HPE Zerto: Enterprise Backup Ledger 2026
Zerto is extending journal-based VM recovery with vaulting and conversational operator tools.
Part of the Enterprise Backup Ledger (edition 2026-10-03). How the scores work: methodology.
Snapshot
- Tier: Storage-vendor suite
- Owner: HPE; Zerto acquisition completed 2021-09-01 for net cash consideration USD374m.
- Licence model: VM/edition and service-provider entitlements; historical perpetual Enterprise Cloud exists, current commercial minimums unknown.
- Products scored: Zerto VM replication/journal/LTR software and separately labelled vault services; no physical-server or DB-native suite assumed.
- Latest release: 10.9 documentation observed; exact GA/build/date not verified
- Next signal: No dated next milestone established in the accepted research.
- Archetype: Journal based VM recovery
- Evidence grade: C. Overall grade uses all scored history/AI steps and lens criteria: 30 A, 1 B, 17 C of 48; the lowest grade covering more than 25% wins. Judgement itself does not demote a sourced fact; unresolved eligibility, baseline or contract estimates do.
Scope of the scores: Product capability cutoff 2026-10-01; scoring edition 2026-10-03. Combined portfolio scores do not imply one SKU or uniform feature parity. History is evidence-bounded; freezes and first-feature GA dates can be incomplete. AI services named in the AI section do not broaden the ten core domains.
Scorecard
| Dimension | Score | Direction |
|---|---|---|
| Capability today | 62.0 / 100 | higher is better |
| Momentum since end of 2022 | +13.0 points | higher is better |
| Credibility | 14.0 / 25 | higher is better |
| Commercial risk | 14.5 / 25 | lower is better |
| Technical lock-in | 14.0 / 25 | lower is better |
| Integrator fit | 14.5 / 20 | higher is better |
| AI leverage | 10.0 / 20 | higher is better |
| Ledger Index | 57.0 / 100 | balanced weights |
Capability by domain
Scores 0 to 5 against fixed anchors; total is weighted to 100.
| Domain (weight) | 2016 | 2019 | 2022 | Today |
|---|---|---|---|---|
| Virtual and physical servers (12) | 2.5 | 2.5 | 2.5 | 2.5 |
| Databases and applications (12) | 1 | 1 | 1 | 1 |
| Recovery (14) | 3 | 3.5 | 4 | 4 |
| Cyber resilience (14) | 0.5 | 0.5 | 0.5 | 3.5 |
| Storage efficiency and targets (10) | 1.5 | 3 | 3.5 | 3.5 |
| Long-term retention and tape (6) | 1.5 | 2.5 | 2.5 | 2.5 |
| Replication and DR (10) | 4.5 | 4.5 | 4.5 | 4.5 |
| Security and compliance (8) | 2 | 2.5 | 3 | 3 |
| New-platform support (VMware exit) (8) | 0 | 0 | 0 | 2.5 |
| Management at scale and automation (6) | 2.5 | 3.5 | 3.5 | 4 |
| Total / 100 | 38.2 | 45.8 | 49.0 | 62.0 |
Year by year: 2016: 38.2 · 2017: 38.2 · 2018: 39.6 · 2019: 45.8 · 2020: 49.0 · 2021: 49.0 · 2022: 49.0 · 2023: 49.0 · 2024: 57.4 · 2025: 57.4 · 2026: 62.0
What moved the score
| Year | Domain | Change | Points | Trigger |
|---|---|---|---|---|
| 2018 | Recovery | 3 → 3.5 | +1.4 | 6.5 (2018-09-16 lifecycle GA; RNrevisionSept2019): Selective-VM failover/test/clone in VPG; incremental scaled-out LTR; file-recovery API; Hyper-V-agentTLS 1.2. Selective operations require protected site connected and excludev CD sources. Selective VM failover/LTR limits preserved. Evidence A. rn65; oldlife |
