A DR product keeps a second, runnable copy of your systems somewhere else — replicated continuously, periodically, or rebuilt from backups — and fails the estate over to it in an order that works, then brings it back. The copy is the easy half. The order, the network and the failback are the product.
Veeam documents continuous data protection with RPOs in seconds for vSphere. Druva documents failover into AWS Mumbai from backups it already holds, at an RPO of hours. Both are “disaster recovery”. They are not the same purchase.
Already decided — before the runbook demo
Still yours to weigh
A way to run your systems somewhere else when the place they run is gone — power, flood, fibre cut, a hypervisor cluster that will not come back. The product keeps a second runnable copy (by continuous replication, periodic replication, or by standing up backups), fails over to it in a dependency-ordered plan — domain controllers before databases before applications — re-IPs and re-points what must change, and, when the site is back, fails back without losing what happened in between.
Two numbers define every product here. RPO — how much data you lose (seconds for continuous replication, minutes for periodic, hours for backup-based). RTO — how long until users are working again (minutes with orchestration and a warm target; hours to days by hand). Everything else is a variable: where the target is, who hosts it, whether failback is a button or a project. The data-only half of this decision is the backup and recovery guide; what to do when the second copy is also the attacker’s is the cyber-recovery guide.
The most common mis-purchase
A replication product bought as the ransomware plan. Replication copies the encryption to the second site within its RPO — seconds, if you paid for the good tier. DR assumes the source is trustworthy. Cyber recovery assumes it is not.
Often confused withBackup & Recovery — restoring data, versus restoring operations →·Cyber Recovery — when the replica is the attacker's copy too →·SaaS Backup — Microsoft runs the service; DR for your own estate is this page →
The four routes of backup and cyber resilience — and which one is yours →
Two pairs this buyer confuses, and nothing more. The first pair is two numbers that get used interchangeably; the second is three mechanisms that get sold as tiers. They are not tiers — they answer different failure modes.
RPO — how much you lose
Recovery point objective: the age of the last good copy when the failure hits. Continuous replication (Veeam CDP, Cohesity SiteContinuity) — seconds. Periodic replication (Commvault, NetBackup) — minutes. Backup-based recovery (Druva, Acronis, Rubrik recovery plans, Barracuda) — hours. A tight RPO costs storage, WAN and a warm target; it says nothing about how fast you are back.
RTO — how long until you are back
Recovery time objective: the time from failure to users working. Orchestration with boot order, re-IP and a warm target — minutes. Hand-built failover from backups — hours to days. A product can have a five-minute RTO on paper and a two-day RTO over your network. It is measured, or it is a guess.
HA vs DR
High availability keeps a system up through a component failure — a cluster, a second node, a load balancer — in the same place, automatically, with no data loss. DR moves the estate to another place after the place itself fails. HA does not survive the site; DR does not survive a bad transaction being replicated. Most estates need both; they are different purchases.
DR vs backup
Backup restores data to a point in time, slowly, anywhere — it is the copy of record. DR restores operations, fast, to a prepared place — from replicas or from backups stood up in order. Backup without DR is a long outage; DR without backup is a fast failover to whatever was replicated, including the corruption.
Seven variables decide this purchase. The instrument tests the ones documentation can verify (RPO class, target, orchestration, scope, India site); achievable RTO, failback time and the regulator’s expectations are prose because the honest answers come from your last drill, not a datasheet.
Achievable RPO and RTO — tested, not claimed
Seconds / minutes / hours by mechanism; then the number you measured in a real drill with the real application stack over the real network. If it has never been measured, it is unknown.
Failover target
A second site you own, your own cloud account (AWS, Azure, GCP, OCI), or the vendor's hosted DRaaS. Decides who pays for the target on a quiet day and on the day.
Orchestration and runbook automation vs manual failover
Boot order, dependencies, re-IP, scripts, one click — or a wiki page and a phone tree. The RTO lives here.
Failback
Bringing the estate home without losing what happened while you were away — and the step where most DR plans actually break. Documented as one operation at most products here; flagged where not.
Testing without disrupting production
Isolated test networks, automated reports, drill evidence for the auditor. Documented everywhere here; done quarterly almost nowhere.
RBI and sectoral business-continuity expectations
Documented RPO/RTO, periodic drills with evidence, data in India for regulated entities. Your design artefact on most products; hosted for you on one.
India DR site availability
A vendor-hosted failover target in India (Druva's AWS Mumbai DRaaS), your own second Indian site or India cloud region (the rest), or not documented (flagged).
Set what is true for you. Products that miss a constraint fade and carry the reason; where documentation cannot settle your case they are flagged, not removed. Every chip is reversible.
The RPO you need
Where it fails over to
What must fail over
How it fails over
India
Estate size
Measured RTO, failback duration and regulator expectations are in the notes below, not chips — they are drill results and design artefacts, not datasheet lines.

per workload (VUL) / year reported; replication and CDP are in every edition, and Premium adds Recovery Orchestrator, automated testing and the ransomware warranty; the DR site and its compute are yours
VMware-centric estates that want replication and continuous data protection to a second site or cloud, with one-click failover plans, automated testing and documented failback — on the licence they already run for backup.
The catch: CDP replicates into VMware vSphere only (v13 Universal CDP brings other machines into vSphere); the secondary site, its hypervisor and its storage are your cost and your build; Recovery Orchestrator is Premium — Foundation has replication without the orchestration.

per VM / instance or per front-end TB on quote; replication to a second site or to AWS, Azure, GCP and OCI; recovery groups with boot order; the target is yours
Mixed estates that want replication, cross-hypervisor and cloud-target failover and policy-driven recovery groups from the same platform that backs them up.
The catch: Periodic replication rather than continuous (minutes, not seconds); the failover target — second site or cloud account — is yours to run and pay for; quote-only.

