Your data sits across dozens of AWS accounts and a VMware cluster. Its backups shouldn’t depend on a script in each one — AWS Backup protects EC2, S3, RDS, DynamoDB, EFS and on-prem VMware from one set of policies, with free Vault Lock, an air-gapped vault and scheduled restore tests — in Mumbai or Hyderabad.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers AWS Backup — including Vault Lock, the logically air-gapped vault, restore testing and the VMware Backup gateway. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Policy-based backup means one plan decides what is copied, how often and for how long, across every account.
What consolidation actually replaces, dimension by dimension.
| Dimension | Snapshot scripts per account | AWS Backup |
|---|---|---|
| Coverage | Snapshot scripts per service, per account | One plan across EC2, RDS, S3, EFS, DynamoDB and VMware |
| New accounts | Protected when someone remembers | An Organizations backup policy covers them from day one |
| Deletion risk | An admin or attacker can delete snapshots | Compliance-mode Vault Lock refuses every early delete |
| Isolation | Copies in the same account as production | An air-gapped vault in a service-owned account |
| Proof | A restore tried once, after the incident | Scheduled restore tests with timings and audit reports |
| What it is NOT | — | Backup for Hyper-V, physical servers or SaaS apps |
The cheapest test: lock one vault in governance mode, back up one RDS database to it, and schedule a weekly restore test.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Rules set frequency, lifecycle and copy actions; resources join by tag or ARN, and AWS Organizations backup policies push the same plan to every member account.
Each Region holds vaults of recovery points, up to 1,000,000 per vault by default; Vault Lock in governance or compliance mode blocks deletes and early expiry.
A vault locked in compliance mode by default and stored in an AWS Backup service-owned account, shareable through AWS RAM and recoverable via multi-party approval.
A free VM on vSphere 6.7, 7 or 8 that backs VMware VMs up into AWS Backup, four jobs per gateway at a time; Hyper-V and physical servers are not supported.
Backup plans write into vaults in your account — locked by Vault Lock, isolated in an air-gapped vault, proven by restore tests.
AWS Backup puts every AWS account under one backup policy, with locks no one can lift early.
EC2, EBS, S3, RDS, Aurora, DynamoDB, EFS, FSx, Redshift, EKS and SAP HANA on EC2 are scheduled from the same backup plans.
AWS Organizations backup policies apply a plan to member accounts, so a new account is protected without anyone writing a job.
The free Backup gateway VM protects vSphere 6.7, 7 and 8 VMs, and VMware Cloud on AWS, under the same plans as cloud resources.
In compliance mode, once a grace time of at least 72 hours ends, no user, root or AWS can delete recovery points before expiry.
Air-gapped vaults sit in a service-owned account, locked by default, and multi-party approval restores them if your account is lost.
Copy rules send recovery points across Regions or accounts; DynamoDB needs advanced features to copy, and Redshift Serverless cannot.
Plans restore chosen or random recovery points on a schedule, time each job, optionally validate, then delete what they restored.
GuardDuty Malware Protection scans EC2, EBS and S3 recovery points for malware, billed by GuardDuty rather than AWS Backup.
Backup Audit Manager checks controls such as retention and restore-test results and builds reports, at $0.00125 per evaluation.
An AWS Backup overview, the logically air-gapped vault, a restore testing plan, and a re:Invent 2025 session on ransomware recovery. All from AWS’s official channels.
What AWS Backup centralises: plans, vaults and policies across AWS services.
Creating an air-gapped vault, copying into it and sharing it to another account.
Building a restore testing plan and reading the timed results it produces.
A ransomware-recovery design built on locked vaults, isolated copies and tested restores.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
There are no editions, seats or terms. AWS Backup bills storage per GB-month by Region (warm $0.055 and cold $0.011 in Mumbai) plus restores per GB and $1.65 per recovery point tested. Vault Lock adds nothing, and EC2 and EBS backups bill as EBS snapshots.
A logically air-gapped vault keeps copies in an AWS Backup service-owned account, compliance-locked by default and shareable to a clean account through AWS RAM. Since November 2025 it can be the primary target, so the one copy you keep can be the isolated one.
Restore testing plans restore recovery points on a cadence, record how long each took, optionally validate them and clean up afterwards. Backup Audit Manager turns the results into reports, which is the evidence an auditor or a cyber-recovery review asks for.
It protects AWS services and on-prem VMware only: no Hyper-V, physical servers, Microsoft 365, Google Workspace or Salesforce. Every copy stays inside AWS. Gartner names AWS a Leader for cloud platforms, but AWS is not in Gartner’s backup Magic Quadrant.
List accounts, Regions and resource types, mark what is regulated, and note any VMware or Hyper-V hosts outside AWS.
Set rules and lifecycles, choose governance or compliance Vault Lock, and decide where the air-gapped copy lives.
Push backup policies to member accounts, tag resources into plans, and deploy the Backup gateway for vSphere in Mumbai.
Create restore testing plans for EC2, RDS and S3, add validation, and record each restore time against your RTO.
Let the compliance lock pass its grace time, share the air-gapped vault to a recovery account, and turn on audit reports.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Organizations backup policies meant the 40 accounts our platform team created last quarter were covered on day one, with no ticket raised.”
“We moved our second copy into a logically air-gapped vault and shared it to a recovery account. The tabletop finally had a clean answer.”
“Restore testing runs weekly against random RDS points. The audit pack used to take two days; now it is a report we download.”
