Call Us (877) 740-5028
Most enterprises want what the public cloud gave them: fast provisioning, elastic capacity, and teams that don’t wait two weeks for a virtual machine. What they don’t want is the bill, the sovereignty headaches, or the discovery that a 15-year-old application won’t survive a refactor. So they end up straddling both worlds.
Flexera’s 2026 State of the Cloud report found 73% of organizations running hybrid-cloud environments. The problem is that few of them planned it that way. In the Kyndryl Readiness Report 2025, 70% of CEOs said their cloud environment developed “by accident” rather than by design.
That accident is what VMware Cloud Foundation is meant to correct. It offers a way to run private infrastructure with a single, consistent operating model instead of a pile of tools that grew organically. Here’s what IT leaders should understand before committing to it.
VCF is Broadcom’s full-stack, software-defined platform for building and operating a private cloud. It is not a hypervisor with a new name, and treating it that way is the fastest route to a disappointing business case.
The core VCF 9 subscription pulls together vCenter and ESX, VCF Operations, NSX, HCX, VCF Automation, vSAN, vSphere Kubernetes Service (VKS), and Private AI Services. That bundle matters less than what it enables. Virtualization lets several virtual machines share physical hardware.
A private cloud goes further: self-service provisioning, standardized service catalogs, APIs and infrastructure as code, tenant isolation, policy-based governance, and visibility into what things cost. VMware Cloud Foundation is designed to wrap those capabilities around the virtualization stack most enterprises already run.
Still, not everything with a VMware logo is in the box. Avi Load Balancer, vDefend Firewall, and Live Recovery are licensed separately as advanced services. If your business case assumes every security, load-balancing, and recovery feature ships with the core subscription, revisit it.
The architecture looks intimidating until you see the hierarchy behind it.
Every deployment starts with a management domain. Think of it as the control room: It hosts the SDDC Manager and the core components that operate that instance, kept separate from production workloads. That separation buys you failure isolation, cleaner upgrade control, and security boundaries that don’t blur under pressure.
Workload domains are where the actual work takes place. Each is a group of infrastructure resources shaped around a class of workload, with its own vCenter Server. You might run separate domains for production, dev and test, regulated applications, Kubernetes, and AI. The point is that VMware Cloud Foundation standardizes the platform without forcing every workload to be operated identically.
VCF 9 also loosened a constraint that used to be a dealbreaker. vSAN is no longer universally required. Management and workload domains can use external block and file storage, including Fibre Channel, iSCSI, and NFS, so organizations can preserve supported storage investments rather than write them off.
On scale, VCF 9.1 handles up to 5,000 ESXi hosts in a single instance and supports parallel upgrades across as many as 256 clusters.
Most enterprise teams already know how to run VMware virtual machines. What they struggle with is operating the entire environment as one thing.
VCF Operations is the layer that tries to fix that. It consolidates monitoring, diagnostics, cost and capacity management, and compliance work into a single operations plane instead of spreading them across separate log, network, storage, and diagnostic tools.
Automated lifecycle management sits alongside it, coordinating patching and upgrades across the stack rather than leaving vCenter, ESX, vSAN, NSX, and the automation tooling to be upgraded as unrelated projects. The payoff is less configuration drift, fewer missed security updates, and shorter maintenance windows.
There’s also an unglamorous set of wins here. Centralized identity, certificate handling, and credential rotation mean administrators stop maintaining separate authentication configurations for every component. Unified observability correlates signals across storage, network, and host, which matters because outages rarely stay inside one silo. An application problem often turns out to be storage latency or an expired certificate.
Cost visibility rounds it out. Showback and chargeback tie consumption back to a department, project, or business unit, so private infrastructure stops looking like one undifferentiated capital expense.
A Broadcom survey of VCF 9 customers reported an average 51% reduction in infrastructure-management time and 47% less capacity required than previously projected. Treat that as directional rather than definitive, as it was a small vendor-run survey.
Modernization does not have to mean converting every application into microservices. That framing has sunk more than a few transformation projects, and VCF supports several gentler paths.
The first is doing nothing dramatic to the applications at all. Reliable VM-based systems stay on vSphere while you modernize what surrounds them: operations, automation, lifecycle, governance. The code doesn’t change; the way you run it does.
The second path is convergence. VKS brings a conformant Kubernetes runtime onto the same platform, so virtual machines and container clusters share APIs, policies, and infrastructure controls instead of living on two disconnected stacks.
The third path is to modernize the operating model first. Bring the existing vSphere estate under VCF management, standardize identity, monitoring, and lifecycle, introduce self-service provisioning, then add Kubernetes and AI services where they’re justified.
Self-service is where governance usually gets nervous. VCF Automation handles it through catalogs, REST APIs, Terraform providers, and reusable blueprints, with YAML-based policy-as-code enforcing quotas, naming standards, and resource limits at the project level. Teams move faster inside guardrails that infrastructure still defines.
And the starting point can be the estate you already own. VCF 9.1 can import supported vSphere 8 Update 3 environments into VCF management without moving application data or taking downtime for the import itself. Validate your version, storage, and networking requirements first, but the door is open.
The value story is less about a single dramatic number and more about compounding effects: a consistent operating model, faster service delivery, better utilization, more predictable economics for stable high-utilization workloads, and the preservation of VMware skills and applications you’ve already paid for.
Vendors have numbers, and they should be read as such. An IDC business value white paper sponsored by VMware reported a 564% three-year ROI, a 10-month payback, and 42% lower three-year operating costs. Those are modeled results that depend heavily on the participating organizations.
The market signal is more interesting: Broadcom’s Private Cloud Outlook 2025 found 53% of surveyed IT decision-makers naming private cloud as a leading three-year priority for new workloads, and 69% repatriating or considering repatriating workloads from public cloud.
VMware Cloud Foundation fits best where there’s a large VMware estate, regulated or sovereignty-sensitive data, stable workloads with real utilization, a need to run VMs and Kubernetes together, or tooling fragmentation that’s slowing everything down. It deserves harder scrutiny when the environment is small and needs only core virtualization, when most applications are SaaS, when the strategy is genuinely public-cloud-native, or when nobody has the capacity to operate the platform once it’s live.
That last one is the real dividing line. Buying the infrastructure doesn’t produce the outcomes. Process maturity, automation discipline, and a platform team do.
VMware Cloud Foundation gives you the software platform. It does not give you the architecture decisions, the migration plan, the Day 2 operations, the data protection design, the compliance evidence, or the engineers who’ve done this before.
That’s the layer we supply. As a Broadcom Pinnacle Partner, OTAVA delivers managed VCF through VCFaaS offering in either dedicated or virtual private cloud models. Veeam-integrated data protection and HIPAA, HITRUST, PCI, SOC 2, and ISO 27001 compliance are built into the foundation rather than bolted on afterward.
Siloed teams and thin internal skills are consistently the biggest barriers to private-cloud adoption. You shouldn’t have to build a full platform team from scratch to get past them. Talk to our team about a migration and modernization roadmap that starts with the estate you already have.