per protected cloud application / resources on quote; rebuilds the whole cloud application — infrastructure, configuration, dependencies — in a new account or region
Cloud-native estates (AWS, Azure, GCP) that need the application, not only its data, rebuilt after an account compromise or region loss — with periodic rebuild tests.
The catch: Cloud-native applications only — no VMware, no physical; RPO follows the snapshot schedule; failback to the original account after rebuild is not documented as a one-step operation.

licensed on the Cohesity platform (per TB) on quote; continuous replication for VMware to a second Cohesity cluster or to AWS; application-level runbooks
Cohesity estates that want near-zero RPO for VMware workloads and orchestrated, tested failover to a second cluster or to AWS, from the backup platform's console.
The catch: Continuous replication is VMware-centric; the second cluster or the AWS account is yours to own; Hyper-V and Nutanix are backup-level protection, not continuous DR here; quote-only.

enterprise licensing on quote alongside NetBackup (per front-end TB); resiliency orchestration across data centre and cloud with rehearsals
Large NetBackup estates that want cross-site and cloud recovery orchestration, rehearsal and reporting on the platform they already operate.
The catch: Enterprise-priced and enterprise-operated; the orchestration layer is a separate licence from NetBackup itself; the DR site is yours.

part of Rubrik Security Cloud Enterprise Edition (reported ~$130 per back-end TB / month on three-year terms); recovery plans with boot order and test mode for VMware and Azure
Rubrik estates that want application-level recovery plans — boot order, dependencies, test mode — from backups and replicas in the same console as the cyber-recovery posture.
The catch: Recovery from backups and replicas, not continuous data protection — RPO is the backup interval, not seconds; VMware and Azure are documented, other hypervisors are not; the target site is yours.
per protected VM / month on quote on top of Hybrid Workloads; failover into your AWS account (Mumbai region available); one-click runbooks, failback to on-prem; no second site to build
Organisations without a second data centre that want VMware, Hyper-V and physical servers failed over into AWS — in India — from the backup copies Druva already holds, with documented failback.
The catch: RPO is the backup frequency (hours), not replication; AWS only as the target, and the failover compute runs in your AWS account at your cost; quote-only.

per-GB storage plus compute points consumed during test and production failover, through MSPs; runbooks; failover into Acronis Cloud; failback to original or new hardware
MSP-run SMBs that want servers and VMs recoverable into Acronis Cloud in minutes with runbooks and a test failover they can actually run, on the same agent as backup and security.
The catch: Billed in compute points and GB through a partner — no public rate card; whether the Mumbai data centre hosts DR (not only backup storage) is not documented; enterprise scale is not where it is documented.

per TB / year list for replication to Barracuda Cloud (appliance or Vx priced apart); LiveBoot runs VMs from the appliance or from Barracuda Cloud; site-to-site replication between appliances
Mid-market sites with a Barracuda appliance that want VMs bootable from the local appliance or from Barracuda's cloud after a site loss, at a flat replication price.
The catch: No runbook orchestration — LiveBoot is per VM, not a dependency-ordered plan; RPO is the backup interval; an India region for Barracuda Cloud is not documented; VMware and Hyper-V only.
quote-only; pooled storage for a flat fee under Axcient’s fair-use policy, 3-, 5-, 7- or 10-year retention, appliances bought or leased; a 15-minute RPO is Axcient’s claim
MSPs protecting client servers that want nightly boot verification, immutable snapshots and a Virtual Office in Axcient’s cloud while a site is down.
The catch: Axcient stores backups in the US and (from August 2026) Australia — India only through a BYOC vault you run; no public price; built for MSPs rather than in-house IT.

through your MSP: a flat monthly fee per appliance by capacity and cloud retention (1-year, 7-year or infinite), hardware included and returned at the end; no charge for cloud DR, egress or DR testing; Datto publishes no price
Servers protected by an MSP that wants instant recovery on a local appliance and one-click failover to the Datto Cloud, with DR tests at no extra charge.
The catch: Sold only through MSPs with no published price; cloud failover is to the Datto Cloud (nearest site Singapore — no India data centre), not your own Azure or AWS, and it is for emergencies and tests, not production.

through your MSP: a flat fee that includes egress, virtualisation and DR testing; Azure VMs back up to a Datto-owned Azure tenant and replicate hourly to the Datto Cloud; Datto publishes no price
Azure workloads whose MSP wants a copy outside the customer’s own Azure tenant, and the option to start the VMs in Azure or in the Datto Cloud if Azure is down.
The catch: Azure VMs and Azure Files only; Datto maps no Indian Azure region (Southeast Asia goes to Sydney); quote-only through an MSP; failover runbooks and failback are not documented.

a licence add-on to Nutanix Cloud Infrastructure (NCI) Pro and included in NCI Ultimate; NearSync and synchronous (zero-RPO) replication need the right tier; the DR site — your second cluster, or Nutanix Cloud Clusters (NC2) in AWS or Azure — is yours
Nutanix estates that want replication and orchestrated recovery plans between their own clusters — down to zero data loss on synchronous links — without buying a separate DR product.
The catch: Nutanix-to-Nutanix only: it protects workloads on the Nutanix platform, not the rest of the estate; zero-RPO synchronous replication needs low-latency links between sites; quote-only.
Cove is one flat rate per server or workstation with cloud storage included; Standby Image keeps a bootable VM ready in your own Hyper-V, ESXi or Azure, and N-able’s DRaaS recovers in its cloud; whether Standby Image costs extra is not published
MSP-managed servers that need a warm standby VM ready to boot — on the client’s own Hyper-V or ESXi host, or in Azure — with automated recovery testing, from the backup they already run.
The catch: A capability of Cove, not a separate DR product: no runbooks with boot order, failback is not documented, and Cove stores backups in 17 countries, none of them in India.

