Comparison · z/OS security

ACF2 vs Top Secret vs RACF: the deepest switch on the platform.

Broadcom (CA) ACF2, Broadcom (CA) Top Secret, and IBM RACF are the three external security managers for z/OS. All price on capacity, but ACF2 and Top Secret are separate Broadcom line items while RACF rides inside the z/OS stack. Because the security manager mediates every access decision, switching is the hardest migration on the mainframe, so licensing structure and leverage decide this, not the feature sheet.

№ 01

The verdict

Incumbency winsSwitch on strategy

Keep the security manager you run and negotiate it hard. ACF2, Top Secret, and RACF all do the job, and the external security manager is the single deepest dependency on z/OS, mediating every access decision through rules and exits built up over decades. A migration is a major staged program with real operational risk, justified by consolidation or vendor strategy, not by the licensing line. Where it matters most is leverage: for the two Broadcom products, a credible, prepared evaluation of the alternative disciplines the renewal, and the standing option to consolidate security into the IBM stack is itself a lever. The prize is almost always a better deal on the incumbent.

№ 02

Head to head

Side by side

The function is close across all three. The differences that decide cost sit in who owns it and how it is licensed:

ACF2 vs Top Secret vs RACF, the licensing levers compared
DimensionCA ACF2CA Top SecretIBM RACF
VendorBroadcom (CA)Broadcom (CA)IBM
DeliveryStandalone ESM productStandalone ESM productIBM Security Server component of z/OS
Licensing metricMSU capacityMSU capacityz/OS MLC, sub-capacity via SCRT
Contract vehicleBroadcom portfolio or MCLBroadcom portfolio or MCLInside the z/OS stack entitlement
Negotiated asNamed Broadcom line itemNamed Broadcom line itemBound into the z/OS position
Switching costVery highVery highVery high

Directional and pattern level. Delivery, components, and consumption terms evolve, so confirm the current packaging, the SCRT position for RACF, and the Broadcom agreement terms in your own schedules before modeling a renewal or a migration.

№ 03

Who should pick which

Decision

For almost every estate this is a renewal and leverage question, not a procurement one. Use it this way:

Stay with the incumbent and negotiate if

  • The security manager is woven into your rules, exits, automation, and audit posture, as it always is
  • You run ACF2 or Top Secret and a prepared evaluation of the alternative, including a move to RACF, gives you a credible lever
  • Right sizing the licensed MSU and choosing the Broadcom vehicle deliberately captures most of the available saving

Genuinely consider migrating if

  • You are consolidating security strategy into the IBM stack and want RACF inside the z/OS entitlement
  • A wider Broadcom or IBM negotiation makes the migration cost ride on a program that is happening anyway
  • Vendor strategy or support direction makes the incumbent untenable on its own terms

Either way, treat the security manager migration as a security program with its own risk governance, never as a line on a cost spreadsheet, and use the alternative primarily to discipline the renewal you actually face.

№ 04

Frequently asked

FAQ
Q1
How are they licensed?All on capacity. ACF2 and Top Secret on MSU as Broadcom line items, often inside a portfolio or MCL deal. RACF rides inside the z/OS MLC entitlement via SCRT.
Q2
Is switching worth it?Rarely as a cost play. The security manager is the deepest dependency on z/OS, so migration is a strategic, risk governed program, not a licensing exercise.
Q3
What decides the cost?Which side of the IBM versus Broadcom line you sit on, the contract vehicle and bundle, and your incumbency plus a credible, prepared alternative.
Q4
What is the first lever?For ACF2 or Top Secret, right size the licensed MSU and prepare the alternative as leverage. For RACF, manage the z/OS sub-capacity position.

The hardest thing to move on the platform. Use that, do not fight it.

Audit notice or renewal under 18 months out? We mobilize within 48 hours.

The switch you will not make is your leverage. We make it count.

Get expert help