Mr.PlanB Logo
    Enterprise Backup Ledger 2026
    Ledger
    Enterprise Backup Ledger 2026

    Druva Enterprise Workloads: Enterprise Backup Ledger 2026

    Druva is extending a cloud-managed backup service across alternative hypervisors and cyber recovery workflows.

    Edition October 3, 20266 min read

    Part of the Enterprise Backup Ledger (edition 2026-10-03). How the scores work: methodology.

    Snapshot

    • Tier: Mid-market / MSP
    • Owner: Druva; venture-backed financing rounds 2016 to 2021, no sale of Druva recorded in the accepted research.
    • Licence model: Consumption credits measured as one TB-month of post-dedupe/compressed stored data; Premium/ARR security entitlements.
    • Products scored: Enterprise Workloads hybrid VM/server/database service; SaaS-only application protection excluded.
    • Latest release: 2026-09-21 staged Enterprise Workloads release; component builds distinct
    • Next signal: No dated next milestone established in the accepted research.
    • Archetype: Cloud managed hybrid backup
    • Evidence grade: B. History rebuilt from archived Druva release notes (Wayback, grade A); VMware first-GA is a window (grade B); 2020 notes unavailable.

    Scope of the scores: Product capability cutoff 2026-10-01; scoring edition 2026-10-03. Combined portfolio scores do not imply one SKU or uniform feature parity. History is evidence-bounded; freezes and first-feature GA dates can be incomplete. AI services named in the AI section do not broaden the ten core domains.

    Scorecard

    DimensionScoreDirection
    Capability today72.2 / 100higher is better
    Momentum since end of 2022+5.6 pointshigher is better
    Credibility17.0 / 25higher is better
    Commercial risk11.5 / 25lower is better
    Technical lock-in17.5 / 25lower is better
    Integrator fit14.0 / 20higher is better
    AI leverage13.5 / 20higher is better
    Ledger Index62.4 / 100balanced weights

    Capability by domain

    Scores 0 to 5 against fixed anchors; total is weighted to 100.

    Domain (weight)201620192022Today
    Virtual and physical servers (12)33.53.53.5
    Databases and applications (12)2333.5
    Recovery (14)2.533.53.5
    Cyber resilience (14)1.51.53.54.5
    Storage efficiency and targets (10)3.53.53.53.5
    Long-term retention and tape (6)22.533
    Replication and DR (10)1.53.53.53.5
    Security and compliance (8)22.533.5
    New-platform support (VMware exit) (8)0033.5
    Management at scale and automation (6)33.53.53.5
    Total / 10042.453.466.672.2

    Year by year: 2016: 42.4 · 2017: 45.4 · 2018: 46.8 · 2019: 53.4 · 2020: 54.8 · 2021: 60.4 · 2022: 66.6 · 2023: 67.8 · 2024: 69.2 · 2025: 70.0 · 2026: 72.2

