The 3-2-1 backup rule and 3-2-1-1-0: what each number means and what counts as a copy
Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software
- The 3-2-1 backup rule asks for three copies of your data on two different types of media, one of them off-site; production counts as the first copy, so the rule means two backups
- 3-2-1-1-0 is Veeam’s extension: one copy offline, air-gapped or immutable, and zero errors after recovery verification; Veeam’s own texts leave open whether that copy is a fourth one or one of the two backups
- Snapshots, RAID, storage mirrors, sync shares and a SaaS provider’s redundancy are not backup copies, and Broadcom says “Do not use VMware snapshots as backups”; Veeam lists replication among 3-2-1 configurations, but we count a replica as a failover copy on top of the two backups
- In the NIST glossary an air gap has no physical connection and no automated logical connection: a tape moved to a vault or a rotated disk on the shelf qualifies, an immutable repository stays online
- The zero is met with evidence beyond job status, such as health checks on backups and backup copies, boot tests in an isolated network and timed restores from the off-site and offline copies
Eurokommerz × Vixen.UNO: Cyber Resilience Talk to an expert →
What the 3-2-1 backup rule says
The 3-2-1 backup rule, also written 321 or called the 3-2-1 backup strategy, asks for three copies of your data on two different types of media, with one copy kept off-site. Production counts as the first copy, so the rule means two backups. Veeam’s Quick Start Guide for Backup & Replication 13 defines the 3 as “the original production data and two backups” and names local disk and cloud as an example of two media types. 3-2-1-1-0 is Veeam’s extension of the same strategy, adding one copy that is offline, air-gapped or immutable and a requirement of zero errors when the backups are verified by recovery.
Computer Weekly reported in March 2021 that the term was coined by a US photographer writing a book about digital asset management in the early 2000s.
What 3-2-1-1-0 adds, and how many copies it means
Veeam’s blog post on the rule (February 2024, updated July 2026) states “At Veeam, we extended the rule to 3-2-1-1-0” and explains the extra copy by noting that “ransomware increasingly targets backups”. Veeam’s best-practice guide for Backup & Replication lists five elements: at least three copies, two different media, one backup copy off-site, “One Copy Offline, Air-gapped, or Immutable”, and zero errors, which it ties to SureBackup recovery verification.
Read together, the two texts leave the number of copies open. The blog’s FAQ describes “One more copy stored in an immutable or air-gapped location”, which suggests a fourth copy; the best-practice guide asks you to make one of the copies offline, air-gapped or immutable. In our reading, three copies meet 3-2-1-1-0 when one of the two backups carries that property, for example an off-site copy in object storage locked in compliance mode.
Three copies: what counts as a copy and what does not
A backup counts as a copy when it survives the loss of the system it was taken from. Veeam’s user guide gives the reason for keeping more than one: “The primary backup may get destroyed together with production data”. A backup on the same array as production, or a repository VM on the cluster it protects, is lost together with production. The mechanisms in the table look like copies but protect against narrower failures.
| MECHANISM | PROTECTS AGAINST | WHY NOT A BACKUP |
|---|---|---|
| VM snapshot | a failed change on a healthy VM | depends on the base disks; Broadcom: “Do not use VMware snapshots as backups” |
| RAID or erasure coding | a failed disk or node | deletion, encryption and corruption reach every member at once |
| Storage mirror | loss of the primary array or site | writes every change to the target, harmful ones included |
| File sync share | a lost or broken laptop | deletions and encrypted versions sync to every endpoint |
| VM replica | loss of the primary site, with fast failover | a VM in native vSphere format on a target host, deletable by whoever administers that host |
| SaaS provider redundancy | faults in the provider’s own hardware | a deletion by one of your administrators is replicated like any other change |
Broadcom KB 318825 (snapshot best practices); Veeam Backup & Replication 13 Quick Start Guide, VM replication (updated 21 August 2026). The other rows are our reasoning from how each mechanism writes data.