| 2019 | Long-term retention and tape | 1.5 → 2.5 | +1.2 | 7.0 (2019-04-26 lifecycle GA; FAQ April 16 code-availability conflict): SMB/CIFS and backup-appliance LTR; daily/weekly/monthly/yearly retention; indexed restore selection; evacuate-host operation. Standard VSS removed; separate VSS product docs required. Evidence A. z70; oldlife |
| 2019 | Management at scale and automation | 2.5 → 3.5 | +1.2 | 7.0 (2019-04-26 lifecycle GA; FAQ April 16 code-availability conflict): SMB/CIFS and backup-appliance LTR; daily/weekly/monthly/yearly retention; indexed restore selection; evacuate-host operation. Standard VSS removed; separate VSS product docs required. Evidence A. z70; oldlife |
| 2019 | Security and compliance | 2 → 2.5 | +0.8 | End-2019 checkpoint: 7.5 requires token-authenticated new pairings between 7.5+ sites; FIPS-enabled Windows supported but product expressly not FIPS compliant. Evidence A. rn75 |
| 2019 | Storage efficiency and targets | 1.5 → 3 | +3.0 | 7.5 (2019-09-22 historical lifecycle GA): Opened cumulative 7.5U4 notes: version-specific LTR/local-backup and cloud improvements; minor/date mapping still pending. Evidence A. z75; oldlife |
| 2020 | Recovery | 3.5 → 4 | +1.4 | 8.5 (2020; exact GA audit pending): Journal file restore back to source with permissions; Azure Blob/S3 LTR without gateway; VRA TLS encryption; PowerShell cmdlet module. Evidence A. z85 |
| 2020 | Security and compliance | 2.5 → 3 | +0.8 | 8.5 (2020; exact GA audit pending): Journal file restore back to source with permissions; Azure Blob/S3 LTR without gateway; VRA TLS encryption; PowerShell cmdlet module. Evidence A. z85 |
| 2020 | Storage efficiency and targets | 3 → 3.5 | +1.0 | 8.5 (2020; exact GA audit pending): Journal file restore back to source with permissions; Azure Blob/S3 LTR without gateway; VRA TLS encryption; PowerShell cmdlet module. Evidence A. z85 |
| 2024 | Cyber resilience | 0.5 → 3.5 | +8.4 | Cyber Resilience Vault Alletra MP integration: announcement 2024-05-15; shipped, availability By2024-05-15 announcement; first GA build unresolved. Immutable secure copies/air-gapped recovery asserted; HPE BlockStorage/private-cloud future dates are separate products. Version-specific secure-vault details remain incomplete. Evidence C. alletra24 |
| 2026 | Management at scale and automation | 3.5 → 4 | +0.6 | Observed by 2026-10-01: 10.9 VMware Enterprise: role-controlled AI assistant plus official local ZVM MCP; separate read-only Analytics MCP authenticates through Cognito. Documentation dates do not establish first GA. Evidence A. ai109; ai109sec; zvmMCP; zaMCPauth |
| 2026 | New-platform support (VMware exit) | 0 → 2.5 | +4.0 | VMware migration to HPE VMs with CDP: announcement 2026-05-12; partial, availability ByMay12 vendor availability assertion; version-specific support/GA unresolved. Integrated private-cloud protection has a separate now-available clock from broader Q2 Zerto enhancements. HPE availability claim, agentless supported-source matrix unresolved; do not infer all KVM. Evidence C. may26 |
Direction, 2023 to 2026
Each item carries one theme and one driver (V vision, C customer need, M market window, U upstream, P portfolio).
