Acronis Cyber Protect Cloud
Acronis Cyber Protect Cloud offers hybrid backup solutions with local and cloud options, advanced encryption, multi-tenancy, and multi-tier architecture. It supports various platforms, virtual machines, and provides granular recovery. Integration capabilities, compliance features, anti-ransomware protection, centralised management, scalability, multiple storage options, and 24/7 support make it comprehensive
Features
- Advanced Backup, Sql, Oracle DB, SAP Hana, Data Protection
- Advanced Security, URL Filtering, Exploit Prevention
- Advanced Management, Patch Management, Software Deployment, Inventory
- Advanced Email Security, Anti Phishing, Anti Spam, Anti Malware, APT
- Advanced Disaster Recovery, Production and Test Failover, Runbooks
- Advanced File Sync and Share, Notarisation, e-signature, collaboration
- Antivirus and Malware Protection
Benefits
- Backup and Restore Data
- Protect your data and devices
- Securely access your data and systems
- Simple fixed price plans (storage costs apply on some products)
- Business continuity
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 9 8 4 1 1 9 2 6 2 2 3 5 4 0
Contact
TRANSPUTEC LIMITED
G-Cloud Team
Telephone: 0203 5886570
Email: G-cloud@transputec.com
About your service
- Service categories
-
Systems Infrastructure Software
Storage
Data replication and protection
- Data Protection Software
- Backup and Recovery Reporting Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- The suite of services that are provided by the vendor – Acronis, these can be modified or withdrawn at the vendors timelines, we will endeavour to communicate any such service impacting changes as soon as possible. Any such pricing changes will be communicated in line with vendor guidelines. Transputec will act as master payer for each of the vendor services and will invoice the client directly based upon the agreed payment schedules. By paying for said vendor services, the client will be accepting the vendors terms and conditions for use of such services.
- System requirements
- N/A
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- Our team of certified cloud experts is ready to assist with any issues or queries you may have, no matter the time of day - 24x7 Support
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes, at an extra cost
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- EN 301 549
- Web chat accessibility testing
- Basic accessibility testing has been carried out on the web chat functionality using common assistive technologies, including screen readers (such as NVDA and VoiceOver), keyboard-only navigation, and browser accessibility tools. This testing focused on ensuring that core chat features, including message input, submission, notifications, and conversation flow, are usable without reliance on a mouse or visual cues.
- Onsite support
- Yes, at extra cost
- Support levels
-
1. Fully Managed Service
2. Co‑Managed Service
3. Bespoke (Standard → Advanced) Support Levels
4. Technical Account Manager (TAM)
5. Strategic Advisor 6. Third‑Party Support Availability. Support level and cost are tailored to the scope of the agreement. - Support available to third parties
- No
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- As an Acronis partner and managed services provider, Transputec Limited helps users start using Acronis Cyber Protect through a guided onboarding and managed deployment approach, reducing complexity and speeding up adoption.Transputec assists with - Initial setup of Acronis Cyber Protect, Agent deployment across endpoints and servers, Configuration of backup, retention, security, and ransomware protection policies This ensures the service is correctly configured from day one and aligned with best practices. Onboarding and training - Users receive guided onboarding, including administrator orientation and basic training on how to monitor backups, respond to alerts, and perform restores. This helps internal teams become operational quickly.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- When a customer’s contract with Transputec Limited ends, data extraction is handled in a structured, customer‑controlled manner to ensure continuity and security. All backup data and protected workloads remain the property of the customer throughout the contract. During the offboarding period, Transputec ensures that customers retain full access to their Acronis Cyber Protect tenant for data retrieval. Data extraction methods - Restore to original or alternate locations, allowing data to be recovered back into customer‑owned environments. Download of file‑level or image‑based backups where supported by the platform. Migration to new backup targets or platforms, if customers are transitioning to another provider or internal solution. Export of configuration and reporting data, such as protection plans and audit information, where applicable. Transputec provides offboarding documentation and hands‑on assistance to guide customers through: Restoring or exporting required data Verifying data integrity post‑extraction Removing agents and revoking access credentials
- End-of-contract process
- At contract end, Transputec Limited follows a formal offboarding process designed to protect customer data and ensure a smooth exit. Customers are notified in line with contractual notice periods and retain temporary access to Acronis Cyber Protect to extract their data. During this period, Transputec supports data restoration or migration, verifies successful data export if required, and documents the offboarding steps. Once the agreed offboarding window closes, access to the service is revoked, agents are decommissioned, and any remaining customer data is securely deleted in accordance with data retention and security policies. The standard contract price typically includes: Access to Acronis Cyber Protect based on the agreed edition and licences Initial onboarding support and setup assistance Standard operational documentation Access to Transputec support as defined in the service level agreement Use of included Acronis features covered by the contracted subscription (for example backup, security, monitoring) Additional charges may apply for: Extended data retention or offboarding periods beyond the contracted timeframe Large‑scale data export, migration assistance, or bespoke offboarding projects Additional cloud storage, disaster recovery, or advanced security features not included in the base subscription Professional services, custom configurations, or enhanced support tiers.
