Evaluating ISP Redundancy Capabilities Before You Sign the Contract
How to evaluate an ISP's redundancy claims before you commit: SLA math, last mile diversity, restoration commitments, the contract clauses that matter, and the evidence to collect.

On this page
Every ISP sells some version of redundancy. The pitch varies by carrier: a second circuit bundled at a resilience discount, a metro Ethernet product described as carrier grade, a failover router that will just work when the primary goes down. What the pitch does not say is that the SLA was drafted by pricing, the last mile was subcontracted, and the details that determine whether the setup actually fails over are buried in boilerplate you will not read until the first outage. Redundancy is the most expensive property a connectivity contract can sell, and it is the least verified one, because it cannot be tested before you commit.
This guide walks through an evaluation you do before you sign: where ISP redundancy claims actually fail, how to read an SLA the way a procurement engineer does, what restoration targets to demand, the contract clauses that quietly undo the design, and the evidence you can collect while you still have leverage. After the signature, the terms only move in the carrier’s favor, so the whole evaluation belongs on the front end.
Redundancy Is Claimed More Than It Is Designed
A carrier quoting a resilient fiber product is describing layers, even when the sales page never shows them. Connectivity to your site passes through the building entry, the local loop, the carrier’s aggregation point, its backbone, and its peering relationships, and a failure at any one of these layers takes down the product regardless of how redundant the other four are. When you evaluate a redundancy offer, decompose the claim layer by layer and force a concrete answer at each one. A product is only as redundant as its weakest layer, and in commercial connectivity the weakest layer is almost always the local loop and the building entry, because those are the segments the carrier owns least and controls least.
Ask each layer its own question. At the building entry: do the primary and backup paths share a conduit, a wall penetration, or a demarcation room? On the local loop: does the carrier own the fiber, or is it leasing from a wholesaler? At the aggregation point: do both circuits hand off within the same central office, or meet at a single carrier hotel? On the backbone: does the product routing have a genuine second path, and does the network advertise it automatically? At the peering layer: what happens when the carrier’s upstream transit provider fails? A sales engineer who answers all five without a pause is rare, and the ones who answer with a blanket “our network is fully redundant” are answering none.
The Last Mile Is Where Independence Disappears
Network diversity claims deserve the least trust at the last mile, for a structural reason: the fiber that reaches your building is usually not the carrier’s own. A large share of business fiber is leased from wholesale operators, so the two ISPs you are comparing may be reselling the same underlying dark fiber, and two circuits from different providers can ride the same physical cable for a mile before they separate. Checking provider names is the weakest possible diversity test. Checking who owns the physical fiber from the building to the carrier’s aggregation point is the real one, and the answer is rarely written in the sales materials.
Your own inspection closes the gap that no carrier document covers. Walk the building: note where each circuit’s feed enters, which conduit it shares, which room houses the demarcation, and whether the primary and backup terminate on the same rack, the same power feed, or the same switch. The network topology records in your documentation should show every circuit terminating at the site and every device it feeds, because shared entry points and shared handoffs are exactly the single points of failure that redundancy marketing is designed to obscure. Diversity is the difference between a pair of circuits that fails independently and a pair that fails together, and in practice that difference lives in the last mile near your own walls rather than anywhere else in the carrier’s network.
Read the SLA as a Contract, Not a Brochure
The SLA is where marketing becomes arithmetic, and arithmetic is where you can catch the carrier. Uptime percentages are only meaningful with their measurement window: a 99.99 percent monthly SLA allows about 53 minutes of downtime per month, while the same percentage measured annually lets that 53 minutes spread across the year and mostly disappear during periods when it matters less. The measurement boundary matters just as much. Many SLAs measure only the carrier’s core network and exclude the local loop, the CPE, and the segments that fail most often, which means a contract that looks like 99.99 percent can quietly cover a fraction of your actual connectivity. Ask where the boundary sits and write the answer into your evaluation notes.
Exclusions do the quiet damage. Planned maintenance windows are commonly carved out of uptime calculations, which is defensible when they are rare, announced, and scheduled at hours you can reroute around, and indefensible when they are unlimited or unannounced. Force majeure clauses that count any third party act as excusable can cover the contractors who routinely cut buried fiber, which is the single most common cause of the very outages an SLA is supposed to compensate. Credits are the enforcement mechanism, so check the mechanics before you need them: what share of the monthly recurring charge a breach returns, how long an outage must run before credits begin, whether credits are paid directly or merely offset against future invoices, and how long you have to file. Most eligible SLA credits go unclaimed, and the usual reason is that teams cannot produce the timestamped, provider referenced evidence the carrier demands within its filing window.
Restoration Commitments Beat Uptime Averages
An uptime percentage is an average, and averages forgive the outages that hurt. Two circuits can both post 99.99 percent while one recovers in fifteen minutes and the other takes eight hours, because the average is blind to the shape of the downtime. Restoration commitments are the number that captures the shape: how quickly the carrier dispatches after a confirmed fault, how long before the circuit is repaired rather than patched, and what happens when the restoration target is missed. A target worth demanding is a dispatch commitment of four to eight hours for business circuits, restoration within twenty four to forty eight hours for a damaged local loop, and a monthly credit on top of the uptime credit when restoration slips. Restoration targets convert SLA arithmetic into a promise about your worst day, and the worst day is the only day you will care about the contract.
