---
title: "RTO, RPO, and MTPD: Setting Time Targets Without a Fight"
description: Learn how to set RTO, RPO, and MTPD in a practical way that aligns business impact, IT recovery, and BIA workflows.
image: https://bcmmetrics.com/hubfs/RTO%2c%20RPO%2c%20and%20MTPD%20Setting%20Time%20Targets%20Without%20a%20Fight.png
---

[Skip to content](https://bcmmetrics.com/blog/rto-rpo-mtpd-setting-time-targets#main-content)

<https://bcmmetrics.com/>

SOLUTIONS

[PRICING](https://bcmmetrics.com/pricing)

USE CASES

RESOURCES

[ABOUT US](https://bcmmetrics.com/about-bcmmetrics)

Flexible BCM software solutions

[See all solutions →](https://bcmmetrics.com/business-continuity-solutions)

[![Group 1171274363](https://bcmmetrics.com/hubfs/Group%201171274363.svg) **REGULATORY COMPLIANCE** A self-assessment tool to evaluate the level of compliance of your business continuity program](https://bcmmetrics.com/business-continuity-solutions/compliance-confidence)

[![Frame 16367](https://bcmmetrics.com/hubfs/Frame%2016367.svg) **BUSINESS CONTINUITY PLANNING** A single platform where you can build and share business continuity plans (BCPS) across your entire team](https://bcmmetrics.com/business-continuity-solutions/bcm-planner)

[![Frame 16365](https://bcmmetrics.com/hubfs/Frame%2016365.svg) **BUSINESS IMPACT ANALYSIS** An everyday business impact analysis (BIA) software to help you prepare and plan for anything](https://bcmmetrics.com/business-continuity-solutions/bia-on-demand)

[![Group 1171274403](https://bcmmetrics.com/hubfs/Group%201171274403.svg) **FACILITIES MANAGEMENT** An intuitive icon-based mapping tool to better manage your facilities around the globe](https://bcmmetrics.com/business-continuity-solutions/bcm-one)

[**INSURANCE** Identify critical systems and create streamlined response plans](https://bcmmetrics.com/industry/insurance)

[**HEALTHCARE** Simplify compliance and risk assessments in one platform](https://bcmmetrics.com/industry/healthcare)

[**FINANCE** Manage audits and meet standards with ease](https://bcmmetrics.com/industry/finance)

[**![case-studies](https://bcmmetrics.com/hubfs/Website%20Images/Global/case-studies.svg) CASE STUDIES** Learn how others have redefined their BC management with BCMMetrics](https://bcmmetrics.com/business-continuity-case-studies)

[**![case-studies](https://bcmmetrics.com/hubfs/Website%20Images/Global/resource-library.svg) RESOURCE LIBRARY** Access our collection of free downloadable resources](https://bcmmetrics.com/business-continuity-resources)

[**![case-studies](https://bcmmetrics.com/hubfs/Website%20Images/Global/blog.svg) BLOG** Read along for expert BC advice from our senior consultants](https://bcmmetrics.com/blog)

[LOG IN](https://app.bcmmetrics.com/Portal/login.aspx) [VIRTUAL TOUR](https://bcmmetrics.com/virtual-tour-form) [BOOK YOUR DEMO](https://bcmmetrics.com/demo)

![Mask group (7)](https://bcmmetrics.com/hubfs/Mask%20group%20(7).png)

![Mask group (6)](https://bcmmetrics.com/hubfs/Mask%20group%20(6).png)

# RTO, RPO, and MTPD: Setting Time Targets Without a Fight

 Michael Herrera

 Published on: April 29, 2026

### Prepare For the Worst with the Best in the Business

Experience capable, consistent, and easy-to-use business continuity management software.

[BOOK YOUR DEMO](https://bcmmetrics.com/demo)

RTO, RPO, and MTPD are not competing targets. They answer different questions.

RTO is how quickly a service, process, or supporting system needs to recover. RPO is how much data loss the organization can tolerate, expressed as a point in time to which data must be recovered after an outage. MTPD is the outer limit, the point where the impact of not resuming becomes unacceptable.

