RTO, RPO, and recovery tiers

  • Release version: Australia
  • Updated March 12, 2026
  • 3 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of RTO, RPO, and recovery tiers

    In the context of business continuity, ServiceNow’s Business Continuity Management (BCM) application enables organizations to classify business processes by recovery tiers to prepare for disruptive events. This classification helps determine the acceptable downtime and data loss without significantly impacting operations.

    Show full answer Show less

    Key Features

    • Recovery Time Objective (RTO): Defines the maximum allowable time for recovery of IT systems or business processes after an outage. Business users and IT owners assess RTO by responding to tailored Recovery Time Objective assessments within the BCM workspace.
    • Recovery Point Objective (RPO): Specifies the maximum acceptable data loss measured in time. IT owners estimate RPO through the Recovery Point Objective assessments configured by BCM administrators.
    • Recovery Tiers: BCM administrators group business applications with similar RTOs into recovery tiers such as Mission Critical, Business Critical, Essential, and Non-essential. Each tier has associated recovery timeframes and organizational expectations like support levels and communication protocols.
    • Recovery Timeframe Configuration: Administrators configure recovery timeframes (e.g., Immediately, 1 Hour, 4 Hours, up to 2 weeks) that define the period from disruption to resumption of normal operations. These timeframes are linked to recovery tiers and help automate classification based on BIA results.

    Practical Application for ServiceNow Customers

    ServiceNow customers can leverage BCM to conduct business impact analyses (BIA) and technical impact analyses, capturing RTO and RPO values through configurable assessments. By defining recovery tiers and timeframes, organizations can automate recovery planning, prioritize critical applications, and align recovery efforts with business priorities. This structured approach aids in minimizing downtime and data loss during disruptions and ensures clear expectations for recovery support and communication.

    Administrators can configure and customize recovery tiers and timeframes within the BCM application to reflect organizational needs, facilitating ongoing resilience and recovery readiness.

    Due to unforeseen disruptive events, the business processes in your organization can face a downtime. Therefore, it is important to classify your business processes in the recovery tiers. You can then calculate the amount of time and amount of data loss that your organization can handle without significant effect on the operations.

    Recovery time objective

    Recovery time objective (RTO) is maximum amount of time a computer, network, or application takes to recover after an outage or data loss without causing effect to operations.

    The business users and IT owners can perform business impact analysis and technical impact analysis respectively by responding to the assessment in the BIA component in the BCM UIB Workspace. A sample view of the Assessments tab is shown in the example.

    Assessments in the BIA.

    If you are the business user, you can estimate the RTO for your business services and processes by responding to the Recovery time objective assessment in the Assessments tab. The questions are displayed in the Recovery time objective assessment tab according to the configuration set up by BCM administrators. A sample Recovery time objective assessment with demo data is shown in the example.

    Recovery time objective assessment.

    Recovery point objective

    Recovery point objective (RPO) defines the maximum acceptable data loss that a business process can handle without significant effect on operations.

    If you are the IT owner, you can estimate the RPO for your data applications and systems by responding to the Recovery point objective assessment in the BIA. Based on the configuration set up by the BCM administrator, the questions are displayed in the Recovery time objective assessment tab as shown in the example.

    Recovery point objective assessment.

    Recovery tier

    With BCM administrator role, classify a set of business applications that follow a similar range of recovery time objective (RTO) values in one type of recovery tier. For example, for the Mission Critical recovery tiers, recovery time objectives can be Immediately, one Hour, and four Hours.

    The recovery tiers and their associated recovery time objectives are displayed in the example.

    Recovery tiers and their configured recovery time objectives.

    BCM administrators can configure a recovery tier and set its recovery time objective as shown in the example.

    Recovery tier and its recovery time objective.

    Recovery tiers are also associated with other organizational expectations such as levels of support, escalation, and communication.

    Recovery tiers are used in the areas:
    • BIA scores and impact assessment result
    • Element recovery times
    Although there is no limitation to the number of the recovery tiers, an organization can set 4 to 6 recovery tiers. Recovery tiers are automatically calculated on BIAs and element RTO by selecting the nearest recovery tier maximum time.
    Recovery tiers can be classified as per their importance and criticality:
    • Mission Critical
    • Business Critical
    • Essential
    • Non-essential
    • Critical
    • Non-Critical

    Recovery tier configuration by the administrators

    For more information on how to configure a recovery tier in the Business Continuity Management application, see Configure recovery tiers for BIA.

    Recovery timeframe

    You can set up the recovery timeframe for a recovery tier. It is the timeframe that starts from when a disruptive event happens to the time when your business can resume usual operations. The BCM administrator can configure the recovery timeframe and its start time. You can configure different recovery timeframes as shown in the example:
    • Immediately
    • 1 Hour
    • 4 Hours
    • 8 Hours
    • 24 Hours
    • 72 Hours
    • 1 Week
    • 2 weeks
    The example shows the configured recovery timeframes in the Business Continuity Management application. Recovery timeframes.

    The example shows the configuration of a recovery timeframe in the Business Continuity Management application. New recovery timeframe.

    For more information on how to configure a recovery timeframe in the Business Continuity Management application, see Set up recovery timeframe for a recovery tier.