CIOPages
All RFP packages

RFP Package · Foundational IT & Infrastructure

Backup & Disaster Recovery RFP questions and template

123 questions, 10 demo scenarios and a five-vendor scorecard for choosing Backup & Disaster Recovery software, in one Excel workbook.

What this package is for

Use it to run a Backup & Disaster Recovery software selection, from the first long list to the final scorecard.

What the category covers. Software that backs up servers, virtual machines, databases, SaaS applications, cloud workloads and endpoints, keeps copies that cannot be altered or deleted, and restores and fails over systems after ransomware, corruption or site loss. Bought by IT operations and security teams that must meet recovery targets and prove recovery by test.

A selection usually runs in three rounds. The package has questions for each:

  • RFI, to the long list. 23 questions screen out products that lack something you need.
  • RFP, to the shortlist. 63 questions ask how each product does the work.
  • Deep dive, to the finalists. 37 questions ask for proof on your own data.

10 demo scenarios tell each vendor what to load and what to show, so every product does the same work in front of you. 100 due-diligence questions cover security, integration, implementation and exit. The scorecard weights the answers and ranks up to five vendors.

Each question comes with why it matters, what a good answer looks like and the red flags, so the people scoring the replies know what to look for.

3 questions from the package

From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.

1. Provide your published support matrix for the current release, listing each supported version of [server operating systems], [hypervisors] and [database platforms].

Why it matters. If a version the buyer runs is missing or listed with limits, those systems either go unprotected or block the buyer's upgrade plans. Without the matrix, the gap shows up during deployment.

Good answer
  • The matrix is public or provided as a dated document tied to a specific product release
  • Each entry states the supported version and patch level, not only the product family
  • Limits are stated per entry, such as agentless-only, file-level-only or no point-in-time restore
Red flags
  • Answers with 'all major platforms' instead of a list
  • The matrix is undated or not tied to a release number
  • Support for a version the buyer runs is described as 'on request' or 'on the roadmap'

2. Provide a table that lists each data type in each of [SaaS applications] (such as mail, calendars, contacts, files, sites, chats and channel messages) and marks which ones your product backs up through the application's API.

Why it matters. SaaS backup coverage differs by data type, and a data type the product does not capture cannot be restored after deletion or tampering. The buyer may only find the gap when a user asks for data that was never backed up.

3. Can one backup policy include or exclude files by folder path, file type and file size?

Why it matters. Without these rules the buyer either backs up temporary files, media and caches that consume storage and backup window, or leaves out folders that need protection.

Capability areas

Data center workload coverage (12)

Covers file-level backup of server operating systems, agentless VM backup through hypervisor APIs, image-level backup for bare-metal rebuild, application-consistent database backup with transaction logs, NAS shares over SMB/NFS, Kubernetes workloads, published version support and how quickly new versions are supported, agent footprint, and scale limits on sources and capacity. SaaS, public cloud and endpoint sources are covered in CLD.

SaaS, cloud-native and endpoint coverage (10)

Covers API-based backup of SaaS applications (mail, files, sites, chats) and how it works within each application's API limits, backup of cloud VMs, managed databases and object storage, laptops and desktops backed up over the internet without VPN, attached external drives, and automatic discovery and protection of new SaaS users and endpoints. Restore of these sources is covered in RES.

Backup policy, scheduling and backup performance (13)

Covers schedules and backup windows, include/exclude rules, incremental chain method, continuous protection for selected systems, retention tiers, deleted-file retention, version counts, policy assignment by group or tag, bandwidth and CPU/disk throttling, pre/post scripts, legal hold, resuming interrupted jobs, and meeting [initial backup window] and [daily backup window] at [daily change rate]. Retention enforcement against deletion is covered in IMM.

Storage targets, copies and efficiency (9)

Covers local plus offsite copies, replication to a second region or location, deduplication and compression, writing to storage in our own cloud account, drive-based seeding, tiering to lower-cost storage with stated restore times and retrieval costs, storage-used reporting, region placement of primary and secondary copies, and documented durability design. Licensing and price terms belong to the commercial module.

