HomeIBM Knowledge HubIBM Red Hat Audit Defense
IBM  |  Red Hat Estate Brief 2026

Unentitled virtual guests ran 15 to 30 percent of the estate, almost always from the sprawl that followed a CentOS migration, which means the exposure was built years before the notice arrived

A Red Hat review does not count licenses. It counts running systems, and the migration that quietly multiplied them is the event that decides what the reconciliation finds.

Prepared by Redress Compliance · August 18, 2026 · IBM and Red Hat advisory. 30 to 35 estates reviewed, 2024 to 2025.

Executive summary

Unentitled virtual guests made up 15 to 30 percent of the running estate. Almost every case traced to virtualization sprawl after a CentOS migration, where guests multiplied faster than anyone reconciled subscriptions.

The opening reconciliation figure ran about three times the settlement. Across the estates reviewed it landed near a third of the first number, which makes the opening a negotiating position rather than a finding.

Simple Content Access removed the technical stop in 2021. Nothing in the platform prevents an unentitled host from pulling updates, so compliance moved from the tool to the contract and drift produces no error message.

The unit of risk is the running instance, not a license count. There is no key to count and no perpetual right to defend, so the only question a review asks is what is running now and is it entitled at the right tier.

15 to 30%
Unentitled virtual guests as a share of the running estate.
3x
The opening reconciliation figure against the number finally settled.
20 to 40%
Overstatement in OpenShift core counts sized to allocated cores.
1 in 4
Estates running production workloads on self support subscriptions.
1.

What does a Red Hat review actually count?

Running systems, not licenses. Red Hat sells subscriptions to updates and support, so the test is whether every running instance maps to an active subscription at the right tier. Terms sit in the Red Hat enterprise agreements.

That is a different exercise from an Oracle or IBM mainframe audit, which measures deployed metrics against entitlements you bought. Here there is no key to count and no perpetual right to fall back on.

ElementA license auditA Red Hat reconciliation
Unit of riskA deployed license metricA running instance, physical or virtual
The questionWhat did you buy and deployWhat is running right now and is it entitled
The remedy proposedBackdated license purchaseBackdated true up plus a forward uplift
What is not in playVaries by contractPer copy fines. This is a commercial reconciliation

The mechanics of how entitlements are counted are covered in our guide to Red Hat subscription compliance, and the sequence of a notice in audit triggers and response.

Why the distinction changes the defense

If the unit is the running instance, then your own inventory is the evidence. The estate you can describe accurately is the estate you can argue about, and everything you cannot describe gets counted the vendor's way.

2.

Why did Simple Content Access raise the risk?

Because it removed the technical stop. Before 2021 a system had to attach a subscription to receive content, which enforced compliance automatically. After it, any registered system pulls updates whether or not a matching subscription exists.

Enforcement moved from the tool to the contract. An estate can drift out of compliance for years without producing a single error message, which is precisely what makes a migration so expensive later.

The absence of a block is not the absence of an obligation. The organizations that struggle in a review are the ones that read a working update as a licensed one. Nothing in the platform was ever telling them otherwise.

Free white paper

The Red Hat negotiation and subscription brief

How entitlements are counted across RHEL and OpenShift, where the gaps hide, and the evidence pack that decides what a reconciliation settles at.

Get the brief →
3.

What 30 to 35 Red Hat estates showed

Across roughly 30 to 35 Red Hat and IBM Red Hat estates reviewed between 2024 and 2025, the opening reconciliation figure ran about three times the number finally settled at. The gap was evidence, not negotiation skill.

Unentitled virtual guests made up 15 to 30 percent of the running estate. Almost every case traced back to the same event: a CentOS to CentOS Stream shift that pushed teams onto RHEL, after which guests multiplied faster than anyone reconciled subscriptions.

OpenShift core counts were overstated by 20 to 40 percent, because subscriptions were sized to allocated cores rather than the cores actually in use. Our brief on sizing OpenShift to used cores works that arithmetic.

Self support subscriptions were carrying production workloads in one estate in four. The vendor prices that tier mismatch as a full true up, which is why support tier hygiene belongs in the inventory rather than in the response.

The pattern underneath all three is timing. Every one of these exposures was created by a decision taken well before the notice, and none of them announced itself when it happened.

Try Vera AI · free 30 day trial
Vera reads the contract before the auditor reads your estate.
  • Every risky clause flagged with the verbatim quote and the page anchor
  • Entitlements, caps and protections verified across the whole contract portfolio
  • Paste ready replacement language and an evidence trail for the response
Start the free Vera AI trial →30 days free · no credit card · cancel anytime
4.

Where does the costly exposure actually hide?

