DRaaS checklist: what to check before you sign a disaster recovery as a service contract
Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software
- Recovery targets belong in the SLA per tier of systems, with the RTO counted from your failover request to running systems; ENISA’s guide to monitoring security service levels in cloud contracts measures restoration speed the same way, from the time of request
- Capacity is reserved only if the contract says so: in Veeam Cloud Connect one hardware plan can serve several tenants, each able to use all of its resources, and NIST SP 800-34 Rev. 1 warns that a site shared by several organisations may be unable to accommodate all of them if a disaster hits enough of them at once
- Veeam’s test of a cloud failover plan boots each replica from its latest restore point and checks that it answers ping, so application checks and a written report have to be agreed in the contract, along with the number of tests per year
- In Veeam Cloud Connect, when the production site and the tenant’s backup server are lost together, the provider starts the failover plan the tenant created in advance, so the contract has to name who may request it, through which channel and how fast the provider acts
- Implementing Regulation (EU) 2024/2690 point 5.1.4(h) names retrieval and disposal of information among the obligations at termination, and a Veeam Cloud Connect tenant whose lease has expired can no longer restore or copy VM data from the cloud host, so the exit clause has to keep access open until the data is back
Eurokommerz × Vixen.UNO: Cloud Disaster Recovery Talk to an expert →
What to check before you sign a DRaaS contract
Before you sign a DRaaS (disaster recovery as a service) contract, check that it fixes the recovery targets per tier of systems and how they are measured, the capacity held for you, the number and scope of failover tests, the procedure for declaring a disaster, where your data sits and who can reach it, and how the data comes back to you and is deleted when the contract ends. Each answer belongs in the contract or its service level agreement (SLA), in terms you can check during a test.
DRaaS is a recovery site run by a provider: your virtual machines replicate to its data centre and can be started there while your own site is down, a site between warm and hot that you rent instead of building it (see our comparison of hot, warm and cold DR sites). Backup keeps copies of data that still need hardware and a rebuild; DRaaS keeps the systems ready to start.
The questions draw on NIST SP 800-34 Rev. 1, Implementing Regulation (EU) 2024/2690, ENISA’s 2012 guide to monitoring security service levels in cloud contracts and Veeam’s Cloud Connect documentation. The regulation binds only the entities listed in its Article 1, and which rules bind your company is a legal assessment for your legal department.
| AREA | WHAT TO ASK | A GOOD ANSWER |
|---|---|---|
| RPO and RTO per tier | How are they defined, measured and reported? | Targets per tier in the SLA, the RTO counted from your failover request, the achieved RPO reported |
| Recovery capacity | Are CPU, RAM and storage reserved for you? | The reserved amount, how many customers share it, your priority when several fail over at once, how long you may run there |
| Failover tests | How many per year, and what do they prove? | A number per year, test capacity included, an isolated network, application checks, a written report with times |
| Declaring a disaster | Who may start a failover, and how fast does the provider act? | Named people on both sides, a channel that works without your email, the response time in the SLA |
| Network at failover | How do users and partners reach the replicas? | A written design for IP addresses, VPN, DNS and firewall changes, an owner per step, tried in a test |
| Failback | How do systems return, and who runs it? | A written procedure with the data path back, the downtime window and an owner per step |
| Data location | Where are replicas, plans and logs kept? | Country and data centres named in the contract, no move without your consent |
| Encryption | How is data protected in transit and at rest? | TLS in transit, encryption at rest for the replica storage, the key holder named |
| Operator and certificates | Who runs the data centre? | The operator named, an ISO/IEC 27001 certificate whose scope includes the site, audit rights or audit reports |
| Provider access | Who at the provider can reach your replicas? | Named roles, access approved and logged, your backup server managed only with your consent |
| Subcontractors, incidents | Who else is involved, and when are you told of incidents? | Subcontractors named in the contract, a data processing agreement, incidents notified without undue delay |
| Maintenance, versions | Can you fail over during provider maintenance? | Maintenance announced in advance, failover requests handled during it, software versions kept compatible |
| Support | How fast does support respond? | Hours and response times in the SLA, a named escalation contact |
| Exit | What happens to your data when you leave? | A notice period covering replication to a new site, access until your data is back, deletion confirmed in writing |
NIST SP 800-34 Rev. 1 (2010), section 3.4.3; Implementing Regulation (EU) 2024/2690, Annex points 4.2.6 and 5.1.4; ENISA, Procure Secure (April 2012); Veeam Cloud Connect Guide, build 13.1.1.18, read on 6 October 2026. The good answers are our reading of these sources.
