Aisle of server racks in a data center
IBM Sub Capacity

IBM sub capacity licensing and ILMT compliance. What keeps the discount, and what loses it.

How IBM counts virtual cores, the four ILMT conditions behind sub capacity, what a coverage gap costs in an audit, and how containers change the evidence you keep.

Contact Us IBM Advisory
500+Enterprise clients
$2B+Under advisory
PublishedFebruary 25, 2025UpdatedSeptember 24, 2026
ContentsKey takeawaysHow sub capacity worksThe four ILMT conditionsHow gaps become claimsChecking your coverageContainers and Cloud PaksWhat we have seenAuditor lines and repliesWhat to do nextFAQ

Sub capacity allows you to license IBM software to the virtual cores it can use instead of the whole host. It holds only while ILMT scans every host and you keep two years of quarterly reports. Break either condition and IBM counts every physical core.

Key takeaways
  • Full capacity is the default. Sub capacity is an exception you earn each quarter, and in an audit the burden is on you to prove it.
  • Four conditions, every quarter. ILMT installed within 90 days of the first eligible deployment, scanning every host, reporting at least quarterly, with reports kept for two years.
  • Manual counting has ended. IBM stopped accepting the small company and unsupported technology exceptions in 2023, so every sub capacity claim now needs an approved tool.
  • Partial coverage is the usual failure. In 1 in 3 environments we reviewed, ILMT was running but missed hosts, and each missed host is priced at its full physical core count.
  • Containers need a second tool. Cloud Paks and containerized products are measured by the IBM License Service, which has its own 90 day, quarterly and two year duties.
  • Give ILMT a financial owner. Treat the quarterly reconciliation as a finance control, because it protects the largest discount in your IBM contract.

How does IBM sub capacity licensing work?

Sub capacity licensing allows you to license a core based IBM product to the virtual cores it can use, instead of every core in the physical host as full capacity does. On a consolidated virtualization platform the gap is routinely 4 to 8 times, which makes sub capacity the most valuable right in your IBM contract.

Under the PVU metric, IBM assigns a value per core by processor type, and a product needs the sum of those values across the cores it can use. Sub capacity counts only the virtual cores allocated to the product, at the quarterly peak, capped at the physical host. The counting rules per metric are in our PVU sub capacity guide.

The three ways IBM can count a core based product
Counting basisWhat is licensedWhen it applies
Sub capacityThe virtual cores allocated to the product, measured at peak within each quarterOnly while every eligibility condition holds: tool, scanning, reporting, retention
Full capacityEvery physical core in the host, whatever the product touchesThe automatic fallback whenever a condition breaks, applied to the whole broken period
Container licensing, VPCVirtual Processor Cores metered by the IBM License ServiceCloud Paks and containerized deployments, where ILMT cannot measure

Which metrics and platforms qualify?

Three metrics are eligible: Processor Value Unit (PVU), Resource Value Unit MAPC (RVU MAPC) and Virtual Processor Core (VPC). The product must also run on virtualization and processor technologies from IBM's eligible lists, or it is licensed at full capacity whatever tool you run. Current PVU values per processor are in the IBM PVU table.

Why is full capacity the default and not a penalty?

Your contract grants sub capacity as an exception that you earn continuously. Full capacity is the standard basis, and it returns the moment the conditions stop being met. That changes who carries the burden in an audit.

IBM does not have to prove you owe full capacity. You have to prove you earned the discount, quarter by quarter, with reports you still have.
Watch the briefingResearch briefing · 5:44

The IBM Audit Is the Sales Call: Timing and ILMT Hygiene Decide It

What does IBM require to keep sub capacity eligibility?

IBM requires four things, and all of them must hold in every quarter. Eligibility behaves like a chain, so one weak quarter or one missed host is enough to lose the discount for that period.

  • Installed in time. The IBM License Metric Tool (ILMT) must be deployed within 90 days of your first sub capacity eligible deployment. A tool installed late earns the discount only from the installation date forward.
  • Scanning everything. The agent must cover every host running PVU products, on the tool's half hour scan cycle. Every unscanned host is a full capacity host, whatever the rest of your environment shows.
  • Reported quarterly. Reports must be generated at least every quarter. IBM's terms describe the quarter as the longest period allowed before you analyze, reconcile and sign the ILMT reports.
  • Retained for two years. The reports must still exist when the audit arrives. Generating them without keeping them earns nothing.

