Checklist · Disaster Recovery
DR Readiness Checklist
A practical self-assessment for teams that want to test whether recovery plans, dependencies, runbooks and evidence are ready for scrutiny.
Download it, use it with your team and record the basis for each answer.

Use this checklist against one critical service first. For each prompt, record whether the answer is evidenced, partially evidenced, not evidenced or not yet assessed. Record those states directly; a percentage score can imply more certainty than the evidence supports.
1. Critical services and scope
- The service has a named business and technical owner.
- The recovery scope includes every component required to deliver a usable service.
- Recovery priorities are agreed where services share constrained infrastructure or people.
- Exclusions and assumptions are explicit.
2. Recovery targets
- RTO and RPO expectations are documented and owned.
- Targets reflect business impact and confirmed service needs.
- The recovery design can plausibly meet those targets.
- Exercise evidence demonstrates whether the targets have been achieved.
3. Backup and recoverability
- Backup coverage has been reconciled against the recovery scope.
- Retention, immutability and administrative access have been reviewed.
- Restore paths have been tested using representative data or workloads.
- Encryption keys, credentials and recovery media remain available during the scenario.
4. Dependencies
- Identity and privileged-access dependencies are documented.
- DNS, network, firewall and load-balancer changes are understood.
- Application, database, storage and external-service dependencies are sequenced.
- Service accounts, secrets and certificates have a recovery path.
5. People and runbooks
- Recovery roles, decisions and escalation paths are assigned.
- Runbooks identify prerequisites, validation steps and rollback points.
- Procedures can be followed by someone other than the original author.
- Business or user validation is included before service return.
6. Testing and evidence
- The recovery scenario and success criteria are agreed before the exercise.
- Tests include realistic dependencies as well as isolated component restores.
- Timestamps, results, exceptions and decisions are recorded.
- Findings have owners, priorities and target dates.
- Retesting confirms that important remediation has worked.
Interpreting the result
This checklist provides a structured starting point. Concentrate on important services where targets are unsupported, dependencies are unclear or recovery evidence is old or incomplete.
The DR Assurance Sample Report shows how Cygnus turns this information into service findings, recovery priorities and recommended actions.
The Cygnus DR Assurance Review applies that approach to the services and disruption scenarios that matter to your organisation.