How a DRaaS SLA should define RPO and RTO
A provider’s RTO covers only part of your outage, because detection and the decision to declare a disaster usually stay on your side; our guide to setting RPO and RTO for each system lists what else a full RTO includes. The SLA therefore has to say where the provider’s clock starts and stops. A clear wording starts it at your failover request through the agreed channel and stops it when the systems of that tier run at the recovery site and answer on the agreed network. ENISA’s guide measures restoration from backup the same way, as “the time taken to obtain data from back-up from the time of request”.
With an hourly replication schedule, the newest usable restore point at the moment of a failure can be older than an hour, because a point counts only once its run has completed, and a failed or overrunning run leaves the previous point as the newest. Ask how replication lag is monitored and reported to you.
A tier’s RTO also depends on how many machines start at once. Veeam’s guide to cloud failover plans states that “The maximum number of VMs that can be started simultaneously when you run a failover plan is 10.” For a large tier, ask for the timing from a test of the full plan.
In our disaster recovery service, support and the target RPO and RTO per tier are fixed in the SLA. Send us your systems by tier and the targets you need; on the first call we work through them with you.
Recovery capacity in a disaster: reserved or shared
A provider’s recovery hosts serve many customers, and the contract decides what that means when a regional power failure or flood makes several of them fail over at once. NIST SP 800-34 Rev. 1 warns that a site shared by several organisations “may be unable to accommodate all of the customers if a disaster affects enough of those customers simultaneously”, and asks for the vendor’s priority policy and the recovery days, how long you can occupy the site, to be negotiated in the contract.
In Veeam Cloud Connect, a hardware plan sets the CPU, RAM, storage and networks a tenant may use, and in Veeam’s words “The SP can subscribe one or several tenants to the same hardware plan” and “Each tenant subscribed to the hardware plan can use the whole set of resources specified in the hardware plan.” A hardware plan therefore sets limits per tenant; whether the hosts behind it can run every subscribed tenant at once depends on the provider’s capacity planning. Write the capacity held for you into the contract, with whether it is shared and how it grows when you add systems.
Failover tests: how often, how isolated, what the report shows
Fix the number of failover tests per year in the contract, with what each covers and whether the test capacity is included. NIST asks agreements to cover “Testing, including scheduling, availability, test time duration, and additional testing, if required”, and point 4.2.6 of the regulation requires the entities it covers to “document the results of the tests”.
Veeam’s test of a cloud failover plan “does not switch from a production VM to its replica”; it reverts each replica to its latest restore point, boots the operating system and checks that the VM answers ping. That shows the machines start, while a login to the ERP system and working interfaces need application checks by the system owners, timed against the RTO. Tests boot replicas on the provider’s hosts and so draw on the failover capacity, and they belong in a network isolated from production; our article on disaster recovery testing covers such setups.
Our disaster recovery service includes scheduled failover tests in an isolated environment, with a report after each test on what came up, how fast and what to fix. Describe the systems you would want tested first in the form below.
Declaring a disaster, the failover network and failback
In Veeam Cloud Connect, “The cloud failover plan must be created in advance by a tenant” and is stored on the provider’s backup server. If the tenant’s backup server is lost with the production site, the documented route is for the tenant to contact the provider, who starts the plan. The contract should name who on your side may make that request, through which channel (one that works without your email and directory service), how the provider confirms the caller and how fast it acts. While the provider’s backup server is in maintenance mode, tenants can start neither partial nor full site failover, and operations with cloud failover plans stay available only on the provider’s side, so the contract should also cover how maintenance is announced and how failover requests are handled during it. Under Veeam’s compatibility rules a major upgrade “must start on the SP side”, which ties your own major upgrades to the provider’s schedule.
