Mr.PlanB Logo
    Enterprise Backup Ledger 2026
    Ledger
    Enterprise Backup Ledger 2026

    Veeam Data Platform: Enterprise Backup Ledger 2026

    Veeam is expanding recovery portability and cyber controls around Backup & Replication and ONE.

    Edition October 3, 20266 min read

    Part of the Enterprise Backup Ledger (edition 2026-10-03). How the scores work: methodology.

    Snapshot

    • Tier: Leader incumbent
    • Owner: Insight Partners majority owner since 2020-03-02; TPG-led secondary shareholder offering announced 2024-12-04.
    • Licence model: Portable VUL workload subscription/perpetual options described; legacy socket new-sales policy changed 2022; no universal 2023 perpetual ban inferred.
    • Products scored: Backup & Replication 13.1/13.1.1 and Veeam ONE; distinct component maintenance dates.
    • Latest release: 13.1.1 (2026-08-13); maintenance 13.0.3 dated 2026-08-25
    • Next signal: DataAI Resilience Module: 2026-05-12 promise; module-specific GA still unresolved.; Official MCP: VDC future-release promise; no dated GA contract established for B&R.
    • Archetype: Portable recovery platform
    • Evidence grade: A. Overall grade uses all scored history/AI steps and lens criteria: 53 A, 0 B, 10 C of 63; the lowest grade covering more than 25% wins. Judgement itself does not demote a sourced fact; unresolved eligibility, baseline or contract estimates do.

    Scope of the scores: Product capability cutoff 2026-10-01; scoring edition 2026-10-03. Combined portfolio scores do not imply one SKU or uniform feature parity. History is evidence-bounded; freezes and first-feature GA dates can be incomplete. AI services named in the AI section do not broaden the ten core domains.

    Scorecard

    DimensionScoreDirection
    Capability today86.8 / 100higher is better
    Momentum since end of 2022+7.2 pointshigher is better
    Credibility18.5 / 25higher is better
    Commercial risk12.5 / 25lower is better
    Technical lock-in8.0 / 25lower is better
    Integrator fit16.0 / 20higher is better
    AI leverage11.0 / 20higher is better
    Ledger Index72.3 / 100balanced weights

    Capability by domain

    Scores 0 to 5 against fixed anchors; total is weighted to 100.

    Domain (weight)201620192022Today
    Virtual and physical servers (12)3444.5
    Databases and applications (12)344.54.5
    Recovery (14)3.544.54.5
    Cyber resilience (14)123.54.5
    Storage efficiency and targets (10)33.544
    Long-term retention and tape (6)344.54.5
    Replication and DR (10)334.54.5
    Security and compliance (8)22.533.5
    New-platform support (VMware exit) (8)0034.5
    Management at scale and automation (6)33.544
    Total / 10049.462.079.686.8

    Year by year: 2016: 49.4 · 2017: 51.2 · 2018: 51.2 · 2019: 62.0 · 2020: 66.2 · 2021: 79.6 · 2022: 79.6 · 2023: 84.8 · 2024: 86.4 · 2025: 86.4 · 2026: 86.8