    What moved the score

    YearDomainChangePointsTrigger
    2017Databases and applications2 → 2.5+1.2SQL Server transaction-log point-in-time restore (2017-01). Source: Ledger review fact pass, 2026-10-03
    2017Long-term retention and tape2 → 2.5+0.6Retention limits removed for long-term retention (2017-02). Source: Ledger review fact pass, 2026-10-03
    2017Virtual and physical servers3 → 3.5+1.2Phoenix 4.7.0 (2017-12): Hyper-V; vCenter auto-configuration and proxy pools (2017). Source: Ledger review fact pass, 2026-10-03
    2018Management at scale and automation3 → 3.5+0.6Druva Cloud Platform console (2018-07); public APIs (2019-07); no Terraform or Ansible found. Source: Ledger review fact pass, 2026-10-03
    2018Security and compliance2 → 2.5+0.8Enhanced RBAC with custom roles (2018-11); audit trail reporting (2018-04). Source: Ledger review fact pass, 2026-10-03
    2019Databases and applications2.5 → 3+1.2Phoenix 4.8.0 (2019-02): Oracle RMAN to Phoenix Backup Store. Source: Ledger review fact pass, 2026-10-03
    2019Recovery2.5 → 3+1.4One-click DR failover of many VMs to EC2 with runbooks (2019-05). Source: Ledger review fact pass, 2026-10-03
    2019Replication and DR1.5 → 3.5+4.0Automated runbooks and one-click failover (2019-05), failback (2019-09), DRaaS GA (2019-08); no site-to-site replication. Source: Ledger review fact pass, 2026-10-03
    2020Long-term retention and tape2.5 → 3+0.6Warm-to-cold long-term retention tiering (2020); no tape target. Source: Ledger review fact pass, 2026-10-03
    2020Security and compliance2.5 → 3+0.8Two-factor login (2020-11). Source: Ledger review fact pass, 2026-10-03
    2021Cyber resilience1.5 → 3+4.2Accelerated Ransomware Recovery (2021-06): anomaly detection, quarantine, malware scan before restore; curated snapshots (2021-09). Source: Ledger review fact pass, 2026-10-03
    2021Recovery3 → 3.5+1.4VMware instant restore from CloudCache (2021-10); no native bare-metal recovery. Source: Ledger review fact pass, 2026-10-03
    2022Cyber resilience3 → 3.5+1.4Data Lock immutability for all hybrid workloads (2022-06). Source: Ledger review fact pass, 2026-10-03
    2022New-platform support (VMware exit)0 → 3+4.8Nutanix AHV agentless (2022-01). Source: Ledger review fact pass, 2026-10-03
    2023Databases and applications3 → 3.5+1.2SAP-certified SAP HANA (2023-03); no Db2 or on-prem Exchange found. Source: Ledger review fact pass, 2026-10-03
    2024Cyber resilience3.5 → 4+1.4VMware threat hunting and auto-quarantine (2024-08). Source: Ledger review fact pass, 2026-10-03
    2025Security and compliance3 → 3.5+0.8FedRAMP Moderate extended to data-centre workloads (2025-04). Source: Ledger review fact pass, 2026-10-03
    2026Cyber resilience4 → 4.5+1.4Cyber Recovery Plans with isolated recovery environment (2026-03). Source: Ledger review fact pass, 2026-10-03
    2026New-platform support (VMware exit)3 → 3.5+0.8Proxmox VE (2026-06) and Canonical OpenStack (2026-09); no OpenShift Virtualization found. Source: Ledger review fact pass, 2026-10-03

    Direction, 2023 to 2026

    Each item carries one theme and one driver (V vision, C customer need, M market window, U upstream, P portfolio).