Broadcom’s snapshot guidance explains the first row: “If the base disks are deleted, the snapshot files alone are not sufficient to restore a virtual machine.” Veeam’s blog lists replication to another host or site among the configurations that align with 3-2-1, while its Help Center counts two backups. A replica is a VM kept “in the ready-to-start state” on a target host rather than a backup in a repository, so we treat a replica as a failover copy in addition to the two backups. Our comparison of Veeam replication and backup copy jobs sets out what each job protects against.
Two media types and one off-site copy
The 2 exists so that one fault cannot destroy every copy at once; Veeam’s examples are local disk and cloud, or disk and tape. We count two repositories as different media when they share no controller, firmware, filesystem or administrator account: a hardened repository on local disks and an object store pass that test, while two LUNs on one array do not.
The off-site 1 adds, in the words of Veeam’s blog, “a geographic and network separation”. For the entities it covers, Implementing Regulation (EU) 2024/2690 point 4.2.2(c) asks for backup plans that include storing copies “(online or offline)” in a safe location “not in the same network as the system” and “at sufficient distance to escape any damage from a disaster at the main site”. The point leaves open whether copies are online or offline; in 3-2-1-1-0 the offline property belongs to the second 1. Whether the regulation binds your company is a legal assessment for your legal department.
In Veeam, a backup copy job makes the off-site copy, for example to a service provider’s cloud repository as the Cloud Connect guide describes. A scale-out backup repository’s capacity tier does the same with object storage at another site or in the cloud, through two check boxes: “Copy backups to object storage as soon as they are created” and “Move backups to object storage as they age out of the operational restores window”. Only the copy option creates a second instance, because a moved restore point exists once.
Distance does not help when the same account can delete both copies. The UK National Cyber Security Centre’s principles for ransomware-resistant cloud backups (November 2024) suggest, as one of four options, “forbidding destructive requests from customer accounts”, administrative users and backup agents included, with exceptions authorised out of band. To check an off-site copy, list every account that can delete it, the backup server’s service account included, and keep those accounts out of the production directory.
Air-gapped backup, offline or immutable: the second 1
The NIST glossary defines an air gap as an interface between two systems that are not connected physically and whose logical connection, if any, is not automated, so that data crosses it “only manually, under human control”. A backup is therefore air-gapped while no network path reaches it, as with a tape exported from the library or a removable disk unplugged and stored. A tape in a library slot is online, because the backup server, and anyone who controls it, can load and erase it.
Veeam supports both offline forms. Its user guide describes vaults as logical containers for “offline tapes” recorded and moved off-site, and repositories on rotated drives, which “can be detachable USB or eSATA hard drives” moved between locations on a schedule. A rotated disk is offline only while it is on the shelf; the one plugged in for tonight’s job is as reachable as any other repository.
Immutable copies stay online and refuse deletion until a lock expires, on a Veeam hardened repository or on object storage locked in compliance mode. Our article on what immutable backup protects against explains the lock and how long to set it, and our Veeam hardened repository guide covers the build.
An immutable repository on local disk can start a restore at once but stays on a running server; an offline tape cannot be reached by any account, and its restore starts with fetching it from the vault. 3-2-1-1-0 accepts either for its second 1, and the two can be combined.
Zero errors: how to verify every copy
Veeam’s blog calls the last digit, zero recovery errors, a matter of trust: “A backup only matters if you can count on it to restore when it’s needed.” A successful job shows only that data was written. Veeam’s health check, which can run periodically on the latest restore point of backup jobs and backup copy jobs, verifies what was written with a cyclic redundancy check of the metadata and a hash check of the data blocks. A restore confirms that the machine starts and its application answers. For the “regular integrity checks on the backup copies” of point 4.2.3, ENISA’s guidance of June 2025 advises the entities the regulation covers to “use checksums or hashing algorithms to verify that the data in your backups matches the original data”.
- Treat every failed or warning job session as an open error until a later run of the same job succeeds.