| Date | Item | Theme | Driver |
|---|---|---|---|
| 2023-12 | AWS Linux VRA architecture: shipped; By2023-12-07; exact first GA unresolved. Linux ZCA plus separate lightweight cloud VRAs; scaling claim is vendor-authored. No earlier forward promise recovered. | D10 Scale and automation | C |
| 2023-12 | UEFI EC2 protection: shipped; By2023-12-07; exact first GA unresolved. Zerto In-Cloud AWS UEFI instances; cloud component, not universal guest-platform coverage. No earlier forward promise recovered. | D10 Scale and automation | C |
| 2023-12 | ZVM appliance upgrades through GUI: shipped; By2023-12-07; exact first GA unresolved. Replaces CLI-only upgrade process; linked 10.0U2 guide body returned shell. No earlier forward promise recovered. | D10 Scale and automation | C |
| 2023-12 | vSphere Lifecycle Manager integration: shipped; By2023-12-07; exact first GA unresolved. Dated blog links 10.0U2 guide, but guide body returned portal shell; not a proved first GA day. No earlier forward promise recovered. | D10 Scale and automation | C |
| 2024-05 | Cyber Resilience Vault Alletra MP integration: shipped; By2024-05-15 announcement; first GA build unresolved. Immutable secure copies/air-gapped recovery asserted; HPE BlockStorage/private-cloud future dates are separate products. | D4 Cyber resilience | C |
| 2024-12 | Zerto Cloud Vault MSP service: partial; Exact global GA/build unresolved. Managed logical isolation/immutable copies up to 12months/isolated recovery/non-disruptive tests; launch partners Assurestor/Converge/LincolnIT/Verinext. Separate from self-hosted CyberResilienceVault. | D4 Cyber resilience | C |
| 2025-08 | Integration hub/CrowdStrike recovery-point tagging: pending; Exact GA not established. Primary preview mapped to 10U8; RN route remains a shell. Store external API endpoints/secrets and tag suspected-compromised journal points using Falcon alerts. | D3 Recovery | C |
| 2025-08 | Refactored isolated vault recovery: pending; Exact GA not established. Primary preview mapped to 10U8; RN route remains a shell. New-hardware isolated recovery from journal; speed is a vendor assertion, not a measured result. | D4 Cyber resilience | C |
| 2025-08 | Syslog collector support: pending; Exact GA not established. Primary preview mapped to 10U8; RN route remains a shell. Export Zerto messaging logs to centralized collectors. | D10 Scale and automation | C |
| 2025-08 | Vault secure boot/VAIO replication: pending; Exact GA not established. Primary preview mapped to 10U8; RN route remains a shell. VMware I/O filtering replication and secure boot within vault environment. | D4 Cyber resilience | C |
| 2026-03 | AI/vGPU workload enablement: partial; Documented/claimed by May2026; first GA day unresolved. May 12 press says enhancements GA in Q2 rather than proving April delivery. Protection of AI-related workloads including vGPU; not proof of vector/model-registry application consistency. | D10 Scale and automation | C |
| 2026-03 | Microsoft Defender threat integration: partial; Documented/claimed by May2026; first GA day unresolved. May 12 press says enhancements GA in Q2 rather than proving April delivery. Correlate threat visibility with recovery operations. | D4 Cyber resilience | C |
| 2026-03 | Recovery runbooks/platform expansion: partial; Documented/claimed by May2026; first GA day unresolved. May 12 press says enhancements GA in Q2 rather than proving April delivery. Orchestrated cyber/DR workflows and additional virtual/cloud platforms. | D6 Replication and DR | C |
| 2026-05 | AI assistant operator workflows: shipped; 10.9 documentation May 13/20; first GA day unresolved. Primary assistant documentation confirms role-controlled read/recommend/actions; documentation date is not GA. | D7 AI-assisted operations | V |
| 2026-05 | VMware migration to HPE VMs with CDP: partial; ByMay12 vendor availability assertion; version-specific support/GA unresolved. Integrated private-cloud protection has a separate now-available clock from broader Q2 Zerto enhancements. | D6 Replication and DR | C |
- Centre of gravity: Scale and automation (6), Cyber resilience (5), Replication and DR (2)