The credit process deserves its own scrutiny, because it only works if the evidence exists when the outage happens. Confirm the carrier’s filing window, typically thirty to ninety days, and the documentation it accepts: the circuit ID from your own records, ticket timestamps, monitoring graphs, and a clean start and end time for the event. The teams that routinely collect credits have the baseline before the outage, not after, which means the outage record, the monitoring data, and the SLA parameters live somewhere the same team can query together. Everything else in this evaluation is negotiation; the credit step is pure housekeeping, and housekeeping is where carriers make their margins back.
Contract Clauses That Reinforce the Design
Beyond the SLA, the contract that actually supports a redundancy design covers clauses that never make the sales conversation. The auto renewal and notification window determines whether you can leave at the end of the term, and carriers draft those windows in their own favor, so a negotiated sixty day review period is a concrete win even when the headline price does not move. The term lengths of paired circuits deserve to be aligned, because a backup that renews a year after its primary traps you in a design running on one leg at the exact moment you want to renegotiate the pairing. The change process matters too: ask what notice the carrier gives before planned maintenance, and confirm you can schedule your own failover tests without the carrier counting them as ticket events.
Two clauses quietly undo redundancy designs later, and both are worth negotiating before signing. The first is substitution language that lets the carrier restore one service onto another path during repair, for example rebuilding your diverse pair on the same route and calling the work complete, so the contract should require that repair restore the original routing and diversity. The second is the third party local loop clause: if the last mile is provided by a wholesaler, the contract should name the owner, define a restoration path, and apply the same credits to third party outages that apply to the carrier’s own network. A redundancy contract that cannot survive the second year of operation is not a contract for redundancy at all, it is a contract for two circuits that used to be different.
Collect Evidence Before You Commit
The evaluation should produce documents, not impressions. Ask for the carrier’s network maps at a level that shows your building, the local loop ownership, and the aggregation point, and treat anything marked illustrative as marketing. Ask for the carrier’s outage statistics for the specific metro region, many larger carriers publish network transparency reports, and a reference customer on the same product in the same region is worth more than any brochure. On net buildings, where the carrier owns the loop directly, genuinely see faster restoration than off net ones delivered over a wholesaler, so ask whether your building is on net and what the SLA difference actually is. If the terms allow it, a short pilot circuit carries the most convincing evidence there is: your own monitoring data from the first months, including the failover behavior you actually observed rather than the behavior the engineers described.
Acceptance testing belongs in the same set of asks. Negotiate a defined test window after installation where the failover is exercised, the failover target is measured, and the results are signed off before the full contract term starts. No carrier will fail a test gracefully, but the test still produces the baseline you will compare against at every review, and it establishes, before the bulk of the money is committed, whether the redundancy story is real. The price of skipping it is discovering the truth during the first real outage, when the only question left is which clause covers the damage.
Record What You Agreed To
Redundancy evaluations fail in two ways: before signing, by trusting claims over evidence, and after signing, by letting the negotiated terms evaporate into email threads and account manager handoffs. The fix for both is a record that survives the negotiation process. Write down the terms you evaluated: the SLA boundary and window, the restoration targets, the credit mechanics, the loop owner, the auto renewal date, and the entry points you verified in person. That record is your baseline for the next renewal, it is the reference your team reaches for during the first outage, and it is what stops a future team from reordering the same flawed design by habit.
The ISP service inventory template captures the provider, service type, SLA uptime, term, and renewal dates that this evaluation produces, and circuit records in Obelinf hold the same fields as part of your regular circuit inventory, with SLA parameters, contract dates, and provider details sitting alongside the sites and devices they serve. When the terms you evaluated are the terms you documented, the next contract sign takes minutes instead of a full investigation, and the redundancy you paid for is the redundancy you can actually hold the carrier to.
Frequently Asked Questions
What should I check in an ISP contract before signing for redundancy?
Should I care whether an ISP SLA is measured monthly or annually?
What is a realistic restoration time to demand from an ISP?
How do I negotiate a better ISP redundancy deal?
Is a broadband backup circuit worth signing a second contract for?
Stop reaching for a spreadsheet
Obelinf keeps every subnet, device, circuit, and rack in one live source of truth, with audit logs and a topology view. Free for personal use.
Related Articles

Fixed Wireless and LEO Satellite as ISP Backup: When to Use Them Over Broadband
When a second broadband line is not diverse enough, fixed wireless and LEO satellite give you true path independence. Learn where each fits, what it costs, and how to size and test a wireless backup that actually fails over.
Read more
How to Switch ISPs Without Downtime: IP Renumbering, DNS and Cutover Planning
Switch ISPs without downtime by planning IP renumbering, DNS TTL strategy, and a parallel cutover that keeps your network reachable throughout the migration.
Read more
ISP Diversity Audit: How to Prove Two Providers Don't Share the Same Fiber
Two ISP contracts do not guarantee diverse fiber. Learn how to audit physical paths, local loop ownership, and routing to prove your providers are truly independent.
Read more