IBM also expects you to run the current version of ILMT and install updates promptly, so a server left on an old release since the original rollout is a compliance gap of its own. Our ILMT deployment guide covers installation and configuration.

Is there still a manual exception for small companies?

No, IBM closed it in 2023. It once accepted manual counting from companies with fewer than 1,000 employees and contractors and under 1,000 PVUs of capacity, and for virtualization ILMT did not support. Those exceptions ended on May 1, 2023, and manual reporting for unsupported technologies was honored only until January 1, 2024.

Which tools does IBM accept besides ILMT?

IBM lists HCL BigFix Inventory and Flexera One IT Asset Management, including its Select and IBM Observability editions, as validated alternatives. The same coverage, reporting and retention duties apply. For smaller environments, IBM lists the ILMT Lite configuration with the disconnected scanner as pre approved when fewer than 5,000 VMs or LPARs are in scope.

Free white paper

IBM Audit Defense Guide

The ILMT health check and the sub capacity evidence pack IBM auditors ask for, in one download.

Get the white paper →

How does a broken ILMT deployment become an IBM audit claim?

A gap in ILMT coverage allows the auditor to reprice affected hosts at full capacity without proving any real over deployment. That is why IBM audits, usually carried out by third party firms on IBM's behalf, ask about ILMT first. It is the highest yield finding available to them.

A product using 8 virtual cores on a 64 core host reprices from 8 cores to 64 as soon as coverage fails, and the assessment reaches back across the whole period you cannot prove. Back support is then added to the license shortfall.

How an ILMT finding is priced
  • License fees. The shortfall between full capacity and your entitlement, charged as new licenses.
  • Back support. Roughly 20 percent a year of those fees.
  • The two year limit. IBM's Passport Advantage agreement charges back support for the shorter of the period of excess use or two years, so this layer adds up to about 40 percent of the license shortfall.

Our audit penalties guide works through the full claim construction, and the audit defense playbook sets out the response sequence once a letter arrives.

A worked example: three hosts, one outside the scan

Say you run WebSphere Application Server on three two socket Intel Xeon hosts, rated at 70 PVUs per core. Host A has 64 cores with 8 WebSphere vCPUs, host B has 48 cores with 12, and host C has 32 cores with 6. Host C was added last year and never got an ILMT agent, and you own 1,820 PVUs.

Hypothetical WebSphere position under three coverage scenarios, with each VM staying on its host
ScenarioCores countedPVUs requiredShortfall against 1,820 PVUs owned
All three hosts scanned and reported8 + 12 + 6 = 261,820None
Host C outside the scan scope8 + 12 + 32 = 523,6401,820 PVUs
No ILMT evidence for the period64 + 48 + 32 = 14410,0808,260 PVUs

One missed host doubles the requirement. Losing all evidence multiplies it by about 5.5, inside the range we see in audits. Add back support of up to two years and the no evidence case becomes a claim for 8,260 PVUs at your license price, plus up to about 40 percent on top.

Why a green ILMT dashboard is weak evidence

The usual advice is to confirm ILMT runs and its dashboard shows healthy scans, then treat sub capacity as settled. We disagree, since the dashboard reports only on agents ILMT knows, and the costly findings in our reviews came from hosts outside the scan scope. Check ILMT against an independent host inventory every quarter instead.

Engineer working at a desk in front of several monitoring dashboards
A scan health view covers the agents ILMT has registered. A cluster built after the rollout, or a segment the scanner cannot reach, has to be found by comparing ILMT with vCenter or the CMDB.

How do you check your own ILMT coverage?

You check coverage by reconciling three lists every quarter: the hosts that run IBM products, the hosts ILMT scans, and the reports you have archived. Any host on the first list and missing from the second is full capacity exposure. Any quarter missing from the third is a period you cannot prove.