per protected instance a month after its first 31 days free; the target is always Azure (another region, another zone, or from your data centre); replica disks, snapshots, transfer and failover compute are billed on top; the same rate in the India regions
Estates already on Azure — or ready to make Azure the DR site — that want region-to-region, zone-to-zone or on-premises-to-Azure failover, with recovery plans and drills that leave replication running.
The catch: Into Azure only — failover to your own second site was retired; recovery points last 15 days at most, so it is not backup; the 1-hour RTO SLA lapses if the target region lacks capacity, and there is no RPO SLA.

per protected VM, perpetual or as a 1-, 3- or 5-year subscription, in two editions; HPE publishes no list price; the DR target — your second site, Azure, AWS or a service provider — and the journal storage are yours
VMware estates that need recovery points seconds apart and orchestrated, tested failover to a second site or a public cloud — and a route from VMware to HPE VM Essentials.
The catch: Not backup — the journal keeps 30 days at most; Hyper-V only on the older 9.7 line, and no Nutanix AHV, physical servers or Kubernetes; HPE publishes no list price.

per 36-month AWS Marketplace contract covering 10 EC2 instances (about $599 per instance a year); copies EBS snapshots to another region, zone or account; EC2 and storage at the target are billed by AWS
Teams running production on EC2 that want grouped, testable failover to another AWS region, zone or account without building their own snapshot-copy tooling.
The catch: Snapshot copies, not a CDP journal — protection groups default to a 30-minute RPO; consistency is per instance, not per group; Mumbai and Hyderabad support is not published.

per workload a month on a 3-year Enterprise Essentials subscription ($3.20 on a 1-year term), the first edition with Site Recovery; Pro editions lack it; replication is scheduled, so the RPO is your interval; the DR site is yours
VMware, Hyper-V or EC2 estates that want ordered failover, scheduled test runs and failback scripted in the console that backs them up, at a published price.
The catch: Site Recovery covers VMware, Hyper-V and EC2 only — not Proxmox, Nutanix AHV or physical servers; replication is scheduled, so the RPO is your interval; Essentials caps at 50 workloads.

per VMware VM a month ($2.35 on a 3-year term, $2.95 on 1-year), or $550 per socket perpetual; not in Pro editions; the RPO is configurable from 1 second to 1 hour
VMware vSphere estates that want near-zero data loss for their critical VMs at a published per-VM price instead of a quote-only CDP product.
The catch: vSphere 7.0–9.1 only and generally available only since October 2025; a failback step for it is not documented, and the 1-second RPO is a setting, not a guarantee.

per replicating source server an hour (about $20 a month), the same in Mumbai and Hyderabad — the DRS fee only: staging EBS volumes, snapshots, replication servers and drill or recovery compute are billed on top; AWS India invoices in INR with GST
Estates that want AWS as the DR site for physical, VMware, Hyper-V or other-cloud servers — continuous replication, drills that leave replication running, and ordered recovery plans.
The catch: AWS is the only target; the per-server fee is a fraction of the bill once storage and compute are added; 300 servers replicate per account per Region (more through staging accounts).

per front-end TB a year for UDP Premium on the US e-store; Virtual Standby is in every edition, Instant VM and cloud standby from Advanced, Assured Recovery tests on Premium; DR Runbooks is a separately quoted add-on that recovers into your own AWS account, and AWS bills the resources
Teams already backing up with UDP who want standby VMs on-premises or in EC2, Azure or Google Cloud, and scheduled recovery tests, without a second DR product.
The catch: Backup-based: the RPO is the backup interval, not seconds (that is Arcserve RHA); DR Runbooks recovers into AWS only in its first release; Nutanix AHV standby needs Premium.

quoted per protected server; Arcserve’s e-store does not sell RHA and no list price is published; the replica — a second site, a VMware or Hyper-V host, or EC2 or Azure — is yours to provide and pay for
Windows and Linux estates running SQL Server, Exchange, Oracle or file servers that need continuous byte-level replication, heartbeat failover and rollback to a point before ransomware.
The catch: The 18.0 line dates from 2019 (service packs to September 2025); there is no published price; you build and run the replica site; the RPO of seconds is Arcserve’s claim, not an SLA.

Broadcom publishes no price; bought as Advanced Cyber Compliance (a VCF-only add-on, per core per Broadcom’s VCF 9.1 FAQ) or as standalone Site Recovery Manager for VCF, vSphere Foundation or older vSphere; commit subscription billed upfront in USD; the recovery site is yours
vSphere estates that want recovery plans, non-disruptive tests and automated failback run from vCenter, between their own sites or into Azure VMware Solution, Google Cloud VMware Engine or Amazon EVS.
The catch: vSphere VMs only; the RPO depends on the licence (1 minute to 24 hours with ACC, 5 minutes on a legacy SRM licence, over 5 minutes on VCF alone); 9.1 needs a redeploy from the standalone appliances.

per protected VM plus per protected TiB, minimum 10 TiB per region in 1 TiB steps; recovery runs in VMware Cloud on AWS, with at least two pilot-light hosts billed separately; Broadcom publishes no price; USD, upfront
vSphere estates that want an immutable off-site copy and a clean-room ransomware recovery without building a second data centre, recovering VMs in native vSphere format.
The catch: Snapshot-based: every 30 minutes on high-frequency snapshots, 4 hours on standard, never seconds; recovers only into VMware Cloud on AWS; Mumbai is listed, Hyderabad is for existing customers only.

per server or VM by tier, on top of Forever Cloud capacity sold in 500 GB blocks, on 1-, 3- or 5-year terms; Kaseya publishes no price; the Unitrends Cloud runs in the US, Canada, Germany, the UK, Ireland and Australia — none in India
Teams already backing up with a Unitrends appliance or Backup Software who want a managed DR site with a contractual recovery-time SLA and scheduled recovery tests run for them.
The catch: Needs a Unitrends appliance or Backup Software as the source; backup-based, so the RPO is your replication schedule; disaster is declared by phone and failback ships data back overnight; no India region.

