Try our new research platform with insights from 80,000+ expert users

Amazon Inspector vs RSA Archer comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 1, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Amazon Inspector
Ranking in IT Vendor Risk Management
6th
Average Rating
8.2
Reviews Sentiment
7.6
Number of Reviews
7
Ranking in other categories
Vulnerability Management (17th)
RSA Archer
Ranking in IT Vendor Risk Management
4th
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
42
Ranking in other categories
GRC (1st), IT Governance (1st)
 

Mindshare comparison

As of August 2025, in the IT Vendor Risk Management category, the mindshare of Amazon Inspector is 0.9%, down from 1.3% compared to the previous year. The mindshare of RSA Archer is 11.8%, down from 12.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Vendor Risk Management
 

Featured Reviews

John D'Arcy - PeerSpot reviewer
Automated vulnerability assessments continuously enhance security
The most valuable features probably are the ability to do automated vulnerability assessments, which it does with Amazon Inspector version two. It operates continuously, so as soon as resources are created, it scans them for vulnerabilities. This allows me to pinpoint potential security vulnerabilities and provide actionable recommendations relatively quickly. Larger enterprises usually use Inspector to gather all the vulnerabilities, the CVEs, across all accounts in an AWS organization. The enterprises I work for typically have many accounts in their organization, such as thousands of accounts where I am at the moment. It is a way to gather the vulnerabilities that are present on EC2 instances, container images, and Lambda functions.
IMRAN ALMARZOOQI - PeerSpot reviewer
Automates compliance management effectively but needs improved interface and dashboards
The tool basically automates whatever processes you already have, so I cannot specify improvements in that regard. However, my main issue with Archer is the graphics. The graphics have always been lacking. I always need to depend on another tool to read information from Archer to have better dashboards. It is like using Linux, and it has a Linux mindset and interface. I want to use Archer for top management and CEOs, but it looks too technical, and the dashboards are not really friendly. They are bulky, like opening an old Nintendo system from nineteen-ninety. The management agrees that Archer lacks in terms of presentation and dashboarding. It is complex, not user-friendly, and bulky. The interface just looks old.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It operates continuously, so as soon as resources are created, it scans them for vulnerabilities."
"I recommend Amazon Inspector because it allows the automation of processes and requires less manual monitoring."
"The automated vulnerability detection aspect is most valuable."
"Amazon Inspector is highly stable, rated ten out of ten, and this stability impacts business security and administration positively."
"The findings dashboards are neat and easy to understand, offering clear demarcations for different types of findings and detailed insights into specific vulnerabilities and their associated instances. It is not a place where everything is dumped together. It offers an easy-to-understand layout."
"The integration of Amazon Inspector with other AWS services has enhanced our security. Security Hub is a major asset because it allows us to centralize data from various AWS services. We can integrate third-party tools as well. It is just a single-click option."
"The scalability of the solution itself is unparalleled."
"The most valuable feature of Amazon Inspector is the categorization of findings, which filters vulnerabilities by instance, container image, container repository, and Lambda function."
"Risk management is one of the most impressive features of Archer, especially with the recent restructuring of the user interface."
"The Advance Workflow feature simplifies things."
"I have found all the features to be valuable, including those involving reporting, the dashboard, notifications, email modules, the database and data input."
"The integrated data model of a one-to-many/many-to-one relationship is quite useful."
"Enables development of any application, automation of any workflow including the GRC work processes."
"Archer seamlessly integrates data systems without requiring additional software."
"The most valuable feature is the enterprise module, which provides the capability of having all of the information stored and linked with everything else."
"Flexible record permissions and data import features."
 

