Customer Asked for Your RTO, RPO and Disaster-Recovery Evidence. What Should a Small SaaS Vendor Share?
Published August 2026 by Solarc Labs
The buyer is trying to understand how much outage and data loss their business could absorb
Recovery questions are not asking whether your architecture sounds resilient. They are asking what happens to the customer if the service becomes unavailable or data is damaged. NCSC cloud guidance says buyers should have enough confidence that a provider’s availability commitments and ability to recover from outages meet their business needs. It also recommends looking at evidence behind provider claims rather than relying on an unsupported promise. That makes a useful procurement answer concrete: what the recovery objective is, what data protection exists, what has actually been tested, when it was tested, what the result showed and which limitations still remain.
State RTO and RPO only when they are real targets owned by your service
RTO describes the recovery-time objective for restoring an affected service. RPO describes the recovery-point objective: the amount of data loss the recovery design is intended to limit. Those labels are useful only when they map to the service the customer is buying and to an actual recovery process. Do not invent an RTO or RPO because a questionnaire has mandatory numeric fields. If the business has not approved a target, say that the value is not formally established and route the gap to the responsible owner. A made-up four-hour target can become a commercial promise that your operating evidence does not support.
A target is not the same thing as a tested result
A written objective says what the organisation intends to achieve. A restore or disaster-recovery exercise provides evidence about what happened under a particular test scope. Keep those states separate. Record the target, the date and scope of the most relevant exercise, the observed recovery result, material exclusions and any remediation still open. If a test recovered one database but did not exercise the full customer-facing service, do not present it as a full-service recovery result. If the last exercise is old, state its date rather than silently describing it as current evidence.
Backups matter only if the recovery path is understood and tested
NCSC guidance for SaaS users says critical data should be held in resilient backup so it can be recovered after data loss, and its cloud resilience guidance says buyers should be confident that backups can return data to a known good state. A questionnaire answer therefore needs more than “we take backups.” Describe only what you can support: which important data is covered, backup frequency or trigger, isolation or resilience characteristics that are actually implemented, retention where relevant, and the most recent evidence that a restore was attempted successfully. Do not imply that a backup policy proves restorability if nobody has tested the recovery path.
Build one evidence record that can survive the buyer’s follow-up questions
Keep the approved customer-facing answer beside the sources that support it: business-continuity or disaster-recovery plan, architecture or backup record, service-level terms where applicable, test date and scope, observed result, remediation items, accountable owner and next review trigger. Classify sensitive operational detail before sharing it externally. This lets the next questionnaire reuse a reviewed answer without turning an old response into permanent truth. When the infrastructure, recovery process or commercial commitment changes, the answer can be routed back to the owner for review instead of being copied forward blindly.
VendorOS can organize the response; it cannot manufacture resilience evidence
VendorOS Security Questionnaire Rescue can help map a buyer’s recovery question to approved wording, source evidence, owners, review dates and explicit gaps. It does not create a business continuity plan, choose RTO or RPO targets, configure backups, execute a restore, perform a disaster-recovery test, guarantee availability or certify that a recovery design is sufficient for a customer. If the buyer needs evidence that does not exist, record the gap and decide whether to test or improve the underlying control. Better questionnaire prose is not a substitute for recovery capability.
Primary sources
Sources used for this article
Continue the job