"The most valuable feature is strict and reliable access control to CICS Resources."
"Logging and monitoring are most valuable. It is for the mainframe environment, and it is at the forefront for security and resilience."
"I am deeply impressed with the quality and depth and breadth of security and functionality in CA’s ACF2 and Top Secret products."
"By providing a high level of access control to the z/OS systems, ACF2 allows us to maintain tight controls on dataset and system access and helps us keep unauthorized users from accessing PHI or PII data."
"It is a good product."
"Without the product, extracting this information may take us as much as several days; instead, we can get it in real time."
"The NOACCESS by default is another very good feature. Also, access rules are straightforward, and easy to understand."
"Cost-wise, it is not a cheap product, but it does a ton of things, and it does them well."
"All the features of CyberArk are useful for me, but the biggest one is that CyberArk has logs for all the features. That is important when there is a problem. You know where to look and you have the information. In cyber security, the most important aspect is information."
"I find the discovery feature, which includes credential management, session management, monitoring, and remediation within a session, to be very valuable."
"We are able to know who is accessing what and when; having accountability."
"Password Vault's main advantage is its scalability. We constantly see huge enterprises implementing something like this, and the privileged session management is an excellent piece. You can kind of watch videos of whatever an admin has done."
"I have used other privileged account management tools in the past; this, by far, outranks them as far as features and usability."
"Overall, I think CyberArk Privileged Access Manager is very good and can be considered a market leader in this space."
"CPM helps keep the password policy up to date."
 

Cons

"I would like my team and me to be able to use simple browsers, like Chrome, to be able to access mainframe data and provision users using the browser.​"
"The user access review could also be improved. It produces a lot of false positives."
"They can work on its ability to work in a distributed environment. It's a mainframe product. As many companies move to the cloud, depending on what cloud models they choose, such as a public, hybrid, or private cloud, it should be deployable. I am not sure if it can be deployed on those platforms. It has been there since the '50s or '60s, and it's still scalable. It has survived all these years, and it's scalable to many platforms, but I don't know about the cloud."
"They can work on its ability to work in a distributed environment."
"Initial setup could be complex if you rely on contractors to help with implementation."
"Reporting can sometimes include false positives."
"It needs longer rules. The max rule is 32K."
"It is only good as a PAM solution. If they could work more on Privileged Threat Analytics, it would be beneficial. It has limitations, so improvements on PTA would be fine."
"The downside is that it's a big program. To scale excessively, locally, on an on-prem application, takes a lot of servers."
"I don't know if "failed authentication" is a glitch or if that was an update... However, since we are the CyberArk support within our organization, we need to know that the password is suspended and we won't know that unless we have the ITA log up. So when a user calls and says, "Hey, I'm locked out of CyberArk, I can't get into CyberArk," we have to go through all of these other troubleshooting steps because the first thing we don't think of right now is, "The account is suspended." It doesn't say that anymore."
"The price is high compared to Azure Key Vault. It's the most expensive solution."
"Functionality to enable drive mappings to platforms and default connectors without the need to use AutoIt."
"I'm not a fan of technical support with CyberArk. It's like jumping through red tape and hoops."
"The major pain point that we have is the capacity of CyberArk due to the sheer volume of NPAs that we are managing."
"There are upwards of six components you need to set it up. And you might need anywhere from two to five servers. It takes some work to set that up, especially in a larger environment."
 

Pricing and Cost Advice

Information not available
"The solution is very expensive and requires a license. We pay for an enterprise license."
"CyberArk DNA is free if you purchase the CyberArk solution. There is no additional charge for CyberArk DNA, which is great."
"CyberArk Enterprise Password Vault is a very expensive product."
"The main problem for the tool is its licensing. I work for a really big company. When you try to develop this as a service, usually you work with leverage teams who are formed with dozens of members. You might dedicate one FTE, or less, for something, e.g., an antivirus administrator. You might have half an FTE's effort dedicated to administering the antivirus, but then you have a team of about 30 users who might access that ticket. The problem is that CyberArk eliminated the possibility of concurrent users years ago. This is a big problem for companies who work with leverage teams. You need to pay for everyone. 40 licenses are used by 20 or 30 people. This is a big problem because licenses are not precisely cheap."
"CyberArk Privileged Access Manager is more expensive than its competitors, such as BeyondTrust, Delinea, and ManageEngine PAM360."
"The price of this solution is expensive."
"The price of the solution is reasonable."
"I focus more on the technical side, but I hear customers say that if CyberArk was more affordable, they might have acquired more licenses. Some clients consider alternative solutions due to pricing concerns."
report
Use our free recommendation engine to learn which Mainframe Security solutions are best for your needs.
911,549 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
18%
Educational Organization
10%
Insurance Company
9%
Manufacturing Company
9%
Financial Services Firm
12%
Outsourcing Company
10%
Manufacturing Company
10%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise1
Large Enterprise4
By reviewers
Company SizeCount
Small Business59
Midsize Enterprise42
Large Enterprise175
 

Questions from the Community

Ask a question
Earn 20 points
How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the m...
What is your experience regarding pricing and costs for CyberArk Privileged Access Manager?
My thoughts on the pricing of CyberArk Privileged Access Manager depend entirely on the vendors' requirements. If they want their things to be secure, they have to spend accordingly. We have four t...
What needs improvement with CyberArk Privileged Access Manager?
I believe account discovery and rolling support need to be improved. Account discovery is important when integrating with other systems, as other PAM solutions can perform account discovery and onb...
 

Also Known As

CA ACF2
CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
 

Overview

 

Sample Customers

Sky, Rogers Communications
Rockwell Automation
Find out what your peers are saying about ACF2 vs. Idira Privileged Access Manager and other solutions. Updated: August 2026.
911,549 professionals have used our research since 2012.