Mr.PlanB Logo
    Enterprise Backup Ledger 2026
    Ledger
    Enterprise Backup Ledger 2026

    Acronis Cyber Protect: Enterprise Backup Ledger 2026

    Acronis is extending combined protection and recovery across additional hypervisors.

    Edition October 3, 20266 min read

    Part of the Enterprise Backup Ledger (edition 2026-10-03). How the scores work: methodology.

    Snapshot

    • Tier: Mid-market / MSP
    • Owner: EQT majority acquisition proposed 2024-08-07; investor portfolio records 2025 entry, exact closing day unresolved.
    • Licence model: Standard/Advanced/Backup Advanced subscription and legacy perpetual; cloud metrics and peak-usage billing are separate.
    • Products scored: Cyber Protect 17.1 and maintained 15; cloud agent/console/DR features explicitly distinguished from on-prem software.
    • Latest release: 17.1.43095 (2026-09-09); separate 15 U7 build 41800 (2026-02-10)
    • Next signal: Linux EDR extensions: 16 notes describe future rollback, desktop support and isolation; shipment/timing not confirmed against later cloud notes
    • Archetype: Integrated protection and recovery
    • Evidence grade: C. Overall grade uses all scored history/AI steps and lens criteria: 40 A, 0 B, 15 C of 55; the lowest grade covering more than 25% wins. Judgement itself does not demote a sourced fact; unresolved eligibility, baseline or contract estimates do.

    Scope of the scores: Product capability cutoff 2026-10-01; scoring edition 2026-10-03. Combined portfolio scores do not imply one SKU or uniform feature parity. History is evidence-bounded; freezes and first-feature GA dates can be incomplete. AI services named in the AI section do not broaden the ten core domains.

    Scorecard

    DimensionScoreDirection
    Capability today72.8 / 100higher is better
    Momentum since end of 2022+6.8 pointshigher is better
    Credibility16.0 / 25higher is better
    Commercial risk14.5 / 25lower is better
    Technical lock-in12.5 / 25lower is better
    Integrator fit15.0 / 20higher is better
    AI leverage8.5 / 20higher is better
    Ledger Index60.9 / 100balanced weights

    Capability by domain

    Scores 0 to 5 against fixed anchors; total is weighted to 100.

    Domain (weight)201620192022Today
    Virtual and physical servers (12)33.53.54
    Databases and applications (12)2.5333.5
    Recovery (14)3.5444.5
    Cyber resilience (14)0.52.533.5
    Storage efficiency and targets (10)333.53.5
    Long-term retention and tape (6)1.533.53.5
    Replication and DR (10)1.5333
    Security and compliance (8)1.52.52.53
    New-platform support (VMware exit) (8)0333.5
    Management at scale and automation (6)2.5444
    Total / 10040.663.066.072.8

    Year by year: 2016: 40.6 · 2017: 40.6 · 2018: 45.4 · 2019: 63.0 · 2020: 64.4 · 2021: 64.4 · 2022: 66.0 · 2023: 66.0 · 2024: 66.0 · 2025: 66.8 · 2026: 72.8

