Recovery Time Objective (RTO)
The recovery time objective is the maximum acceptable duration a business function or supporting ICT system can be unavailable after a disruption before the impact becomes unacceptable. Under DORA it is a core input to the business-continuity and disaster-recovery plans required by Article 6's ICT risk-management framework.
Detailed explanation
RTO answers the question: how quickly must this service be restored? It is set for each critical or important function and the ICT assets that support it, based on the operational and financial impact of downtime, and is usually paired with a recovery point objective (RPO), which addresses how much data loss is tolerable rather than how much downtime is tolerable. DORA does not prescribe fixed RTO figures; instead Article 6 requires entities to define business-continuity and disaster-recovery plans proportionate to their risk profile, and Article 11 requires response and recovery procedures that put those objectives into practice, including backup policies and restoration testing. Setting an RTO too loosely undermines the entity's own risk assessment, while setting it unrealistically tight without the infrastructure to meet it creates a documented gap that supervisors and auditors will flag. RTOs also feed into third-party contracts: where a critical or important function depends on an ICT third-party provider, the entity's RTO should be reflected in the service-level agreement and exit-strategy planning for that arrangement, so a provider outage does not silently exceed what the business can tolerate.
In context
This term relates to the ICT Risk Management pillar and is grounded in DORA Article 6.