Free procurement tool

    Disaster Recovery & Backup RFP Template Builder

    Answer a few questions about the estate you need protected and get a complete, editable request for proposal - scope, recovery objectives by tier, transition plan, pricing schedule and published evaluation weightings - ready to send to providers as a Word document or PDF.

    Eight sections and a full pricing schedule, in Word or PDF
    Numbered questions that ask for evidence, not description
    No sign-up, no watermark - the document is ungated

    Nothing you type is sent anywhere. The document is generated in your browser, and we only receive your details if you ask us to review it.

    Most DR tenders buy a document, not a capability

    Backup and DR proposals are unusually easy to write well and hard to compare. Providers describe the same architecture in different language, and the differences that matter - who is woken at 02:00, what an invocation costs, whether anyone has ever actually failed over - never surface. These are the four gaps we see most often.

    One RPO and RTO for the whole estate

    Sub-hour recovery for every workload costs several times what it needs to. Tier honestly: the handful of systems the business cannot lose for a morning, and everything else.

    Backup treated as recovery

    A green job report is not a recovery capability. Ask for evidence of real failovers with timings, and make tested recovery a contractual deliverable.

    No stated immutability requirement

    Ransomware targets the backup platform first. If you do not specify an immutable copy outside the production identity domain, you will be quoted without one.

    Transition and exit left unpriced

    Moving protection between providers takes weeks and getting your data back at the end costs money. Both belong in the pricing schedule, not in a later conversation.

    Build your DR and backup RFP

    Everything is pre-filled with the assumptions we use on a typical UK mid-market estate, so you can download something usable immediately and refine it afterwards. The preview updates as you type.

    Your organisation

    Appears on the cover and in section 1.

    The environment

    Section 2 - the numbers providers price on.

    SaaS and identity in scope

    Services to price

    Section 3 - anything unticked is listed as explicitly out of scope.

    Service levels

    Section 4 - set recovery objectives by tier, not for the whole estate.

    Compliance

    Providers must evidence each one in their response.

    Transition, commercial and scoring

    Sections 5, 6 and 8. Weightings are normalised to 100 per cent.

    Technical capability25
    Service delivery model20
    Transition approach15
    Commercial25
    References and evidence15

    Key dates

    Populates the timetable in section 7.

    Anything else

    Added to section 3 as additional requirements.

    Your DR & backup RFP is ready

    8 sections, 20 numbered provider questions, about 1,652 words.

    No sign-up, no watermark, free to use and edit commercially. Everything is generated in your browser.

    Commercial in confidence

    Request for Proposal: Disaster Recovery and Backup Services

    [Organisation name] - DR-RFP-2026-001 - issued 9 September 2026

    1. Background

    [Organisation name] is inviting proposals for the provision of backup, data protection and disaster recovery services. This document sets out our background, the environment to be protected, the scope of services required, the service levels we are buying against, and how responses will be evaluated (reference DR-RFP-2026-001).

    The driver for going to market is: Existing contract expiry. We are looking for a provider who can demonstrate recovery, not describe it.

    ItemDetail
    Organisation[Organisation name]
    SectorPrivate sector
    Procurement referenceDR-RFP-2026-001
    Primary contact[Contact name]
    Contact email[Contact email]
    Initial contract term36 months
    Target service commencement23 November 2026

    All communication regarding this request must be directed through the primary contact above. Providers must not approach other members of staff in connection with this procurement.

    2. Current environment

    The figures below describe the estate as currently understood and will be confirmed during due diligence. Vague inputs produce padded prices and later change requests, so where a figure is an estimate we have said so. Providers must state clearly any assumption their pricing depends on.

    AttributeCurrent state
    Primary platformVMware vSphere (on-premises)
    Intended recovery targetProvider-hosted DR (DRaaS)
    Sites in scope2
    Virtual machines250
    Physical servers12
    Protected data (approximate)80 TB
    Users600
    SaaS and identity workloadsMicrosoft 365, Entra ID / Active Directory

    Questions for providers

    1. Describe the due diligence you would carry out to validate these figures, and what you need from us to do it.
    2. State anything in the environment above you would treat as out of scope, and why.
    3. Confirm how growth in protected data is handled commercially over the contract term.

    3. Scope of services

    The following services are explicitly in scope and must be priced individually as well as in total.

    • Backup as a service - Backup of virtual machines, physical servers and file data, with monitoring and reporting.
    • Offsite / immutable copy - A second copy held away from production, immutable and outside the production identity domain.
    • Replication for DR - Continuous or scheduled replication of tier one workloads to the recovery target.
    • DR as a service (failover capability) - Provider-hosted recovery capacity with a contracted failover capability.
    • Runbook design and maintenance - Documented recovery order, dependencies and named owners, kept current.
    • DR testing and evidence - Scheduled test failovers with written evidence suitable for audit.
    • Microsoft 365 / SaaS backup - Mail, OneDrive, SharePoint and Teams data protected independently of the SaaS platform.
    • Invocation and crisis support - Named crisis contacts, declaration process and support during a live invocation.
    • 24x7 monitoring of protection jobs - Proactive alerting and remediation of failed jobs, not just a monthly report.