The trouble starts when teams try to set all three as if they were one number.

**In short**

RTO tells you how quickly something needs to recover, RPO tells you how much data loss is tolerable, and MTPD tells you the outer limit before the impact becomes unacceptable.

- Most conflict happens when business and IT set these targets separately
- A better BIA workflow starts with impact over time, not system restoration alone
- Cleaner structure makes the targets easier to defend, report on, and revisit later

## What RTO, RPO, and MTPD actually mean

It helps to start with the simplest version.

**MTPD** answers: how long can this disruption continue before the impact becomes unacceptable?

**RTO** answers: how fast do we need to recover to avoid crossing that boundary?

**RPO** answers: how much data loss can we tolerate?

Those definitions are straightforward. What is less straightforward is getting the business and IT to arrive at them together.

## Why teams argue about time targets

Most disagreements about time targets are not really about acronyms. They are about perspective.

Business leaders usually think in terms of customer impact, service interruption, missed deadlines, regulatory exposure, and when disruption becomes intolerable. IT teams often think in terms of backup frequency, application architecture, recovery sequencing, restoration times, and technical dependencies. Both views matter. The fight starts when one side sets the number first and the other side is asked to accept it afterward.

A second source of friction is weak impact framing.

If one business unit says a process is “critical” and another uses the same word to mean “important but not urgent,” the time targets that come out of those conversations will not be comparable. The same problem shows up when time bands are vague, impact categories are inconsistent, or the interview process is too loose.

A third source of conflict is dependency blindness.

A business process may carry an aggressive RTO that looks justified. But if its supporting application, supplier, or shared service cannot meet that timeline, the target is not aligned. It is just optimistic.

[![bcmmetrics-new-logo-navy](https://no-cache.hubspot.com/cta/default/46578083/interactive-188681423137.png)](https://bcmmetrics.com/hs/cta/wi/redirect?encryptedPayload=AVxigLKVqokdhbwb4EV0nXR%2BRp8%2BEtPYXONukM6Wsa921KicPsW4Bk2MFxdGA3JGOVewL3XxhtcjWRgxPESPNNeGfM8JXFVmtTbCFDDvYK7pXjNmMVCyHDzAwb9wjf0GXnYoQv4IKR1JXjGOAKu%2BKx3vX%2BPlVgVxVFDoAdJ155OL38rykC0TvzRXfIbrhZCN85SrRg1gwbnb5PTOwKdxi6c9J5RVNaT%2Fv30otAIqwFl5tcotLgTJ%2F6sbV6HuIg%3D%3D&webInteractiveContentId=188681423137&portalId=46578083)

## A better workflow for setting them

The cleanest way to set time targets is to stop treating them as isolated numbers and instead treat them as linked outputs of the BIA workflow.

**Start with impact over time.**  
Before debating systems or backups, determine when disruption becomes unacceptable for the business activity. That is the basis for MTPD.

**Then set the business recovery target.**  
Once the business understands the outer limit, it can decide what restoration target sits safely inside it. That is where the business-side RTO becomes useful.

**Then set the data-loss tolerance.**  
RPO should come from the practical question of how much lost data, missing transactions, or stale information the business can absorb.

**Then reconcile the dependencies.**  
This is where the business-side target meets reality. If the process RTO is four hours but a supporting platform can only be restored in eight, the issue is not just technical. It is a priority conflict that needs to be resolved.

This is also where a structured tool can help without becoming the center of the story. [BCMMetrics BIA On-Demand](https://bcmmetrics.com/business-continuity-solutions/bia-on-demand) supports the kind of alignment work that feeds RTOs and RPOs. It gives teams a more consistent way to capture pre-work, structure impact categories, review assessment data, and document adjusted values when targets need refinement.

If your team needs stronger groundwork before the target-setting discussion starts, these two related articles can help: [BIA Criticality Definitions and Time Bands](https://bcmmetrics.com/blog/bia-criticality-definitions-time-bands) and [BIA Scoring Models, Impact Scales, and Time Bands](https://bcmmetrics.com/blog/bia-scoring-models-impact-scales-time-bands).

