Browser-only calculation · no form data sent

3-2-1 backup capacity and retention planner

Size local and off-site copies, estimate retention and transfer time, and check recovery objectives in one plan.

Failure-domain separation

How to read the plan

  1. Check required capacity per backup target and across both backup targets.
  2. Confirm that the retention coverage reaches the oldest recovery point you need.
  3. Compare backup interval with RPO and full restore time with RTO.
  4. Verify actual device, site, and isolation boundaries.
Capacity limitation: This conservative model carries the entered daily change across the retention window. It does not promise deduplication or compression savings. Metadata, verification, and retry time remain outside the estimate.

RPO and RTO

RPO is the maximum acceptable data-loss window. RTO is the time allowed to complete recovery. Test local and off-site recovery paths separately.

Related checks

Use the backup and restore time planner and 3-2-1 backup guide with this estimate.

Formula and units

Capacity per backup target is (source TB + daily change × longest retention window) × headroom. The window is the maximum of daily count, weekly count × 7, and monthly count × 30. Full and incremental transfer times divide data bits by effective Mbps.

Worked examples

2 TB family library

At 20 GB changed per day, 7 daily, 4 weekly and 6 monthly points, plus 20% headroom, plan about 6.72 TB for each backup target over a 180-day window.

100 Mbps off-site path

A 2 TB first copy takes about 55.6 hours at 80% efficiency, so it misses a 12-hour RTO. Keep a separate local recovery path.

Twice-daily backup

A 12-hour interval meets a 24-hour RPO arithmetically, but failed-job alerts and the next successful run still matter.

How to interpret the result

The capacity total belongs on backup targets in separate failure domains, not on another mirror inside the source device. The 3-2-1 status combines your device, off-site and isolation declarations; it does not certify restore success.

Error sources and limits

Changed-block overlap, compression, deduplication, synthetic full jobs, growth, cloud minimum-retention charges, and API limits vary by product. This conservative model assumes no compression or deduplication saving and must be corrected with product forecasts and restore tests.

Frequently asked questions

Does six monthly points mean exactly 180 days?

The planner uses 30 × 6 for sizing. Calendar months and each product's GFS implementation differ.

Does meeting RPO make the design safe?

No. Job-failure detection, immutability or isolation, key custody, and restore tests remain necessary.

Does a failed off-site RTO break 3-2-1?

Copy placement and recovery time are separate checks. A valid 3-2-1 layout can still restore too slowly from off-site.

Last reviewed: 2026-08-21