IBM Passport Advantage  |  ILMT Sub Capacity Compliance White Paper

Defending IBM Sub Capacity Pricing With ILMT Evidence That Holds in an Audit

Miss the 90 day ILMT install window or a quarterly snapshot and IBM reprices the period at full physical capacity, a 6x swing worth 5.04 million dollars of back license on the worked estate.

Prepared by Redress Compliance  ·  June 2026  ·  Representative IBM middleware estate scenario (benchmark scenario, not a quote)

Executive Summary

Sub capacity pricing is not a discount you are given, it is an entitlement you have to evidence. The IBM License Metric Tool is the condition: deploy it within 90 days of your first eligible sub capacity product, report quarterly, and retain the snapshots for two years, or the contract default is full physical capacity.

That default is not a rounding error. On a densely virtualized cluster, full capacity counts every physical core on every server where the product could run, not the handful of virtual cores in use. On the worked estate that is 8,400 sub capacity PVUs against 50,400 full capacity, a 6x multiplier worth 5.04 million dollars.

The failure is rarely the install. Across the IBM estates we review, the recurring causes are PVU bundle misclassification, stale or missing quarterly snapshots, and retention gaps, not a missing agent. A running ILMT server with the wrong product bundling still hands IBM a full capacity argument.

This paper sets the your side sequence: decode the contractual framework, architect ILMT to survive scrutiny, fix the bundling, recover a scan gap with the right clause, handle the PVU to VPC dual metric reporting, lock the protective levers, and run the whole thing as a multi year operation rather than an annual fire drill.

90 days
To install ILMT after the first eligible sub capacity deployment, or the period reverts to full capacity
2 years
Minimum retention for the quarterly ILMT audit snapshots, available at IBM request
6x
Full capacity exposure on the worked estate, a 5.04 million dollar back license claim if ILMT lapses
1,000 PVU
The physical capacity floor below which a small estate may keep manual records instead of ILMT
30 to 40%
Of IBM estates we review run ILMT with at least one product mis bundled against its true classification
5x to 10x
The full capacity multiplier we see on dense virtualization when sub capacity evidence fails
70 : 1
The common PVU to Virtual Processor Core conversion baseline as workloads move to Cloud Paks

Benchmark ranges: Redress Compliance advisory engagement file, 2024 to 2025.

1

What does the ILMT contractual approach actually require?

Sub capacity pricing lets you license the virtual cores a workload uses rather than the full server, but the entitlement is conditional. The Passport Advantage terms require ILMT deployed within 90 days of the first eligible product, quarterly reports, and two year retention. Miss any one and the default is full capacity for the whole period.

The three obligations are independent. A perfect install does not cure a missing quarterly snapshot, and current reports do not cure a retention gap from eighteen months ago. The terms are set out in the IBM virtualization capacity licensing terms and the IBM sub capacity ILMT FAQ.

ObligationThe requirementThe default if you miss it
Deployment windowILMT installed within 90 days of first eligible sub capacity productFull capacity from the deployment date
Report frequencyGenerate, reconcile, and sign reports at least quarterlyFull capacity for the unreported quarters
RetentionHold each snapshot for a minimum of two yearsNo defensible evidence for that period
AccuracyBundling and product classification correct in the toolDisputed report, full capacity argument

The number that focuses the mind is the multiplier. On the worked estate, three middleware products run on a shared cluster, using 120 virtual cores between them. Sub capacity licenses 8,400 PVUs; full capacity, counting all 240 physical cores per product, reaches 50,400 PVUs. That is the exposure the framework either protects or releases.

Sub capacity versus full capacity, by product (PVU)

Benchmark scenario, not a quote. Bars match the bundling table in section 3. Full capacity counts all 240 physical cores per product.

18K 9K 0 3,500 16,800 WebSphere 2,100 16,800 IBM MQ 2,800 16,800 Db2 Sub capacity (ILMT held) Full capacity (ILMT failed)
2

How should ILMT be architected to survive an audit?

Architect ILMT so the evidence is continuous, not reconstructed the week IBM calls. ILMT runs on BigFix Inventory: a central server with a database backend, a relay tier, and a lightweight agent on every machine that runs an eligible product. The agent discovers software and measures the peak processor capacity available to it.