## Where time targets usually go wrong

The most common mistake is setting RTO before agreeing on impact.

That usually produces a number that sounds decisive but is weakly supported. A second mistake is treating the system target as the business target. They are related, but they are not always identical. A business process may need a certain recovery level while individual systems and data components have different sequencing and tolerance requirements.

A third mistake is failing to document exceptions. Sometimes the calculated or discussion-based target needs to be adjusted because the organization already knows the acceptable number, or because the raw output is not workable. That is not inherently wrong. It just needs to be visible, explained, and reviewed.

The fourth mistake is never revisiting the targets after the environment changes. New vendors, shared services, staffing changes, new applications, and new peak-period assumptions can all make last year’s targets less trustworthy.

If your team wants the deeper advisory view on this topic, MHA’s related article is [RTO and RPO in Practice: How to Set Recovery Targets You Can Defend](https://mha-it.com/blog/rto-and-rpo).

## What good alignment looks like

Good alignment is not perfect agreement on the first try. It is a process that produces targets people can defend.

What good looks like:

- the business defines when disruption becomes unacceptable
- RTO is set inside that outer limit, not confused with it
- RPO reflects actual data-loss tolerance
- supporting systems and vendors are reconciled to business priorities
- exceptions are documented clearly
- the outputs are easy to review, report on, and revisit later

That is what keeps the discussion from turning into a fight. The team is no longer arguing over labels. It is working through a shared workflow.

[![SEE BCMMETRICS IN ACTION](https://no-cache.hubspot.com/cta/default/46578083/interactive-184669086823.png)](https://bcmmetrics.com/hs/cta/wi/redirect?encryptedPayload=AVxigLLx9SPXlnu%2Ben2W%2B8SoOPG5a5RFk7YkPBGa3M92OveIKQPd8%2FJCKGCeC93pd0hEG840EV5nUgKD910NLb%2BSF2%2BeOZWCI1auGk5LhQERoWi5SiXr46yDaavGM%2BFLqDC9fEVGkNoxVhkYLRXMkfZNtAWEpycCsm3mewdBl8dpOR6VTk8P7W%2FmF8ql1ySvRRbdWa2mqJTKkRI%2Bo6HY6YWLmw%3D%3D&webInteractiveContentId=184669086823&portalId=46578083)

## Conclusion

RTO, RPO, and MTPD do not need to create friction. They become contentious when they are set in separate conversations, with different assumptions and no shared view of impact over time.

A better BIA workflow fixes that. Start with the point where disruption becomes unacceptable. Set recovery targets inside that boundary. Define data-loss tolerance clearly. Then reconcile the dependencies and document the exceptions. That is how the targets become more than acronyms. They become usable.

## Download A Step-By-Step Business Impact Analysis Checklist

If your team is still debating time targets without a clean way to connect business impact, data loss, and recovery priorities, **A Step-By-Step Business Impact Analysis Checklist** can help structure the process. And if you want a more consistent way to capture, adjust, and report RTO and RPO inputs, BCMMetrics can support that workflow without adding a lot of overhead.

[Download A Step-By-Step Business Impact Analysis Checklist](https://bcmmetrics.com/resources/business-impact-analysis-checklist)

[Take a quick virtual tour of BIA On-Demand](https://bcmmetrics.com/virtual-tour-form)

---

![](https://bcmmetrics.com/hubfs/Website%20design/Michael-Herrera-MHA-Consulting.jpg)

#### Michael Herrera

 Michael Herrera is the Chief Executive Officer (CEO) of MHA. In his role, Michael provides global leadership to the entire set of industry practices and horizontal capabilities within MHA. Under his leadership, MHA has become a leading provider of Business Continuity and Disaster Recovery services to organizations on a global level. He is also the founder of BCMMETRICS, a leading cloud based tool designed to assess business continuity compliance and residual risk. Michael is a well-known and sought after speaker on Business Continuity issues at local and national contingency planner chapter meetings and conferences. Prior to founding MHA, he was a Regional VP for Bank of America, where he was responsible for Business Continuity across the southwest region.

