① Comparison · z/OS security
Broadcom (CA) ACF2, Broadcom (CA) Top Secret, and IBM RACF are the three external security managers for z/OS. All price on capacity, but ACF2 and Top Secret are separate Broadcom line items while RACF rides inside the z/OS stack. Because the security manager mediates every access decision, switching is the hardest migration on the mainframe, so licensing structure and leverage decide this, not the feature sheet.
Keep the security manager you run and negotiate it hard. ACF2, Top Secret, and RACF all do the job, and the external security manager is the single deepest dependency on z/OS, mediating every access decision through rules and exits built up over decades. A migration is a major staged program with real operational risk, justified by consolidation or vendor strategy, not by the licensing line. Where it matters most is leverage: for the two Broadcom products, a credible, prepared evaluation of the alternative disciplines the renewal, and the standing option to consolidate security into the IBM stack is itself a lever. The prize is almost always a better deal on the incumbent.
The function is close across all three. The differences that decide cost sit in who owns it and how it is licensed:
| Dimension | CA ACF2 | CA Top Secret | IBM RACF |
|---|---|---|---|
| Vendor | Broadcom (CA) | Broadcom (CA) | IBM |
| Delivery | Standalone ESM product | Standalone ESM product | IBM Security Server component of z/OS |
| Licensing metric | MSU capacity | MSU capacity | z/OS MLC, sub-capacity via SCRT |
| Contract vehicle | Broadcom portfolio or MCL | Broadcom portfolio or MCL | Inside the z/OS stack entitlement |
| Negotiated as | Named Broadcom line item | Named Broadcom line item | Bound into the z/OS position |
| Switching cost | Very high | Very high | Very high |
Directional and pattern level. Delivery, components, and consumption terms evolve, so confirm the current packaging, the SCRT position for RACF, and the Broadcom agreement terms in your own schedules before modeling a renewal or a migration.
For almost every estate this is a renewal and leverage question, not a procurement one. Use it this way:
Stay with the incumbent and negotiate if
Genuinely consider migrating if
Either way, treat the security manager migration as a security program with its own risk governance, never as a line on a cost spreadsheet, and use the alternative primarily to discipline the renewal you actually face.
The hardest thing to move on the platform. Use that, do not fight it.
Explainers: Workload License Charges history and variants and what auditors test. Other comparisons: MainView vs SYSVIEW and BMC vs Broadcom. Hubs and commercial: the Broadcom (CA) buyer side guide, the IBM buyer side guide, Broadcom (CA) license negotiation, and IBM contract review.
Audit notice or renewal under 18 months out? We mobilize within 48 hours.