    What moved the score

    YearDomainChangePointsTrigger
    2018New-platform support (VMware exit)0 → 3+4.812.5 Update 3.2 (2018-10-15 build 11010): Nutanix AHV support; XenServer 7.3 to 7.5; macOS Mojave 10.14. Evidence A. rn125
    2019Cyber resilience0.5 → 2.5+5.6End-2019 checkpoint: 12.5 base Active Protection; Update4 adds cryptomining detection and mapped-network-folder protection. This does not prove backup immutability. Evidence A. rn125
    2019Databases and applications2.5 → 3+1.2End-2019 checkpoint: 12.5 Update3 Advanced: Linux Oracle application-aware backup; Update4: Exchange2019, SQL/Exchange CBT can be disabled. Evidence A. rn125
    2019Long-term retention and tape1.5 → 3+1.8End-2019 checkpoint: 12.5 base tape/autoloaders/libraries; Update2 Advanced adds full LTO8, subject to hardware compatibility list; Update3 selects drives/devices per plan. Evidence A. rn125
    2019Management at scale and automation2.5 → 4+1.8End-2019 checkpoint: 12.5 Update4: up to 8000 physical machines per management server; role/group administration and dynamic grouping. Distinct physical-machine limit, not VM count. Evidence A. rn125
    2019Recovery3.5 → 4+1.4End-2019 checkpoint: 12.5 base: Instant Restore/vmFlashback VMware/Hyper-V and remote bootable media. Update3 selects BIOS/UEFI Windows recovery mode. Evidence A. rn125
    2019Replication and DR1.5 → 3+3.0End-2019 checkpoint: 12.5 base VMware VM replication with WAN optimization; off-host backup copying/validation/retention. Do not equate backup copy with CDP. Evidence A. rn125
    2019Security and compliance1.5 → 2.5+1.6End-2019 checkpoint: 12.5 Update4: device registration HTTPS mandatory, anonymous registration can be disabled, token-based mass registration; Linux Secure Boot uses enrolled signed snapapi module. Evidence A. rn125
    2019Virtual and physical servers3 → 3.5+1.2End-2019 checkpoint: 12.5 Update4: Hyper-V2019; Update3: vSphere 6.7. VMware ESXi configuration backup excluded at 6.7. Evidence A. rn125
    2020Cyber resilience2.5 → 3+1.42020-09-09 build record; released build; first GA not found: 15 notes describe AI malware protection; no generative assistant inference. 15 released AI malware protection; immutability is a later independent control. Evidence A. p15
    2022Long-term retention and tape3 → 3.5+0.6End-2022 checkpoint: 15U1 tape multistreaming/multiplexing; LTO/library and WORM matrix still pending. Evidence A. p15
    2022Storage efficiency and targets3 → 3.5+1.0End-2022 checkpoint: 15U4 Secure Zone incremental-forever; 15U5 compatibility with Data Domain retention lock. Evidence A. p15
    2025New-platform support (VMware exit)3 → 3.5+0.8Observed by 2026-10-01: 17 on-prem AHV/PVE source support; 17U1 instant backup-to-Proxmox run including physical machines and Hypercore 9.5/9.6.16U4 AHV feature is cloud-labelled and not substituted for 17 onprem GA. Onprem 17 AHV/PVE GA Oct2025; 16U4 AHV is cloud-only. Evidence A. p16; p17
    2026Cyber resilience3 → 3.5+1.4Observed by 2026-10-01: 17 guidepp 847 to 848: onprem immutable storage only registered AcronisCyberInfrastructure 6.0.1+,agent 16.0.37277+,TIBXv12 backups. Compliance mode irreversible; governance can be disabled only through support. Cloud paths have separate agent 24.01+/BackupGateway requirements. 15 AI malware feature retained separately. Onprem immutable storage requires registered Acronis Cyber Infrastructure; lock modes differ. Evidence A. guide17full; p15
    2026Databases and applications3 → 3.5+1.2Observed by 2026-10-01: 17 user guidepp 77 to 78: SQL2012 to 2022 including Express; Oracle11g/12c/19c/21c single-instance only; HANA2SPS03 RHEL 7.6 physical/ESXi or SUSE15XFS, single tenant. SQLAAG and ExchangeDAG unsupported on WindowsServer2025. Management-server PostgreSQL is infrastructure, not evidence of native protected PostgreSQL workload. Exact feature first-version clocks separate. Oracle single-instance and SQLAG/ExchangeDAG exclusions keep below broad enterprise depth. Evidence A. guide17full; p17
    2026Recovery4 → 4.5+1.4Observed by 2026-10-01: 17 U1 on-premises Instant VM on Proxmox Evidence A. p15; p17
    2026Security and compliance2.5 → 3+0.8Observed by 2026-10-01: 17 on-prem RBAC; U1 on-prem SIEM CEF/JSON, separate from cloud tenant roles Evidence A. p17
    2026Virtual and physical servers3.5 → 4+1.2Observed by 2026-10-01: 17 adds on-premises Proxmox/AHV; U1 Scale Hypercore 9.5/9.6 Guidepp62 to 68 distinguishes Windows Legacy agent, Linux kernel/distribution caveats and VMware/Hyper-V/HC3/RHV/AHV agents; catalogue observation not first support date. Evidence A. p15; p17; guide17full

    Direction, 2023 to 2026

    Each item carries one theme and one driver (V vision, C customer need, M market window, U upstream, P portfolio).

