Signal
Commvault SaaS revenue crosses $100M in fiscal Q1 Microsoft deal brings resilience services natively to Azure Fifteen consecutive years in Gartner's leader quadrant Commvault SaaS revenue crosses $100M in fiscal Q1 Microsoft deal brings resilience services natively to Azure Fifteen consecutive years in Gartner's leader quadrant
Company profile / Cyber resilience

Commvault Is Selling the Rehearsal for a Very Bad Day

Backup used to mean making a copy. Commvault is betting the harder, more valuable job is proving an entire business can come back clean - data, identities, applications and cloud infrastructure included.

The strange thing about a backup is that its moment of truth arrives when almost everything else has gone wrong. Servers may be encrypted. An administrator account may be compromised. A cloud application may still have its data but no longer remember how its pieces fit together. The executive team is counting hours, customers are counting outages and someone is discovering that the recovery plan was last tested against a world that no longer exists.

This is the gap Commvault has spent the past few years turning into a business. The New Jersey software company still makes backup and recovery tools, but the vocabulary has widened: data security, identity resilience, cleanrooms, cyber forensics, application rebuilding and continuous readiness. Its flagship Commvault Cloud Unity platform is designed to move from finding important data to protecting it, watching for unusual behavior, validating recovery points and restoring an operating business.

That last phrase matters. Restoring a folder is a technical event. Restoring payroll, customer service, authentication, production databases and the cloud infrastructure around them is an organizational one. Commvault's bet is that enterprises will pay for one control plane that can coordinate both.

“The first step in building cyber resilience in your organization is the ability to recover with trust and speed.”Pranay Ahlawat, chief technology and AI officer

The backup category grew teeth

For much of its history, backup was an insurance policy managed deep inside IT. The job was to make copies on schedule, retain them for the required period and retrieve them after hardware failure or human error. Ransomware changed the adversary. Cloud changed the terrain. AI is expanding the amount of valuable data while introducing new stores, pipelines and access patterns.

An attacker may target the backup system itself, steal credentials or wait until corrupted data has flowed into protected copies. A cloud outage can leave the underlying bytes intact while scattering networking rules, service dependencies and infrastructure configuration. The modern recovery question is not simply whether a copy exists. It is whether that copy is trustworthy, reachable through uncompromised identities and attached to everything the application needs.

The resilience loop

The fire drill that never clocks out. Unity frames resilience as a loop, not a finish line. A recovered system becomes a live system that must be discovered and protected again.

Commvault calls this operating model Resilience Operations, or ResOps. The name is marketing, but the underlying habit is useful: treat recoverability as something teams continuously measure and rehearse, closer to production reliability than emergency paperwork. Cleanroom Recovery creates isolated cloud environments where teams can examine an incident, test a recovery and avoid reconnecting contaminated systems to production. Cloud Rewind maps application dependencies and uses automation to reconstruct cloud infrastructure alongside its data.

$1.184BFiscal 2026 revenue
52%Fiscal 2026 SaaS revenue growth
2,800+Employees worldwide

One console, several generations of computing

Commvault's unglamorous advantage is its memory. The technology began as a development group inside Bell Labs in 1988, and the company became independent in the 1990s. It has lived through tape libraries, client-server computing, virtualization, public cloud and SaaS. Large organizations rarely replace one era neatly with the next. A hospital might run Microsoft 365, decades-old databases, virtual machines, cloud-native applications and medical systems that cannot tolerate a casual migration. A bank adds regulatory retention and identity controls. A university adds thousands of users and research workloads.

Unity is meant to place policy across that mess. It covers on-premises systems, edge sites, SaaS applications, DevOps repositories, Active Directory, Entra ID and data across AWS, Azure and Google Cloud. Metallic AI supplies automation, anomaly detection and what Commvault calls cleanpoint identification - the attempt to locate a recovery point before suspicious activity or corruption began.

The breadth differentiates Commvault from buying separate point tools for every workload, though it also creates the familiar enterprise-platform challenge: capability can bring complexity. Veeam, Rubrik, Cohesity, Druva, Dell, IBM and cloud-native backup services all compete for parts of the same budget. Some buyers will prefer a narrower SaaS product. Commvault is strongest where the environment itself refuses to be narrow.

That usually means institutions with many kinds of critical data and little tolerance for improvisation: banks working under retention rules, hospitals with patient systems, public agencies with continuity mandates, retailers spread across edge locations and universities balancing central IT with independent research. Backup administrators remain core users, but security operations, identity teams, cloud engineers and compliance leaders increasingly enter the same recovery exercise. Commvault says its technology supports more than 100,000 companies through direct and partner relationships.

