Ask ten IT directors what their RTO is and most will quote a number from a business impact analysis written three budget cycles ago. Ask how long the last full restore actually took, and the room goes quiet. Industry surveys have repeatedly found that a majority of organizations — around 60% in recent studies — need six hours or more to complete a full restore, while only about 5% finish inside an hour. That gap between the declared number and the tested number is where DR programs fail audits, and it is where this brief starts.
Below: a clean tier-by-tier benchmark table for RTO and RPO targets as of mid-2026, an honest mapping of which technology actually delivers each tier — Zerto, Veeam, and Rubrik each earn a place, and each has limits — and the diagnostics to tell whether your declared targets are real or fiction.
The benchmarks: four recovery tiers, as of mid-2026
Most published tier models are either vendor marketing or academic. Here is the version I use when a client asks what “realistic” means. These are targets that well-run enterprises actually hit in tested recoveries — not aspirational numbers for the audit binder.
| Workloads | RTO target | RPO target | Technology that delivers it | Relative cost | |
|---|---|---|---|---|---|
| Tier 1 — Mission-critical | Payments, order capture, EHR, trading, identity | Under 15 minutes | 1–5 minutes (seconds achievable) | Journaled CDP replication; active-active where justified | ~10x Tier 2 |
| Tier 2 — Business-critical | ERP, core databases, key line-of-business apps | 1–4 hours | 15–60 minutes | Snapshot-based replication plus frequent backup | ~10x Tier 3 |
| Tier 3 — Important | Internal apps, file services, collaboration | 4–24 hours | 4–24 hours | Standard backup with instant-VM recovery | Baseline backup spend |
| Tier 4 — Deferrable | Archives, dev/test, reporting | 24+ hours | 24 hours or more | Standard backup, cold or cloud tier | Lowest |
Two rules make this table useful. First, the tier is defined by the business cost of downtime, not by what the application team wants — everyone believes their app is Tier 1 until they see the invoice. Second, RTO and RPO travel together: a sub-15-minute RTO paired with a 24-hour RPO means you will be back online quickly with yesterday’s data, which for a payments platform is not recovery at all.
The reality gap: declared RTOs are fiction without testing
The survey math deserves a second look. If roughly 60% of organizations need six-plus hours for a full restore and only about 5% finish under an hour, then most of the sub-one-hour RTOs written into DR plans are unfunded promises. The declared number describes the technology the organization wishes it had bought.
The failure modes are consistent. Restore throughput is measured against a single VM, then extrapolated to 400. Dependencies — DNS, identity, load balancers — are not in the runbook, so the application is “restored” but nobody can log in. And the plan has never been exercised end to end, because a full failover test is disruptive and nobody wants to own the outage. The fix is procedural, not technical: a tested tier assignment beats an ambitious untested one every time. I covered how often each tier should be exercised, and what DORA now requires of financial entities, in our brief on DR testing cadence.
The takeaway for the meeting: an RTO that has never been demonstrated in a test is a hypothesis, and the board should hear it described that way.
Matching technology to tier: Zerto, Veeam, Rubrik
Vendors will happily sell you Tier 1 technology for Tier 3 workloads. Mapping honestly saves seven figures at renewal.
Zerto: the Tier 1 specialist
Zerto, now sold as HPE Zerto Software, built its reputation on journal-based continuous data protection: every write is replicated and logged, so you can rewind to a checkpoint seconds before corruption hit. For genuine Tier 1 workloads — where a five-minute RPO is a requirement, not a preference — journaled CDP is the honest answer, and Zerto remains the reference implementation. The 10.9 release (May 2026) added cross-hypervisor replication between VMware and HPE VM Essentials, which matters if Broadcom pricing has you planning a hypervisor exit for part of the estate. The limits are equally clear: per-VM licensing makes it expensive to spread across the whole environment, and it is a replication-first product — most shops still pair it with a separate backup platform for long-term retention. Fit: your top 5–10% of workloads, not your standard.
Veeam: the Tier 2–3 workhorse
Veeam Data Platform v13, shipped in November 2025, is where most of the market lives. Instant VM recovery boots workloads directly from backup storage in minutes — degraded performance until storage migration completes, but running — which is what makes a 1–4 hour Tier 2 RTO achievable from backup infrastructure rather than replication. v13 added instant recovery into Azure with a cleanroom validation step and made backups immutable by default, both of which harden the ransomware case. Veeam’s strengths are breadth of workload coverage and cost per protected VM; its CDP capability exists but is younger and narrower than Zerto’s journaling, and instant-recovery performance depends heavily on the repository hardware underneath it. Fit: the 70–80% of the estate sitting in Tiers 2 and 3.
