Skip to main content
Category: Business Continuity & Resilience

Maximum Acceptable Outage

Also known as: MAO, Maximum Tolerable Downtime, MTD
Simply put

Maximum Acceptable Outage (MAO) is the longest amount of time a business process, service, or system can be unavailable before the disruption causes unacceptable harm to the organization. It represents the point beyond which an outage begins to compromise the organization's objectives and ability to operate. In practice, it helps organizations decide how quickly they must restore a given function after a disruption.

Formal definition

MAO is the maximum duration a business process, service, or system can remain unavailable before its loss compromises the organization's objectives or causes unacceptable damage. It defines the outer time boundary within which recovery must become effective, and in some sources it is described as encompassing the time required to execute the reconstitution phase. MAO is frequently treated as equivalent to Maximum Tolerable Downtime (MTD), and it typically serves as a constraint against which recovery objectives such as Recovery Time Objective (RTO) are set, ensuring recovery targets fall within the acceptable outage window. Note that MAO reflects a business impact threshold determined through impact analysis rather than a purely technical recovery capability; the value assigned depends on organizational context and stakeholder-defined tolerance for disruption.

Why it matters

Maximum Acceptable Outage sets the outer boundary that keeps continuity planning honest. Without a defined MAO, organizations tend to make recovery investment decisions based on technical convenience or budget rather than on the actual point at which a disruption begins to cause unacceptable harm. Because MAO reflects a business impact threshold determined through impact analysis rather than a technical recovery capability, it forces leadership to articulate how much downtime a given process can genuinely sustain before objectives are compromised. This is a governance and business risk question, not a purely technical one, which is why it belongs in conversations at the executive and board level as much as in the recovery team.

Who it's relevant to

Executives and Business Owners
MAO is fundamentally a statement of business risk tolerance, so accountability for defining it rests with organizational leadership and the officers who own the affected objectives. A virtual CISO can facilitate and advise on the process, but the tolerance for disruption must be owned by the business, since it reflects how much harm the organization is willing to accept before recovery is complete. The quality of an MAO depends heavily on candid stakeholder input about what unacceptable harm actually means for the organization.
Virtual and Fractional CISOs
A vCISO or fractional CISO typically advises on establishing MAO as part of governance and resilience strategy, helping the organization connect impact analysis to recovery targets such as RTO. This is advisory and directive work rather than hands-on execution; the vCISO generally does not perform the operational recovery itself unless explicitly contracted. Engagement value here depends on organizational maturity, access to stakeholders, and cooperation in defining honest tolerance thresholds.
Business Continuity and Resilience Teams
Continuity and resilience practitioners use MAO as the anchoring constraint for continuity planning, ensuring that recovery objectives fall within the acceptable outage window. They translate the business-defined threshold into operational recovery plans and validate that planned recovery, including the reconstitution phase in sources that describe it that way, can become effective within the MAO.
Recovery and Operations Teams
Teams responsible for restoring systems and services rely on MAO to understand the outer limit within which recovery must be effective. It gives them a business-grounded ceiling against which to test whether their technical recovery capability is sufficient, and it highlights gaps where current capability cannot meet the tolerance the business has stated.

Inside MAO

Outage Tolerance Threshold
The Maximum Acceptable Outage (MAO), sometimes called Maximum Tolerable Period of Disruption (MTPD), represents the longest duration a business function or process can be unavailable before the resulting consequences become unacceptable to the organization. It defines the outer time boundary that continuity planning must respect.
Business Impact Basis
MAO is typically derived from a Business Impact Analysis (BIA), where the organization assesses how disruption to a given function affects operations, finances, reputation, legal obligations, and stakeholders over time. The MAO reflects the point at which those cumulative impacts cross into intolerable territory.
Relationship to Recovery Objectives
MAO acts as an upper constraint on the Recovery Time Objective (RTO). The RTO, which is the targeted time to restore a function, should generally be set shorter than the MAO to leave a margin of safety. Confusing the two is a common error; the MAO is a tolerance limit, not a recovery target.
Governance and Advisory Role
In a security or continuity leadership context, a virtual or fractional CISO may advise on defining and validating MAO values as part of governance and risk management, but accountability for accepting these thresholds typically remains with the client organization's officers and business owners who understand the operational consequences.
Per-Function Variability
MAO is not a single organization-wide number. It typically varies by business function, process, or service, since different activities carry different tolerance levels for disruption. Critical customer-facing or regulated functions often carry shorter MAOs than lower-priority internal processes.

Common questions

Answers to the questions practitioners most commonly ask about MAO.