  1. Build the host list independently. Export hosts and clusters from vCenter, the PowerVM HMC or your CMDB, and mark every one running an IBM PVU product.
  2. Match hosts to reporting agents. Compare that list with the computers ILMT reports, and investigate every host with no agent or an outdated scan.
  3. Check the VM manager connections. On VMware and Hyper-V, ILMT reads host capacity through connections to the VM managers. Expired credentials or a new vCenter that was never registered leave ILMT without the host data it needs.
  4. Review software classification. Confirm that each discovered component is assigned to the product and license you actually own, so bundled components are not counted twice or against the wrong part.
  5. Keep the software catalog current. ILMT identifies products through IBM's catalog, and an old catalog misses newer releases.
  6. Archive the audit snapshot. Export the quarterly audit snapshot, have it signed, and store it where the IBM owner can retrieve it two years later.

Run this once before you rely on any ILMT figure in a renewal. Our ILMT sub capacity guide covers the report settings in more detail.

How does this differ for a small and a large IBM customer?

A company with a few hundred VMs on one vCenter can usually cover everything with a single ILMT server or the disconnected scanner. Its usual failures are simple: the person who installed ILMT left, and no one took over the quarterly report. The fix is a named owner and a calendar reminder.

A company with 20,000 VMs across several vCenters, PowerVM frames and segmented networks fails differently. Agents drop out behind firewalls, relays fall behind, and new clusters appear faster than the ILMT team hears about them. At that size the reconciliation needs to be automated against the CMDB, with a report of unmatched hosts reviewed every month.

How are Cloud Paks and containerized IBM products measured?

Containerized IBM software and Cloud Paks are licensed on the Virtual Processor Core metric, measured by the IBM License Service running inside the cluster. ILMT cannot see Kubernetes workloads, so the License Service takes its place for containers. The principle is the same, license what the workload uses, but the tooling, reports and audit trail form a separate system.

IBM applies matching duties. The License Service must be deployed within 90 days of your first eligible container deployment, and its usage reports must be generated each quarter and kept for two years. Without it, IBM charges for all cores in the entire cluster.

What changes when WebSphere or Db2 runs on OpenShift?

Moving WebSphere or Db2 into containers adds a second measurement duty on top of the first. IBM states that a hybrid environment needs both tools, so ILMT keeps covering the VMs, the License Service covers the clusters, and your quarterly evidence now comes from two sources.

  • Before the first container deployment. Put the License Service into the cluster build, so the 90 day clock never runs out unnoticed.
  • At each quarter end. Archive the License Service report next to the ILMT audit snapshot.
  • When a workload migrates. Retire the old VMs from ILMT scope once the container version runs, so the same product is not counted twice.

Our Cloud Pak licensing guide covers the VPC mechanics and the ratios behind Cloud Pak entitlements, and the Red Hat integration analysis explains how OpenShift sits underneath it all.

What have we seen in recent IBM audits and reviews?

Across roughly 15 to 25 IBM audits and reviews that Morten Andersen and the Redress team supported between 2024 and 2026, missing or broken ILMT was the most expensive single finding. It cost more than any real over deployment we found.

  • Full capacity against real use. Hosts running PVU products without tool coverage were assessed at the whole physical machine, 4 to 8 times actual consumption.
  • Partial scan coverage. In 1 in 3 of the environments we reviewed, ILMT was deployed but did not scan every host. Agent failures, network segmentation and unregistered clusters were the causes, and the dashboards still looked healthy.
  • Reports generated but lost. In 2 in 5 environments, quarterly reports existed at some point but had not been retained, which broke the two year audit trail.

The common cause was ownership. A project installed ILMT, no team inherited it, and an audit found it broken. The companies that fared best treated ILMT output as a quarterly financial control, reviewed with the same care as the invoices it protects.

What will IBM or its auditor say, and how should you respond?

Expect the ILMT questions in the first data request, and answer each one with evidence and a clear scope. These are the lines we hear most often, with the replies we recommend.

Typical audit lines and replies
What you will hearWhat to say back
"Please run our collection scripts on all servers."We will provide ILMT audit snapshots for the audit period. Scripts can run only on hosts ILMT does not cover, on a list we agree in writing.
"Two quarterly reports are missing, so the whole period is full capacity."Full capacity applies to the quarters we cannot evidence. The reports we hold cover the rest, and we will show VM configuration history for the gap.
"Some hosts in the cluster were not scanned, so we will count the cluster."Show us where the product was installed. The claim should cover the unscanned hosts that ran it, each capped at its own physical cores.
"A new agreement or Cloud Pak purchase would resolve this finding."Price the finding on its own first, in writing. We will consider any purchase separately, against that number.