quote-only, by server — reseller catalogues list per-physical-server and per-VM licences with yearly maintenance; OpenText Migrate (same engine) is a separate product and the one-day QuickStart setup is a paid service; the standby is a server you run
Teams that need a warm standby for individual Windows and Linux servers — byte-level changes streamed to physical, any hypervisor or AWS, Azure or Google Cloud, with heartbeat failover that updates DNS.
The catch: Server-by-server replication, not multi-tier runbooks; ‘moments behind’ is OpenText’s wording, with no RPO SLA, and corruption or ransomware replicates too, so keep backups. OpenText classes the SMB and consumer security line it is sold from as non-core and is divesting non-core units — ask about the roadmap.

per GB of used capacity a month pay-as-you-go ($0.038 on 12 months, $0.034 on 36), billed per TiB-hour, 30-day trial; SnapMirror itself is part of ONTAP One, not sold separately; async SnapMirror goes down to a 5-minute schedule
ONTAP estates running VMware on NFS or VMFS datastores, or Kubernetes, that want orchestrated failover, FlexClone test runs that use no extra capacity, and failback on SnapMirror they already own.
The catch: Needs ONTAP at both ends; runs only in the SaaS NetApp Console (not restricted or air-gapped mode); no vSAN or Hyper-V; zero RPO comes from SnapMirror sync in ONTAP, not from the service.
Seconds of RPORules out Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), NetBackup — Resiliency Platform & IT Analytics (Cohesity), Axcient x360Recover, Datto SIRIS & ALTO (BCDR appliances · Datto Cloud), N-able Cove Data Protection — Standby Image & DRaaS, Azure Site Recovery, HPE Zerto In-Cloud for AWS, NAKIVO Backup & Replication — Site Recovery (Enterprise editions), VMware Live Recovery (now VCF Protection and Recovery) — Site Recovery and vSphere Replication, VMware Live Recovery Cloud and NetApp Disaster Recovery (+ SnapMirror) — periodic replication (minutes), not continuous; Commvault Cloud Rewind, Rubrik Orchestrated Application Recovery, Druva Disaster Recovery as a Service (AWS), Acronis Disaster Recovery (Cyber Protect Cloud add-on), Barracuda Backup — Cloud LiveBoot & replication, Datto Backup for Microsoft Azure, Arcserve UDP — Virtual Standby, Instant VM and DR Runbooks and Unitrends DRaaS (Premium · Elite · Standard · Unlimited) — recovers from backups or snapshots (hours), not replication. That leaves Veeam Data Platform — Replication & CDP (every edition) · Recovery Orchestrator (Premium), Cohesity SiteContinuity (DataProtect DR), Nutanix Disaster Recovery (NCI Pro add-on · included in NCI Ultimate), HPE Zerto Software (Enterprise Cloud · Advanced Resilience), NAKIVO Real-Time Replication for VMware, AWS Elastic Disaster Recovery, Arcserve Replication and High Availability (RHA) 18 and OpenText Availability (formerly Carbonite Availability).
Minutes of RPORules out Commvault Cloud Rewind, Rubrik Orchestrated Application Recovery, Druva Disaster Recovery as a Service (AWS), Acronis Disaster Recovery (Cyber Protect Cloud add-on), Barracuda Backup — Cloud LiveBoot & replication, Datto Backup for Microsoft Azure, Arcserve UDP — Virtual Standby, Instant VM and DR Runbooks and Unitrends DRaaS (Premium · Elite · Standard · Unlimited) — recovers from backups or snapshots (hours), not replication. That leaves Veeam Data Platform — Replication & CDP (every edition) · Recovery Orchestrator (Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Cohesity SiteContinuity (DataProtect DR), NetBackup — Resiliency Platform & IT Analytics (Cohesity), Axcient x360Recover, Datto SIRIS & ALTO (BCDR appliances · Datto Cloud), Nutanix Disaster Recovery (NCI Pro add-on · included in NCI Ultimate), N-able Cove Data Protection — Standby Image & DRaaS, Azure Site Recovery, HPE Zerto Software (Enterprise Cloud · Advanced Resilience), HPE Zerto In-Cloud for AWS, NAKIVO Backup & Replication — Site Recovery (Enterprise editions), NAKIVO Real-Time Replication for VMware, AWS Elastic Disaster Recovery, Arcserve Replication and High Availability (RHA) 18, VMware Live Recovery (now VCF Protection and Recovery) — Site Recovery and vSphere Replication, VMware Live Recovery Cloud, OpenText Availability (formerly Carbonite Availability) and NetApp Disaster Recovery (+ SnapMirror).
Vendor-hosted failoverRules out Veeam Data Platform — Replication & CDP (every edition) · Recovery Orchestrator (Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Commvault Cloud Rewind, Cohesity SiteContinuity (DataProtect DR), NetBackup — Resiliency Platform & IT Analytics (Cohesity), Rubrik Orchestrated Application Recovery, Nutanix Disaster Recovery (NCI Pro add-on · included in NCI Ultimate), Azure Site Recovery, HPE Zerto In-Cloud for AWS, NAKIVO Backup & Replication — Site Recovery (Enterprise editions), NAKIVO Real-Time Replication for VMware, AWS Elastic Disaster Recovery, Arcserve UDP — Virtual Standby, Instant VM and DR Runbooks, Arcserve Replication and High Availability (RHA) 18, VMware Live Recovery (now VCF Protection and Recovery) — Site Recovery and vSphere Replication, OpenText Availability (formerly Carbonite Availability) and NetApp Disaster Recovery (+ SnapMirror) — fails over to a site or cloud account you own and run. That leaves Druva Disaster Recovery as a Service (AWS), Acronis Disaster Recovery (Cyber Protect Cloud add-on), Barracuda Backup — Cloud LiveBoot & replication, Axcient x360Recover, Datto SIRIS & ALTO (BCDR appliances · Datto Cloud), Datto Backup for Microsoft Azure, N-able Cove Data Protection — Standby Image & DRaaS, HPE Zerto Software (Enterprise Cloud · Advanced Resilience), VMware Live Recovery Cloud and Unitrends DRaaS (Premium · Elite · Standard · Unlimited).
