Data as of Sep 9, 2026 · Based on 319 AI responses from ChatGPT Search and Google AI Mode · See how Parse measures this
For businesses requiring minimal downtime, several incident response providers offer guaranteed one-hour response service level agreements (SLAs). Key providers such as LevelBlue, eSentire, Pondurance,
Dragos,
Cybereason, and stand out for offering these fast, 24/7 prioritized engagements. While these services help minimize business impact, some providers offer additional benefits like technology-agnostic support or proactive threat hunting to stop incidents before they result in active business disruption.
Brands AI recommends here
Named in 65% of answers
Named in 55% of answers
Named in 46% of answers
Named in 37% of answers
eSentire is a top choice for rapid response, providing a one-hour SLA for critical incidents while combining emergency support with proactive threat hunting to help prevent downtime from occurring.
For businesses where downtime carries heavy financial or operational penalties, standard "best-effort" or 24-hour response windows are insufficient. The fastest guaranteed remote response SLAs in the industry sit at **1 to 2 hours** , though these speeds are almost exclusively gated behind `top-tier annual retainers`…
For businesses where downtime carries heavy financial or operational penalties, standard "best-effort" or 24-hour response windows are insufficient. The fastest guaranteed remote response SLAs in the industry sit at 1 to 2 hours , though these speeds are almost exclusively gated behind top-tier annual retainers or large prepaid hour commitments.
The leading incident response (IR) retainer services offering the fastest guaranteed SLAs include:
A 1- or 2-hour contract SLA is only as fast as your preparation. To prevent downtime during an activation, ensure your retainer includes:
To help narrow down which provider fits your environment best, tell me:
If **contractually guaranteed response time** is the priority, the shortlist is surprisingly small. Based on currently published vendor commitments, I’d rank them roughly like this: Provider | Published retainer SLA / response | Best fit | My take --- | --- | --- | ---
If contractually guaranteed response time is the priority, the shortlist is surprisingly small. Based on currently published vendor commitments, I’d rank them roughly like this:
| Provider | Published retainer SLA / response | Best fit | My take |
|---|---|---|---|
| CrowdStrike | As fast as 1 hour for remote response on certain retainer options | Businesses already using Falcon | Fastest published option I found |
| Mandiant | 2 hours enhanced SLA | High-impact enterprise breaches | Strongest choice when expertise/depth matters as much as speed |
| Secureworks | Contract-dependent; published Taegis incident notification SLA is 15 minutes after Secureworks determines an incident exists | Organizations wanting MDR + IR | Don't confuse notification SLA with guaranteed responder arrival |
| Fortra / Alert Logic | 15-minute critical-incident triage (MDR) | Organizations wanting managed detection/response | Again, this is triage, not necessarily an IR-retainer deployment SLA |
CrowdStrike's current Services Retainer says its experts can deploy globally within hours, and its retainer materials advertise rapid response. A current independent comparison reports a 1-hour remote-response SLA option; importantly, CrowdStrike's own older published retainer datasheet shows tiers ranging from 8 hours down to 2 hours, so I'd insist that the specific 1-hour commitment be written into your current contract rather than relying on marketing language.
For a business where minutes matter, this would be my first vendor to RFP.
Mandiant's current retainer explicitly provides a 2-hour response time, 24/7, with pre-negotiated terms and prepaid funds. Its datasheet distinguishes the standard four-hour initial contact from an enhanced two-hour SLA, so make sure you're buying the enhanced SLA rather than assuming it's automatic.
This is particularly compelling if a catastrophic breach—ransomware, major data theft, nation-state intrusion—is more concerning than the incremental difference between a one- and two-hour SLA.
Secureworks' Incident Management Retainer is designed for emergency incident response, with the actual response parameters defined by the customer's contract. Its publicly documented Taegis NDR SLA provides customer notification within 15 minutes after Secureworks determines that activity constitutes a security incident. That's not equivalent to a 15-minute IR-team arrival/engagement SLA.
