Mr.PlanB Logo
    Enterprise Backup Ledger 2026
    Ledger
    Enterprise Backup Ledger 2026

    Enterprise Backup Ledger Methodology: How Every Score Is Built

    How the Enterprise Backup Ledger scores 17 backup vendors: fixed anchors, public evidence only, a security-record rule and two entries left unranked.

    Edition October 3, 20268 min read

    Part of the Enterprise Backup Ledger (edition 2026-10-03). The results are in the overview and the vendor reports. The Ledger uses the same method as the VM Platform Ledger and shares its capability scale with the Open-Source Backup Ledger; this page covers what is specific to commercial enterprise backup.

    Who this is for

    IT buyers and system integrators choosing or recommending backup and recovery software for traditional enterprise environments: VMs, physical servers, databases, enterprise applications, file servers and tape. Many are leaving VMware and need backup for the new hypervisor. No vendor was briefed on, paid for or reviewed any score.

    What is in scope

    A product is included when it shipped a release in the last 12 months, has public documentation or release notes, is sold beyond one country, and protects VMs on at least one enterprise hypervisor, physical servers and at least one enterprise database. Kubernetes-native backup, SaaS-application backup (Microsoft 365, Salesforce) and personal backup are left for separate Ledgers. Open-source projects are covered in the Open-Source Backup Ledger; Bacula Enterprise, a commercial product from an open-core vendor, is scored here.

    The 17 entries

    TierVendors
    Leader incumbentsVeeam, Commvault, Cohesity (with NetBackup), Rubrik
    Storage-vendor suitesDell (PowerProtect Data Manager, Avamar, NetWorker), IBM (Storage Defender, Storage Protect), HPE Zerto
    Legacy enterpriseOpenText Data Protector, Bacula Enterprise
    Challengers and mid-marketHYCU, Druva, NAKIVO, Arcserve, Acronis
    Open-virtualization specialistStorware
    Regional candidates (not ranked)Huawei OceanProtect DataBackup, Sangfor

    Huawei and Sangfor are scored for reference but left out of every ranking: the public evidence was not enough to confirm their software availability, physical and database support and management plane.

    The scores

    DimensionScaleDirectionWhat it measures
    Capability0 to 100Higher is betterTen domains scored 0 to 5 against fixed anchors and weighted
    MomentumPointsHigher is betterCapability gained since the end of 2022
    Credibility0 to 25Higher is betterCadence, roadmap transparency, say-do, velocity, lifecycle stability
    Commercial risk0 to 25Lower is betterPrice and licence volatility, purchase constraints, channel access, owner stability, cost of staying supported
    Technical lock-in0 to 25Lower is betterBackup formats, export path, stack coupling, hardware or cloud coupling, skills
    Integrator fit0 to 20Higher is betterPartner programme, multi-tenancy and self-service, API and infrastructure-as-code, skills and certification
    AI leverage0 to 20Higher is betterAI for protection, AI platform stack, AI-assisted operations, agent openness
    Ledger Index0 to 100Higher is betterA weighted blend of all of the above

    Capability domains and anchors

    Domain (weight)3 = solid5 = reference
    Virtual and physical servers (12)VMware and Hyper-V agentless with changed-block tracking; Windows and Linux agentsPlus Unix and very large estates, application-aware processing everywhere, policy-based protection at thousands of VMs
    Databases and applications (12)SQL Server and Oracle with log backup; Exchange or AD item restoreSAP HANA, Oracle RMAN, PostgreSQL, MySQL, Db2; point-in-time and item-level restore; vendor-certified integrations
    Recovery (14)File, item and image restore; instant VM recoveryMass instant recovery, cross-platform restore, bare-metal restore, automated recovery testing
    Cyber resilience (14)Immutable backups on one target; MFA; basic anomaly alertsImmutability on several targets, isolated vault, ML anomaly and malware scanning before restore, clean-room recovery, threat hunting in backups
    Storage efficiency and targets (10)Dedupe and compression; disk and object targetsGlobal source-side dedupe, tape, several object and cloud tiers, broad certified storage partners
    Long-term retention and tape (6)Tape support and GFS retentionTape at scale with WORM and vaulting, archive tiers, legal hold
    Replication and DR (10)Async VM replication with failoverContinuous data protection, orchestrated failover and failback runbooks, DR to cloud, DR test reports
    Security and compliance (8)Encryption, RBAC, MFAMulti-person approval for destructive actions, FIPS, hardened appliance, compliance reporting, audit trail to SIEM
    New-platform support for VMware leavers (8)One non-VMware, non-Hyper-V hypervisorAgentless changed-block backup for Proxmox, AHV, OpenShift Virtualization, XCP-ng and KVM, plus cross-hypervisor restore
    Management at scale and automation (6)One console for several sites; REST APICentral control plane for thousands of sites, multi-tenant MSP portal, Terraform and Ansible, SIEM/SOAR integrations

    Only released capability counts; previews count half a step at most. History is scored from 2016 (or the product's launch year) against these same anchors, so a vendor's line only rises when something ships.

    The security-record rule

    A backup server holds the keys to an organisation's recovery, so attackers target it. For each flaw in a vendor's own backup product on the CISA Known Exploited Vulnerabilities list with a listing date from 2023 to 2026, today's security and compliance score drops by 0.5, up to 1.5. Every report states the vendor's record and patch timing.

    Ledger Index weights

    Capability 35, credibility 20, buyer safety 20 (commercial risk and lock-in, inverted), AI leverage 10, integrator fit 10, momentum 5. The interactive Ledger offers other presets (risk-averse buyer, innovation-first, integrator). The index starts in 2023, because credibility, risk and integrator fit are scored from the 2023 to 2026 record; earlier years show capability and AI only.

    Evidence

    Every fact in the underlying research carries a source URL and a grade: A when the primary source (release notes, documentation, vendor press release, regulatory filing) was opened, B for secondary sources, C for inferences. The say-do record compares what each vendor announced from 2023 to 2026 (keynotes, press releases, product blogs, beta programmes) with what later shipped. Where older release history was thin, a separate review pass dated first releases from archived release notes; the reports say where history is carried forward from the nearest evidence.

    What the scores are not

    They are not a measure of market share or popularity, and they are not a recommendation for any one environment. Archetype labels are short readings of the scores, not separate scores. The Ledger will be refreshed twice a year, re-checking each vendor's stated plans as shipped, slipped or dropped.

    Related reading

    More from Enterprise Backup Ledger 2026