Immutability, isolation and backup tamper protection (11)

Covers the mechanism that enforces immutability and who can lift it, logically isolated copies with credentials and a control plane separate from production, second-administrator approval for destructive actions, recoverable holding of deleted backups, protection and rebuild of the backup catalog, MFA on every console sign-in, and administrator accounts separate from the production directory. Detection of ransomware inside backup data is covered in THR.

Threat detection and clean recovery point identification (10)

Covers anomaly detection on backup data (change rates, mass deletion, encryption), malware scanning of restore points, identification of the most recent clean restore point, alerts on agent removal, disabled policies or silent sources, and forensic restore into an isolated clean-room environment. General SIEM event delivery is covered in MON. Also covers discovery of sensitive data inside backups and the clean-room environment used to investigate and scan before data returns to production. Validation of restored systems before cutover in a planned recovery is covered in DRO.

Restore and granular recovery (12)

Covers file and folder restore with overwrite options, browse-by-date and cross-backup search, whole-machine restore to the same hardware, different hardware or a VM, running a VM directly from backup storage, database point-in-time restore, single-item SaaS restore, end-user self-service restore, preservation of permissions and metadata, restore throughput from cloud storage, and drive-shipped restores. Multi-system orchestrated recovery is covered in DRO.

Disaster recovery orchestration and recovery at scale (10)

Covers saved recovery plans that restore many machines in a set order and priority, recovery of servers as VMs in [cloud provider], restore into an isolated network before production cutover, failback, the break-glass restore process when the console or production identity provider is unavailable, and meeting [RTO] for [largest critical system]. Scheduled restore testing is covered in TST. Also covers journal-based continuous replication of tier-1 VMs to a secondary site or cloud, network and IP re-mapping at failover, and non-disruptive DR rehearsal of a plan without touching production.

Restore testing and verification (9)

Covers scheduled restore tests that restore, boot, run our check scripts and report pass or fail, measured restore time against [RTO], isolation of tests from production, checksum integrity verification on a schedule and at restore, auditor-ready test reports, and retention of test results for [test result retention period].

Encryption, key custody and restore access control (10)

Covers encryption of backup data in transit and at rest, customer-held keys in [key management service] or as a private key, the documented procedure if we lose a key we hold, role separation for backup, restore, delete and policy change, restricting users to restoring data they may access, administrator sign-in through our identity provider, logged and approved vendor staff access to backup data, and permanent deletion at end of retention that respects legal hold and immutability. The vendor's own corporate security program belongs to the security module.

Protection monitoring, reporting and SOC integration (9)

Covers the view of every protected and unprotected source with last successful backup, alerts on failed, missed and partial backups and their delay, reports of sources outside [RPO], scheduled CSV/PDF reports, the administrator audit log with its retention and tamper protection, event delivery to [SIEM] and response actions triggered from [SOAR platform], and ticket creation in [ticketing system].

Administration, automation and agent lifecycle (8)

Covers single-console management across all sources and locations, API coverage for policies, jobs, restores and reports, infrastructure-as-code support, silent agent deployment through [software distribution tools], staged automatic agent updates, and delegated administration limited to each business unit's sources. Generic API availability and SSO/SCIM belong to the integration module.

Demo scenarios

Each scenario lists the data to load before the demo, then the steps to show, and the questions it scores.

  1. Stolen admin account tries to destroy backups
  2. Ransomware has encrypted a tier-1 application
  3. Primary site is lost
  4. Recovery without console or identity provider
  5. Database corrupted at a known time
  6. Deleted SaaS data needs to come back
  7. Weekly restore tests for the auditor
  8. New machines need protection at scale
  9. Backups move across copies, regions and tiers
  10. Remote worker restores files on an off-network laptop

Due diligence

The workbook carries the screening questions from these modules. Each module is also sold on its own.

Questions about this package

How many Backup & Disaster Recovery RFP questions are there?

123 solution questions in 12 capability areas: 23 for the RFI, 63 for the RFP and 37 deep-dive questions for the finalists. The workbook adds 100 due-diligence questions on security, integration, implementation and exit.

What comes with each question?

Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.

Can I edit the questions?

Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.

Which license do I need?

The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.

Before you shortlist

The buyer guide compares the products in this category and what decides between them.

Buyer Guide
Backup & Disaster Recovery