drj logo

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Name*
Zip Code*
Please enter a number from 0 to 100.
Strength indicator
I agree to the Terms of Service and Privacy Policy*
Yes, of course I want to receive emails from DRJ!

Already have an account? Log in

drj logo

Welcome to DRJ

Already registered user? Please login here

Login Form

Register
Forgot password? Click here to reset

Create new account
(it's completely free). Subscribe

x
Skip to content
Disaster Recovery Journal
  • EN ESPAÑOL
  • SIGN IN
  • SUBSCRIBE
  • THE JOURNAL
    • Why Subscribe to DRJ
    • Digital Edition
    • Article Submission
    • DRJ Annual Resource Directories
    • Article Archives
    • Career Spotlight
  • EVENTS
    • DRJ Spring 2026
    • DRJ Fall 2026 Call for Presentations
    • DRJ Scholarship
    • Other Industry Events
    • Schedule & Archive
    • Send Your Feedback
  • WEBINARS
    • Upcoming Webinars
    • On Demand
  • MENTOR PROGRAM
  • RESOURCES
    • New to Business Continuity?
    • White Papers
    • DR Rules and Regs
    • Planning Groups
    • DRJ Glossary of Business Continuity Terms
    • Careers
  • ABOUT
    • Advertise with DRJ
    • Board and Committees
      • Executive Council Members
      • Editorial Advisory Board
      • Career Development Committee
      • DEI
      • Glossary Committee
      • Rules and Regulations Committee

RTO and RPO: Making It Simple

by Jon Seals | March 11, 2021 | | 0 comments

This post first appeared on the MHA Consulting blog.

By RICHARD LONG

Everyone involved in business continuity management knows that the concepts of RTO and RPO are important. Knowing exactly what they are, how they should be used, why they matter, and how to establish them may be a bit less understood. In today’s blog, we’ll lay out the facts about these key concepts in as simple a manner as possible.

Related on MHA Consulting: All About RTOs: What They Are and Why You Have To Get Them Right

Two Critical Concepts

Recovery time objective (RTO) and recovery point objective (RPO) are two concepts that everyone involved in BCM has heard of and knows (we will define them shortly). The details around what they mean or why they are important—much less how to go about establishing them throughout their organization can be confusing.

Let’s try to clear up some of the confusion.

RTO and RPO are indeed very important in developing a solid BCM program. Determining them is a prerequisite for developing sound business and technical recovery strategies.

Each key business process or technical process at the organization should have an identified RTO that must be determined through impact analysis. Associated applications or systems supporting the business process will have an RPO identified.

RTOs and RPOs pertain specifically to the requirements around recovery or resiliency needs in the event of serious events and outages. They do not come into play in the ordinary day-to-day operation of our organization.

Both concepts are measured in terms of elapsed time (hours, minutes, or sometimes days). RTO is related to time after an outage, while RPO is related to time prior to the outage. 

Knowing the RTOs and RPOs for the processes and technologies used across your organization helps you understand how you need to protect both processing and technology needs. Knowing them helps ensure that your strategies, implementation, and plans are neither overly aggressive (wasting resources) or inadequate (providing insufficient protection).

Let’s look at these key concepts one at a time.

Recovery Time Objective (RTO)

The recovery time objective (RTO) is the amount of time in which, following an outage, a business process and its associated applications must be restored in order to prevent a defined amount of impact.

It represents a determination of when it is essential to get a process functional again in order to prevent significant damage to the organization. It is arrived at through a combination of analysis of the company’s overall operations and prioritization by staff.

Recovery Point Objective (RPO)

The recovery point objective is somewhat trickier to understand; it is a description of a capability. That capability establishes the requirements for data protection.

The capability that RPO refers to has to do with the organization’s ability to recreate lost data. Specifically, the RPO refers to how much data could be manually recovered following the restoration of an application. This determines the appropriate data protection strategy for the underlying data in an application.

Manually recovering the data means recreating it by various methods such as reproducing it from memory, locating it in other applications or in hard copy, or contacting customers and asking them to resubmit their orders.

RPO is determined by identifying how much data, for a given application, the staff could manually recreate (not as a routine matter, but rather following a serious outage). Could the staff recreate up to two hours’ worth of data? Up to eight hours’ worth? Up to twenty-four hours’ worth? This is the question to be answered to determine the RPO for a given process or application.

RTOs vs. RPOs

Let’s look at some general facts about RTOs and RPOs.