- Driver mix: Vision 7%, Customer need 93%, Market window 0%, Upstream 0%, Portfolio 0%
Credibility: 14.0 / 25
| Criterion | Score | Basis |
|---|---|---|
| Cadence | 3.5 | 40 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. Zerto10 (2023-05 announcement context): Linux appliance and vault direction in primary PDF snippet; GA date not verified Evidence A. v10 |
| Roadmap transparency | 2.5 | Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: not found; dated release and vendor announcement pages used. No open-roadmap-tracker reference score is awarded. Zerto10 (2023-05 announcement context): Linux appliance and vault direction in primary PDF snippet; GA date not verified Evidence A. v10 |
| Say-do | 2.5 | Recorded ledger: 15 items; 6 shipped, 5 partial, 0 slipped, 4 pending, 0 dropped. Mature dated prospective cohort: 5; 0 documented within 12 calendar months, 0 later than 12 months, 5 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F. |
| Velocity | 3.5 | Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. 10.0U2-correlated Q4 features (2023-12-07 blog delivery assertion): AWSLinuxVRA architecture; vLCM integration; GUI appliance upgrades; EC2UEFI support. Original guide links corroborate U2 family, but guide bodies unread. Evidence A. q423mirror; vlcmU2; upgradeU2 |
| Lifecycle stability | 2 | Adjacent-release paired-site upgrades and LTR configuration/restore-only transitions are explicit. Historical 8.5 upgrade guide: 6.0→6.5 deletes backup/repository configurations; 6.5→7.0 preserves old repositories/retention sets for restore only. PairedsitesN±1; no direct N+2 upgrade. Licence expiry is a separate question. Evidence A. upgrade85 |
Say-do record, 2023 to 2026: Recorded ledger: 15 items; 6 shipped, 5 partial, 0 slipped, 4 pending, 0 dropped. Mature dated prospective cohort: 5; 0 documented within 12 calendar months, 0 later than 12 months, 5 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample.
Commercial risk: 14.5 / 25 (lower is better)
| Criterion | Score | Basis |
|---|---|---|
| Price and licence volatility | 2.5 | 2023 to cutoff model/packaging observations are distinguished from historical introductions. Without a reconstructed price series this is a provisional estimate, not a measured price increase. 2021-09-01: HPE acquisition completed for net cash consideration 374m USD; historical context Evidence C. acquisition |
| Purchase constraints | 3 | Licence metrics, edition gates and purchase routes determine this estimate; undisclosed minimums are not assumed zero. Current: VM-based packages linked by secondary article; primary pricing/entitlement body not retrieved Evidence A. secondary |
| Channel and access | 3 | Partner entry and public documentation access are both considered. Research documentation finding: portal. PowerShell 8.5: Official cmdlet module built on ZVM REST API; public install/download counts and certification launch audit pending. Evidence A. z85 |
| Owner stability | 2.5 | HPE acquisition predates current risk window, while portfolio integration remains material. 2021-09-01: HPE acquisition completed for net cash consideration 374m USD; historical context Evidence A. acquisition |
| Cost of staying supported | 3.5 | Dated support endpoints and constrained upgrade paths increase maintenance dependence; current policy incomplete. 2022-06-01 historical EOS: 8.0 technical-guidance end; support end 2021-05-31. Historical 8.5 upgrade guide: 6.0→6.5 deletes backup/repository configurations; 6.5→7.0 preserves old repositories/retention sets for restore only. PairedsitesN±1; no direct N+2 upgrade. Licence expiry is a separate question. Evidence A. oldlife; upgrade85 |
Security record of the product itself: No in-scope match located in the accepted security-record.md manual product-name filter of the CISA 2026-09-30 catalogue; no deduction. This is not an exhaustive advisory audit or a claim of no exploitation. Arcserve CVE-2015-4068 was added to KEV in 2022, outside the adjustment window. Adjacent array/infrastructure/hosting-plugin CVEs are excluded. Security record: CISA Known Exploited Vulnerabilities catalogue and vendor advisories.