For a "cannot afford downtime" business, don't compare vendors based simply on a number like 15 minutes. Ask each vendor to specify these separately:
Bottom line: If you mean fastest guaranteed access to an actual IR team, CrowdStrike (1-hour option, subject to confirming the current contractual terms) appears to be the fastest published retainer SLA I found, followed by Mandiant's 2-hour enhanced SLA. Secureworks/Alert Logic advertise much faster detection/notification/triage SLAs, but those shouldn't be treated as equivalent to a guaranteed IR deployment time.
If you tell me your approximate company size (e.g. 100, 1,000, or 10,000+ employees) and whether you need onsite response, I can narrow this to the 3–5 retainers I'd put into an RFP and compare their SLA language, coverage, and likely cost.
For a business where minutes matter, this would be my first vendor to RFP.
Mandiant's current retainer explicitly provides a 2-hour response time, 24/7, with pre-negotiated terms and prepaid funds. Its datasheet distinguishes the standard four-hour initial contact from an enhanced two-hour SLA, so make sure you're buying the enhanced SLA rather than assuming it's automatic.
This is particularly compelling if a catastrophic breach—ransomware, major data theft, nation-state intrusion—is more concerning than the incremental difference between a one- and two-hour SLA.
Secureworks' Incident Management Retainer is designed for emergency incident response, with the actual response parameters defined by the customer's contract. Its publicly documented Taegis NDR SLA provides customer notification within 15 minutes after Secureworks determines that activity constitutes a security incident. That's not equivalent to a 15-minute IR-team arrival/engagement SLA.
**Top-tier incident response (IR) retainers generally guarantee initial remote response Service Level Agreements (SLAs) ranging from 1 hour to 4 hours for critical-severity (P1) breaches, with elite providers like** **Sygnia, [Mandiant (Google Cloud)](https://cloud.google.com/mandiant) , and CrowdStrike leading the…
Top-tier incident response (IR) retainers generally guarantee initial remote response Service Level Agreements (SLAs) ranging from 1 hour to 4 hours for critical-severity (P1) breaches, with elite providers like Sygnia, Mandiant (Google Cloud) , and CrowdStrike leading the industry in raw emergency activation speed.
For zero-downtime environments, a contractual 1-hour remote SLA is the gold standard, though true operational resilience depends heavily on pre-positioning access credentials and telemetry rather than just waiting for an emergency phone call.
Comparison of Leading IR Retainer SLAs
| Provider | Guaranteed Remote SLA (P1 Critical) | Key Advantage / Differentiator |
|---|---|---|
| Sygnia | 1 Hour (Immediate triage) | Renowned for elite raw containment speed, deep enterprise forensic execution, and complex adversary ouster. |
| Mandiant | 1 to 2 Hours | Unmatched threat intelligence depth, proprietary FLARE reverse engineering, and global scale. |
| CrowdStrike | 1 to 2 Hours (With Falcon telemetry) | Instant remote deployment if endpoint telemetry is already active in your environment. |
| Cybereason | 1 Hour (Resilience Retainer) | Rapid 24x7 response commitment with flexible multi-service credits. |
Key Factors Beyond the SLA Clock
When downtime costs thousands of dollars per minute, a printed SLA guarantee is only as good as the operational framework backing it up. Keep these constraints in mind:
If you'd like to narrow this down, please share:
I can help tailor the ideal vendor recommendation to your infrastructure.