  • The two values are independent of one another. There’s no correlation.
  • The RTO is about when the business process and its associated applications must be recovered to limit the damage to the organization.
  • The RPO is about how much data could be manually recovered, if this became necessary.
  • It is possible for a business process and its associated applications to have a short RTO and a long RPO.
  • A business process and its associated applications can also have a long RTO and a short RPO.
  • RTOs vary widely, depending on the criticality of the process to the organization.
  • With both RTO and RPO, you have to plan for the worst-case scenarios.

Devising Your Categories

Every organization must devise a scale of RTO and RPO categories for itself. It is best to limit these to around five or six categories for each objective. Having more can be a maintenance nightmare.

The following is a scale of RTOs that we have seen work well for many organizations:

  
RTO 0Immediate/high availability
RTO 1< 8 hours
RTO 2< 24 hours
RTO 3< 72 hours
RTO 4< 5 days
RTO 5> 5 days

And here is a scale of RPOs that many organizations have used successfully:

  
RTO 0Zero data loss
RTO 1< 4 hours of data loss
RTO 2< 12 hours
RTO 3< 24 hours
RTO 4> 24 hours

Once a company devises its categories, each of the company’s key business processes are analyzed and placed into an RTO category and an RPO category. These designations guide the subsequent development of the company’s recovery plans and strategies.

Determining RTOs and RPOs

Beyond the general guidelines given above, how does a company go about determining the best and most correct RTOs and RPOs for its processes and applications?

The BCM office develops proposed RTOs and RPOs based on the organization’s known risks and needs. The IT team can be a good place to start by leveraging the times they use for their current protection and recovery strategies. Using those values, the BCM office can then make adjustments based on discussions with management to understand the general times departments would need to be recovered.

Making the best choices depends on factoring in information and insights commonly held across many different levels within the organization.

The final decisions regarding RTOs and RPOs should emerge after a process of data gathering and collaborative discussion. Once defined, those proposals should be submitted to upper management for review.

Throughout this process, the BCM office has the job of educating others, facilitating the discussion, seeking consensus, and obtaining the necessary approvals.

Keeping Up to Date

Every organization should review its RTOs and RPOs on a regular basis. This is because organizations and the environment change. A company that has outgrown its recovery plan has no recovery plan. It is critical that RTOs and RPOs be kept up to date.

The need for companies to regularly review and update their RTOs an RPOs has never been greater than it is now. After a year of the pandemic and working from home, very few companies today are in the same posture they were even a year ago.

The pace of change will continue to be swift as organizations chart their post-pandemic futures in the coming months.

Summing Up

Recovery time objective (RTO) and recovery point objective (RPO) are two of the fundamental concepts in business continuity.

The RTO addresses how soon after an outage a business process and its associated applications must be recovered to limit the damage to the organization. The RPO is about how much data could be manually recovered, if this became necessary.

The RTO and RPO for each key business process and its associated applications must be determined through analysis of the company’s operations and priorities. They form the basis of the organization’s recovery plans and strategies.  

With the BCM office facilitating, the RTO and RPO for each key business process and its associated applications should be determined collaboratively. They should be reviewed and updated regularly to ensure that the company’s recovery plans and strategies can truly protect it in the case of an outage.  

Further Reading

For more information on RTOs and RPOs and other hot topics in BC and IT/disaster recovery, check out these recent posts from MHA Consulting and BCMMETRICS:

  • BCM by the Numbers: The Metrics That Matter Most
  • How to Weight Your BIA Impact Categories
  • The Darkest Hour: The COVID News Is Grim But a Vaccine Hints at Dawn
  • All About RTOs: What They Are and Why You Have To Get Them Right
  • 8 Oversights That Can Bring Your Operations to a Standstill

Related Content

  1. Disaster Recovery Journal
    Recovery Time Objective: Promise or Aspiration?
  2. Disaster Recovery Journal
    Exercising IT Disaster Recovery Plans
  3. Disaster Recovery Journal
    Make the Right Choice Between Hybrid and All-in-One DRaaS Providers

Recent Posts

Keeper Security Achieves GovRAMP High Authorization, Enabling SLED Organizations to Secure Their Most Sensitive Systems and Data

February 11, 2026

Pathlock Brings Real-Time SAP Threat Detection to Microsoft Sentinel Solution for SAP

February 11, 2026

Half of Organizations Still Rely Primarily on Public AI Tools for AI Implementation, According to SOUTHWORKS Research

February 11, 2026

FIRST Releases 2026 Vulnerability Report, Projecting Record-Breaking Common Vulnerabilities and Exposures

February 11, 2026

Azul 2026 State of Java Survey & Report

February 10, 2026

Backslash Security Raises $19M Series A to Secure Vibe Coding Boom in the Enterprise, Bolsters Board with Cybersecurity Industry Leader