Which contract terms protect sub capacity?

Ask for these at renewal or in a settlement. None of them is standard, but each one narrows the exposure described above.

  • A closed compliance period. The settlement should state that all use up to a named date is resolved and that sub capacity applies from that date, so the same quarters cannot be reopened.
  • A cure period for coverage gaps. Ask for written notice and a fixed number of days to add a missed host to ILMT before full capacity applies to it.
  • Per host scope. Full capacity, if it applies, should cover only the physical hosts where the product ran, never a whole cluster or data center.
  • Audit notice and frequency. Set a minimum notice period and a limit of one audit in a set number of years. Our guide to audit clause redlines gives wording.

What to do next

  1. Now. Give ILMT an owner with a financial mandate as well as an operational one, and put its quarterly review on the finance calendar.
  2. This quarter. Reconcile scan coverage against the deployment inventory. Match every host running a PVU product to a reporting ILMT agent. The difference is your full capacity exposure.
  3. At every quarter end. Archive the signed reports for two years, somewhere an audit can reach them even if the ILMT server is rebuilt.
  4. Before any container go live. Deploy the IBM License Service wherever Cloud Paks and containerized products run. ILMT does not see them, and the same rules apply there.
  5. Six months before renewal. Price your own full capacity exposure before IBM does. Run the worst case on every coverage gap, fix the cheap ones, and take the evidence into any audit or renewal.
  6. If you want help. Our IBM practice and the IBM assessment tools run the reconciliation with you.

Frequently asked questions

What is IBM sub capacity licensing?

It is the right to license core based IBM products on the PVU, RVU MAPC and VPC metrics to the virtual cores the product can use rather than every core in the physical host. On consolidated virtualization platforms the saving is large, which is why eligibility discipline is often worth more than a negotiated discount.

Is ILMT mandatory for sub capacity licensing?

Yes, or one of the validated alternatives IBM lists. Eligibility requires the tool within 90 days of the first eligible deployment, scanning every relevant host, with quarterly reports generated and kept for two years. The old manual route for very small companies closed in 2023, so running virtualized IBM software without a tool means full capacity exposure.

What happens if ILMT is missing or broken during an IBM audit?

The hosts you cannot evidence are repriced at every physical core for the period coverage cannot be proven, with back support of roughly 20 percent a year on the shortfall. Partial coverage is priced the same way, host by host, so a single unscanned cluster can produce a claim on a fully licensed product.

Can we install ILMT after the fact to fix exposure?

Installing ILMT protects future quarters only. IBM allows a window to deploy the tool, but sub capacity applies from the date eligibility is actually met, so the broken period stays exposed. Install at once, then negotiate the historical period, which settles far better once you can show a working control.

How does sub capacity work for containers and Cloud Paks?

Through the Virtual Processor Core metric, measured by the IBM License Service running inside each cluster, since ILMT cannot see Kubernetes workloads. The evidence duties mirror ILMT: deployment on time, quarterly reports and retention. Companies that containerized workloads without adding the License Service have recreated the missing tool problem on a newer platform.

How often should ILMT reports be generated and kept?

At least once a quarter, kept for two years, and reconciled against the host inventory each cycle so unscanned hosts show up before an auditor finds them. In 2 in 5 environments we reviewed, reports had been produced but not kept, which leaves you as exposed as never running the tool.

Does IBM charge for the License Metric Tool?

No, IBM provides ILMT at no charge to customers using sub capacity licensing. You pay for the servers it runs on and for the people who keep agents and VM manager connections healthy and file the quarterly reports. Budget that work as a cost of the discount, since it protects a far larger license bill.

Newsletter
Licensing news that changes what you pay

One email a week on vendor price moves, audit activity and what worked in recent renewals.

Subscribe
Vendor Shield
An advisor on call for every vendor conversation

Always on advisory for renewals, audits and contract questions across your software vendors.

Explore Vendor Shield
Advisory White Paper

Get the IBM audit defense guide.

The ILMT health check, the sub capacity evidence pack, the counterarguments to full capacity claims, and the settlement structures that close IBM audits.

Gated with a work email on the download page. No sales follow up you did not ask for.

Get the White Paper →
We never share your details with vendors.

IBM licensing news, once a week.

Price changes, audit activity and what worked in recent renewals. No vendor spin.