Two architecture choices decide whether the data is defensible. The first is coverage. An agent missing from a host means that host is invisible, and an invisible host is an undetected full capacity exposure. The second is the scan environment for closed networks.

ComponentRoleWhat to get right
BigFix serverCentral inventory and report engineSized for the endpoint count, patched current
Database backendStores raw scan and capacity dataBacked up so two years of snapshots survive
Agent fleetDiscovers software, measures capacityDeployed on every eligible host, no gaps
Disconnected ScannerCovers isolated or air gapped networksPre approved for ILMT Lite under 5,000 VMs
High availabilityKeeps the report engine runningFailover so a server outage is not a gap

The exemption is worth naming because it is misread. An organization with fewer than 1,000 employees and contractors and under 1,000 PVUs of total physical capacity, not an IBM service provider, may keep manual records instead of ILMT. The threshold sits in the IBM sub capacity FAQ overview. Most enterprises clear it on day one.

3

Where does PVU bundling discipline break, and how do you fix it?

Bundling is where most ILMT data quietly fails. Each product must be classified against the exact part number and edition you are entitled to, because ILMT measures what it thinks is installed, and a misread edition either overstates your liability or destroys your sub capacity defense. The middleware portfolio is the usual offender.

Db2, WebSphere, and MQ each ship in multiple editions with different PVU treatment, and supporting programs bundled with a parent product must be measured under the parent, not licensed twice. The worked estate shows the sub capacity position the bundling has to defend.

ProductVirtual coresPVU per coreSub capacity PVU
WebSphere Application Server ND50703,500
IBM MQ30702,100
Db2 Advanced Edition40702,800
Total sub capacity120708,400

The classification mistakes cluster into a few repeat patterns. The chart shows how the failures distribute across the estates we review, and bundle misclassification leads every time.

Where ILMT sub capacity compliance fails, by cause

Benchmark scenario, not a quote. Shares of observed failures, summing to 100 percent.

Bundle misclassification 40% Scan or report gaps 30% Retention or snapshot gaps 18% Agent coverage gaps 12%
Where the common advice on ILMT is wrong: the standard reseller line is that installing ILMT makes you compliant, so the project is an IT deployment that ends at go live. We disagree. In roughly a third of the estates we review, ILMT is running and the sub capacity position still fails, because a product is bundled to the wrong edition, a quarter went unsigned, or an air gapped segment was never scanned. The agent is the easy 20 percent. The counter move is to treat ILMT as a quarterly evidence discipline with a named owner who reconciles bundling against entitlement and signs the report, not as a tool you switch on and forget.
4

What happens when you miss the 90 day rule, and how do you recover?

A missed window or an unsigned quarter is recoverable, but only if you act before the audit, not during it. The default reprices the gap at full capacity, turning a 1.01 million dollar sub capacity value into a 6.05 million dollar claim on the worked estate. The 5.04 million dollar delta is what you negotiate to avoid.

Recovery rests on rebuilding defensible evidence and on contract language that lets historical data stand. The dollar exposure makes the case for fixing it quickly.

License value at risk: sub capacity held versus full capacity claim

Benchmark scenario, not a quote. PVU totals from section 3, at a benchmark 120 dollars per PVU license value.

$6M $3M $0 $1.01M Sub capacity held $6.05M Full capacity claim A 5.04 million dollar exposure rides on the ILMT evidence

The recovery sequence is mechanical. Deploy or repair ILMT immediately, backfill capacity evidence from any available historical data, and document the remediation date. Then the contract work begins.

The contract lever that matters here is a scan gap recovery clause, agreed in advance, that lets reconstructed evidence settle a lapse at the deployed position rather than at full capacity. IBM grants it more readily inside a renewal than mid audit.

5

How does the PVU to VPC transition change ILMT reporting?

The move to containers does not retire ILMT, it adds a second meter. Legacy software on virtual machines stays on PVU measured by ILMT, while Cloud Pak and container workloads move to Virtual Processor Core, where one VPC equals one virtual core with no processor multiplier, measured by the IBM License Service. During the transition you run both.