Your cloud account as the targetRules out Acronis Disaster Recovery (Cyber Protect Cloud add-on), Barracuda Backup — Cloud LiveBoot & replication, Datto SIRIS & ALTO (BCDR appliances · Datto Cloud), NAKIVO Real-Time Replication for VMware, VMware Live Recovery Cloud and Unitrends DRaaS (Premium · Elite · Standard · Unlimited) — does not fail over into your cloud account. That leaves Veeam Data Platform — Replication & CDP (every edition) · Recovery Orchestrator (Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Commvault Cloud Rewind, Cohesity SiteContinuity (DataProtect DR), NetBackup — Resiliency Platform & IT Analytics (Cohesity), Rubrik Orchestrated Application Recovery, Druva Disaster Recovery as a Service (AWS), Axcient x360Recover, Datto Backup for Microsoft Azure, Nutanix Disaster Recovery (NCI Pro add-on · included in NCI Ultimate), N-able Cove Data Protection — Standby Image & DRaaS, Azure Site Recovery, HPE Zerto Software (Enterprise Cloud · Advanced Resilience), HPE Zerto In-Cloud for AWS, NAKIVO Backup & Replication — Site Recovery (Enterprise editions), AWS Elastic Disaster Recovery, Arcserve UDP — Virtual Standby, Instant VM and DR Runbooks, Arcserve Replication and High Availability (RHA) 18, VMware Live Recovery (now VCF Protection and Recovery) — Site Recovery and vSphere Replication, OpenText Availability (formerly Carbonite Availability) and NetApp Disaster Recovery (+ SnapMirror).
Your own second siteRules out Commvault Cloud Rewind, Druva Disaster Recovery as a Service (AWS), Acronis Disaster Recovery (Cyber Protect Cloud add-on), Datto Backup for Microsoft Azure, Azure Site Recovery, HPE Zerto In-Cloud for AWS, AWS Elastic Disaster Recovery, VMware Live Recovery Cloud and Unitrends DRaaS (Premium · Elite · Standard · Unlimited) — vendor-hosted or cloud-only failover. That leaves Veeam Data Platform — Replication & CDP (every edition) · Recovery Orchestrator (Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Cohesity SiteContinuity (DataProtect DR), NetBackup — Resiliency Platform & IT Analytics (Cohesity), Rubrik Orchestrated Application Recovery, Barracuda Backup — Cloud LiveBoot & replication, Axcient x360Recover, Datto SIRIS & ALTO (BCDR appliances · Datto Cloud), Nutanix Disaster Recovery (NCI Pro add-on · included in NCI Ultimate), N-able Cove Data Protection — Standby Image & DRaaS, HPE Zerto Software (Enterprise Cloud · Advanced Resilience), NAKIVO Backup & Replication — Site Recovery (Enterprise editions), NAKIVO Real-Time Replication for VMware, Arcserve UDP — Virtual Standby, Instant VM and DR Runbooks, Arcserve Replication and High Availability (RHA) 18, VMware Live Recovery (now VCF Protection and Recovery) — Site Recovery and vSphere Replication, OpenText Availability (formerly Carbonite Availability) and NetApp Disaster Recovery (+ SnapMirror).
Hyper-VRules out Commvault Cloud Rewind, Cohesity SiteContinuity (DataProtect DR), Rubrik Orchestrated Application Recovery, Axcient x360Recover, Datto Backup for Microsoft Azure, Nutanix Disaster Recovery (NCI Pro add-on · included in NCI Ultimate), HPE Zerto Software (Enterprise Cloud · Advanced Resilience), HPE Zerto In-Cloud for AWS, NAKIVO Real-Time Replication for VMware, VMware Live Recovery (now VCF Protection and Recovery) — Site Recovery and vSphere Replication, VMware Live Recovery Cloud and NetApp Disaster Recovery (+ SnapMirror) — Hyper-V not documented for DR here. That leaves Veeam Data Platform — Replication & CDP (every edition) · Recovery Orchestrator (Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), NetBackup — Resiliency Platform & IT Analytics (Cohesity), Druva Disaster Recovery as a Service (AWS), Acronis Disaster Recovery (Cyber Protect Cloud add-on), Barracuda Backup — Cloud LiveBoot & replication, Datto SIRIS & ALTO (BCDR appliances · Datto Cloud), N-able Cove Data Protection — Standby Image & DRaaS, Azure Site Recovery, NAKIVO Backup & Replication — Site Recovery (Enterprise editions), AWS Elastic Disaster Recovery, Arcserve UDP — Virtual Standby, Instant VM and DR Runbooks, Arcserve Replication and High Availability (RHA) 18, Unitrends DRaaS (Premium · Elite · Standard · Unlimited) and OpenText Availability (formerly Carbonite Availability).
Physical serversRules out Commvault Cloud Rewind, Rubrik Orchestrated Application Recovery, Datto Backup for Microsoft Azure, Nutanix Disaster Recovery (NCI Pro add-on · included in NCI Ultimate), HPE Zerto Software (Enterprise Cloud · Advanced Resilience), HPE Zerto In-Cloud for AWS, NAKIVO Backup & Replication — Site Recovery (Enterprise editions), NAKIVO Real-Time Replication for VMware, VMware Live Recovery (now VCF Protection and Recovery) — Site Recovery and vSphere Replication, VMware Live Recovery Cloud and NetApp Disaster Recovery (+ SnapMirror) — physical servers not documented. That leaves Veeam Data Platform — Replication & CDP (every edition) · Recovery Orchestrator (Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Cohesity SiteContinuity (DataProtect DR), NetBackup — Resiliency Platform & IT Analytics (Cohesity), Druva Disaster Recovery as a Service (AWS), Acronis Disaster Recovery (Cyber Protect Cloud add-on), Barracuda Backup — Cloud LiveBoot & replication, Axcient x360Recover, Datto SIRIS & ALTO (BCDR appliances · Datto Cloud), N-able Cove Data Protection — Standby Image & DRaaS, Azure Site Recovery, AWS Elastic Disaster Recovery, Arcserve UDP — Virtual Standby, Instant VM and DR Runbooks, Arcserve Replication and High Availability (RHA) 18, Unitrends DRaaS (Premium · Elite · Standard · Unlimited) and OpenText Availability (formerly Carbonite Availability).