In five places, and four of them are consequences of a platform decision rather than a procurement one. RHEL and OpenShift count differently, which is where most of the argument sits.

The tier question is separate from the count

A right count at the wrong tier is still a finding. Our Red Hat subscription cost analysis covers the Premium support question, which runs in the other direction and is worth money back rather than owed.

5.

How is the opening figure argued down?

With your own subscription data, captured and reconciled before you respond. The opening number is built on the vendor's view of your estate, and the only thing that moves it is a better view produced by you.

The wider defense sequence, across IBM as well as Red Hat, is set out in our IBM audit defense brief.

Expect it to be folded into a wider IBM negotiation

Since the acquisition these reconciliations are run with more commercial discipline and often arrive attached to something larger. Our analysis of running IBM and Red Hat as one negotiation covers what that changes.

6.

What the estates measured, 2024 to 2025

Two cuts of the engagement file frame the size of the opening position.

3x
Opening against settlement

The first reconciliation figure ran about three times the number finally agreed, across the estates reviewed.

15 to 30%
Unentitled guests in the estate

As a share of running systems, almost always traceable to sprawl after a CentOS migration.

Neither number is about negotiation technique. Both describe how far the vendor's opening view of an estate sits from a reconciled one.

IBM audit briefing on timing and inventory hygieneWatch the briefing · 5:12The IBM Audit Is the Sales CallWhy timing and inventory hygiene decide the settlement before the argument about entitlement even starts.
7.

Your first five moves

  1. Inventory every running instance before you answer anything, since the unit of risk is the running system rather than a license count.
  2. Reconcile the guests created since your CentOS migration, which is where 15 to 30 percent of the exposure was found.
  3. Recount OpenShift against cores actually in use, not against allocated cores, worth 20 to 40 percent of the count.
  4. Check which production workloads sit on self support, a mismatch found in one estate in four and priced as a full true up.
  5. Treat the opening figure as a position, not a finding. The IBM practice reconciles the estate before the response goes back, which is what moved the number to a third.
8.

Frequently asked questions

Is a Red Hat audit the same as a license audit?

No. It is a subscription reconciliation. Red Hat counts running instances against active subscriptions at the right tier, so there is no license key to count and no perpetual right to defend.

What is the single biggest source of exposure?

Unentitled virtual guests, at 15 to 30 percent of the running estate. Almost every case reviewed traced to virtualization sprawl following a CentOS migration.

How far does the opening figure usually move?

A long way. Across the 30 to 35 estates reviewed the opening reconciliation ran about three times the number finally settled at, landing near a third of the first figure.

What changed with Simple Content Access?

The technical stop disappeared. Since 2021 any registered system can pull updates whether or not a matching subscription exists, so compliance became contractual and self policed rather than enforced by the platform.

Why are OpenShift counts so often wrong?

Because subscriptions get sized to allocated cores rather than to the cores actually in use, which overstated the count by 20 to 40 percent in the estates reviewed.

Does the support tier matter as much as the count?

Yes. Self support subscriptions were carrying production workloads in one estate in four, and the vendor prices that mismatch as a full true up regardless of whether the count itself is right.

Should we give the vendor access to our estate?

No. Never grant unmanaged access. Scope, evidence control and timing decide the outcome, and an estate you describe yourself is the only estate you can argue about.

Do developer subscriptions cause findings?

They do when they run production. The developer subscription is free until production appears in the ledger, at which point it converts into an ordinary entitlement gap.

Has the IBM acquisition changed how reviews run?

Yes. Reconciliations are run with more commercial discipline and are often folded into a wider IBM negotiation rather than settled as a standalone compliance matter.

What is the first thing to do on receiving a notice?

Reconcile your own subscription data before responding. The opening number is built on the vendor's view of your estate, and only a better view of your own moves it.

© 2026 Redress Compliance · Independent, buyer sideredresscompliance.com
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Independent
Free Download

The full IBM and Red Hat audit defense framework from the IBM Advisory Services.

ILMT, PVU, Red Hat subscriptions, and the response framework, decoded.

Used across more than five hundred enterprise clients. Independent. Your side. Built for procurement leaders running the next renewal cycle.

Get the white paper →
Opens the white paper landing page. We only email you about this download.
Run the IBM audit readiness assessment against your estate in under five minutes.
Open the Tool →
500+
Enterprise clients
$120M
Aggregate IBM savings
100%
Your side

Red Hat counts the running instance, not the purchase order. Win the reconciliation with your own data.

Morten Andersen
Co Founder. Ex IBM, ex Oracle.
Editorial boardroom interior

The advisor your vendors do not want.

500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.

Stay close to the your side.

Monthly intelligence on IBM, Red Hat, and enterprise software audit risk.