    What moved the score

    YearDomainChangePointsTrigger
    2017Management at scale and automation3 → 3.5+0.69.5 Update 3 (2017-12-18): Central Windows/Linux agent deployment; Cloud Connect insider protection; data-location tags; universal storage API. Evidence A. kb2353; build
    2017Virtual and physical servers3 → 3.5+1.29.5 Update 3 (2017-12-18): Central Windows/Linux agent deployment; Cloud Connect insider protection; data-location tags; universal storage API. Evidence A. kb2353; build
    2019Cyber resilience1 → 2+2.89.5 Update 4 (2019-01-22 GA; RTM 2018-12-28): Object capacity tier; Secure Restore; Oracle RMAN/SAP HANA plug-ins; WORM tape. Evidence A. wn95u4; rn95u4; build
    2019Databases and applications3 → 4+2.49.5 Update 4 (2019-01-22 GA; RTM 2018-12-28): Object capacity tier; Secure Restore; Oracle RMAN/SAP HANA plug-ins; WORM tape. Evidence A. wn95u4; rn95u4; build
    2019Long-term retention and tape3 → 4+1.29.5 Update 4 (2019-01-22 GA; RTM 2018-12-28): Object capacity tier; Secure Restore; Oracle RMAN/SAP HANA plug-ins; WORM tape. Evidence A. wn95u4; rn95u4; build
    2019Recovery3.5 → 4+1.49.5 Update 4 (2019-01-22 GA; RTM 2018-12-28): Object capacity tier; Secure Restore; Oracle RMAN/SAP HANA plug-ins; WORM tape. Evidence A. wn95u4; rn95u4; build
    2019Security and compliance2 → 2.5+0.89.5 Update 4 (2019-01-22 GA; RTM 2018-12-28): Object capacity tier; Secure Restore; Oracle RMAN/SAP HANA plug-ins; WORM tape. Evidence A. wn95u4; rn95u4; build
    2019Storage efficiency and targets3 → 3.5+1.09.5 Update 4 (2019-01-22 GA; RTM 2018-12-28): Object capacity tier; Secure Restore; Oracle RMAN/SAP HANA plug-ins; WORM tape. Evidence A. wn95u4; rn95u4; build
    2019Virtual and physical servers3.5 → 4+1.29.5 Update 4 (2019-01-22 GA; RTM 2018-12-28): Object capacity tier; Secure Restore; Oracle RMAN/SAP HANA plug-ins; WORM tape. Evidence A. wn95u4; rn95u4; build
    2020Cyber resilience2 → 3+2.810 (2020-02-18 GA; RTM 2020-02-04): NAS backup; multi-VM Instant Recovery; immutable S3 capacity tier; data-reuse API. Evidence A. wn10; build
    2020Recovery4 → 4.5+1.410 (2020-02-18 GA; RTM 2020-02-04): NAS backup; multi-VM Instant Recovery; immutable S3 capacity tier; data-reuse API. Evidence A. wn10; build
    2021Cyber resilience3 → 3.5+1.411 (2021-02-24 GA; RTM 2021-02-11): VMware CDP; hardened Linux repository; instant NAS/SQL/Oracle recovery; cloud archive tier. Evidence A. wn11; build
    2021Databases and applications4 → 4.5+1.211 (2021-02-24 GA; RTM 2021-02-11): VMware CDP; hardened Linux repository; instant NAS/SQL/Oracle recovery; cloud archive tier. Evidence A. wn11; build
    2021Long-term retention and tape4 → 4.5+0.611 (2021-02-24 GA; RTM 2021-02-11): VMware CDP; hardened Linux repository; instant NAS/SQL/Oracle recovery; cloud archive tier. Evidence A. wn11; build
    2021Management at scale and automation3.5 → 4+0.611 (2021-02-24 GA; RTM 2021-02-11): VMware CDP; hardened Linux repository; instant NAS/SQL/Oracle recovery; cloud archive tier. Evidence A. wn11; build
    2021New-platform support (VMware exit)0 → 3+4.8Observed by 2026-10-01: 13.1: native XenServer/XCP-ng/Sangfor; UHAPI Platform9/VergeOS. Proxmox arrived in 12.2; Kubernetes-native Kasten excluded. AHV paths documented by 11; first native AHV release remains uncertain. No Proxmox before 12.2. Evidence C. wn131; v122
    2021Replication and DR3 → 4.5+3.011 (2021-02-24 GA; RTM 2021-02-11): VMware CDP; hardened Linux repository; instant NAS/SQL/Oracle recovery; cloud archive tier. Evidence A. wn11; build
    2021Security and compliance2.5 → 3+0.811a (2021-10-07 GA; RTM 2021-09-24): Server 2022/Hyper-V; Azure Stack HCI 21H2; Cloud Director 10.3; restores directly from object tier. Evidence A. kb4215; rn11a; build
    2021Storage efficiency and targets3.5 → 4+1.011 (2021-02-24 GA; RTM 2021-02-11): VMware CDP; hardened Linux repository; instant NAS/SQL/Oracle recovery; cloud archive tier. Evidence A. wn11; build
    2023Cyber resilience3.5 → 4.5+2.812.1 (2023-12-05 GA): Inline ML detection; YARA scans; four-eyes approval; AI documentation assistant. Evidence A. wn121; build
    2023Security and compliance3 → 4.5+2.412.1 (2023-12-05 GA): Inline ML detection; YARA scans; four-eyes approval; AI documentation assistant. Evidence A. wn121; build
    2024New-platform support (VMware exit)3 → 4+1.612.2 (2024-08-28): Native Proxmox VE; MongoDB; expanded platform support. Evidence A. rn122; v122; build
    2026New-platform support (VMware exit)4 → 4.5+0.8Observed by 2026-10-01: 13.1: native XenServer/XCP-ng/Sangfor; UHAPI Platform9/VergeOS. Proxmox arrived in 12.2; Kubernetes-native Kasten excluded. Core OpenShift Virtualization agentless coverage is not established; no 5. Evidence A. wn131; v122
    2026Security and compliance4.5 → 3.5-1.612.1 (2023-12-05 GA): Inline ML detection; YARA scans; four-eyes approval; AI documentation assistant. Evidence A. wn121; build 2026 security-record adjustment: raw capability 4.5, minus 1.0 for CVE-2023-27532, CVE-2024-40711. KEV entry dates in 2023 to 2026; maximum deduction 1.5. Security record: CISA Known Exploited Vulnerabilities catalogue and vendor advisories.
    2026Virtual and physical servers4 → 4.5+1.2Observed by 2026-10-01: 13.1: native Citrix XenServer/XCP-ng/Sangfor plus UHAPI Platform9/VergeOS; Windows/Linux and AIX/Solaris agents are distinct components. Evidence A. wn131; rn131

