Defending IBM Sub Capacity Pricing With ILMT Evidence That Holds in an Audit
Miss the 90 day ILMT install window or a quarterly snapshot and IBM reprices the period at full physical capacity, a 6x swing worth 5.04 million dollars of back license on the worked estate.
Prepared by Redress Compliance · June 2026 · Representative IBM middleware estate scenario (benchmark scenario, not a quote)
Executive Summary
Sub capacity pricing is not a discount you are given, it is an entitlement you have to evidence. The IBM License Metric Tool is the condition: deploy it within 90 days of your first eligible sub capacity product, report quarterly, and retain the snapshots for two years, or the contract default is full physical capacity.
That default is not a rounding error. On a densely virtualized cluster, full capacity counts every physical core on every server where the product could run, not the handful of virtual cores in use. On the worked estate that is 8,400 sub capacity PVUs against 50,400 full capacity, a 6x multiplier worth 5.04 million dollars.
The failure is rarely the install. Across the IBM estates we review, the recurring causes are PVU bundle misclassification, stale or missing quarterly snapshots, and retention gaps, not a missing agent. A running ILMT server with the wrong product bundling still hands IBM a full capacity argument.
This paper sets the your side sequence: decode the contractual framework, architect ILMT to survive scrutiny, fix the bundling, recover a scan gap with the right clause, handle the PVU to VPC dual metric reporting, lock the protective levers, and run the whole thing as a multi year operation rather than an annual fire drill.
Benchmark ranges: Redress Compliance advisory engagement file, 2024 to 2025.
What does the ILMT contractual approach actually require?
Sub capacity pricing lets you license the virtual cores a workload uses rather than the full server, but the entitlement is conditional. The Passport Advantage terms require ILMT deployed within 90 days of the first eligible product, quarterly reports, and two year retention. Miss any one and the default is full capacity for the whole period.
The three obligations are independent. A perfect install does not cure a missing quarterly snapshot, and current reports do not cure a retention gap from eighteen months ago. The terms are set out in the IBM virtualization capacity licensing terms and the IBM sub capacity ILMT FAQ.
| Obligation | The requirement | The default if you miss it |
|---|---|---|
| Deployment window | ILMT installed within 90 days of first eligible sub capacity product | Full capacity from the deployment date |
| Report frequency | Generate, reconcile, and sign reports at least quarterly | Full capacity for the unreported quarters |
| Retention | Hold each snapshot for a minimum of two years | No defensible evidence for that period |
| Accuracy | Bundling and product classification correct in the tool | Disputed report, full capacity argument |
The number that focuses the mind is the multiplier. On the worked estate, three middleware products run on a shared cluster, using 120 virtual cores between them. Sub capacity licenses 8,400 PVUs; full capacity, counting all 240 physical cores per product, reaches 50,400 PVUs. That is the exposure the framework either protects or releases.
Sub capacity versus full capacity, by product (PVU)
Benchmark scenario, not a quote. Bars match the bundling table in section 3. Full capacity counts all 240 physical cores per product.
How should ILMT be architected to survive an audit?
Architect ILMT so the evidence is continuous, not reconstructed the week IBM calls. ILMT runs on BigFix Inventory: a central server with a database backend, a relay tier, and a lightweight agent on every machine that runs an eligible product. The agent discovers software and measures the peak processor capacity available to it.
Two architecture choices decide whether the data is defensible. The first is coverage. An agent missing from a host means that host is invisible, and an invisible host is an undetected full capacity exposure. The second is the scan environment for closed networks.
| Component | Role | What to get right |
|---|---|---|
| BigFix server | Central inventory and report engine | Sized for the endpoint count, patched current |
| Database backend | Stores raw scan and capacity data | Backed up so two years of snapshots survive |
| Agent fleet | Discovers software, measures capacity | Deployed on every eligible host, no gaps |
| Disconnected Scanner | Covers isolated or air gapped networks | Pre approved for ILMT Lite under 5,000 VMs |
| High availability | Keeps the report engine running | Failover so a server outage is not a gap |
The exemption is worth naming because it is misread. An organization with fewer than 1,000 employees and contractors and under 1,000 PVUs of total physical capacity, not an IBM service provider, may keep manual records instead of ILMT. The threshold sits in the IBM sub capacity FAQ overview. Most enterprises clear it on day one.
- Coverage proof: reconcile the agent fleet against the CMDB so no eligible host is unscanned.
- Disconnected path: use the Disconnected Scanner for closed segments rather than excluding them.
- Snapshot survival: protect the database so the two year evidence trail is recoverable.
Where does PVU bundling discipline break, and how do you fix it?
Bundling is where most ILMT data quietly fails. Each product must be classified against the exact part number and edition you are entitled to, because ILMT measures what it thinks is installed, and a misread edition either overstates your liability or destroys your sub capacity defense. The middleware portfolio is the usual offender.
Db2, WebSphere, and MQ each ship in multiple editions with different PVU treatment, and supporting programs bundled with a parent product must be measured under the parent, not licensed twice. The worked estate shows the sub capacity position the bundling has to defend.
| Product | Virtual cores | PVU per core | Sub capacity PVU |
|---|---|---|---|
| WebSphere Application Server ND | 50 | 70 | 3,500 |
| IBM MQ | 30 | 70 | 2,100 |
| Db2 Advanced Edition | 40 | 70 | 2,800 |
| Total sub capacity | 120 | 70 | 8,400 |
The classification mistakes cluster into a few repeat patterns. The chart shows how the failures distribute across the estates we review, and bundle misclassification leads every time.
