Disaster recovery, backup and ransomware protection for ONTAP data— the three NetApp Console services, with what each costs per GB and what is already inside ONTAP One. This hub covers NetApp’s resilience services only.
Buy through TechBag
Same software. Better outcome — at a lower cost.
The company, at a glance
Quick answer
NetApp’s resilience services, one by one — every linked card is a full intel page, from SnapMirror-based disaster recovery to backup and ransomware resilience for ONTAP.
Orchestrated failover for VMware and Kubernetes.
Fails VMware and Kubernetes workloads over between ONTAP sites, or into AWS and Google Cloud VMware services, on SnapMirror.
3-2-1 backups of ONTAP volumes, VMs and databases.
Snapshots, SnapMirror copies and object-store backups for ONTAP volumes, SQL Server, Oracle, VMware, Hyper-V, KVM and Kubernetes.
Spots attacks in ONTAP and guides a clean restore.
Joins ONTAP’s Autonomous Ransomware Protection with user-behaviour alerts, SIEM feeds, readiness drills and guided clean restores.
Not sold on their own: SnapMirror (asynchronous, synchronous and active sync), SnapCenter, SnapLock and Autonomous Ransomware Protection come in ONTAP One, the licence bundle shipped with every AFF and FAS since May 2023; older systems upgrade to ONTAP One for a fee. The three Console services are priced on top
Storage rather than resilience services: Cloud Volumes ONTAP runs ONTAP in a public cloud on a per-TiB licence, and its Professional package includes Backup and Recovery volume backups; Keystone is NetApp’s storage subscription, offered in India since December 2021
Amazon FSx for NetApp ONTAP, Azure NetApp Files and Google Cloud NetApp Volumes are sold and billed by AWS, Microsoft and Google; they serve as targets and sources for Disaster Recovery and Ransomware Resilience, not as products bought from NetApp
Still a NetApp business, running managed open-source data platforms, and outside resilience, so not reviewed here; Spot and CloudCheckr, by contrast, were sold to Flexera in a deal announced in January 2025
NetApp sells across 3 of the products TechBag carries in backup & cyber resilience. The Backup & Cyber Resilience guide shows how the category splits and which part is yours. →
Much of NetApp’s protection — SnapMirror, SnapCenter, SnapLock and autonomous ransomware protection — is already licensed in ONTAP One. The Console services add the orchestration on top, priced per GB. Check what you own before you buy.
Asynchronous SnapMirror sends new snapshots on a schedule; synchronous mode holds RPO at zero, and active sync fails over automatically between sites.
ARP/AI, from ONTAP 9.16.1, is a pre-trained model with no learning period; SE Labs rated it AAA in June 2024, with 99% recall.
WORM retention in Compliance or Enterprise mode, plus tamperproof snapshots; patch CVE-2026-22050, which let a privileged attacker remove a lock’s expiry.
Standard mode is SaaS; restricted and private modes run in your own cloud or air-gapped, where only Backup and Recovery works — for ONTAP volumes only.
Start with the job — failover, backup or ransomware recovery — then check what your ONTAP licence already covers.
Every claim on this hub traces to one of these public signals.
in the 2025 and 2026 Magic Quadrants; this rates NetApp as a storage vendor, not as backup or DR software
NetApp was not evaluated in Backup and Data Protection Platforms, and TechBag found no DR or cyber recovery placement
a June 2024 test of ONTAP’s AI ransomware detection found 99% recall and no false positives; a lab test, not an analyst ranking
NetApp has worked in India since 2000; its owned 15-acre Bengaluru campus followed in 2017
every new AFF and FAS ships with SnapMirror, SnapCenter, SnapLock and Autonomous Ransomware Protection included
the rename on 6 October 2025 gave all three resilience services their current names on the same day
Disaster Recovery 4.3.7, on 16 September 2026, added Kubernetes and OpenShift Virtualization alongside VMware
but SnapCenter’s CVE-2025-26512 scored 9.9, and CVE-2026-22050 targeted snapshot locking itself; patch both
A NetApp INSIGHT 2025 session on detection, backup and DR for SAN workloads together.
An INSIGHT 2025 session, with demos, on AI-based ransomware protection in ONTAP.
A short October 2024 explainer from NetApp, recorded before BlueXP became Console.
Two company-level views you won’t find on any vendor site — tap any dot for the rationale. The category-level grid lives on the product page.
Each dot is a NetApp solution area: competitive position vs category momentum.
SnapMirror asynchronous, synchronous and active sync, orchestrated by Disaster Recovery for VMware and, since September 2026, Kubernetes.
How many resilience jobs each vendor covers — backup, DR, cyber recovery — vs how much of its pricing it publishes.
Replication DR, backup, in-storage ransomware detection and locked snapshots, all tied to ONTAP storage, with no SaaS backup. Per-GB prices are published.
Positions are TechBag’s illustrative synthesis of public review-platform standings and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Zero-jargon starting points, in reading order. Each links into the deep education on the product page.
Answer three questions; we’ll point you at the right starting product. No email required — this isn’t that kind of quiz.