“Our surprise was the EBS snapshot line, not the AWS Backup one. Model snapshot growth before you set daily retention to a year.”
“The gateway handles our vSphere 7 cluster, but the Hyper-V hosts needed a second product. Check every hypervisor before you commit.”
“We set compliance mode, then found test points marked to keep forever. Read the grace-time warning twice before it expires.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the AWS backup market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Metered per GB-month; warm storage $0.055 in Mumbai.
The grid nobody publishes — how far the backup copy sits from the account an attacker could take vs how many AWS services one policy protects.
Air-gapped vault in a service-owned account; widest AWS list.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Veeam Backup for AWS, N2W Backup & Recovery, Druva Cloud Workloads, Commvault Cloud (Clumio) and Rubrik Security Cloud — on deployment, coverage, price, isolation, support and India.
| Dimension | AWS Backup | Veeam Backup for AWS | N2W Backup & Recovery | Druva Cloud Workloads | Commvault Cloud (Clumio) | Rubrik Security Cloud |
|---|---|---|---|---|---|---|
| What it is | AWS’s own backup service | Backup inside your AWS | Policy snapshot platform | SaaS cloud backup | Serverless AWS backup | Cyber-resilience suite |
| Deployment | Nothing to deploy | Appliance you run | Server in your account | SaaS, agentless | SaaS, serverless | SaaS control plane |
| AWS services covered | Widest AWS list | EC2, RDS, DynamoDB… | EC2, EBS, RDS, S3… | EC2, EBS, RDS, S3 | S3, EBS, RDS, DynamoDB | EC2, RDS, S3, DynamoDB |
| Other clouds, on-prem | VMware only off AWS | Azure, GCP, on-prem | AWS, Azure, Google | Azure, data centre, SaaS | AWS-first; GCP coming | Azure, GCP, DC, SaaS |
| Pricing model | Per GB-month, metered | Per instance (VUL) | Flat monthly edition | Credits, on quote | Per GiB-month, public | Subscription, on quote |
| Published entry price | $0.055/GB-month Mumbai | Free for 10 instances | $249 a month | Not published | $0.025/GiB-month S3 | Not published |
| Included vs add-on | Lock free, tests metered | Free tier trims services | DR in every edition | Snapshots billed by AWS | Vault in the rate | Platform subscription |
| Scale limits | 1M points per vault | Units set the ceiling | Caps by edition | Not published | Petabyte-scale S3 | Not published |
| Air gap and immutability | Lock + air-gapped vault | Object Lock you set up | Immutable snapshots | Copies outside your AWS | Vault outside accounts | Immutable, MFA enforced |
| Governance and SSO | IAM, Org policies, audit | SAML SSO, MFA | SAML SSO; local root | SAML SSO | SSO and MFA settings | SAML SSO, RBAC |
| India storage | Mumbai, Hyderabad | Your bucket, your Region | Your Regions; confirm | Mumbai region; confirm | Not documented | Not documented |
| Support | Your AWS Support plan | Paid 24/7; free = forum | 24/7 on paid plans | 24/7, 1 h critical | Via Commvault | 24x7 by phone or web |
| Lock-in and exit | Copies stay in AWS | Your S3, portable units | Native snapshots kept | Copies in Druva’s cloud | History in SecureVault | 3-year platform terms |
| Best fit | AWS-first estates | Veeam shops on AWS | Fixed-price AWS backup | Druva estates in cloud | Big S3 and databases | Rubrik-wide resilience |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
AWS Backup is one of 27 backup & recovery products TechBag carries. The Backup & Recovery guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (AWS resources you protect; cloud engineer-hour cost). Estimates model engineering time spent on per-account snapshot scripts, retention clean-up and manual restore checks at an assumed 1.5 hours per resource a year, with 70% of it removed by organisation-wide plans, locked vaults and scheduled restore tests. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Published, in USD, per Region. In Mumbai, warm storage for S3, EFS and VMware backups is $0.055 per GB-month and cold storage $0.011; restores from warm storage cost $0.022 per GB; restore testing is $1.65 per recovery point tested; the logically air-gapped vault is metered higher, at $0.0633 per GB-month for S3, EFS and VMware. EC2 and EBS backups bill as EBS snapshots, not on the AWS Backup meter. Vault Lock is free; GuardDuty bills malware scans. There is no free tier and no INR list price — AWS India invoices in rupees with GST. TechBag models your bill in INR with GST before you commit.
Best for day-to-day backup and restore
Best for a broader rollout
Best for the isolated, cyber-recovery copy
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Is everything in AWS or on VMware? Hyper-V, physical servers and SaaS apps need a different product.
Mumbai or Hyderabad? Hyderabad is opt-in and has no VMware gateway, SAP HANA or Neptune backups.
Governance or compliance Vault Lock? Compliance cannot be undone after a grace time of at least 72 hours.
Are any recovery points set to keep forever? In a compliance-locked vault they can never be deleted.
Is the isolated copy your primary target or a second copy, and which account will it be shared to via AWS RAM?
Have you modelled EBS snapshot growth? EC2 and EBS backups bill as snapshots, not on the AWS Backup meter.
Which resources get scheduled restore tests, how often, and who reads the timings against your RTO?
Will you scan recovery points with GuardDuty before a restore, and is that cost budgeted under GuardDuty?
Map your accounts and services first, or let a TechBag advisor design the plans, the lock mode and the air-gapped copy, and model the bill in INR with GST.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.