How we rank cloud resilience vendors

Short answer

We score each vendor 0 to 100 on seven criteria about rebuilding cloud infrastructure, weight them, and publish the math. Every score comes from public vendor material reviewed in September 2026. We did not test the products or interview vendors.

Ranking current as of September 2026 · By the Cloud Resilience Vendors research desk

What do the seven criteria measure?

Criteria and weights, edition 2026.09
CriterionWeightWhat it measures
COV Infrastructure coverage beyond data20How much of a cloud environment the tool captures and can restore besides data: resource configuration, networking, identity, DNS, Kubernetes and SaaS configuration, and across which clouds.
AUTO Recovery automation16How much of the rebuild runs without people writing runbooks or code during an incident: dependency ordering, one-step restore, failover and failback, test runs.
XREG Cross-region and cross-account rebuild14Documented ability to rebuild into a different region, account or subscription, including a clean, isolated target after ransomware.
DRIFT Drift and change history12Continuous record of what changed, when and by whom, and detection of drift from a known-good state.
IAC Restore as code (IaC generation)10Whether recovery produces reviewable infrastructure as code (Terraform, OpenTofu, Pulumi, CloudFormation) the team can keep.
DATA Data protection depth and cloud DR track record18Protection of the data inside the infrastructure (volumes, databases, object storage), immutability, replication and RPO, and how long the vendor has shipped cloud recovery.
PRICE Pricing transparency10Whether a buyer can model the cost of the recovery capability from public pricing before talking to sales.
Total100Weights sum to 100.

Editorial assessment, 0-100 per criterion. Weighted total = sum of (score × weight) / 100. It measures fit for rebuilding cloud infrastructure and configuration after an incident. It is not a measure of overall product quality: data backup platforms and IaC orchestration tools score lower here because they solve a different part of the problem.

Why these weights?

Coverage beyond data carries the most weight (20%) because it is the reason this category exists: a restore that brings back data into an environment that no longer exists does not bring back the service. Data protection depth and track record (18%) is next because an infrastructure rebuild without the data is also not a recovery, and because regulated buyers are asked to show proven recoverability. Recovery automation (16%) and cross-region and cross-account rebuild (14%) decide how long an incident lasts and whether you can recover into a clean target after ransomware. Drift and change history (12%) and restore as code (10%) decide whether the rebuilt environment matches the one you lost and whether your team can review it. Pricing transparency (10%) matters because recovery tools are bought against a budget, and a price you cannot see is a price you cannot compare.

How is a score decided?

How is the total calculated?

Total = sum of (criterion score × weight) / 100, rounded to one decimal for display and sorted on the unrounded value. Equal totals share a rank.

Worked example: Firefly
CriterionScoreWeightScore × weight
Infrastructure coverage beyond data86201720
Recovery automation84161344
Cross-region and cross-account rebuild82141148
Drift and change history92121104
Restore as code (IaC generation)9410940
Data protection depth and cloud DR track record3018540
Pricing transparency5510550
Sum divided by 10010073.46 (displayed as 73.5)

What evidence counts?

Vendor websites, product documentation, pricing pages, and, for corporate history, reputable reference pages. Each fact on a vendor page links to the page we read. When a vendor's claim is a performance number, such as an RTO, we label it a vendor claim. We do not use review-site ratings, analyst report placements we could not read, or unnamed customer anecdotes.

What are the limitations of this ranking?

How do corrections work?

Vendors and readers can send corrections with a public source to editors@cloudresiliencevendors.com. We verify against the source, update the data file and let the scores recompute. The change and its date appear on the affected page.

How often is the ranking updated?

Every quarter, and when a vendor changes pricing, ships a recovery capability, or is acquired. The next scheduled review is December 2026.