Try our new research platform with insights from 80,000+ expert users

MetricStream vs NAVEX One vs RSA Archer comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

As of October 2025, in the GRC category, the mindshare of MetricStream is 4.6%, up from 4.0% compared to the previous year. The mindshare of NAVEX One is 1.3%, up from 1.2% compared to the previous year. The mindshare of RSA Archer is 12.8%, down from 16.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
GRC Market Share Distribution
ProductMarket Share (%)
RSA Archer12.8%
MetricStream4.6%
NAVEX One1.3%
Other81.3%
GRC
 

Featured Reviews

AP
Reasonably priced, stable, with out of the box deployment, and has good local support
They have now reworked it. The interface is mobile-friendly and it is getting a good response from our customers. It's a very good feature that the product offers. It is also available as a cloud option, which is getting a lot of interest from customers who are looking into the GRCC. It is very useful, especially in the solution platform. It has good features and good functionality, and our customers feel there is a lot of merit in that. I think that the portal is constantly improving. They do their own enhancements very often. They keep doing those enhancements from their site itself.
EV
Useful for risk assessment and has customization capability
The tool helps us with security incidents, policies, business continuity, disaster recovery, and internal audits. The feature I like the most is its customization capability. It acts like a blank canvas where you can construct forms and workflows according to your needs. You can configure and customize a lot yourself, whether starting from scratch or using some out-of-the-box options. The solution has impacted our operations by helping us manage and prioritize environmental risks. It also assists in establishing ownership of risks and enables us to mitigate or mediate existing risks. Additionally, it facilitates tracking risks throughout their entire lifecycle.
IMRAN ALMARZOOQI - PeerSpot reviewer
Automates compliance management effectively but needs improved interface and dashboards
The tool basically automates whatever processes you already have, so I cannot specify improvements in that regard. However, my main issue with Archer is the graphics. The graphics have always been lacking. I always need to depend on another tool to read information from Archer to have better dashboards. It is like using Linux, and it has a Linux mindset and interface. I want to use Archer for top management and CEOs, but it looks too technical, and the dashboards are not really friendly. They are bulky, like opening an old Nintendo system from nineteen-ninety. The management agrees that Archer lacks in terms of presentation and dashboarding. It is complex, not user-friendly, and bulky. The interface just looks old.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Key features are usability and ease of configuration. It allows us to have all the information in a single place and provide real-time indicators and information for our executives."
"The interface is mobile-friendly and it is getting a good response from our customers."
"The tool helps us with security incidents, policies, business continuity, disaster recovery, and internal audits. The feature I like the most is its customization capability. It acts like a blank canvas where you can construct forms and workflows according to your needs. You can configure and customize a lot yourself, whether starting from scratch or using some out-of-the-box options."
"The solution has improved my organization by having everything combined to a single platform."
"With RSA Archer, an admin can set permissions for a normal user to go directly to the tool they need to input some data. Admins can then go through that and approve some requests. Also, they can log in based on these kinds of permissions, including ticketing, service patches, or upgrades."
"Enables development of any application, automation of any workflow including the GRC work processes."
"The most valuable features are the advanced workflow and the dashboards. This tool can present data wonderfully to management, and it is easy for them to manage the risk plans."
"The most valuable features of RSA Archer are the asset management, risk management, and vendor management."
"Archer has simplified our security audits. It's made it easier to raise and trigger questionnaires to customers."
"First of all, its access control feature where it provides application level access, solution level access, and even recall access, as well."
"The most valuable part of the product is the ease-of-use and the opportunity to create custom security applications easily."
 

