Enterprise Backup Ledger Methodology: How Every Score Is Built
How the Enterprise Backup Ledger scores 17 backup vendors: fixed anchors, public evidence only, a security-record rule and two entries left unranked.
Part of the Enterprise Backup Ledger (edition 2026-10-03). The results are in the overview and the vendor reports. The Ledger uses the same method as the VM Platform Ledger and shares its capability scale with the Open-Source Backup Ledger; this page covers what is specific to commercial enterprise backup.
Who this is for
IT buyers and system integrators choosing or recommending backup and recovery software for traditional enterprise environments: VMs, physical servers, databases, enterprise applications, file servers and tape. Many are leaving VMware and need backup for the new hypervisor. No vendor was briefed on, paid for or reviewed any score.
What is in scope
A product is included when it shipped a release in the last 12 months, has public documentation or release notes, is sold beyond one country, and protects VMs on at least one enterprise hypervisor, physical servers and at least one enterprise database. Kubernetes-native backup, SaaS-application backup (Microsoft 365, Salesforce) and personal backup are left for separate Ledgers. Open-source projects are covered in the Open-Source Backup Ledger; Bacula Enterprise, a commercial product from an open-core vendor, is scored here.
The 17 entries
| Tier | Vendors |
|---|---|
| Leader incumbents | Veeam, Commvault, Cohesity (with NetBackup), Rubrik |
| Storage-vendor suites | Dell (PowerProtect Data Manager, Avamar, NetWorker), IBM (Storage Defender, Storage Protect), HPE Zerto |
| Legacy enterprise | OpenText Data Protector, Bacula Enterprise |
| Challengers and mid-market | HYCU, Druva, NAKIVO, Arcserve, Acronis |
| Open-virtualization specialist | Storware |
| Regional candidates (not ranked) | Huawei OceanProtect DataBackup, Sangfor |
Huawei and Sangfor are scored for reference but left out of every ranking: the public evidence was not enough to confirm their software availability, physical and database support and management plane.
The scores
| Dimension | Scale | Direction | What it measures |
|---|---|---|---|
| Capability | 0 to 100 | Higher is better | Ten domains scored 0 to 5 against fixed anchors and weighted |
| Momentum | Points | Higher is better | Capability gained since the end of 2022 |
| Credibility | 0 to 25 | Higher is better | Cadence, roadmap transparency, say-do, velocity, lifecycle stability |
| Commercial risk | 0 to 25 | Lower is better | Price and licence volatility, purchase constraints, channel access, owner stability, cost of staying supported |
| Technical lock-in | 0 to 25 | Lower is better | Backup formats, export path, stack coupling, hardware or cloud coupling, skills |
| Integrator fit | 0 to 20 | Higher is better | Partner programme, multi-tenancy and self-service, API and infrastructure-as-code, skills and certification |
| AI leverage | 0 to 20 | Higher is better | AI for protection, AI platform stack, AI-assisted operations, agent openness |
| Ledger Index | 0 to 100 | Higher is better | A weighted blend of all of the above |
Capability domains and anchors
| Domain (weight) | 3 = solid | 5 = reference |
|---|---|---|
| Virtual and physical servers (12) | VMware and Hyper-V agentless with changed-block tracking; Windows and Linux agents | Plus Unix and very large estates, application-aware processing everywhere, policy-based protection at thousands of VMs |
| Databases and applications (12) | SQL Server and Oracle with log backup; Exchange or AD item restore | SAP HANA, Oracle RMAN, PostgreSQL, MySQL, Db2; point-in-time and item-level restore; vendor-certified integrations |
| Recovery (14) | File, item and image restore; instant VM recovery | Mass instant recovery, cross-platform restore, bare-metal restore, automated recovery testing |
| Cyber resilience (14) | Immutable backups on one target; MFA; basic anomaly alerts | Immutability on several targets, isolated vault, ML anomaly and malware scanning before restore, clean-room recovery, threat hunting in backups |