Cons

"One area for improvement in Amazon Inspector is the automation aspect."
"One major area for improvement is remediation. My team works on remediating findings over time, likely using available patches. However, easier integration with Amazon's patching services would be very helpful."
"There is room for improvement in the scanning capabilities. I'd like to see broader coverage in terms of the vulnerabilities detected."
"The other point is that the reporting features of Inspector need improvement. For example, I am in an organization with millions of CVEs, and getting an overview of all this is challenging."
"It has a limited scope. So, AWS Inspector primarily focuses on the security of the EC2 instance. So, if your architecture includes other AWS services, then you may need to use additional tools for your comprehensive security assessment. So that is one con. Another is, like, we have a dependency on agents."
"There are challenges associated with the interdependencies in AWS services, like requiring an Active Directory for other services, resulting in additional charges."
"It has automated vulnerability assessment, yet I seek more flexibility in defining custom vulnerability checks tailored to my needs, which is more difficult."
"There isn't too much to improve right now. Scanning on demand or as a part of the pipeline versus a post pipeline solution would be good, but it is not a deal breaker by any means."
"The product is expensive."
"I find the tech support to be inadequately knowledgeable."
"The solution can be a little slow due to the Silverlight feature."
"An area for improvement would be the user interface. They could also offer more on-demand applications free of cost."
"There should be built-in integration mechanisms, for example, for organizations switching from platforms like ServiceNow to Archer, instead of custom integrations for each client."
"The first improvement I would suggest for RSA Archer is a better search feature. The search criteria needs to be improved. Sometimes I do a search and the search doesn't return the exact item I'm looking for. RSA Archer could also be improved by being more user-friendly. Maybe I have been using a limited version of RSA Archer, but I'm not sure whether it has ESG, environmental and social governance. In the next couple of years, ESG is the next feature that will be integrated into GRC tools. I would recommend RSA Archer adds ESG."
"There should be a way to export and get data from the system in PDF or PowerPoint presentation format. This would be a great addition."
"If you need to integrate the RSA products with another SEIM solution, then it doesn't work properly."
 

Pricing and Cost Advice

"The pricing is very transparent and clear."
"The lowest cost would be around $10 for a few small accounts, however, for thousands of accounts, it could be around $5000 to $6000 dollars per month."
"It's priced according to market standards for its services."
"It is scaled as you go. There are probably a certain number of scans per month, and there are tiers. If you're under a certain tier, it is free. The second level is pennies, and then all the way up to like a million. So, it has a tiered pricing program. They're pretty good with your initial scanning, and there is room to scale based on being affordable, but it is fairly cheap. There are no additional costs. They pretty much think about it as a pay-per-scan type model."
"Fairly highly-priced, especially for smaller companies."
"The initial purchase is cheap. You pay a nominal price to start then renew the license annually. You also must buy a license for each module. I'm not too fond of that aspect of the licensing model. You buy the elephant and then spend more money to feed the elephant."
"The license is costly for the solution, but the remaining set up and maintenance is quite cheaper."
"It is not expensive. It is reasonable. We only pay for the licensing."
"I am not sure about other companies, but it's quite expensive."
"RSA Archer's price is justifiable and not as expensive, compared to ServiceNow. I have heard that the licensing for ServiceNow is much more expensive. I'm unaware whether there are any additional costs after licensing fees."
"The pricing is okay. The licensing costs are very reasonable; it is very affordable to us."
"The solution is not at all a cheap product."
report
Use our free recommendation engine to learn which IT Vendor Risk Management solutions are best for your needs.
865,384 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Computer Software Company
12%
Government
7%
Manufacturing Company
6%
Financial Services Firm
23%
Insurance Company
12%
Manufacturing Company
9%
Computer Software Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Amazon Inspector?
The integration of Amazon Inspector with other AWS services has enhanced our security. Security Hub is a major asset because it allows us to centralize data from various AWS services. We can integ...
What is your experience regarding pricing and costs for Amazon Inspector?
I manage pricing and purchase reserved instances, yet face challenges due to dependencies and lack of options for reserved capacity for EBS volumes. Some services create extensive costs upon launch.
What needs improvement with Amazon Inspector?
There are challenges associated with the interdependencies in AWS services, like requiring an Active Directory for other services, resulting in additional charges. Also, there is no option to buy r...
What do you like most about RSA Archer?
It has various valuable features. For example, showing us if a control aligns with specific standards or frameworks helps us understand it better and verify its compliance.
What needs improvement with RSA Archer?
While it provides benefits in terms of security, the pricing is a bit higher than customers typically expect. It would be helpful if RSA Archer had the capability for two-way integration because, i...
What is your primary use case for RSA Archer?
Regarding the compliance, risk, and governance tools, I am comfortable discussing the tools in the GRC category. The specific module from ServiceNow is the ServiceNow Compliance, Risk, and Governan...
 

Also Known As

No data available
Archer
 

Overview

 

Sample Customers

betterment, caplinked, flatiron, university of nutri dame
T-Systems, Bridge Point, Equifax, First Data, Global Imaging Company, Manulife Financial
Find out what your peers are saying about Amazon Inspector vs. RSA Archer and other solutions. Updated: July 2025.
865,384 professionals have used our research since 2012.