    Explicitly out of scope

    • Endpoint and remote user protection
    • Cyber recovery / clean room
    • Exit and data handback
    • Application-level remediation and code fixes following a recovery.
    • Third-party software licensing not stated in the pricing schedule.

    Security and compliance requirements

    The provider must comply with the following for the duration of the contract, and supply current certification evidence with their response.

    • ISO 27001
    • ISO 22301 (business continuity)
    • Cyber Essentials Plus
    • UK GDPR / Data Protection Act 2018

    At least one copy of our data must be immutable for a minimum of 30 days, held outside our production identity domain, and not deletable by any single administrator acting alone.

    Questions for providers

    1. Confirm, line by line, that each in-scope service is included in your standard offering, or state where it is delivered by a third party.
    2. Confirm where our data would be stored, processed and accessed from, including by any subcontractor.
    3. Describe how immutability is enforced, who is technically able to shorten a retention lock, and what evidence of that we would receive.
    4. Describe your process for recovering into a clean environment after a ransomware event, including how backups are scanned before restore.

    4. Service levels

    Recovery objectives are set by tier. Tier one covers the systems the business cannot operate without for a working morning; tier two covers everything else in scope. Hours of cover for the service are 24x7x365.

    TierRPORTOTest frequency
    Tier one (critical)1 hour4 hourstwice a year
    Tier two (standard)24 hours24 hoursAnnually
    RequirementTarget
    Backup success rate99.5% of scheduled jobs per calendar month
    Failed job remediationInvestigated within 4 hours, resolved or escalated within 1 business day
    Retention12 months
    Immutable retention30 days minimum
    Restore request acknowledgement30 minutes (P1), 4 hours (routine)
    DR invocation acknowledgement30 minutes, 24x7, with a named crisis contact
    Test failover evidenceWritten report within 10 business days of each test

    Questions for providers

    1. Confirm you can meet each service level above, or propose an alternative with the reasoning.
    2. State your service credit regime, including what happens after repeated failures, and whether credits are automatic or must be claimed.
    3. Walk through what actually happens when we declare a disaster at 02:00 on a Sunday, naming the roles involved at each step.
    4. Give an example of a recovery objective you missed in the last year and what changed as a result.
    5. Provide evidence of an actual customer failover or major recovery you have performed, with timings against the contracted RTO.

    5. Transition

    Transition from the incumbent arrangement must be complete within 8 weeks of contract start. Transition is complete only when a first full protected copy exists for every in-scope workload, runbooks are published, and one successful test failover has been evidenced.

    MilestoneTargetAcceptance
    Due diligence and protection designWeek 2Signed off by our technical lead
    Infrastructure and connectivity in placeWeek 4Connectivity and capacity proven
    First full protected copy of all workloadsWeek 6Job reports supplied for every workload
    Runbooks and recovery order publishedWeek 6Reviewed and accepted by us
    Test failover of tier one workloadsWeek 8Written evidence against contracted RTO
    Service acceptance and handover to runWeek 8All above accepted in writing

    Questions for providers

    1. Provide a week-by-week transition plan for an environment of our size, stating exactly what you need from us and when.
    2. Describe how you run transition in parallel with the incumbent so we are never unprotected, and who carries the risk during that period.
    3. What happens in the first thirty days if you discover the environment is not as documented?
    4. Name the individuals who would run transition, their qualifications and what else they are assigned to during that period.

    6. Commercial

    Pricing must be submitted on the basis of a fixed monthly service charge for the defined scope, with a published rate card for anything outside it. All prices are to be quoted in GBP, excluding VAT, and must remain valid for 90 days from the response deadline. The initial term is 36 months.

    Pricing lineBasisPrice (GBP, ex VAT)
    One-off transition and onboardingFixed 
    Backup as a serviceMonthly 
    Offsite / immutable copyMonthly 
    Replication for DRMonthly 
    DR as a service (failover capability)Monthly 
    Runbook design and maintenanceMonthly 
    DR testing and evidenceMonthly 
    Microsoft 365 / SaaS backupMonthly 
    Invocation and crisis supportMonthly 
    24x7 monitoring of protection jobsMonthly 
    DR invocation charge (if any)Per invocation / per day 
    Additional test failover beyond contracted frequencyPer test 
    Additional protected capacityPer TB per month 
    Exit and data handbackFixed 
    Total monthly service charge  
    Total contract value over 36 months  

    Questions for providers

    1. State every event that triggers a charge outside the monthly service fee, including invocation, additional tests and data egress.
    2. Confirm your indexation or annual uplift mechanism, with a cap.
    3. State the cost and timescale of exiting the service and receiving our data back in a usable format.
    4. Confirm what is explicitly not included at the quoted price.

    7. Response requirements

    Responses must be submitted by email to [contact email] no later than 7 October 2026. Late responses will not be considered.