Technical lock-in: 14.0 / 25 (lower is better)
| Criterion | Score | Basis |
|---|---|---|
| Formats | 3.5 | 2026-10-01 evidence boundary: Independent backup-format specification/readability is not established in the accepted research. Provisional format-dependency estimate, not proof that only a running licensed instance can read it. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C. |
| Export path | 2.5 | 2026-10-01 evidence boundary: Independent data extraction and post-licence restoration terms are incomplete. Provisional export estimate, not proof of no export or licence-required restore. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C. |
| Stack coupling | 3 | The documented component/management stack is considered; cross-workload or cross-hypervisor recovery is not inferred from an API. Management: Linux ZVM and replication appliance architecture in 10 material; exact release constraints and export path unverified Evidence C. v10 |
| Hardware / cloud coupling | 2 | Deployment/service dependencies determine this score; missing offline/hardware terms are a provisional estimate. Management: Linux ZVM and replication appliance architecture in 10 material; exact release constraints and export path unverified Evidence C. v10 |
| Skills and tooling coupling | 3 | Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. PowerShell 8.5: Official cmdlet module built on ZVM REST API; public install/download counts and certification launch audit pending. Evidence A. z85 |
Integrator fit: 14.5 / 20
| Criterion | Score | Basis |
|---|---|---|
| Partner programme openness | 3 | Published partner routes and entry/tier qualifications earn credit; undisclosed obligations limit the score. PowerShell 8.5: Official cmdlet module built on ZVM REST API; public install/download counts and certification launch audit pending. Evidence A. z85 |
| Multi-tenancy and self-service | 4 | Documented tenant/provider isolation and self-service earn credit; reporting or multi-site visibility alone does not prove billing/tenant self-service. Observed by 2026-10-01: 10.9 VMware Enterprise: role-controlled AI assistant plus official local ZVM MCP; separate read-only Analytics MCP authenticates through Cognito. Documentation dates do not establish first GA. Evidence C. ai109; ai109sec; zvmMCP; zaMCPauth |
| API and infrastructure-as-code | 3.5 | Official REST/PowerShell and local MCP; no official Terraform/Ansible asserted. 8.5 automation ecosystem: Official PowerShell cmdlets module distributed through PowerShell Gallery supports VPG/VRA operations, alerts and reports; this is not Terraform/Ansible evidence. 10.9+; documentation 2026-05-13; Documented available: Official MCP local deployment for enterprise VMware; protection/RPO/alerts/task queries and starting/stopping failover tests. Overview does not disclose a complete per-tool audit-retention policy. Evidence A. rn85; zvmMCP; ai109sec |
| Skills and certification | 4 | Associate, Enterprise Engineer lab/exam and partner-only CSP credential; intro courses are not certifications. Certifications / August2019 document path; first-launch unresolved: Zerto Certified Associate; ZCP Enterprise Engineer with hands-on lab/exam; ZCP Cloud Service Provider restricted to Alliance Partners. Azure/AWS Intro courses are training-only, not certifications. ZCP technical tracks / April 2019 path; first launch unresolved: Official PDF names ZCP Enterprise Engineer with hands-on lab and exam, and ZCP Cloud Service Provider restricted to Alliance Partners. AWS/Azure introductory courses and Foundations are explicitly training-only. April 2019 URL is an archive hint, not a printed first-certification launch date. Evidence A. cert2019; certApr19PDF |
AI leverage: 10.0 / 20
| Strand | Today | Latest step |
|---|---|---|
| AI for protection / protecting AI | 0 | 2016: 2016 initial scoring observation: no affirmative released in-scope AI evidence is credited in this strand. Zero is an evidence-bounded score, not a claim that the capability was absent. Evidence C. |
| AI platform stack | 1.5 | 2026: Documentation2026-05-13/20; Documented: RAG knowledge base; AWS us-east-1 processing; required Bedrock runtime endpoint identifies runtime service, not a specific model. Outbound443/API/S3/logging; blocked endpoints can produce documentation-only fallback. Monthly token quota resets. Bedrock product-context RAG; no general backed-up business-data service established. Evidence A. ai109how; ai109pre; ai109sec |
| AI-assisted operations | 4.5 | 2026: 10.9+; documentation 2026-05-13, GA day unverified; Documented available: ZVM UI assistant for VMware Enterprise customers: RAG over official docs/live ZVM context. Signed-in user RBAC controls reads, VPG edits and failover tests; view-only cannot change configuration. Available role-controlled VPG changes/failover tests; exact first GA and affirmative approval contract unresolved. Evidence A. ai109; ai109how; ai109sec |
| Agent openness | 4 | 2026: 10.9+; documentation 2026-05-13; Documented available: Official MCP local deployment for enterprise VMware; protection/RPO/alerts/task queries and starting/stopping failover tests. Overview does not disclose a complete per-tool audit-retention policy. Official available local MCP; complete invocation-log retention/governance insufficient for 5. Evidence C. zvmMCP; ai109sec |
AI say-do sample: 3 recorded announcement rows; 1 GA/shipped matches, 0 preview/early/limited at announcement, 1 partial, 1 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. "Shipped" may be a vendor availability assertion rather than an independently verified first-GA day.