Cloud-native applicationsRules out Druva Disaster Recovery as a Service (AWS), Acronis Disaster Recovery (Cyber Protect Cloud add-on), Barracuda Backup — Cloud LiveBoot & replication, Datto SIRIS & ALTO (BCDR appliances · Datto Cloud), Nutanix Disaster Recovery (NCI Pro add-on · included in NCI Ultimate), N-able Cove Data Protection — Standby Image & DRaaS, NAKIVO Real-Time Replication for VMware, Arcserve UDP — Virtual Standby, Instant VM and DR Runbooks, VMware Live Recovery (now VCF Protection and Recovery) — Site Recovery and vSphere Replication, VMware Live Recovery Cloud, Unitrends DRaaS (Premium · Elite · Standard · Unlimited), OpenText Availability (formerly Carbonite Availability) and NetApp Disaster Recovery (+ SnapMirror) — on-prem workloads only. That leaves Veeam Data Platform — Replication & CDP (every edition) · Recovery Orchestrator (Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Commvault Cloud Rewind, Cohesity SiteContinuity (DataProtect DR), NetBackup — Resiliency Platform & IT Analytics (Cohesity), Rubrik Orchestrated Application Recovery, Axcient x360Recover, Datto Backup for Microsoft Azure, Azure Site Recovery, HPE Zerto Software (Enterprise Cloud · Advanced Resilience), HPE Zerto In-Cloud for AWS, NAKIVO Backup & Replication — Site Recovery (Enterprise editions), AWS Elastic Disaster Recovery and Arcserve Replication and High Availability (RHA) 18.
Orchestrated runbooksRules out Barracuda Backup — Cloud LiveBoot & replication, Datto Backup for Microsoft Azure, N-able Cove Data Protection — Standby Image & DRaaS, HPE Zerto In-Cloud for AWS and OpenText Availability (formerly Carbonite Availability) — per-VM failover, no dependency-ordered plan. That leaves Veeam Data Platform — Replication & CDP (every edition) · Recovery Orchestrator (Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Commvault Cloud Rewind, Cohesity SiteContinuity (DataProtect DR), NetBackup — Resiliency Platform & IT Analytics (Cohesity), Rubrik Orchestrated Application Recovery, Druva Disaster Recovery as a Service (AWS), Acronis Disaster Recovery (Cyber Protect Cloud add-on), Axcient x360Recover, Datto SIRIS & ALTO (BCDR appliances · Datto Cloud), Nutanix Disaster Recovery (NCI Pro add-on · included in NCI Ultimate), Azure Site Recovery, HPE Zerto Software (Enterprise Cloud · Advanced Resilience), NAKIVO Backup & Replication — Site Recovery (Enterprise editions), NAKIVO Real-Time Replication for VMware, AWS Elastic Disaster Recovery, Arcserve UDP — Virtual Standby, Instant VM and DR Runbooks, Arcserve Replication and High Availability (RHA) 18, VMware Live Recovery (now VCF Protection and Recovery) — Site Recovery and vSphere Replication, VMware Live Recovery Cloud, Unitrends DRaaS (Premium · Elite · Standard · Unlimited) and NetApp Disaster Recovery (+ SnapMirror).
Failback documentedRules nothing out on published terms. It flags Commvault Cloud Rewind — Failback to the original environment not documented as a single operation, Axcient x360Recover — Failback to the original environment not documented as a single operation, Datto Backup for Microsoft Azure — Failback to the original environment not documented as a single operation, N-able Cove Data Protection — Standby Image & DRaaS — Failback to the original environment not documented as a single operation, NAKIVO Real-Time Replication for VMware — Failback to the original environment not documented as a single operation and Arcserve UDP — Virtual Standby, Instant VM and DR Runbooks — Failback to the original environment not documented as a single operation — marked on the cards, not removed.
DR site in IndiaRules nothing out on published terms. It flags Veeam Data Platform — Replication & CDP (every edition) · Recovery Orchestrator (Premium) — Your second site or your cloud region, Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration) — Your second site or your cloud region, Commvault Cloud Rewind — Your second site or your cloud region, Cohesity SiteContinuity (DataProtect DR) — Your second site or your cloud region, NetBackup — Resiliency Platform & IT Analytics (Cohesity) — Your second site or your cloud region, Rubrik Orchestrated Application Recovery — Your second site or your cloud region, Acronis Disaster Recovery (Cyber Protect Cloud add-on) — An India-hosted failover target is not documented, Barracuda Backup — Cloud LiveBoot & replication — An India-hosted failover target is not documented, Axcient x360Recover — Your second site or your cloud region, Datto SIRIS & ALTO (BCDR appliances · Datto Cloud) — Your second site or your cloud region, Datto Backup for Microsoft Azure — An India-hosted failover target is not documented, Nutanix Disaster Recovery (NCI Pro add-on · included in NCI Ultimate) — Your second site or your cloud region, N-able Cove Data Protection — Standby Image & DRaaS — Your second site or your cloud region, HPE Zerto Software (Enterprise Cloud · Advanced Resilience) — Your second site or your cloud region, HPE Zerto In-Cloud for AWS — An India-hosted failover target is not documented, NAKIVO Backup & Replication — Site Recovery (Enterprise editions) — Your second site or your cloud region, NAKIVO Real-Time Replication for VMware — Your second site or your cloud region, Arcserve UDP — Virtual Standby, Instant VM and DR Runbooks — Your second site or your cloud region, Arcserve Replication and High Availability (RHA) 18 — Your second site or your cloud region, VMware Live Recovery (now VCF Protection and Recovery) — Site Recovery and vSphere Replication — Your second site or your cloud region, Unitrends DRaaS (Premium · Elite · Standard · Unlimited) — An India-hosted failover target is not documented, OpenText Availability (formerly Carbonite Availability) — Your second site or your cloud region and NetApp Disaster Recovery (+ SnapMirror) — Your second site or your cloud region — marked on the cards, not removed.
Above 1,000 VMsRules nothing out on published terms. It flags Acronis Disaster Recovery (Cyber Protect Cloud add-on) — Unverified above 1,000 VMs, Barracuda Backup — Cloud LiveBoot & replication — Unverified above 1,000 VMs, Axcient x360Recover — Unverified above 1,000 VMs, Datto SIRIS & ALTO (BCDR appliances · Datto Cloud) — Unverified above 1,000 VMs, Datto Backup for Microsoft Azure — Unverified above 1,000 VMs, N-able Cove Data Protection — Standby Image & DRaaS — Unverified above 1,000 VMs, HPE Zerto In-Cloud for AWS — Unverified above 1,000 VMs, NAKIVO Backup & Replication — Site Recovery (Enterprise editions) — Unverified above 1,000 VMs, NAKIVO Real-Time Replication for VMware — Unverified above 1,000 VMs, Arcserve UDP — Virtual Standby, Instant VM and DR Runbooks — Unverified above 1,000 VMs, Arcserve Replication and High Availability (RHA) 18 — Unverified above 1,000 VMs, VMware Live Recovery Cloud — Unverified above 1,000 VMs, Unitrends DRaaS (Premium · Elite · Standard · Unlimited) — Unverified above 1,000 VMs, OpenText Availability (formerly Carbonite Availability) — Unverified above 1,000 VMs and NetApp Disaster Recovery (+ SnapMirror) — Unverified above 1,000 VMs — marked on the cards, not removed.