Where ILMT sub capacity compliance fails, by cause
Benchmark scenario, not a quote. Shares of observed failures, summing to 100 percent.
What happens when you miss the 90 day rule, and how do you recover?
A missed window or an unsigned quarter is recoverable, but only if you act before the audit, not during it. The default reprices the gap at full capacity, turning a 1.01 million dollar sub capacity value into a 6.05 million dollar claim on the worked estate. The 5.04 million dollar delta is what you negotiate to avoid.
Recovery rests on rebuilding defensible evidence and on contract language that lets historical data stand. The dollar exposure makes the case for fixing it quickly.
License value at risk: sub capacity held versus full capacity claim
Benchmark scenario, not a quote. PVU totals from section 3, at a benchmark 120 dollars per PVU license value.
The recovery sequence is mechanical. Deploy or repair ILMT immediately, backfill capacity evidence from any available historical data, and document the remediation date. Then the contract work begins.
- Remediate first: get ILMT current and signed before you raise the gap with IBM.
- Backfill evidence: use VM platform logs and asset records to reconstruct peak capacity for the gap.
- Negotiate the basis: argue the true deployed position, not the theoretical full capacity, with the reconstructed data.
The contract lever that matters here is a scan gap recovery clause, agreed in advance, that lets reconstructed evidence settle a lapse at the deployed position rather than at full capacity. IBM grants it more readily inside a renewal than mid audit.
How does the PVU to VPC transition change ILMT reporting?
The move to containers does not retire ILMT, it adds a second meter. Legacy software on virtual machines stays on PVU measured by ILMT, while Cloud Pak and container workloads move to Virtual Processor Core, where one VPC equals one virtual core with no processor multiplier, measured by the IBM License Service. During the transition you run both.
That dual metric state is the new audit trap. IBM expects ILMT reports for every PVU licensed program and License Service reports for every container based program, and a product split across both must reconcile cleanly. The VPC metric is defined in the IBM License Metric Tool documentation.
| Workload state | Metric | Measured by | What to protect in writing |
|---|---|---|---|
| Legacy on VMs | PVU sub capacity | ILMT | The continued sub capacity right |
| Moving to containers | PVU to VPC | Both during cutover | The 70 to 1 conversion ratio |
| Native Cloud Pak | Virtual Processor Core | License Service | The bundled OpenShift entitlement |
| Split product | Dual metric | ILMT and License Service | No double count across the two tools |
The non obvious mechanic is the conversion ratio. IBM presents 70 PVUs to 1 VPC as a clean baseline, but the ratio is product specific and is renegotiated at the point of need unless you fix it in the agreement. Lock the ratio and the dual metric reporting obligation in writing before any workload crosses to a Cloud Pak.
Which contract levers protect the sub capacity position?
The protective clauses cost nothing at signature and remove IBM defaults later. The default position ratchets toward full capacity, leaves the conversion ratio open, and gives IBM open ended audit scope, yet each of those defaults has a clause that reverses it. Put them in the order document or a side letter.
| Lever | What it secures | The default it reverses |
|---|---|---|
| Scan gap recovery | Reconstructed evidence settles a lapse at deployed use | Automatic full capacity on any gap |
| Bundling protection | Agreed product classification stands in an audit | IBM reclassifying editions upward |
| Sub capacity floor | Confirms the sub capacity right for the term | A quiet reversion to full capacity terms |
| Dual metric clause | Fixes the 70 to 1 ratio and the reporting split | A ratio set at the point of need |
| Audit cooperation framework | Defined scope, notice, and data limits | Open ended audit and data demands |
| Executive escalation path | A named route past the account team | Stalling at the standard position |
The lever clients most often skip is the audit cooperation framework. Without defined scope and notice, an IBM verification can demand raw data well beyond the products in question, and an unbounded data request is itself a negotiation lever IBM holds over you. Bound it in advance.
How do you run ILMT as a multi year operational strategy?
Treat ILMT as a standing operation, not an annual scramble before the audit letter. Aligned with the wider IBM licensing and audit posture, the goal is continuous defensible evidence, a clean dual metric reporting state, and a base that gets smaller each year as you release shelfware. The phases set the cadence.
Establish and reconcile
- Confirm agent coverage against the CMDB.
- Correct every product bundle and edition.
- Sign the first four quarterly reports on time.
Operate and protect
- Run quarterly reviews with a named owner.
- Stand up License Service for any containers.
- Reconcile the dual metric position each quarter.
Optimize and align
- Release the shelfware ILMT has surfaced.
- Lock the protective levers at the next renewal.
- Align ILMT with the full Passport Advantage plan.
The compounding benefit is leverage. A clean two year evidence trail turns an IBM audit from an exposure into a non event, and the same data that defends the sub capacity position also surfaces the unused entitlement you negotiate away at renewal. The discipline pays twice.
Recommendation
Run ILMT as the evidence engine for your sub capacity entitlement, not as a tool you installed once. Fix the bundling, sign the quarterly snapshots, retain two years of data, handle the dual metric state, and lock the protective clauses before IBM ever asks.
- Protect the multiplier, not just the tool. On the worked estate, defensible ILMT evidence holds the position at 8,400 PVUs and 1.01 million dollars, against a 50,400 PVU, 6.05 million dollar full capacity claim if the evidence fails.
- Fix the bundling and lock the levers. Correct edition classification, agree the scan gap recovery and 70 to 1 dual metric clauses, and bound the audit scope while you hold the renewal leverage.
We are glad to tie a meaningful part of the fee to delivered value.