February 10, 2026

Archives

  • February 2026 (39)
  • January 2026 (61)
  • December 2025 (45)
  • November 2025 (58)
  • October 2025 (78)
  • September 2025 (65)
  • August 2025 (59)
  • July 2025 (70)
  • June 2025 (54)
  • May 2025 (59)
  • April 2025 (91)
  • March 2025 (57)
  • February 2025 (47)
  • January 2025 (73)
  • December 2024 (82)
  • November 2024 (41)
  • October 2024 (87)
  • September 2024 (61)
  • August 2024 (65)
  • July 2024 (48)
  • June 2024 (55)
  • May 2024 (70)
  • April 2024 (79)
  • March 2024 (65)
  • February 2024 (73)
  • January 2024 (66)
  • December 2023 (49)
  • November 2023 (80)
  • October 2023 (67)
  • September 2023 (53)
  • August 2023 (72)
  • July 2023 (45)
  • June 2023 (61)
  • May 2023 (50)
  • April 2023 (60)
  • March 2023 (69)
  • February 2023 (54)
  • January 2023 (71)
  • December 2022 (54)
  • November 2022 (59)
  • October 2022 (66)
  • September 2022 (72)
  • August 2022 (65)
  • July 2022 (66)
  • June 2022 (53)
  • May 2022 (55)
  • April 2022 (60)
  • March 2022 (65)
  • February 2022 (50)
  • January 2022 (46)
  • December 2021 (39)
  • November 2021 (38)
  • October 2021 (39)
  • September 2021 (50)
  • August 2021 (77)
  • July 2021 (63)
  • June 2021 (42)
  • May 2021 (43)
  • April 2021 (50)
  • March 2021 (60)
  • February 2021 (16)
  • January 2021 (554)
  • December 2020 (30)
  • November 2020 (35)
  • October 2020 (48)
  • September 2020 (57)
  • August 2020 (52)
  • July 2020 (40)
  • June 2020 (72)
  • May 2020 (46)
  • April 2020 (59)
  • March 2020 (46)
  • February 2020 (28)
  • January 2020 (36)
  • December 2019 (22)
  • November 2019 (11)
  • October 2019 (36)
  • September 2019 (44)
  • August 2019 (77)
  • July 2019 (117)
  • June 2019 (106)
  • May 2019 (49)
  • April 2019 (47)
  • March 2019 (24)
  • February 2019 (37)
  • January 2019 (12)
  • ARTICLES & NEWS

    • Business Continuity
    • Disaster Recovery
    • Crisis Management & Communications
    • Risk Management
    • Article Archives
    • Industry News

    THE JOURNAL

    • Digital Edition
    • Advertising & Media Kit
    • Submit an Article
    • Career Spotlight

    RESOURCES

    • White Papers
    • Rules & Regulations
    • FAQs
    • Glossary of Terms
    • Industry Groups
    • Business & Resource Directory
    • Business Resilience Decoded
    • Careers

    EVENTS

    • Fall 2025
    • Spring 2026

    WEBINARS

    • Watch Now
    • Upcoming

    CONTACT

    • Article Submission
    • Media Kit
    • Contact Us

    ABOUT DRJ

    Disaster Recovery Journal (DRJ) is the leading resource for business continuity, disaster recovery, crisis management, and risk professionals worldwide. With a global network of more than 138,000 practitioners, DRJ delivers essential insights through two annual conferences, a quarterly digital magazine, weekly webinars, and a rich library of online resources at www.drj.com. Our mission is to empower resilience professionals with the knowledge, tools, and connections they need to protect their organizations in a fast-changing world. Join our community by attending our events, subscribing to our publications, and following us on social media.

    LEARN MORE

    LINKEDIN AND TWITTER

    Disaster Recovery Journal is the leading publication/event covering business continuity/disaster recovery.

    Follow us for daily updates

    LinkedIn

    @drjournal

    Newsletter

    The Journal, right in your inbox.

    Be informed and stay connected by getting the latest in news, events, webinars and whitepapers on Business Continuity and Disaster Recovery.

    Subscribe Now
    Copyright 2026 Disaster Recovery Journal
    • Terms of Use
    • Privacy Policy

    Register to win a Free Pass to DRJ Spring 2026 | The Future Runs on Resilience

    Leave your details below for a chance to win a free pass to DRJ Spring 2026 | The Future Runs on Resilience. The winner will be announced on February 13. Join us for DRJ's 74th Conference!
    Enter Now