Rocket launches z/Assurance for IBM Z risk & compliance
Thu, 10th Sep 2026 (Today)
Rocket Software has launched Rocket z/Assurance, a risk and compliance management portfolio for IBM Z environments. It is aimed at organisations running critical systems on mainframes and across hybrid estates.
The portfolio brings together tools to identify vulnerabilities, check security controls, monitor compliance readiness and assess remediation priorities across IBM Z systems. It also covers hybrid environments that include mainframes, reflecting how many large organisations run their infrastructure.
The launch comes as security teams face faster discovery and exploitation of vulnerabilities linked to artificial intelligence tools. Rocket Software also pointed to longer-term concerns about quantum computing and its implications for cryptography and data protection.
A commissioned study by Researchscape highlighted the scale of concern among technology leaders. According to the findings, only 24% of IT leaders were extremely confident in their organisation's ability to address mainframe vulnerabilities over the next year.
Portfolio scope
Rocket z/Assurance includes a set of products focused on different parts of security and compliance operations in IBM Z environments. These include tools for code-level vulnerability analysis, continuous monitoring of new exposures, visibility into missing security patches, automated policy adherence checks, and reviews of cryptographic inventories and quantum-related exposure across z/OS, z/VM and Linux on Z.
The portfolio is intended to give security and IT teams real-time visibility into risk and a clearer basis for remediation decisions. Rocket Software is also positioning the software as a way to produce evidence for audits and broader governance reviews.
One part of the announcement concerns planned agentic artificial intelligence functions. Rocket Software said it intends to add AI features to help teams interpret findings, prioritise fixes and access remediation guidance in plain language.
The planned addition reflects a broader shift in cybersecurity operations, as suppliers use AI to reduce manual triage while also responding to the security threats the technology creates. In heavily regulated environments such as banking, government and large-scale enterprise IT, the need to show that controls are working remains central to buying decisions.
IBM Z systems still sit at the core of many transaction-heavy industries and often form part of wider hybrid environments rather than standalone estates. That makes governance and visibility harder, particularly when security teams must track risk across a mix of older and newer platforms.
Rocket Software has long focused on tools for mainframe modernisation and infrastructure software, and the new portfolio fits that position in the market. The aim is to help organisations modernise critical systems without weakening security or governance.
Phil Buckellew, President of Infrastructure Modernisation at Rocket Software, outlined how the company views the role of risk visibility in technology decisions. "Modernisation decisions increasingly depend on an organisation's ability to understand and manage risk across its most critical systems," he said.
He added: "When leaders have clear visibility into where risk exists and confidence that their IBM Z environments remain protected, security becomes an enabler of innovation and modernisation rather than a barrier to progress. It allows organisations to move faster, make informed decisions, and focus resources where they can have the greatest impact."
Rocket Software said 99% of enterprises operate hybrid environments that include mainframes, a point it used to argue that perimeter controls and static checks are no longer sufficient on their own. In that setting, it is targeting teams that need continuous monitoring, patch visibility and evidence that policies are being enforced across core systems.
The emphasis on quantum-related exposure also shows how suppliers are broadening the definition of security preparedness beyond today's active threats. For organisations with long data retention periods or regulated records, understanding where cryptographic methods are used has become part of longer-term planning as well as present-day compliance work.
The portfolio is designed to connect technical findings to business-relevant risk and help teams decide where to act first across critical IBM Z environments.