That dual metric state is the new audit trap. IBM expects ILMT reports for every PVU licensed program and License Service reports for every container based program, and a product split across both must reconcile cleanly. The VPC metric is defined in the IBM License Metric Tool documentation.

Workload stateMetricMeasured byWhat to protect in writing
Legacy on VMsPVU sub capacityILMTThe continued sub capacity right
Moving to containersPVU to VPCBoth during cutoverThe 70 to 1 conversion ratio
Native Cloud PakVirtual Processor CoreLicense ServiceThe bundled OpenShift entitlement
Split productDual metricILMT and License ServiceNo double count across the two tools

The non obvious mechanic is the conversion ratio. IBM presents 70 PVUs to 1 VPC as a clean baseline, but the ratio is product specific and is renegotiated at the point of need unless you fix it in the agreement. Lock the ratio and the dual metric reporting obligation in writing before any workload crosses to a Cloud Pak.

6

Which contract levers protect the sub capacity position?

The protective clauses cost nothing at signature and remove IBM defaults later. The default position ratchets toward full capacity, leaves the conversion ratio open, and gives IBM open ended audit scope, yet each of those defaults has a clause that reverses it. Put them in the order document or a side letter.

LeverWhat it securesThe default it reverses
Scan gap recoveryReconstructed evidence settles a lapse at deployed useAutomatic full capacity on any gap
Bundling protectionAgreed product classification stands in an auditIBM reclassifying editions upward
Sub capacity floorConfirms the sub capacity right for the termA quiet reversion to full capacity terms
Dual metric clauseFixes the 70 to 1 ratio and the reporting splitA ratio set at the point of need
Audit cooperation frameworkDefined scope, notice, and data limitsOpen ended audit and data demands
Executive escalation pathA named route past the account teamStalling at the standard position

The lever clients most often skip is the audit cooperation framework. Without defined scope and notice, an IBM verification can demand raw data well beyond the products in question, and an unbounded data request is itself a negotiation lever IBM holds over you. Bound it in advance.

7

How do you run ILMT as a multi year operational strategy?

Treat ILMT as a standing operation, not an annual scramble before the audit letter. Aligned with the wider IBM licensing and audit posture, the goal is continuous defensible evidence, a clean dual metric reporting state, and a base that gets smaller each year as you release shelfware. The phases set the cadence.

Year 1

Establish and reconcile

  • Confirm agent coverage against the CMDB.
  • Correct every product bundle and edition.
  • Sign the first four quarterly reports on time.
Year 2

Operate and protect

  • Run quarterly reviews with a named owner.
  • Stand up License Service for any containers.
  • Reconcile the dual metric position each quarter.
Year 3

Optimize and align

  • Release the shelfware ILMT has surfaced.
  • Lock the protective levers at the next renewal.
  • Align ILMT with the full Passport Advantage plan.

The compounding benefit is leverage. A clean two year evidence trail turns an IBM audit from an exposure into a non event, and the same data that defends the sub capacity position also surfaces the unused entitlement you negotiate away at renewal. The discipline pays twice.

Recommendation

Run ILMT as the evidence engine for your sub capacity entitlement, not as a tool you installed once. Fix the bundling, sign the quarterly snapshots, retain two years of data, handle the dual metric state, and lock the protective clauses before IBM ever asks.

  • Protect the multiplier, not just the tool. On the worked estate, defensible ILMT evidence holds the position at 8,400 PVUs and 1.01 million dollars, against a 50,400 PVU, 6.05 million dollar full capacity claim if the evidence fails.
  • Fix the bundling and lock the levers. Correct edition classification, agree the scan gap recovery and 70 to 1 dual metric clauses, and bound the audit scope while you hold the renewal leverage.

We are glad to tie a meaningful part of the fee to delivered value.

Prepared by Redress Complianceredresscompliance.com
Data center server racks with network cabling supporting virtualized IBM middleware workloads

Defending IBM sub capacity?

Talk to a negotiation advisor. Thirty minutes, your ILMT evidence, and a sub capacity position sized to what you run, not the full physical capacity.

Negotiation intelligence, monthly

One letter a month. Negotiation moves, audit signals, and price book shifts.