Is Maximum Acceptable Outage (MAO) the same as the Recovery Time Objective (RTO)?
No, and treating them as interchangeable is a common mistake. MAO, sometimes called Maximum Tolerable Downtime or Maximum Tolerable Period of Disruption, represents the longest duration a business function can be unavailable before the resulting damage becomes unacceptable to the organization. The RTO is the target time within which recovery should be achieved and is typically set to be shorter than the MAO to provide a margin of safety. In many engagements, a virtual CISO will help clarify that the MAO is a business-defined tolerance threshold, while the RTO is a planning target derived from it. If an RTO equals or exceeds the MAO, that generally signals a gap that needs to be addressed.
Does defining an MAO guarantee that a business function will always be restored in time?
No. An MAO is a statement of tolerance, not a guarantee of outcome. It defines how much downtime the organization considers acceptable, but it does not by itself ensure recovery capabilities meet that threshold. Whether the MAO is actually met depends on factors such as recovery strategies, resource availability, testing, and the nature of the disruption. A virtual CISO typically advises on aligning recovery capabilities with the MAO and identifying where gaps exist, but accountability for accepting residual risk and funding recovery investments generally remains with the client organization and its officers. Value of this analysis often depends on organizational maturity and the quality of business impact information provided.
How is the MAO typically determined for a business function?
The MAO is generally determined through a business impact analysis, in which stakeholders assess how the escalating consequences of an outage, such as financial loss, reputational harm, regulatory exposure, or safety impact, accumulate over time until they reach an unacceptable level. Because this is a business risk judgment rather than a purely technical exercise, input from process owners and executives is usually essential. A virtual CISO may facilitate this analysis and challenge assumptions, but the tolerance thresholds themselves should be owned by the business. Accuracy depends heavily on stakeholder cooperation and access to reliable impact information.
Who should be responsible for setting and approving the MAO?
Setting the MAO is typically a collaborative exercise, but final approval usually rests with business leadership and function owners rather than with technical staff alone, because the MAO reflects the organization's tolerance for business disruption. A virtual CISO often advises, facilitates, and documents the process and highlights inconsistencies, but they generally direct rather than decide. In many engagements the vCISO will recommend that the MAO be formally reviewed and signed off by accountable executives so that the risk acceptance is explicit and traceable.
How does the MAO relate to recovery planning targets like RTO and RPO?
The MAO typically serves as an upper boundary that informs other recovery objectives. The RTO, the target time to restore a function, is generally set within the MAO to leave a safety margin. The Recovery Point Objective addresses acceptable data loss and is a distinct measure from downtime tolerance, so it should not be conflated with the MAO. In practice a virtual CISO may help ensure these values are internally consistent, so that planned recovery targets do not exceed the tolerance the business has defined.
How often should the MAO be reviewed or revised?
MAO values are generally not static, because the business context that drives them can change. Reviews are often recommended when there are significant changes to the business, such as new dependencies, changes in regulatory exposure, shifts in customer expectations, or major process changes, as well as on a periodic basis as part of broader continuity governance. A virtual CISO may recommend embedding MAO review into an existing risk or business continuity cycle, though the appropriate cadence may vary by organization and by the criticality of the function.

Common misconceptions

MAO and RTO are the same thing and can be used interchangeably.
They are distinct. MAO is the maximum time a function can be down before impacts become unacceptable, while RTO is the recovery target the organization commits to. In sound planning the RTO is set within the MAO, leaving buffer; treating them as identical eliminates that safety margin.
A virtual CISO can simply set the MAO for the organization as a technical decision.
Determining MAO is fundamentally a business risk and governance decision, not a purely technical one. A vCISO or fractional CISO typically advises, facilitates the analysis, and challenges assumptions, but the acceptance of tolerance thresholds and their consequences generally rests with business owners and accountable officers. Its accuracy also depends on stakeholder cooperation and access.
Meeting the MAO guarantees the organization avoids serious harm from an outage.
MAO defines the point beyond which impact is deemed unacceptable, but staying within it does not guarantee outcomes such as breach prevention or absence of loss. Its value depends on the quality of the underlying Business Impact Analysis, organizational maturity, and whether recovery capabilities can realistically meet the defined targets.

Best practices

Derive each MAO from a documented Business Impact Analysis rather than assigning arbitrary time values, and record the impact rationale that justifies the threshold.
Define MAO per business function or process, recognizing that critical, customer-facing, or regulated activities often warrant shorter tolerances than lower-priority functions.
Set Recovery Time Objectives to fall within the MAO with a deliberate margin of safety, and flag any case where the achievable RTO exceeds the MAO as an unaddressed risk requiring executive attention.
Involve business owners and accountable officers in reviewing and formally accepting MAO values, since these are business risk decisions rather than technical ones a vCISO can own alone.
Revisit MAO values periodically and after significant business, regulatory, or operational changes, since tolerance for disruption can shift over time.
Where a virtual or fractional CISO facilitates the process, clearly document the advisory scope and confirm that access to stakeholders and reliable operational input is available, as MAO accuracy depends on that cooperation.