- Enable the periodic health check on backup jobs and backup copy jobs, and read its results, not only the job status.
- Boot a sample of machines from the primary backups in an isolated network, with SureBackup or a scripted restore, and check each application.
- Once per test cycle, restore from the off-site copy and from the offline or immutable copy, including a tape fetched from the vault and restored on a second backup server with the password kept outside the first one.
- Record how long each restore took and what failed, and fix it before counting the cycle as zero.
The tape restore catches faults that job reports do not show. The LTO Program’s compatibility table (November 2025) states that “LTO-10 drives can only read and write to LTO-10 media”, while LTO-9 drives handle LTO-8 and LTO-9. A library upgraded to LTO-10 cannot read the LTO-9 tapes in the vault unless an LTO-9 drive stays in service. Veeam decrypts a tape automatically when the backup server and configuration database that encrypted it read it back and the tape is in the catalogue. A restore on a second backup server therefore shows whether the password exists outside the first one, in line with ENISA’s advice to store encryption keys separately from the backup data.
Under our cyber resilience service, regular test restores verify backup integrity. Tell us which copies you restore from today, how often, and what the last test found.
A 3-2-1-1-0 layout for a mid-size VMware estate
With standard Veeam jobs, production on the vSphere cluster is copy one. A backup job writes copy two to a hardened repository, a Linux server with its own disks outside the cluster and outside the production directory. A capacity tier in copy mode writes copy three to object storage at another site, or a backup copy job writes it to a provider’s cloud repository, with immutability enabled where the target supports it. Where the backup server, the hypervisor management and the directory could be lost together, a monthly tape exported to a vault adds an offline fourth copy. How long each copy keeps its restore points is covered in our guide to backup retention and GFS.
| RULE ELEMENT | TYPICAL SETUP | COMMON MISTAKE |
|---|---|---|
| 3 copies | production, a backup job and a backup copy job | counting a snapshot, a replica or a RAID mirror as a backup |
| 2 media types | hardened repository on local disk, copy on object storage or tape | both backups on one array or one NAS |
| 1 off-site | backup copy to a second site, a provider or another region | capacity tier in move mode only: recent restore points stay on site, older ones exist once |
| 1 offline or immutable | hardened repository, object lock in compliance mode, tapes in a vault | tapes left in the library; a lock shorter than the time to detect an intrusion |
| 0 errors | health checks, boot tests, timed restores from each copy | a green job report taken as proof; only the primary copy ever tested |
Veeam Backup & Replication 13 Quick Start Guide, User Guide and Best Practice Guide; Veeam Cloud Connect Guide. The common mistakes are our judgement.
A complete set of copies says nothing about how long a full restore of the estate takes; our article on why backup is not disaster recovery works through that arithmetic.
Our technical assessment reviews security and backup and ends with a risk map and a prioritised action plan. Send us your job list and where each copy is stored through the form below.
What we do
Under our cyber resilience service, our engineering partner Vixen.UNO sets up Veeam-based backup and runs scheduled test restores to verify backup integrity, with a recovery site in Baltneta’s Tier-3 data centres in Lithuania and target RPO and RTO fixed in the SLA. The paid technical assessment shows where the gaps are between backups that run and a business that recovers, and what to close first; its price is fixed before work begins. Changes are made in agreed maintenance windows with a rollback plan, on one EU contract with Eurokommerz. Where copies must also run as systems at a second site, our disaster recovery service adds Veeam replication and failover tests in an isolated environment, with a report after each test.
FAQ
What is the 3-2-1 backup rule?
What does 3-2-1-1-0 mean?
Does production data count as one of the three copies?
What is an air-gapped backup?
Is a snapshot or a replica a backup copy under the 3-2-1 rule?
Does NIS2 require the 3-2-1 backup rule?
Send us your backup job list, the repository and site each copy lands on, and the date and result of your last test restore. We reply within one business day to arrange a first call, from which you leave with two or three possible solution scenarios. The first call is free of charge.
Talk to an expertWe reply within one business day