Reading
Zerto is extending journal-based VM recovery with vaulting and conversational operator tools. The release record supports cross-cloud failover, long-term repositories and role-controlled failover tests, with current first-GA and matrix gaps retained. VM-focused protection and paired-site upgrade rules constrain its coverage outside disaster recovery.
Open questions and evidence caveats
- Unchanged annual values carry the last scored release; they do not certify a frozen compatibility matrix or exact first-feature GA. Some checkpoint-derived jumps may lag the true first shipment.
- Unverified AI strands receive zero credited evidence; this is a conservative estimate rather than a vendor-wide absence claim. Preview/limited capabilities add at most half a point beyond the preceding established score.
- Say-do counts are a bounded research sample. Same-day/release-note announcements and post-release blogs are not promises delivered instantly. Missing outcome dates do not prove non-delivery.
- Commercial/exit terms not reconstructed use explicit provisional midpoint estimates; executed regional contracts may differ.
- cyber: 2016 baseline is provisional; no frozen checkpoint fact.
- storage: 2016 baseline is provisional; no frozen checkpoint fact.
- platforms: 2016 baseline is provisional; no frozen checkpoint fact.
- DR remains 4.5 using the accumulated CDP/cross-cloud/failback record; exact current topology and recovery-test-report parity are not frozen, so a reference 5 is withheld. Partial 2026 runbook/platform claims do not earn a new full-reference step. Physical and database-native inclusion remains unresolved. Zerto 4.5 March 7/9 and 5.0 November 8/15 date conflicts remain within the same scored years.
Related reading
More from Enterprise Backup Ledger 2026
- Overview: all platforms side by side
- Enterprise Backup Ledger Methodology: How Every Score Is Built
- Acronis Cyber Protect: Enterprise Backup Ledger 2026
- Arcserve UDP: Enterprise Backup Ledger 2026
- Bacula Enterprise: Enterprise Backup Ledger 2026
- Cohesity DataProtect / NetBackup: Enterprise Backup Ledger 2026
- Commvault Cloud: Enterprise Backup Ledger 2026
- Dell: Enterprise Backup Ledger 2026
- Druva Enterprise Workloads: Enterprise Backup Ledger 2026
- Huawei OceanProtect DataBackup: Enterprise Backup Ledger 2026
- HYCU R-Cloud: Enterprise Backup Ledger 2026
- IBM Storage Defender / Storage Protect: Enterprise Backup Ledger 2026
- NAKIVO Backup & Replication: Enterprise Backup Ledger 2026
- OpenText Data Protector: Enterprise Backup Ledger 2026
- Rubrik Security Cloud: Enterprise Backup Ledger 2026
- Sangfor backup / DR software candidate: Enterprise Backup Ledger 2026
- Storware Backup and Recovery: Enterprise Backup Ledger 2026
- Veeam Data Platform: Enterprise Backup Ledger 2026