Cons

"I would like to see out-of-the-box integration with more security, it would be helpful."
"We would like to have more dashboards and reports, such as geographical and trend reports in the next version. Also, an improvement in the mobile version would be helpful."
"We think there's room for improvement, especially with customizing NAVEX One. Their development on the roadmap can be slow."
"GUI could be improved."
"Some areas are not truly automated but are only scheduled."
"Slow turnaround time from support team."
"The solution as a whole could be simplified."
"RSA Archer might be a bit expensive for small companies because it's a vast tool."
"There is no inbuilt alert in Archer to let us know that a data feed has failed or did not run for different reasons. So, we don't even get to know that a feed has not run until somebody reports it to us. This has been a problem all the time. Data feeds have always been a big headache for us because there is no feature to let us know if a feed has not run or has failed. If Archer had a feature to send us an email notification when a feed has failed, it would've been very helpful. This is the reason why our users are slowly moving away to another platform. Some of the modules that I have been managing are being moved to ServiceNow. Next year, a lot of our modules will be moved from RSA Archer to ServiceNow, and the data feed issue has been one of the main reasons."
"In terms of what can be improved, our client always says their user experience, IU/UX in RSA Archer. They found it is not as user friendly as other tools."
"A remaining area for improvement is integration. There should be built-in integration mechanisms, for example, for organizations switching from platforms like ServiceNow to Archer, instead of custom integrations for each client."
 

Pricing and Cost Advice

"They are flexible in terms of customers' needs."
"NAVEX One's pricing comes in the middle range when compared to other products."
"The license is costly for the solution, but the remaining set up and maintenance is quite cheaper."
"RSA Archer's price is justifiable and not as expensive, compared to ServiceNow. I have heard that the licensing for ServiceNow is much more expensive. I'm unaware whether there are any additional costs after licensing fees."
"The price of RSA Archer is good. The price isn't too high considering it is a leading tool in the market."
"Fairly highly-priced, especially for smaller companies."
"The pricing is okay. The licensing costs are very reasonable; it is very affordable to us."
"At the higher end of the price scale, but provides better, more accessible functionality and customization than cheaper products."
"The solution’s pricing is moderate."
"It is not expensive. It is reasonable. We only pay for the licensing."
report
Use our free recommendation engine to learn which GRC solutions are best for your needs.
869,952 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
26%
Computer Software Company
11%
Manufacturing Company
8%
Comms Service Provider
6%
Financial Services Firm
18%
Retailer
13%
Legal Firm
8%
Energy/Utilities Company
7%
Financial Services Firm
21%
Insurance Company
12%
Manufacturing Company
8%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
No data available
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise6
Large Enterprise25
 

Questions from the Community

What are the main differences between RSA Archer, MetricStream and IBM OpenPages?
RSA Archer, IBM OpenPages and MetricStream are the top GRC software solutions in the market today. Out of the 3, IBM ...
What is your experience regarding pricing and costs for NAVEX One?
NAVEX One's pricing comes in the middle range when compared to other products.
What needs improvement with NAVEX One?
We think there's room for improvement, especially with customizing NAVEX One. Their development on the roadmap can be...
What is your primary use case for NAVEX One?
We use the solution to conduct risk assessments on our environment.
What do you like most about RSA Archer?
It has various valuable features. For example, showing us if a control aligns with specific standards or frameworks h...
What needs improvement with RSA Archer?
While it provides benefits in terms of security, the pricing is a bit higher than customers typically expect. It woul...
What is your primary use case for RSA Archer?
Regarding the compliance, risk, and governance tools, I am comfortable discussing the tools in the GRC category. The ...
 

Comparisons

 

Also Known As

No data available
Lockpath Keylight
Archer
 

Overview

 

Sample Customers

Federal Home Loan Bank of Chicago, ACCO Brands Corporation, AgFirst Farm Credit Bank, AIB International, Associated Banc-Corp, BAE Systems, Barclaycard, Dell Inc, DIRECTV, Energizer, Fresenius Kabi, Hasbro, Goodyear, HudsonCity Savings Bank, Infigen Energy, Kaydon, Leroy Merlin, Mountry Financial Corp., Nicholas Piramal, Pepco, Pfizer, Societe Generale, Whitney Bank
Claims Recovery Financial Services (CRFS), Surescript, The University of Chicago
T-Systems, Bridge Point, Equifax, First Data, Global Imaging Company, Manulife Financial
Find out what your peers are saying about RSA, OneTrust, Diligent and others in GRC. Updated: September 2025.
869,952 professionals have used our research since 2012.