| Storage efficiency and targets (10) | Dedupe and compression; disk and object targets | Global source-side dedupe, tape, several object and cloud tiers, broad certified storage partners |
| Long-term retention and tape (6) | Tape support and GFS retention | Tape at scale with WORM and vaulting, archive tiers, legal hold |
| Replication and DR (10) | Async VM replication with failover | Continuous data protection, orchestrated failover and failback runbooks, DR to cloud, DR test reports |
| Security and compliance (8) | Encryption, RBAC, MFA | Multi-person approval for destructive actions, FIPS, hardened appliance, compliance reporting, audit trail to SIEM |
| New-platform support for VMware leavers (8) | One non-VMware, non-Hyper-V hypervisor | Agentless changed-block backup for Proxmox, AHV, OpenShift Virtualization, XCP-ng and KVM, plus cross-hypervisor restore |
| Management at scale and automation (6) | One console for several sites; REST API | Central control plane for thousands of sites, multi-tenant MSP portal, Terraform and Ansible, SIEM/SOAR integrations |
Only released capability counts; previews count half a step at most. History is scored from 2016 (or the product's launch year) against these same anchors, so a vendor's line only rises when something ships.
The security-record rule
A backup server holds the keys to an organisation's recovery, so attackers target it. For each flaw in a vendor's own backup product on the CISA Known Exploited Vulnerabilities list with a listing date from 2023 to 2026, today's security and compliance score drops by 0.5, up to 1.5. Every report states the vendor's record and patch timing.
Ledger Index weights
Capability 35, credibility 20, buyer safety 20 (commercial risk and lock-in, inverted), AI leverage 10, integrator fit 10, momentum 5. The interactive Ledger offers other presets (risk-averse buyer, innovation-first, integrator). The index starts in 2023, because credibility, risk and integrator fit are scored from the 2023 to 2026 record; earlier years show capability and AI only.
Evidence
Every fact in the underlying research carries a source URL and a grade: A when the primary source (release notes, documentation, vendor press release, regulatory filing) was opened, B for secondary sources, C for inferences. The say-do record compares what each vendor announced from 2023 to 2026 (keynotes, press releases, product blogs, beta programmes) with what later shipped. Where older release history was thin, a separate review pass dated first releases from archived release notes; the reports say where history is carried forward from the nearest evidence.
What the scores are not
They are not a measure of market share or popularity, and they are not a recommendation for any one environment. Archetype labels are short readings of the scores, not separate scores. The Ledger will be refreshed twice a year, re-checking each vendor's stated plans as shipped, slipped or dropped.
Related reading
More from Enterprise Backup Ledger 2026
- Overview: all platforms side by side
- Acronis Cyber Protect: Enterprise Backup Ledger 2026
- Arcserve UDP: Enterprise Backup Ledger 2026
- Bacula Enterprise: Enterprise Backup Ledger 2026
- Cohesity DataProtect / NetBackup: Enterprise Backup Ledger 2026
- Commvault Cloud: Enterprise Backup Ledger 2026
- Dell: Enterprise Backup Ledger 2026
- Druva Enterprise Workloads: Enterprise Backup Ledger 2026
- HPE Zerto: Enterprise Backup Ledger 2026
- Huawei OceanProtect DataBackup: Enterprise Backup Ledger 2026
- HYCU R-Cloud: Enterprise Backup Ledger 2026
- IBM Storage Defender / Storage Protect: Enterprise Backup Ledger 2026
- NAKIVO Backup & Replication: Enterprise Backup Ledger 2026
- OpenText Data Protector: Enterprise Backup Ledger 2026
- Rubrik Security Cloud: Enterprise Backup Ledger 2026
- Sangfor backup / DR software candidate: Enterprise Backup Ledger 2026
- Storware Backup and Recovery: Enterprise Backup Ledger 2026
- Veeam Data Platform: Enterprise Backup Ledger 2026