    DateItemThemeDriver
    2023-0312.5 Update 6.1: Maintenance fixes listed separately; no additional headline capability asserted. (clock: 2023-03-06 build 16545)D10 Scale and automationC
    2023-0615 Update6: vSphere/vSAN 8.0; SQL Server2022 database/instance backup; macOS13 and Linux-kernel support. (clock: 2023-06-13 earliest listed build 35681; not independently confirmed GA)D2 Databases and applicationsC
    2023-08Vendor says Cyber Backup is being incorporated into Cyber Protect. This is a product consolidation statement; it supplies no dated end-of-support schedule or executed customer conversion terms. (clock: 2023-08-31 blog update)D4 Cyber resilienceC
    2024-0215 U6 builds 37255 / 37420 / 37853: Maintenance dates (clock: 2024-02-02 / 2024-02-28 / 2024-05-21)D10 Scale and automationC
    2024-0216 initial build 37391: Dated build record; exact first GA declaration not found (clock: 2024-02-21)D10 Scale and automationC
    2024-02Cyber Protect 16 release: shipped; 2024-02-21 build 37391. Launch-day assertion matches the build date; no separate earlier forward promise or first introduction of every launch headline is inferred.D4 Cyber resilienceC
    2024-03Acronis AI Copilot: partial; Demonstrated by 2026-04-08; exact first GA unresolved. Cloud demo is located evidence, not a proved missed 2024 deadline or onprem 17 release.D7 AI-assisted operationsV
    2024-03Cloud onboarding/support AI assistant: partial; December2024 Cloud 24.12. Support assistant shipped in December; March 24.03 separately proves OpenAI-assisted scripting. Complete EDR action plans and on-premises parity are not established; monthly release dates do not establish exact day-relative delivery against the March 22 blog.D7 AI-assisted operationsV
    2024-0616 U1 / U2: Builds 37977 / 38690 (clock: 2024-06-07 / 2024-10-15)D10 Scale and automationC
    2025-0516 Update 4 Linux EDR: partial; 2025-04-28 earliest listed build. Process stop, quarantine, allow/block lists and backup recovery are present; rollback, desktop, isolation and restart remain future in these notes. No missed deadline is established.D10 Scale and automationC
    2025-0516 Update 4 agentless AHV / cloud deployment: shipped; 2025-04-28 earliest listed build; Cloud 25.01 lists January 2025. Retrospective blog is later than build evidence. Cloud and on-premises modes differ; 12.5 had AHV support in 2018, so this is not first AHV support ever.D1 Virtual and physical serversM
    2025-0516 Update 4 backup-only agent / domain rejoin: shipped; 2025-04-28 earliest listed build. Optional Active Protection installation and domain rejoin are explicitly on-premises in the notes. No earlier future commitment was located; later blog publication is not a delivery delay.D10 Scale and automationC
    2026-0215 U7: Build 41800; maintained older line, not newest major (clock: 2026-02-10)D10 Scale and automationC
    2026-06Instant Run as VM on Proxmox: shipped; 2026-06-11. Specific backup mounting and finalization method, not all cross-platform recovery guarantees.D1 Virtual and physical serversM
    2026-0917 U1: 17.1.43095; on-premises and cloud feature sets differ (clock: 2026-09-09)D10 Scale and automationC
    • Centre of gravity: Scale and automation (8), Cyber resilience (2), AI-assisted operations (2)
    • Driver mix: Vision 13%, Customer need 73%, Market window 13%, Upstream 0%, Portfolio 0%

    Credibility: 16.0 / 25

    CriterionScoreBasis
    Cadence444 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. 15 U6 builds 37255 / 37420 / 37853 (2024-02-02 / 2024-02-28 / 2024-05-21): Maintenance dates Evidence A. p15
    Roadmap transparency3Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: not found; release-note future items used. No open-roadmap-tracker reference score is awarded. 15 U6 builds 37255 / 37420 / 37853 (2024-02-02 / 2024-02-28 / 2024-05-21): Maintenance dates Evidence A. p15
    Say-do2.5Recorded ledger: 7 items; 4 shipped, 3 partial, 0 slipped, 0 pending, 0 dropped. Mature dated prospective cohort: 2; 0 documented within 12 calendar months, 0 later than 12 months, 2 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F.
    Velocity3.5Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. 16 Update 4 deployment boundaries (2025-04-28 first listed build 39929; blog updated 2025-05-14): On-premises: optional Active Protection installation, domain rejoin and Rocky Linux management container. Cloud deployment: agentless AHV and Linux EDR. Linux process stop/quarantine/backup recovery shipped; rollback, remote desktop, isolation and restart remain future items in these notes. Evidence A. p16; update16u4Blog
    Lifecycle stability3Accepted lifecycle finding: Exact supported-version/EOL policy not found; old 15 line has dated fixes in 2026.. Grade C where current contract/EOS boundaries remain unresolved. 2023-01-17: Annual Academy curriculum refresh announces 22 courses including five recertification courses. Vendor claims the annual refresh falls from 20 hours to under three; this is a programme update, not the first certification launch. Evidence C. academy23

    Say-do record, 2023 to 2026: Recorded ledger: 7 items; 4 shipped, 3 partial, 0 slipped, 0 pending, 0 dropped. Mature dated prospective cohort: 2; 0 documented within 12 calendar months, 0 later than 12 months, 2 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample.