    DateItemThemeDriver
    2023-09MSP Accelerated Ransomware Recovery: shipped; 2023-09-07 availability assertion. MSP-specific availability expansion, not original product launch; feature-specific service notes and entitlement limits remain separate.D4 Cyber resilienceC
    2023-09MSP Security Posture and Observability: shipped; 2023-09-07 availability assertion. MSP-specific availability expansion, not original product launch; feature-specific service notes and entitlement limits remain separate.D10 Scale and automationC
    2023-10Dru copilot: partial; Exact general GA not established. Read/recommend now; future create-policy/trigger-backup statement not closed by MCP guide, which restricts policy changes.D7 AI-assisted operationsV
    2024-07Dru Assist support guidance: shipped; By2024-07-08; first service rollout day unresolved. Contextual support/troubleshooting and recommendations; no autonomous recovery established.D7 AI-assisted operationsV
    2024-07Threat Hunting IOC search: partial; First matching note GA unresolved. Press release asserts searches across protected data; exact workload/SKU rollout remains unresolved.D4 Cyber resilienceC
    2024-09Dru Investigate metadata investigations: shipped; 2024-09-12 assertion; note-level rollout unresolved. Natural-language metadata investigation using Bedrock/private RAG; no customer-content training claim independently audited.D7 AI-assisted operationsV
    2025-08DruAI prompted EC2 workload recovery: shipped; 2025-08-19 assertion; component notes unresolved. EC2 instance/configuration/volumes/networking example; existing API permissions. Do not infer all onprem recoveries or current MCP policy-edit rights.D7 AI-assisted operationsV
    2025-09Dru Insights Agent: shipped; 2025-09-17 assertion. Metadata summaries/recommendations. February2026 quarterly retrospective corroborates report insights, not exact initial build.D7 AI-assisted operationsV
    2025-09Dru Lifecycle Agent: pending; First matching GA unresolved. Retention/orphaned-data queries and proposed actions; Insights GA cannot be assigned to Lifecycle.D7 AI-assisted operationsV
    2026-06Proxmox VM protection: shipped; 2026-06-15 staged; regions may follow. VM protection; Aug 17 PVE 9.2/NFS; Sep 21 Ceph RBD. These are distinct enhancements.D1 Virtual and physical serversM
    2026-07Platform View-Only Administrator: shipped; 2026-07-16 staged service update. Cross-platform cyber-resiliency visibility without create/edit/delete/block rights; separate from MCP consent. No invented original earlier forward promise.D10 Scale and automationC
    2026-08AzureVM pre-FLR threat filtering: shipped; 2026-08-03 staged service update. AV/IOC scan selected files before restore; filter/quarantine threats; Advanced Ransomware Recovery or Premium entitlement. No invented original earlier forward promise.D4 Cyber resilienceC
    2026-09Canonical OpenStack protection: shipped; 2026-09-21 staged; proxy next-week availability. Agentless VM backup and recovery to original/alternate project/region; no unrelated OpenStack service consistency inferred.D1 Virtual and physical serversM
    2026-09Official Druva MCP: partial; First GA not established. Guide supplies endpoint, OAuth/RBAC and restricted-workflow behavior; no earlier promise or global SKU rollout recovered.D11 Ecosystem opennessV
    2026-09Ransomware Detection: partial; 2026-09-17 staged service update. AI/ML behavioral plus forensic backup analysis; Limited Availability and Premium SKU, support activation; VMware/AzureVM/EC2/EBS. No invented original earlier forward promise.D4 Cyber resilienceC
    • Centre of gravity: AI-assisted operations (6), Cyber resilience (4), Scale and automation (2)
    • Driver mix: Vision 47%, Customer need 40%, Market window 13%, Upstream 0%, Portfolio 0%

    Credibility: 17 / 25

    CriterionScoreBasis
    Cadence431 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. Enterprise Workloads staged release (2026-06-15): Proxmox proxy introduced 7.0.0-958375; component clocks vary Evidence A. notes
    Roadmap transparency3Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: not found; dated release and vendor announcement pages used. No open-roadmap-tracker reference score is awarded. Enterprise Workloads staged release (2026-06-15): Proxmox proxy introduced 7.0.0-958375; component clocks vary Evidence A. notes
    Say-do3Recorded ledger: 21 items; 12 shipped, 7 partial, 0 slipped, 2 pending, 0 dropped. Mature dated prospective cohort: 5; 0 documented within 12 calendar months, 0 later than 12 months, 5 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F.
    Velocity4Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. DruAI service evolution (2024-07/09; 2025-08/09): Support guidance and metadata investigations; prompted EC2 recovery; Insights GA versus Lifecycle forthcoming. Native service feature clocks, not an onprem software version. Evidence A. assist24; investigate24; agents25; graph25
    Lifecycle stability3Accepted lifecycle finding: not found. Grade C where current contract/EOS boundaries remain unresolved. 2023-09-07: MSP portfolio adds SP&O/ARR globally; press states MSP program introduced 2021. Separate from July2023 Partner+ VAR program and current licences. Evidence C. msp23

    Say-do record, 2023 to 2026: Recorded ledger: 21 items; 12 shipped, 7 partial, 0 slipped, 2 pending, 0 dropped. Mature dated prospective cohort: 5; 0 documented within 12 calendar months, 0 later than 12 months, 5 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample.