On the network side, Veeam handles partial and full site failover differently, as our comparison of Veeam replication, backup copy and Cloud Connect explains. The provider allocates public IP addresses for replicas; DNS records, VPN access for users and firewall rules at partners need an owner each, and the last test report should show them done.
Failback needs its own clause, because in Veeam Cloud Connect “The failback operation is available on the tenant side only”, and after a full site failover the tenant fails back each VM in the plan separately. If your backup server was lost with the site, a rebuilt one has to be connected to the provider before failback can start. Agree on who runs those steps, how the data travels back and how long the switch back takes.
Data location, encryption and provider access
The replicas, the provider’s backup server with your failover plans, and the logs each sit in a country and a data centre that the contract should name. NIST recommends a site “in a geographic area that is unlikely to be negatively affected by the same hazard as the organization’s primary site”; our article on how far apart two data centres should be covers distance. In Veeam Cloud Connect the provider’s backup server presents a TLS certificate and establishes a secure connection with yours. For data at rest, Veeam’s guide describes encryption that tenants switch on in backup and backup copy jobs, while replicas are VM files on the provider’s storage, so ask how that storage is encrypted and who holds the keys.
Veeam keeps tenants out of each other’s data, but the provider runs the hosts. Ask which of its roles can reach your replicas, how that access is approved and logged, and whether it may manage your own backup server, which in Veeam needs an option the tenant enables when it connects. Point 5.1.4 of the regulation also covers incident notification “without undue delay”, “the right to audit or right to receive audit reports” and requirements on subcontracting.
Exit: data return and deletion at the end of the contract
Point 5.1.4(h) names “retrieval and disposal of the information” among the obligations at the termination of the contract, and ENISA suggests export tests with a “simulation of termination of service”. In Veeam Cloud Connect a provider can set a lease on a tenant account, and “When the lease period expires, the tenant cannot perform backup, backup copy and replication tasks, restore and copy VM data from the cloud repository or cloud host.” When the provider deletes a tenant account, Veeam “deletes actual replica files from the datastore or volume” for powered-off replicas, but keeps replicas running after a failover.
The exit clause should therefore set a notice period long enough to replicate your systems to a new recovery site, so they stay protected in between, and keep your access open until anything held only at the provider, such as backups or systems running there after a failover, is back with you. It should also name the format the data comes back in; a Veeam replica of a vSphere VM is “the exact copy of the VM in the native VMware vSphere format”. Deletion should be confirmed in writing, including any other copies the provider keeps, for example in its own backups.
What we do
Under our disaster recovery service, the recovery site runs in Baltneta’s Tier-3 data centres in Lithuania (ISO 27001, PCI DSS), with EU data residency, and replicas are transmitted and stored encrypted. Our engineering partner Vixen.UNO sets up virtual-machine replication from a 15-minute interval via Veeam Cloud Connect, managed from your existing Veeam console or entirely on our side. The technical assessment includes sizing the recovery site, and support, RPO and RTO are fixed in the SLA, with your targets defined per tier. Scheduled failover tests run in an isolated environment, with a report after each. Site, replication, tests and support come under one contract with Eurokommerz, with subprocessors named in it and a data processing agreement on request, as our security and compliance page sets out.
FAQ
What is DRaaS (disaster recovery as a service)?
What is the difference between DRaaS and backup?
What should I check before signing with a DRaaS provider?
What should a DRaaS SLA include?
Is recovery capacity reserved in a DRaaS contract?
What happens to our data when a DRaaS contract ends?
Send us the systems you want to protect, grouped by tier with the RPO and RTO each needs, your current backup and replication set-up and the questions from this checklist that matter most to you. We reply within one business day with a date for a first call, on which we work through your critical systems, current backup and targets, and you leave with two or three possible DR scenarios. The first call is free of charge.
Talk to an expertWe reply within one business day