    Direction, 2023 to 2026

    Each item carries one theme and one driver (V vision, C customer need, M market window, U upstream, P portfolio).

    DateItemThemeDriver
    2023-10CDP I/O Anomaly Visualizer: shipped; 2023-12-05. 42 days from dated detailed announcement; earlier broad security preview 2023-09-28.D6 Replication and DRC
    2023-10Four-eyes backup deletion protection: shipped; 2023-12-05. 42 days from dated detailed announcement; earlier broad security preview 2023-09-28.D10 Scale and automationC
    2023-10Incident API infection marking / out-of-band backup: shipped; 2023-12-05. 42 days from dated detailed announcement; earlier broad security preview 2023-09-28.D10 Scale and automationC
    2023-10Inline ML malware detection: shipped; 2023-12-05. 42 days from dated detailed announcement; earlier broad security preview 2023-09-28.D4 Cyber resilienceC
    2023-10Veeam ONE Threat Center: shipped; 2023-12-05. 42 days from dated detailed announcement; earlier broad security preview 2023-09-28.D4 Cyber resilienceC
    2023-10YARA backup threat hunting: shipped; 2023-12-05. 42 days from dated detailed announcement; earlier broad security preview 2023-09-28.D4 Cyber resilienceC
    2024-05Native Proxmox VE protection: shipped; 2024-08-28. 106 days; Q3 target met.D1 Virtual and physical serversM
    2024-06Entra ID backup in B&R: shipped; 2024-12-03. Secondary commitment report; shipped feature verified separately. Not a verified first-announcement date.D10 Scale and automationC
    2024-06MongoDB backup: shipped; 2024-08-28. Secondary commitment report; shipped feature verified separately. Not a verified first-announcement date.D2 Databases and applicationsC
    2025-04ONE v13: Deep Data Analysis Agent: shipped; 2025-09-03 base; 2025-11-19 13.0.1; per-feature first build not fully resolved. November What’s New documents reporting and Intelligence; capability release clock not conflated with B&R early appliance.D10 Scale and automationC
    2025-04ONE v13: Malware/Ransomware Analysis Agent: partial; 2025-09-03 base; 2025-11-19 13.0.1; per-feature first build not fully resolved. November What’s New documents reporting and Intelligence; capability release clock not conflated with B&R early appliance.D4 Cyber resilienceC
    2025-04Veeam Data Cloud MCP integration: pending; GA not established in opened B&R/ONE documents. Adjacent VDC commitment; no B&R MCP GA inferred.D11 Ecosystem opennessV
    2026-0513.1: AD Forest Recovery: shipped; 2026-07-29. 78 days to GA; announcement did not state a dated deadline.D3 RecoveryC
    2026-0513.1: Broader hypervisor portability: shipped; 2026-07-29. 78 days to GA; announcement did not state a dated deadline.D10 Scale and automationC
    2026-0513.1: Hybrid FIPS/post-quantum processing: shipped; 2026-07-29. 78 days to GA; announcement did not state a dated deadline.D9 SecurityC
    • Centre of gravity: Scale and automation (5), Cyber resilience (4), Replication and DR (1)
    • Driver mix: Vision 7%, Customer need 87%, Market window 7%, Upstream 0%, Portfolio 0%

