FillTrust

How to answer

What availability do you commit to, and how is it measured?

A number with no measurement behind it is trivially checkable, against a status page and against the reviewer's memory of your last outage.

A model answerImplied, not stated

We do not offer a contractual uptime guarantee at this tier. Availability is monitored externally and published at [status page URL], where historical incidents remain visible. Over the last [12 months] measured availability was [99.9%].

Square brackets are yours to fill in. FillTrust grades an answer like this implied, not stated when your documents support it.

Answered from
Your terms of service or service level agreement, if you have one. Many small vendors do not, and that is a real answer rather than a gap to paper over.
Evidence to attach
A status page, if it exists. It answers this question, the incident communication question, and the one about historical outages.
Where it is asked
CAIQ v4.0SIG LiteBespoke vendor questionnaires

Two different questions arrive under this heading and it is worth separating them, because one is contractual and one is factual. The contractual one is what you commit to and what happens when you miss it. The factual one is what your availability has actually been. A reviewer will accept "no contractual commitment" much more readily than they will accept a number that turns out to be decorative, so if you only have one of the two, make sure it is the factual one.

Do not say SLA unless you mean it. A service level agreement carries a remedy: usually service credits, sometimes a termination right. A service level objective is an internal target with no remedy attached. Small vendors frequently write "we maintain a 99.9% SLA" meaning the second, and a procurement team reading it means the first. If you have no credits regime, the honest sentence is that you do not offer a contractual guarantee at this tier, and it costs far less than it feels like it does.

A number needs a measurement. Availability measured how, from where, over what period, and counting what as downtime? Partial degradation, a slow endpoint, a failed background job: whether those count is the difference between a real figure and a comfortable one. The cheapest credible answer is external monitoring published on a status page, because it takes the measurement out of your hands and puts the history somewhere the reviewer can read it.

The status page is the highest-value artefact here, and it has to be honest. One updated by hand is always green, which every experienced reviewer knows, so it converts a neutral answer into a small credibility problem. One that records incidents, including the embarrassing ones, does more for this question than any number you could quote, and it also answers the incident communication question that usually appears three rows later.

Your provider's uptime is not yours. Their guarantee covers their infrastructure. Your availability includes your deploys, your schema migrations, your certificate renewals and the third-party API you depend on. Borrowing their figure is the single most common way this answer becomes untrue, and it is the one a reviewer with operational experience spots immediately.

How this one goes wrong

Specific to this question, not general advice.

  • Quoting a number with no measurement behind it. "99.9%" is trivially checkable against a status page and against the reviewer's own memory of your last outage.
  • Confusing an SLA with an SLO. An objective is what you aim for; an agreement carries a remedy, usually service credits. Saying "SLA" when you mean the first creates a contractual expectation.
  • Quoting the cloud provider's availability as your own. Their guarantee covers their infrastructure, not your deploys, your migrations or your dependencies.
  • Publishing a status page that is updated by hand and therefore only ever green. It is worse than no status page, because it is checkable.

There are another two hundred of these in the file.

FillTrust drafts every one from your own documents and shows the passage behind each answer, including the ones it refuses to answer.

Or write this answer down once and publish it on a Trust Center of your own, which costs nothing.