Rubrik: when the threat model is ransomware, not floods
Rubrik Security Cloud approaches the same problem from the security side: an immutable filesystem, anomaly detection on backup data, and threat hunting inside recovery points so you restore a clean copy instead of reinfecting yourself. Through 2025 it kept widening coverage — Okta recovery, PostgreSQL, Red Hat OpenShift Virtualization, Azure DevOps and GitHub repositories. The trade-offs: RPOs are bounded by snapshot frequency, so it is not a CDP play and will not deliver Tier 1 minute-level RPOs, and its pricing sits at the premium end of the backup market. Fit: security-driven Tier 2 and Tier 3 estates where the recovery scenario you actually rehearse is a cyberattack, and where paying more for forensic confidence is defensible. In a ransomware event, RTO includes the time spent proving the restore point is clean — Rubrik’s bet is that this is where the hours actually go, and the survey data on six-hour restores suggests the bet is reasonable.
Diagnostics: where you actually stand
Run your current plan against these thresholds:
- Declared RTO under 1 hour, recovery method is backup restore: you do not have a Tier 1 plan, you have a Tier 1 label. Either fund CDP replication for those workloads or re-tier them honestly.
- Last tested restore took more than 2x the declared RTO: re-tier or re-platform. The gap will not close by itself, and an auditor will find it before you do.
- Claimed RPO under 15 minutes on nightly backup: arithmetic says no. Your real RPO is up to 24 hours; write that down or change the technology.
- No full-scale restore test in the last 12 months: assume you are in the six-plus-hour majority regardless of what the plan says, and schedule the test before the renewal conversation.
- Recovery copies all live on the same platform or site: your RTO is hostage to a single failure domain — the 3-2-1-1-0 rule exists precisely because restore speed means nothing if the copy you need is encrypted alongside production.
The cost curve: every tier jump costs an order of magnitude
The dirty secret of recovery tiers is the pricing curve. Moving a workload from Tier 3 backup to Tier 2 snapshot replication roughly triples to ten-times the protection cost — replica storage, WAN bandwidth, orchestration licensing. Moving from Tier 2 to Tier 1 CDP does it again: journal storage, per-VM replication licensing, and in many designs a warm second site or reserved cloud capacity that sits idle waiting for a disaster. As of mid-2026, list pricing varies too much to quote responsibly, but the shape holds across vendors: each tier jump is an order of magnitude, which is exactly why “everything is Tier 1” is a budget request, not a strategy.
For organizations that cannot fund a second site, DRaaS has become the middle path — Tier 1-adjacent RTOs at a subscription price, with trade-offs we priced out in our DRaaS pricing brief. The discipline that matters is the ratio: if annual protection cost for a workload exceeds the cost of the outage it prevents, the workload is over-tiered. Most enterprises that run this math for the first time move 20–30% of their “critical” list down a tier and fund proper CDP for the handful that genuinely need it.
Frequently asked questions
What is a realistic RTO for most businesses?
For the bulk of the application estate, 4–24 hours is realistic on standard backup infrastructure with instant-recovery features. Sub-hour RTOs are realistic only for workloads protected by replication or CDP — and only if the failover has been tested end to end, dependencies included.
Can you achieve zero RPO?
Effectively, yes — synchronous replication and journaled CDP can hold data loss to seconds or less. But true zero RPO requires synchronous writes, which imposes distance and latency limits and roughly doubles infrastructure cost. Most Tier 1 programs settle for near-zero RPO via asynchronous CDP and spend the savings on testing.
Is a lower RTO always better?
No. Every hour you shave off an RTO costs progressively more, and past a certain point the spend exceeds the downtime cost it avoids. The right RTO is the one where protection cost and outage cost cross — for many internal workloads that crossover sits comfortably at 12–24 hours.
How often should RTO and RPO targets be tested?
Tier 1 workloads: quarterly failover tests at minimum. Tier 2: twice a year. Everything else: an annual full restore test. Regulated industries increasingly have this dictated for them — DORA in particular has turned testing cadence from best practice into obligation for financial entities operating in the EU.
Enterprise Techie publishes vendor-honest analysis like this daily — get the brief by email, free.