    Credibility: 18.5 / 25

    CriterionScoreBasis
    Cadence4.546 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. ONE12 GA /12.1 (2023-02-14 /2023-12-05): Separate ONE build clock; 12 RTM2023-01-30 is not GA Evidence A. one
    Roadmap transparency3Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: not found; conference and release announcements are the direction sources. No open-roadmap-tracker reference score is awarded. ONE12 GA /12.1 (2023-02-14 /2023-12-05): Separate ONE build clock; 12 RTM2023-01-30 is not GA Evidence A. one
    Say-do3.5Recorded ledger: 27 items; 20 shipped, 2 partial, 0 slipped, 5 pending, 0 dropped. Mature dated prospective cohort: 21; 14 documented within 12 calendar months, 1 later than 12 months, 6 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F.
    Velocity4.5Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. ONE 12 feature document (2023-02-14 GA and document footer): Official REST API for infrastructure/jobs/protected workloads and database plug-in protection status; jobs calendar; optional client/web/API action auditing to Windows event log; certificate/CAC authentication and lockdown mode. Microsoft 365 monitoring is separately labelled SaaS-adjacent. Monitoring API does not prove backup-policy execution. Evidence A. onewn12; one12UpdateKB
    Lifecycle stability3Accepted lifecycle finding: not found. Grade C where current contract/EOS boundaries remain unresolved. 2019-10-29 N2WS blog: N2WS states it announced separation from former parent Veeam that week and would operate independently under its co-founders. Exact sale closing day, consideration and government rationale are not supplied by this primary blog. Evidence C. n2wsSeparation19

    Say-do record, 2023 to 2026: Recorded ledger: 27 items; 20 shipped, 2 partial, 0 slipped, 5 pending, 0 dropped. Mature dated prospective cohort: 21; 14 documented within 12 calendar months, 1 later than 12 months, 6 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample.

    Commercial risk: 12.5 / 25 (lower is better)

    CriterionScoreBasis
    Price and licence volatility22023 to cutoff model/packaging observations are distinguished from historical introductions. Without a reconstructed price series this is a provisional estimate, not a measured price increase. 2018-01-16: Acquired N2WS for USD 42.5 million cash. N2WS’s October 2019 primary statement separately establishes its later separation; exact disposal close day and consideration remain unresolved. Evidence C. n2ws; n2wsSeparation19
    Purchase constraints2Licence metrics, edition gates and purchase routes determine this estimate; undisclosed minimums are not assumed zero. Observed licensing: B&R / Availability Suite / Backup Essentials described in FAQ; exact contemporary Data Platform tier price list not found Evidence A. license
    Channel and access1.5Partner entry and public documentation access are both considered. Research documentation finding: extract. VCSP: Service-provider programme with rental licensing and provider services; programme-count claims not independently verified Evidence A. vcsp
    Owner stability4.5Private-equity control plus secondary ownership changes; acquisitions are not treated as feature GA. 2020-03-02: Insight Partners closed acquisition, valuation about $5bn; preserves earlier verified row. 2024-12-04: Announced $2bn secondary shareholder offering at $15bn valuation, led by TPG; not $2bn primary operating funding. Evidence A. owner; secondary
    Cost of staying supported2.5Support/upgrade constraints, distinct from licence-expiry restoration: not found. 2019-10-29 N2WS blog: N2WS states it announced separation from former parent Veeam that week and would operate independently under its co-founders. Exact sale closing day, consideration and government rationale are not supplied by this primary blog. Evidence C. n2wsSeparation19

    Security record of the product itself: 2026 security-record adjustment: raw capability 4.5, minus 1.0 for CVE-2023-27532, CVE-2024-40711. KEV entry dates in 2023 to 2026; maximum deduction 1.5. Security record: CISA Known Exploited Vulnerabilities catalogue and vendor advisories. 27532: patched by 2023-03-07 advisory (exact build ship day unresolved); 40711: fixed 12.2.0.334 GA 2024-08-28, KEV added 2024-10-17. Two other Veeam KEVs were added in 2022 and earn no deduction.

    Technical lock-in: 8.0 / 25 (lower is better)

    CriterionScoreBasis
    Formats3.52026-10-01 evidence boundary: Independent backup-format specification/readability is not established in the accepted research. Provisional format-dependency estimate, not proof that only a running licensed instance can read it. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C.
    Export path1Standalone vendor extract tool works without an installed B&R instance; chain/extent and account-download conditions remain. Backup export: Vendor extract tool works independently of installed B&R on Windows/Linux. Separate download requires registered account. Evidence A. extract
    Stack coupling1Software protects several hypervisors and uses disk/object targets; no vendor appliance prerequisite evidenced. Observed by 2026-10-01: 13.1: native Citrix XenServer/XCP-ng/Sangfor plus UHAPI Platform9/VergeOS; Windows/Linux and AIX/Solaris agents are distinct components. Observed by 2026-10-01: 13.1: managed immutable NFS application repository; expanded object archive targets and scale-out options. Evidence A. wn131; rn131
    Hardware / cloud coupling0.5Windows/Linux independent extract deployment reduces mandatory service dependence. Backup export: Vendor extract tool works independently of installed B&R on Windows/Linux. Separate download requires registered account. Evidence A. extract
    Skills and tooling coupling2Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. VCSP: Service-provider programme with rental licensing and provider services; programme-count claims not independently verified Evidence A. vcsp

