Most managed cloud SLAs commit to two things: an uptime percentage and a time to acknowledge your ticket. Both are inexpensive for the provider to promise, and neither is what you actually care about when something is broken.
Here is what to read first, and what to ask to have added.
Know what the uptime number means in minutes
Percentages hide the scale. Against a thirty-day month:
- 99% — 7 hours 12 minutes of permitted downtime.
- 99.9% — 43 minutes.
- 99.95% — 21 minutes 36 seconds.
- 99.99% — 4 minutes 19 seconds.
The gap between 99% and 99.9% is the difference between an outage that ruins a day and one most customers never notice. Decide which you actually need before comparing quotes, because the higher tiers cost real money and are sometimes genuinely unnecessary.
Acknowledgement is not resolution
This is the most common misreading. A four-hour response target usually means someone will confirm receipt within four hours — not that anyone will have started work, and certainly not that it will be fixed.
Ask for a target time to begin remediation, separated by severity, and ask what happens when that target is missed. A provider unwilling to commit to anything beyond acknowledgement is telling you where their staffing actually is.
Read the exclusions before the commitments
The exclusions determine whether the commitments mean anything. Look for:
- Scheduled maintenance windows — how much notice, how long, and whether they count against uptime. Unlimited excluded maintenance makes any percentage meaningless.
- Upstream provider failures. Most managed providers exclude the underlying hyperscaler’s outages. That is reasonable, but it means your effective availability is theirs multiplied by the provider’s, not the number on the contract.
- Changes you requested. Fair, but check how broadly “customer-caused” is defined.
- Degraded versus down. Many SLAs only count total unavailability. A service responding in forty seconds is functionally broken and often technically “up”.
Service credits are not compensation
Credits are typically a percentage of the monthly fee, which is almost never close to what an outage cost you. They are best understood as a signal of confidence rather than a remedy.
Two things to check regardless: whether credits are applied automatically or only if you notice and claim within a window, and whether repeated misses escalate. A credit you have to discover and request is a credit the provider expects not to pay.
Ask for the commitments nobody offers by default
These matter more than the uptime figure and are usually absent unless requested:
Time to restore from backup. Not that backups exist — how long a full restore takes, tested, with a date on the last test. An untested backup is a hypothesis.
Named escalation. Who you reach at hour four of a major incident, and how.
Patching commitments. How quickly critical vulnerabilities are applied, and who decides the window.
Exit terms. How long you have access to your data and configuration after termination, in what format, and at what cost. This is the clause that determines whether you are a customer or a hostage.
Check that it is measured somewhere you can see
An SLA reported only by the provider, in a monthly summary they compile, is difficult to hold anyone to. Independent monitoring you control — even a simple external check — gives you a number of your own.
Providers confident in their operations do not object to this. The reaction to the request tells you something either way.
Match the tier to the workload
Not everything needs the same commitment, and paying for the top tier across an entire estate is a common waste. An internal reporting tool and a payment path have different tolerances; a sensible agreement prices them differently rather than averaging them.
Our managed cloud services cover migration, monitoring and the controls regulated work requires. Tell us what you are running — or read cloud migration: what to move last.
Common questions
What does 99.9% uptime actually allow?
About 43 minutes of downtime per 30-day month. For comparison, 99% allows 7 hours 12 minutes, 99.95% allows 21 minutes 36 seconds, and 99.99% allows 4 minutes 19 seconds.
Is response time the same as resolution time?
No, and this is the most common misreading. A four-hour response target usually means acknowledgement of your ticket, not that work has started. Ask for a target time to begin remediation, separated by severity.
What is usually missing from a cloud SLA?
Tested time to restore from backup with a date on the last test, named escalation for a major incident, patching commitments for critical vulnerabilities, and exit terms covering how long you can retrieve your data and in what format.