    Commercial risk: 11.5 / 25 (lower is better)

    CriterionScoreBasis
    Price and licence volatility22023 to cutoff model/packaging observations are distinguished from historical introductions. Without a reconstructed price series this is a provisional estimate, not a measured price increase. 2026-10-01 observation: Consumption credit =1TB-month of deduplicated/compressed stored backup data; not 1TB source-data licence Evidence C. credits
    Purchase constraints3.5Licence metrics, edition gates and purchase routes determine this estimate; undisclosed minimums are not assumed zero. Enterprise Data: VM/file/NAS/database protection offered separately from SaaS-app/endpoint plans; exact numeric contracted price not found Evidence A. pricing; credits
    Channel and access2Partner entry and public documentation access are both considered. Research documentation finding: notes. Partner+ launch 2023-07-18: Dated primary press release launches Partner+. Copyright2023 programme guide names Authorized/Certified/Elite tiers; region-dependent accredited sales/technical staffing and revenue requirements. Deal-registration margin protection, Partner Academy, NFR/MDF and selected higher-tier rebates documented. A Certified partner tier is not itself an individual certification name. Evidence A. partnerLaunch23; partnerGuide23
    Owner stability1.5Venture-backed funding recorded; no recent controlling-owner acquisition established. 2021-04-19: $147m financing led by CDPQ with Neuberger Berman; above$2bn valuation is vendor claim. Evidence A. fund21
    Cost of staying supported2.5Support/upgrade constraints, distinct from licence-expiry restoration: not found. 2023-09-07: MSP portfolio adds SP&O/ARR globally; press states MSP program introduced 2021. Separate from July2023 Partner+ VAR program and current licences. Evidence C. msp23

    Security record of the product itself: No in-scope match located in the accepted security-record.md manual product-name filter of the CISA 2026-09-30 catalogue; no deduction. This is not an exhaustive advisory audit or a claim of no exploitation. Arcserve CVE-2015-4068 was added to KEV in 2022, outside the adjustment window. Adjacent array/infrastructure/hosting-plugin CVEs are excluded. Security record: CISA Known Exploited Vulnerabilities catalogue and vendor advisories.

    Technical lock-in: 17.5 / 25 (lower is better)

    CriterionScoreBasis
    Formats42026-10-01 evidence boundary: Independent backup-format specification/readability is not established in the accepted research. Provisional format-dependency estimate, not proof that only a running licensed instance can read it. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C.
    Export path2.52026-10-01 evidence boundary: Independent data extraction and post-licence restoration terms are incomplete. Provisional export estimate, not proof of no export or licence-required restore. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C.
    Stack coupling4Hybrid protection depends on the service/control plane; CloudCache does not establish an independent backup engine. Service dependency: Hybrid workload control plane and cloud backup service; regional release staging and agent upgrade needed. Independent raw repository extractor not found. Evidence A. notes; pricing
    Hardware / cloud coupling5Mandatory cloud service and AWS DR architecture meet the strongest cloud-coupling anchor. Service dependency: Hybrid workload control plane and cloud backup service; regional release staging and agent upgrade needed. Independent raw repository extractor not found. Phoenix DRaaS2018 architecture: AWS account/EC2 proxy/S3/AMI dependencies; proxy region matches backup storage and resulting AMI. Data copied to customer S3 as decrypted 256MB chunks before AMI construction. Evidence A. notes; pricing; dr18
    Skills and tooling coupling2Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. Partner+ launch 2023-07-18: Dated primary press release launches Partner+. Copyright2023 programme guide names Authorized/Certified/Elite tiers; region-dependent accredited sales/technical staffing and revenue requirements. Deal-registration margin protection, Partner Academy, NFR/MDF and selected higher-tier rebates documented. A Certified partner tier is not itself an individual certification name. Evidence A. partnerLaunch23; partnerGuide23