    Integrator fit: 16.0 / 20

    CriterionScoreBasis
    Partner programme openness4Published partner routes and entry/tier qualifications earn credit; undisclosed obligations limit the score. VCSP: Service-provider programme with rental licensing and provider services; programme-count claims not independently verified Evidence A. vcsp
    Multi-tenancy and self-service4Documented tenant/provider isolation and self-service earn credit; reporting or multi-site visibility alone does not prove billing/tenant self-service. Observed by 2026-10-01: 13.1: REST port 443, malware/HA/repository control and any-to-vSphere/Hyper-V Instant Recovery APIs; AI actions require workflow approval. Evidence C. wn131
    API and infrastructure-as-code3.5REST is broad; VeeamHub Ansible is community sample code and Terraform is third-party, limiting IaC credit. Observed by 2026-10-01: 13.1: REST port 443, malware/HA/repository control and any-to-vSphere/Hyper-V Instant Recovery APIs; AI actions require workflow approval. Ansible / support status: VeeamHub veeamhub.veeam is community sample code; VeeamHub explicitly disclaims Veeam R&D development/official QA. Not vendor-supported product IaC. Evidence A. wn131; ansible; hub
    Skills and certification4.5VMCE announced November 2013 for January 2014 launch, with later confirmation. Certification: VMCE announced 2013-11-19 for 2014-01 launch; later vendor retrospective confirms January-2014 EMEA launch. Evidence A. vmce; vmcelaunch

    AI leverage: 11 / 20

    StrandTodayLatest step
    AI for protection / protecting AI32023: 2023-12-05; GA: 12.1 inline entropy analysis uses an ML model; suspicious-file index analysis and YARA are separate mechanisms. Evidence A. wn121
    AI platform stack12025: 2025-05-27 announcement / 2025-11-19 v13.0.1 documentation; announced → documented release: ONE Intelligence uses RAG and ONE APIs for environment/report analysis; Deep Data Analysis Agent queries saved reports. Price follows product edition; separate AI add-on price not established. RAG over product/report metadata; no general AI service over all backed-up business data. Evidence A. onepreview; onewn13
    AI-assisted operations52026: 2026-07-29; 13.1 GA: Intelligence investigates job logs, forecasts capacity and executes workflow-approved operations/recoveries; support-case comment/diagnostic actions documented. Workflow-approved actions and recoveries meet the acting-assistant anchor. Evidence A. wn131
    Agent openness22021: End-2022 checkpoint: 11: backup-server REST API for job/infrastructure administration, in addition to Enterprise Manager API. 11 REST administration shipped 2021, carried into the 2022 checkpoint. Evidence A. wn11

    AI say-do sample: 4 recorded announcement rows; 0 GA/shipped matches, 1 preview/early/limited at announcement, 0 partial, 4 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. "Shipped" may be a vendor availability assertion rather than an independently verified first-GA day. B&R/ONE only; VDC MCP and Kasten/Alcion/Securiti acquisitions do not earn core AI GA credit.

    Reading

    Veeam is expanding recovery portability and cyber controls around Backup & Replication and ONE. The record links Proxmox, malware analysis and approved AI actions to delivered versions. Product-specific archive formats and private-equity ownership remain dependencies despite the independent extract tool.

    Open questions and evidence caveats

    • Unchanged annual values carry the last scored release; they do not certify a frozen compatibility matrix or exact first-feature GA. Some checkpoint-derived jumps may lag the true first shipment.
    • Unverified AI strands receive zero credited evidence; this is a conservative estimate rather than a vendor-wide absence claim. Preview/limited capabilities add at most half a point beyond the preceding established score.
    • Say-do counts are a bounded research sample. Same-day/release-note announcements and post-release blogs are not promises delivered instantly. Missing outcome dates do not prove non-delivery.
    • Commercial/exit terms not reconstructed use explicit provisional midpoint estimates; executed regional contracts may differ.
    • No native B&R/ONE official MCP GA is credited from the adjacent Veeam Data Cloud announcement. Raw security 4.5 becomes 3.5 after two eligible KEVs.

    Related reading

    More from Enterprise Backup Ledger 2026