Tested, not claimedEvery product here documents a non-disruptive test (Veeam SureReplica and Orchestrator reports, Commvault recovery validation, Cohesity and NetBackup rehearsals, Rubrik test mode, Druva and Acronis test failover, Barracuda LiveBoot). None of that is your RPO and RTO. Those are the numbers you measured the last time you failed over the real application stack and came back; if the honest answer is never, the honest RPO is unknown. TechBag's delivery figures for real failover and failback times are [TechBag to confirm].
DR versus cyber recoveryReplication is the fastest way to copy ransomware to the second site. A DR product assumes the source is trustworthy; the moment it is not, you need an immutable backup and a clean room — the cyber-recovery guide. Veeam, Commvault, Cohesity, Rubrik and Druva sell both halves; they are different SKUs and different rehearsals.
RBI and sectoral business-continuity expectationsRBI's IT Governance and outsourcing directions, SEBI's CSCRF and IRDAI's guidelines expect documented RPO/RTO, periodic DR drills with evidence, and data in India for regulated entities. Druva's AWS Mumbai DRaaS is the documented India-hosted target here; every other product leaves the site in your hands, which for most regulated buyers means a second Indian data centre or an India cloud region — your design, and documented as such.
Network and DNSNo product on this page fails over your network. Re-IP, DNS cut-over, firewall rules, identity and the VPN are your runbook's first pages; the orchestration tools (Veeam Orchestrator, Commvault, Cohesity, Rubrik, Druva, Acronis) can script the re-IP and some DNS steps — test that they did.
Under 50 VMsRules nothing out on documentation: Acronis DR and Barracuda LiveBoot are built for the small estate; Druva DRaaS and Veeam replication start at any size; the orchestration products (Orchestrator, SiteContinuity, NetBackup resiliency) are enterprise-positioned. Where the small estate should stop at backup-plus-a-plan is delivery judgement: [TechBag to confirm].
Each shortlist names the mechanism (continuous, periodic, from backups) and where the estate would run. If you have no second site, start from the second row.
Why: Veeam CDP (every edition) and Cohesity SiteContinuity document continuous replication for vSphere with orchestrated failover and failback to a second site you own.
The trade-off: Continuous replication doubles the storage and the WAN; the second site's compute is the bill — and replication will faithfully copy the ransomware.
Why: Druva fails VMs over into your AWS account (Mumbai available) from copies it already holds; Acronis fails over into Acronis Cloud through an MSP on compute points; Veeam replicates to a cloud target you run.
The trade-off: RPO is hours for the DRaaS pair (backup frequency, not replication); the cloud compute during a real event is the number nobody modelled.
Why: Commvault replicates across VMware, Hyper-V, Nutanix and into AWS, Azure, GCP and OCI with recovery groups; NetBackup's resiliency layer orchestrates across data centre and cloud for large estates; Veeam Orchestrator covers replicas, CDP replicas, backups and storage snapshots in one plan.
The trade-off: Breadth is periodic (minutes) rather than continuous; the plan is only as good as the last rehearsal — and someone has to own it.
Why: Cloud Rewind rebuilds the application — infrastructure, configuration, dependencies — in a new account or region; Commvault and Veeam replicate and recover cloud instances and data.
The trade-off: Rebuilding the application is a different test from restoring its data — run the rebuild quarterly, and price the second region's compute for the day.
Why: Rubrik's Orchestrated Application Recovery gives boot order, dependencies and test mode over backups and replicas in the console you already run; Commvault is the like-for-like if continuous replication becomes the requirement.
The trade-off: RPO is the backup interval — honest for most applications, wrong for the one database that cannot lose an hour.
Why: Druva's AWS Mumbai DRaaS is the documented India-hosted target; Veeam and Commvault fail over to the second Indian site or India cloud region you design, with test reports as drill evidence.
The trade-off: Only one product here hosts the India site for you; the rest make the site your cost and your compliance artefact — which many regulated buyers prefer.
Why: Acronis DR adds runbooks and cloud failover to the agent the MSP already runs; Barracuda LiveBoot boots VMs from the appliance or the cloud at a flat replication price; Druva DRaaS needs no second site.
The trade-off: Barracuda has no dependency-ordered runbooks; Acronis is billed in compute points through the partner — ask what a week of production failover costs.
Why: NetBackup's resiliency orchestration and Commvault's recovery groups produce the rehearsal evidence auditors ask for across the estates those platforms already protect; Veeam Orchestrator does the same for the VMware share.
The trade-off: Orchestration licences sit on top of the backup licence; the drill is a project with an owner, not a feature.
Every product here “does DR”. Place each on its mechanism and its target before comparing anything, then ask about the step back.
Mechanism 1
Continuous replication — seconds