    Commercial risk: 14.5 / 25 (lower is better)

    CriterionScoreBasis
    Price and licence volatility3New VM-based licence option and separate cloud peak-usage metering change; neither proves blanket onprem price hike. 2024-10-15 build 38690 /16U2: Introduces Azure/EC2 VM-based licence option for on-prem and cloud deployments; no price inferred. Cloud 26.09 September2026: Partner billing changes from last-day snapshot to per-customer/per-metric highest daily production usage aggregated monthly; cloud commercial model, not onprem 17 price hike. New console no additional partner charge; deployment dates may vary. Evidence A. p16; cloud2609
    Purchase constraints2.5Legacy perpetual use remains; subscription/cloud feature boundaries documented, not subscription-only everywhere. 16 Update 4 guide built 2026-09-08: Standard, Advanced and Backup Advanced editions. Subscription validity starts on purchase; on expiry existing protection plans stop and new plans cannot be created. The page does not explicitly establish restore-only access rights. Evidence A. license16
    Channel and access1.5Partner entry and public documentation access are both considered. Research documentation finding: guide. Technology partners / integration: Official developer portal and cloud integration guide opened; per-API support obligations not audited Evidence A. dev; guide
    Owner stability4.5Recent majority/private-equity transition; exact close day not reconstructed. 2024-08-07: EQT announced proposed majority acquisition, expected 2025 Q1 to Q2. Closing date not established in opened source. 2025: EQT investor portfolio records Acronis entry 2025; exact acquisition closing day not supplied Evidence A. eqt; owner
    Cost of staying supported3Maintenance gates updates/support; subscription plans stop at expiry, restore-only rights unstated. 16 Update 4 guide built 2026-09-08: Standard, Advanced and Backup Advanced editions. Subscription validity starts on purchase; on expiry existing protection plans stop and new plans cannot be created. The page does not explicitly establish restore-only access rights. Evidence A. license16

    Security record of the product itself: No in-scope match located in the accepted security-record.md manual product-name filter of the CISA 2026-09-30 catalogue; no deduction. This is not an exhaustive advisory audit or a claim of no exploitation. Arcserve CVE-2015-4068 was added to KEV in 2022, outside the adjustment window. Adjacent array/infrastructure/hosting-plugin CVEs are excluded. Security record: CISA Known Exploited Vulnerabilities catalogue and vendor advisories.

    Technical lock-in: 12.5 / 25 (lower is better)

    CriterionScoreBasis
    Formats4Version-specific .tib/.tibx vendor archives and password-change compatibility; independent reader unverified. Backup archive format: v11/v12 formats documented; 17 U1 password-change capability limited to v12 .tibx. Independent third-party reader not found. Evidence A. p15; p17
    Export path2.52026-10-01 evidence boundary: Independent data extraction and post-licence restoration terms are incomplete. Provisional export estimate, not proof of no export or licence-required restore. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C.
    Stack coupling2The documented component/management stack is considered; cross-workload or cross-hypervisor recovery is not inferred from an API. Backup archive format: v11/v12 formats documented; 17 U1 password-change capability limited to v12 .tibx. Independent third-party reader not found. Evidence C. p15; p17
    Hardware / cloud coupling1.5Deployment/service dependencies determine this score; missing offline/hardware terms are a provisional estimate. Backup archive format: v11/v12 formats documented; 17 U1 password-change capability limited to v12 .tibx. Independent third-party reader not found. Evidence C. p15; p17
    Skills and tooling coupling2.5Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. Technology partners / integration: Official developer portal and cloud integration guide opened; per-API support obligations not audited Evidence A. dev; guide