- Documentation accessibility standard
- EN 301 549
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile version of Acronis Cyber Protect Cloud offers data‑only backup and recovery for iOS and Android devices, whereas the desktop/server version provides full cyber protection, including system‑level backup, cybersecurity features, vulnerability assessments, patch management, and advanced disaster recovery.
- Service interface
- Yes
- User support accessibility
- EN 301 549
- Description of service interface
- The service interface for Acronis Cyber Protect is a browser‑based web console that allows users to manage all core functions—including backup, recovery, security features, monitoring, and administrative settings—from a centralized dashboard. Users access the interface through a modern web browser, and it provides tools for creating protection plans, managing devices, viewing reports, and performing recovery operations. Acronis Cyber Protect Cloud additionally includes the Cloud Console, which serves as the central management interface for cloud deployments, offering workload management, security configuration, and organizational controls
- Accessibility standards
- EN 301 549
- Accessibility testing
- Acronis Cyber Protect has been tested using assistive technologies including JAWS 2022 (screen reader), Dragon NaturallySpeaking 15 (speech recognition), and ZoomText 2022 (screen magnifier). Testing combined manual evaluation, user‑scenario interaction, and automated accessibility checks through the Level Access AMP platform to validate conformance with WCAG 2.x, Section 508, and EN 301 549 accessibility requirements.
- API
- Yes
- What users can and can't do using the API
- Setup - Users first create an API client and authenticate using JWT tokens. With the Account Management API, they can provision tenants and customer accounts, create users and roles, assign licensed services, and retrieve usage data. Workloads can be onboarded by generating agent installation tokens and registering devices programmatically, enabling automated customer or device setup. Changes - Using the Resource & Policy Management API, users can create, modify, and assign protection plans, manage policies, and enable or disable protection features based on subscription level. Additional APIs allow users to start and monitor protection tasks, retrieve alerts and events, and integrate Acronis data with PSA, RMM, or SIEM systems. Limitations - Not all management-console features are exposed via API, and some system-level or newly introduced settings must be configured manually. API actions are limited by tenant scope, user roles, licensing, rate limits, token expiration, and asynchronous processing, so the API complements but does not fully replace the management console.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- What can be customised - Protection plans and policies, including backup schedules, retention periods, storage locations, malware protection, vulnerability assessments, and recovery options.Enabled features, such as advanced backup, EDR/XDR, disaster recovery, and ransomware protection, based on the licensed edition.Automation and integrations, including workload onboarding, alerting, monitoring, and integration with PSA, RMM, or SIEM platforms using APIs.Branding and white‑labeling (for MSPs), such as logos, colors, service names, custom URLs, agent branding, and support contact details. How users can customise - Performed through the Acronis Management Console for policy, feature, and branding configuration. Also performed through the Acronis Cyber Platform REST APIs for automation and integration-based customisation. Who can customise - Partner and tenant administrators can fully configure policies, features, and branding. Customer administrators can customise protection settings within their assigned scope. Standard users have limited or no customisation rights, based on role permissions.