Every write shipped to the target as it happens (Veeam CDP, Cohesity SiteContinuity — both vSphere-centric). The tightest RPO, the most storage and WAN, a warm target you pay for every day — and the fastest way to replicate an attack.
Mechanism 2
Periodic replication — minutes
Snapshots shipped on a schedule to a second site or cloud account (Commvault, NetBackup, Veeam replication). Cross-hypervisor and cross-cloud breadth; RPO in minutes; the target is still yours.
Mechanism 3
From backups — hours
Stand the estate up from the backup copies, in order, somewhere warm (Druva into AWS, Acronis into its cloud, Rubrik recovery plans, Barracuda LiveBoot, Cloud Rewind rebuilding the application). Cheapest on a quiet day; RPO is the backup interval; the day's compute is the bill.
The failback test
Ask these before the failover demo, in this order.
The India layer
Where the second site is, is a compliance artefact.
DR scales by the number of things that must come up in order, and by the network they must come up across. The bill follows the target; the RTO follows the runbook.
The plan is the constraint
Put this in your PoC
Fail over the three servers that matter into the test network and time it. Then fail back. The second number is the finding.
Dependencies and the target's cost are the constraint
Put this in your PoC
Ask for a recovery-plan report from an automated test on an estate your size, and the cost of the target on a quiet month and a failover month.
Sovereignty, evidence and the operating model are the constraint
Put this in your PoC
Run a full application-stack failover and failback in a quarter, with measured RPO and RTO per tier. Those two numbers are the only slide.
Veeam, Commvault, Cohesity, NetBackup, Rubrik and Druva document large estates; Acronis and Barracuda are flagged unverified above 1,000 VMs, not ruled out. Where a specific product strains for your application tiers: [TechBag to confirm].
Replicas and recovery plans are product-specific. Switching means the new product takes its own first copy of everything and you rebuild the runbooks — while the old protection keeps running until the new one has been tested.
The re-seed
The new product's first replication or backup of the whole estate crosses the WAN once more; for continuous replication the target storage is built again. Plan the window and the bandwidth.
The runbooks
Boot orders, re-IP rules, scripts and dependencies live inside the orchestration product; export the logic as a document before you leave and rebuild it — then test it.
The target
A vendor-hosted target (Druva's AWS account pattern, Acronis Cloud) disappears with the contract; your own second site or cloud account stays and is re-pointed.
The overlap
Run both until the new product has passed a full drill. Two DR bills for a quarter is the honest cost of not being unprotected for one.
Re-seed bandwidth, runbook rebuild and overlap cost for your estate: [TechBag to confirm] — TechBag scopes it from your application tiers and WAN.
What you may already hold, the products priced the way they are sold in USD and INR, and what the licence line leaves out — which, for DR, is the second site or the cloud compute on the day.
Four places a DR capability may already sit. None of them is a plan.
If the mechanism you already own is enough for your RPO and a plan is what is missing, we say so. It costs us a sale and saves you one.
Reported and list meters (INR for scale). The licence is the smaller half everywhere here; the three plates price the target — a warm second site, your cloud on the day, or the vendor’s — at three estate sizes, with the licence lines under it. Where a product is quote-only the line says so.
Storage and the DR site — stated apart from the licence, on purpose
TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.
A second data centre or reserved cloud capacity — $420000 ≈ ₹3,48,60,000 a year indicative for a warm 500-VM cloud target before the licence, or a building. The largest line in most DR budgets, and the one most often left out of the business case.
Production-size compute, storage and egress for the duration of the failover, then the transfer back. Nobody models a two-week event; model it.
A quarterly application-stack failover and failback with measured RPO and RTO, an owner, and the evidence for the auditor. Tools automate the report; the rehearsal is still yours. Your hours: [TechBag to confirm].
Documented behaviour and drill outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover mid-failover.
DR plans never tested end to end
Individual VMs failed over in a test network; the whole application stack never did. The first real failover found the dependency nobody drew. Drill the stack, quarterly.
Failback taking longer than failover
Failover was a button; bringing the estate home with a week of new data was a project. Ask to see failback in the demo — flagged here where it is not documented.
Cloud DR costs during an actual event
The target was cheap while it slept; production-size compute for three weeks was not in the budget. Price a fortnight, not an hour.
Dependency ordering wrong on failover
Applications booted before the database, the database before the domain controller. Boot order is the runbook; the runbook is the product.
Network and DNS not part of the plan
Every VM came up at the second site with the old IPs and nobody could reach them. Re-IP, DNS and firewall rules are pages one to three.
Replication trusted as the ransomware plan
The encryption replicated to the DR site in seconds. DR assumes the source is trustworthy; the cyber-recovery guide is for when it is not.
RPO quoted from the datasheet
Seconds on the slide; the WAN could not sustain the change rate and the journal fell hours behind. Measure the change rate before buying continuous replication.
The India site assumed
The regulator asked where the failover would run; the answer was a region in another country. Druva documents Mumbai; the rest is your design, documented as such.
Vendor-neutral. No gated content.