    1. Executive summary - maximum two pages.
    2. Answers to every numbered question in this document, in order, quoting the question number. Maximum one page per answer.
    3. Proposed solution design, including where data is held and how it is protected.
    4. Transition plan as required by section 5.
    5. Completed pricing schedule from section 6.
    6. Named team with qualifications and current assignments.
    7. Two references for engagements of comparable size that continue, and two that have ended.
    8. Certification evidence for the frameworks in section 3.
    StageDate
    RFP issued9 September 2026
    Deadline for provider questions19 September 2026
    Answers issued to all providers19 September 2026
    Deadline for responses7 October 2026
    Anticipated award24 October 2026
    Target service commencement23 November 2026

    Marketing material in place of a direct answer will be scored as no response. Where a question does not apply, say so and explain why.

    Terms of this request

    • [Organisation name] will not reimburse any cost incurred in preparing a response.
    • This document is confidential and must not be shared outside the responding organisation.
    • We are not bound to accept the lowest priced or any response.
    • Any conflict of interest must be declared with the response.

    8. Evaluation criteria

    Compliant responses are scored 0 (no response or unacceptable) to 5 (excellent, fully evidenced) against each criterion, then weighted. A score of 4 or 5 requires evidence, not description: named people, real dates, actual test results.

    CriterionWeightingWhat we are assessing
    Technical capability25%Genuine depth in our platforms, immutability and cyber recovery design, evidenced by comparable work
    Service delivery model20%How support actually works: job monitoring, escalation, out-of-hours, invocation handling
    Transition approach15%A specific plan for our environment, not a generic methodology
    Commercial25%Total cost over the term, transparency of what triggers charges, exit cost
    References and evidenced recoveries15%Comparable customers, and proof of real recoveries and tests

    [Organisation name] reserves the right to invite shortlisted providers to a clarification session or a technical deep dive before award, and to require a proof of recovery. Scores from that session will be applied to the technical and service delivery criteria above.

    Want a second pair of eyes on it?

    Send yourself a copy and we'll review the finished RFP free of charge - whether your recovery objectives are affordable, where providers will price in risk, and which questions actually separate evidence from marketing. The document above is yours either way.

    What the generated RFP contains

    The structure follows the same eight-section model as our managed IT services RFP guide: state the driver, describe the estate in numbers, define what is in and out of scope, publish the service levels you are actually buying against, plan the transition, price the commercials in full, set the response format, and publish the weightings.

    1. Background
    2. Current environment
    3. Scope of services
    4. Service levels
    5. Transition
    6. Commercial
    7. Response requirements
    8. Evaluation criteria

    Getting the recovery objectives right

    RPO and RTO are the two numbers that drive price more than anything else in the document. If you are not confident in the tiering, our disaster recovery services team runs DR reviews and test failovers, and our business continuity and DR planning work sets the tiers with the business rather than with IT alone.

    Before you send it

    • Check the protected data figure against a real report from your current backup platform.
    • Agree the tier one list with the business, in writing, before responses arrive.
    • Make immutability and a tested failover mandatory, not scored options.
    • Ask every provider for the total cost over the full term, including invocation and exit.
    • Send it to three to five providers, with questions closing a week before the deadline.

    DR and backup RFP questions, answered

    What should a disaster recovery and backup RFP include?

    Eight sections: background and driver, the current environment in numbers, what is explicitly in and out of scope, service levels including RPO and RTO by tier, the transition plan, the commercial model and what triggers extra charges, response requirements, and published evaluation weightings. Anything less and you are comparing four documents that answer four different questions.

    How do I set RPO and RTO properly?

    Set them per tier, not for the whole estate. Tier one is the handful of systems the business genuinely cannot run without for a morning; everything else can usually accept twenty-four hours. Tiering honestly is the single biggest lever on price, because sub-hour recovery for every workload costs several times more than it needs to.

    Should immutability and cyber recovery be mandatory requirements?

    Yes. Ransomware now targets backup infrastructure first, so an immutable copy outside the production identity domain is a baseline requirement rather than an option. Ask how the immutability is enforced, who can shorten the retention lock, and what evidence of that is available.

    How often should DR be tested?

    Twice a year for tier one workloads, with at least one full documented failover, and annually for everything else. Make the test evidence a contractual deliverable — a plan that has never been executed is a document, not a capability.

    How long should the process take?

    Three to four weeks for responses, a week of clarification, then two to three weeks for evaluation and award. Allow a proper transition period afterwards: moving protection between providers typically takes six to twelve weeks before the first clean full backup and a tested failover exist.

    How many providers should we invite?

    Three to five. Fewer gives you no benchmark, more turns evaluation into a project of its own, and strong providers put less effort into a field of ten.

    Is the generated document free to use?

    Yes. Download it as Word or PDF, edit it and use it commercially with no attribution, no watermark and no sign-up. We only email you a copy if you ask for one.

    We'll review your DR RFP before you issue it

    Thirty minutes, no charge, no obligation. We'll tell you whether your recovery objectives are affordable, where providers will price in risk, and which questions are doing no work. We do this whether or not you ever ask us to bid.

    Book a free 30-minute call

    Tell us a little about your environment and a disaster recovery specialist will get back to you within one working day to arrange your call.