## Other resources you might enjoy

![](https://bcmmetrics.com/hs-fs/hubfs/Inherent%20vs.%20Residual%20Risk%20Examples.png?height=245&name=Inherent%20vs.%20Residual%20Risk%20Examples.png)

#### [Inherent vs. Residual Risk: Examples That Get Challenged and How to Fix Them](https://bcmmetrics.com/blog/inherent-vs-residual-risk-examples)

 Michael Herrera

[Read More](https://bcmmetrics.com/blog/inherent-vs-residual-risk-examples)

![business continuity](https://bcmmetrics.com/hs-fs/hubfs/Imported_Blog_Media/get-resilient.jpg?height=245&name=get-resilient.jpg)

#### [When the Going Gets Tough, the Tough Get Resilient](https://bcmmetrics.com/blog/get-resilient)

 Michael Herrera

[Read More](https://bcmmetrics.com/blog/get-resilient)

![recovery plan relevance](https://bcmmetrics.com/hs-fs/hubfs/Imported_Blog_Media/plan-b-as-the-recovery-plan-fades-what-will-take-its-place-1.jpeg?height=245&name=plan-b-as-the-recovery-plan-fades-what-will-take-its-place-1.jpeg)

#### [Plan B: As the Recovery Plan Fades, What Will Take Its Place?](https://bcmmetrics.com/blog/plan-b-recovery-plan)

 Michael Herrera

[Read More](https://bcmmetrics.com/blog/plan-b-recovery-plan)

## Ready to start focusing on higher-level challenges?

### ![Group 1171274345](https://bcmmetrics.com/hubfs/Website%20Images/Footer/bcmmetrics-logo-new-white.svg)

3820 W Happy Valley Road  
Glendale, AZ 85310  
USA

[SOLUTIONS](https://bcmmetrics.com/business-continuity-solutions)

- [Regulatory Compliance](https://bcmmetrics.com/business-continuity-solutions/compliance-confidence)
- [Business Impact Analysis](https://bcmmetrics.com/business-continuity-solutions/bia-on-demand)
- [Business Continuity Planning](https://bcmmetrics.com/business-continuity-solutions/bcm-planner)
- [Facilities Management](https://bcmmetrics.com/business-continuity-solutions/bcm-one)

PRICING

- [Our Pricing Model](https://bcmmetrics.com/pricing)

RESOURCES

- [Case Studies](https://bcmmetrics.com/business-continuity-case-studies)
- [Resource Library](https://bcmmetrics.com/business-continuity-resources)
- [Blog](https://bcmmetrics.com/blog)

COMPANY

- [About us](https://bcmmetrics.com/about-bcmmetrics-old)
- [Contact](https://bcmmetrics.com/demo)
- [MHA Consulting](https://www.mha-it.com/)

© 2026 BCMMetrics. All rights reserved. [Privacy Policy](https://bcmmetrics.com/privacy-policy)

```json
{
  "@context" : "",
  "@type" : "BreadcrumbList",
  "itemListElement" : [ {
    "@type" : "ListItem",
    "item" : "https://bcmmetrics.com",
    "name" : "Home",
    "position" : 1
  }, {
    "@type" : "ListItem",
    "item" : "https://bcmmetrics.com/blog",
    "name" : "Blog",
    "position" : 2
  }, {
    "@type" : "ListItem",
    "name" : "RTO, RPO, and MTPD: Setting Time Targets Without a Fight",
    "position" : 3
  } ]
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Michael Herrera",
    "url" : "https://bcmmetrics.com/blog/author/michael-herrera"
  },
  "dateModified" : "2026-04-29T15:05:36.044Z",
  "datePublished" : "2026-04-29T12:30:00.000Z",
  "headline" : "RTO, RPO, and MTPD: Setting Time Targets Without a Fight",
  "image" : [ "https://bcmmetrics.com/hubfs/RTO%2c%20RPO%2c%20and%20MTPD%20Setting%20Time%20Targets%20Without%20a%20Fight.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://bcmmetrics.com/blog/rto-rpo-mtpd-setting-time-targets",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://bcmmetrics.com/hubfs/Group%201171274345.svg"
    }
  }
}
```