    Integrator fit: 15 / 20

    CriterionScoreBasis
    Partner programme openness4Authorized/Gold/Platinum with no registration fee but certification obligations; current policy not launch-year proof. Reseller programme / current observation: Authorized/Gold/Platinum tiers; Gold adds MDF/account manager/rebates, Platinum dedicated enhanced support; Academy certification required for tier compliance. Entry has no registration fee, certification minimum still applies. Named exam first-launch dates unresolved. Evidence A. resellerNow
    Multi-tenancy and self-service4Documented tenant/provider isolation and self-service earn credit; reporting or multi-site visibility alone does not prove billing/tenant self-service. Observed by 2026-10-01: 17 RBAC; U1 on-prem SIEM CEF/JSON; cloud custom child-tenant roles Evidence C. p17
    API and infrastructure-as-code3Documented APIs and official IaC earn credit. Community examples and publisher-owned repositories do not automatically imply vendor support. Observed by 2026-10-01: 17 RBAC; U1 on-prem SIEM CEF/JSON; cloud custom child-tenant roles Evidence C. p17
    Skills and certification4Paid hands-on Engineer course documented by 2018 and dated 2023 curriculum refresh; no invented first-launch year. Acronis Certified Engineer for Acronis Backup: Official datasheet dated August 2018 documents paid two-day hands-on technical training for on-premises and cloud Backup. Certifications are tied to software versions and renewed when new classes are available. Existence by August 2018 is established; first launch year is unresolved. 2023 #CyberFit Academy curriculum: Global announcement on January 17, 2023 introduces the annual curriculum refresh and recertification courses. This is earlier than the February 27 regional Korean announcement; neither date is the first-ever certification programme launch. Evidence A. academy18; academy23

    AI leverage: 8.5 / 20

    StrandTodayLatest step
    AI for protection / protecting AI32020: 2020-09-09 build record; released build; first GA not found: 15 notes describe AI malware protection; no generative assistant inference. Evidence A. p15
    AI platform stack02016: 2016 initial scoring observation: no affirmative released in-scope AI evidence is credited in this strand. Zero is an evidence-bounded score, not a claim that the capability was absent. Evidence C.
    AI-assisted operations3.52026: Cloud 26.09 September2026; notes updated 2026-09-30; Released cloud console; selected analytics early access: New Cyber Console provides contextual AI answers and user-delegated actions; query visibility respects role/tenant/licence. Console device/policy operations listed, but exhaustive AI tool permissions/confirmation/audit retention not specified. Cyber Intelligence natural-language dashboard/report generation explicitly early access. No onprem 17 parity inferred. Released cloud delegated console actions, approval/governance detail incomplete; no onprem parity. Evidence A. cloud2609
    Agent openness22026: Technology partners / integration: Official developer portal and cloud integration guide opened; per-API support obligations not audited REST/developer APIs, not a product-control MCP endpoint; external MCP monitoring earns no MCP maturity. Evidence A. dev; guide

    AI say-do sample: 3 recorded announcement rows; 1 GA/shipped matches, 0 preview/early/limited at announcement, 2 partial, 0 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. "Shipped" may be a vendor availability assertion rather than an independently verified first-GA day. Cloud console AI is labelled separately; it earns no onprem 17 assistant parity.

    Reading

    Acronis is extending combined protection and recovery across additional hypervisors. Versioned notes establish on-prem Proxmox recovery and malware controls, while cloud console and EDR capabilities follow separate clocks. Edition gates, proprietary archives and the EQT ownership transition remain dependencies.

    Open questions and evidence caveats

    • Unchanged annual values carry the last scored release; they do not certify a frozen compatibility matrix or exact first-feature GA. Some checkpoint-derived jumps may lag the true first shipment.
    • Unverified AI strands receive zero credited evidence; this is a conservative estimate rather than a vendor-wide absence claim. Preview/limited capabilities add at most half a point beyond the preceding established score.
    • Say-do counts are a bounded research sample. Same-day/release-note announcements and post-release blogs are not promises delivered instantly. Missing outcome dates do not prove non-delivery.
    • Commercial/exit terms not reconstructed use explicit provisional midpoint estimates; executed regional contracts may differ.
    • cyber: 2016 baseline is provisional; no frozen checkpoint fact.
    • retention: 2016 baseline is provisional; no frozen checkpoint fact.
    • security: 2016 baseline is provisional; no frozen checkpoint fact.
    • platforms: 2016 baseline is provisional; no frozen checkpoint fact.
    • Linux EDR16U4 ships selected cloud actions, while rollback/remote desktop/isolation/restart remain future in that note. MCP monitoring in 26.05 does not establish an Acronis backup-control server. Subscription expiry guide does not specify restore-only access.

    Related reading

    More from Enterprise Backup Ledger 2026