    Integrator fit: 14 / 20

    CriterionScoreBasis
    Partner programme openness4Authorized/Certified/Elite and regional staffing/revenue requirements documented. Partner+ launch 2023-07-18: Dated primary press release launches Partner+. Copyright2023 programme guide names Authorized/Certified/Elite tiers; region-dependent accredited sales/technical staffing and revenue requirements. Deal-registration margin protection, Partner Academy, NFR/MDF and selected higher-tier rebates documented. A Certified partner tier is not itself an individual certification name. Evidence A. partnerLaunch23; partnerGuide23
    Multi-tenancy and self-service4Documented tenant/provider isolation and self-service earn credit; reporting or multi-site visibility alone does not prove billing/tenant self-service. Observed by 2026-10-01: Central reporting replaces legacy reports in 2026 release notes; API/IaC download counts unverified Evidence C. notes
    API and infrastructure-as-code3Documented APIs and official IaC earn credit. Community examples and publisher-owned repositories do not automatically imply vendor support. Observed by 2026-10-01: Central reporting replaces legacy reports in 2026 release notes; API/IaC download counts unverified Evidence C. notes
    Skills and certification3Technical certification announced April 2024; named credential/exam requirements incomplete. Technical certification announced 2024-04-03: Partner-excellence article announces new technical certification but does not name the credential or first exam day. Programme launch now resolved; named individual credential launch remains open. Evidence C. partnerUpdate24

    AI leverage: 13.5 / 20

    StrandTodayLatest step
    AI for protection / protecting AI32023: VMware anomaly detection (2023-05). Source: Ledger review fact pass, 2026-10-03
    AI platform stack22024: 2024-09-12; Available asserted: Dru Investigate: Amazon Bedrock, isolated LLM/private RAG and metadata-only investigations; available to all customers without added charge. Read/analyze scope; no universal autonomous action claim. Private metadata RAG investigations; backup-content RAG not asserted. Evidence A. investigate24
    AI-assisted operations4.52025: 2025-08-19; Available asserted: Bedrock AgentCore powers permission-bound Data/Help/Action agents; prompted EC2 recovery example. This supersedes a blanket read-only description of the DruAI suite, without changing narrower MCP interface restrictions. Prompted permission-bound EC2 recovery; exhaustive approval/audit contract unresolved. Evidence A. agents25
    Agent openness42026: Druva MCP server in the Cloud Platform release (2026-06-26). Source: Ledger review fact pass, 2026-10-03

    AI say-do sample: 8 recorded announcement rows; 4 GA/shipped matches, 1 preview/early/limited at announcement, 2 partial, 2 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. "Shipped" may be a vendor availability assertion rather than an independently verified first-GA day.

    Reading

    Druva is extending a cloud-managed backup service across alternative hypervisors and cyber recovery workflows. Staged release notes document Proxmox and OpenStack, while DruAI adds metadata investigations and prompted EC2 recovery. Mandatory service dependence and retention-driven credit use remain the main coupling.

    Open questions and evidence caveats

    • Unchanged annual values carry the last scored release; they do not certify a frozen compatibility matrix or exact first-feature GA. Some checkpoint-derived jumps may lag the true first shipment.
    • Unverified AI strands receive zero credited evidence; this is a conservative estimate rather than a vendor-wide absence claim. Preview/limited capabilities add at most half a point beyond the preceding established score.
    • Say-do counts are a bounded research sample. Same-day/release-note announcements and post-release blogs are not promises delivered instantly. Missing outcome dates do not prove non-delivery.
    • Commercial/exit terms not reconstructed use explicit provisional midpoint estimates; executed regional contracts may differ.
    • cyber: 2016 baseline is provisional; no frozen checkpoint fact.
    • dr: 2016 baseline is provisional; no frozen checkpoint fact.
    • security: 2016 baseline is provisional; no frozen checkpoint fact.
    • platforms: 2016 baseline is provisional; no frozen checkpoint fact.
    • 2019/2022 gaps carry the 2016 Phoenix and 2018 DR observations, without credit for later undocumented features. June/September 2026 protection is staged across regions and proxies. Ransomware Detection remains limited; no full GA AI protection score.
    • Review 2026-10-03: capability history rebuilt from a dated fact pass; the earlier history credited most cyber and platform features only in 2026 because older evidence was missing.

    Related reading

    More from Enterprise Backup Ledger 2026