Scaling
- Independence of resources
- Acronis Cyber Protect uses a multi‑tenant, logically isolated architecture. Each customer operates within its own tenant, with separate identities, policies, workloads, storage quotas, and security scopes. This prevents workloads, data, and administrative actions from overlapping between customers.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Transputec Limited provides customers with comprehensive service metrics through Acronis Cyber Protect and supplementary Transputec reporting, giving clear visibility into service usage, performance, and security posture. Customers can access: Protected workload counts, including servers, workstations, virtual machines, and cloud workloads, aligned to active licences Backup activity metrics, such as job success and failure rates, task history, and recovery point trends Storage consumption, covering cloud and local storage usage by tenant and workload. Metrics are available through the Acronis Management Console, via exportable reports and dashboards, and through managed service reports provided by Transputec.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Acronis
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Acronis also enforces strict role‑based access controls, continuous monitoring, hardware hardening and secure key‑management processes to ensure customer data remains protected at rest.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users export their data at contract end by using standard Acronis Cyber Protect recovery and restore functions, with support from Transputec. During the agreed offboarding period, customers can restore backups to their own environments, recover file‑level or full system images, or migrate data to alternative storage or backup platforms. Transputec provides documented guidance and hands‑on assistance to help identify required data, perform restores, and verify integrity. Once data export is completed and confirmed, access is withdrawn and any remaining data is securely deleted.
- Data export formats
- Other
- Other data export formats
- Proprietary Acronis backup archive formats.
- Data import formats
- Other
- Other data import formats
- Not supported
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- Strong cryptographic controls In addition to TLS: Mutual authentication and certificate‑based trust are used Data integrity checks are applied Encryption aligns with modern security and compliance standards
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- Additional internal protections include: Network segmentation and tenant isolation Encryption at rest for stored customer data Strict access controls and audit logging Continuous monitoring and intrusion detection Role‑based administrative separation
Availability and resilience
- Guaranteed availability
- Acronis Cyber Protect, delivered by Transputec Limited, is designed to provide high service availability through resilient architecture, redundant systems, and continuous monitoring. Availability Commitment The service is operated to meet a defined availability target, as specified in the customer contract or Statement of Work. Availability excludes agreed scheduled maintenance windows and events outside reasonable control (e.g. force majeure). Service Level Agreements (SLAs) Availability SLAs are contractually agreed and typically measured on a monthly basis. SLAs also cover incident response and service restoration targets. Service performance is continuously monitored to ensure adherence to agreed levels. Service Credits and Refunds If the service does not meet the agreed availability SLA: Customers may claim service credits, calculated in accordance with the contract Credits are normally applied against future invoices rather than issued as cash refunds Claims must be submitted within the timeframe defined in the SLA and are validated against service monitoring data Supporting Controls High availability is supported by: Redundant infrastructure and failover mechanisms Proactive monitoring and alerting Documented incident and escalation management procedures Built‑in backup and recovery capabilities Full SLA details, including availability percentages and credit calculations, are provided in the customer’s contractual documentation
- Approach to resilience
- This information is available on request.
