Part of Infrastructure hosting standards for the NHS
Disaster recovery and business continuity
Standards you should meet on disaster recovery and business continuity for locally hosted infrastructure and systems.
1. NHS organisations should ensure disaster recovery arrangements are defined, documented, maintained and proportionate to clinical and operational risk
Importance of meeting the standard
Disaster recovery arrangements enable NHS organisations to restore critical services following significant incidents. Clear, accessible recovery documentation supports faster, safer recovery during incidents. Inadequate or poorly defined recovery arrangements increase the risk of prolonged disruption, delayed care and patient safety impact.
When to meet the standard
- deploying new systems or services with defined availability or resilience requirements
- making significant changes to hosting platforms or architectures
- responding to incidents or issues that result in loss of service or data
- reviewing organisational risk appetite or business continuity arrangements.
How to meet the standard
- disaster recovery documentation is clear, current and accessible
- recovery objectives reflect clinical and operational priorities and include dependencies and escalation points
- roles and responsibilities for recovery activities are clearly documented
- disaster recovery arrangements are reviewed regularly and aligned with wider business continuity plans
- recovery strategies should be documented for in‑scope systems
- dependencies and escalation points between systems and processors should be identified and considered during recovery planning
- contact details and escalation routes should be kept up to date
- documentation should be stored in a location accessible during outages
2. NHS organisations should ensure recovery time and recovery point objectives are understood, tested, support recovery decision‑making and validate recovery capability
Importance of meeting the standard
Understanding how long it will take to restore systems and how much data loss may occur is critical during incidents. Testing provides assurance that recovery arrangements are technically viable and that staff understand their roles during major incidents.
Delays in understanding recovery options can be as damaging as delays in technical recovery and clear awareness of likely restoration times enables timely decisions on escalation, workarounds and clinical risk management during incidents.
When to meet the standard
- defining or updating disaster recovery plans
- onboarding new hosted systems or services
- following incidents or recovery exercises
- reviewing service criticality or dependency assessments
- undertaking organisational resilience assurance activity
How to meet the standard
- recovery time objectives (RTOs) and recovery point objectives (RPOs) are understood and defined for critical systems
- testing is performed on a regular basis with tests reflect realistic failure scenarios and the outcomes documented
- the impact of recovery times on clinical and operational decision‑making is considered
- recovery objectives are realistic and achievable based on system design
- the time required to assess recovery options and make informed decisions during incidents is understood and factored into recovery planning (sometimes referred to as a decision time objective)
- recovery objectives should be informed by system architecture, data volumes and dependencies
- recovery times should be aligned with available backup, replication and hosting capabilities
- testing scope should be proportionate to system criticality and may include technical recovery, process walkthroughs or scenario‑based exercises
- changes to systems or infrastructure should trigger review of recovery objectives
- evidence of testing should be retained for assurance purposes
Last edited: 18 June 2026 1:40 pm