- Meaning
- Disaster Recovery Plan (IT recovery plan)
- Focus
- Technical recovery of IT systems
- Metrics
- Recovery time (RTO) and recovery point (RPO)
- Related
- BCP, BCMS
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is a DRP?
The Disaster Recovery Plan is the purely technical contingency plan of the IT function. It describes in detail how IT systems, applications and data are restored as fast as possible and in the right order after a serious incident – ransomware, a fire in the data centre or a severe hardware failure, for example. Unlike the BCP, which looks at the whole business operation, the DRP concentrates on the technical level: which systems are brought back first, from which backup, on which replacement infrastructure and in which steps? That makes it the operational basis of every reliable Recovery.
RTO and RPO
Two metrics are central: the RTO (recovery time objective – how quickly does a system have to be running again?) and the RPO (recovery point objective – how much data loss is tolerable at most?). They are derived from the business impact analysis and determine how often backups are made and how elaborate standby systems have to be.
For example: an online retailer sets an RTO of four hours and an RPO of 15 minutes for its web shop. The DRP therefore describes a mirrored standby data centre and database backups every quarter of an hour. When the main database crashes after an outage, the team switches to the standby system according to the rehearsed plan – the shop is back online after a good two hours, well inside the target values.
DRP, BCP and BCMS
The DRP is the technical building block of contingency planning. While the BCP secures the whole business operation and the BCMS steers everything at a higher level, the DRP looks specifically after the IT. Only together do they produce end-to-end Business continuity.
The DRP and NIS2
NIS2 explicitly requires backup management and recovery as part of the risk management measures under Article 21. A tested DRP – with working backups that are checked regularly and ideally kept offline – is indispensable for that, and a central piece of evidence towards the supervisory authority.
Further reading: ISO 22301 – business continuity management as a framework for recovery
Frequently asked questions
What is a disaster recovery plan?
A disaster recovery plan (DRP) is the purely technical contingency plan of the IT function. It describes in detail how IT systems, applications and data are restored as fast as possible and in the right order after a serious incident – ransomware, a fire in the data centre or a hardware failure, for example: which systems first, from which backup and on which replacement infrastructure. That makes the DRP the operational basis of every reliable recovery.
What do RTO and RPO mean?
RTO and RPO are the two central metrics of a DRP. The RTO (recovery time objective) states how quickly a system has to be running again after an outage, in other words the maximum tolerable recovery time. The RPO (recovery point objective) sets how much data loss is tolerable at most. Both values are derived from the business impact analysis and determine how often backups are made.
What is the difference between a DRP and a BCP?
The DRP (disaster recovery plan) focuses on the technical recovery of IT systems, data and infrastructure. The BCP (business continuity plan), by contrast, secures the whole business operation including staff and processes. The DRP is therefore the IT sub-plan inside the wider business continuity planning. Under NIS2 a tested DRP is a central piece of evidence for backup management and recovery towards the competent authority.