- Outage reporting
- Acronis Cyber Protect, delivered by Transputec Limited, provides clear and structured communication to customers in the event of service outages. Outage Reporting and Notification Public dashboard: Service availability and incident updates are published via the Acronis Service Status Dashboard, which provides real‑time and historical information on platform health, incidents, and maintenance activities. API: Outage and health status information can be accessed programmatically via Acronis management and monitoring APIs, enabling customers and partners to integrate status information into their own monitoring or service management tools. Email alerts: Customers receive email notifications for: Confirmed service incidents Planned maintenance windows Significant service disruptions and resolution updates Email alerts are sent to registered administrative contacts and support distribution lists, ensuring timely awareness and ongoing communication throughout an incident lifecycle.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Management interfaces are secured using strong authentication, including unique user accounts, role‑based access control (RBAC), and support for multi‑factor authentication (MFA). Access is granted on a least‑privilege basis, limited to authorised personnel only. Administrative activity is logged and monitored for audit and security purposes. Support channels are restricted to authenticated and authorised customers through managed service desk systems. Identity verification is performed before any account‑specific assistance is provided. Privileged support access is controlled, time‑limited where appropriate, and fully logged. These controls are regularly reviewed to ensure continued effectiveness and compliance with recognised security best practice.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Transputec Limited follows a formal, documented information security governance framework aligned with recognised industry best practice, including ISO/IEC 27001. Information Security Policies and Processes The organisation maintains a comprehensive set of information security policies, including (but not limited to): Information Security Policy Risk Management and Risk Assessment Access Control and Identity Management Asset Management and Data Classification Incident and Breach Management Change Management and Secure Configuration Supplier and Third‑Party Security Business Continuity and Disaster Recovery These policies are supported by defined operational procedures and are reviewed regularly to ensure continued effectiveness and compliance. Reporting Structure Overall accountability for information security sits with senior management Day‑to‑day governance is managed by a designated Information Security function Security risks, incidents, and compliance status are reported through formal management and escalation channels Ensuring Policy Compliance Compliance is ensured through: Mandatory staff security awareness and training Role‑based access controls and least‑privilege principles Ongoing monitoring, auditing, and risk assessments Documented incident reporting and remediation processes Regular internal reviews and independent external audits Together, these measures ensure policies are consistently applied, enforced, and continually improved across the organisation.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Transputec Limited operates formal configuration and change management processes aligned with recognised standards such as ISO/IEC 27001 and ITIL. All service components (infrastructure, systems, and applications) are tracked throughout their lifecycle using asset and configuration management records, including ownership, versioning, dependencies, and decommissioning status. Changes are managed through a structured change control process requiring documented requests, impact and risk assessments, and appropriate approvals. Each change is reviewed for potential security impact, including effects on confidentiality, integrity, and availability. Security‑relevant changes require additional review and testing before implementation, with logging and post‑change verification to ensure controls remain effective.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Potential threats are identified through regular vulnerability scanning, risk assessments, and review of system configurations. Vulnerabilities are assessed based on severity, exploitability, and potential impact on confidentiality, integrity, and availability, with remediation prioritised accordingly. Security patches are deployed in line with defined timescales based on risk. Critical and high‑severity vulnerabilities are addressed as a priority, with testing performed where required to minimise service impact. Compensating controls are applied if immediate patching is not possible. Information on emerging threats is obtained from a combination of vendor security advisories, industry threat intelligence feeds, CERT/NCSC guidance, vulnerability databases (e.g. CVEs), and security partners.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Security events are identified through centralised logging, continuous monitoring, and automated alerting across systems, networks, and applications. Logs and alerts are reviewed to detect suspicious activity, policy violations, abnormal behaviour, or indicators of compromise. When a potential compromise is identified, it is triaged, investigated, and contained in line with documented incident response procedures. Appropriate remediation actions are taken, and incidents are escalated to senior management and affected customers where required. Monitoring is continuous, and critical security alerts are responded to immediately, with defined response and escalation timelines based on incident severity to minimise risk and impact.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Transputec Limited operates documented incident management processes aligned with recognised security standards. Pre‑defined response procedures exist for common security and service events (e.g. malware, unauthorised access, service disruption), with clear roles, escalation paths, and response actions. Users report incidents through established support channels, including service desk tickets, email, or dedicated customer support contacts. Incidents may also be raised proactively through internal monitoring and alerts. For notifiable incidents, customers are provided with timely updates and post‑incident reports. Reports typically include the nature of the incident, impact, actions taken, resolution status, and any remediation or preventive measures implemented.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Acronis Cyber Protect offers a time‑limited free trial (typically 30 days) including core features like backup, recovery, cybersecurity, management, and reporting. Not included are paid licensing, long‑term production use, and guaranteed SLAs. The trial is fully functional but expires automatically.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 2%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7.5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 12.5%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- LRQA
- ISO/IEC 27001 accreditation date
- Tuesday 28 October 2025
- What the ISO/IEC 27001 doesn’t cover
- All 27001:2022 are in scope
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- LRQA
- ISO 9001 accreditation date
- Tuesday 28 October 2025
- What the ISO 9001 doesn’t cover
- All business areas are in scope
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 9e3e144e-b733-4e15-9443-1f700628effc
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 8cf1ff77-ade7-4f78-810d-44f8e9e7f72a
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-