In practice, they can protect Microsoft 365 mailboxes, Salesforce records, virtual machines, databases, Kubernetes applications, source-code systems and files under one policy structure. They can keep an immutable copy outside a production account, scan for anomalous behavior, restore an Active Directory forest, spin up an isolated recovery room or rebuild a distributed cloud application. Professional and managed services add planning, readiness checks and help during an incident. The expertise being sold is less about moving bytes than coordinating the order in which a complicated organization becomes usable again.

What operators can steal

Define recovery around a business service, not a storage volume. List its data, identities, application dependencies, infrastructure and owners. Then test all five together and time the result. A green backup report is evidence of a copy, not proof of continuity.

Three acquisitions, three missing pieces

Commvault's recent dealmaking reads like a diagram of where backup stopped. Appranix, acquired in 2024, brought discovery and automated rebuilding for distributed cloud applications. Clumio, acquired later that year, brought a SaaS control plane and air-gapped protection for cloud-native AWS data such as S3 and DynamoDB, since expanded toward Google Cloud. Satori Cyber, acquired in 2025, added sensitive-data discovery, access governance and security for data used in AI.

Together they widen the sequence. Before an incident, find sensitive data and govern who can reach it. During one, detect abnormal access and preserve isolated copies. Afterward, rebuild not only the database but the application topology around it. The acquisitions also give Commvault a path into budgets adjacent to classic backup - cloud operations, identity, data governance and AI security.

How the machinery makes money

Commvault sells SaaS subscriptions, term-based software licenses, support and professional services, plus a shrinking amount of perpetual software. It reaches customers directly and through resellers, managed service providers, system integrators and cloud marketplaces. Fiscal 2026 revenue rose 19 percent to $1.184 billion. SaaS revenue rose 52 percent to $333 million, while total annual recurring revenue reached $1.122 billion at year-end.

The next quarter kept the direction intact. For the three months ended June 2026, SaaS revenue crossed $100 million and subscription annual recurring revenue reached $1.054 billion under the company's recast presentation. This is the economic logic of the transition: an ongoing readiness service creates recurring revenue in a way that a one-time backup license cannot.

The customer pitch is partly consolidation. A single platform can replace overlapping backup consoles, recovery scripts and isolated tools, while common policy helps security and infrastructure teams work from the same map. The risk is that platform value only appears when implementation, testing and ownership are disciplined. Software cannot decide which business service must return first. It can make that decision executable.

Partnerships are part of the product

No resilience platform owns the entire environment, so Commvault's alliances do practical work. A multi-year Microsoft agreement announced in June 2026 is designed to make Commvault a native ISV service inside Azure, simplifying discovery, purchase and deployment for Azure customers. A NetApp alliance joins storage-side ransomware signals with automated Commvault recovery. STACKIT addresses sovereign-cloud requirements in Europe, while a CloudSEK integration feeds exposed-credential intelligence into identity protection.

These relationships also reveal where Commvault sits in the market. It is not a primary cloud, a storage array or an identity provider. It is the connective tissue that observes those systems, protects their state and tries to coordinate their return. That neutrality is valuable in hybrid companies, where dependence on any one vendor is usually incomplete.

1988

Technology work begins inside Bell Labs.

2006

Commvault lists on Nasdaq under the ticker CVLT.

2023

Commvault Cloud unifies the portfolio and introduces cleanroom recovery.

2024-2025

Appranix, Clumio and Satori expand cloud rebuilding, cloud-native backup and data governance.

2026

Unity sharpens the platform story as a native Azure deal expands distribution.

The product is confidence, with a stopwatch

Cyber resilience is difficult to evaluate on an ordinary Tuesday. The interface can look tidy, policies can show green and every scheduled job can finish. The useful evidence is a timed recovery under realistic constraints. Can the team find a clean copy? Can it restore identity before applications need authentication? Can it recreate networks and dependencies? Can investigators work without contaminating production? And can the business repeat the process next month?

Commvault now sells tools for that sequence. Its heritage gives it coverage across the old estate; its acquisitions reach toward cloud-native and AI-era data; its subscription growth shows customers are buying more of the service model. The company still competes in backup, but its more interesting market is the space between a completed backup job and a functioning organization.

There is a quietly comic truth here. The best recovery software is purchased in the hope that its most dramatic features never become necessary. Commvault's answer is to use them anyway - in a cleanroom, on a schedule, with a stopwatch running. The bad day remains hypothetical. The recovery does not have to be.

Cyber resilienceEnterprise softwareCloud securityBackupSaaSAI data