A service is not placed ahead of a named prerequisite, even when its impact is higher.
Restore what the business needs—in a workable order
Free recovery priority planner.
Compare business impact, acceptable downtime, RTO, RPO and dependencies to build an explainable technology recovery order. Use it to begin the conversation with business owners before an outage.
Build a recovery orderEditable starting points
Start with business tolerance, then map the technology.
Choose the closest example or edit the worksheet directly. Use service names consistently so dependencies can be placed before the services that need them.
How the sequence is formed
A dependency-aware order with visible reasons.
The planner does not call every urgent-looking system “priority one”. It places recorded foundations first, then uses a transparent planning index to order services that are otherwise available.
Impact receives four parts, downtime urgency three and RTO urgency two. It is a sequencing aid, not a risk or readiness score.
The target recovery time should fit inside the maximum disruption the business can tolerate.
Three different decisions
Do not use RTO, RPO and maximum downtime interchangeably.
Agree these terms with the people responsible for the business process. Technical teams can test whether the targets are achievable, but they should not invent the business tolerance. Minimum viable operating mode matters too: it tells the recovery team what “usable” means.
Maximum tolerable downtime
The longest interruption the business says it can accept before consequences become unacceptable.
Recovery time objective (RTO)
The target time for restoring a usable service. It should leave margin inside the business limit.
Recovery point objective (RPO)
The maximum age of recovered data—the amount of recent data the business can tolerate losing.
Official planning guidance
Start with business functions and their dependencies.
NIST describes business impact analysis as identifying critical processes, outage impacts, allowable downtime, required resources and recovery priorities. Current NCSC recovery guidance also stresses trusted identity, shared infrastructure and restart sequencing.
Recovery planning questions
Make the order useful before you need it.
Is the first item always the most important business system?
Not always. Identity, networking, power, facilities or a supplier connection may need to return before the most visible service can be recovered. The planner therefore honours recorded dependencies before comparing impact and time pressure.
Who should agree maximum tolerable downtime?
The accountable business owner should agree it using customer, operational, financial, safety, contractual and legal consequences. Technology teams should then test whether the proposed RTO and recovery design can fit inside that limit.
Why is the planning index not shown as a score?
Its only purpose is to order services that are ready to recover. A high number would not prove resilience, compliance or technical readiness, so the result instead shows the business inputs and dependency reasons directly.
Can this replace a business impact analysis?
No. It is a compact worksheet for an early conversation. A full analysis should validate business processes, impacts over time, people, facilities, suppliers, data, legal obligations, recovery resources and tested strategies.
Need to prove the sequence?
Turn business priorities into tested recovery plans.
ACA can help map services and dependencies, validate targets, document recovery procedures and run practical exercises with the people who own each business process.