1. What would hurt most if it failed today?
2. How far back might you need to go?
3. Where must the management console run?
Disaster Recovery fails workloads over, Backup and Recovery keeps dated copies in object storage, and Ransomware Resilience spots and reverses attacks.
Read →SnapMirror, SnapCenter, SnapLock and ARP come with new arrays. The three Console services are what you pay extra for, per GB.
Read →The October 2025 rename changed every service name, so older videos, quotes and documents still say BlueXP for the same products.
Read →Prices count used capacity on the source volume and bill per TiB-hour; the list rate is an estimate, and term discounts lower it.
Read →SnapLock and tamperproof snapshots hold copies for a set period. Patch ONTAP first, since CVE-2026-22050 went after that very lock.
Read →The Backup & Cyber Resilience guides separate backup, DR and cyber recovery and place NetApp’s three services within them.
Read →The procurement playbook TechBag runs with IT buyers — steps, licensing cheat-sheet, and the pitfalls that cost quarters.
Arrays on ONTAP One already have SnapMirror, SnapLock and ARP; ONTAP Base must be upgraded before any of them can be used.
Disaster Recovery and Ransomware Resilience need SaaS standard mode; air-gapped or restricted sites can run only Backup and Recovery, for ONTAP volumes.
All three services meter used capacity on the source volume, before efficiencies; measure it per service, since each bills separately.
Pay as you go suits a trial year; 12- and 36-month terms cut each per-GB rate, and BYOL licences come from NetApp sales.
Fix CVE-2026-22050 before trusting locked snapshots and CVE-2025-26512 on SnapCenter, then run a failover test and a clean-restore drill.
NetApp lists prices only in USD. TechBag sizes capacity across the three services, compares terms and quotes the total in INR with GST.
| Product | Licensing model | How you enter | Best for |
|---|---|---|---|
| Disaster Recovery | Per GB of used source capacity a month, billed per TiB-hour · Marketplace pay as you go, annual or BYOL · SaaS mode only | $0.04/GB/mo · $0.034 on 36 months | VMware and Kubernetes DR |
| Backup and Recovery | Per GB of used source capacity a month · BYOL on 1- to 3-year terms, floating across the Console organisation | $0.05/GB/mo · $0.0425 on 36 months | Backup of ONTAP workloads |
| Ransomware Resilience | Per GB of used source capacity a month · Marketplace or BYOL · SaaS mode only | $0.07/GB/mo · $0.0595 on 36 months | Ransomware detection and recovery |
| ONTAP One | Bundled with new AFF and FAS · includes SnapMirror, SnapCenter, SnapLock and ARP · excludes the Console services | No separate price | Replication and locks on arrays |
| Cloud Volumes ONTAP | Per-TiB capacity licence · Professional package includes Backup and Recovery volume backups | Freemium up to 500 GiB per system | ONTAP in a public cloud |
| Ransomware Recovery Guarantee | A programme, not a product · new FAS, AFF or ASA HA pairs with ONTAP One and validated SnapLock snapshots | Subject to NetApp’s terms | Contractual recovery backing |
NetApp publishes per-GB monthly prices for all three services; ONTAP systems themselves are quoted. TechBag gets the quote itemised in INR with GST.
Disaster Recovery and Ransomware Resilience run only in SaaS mode; a sovereign or air-gapped bank can use Backup and Recovery alone.
It comes in ONTAP One with new arrays. On older systems the only route is an upgrade to ONTAP One, at an extra fee.
NetApp calls its prices estimates: billing runs per TiB-hour on used source capacity, and term and volume breaks change the total.
Backup and Recovery protects ONTAP workloads, not Microsoft 365, and NetApp’s old SaaS backup for it is a legacy product.
CVE-2026-22050 let a privileged attacker clear a locked snapshot’s expiry on 9.16.1 before P9 and 9.17.1 before P2. Patch first.
Each intel page carries an 8-question vendor checklist and a value calculator:
Bring your requirements and current tool bills — a TechBag advisor models the whole decision for you.
Book a discovery call →Four trends with momentum scores (TechBag’s read of analyst and market signals) — and what each means for your next decision.
*TechBag’s illustrative estimate, not a quoted analyst figure. The takeaway: storage that detects ransomware itself is becoming expected — which is why NetApp builds it into ONTAP.
ONTAP’s ARP/AI, a pre-trained model with no learning period, covers NAS from 9.16.1, SAN from 9.17.1 and FlexGroup from 9.18.1.
What it means for you
The array can raise the alarm before the backup does.
NetApp Disaster Recovery made Kubernetes and OpenShift Virtualization generally available on 16 September 2026.
What it means for you
Plan one runbook for VMs and containers together.
Ransomware Resilience added Microsoft Sentinel, Google SecOps and webhook SIEM feeds during 2026, plus automatic user blocking.
What it means for you
Let the security team see storage alerts as they happen.
NetApp announced Elastio scanning of snapshots in March 2026 as planned for the near future; TechBag found no release yet.
What it means for you
Buy on what ships today, not on announcements.
Open any of the three intel pages for the deep dive, or let a TechBag advisor build the case with you — the capacity to protect, the ONTAP licence, quotes, trials, GST invoicing and lifecycle support included.
Stats, positions and figures are illustrative syntheses of public materials; verify before purchase.