If **downtime is genuinely unacceptable**, I’d prioritize the contractual SLA—not a vendor’s average response time or marketing claim. Based on publicly stated 2026 offerings, the fastest retainer commitments I found are: Provider | Fastest stated SLA | What it appears to guarantee | My take --- | --- | --- | ---
If downtime is genuinely unacceptable, I’d prioritize the contractual SLA—not a vendor’s average response time or marketing claim. Based on publicly stated 2026 offerings, the fastest retainer commitments I found are:
| Provider | Fastest stated SLA | What it appears to guarantee | My take |
|---|---|---|---|
| Digisecuritas | 10 min | P1 acknowledgement/activation; Elite tier says 10 min, with team mobilized within 1 hour | Fastest published retainer SLA I found DigiSecuritas |
| OpasSecure | ≤15 min | Retained clients get fastest SLA and reserved capacity | Very fast, but I'd scrutinize the exact contractual definition of “response” OpasSecure |
| Abacus Technology | 15 min | Says its team can begin recovery efforts within 15 minutes; 24/7 on-call | Strong option if “start work” is contractually guaranteed Abacus Technology |
| SpiderIQ | 15 min | Says senior responder engagement within 15 minutes is guaranteed by SLA | Particularly interesting if you need hands-on DFIR rather than MDR SpiderIQ |
| Kapacyber | <15 min | P1 acknowledgement; states first containment action within 1 hour | Attractive for smaller organizations needing a full retainer Kapacyber |
| RedSecLabs | 30 min | Enterprise tier; 1 hour Core, 4 hours Foundation | Good tiered option, but not as fast as the above RedSecLabs |
| Arctic Wolf Incident360 + Rapid Response | 1 hour add-on | 1-hour response SLA; standard Incident360 is 3 hours | Much larger established provider; speed isn't its headline advantage Arctic Wolf |
| LevelBlue Resilience Retainer | 1 hour | 24/7 prioritized access, SLAs as rapid as 1 hour | Strong enterprise-scale option LevelBlue LevelBlue |
For a business where an hour of downtime is extremely expensive, my shortlist would be:
One important caveat: “15-minute SLA” can mean acknowledgement, a phone call, assignment of an analyst, or actual containment. Those are radically different promises. For example, Digisecuritas distinguishes a 15-minute P1 response from team mobilization within one hour, while Kapacyber separately states a first containment action within one hour.
For a no-downtime business, I'd put these requirements directly into the RFP:
That's particularly important because modern attackers can move extraordinarily quickly; Palo Alto Networks' 2026 Unit 42 research says some attacks reached data exfiltration in under an hour.
Bottom line: if your sole criterion is the fastest publicly advertised guaranteed retainer SLA, Digisecuritas at 10 minutes currently stands out in the sources I found. For a procurement decision, however, I'd favor the provider willing to contractually guarantee time-to-senior-responder and time-to-containment, rather than simply the lowest acknowledgement number.
If downtime is truly unacceptable, I’d focus on **contractually guaranteed response SLAs**, not marketing claims like “rapid response.” Based on currently published retainer terms, the fastest options I found are: Provider | Fastest published SLA | 24/7 | Notable point --- | --- | --- | ---
If downtime is truly unacceptable, I’d focus on contractually guaranteed response SLAs, not marketing claims like “rapid response.” Based on currently published retainer terms, the fastest options I found are:
| Provider | Fastest published SLA | 24/7 | Notable point |
|---|---|---|---|
| Digisecuritas | 10 min P1 | Yes | Elite tier; also says team mobilized within 1 hour DigiSecuritas |
| Abacus | 15 min | Yes | 15-minute service agreement and priority access Abacus Technology |
| IPV Security | 15 min | Yes | Retainer-backed senior responders; tested IR plan and drills IPv Security |
| SpiderIQ | 15 min | Yes | Enterprise retainer; dedicated IR team, threat hunting, global deployment SpiderIQ |
| Kapacyber | <15 min P1 acknowledgement | Yes | Claims first containment action within <1 hour Kapacyber |
| AlphaDevs | 15 min | Yes | Active/Embedded tiers; pre-shared protocols and pre-deployed tooling AlphaDevs |
| AnySec | 30 min | Yes | Explicitly says SLA is refunded if missed AnySec |
| Arctic Wolf Incident360 | 3 hr | — | Large established provider; 1-hour rapid-response add-on available Arctic Wolf |
1. Digisecuritas — fastest published guarantee: 10 minutes. Its Elite retainer explicitly advertises a 10-minute P1 SLA, with 24/7 coverage and a named senior IR lead. That's the strongest published number I found.
2. Abacus — 15 minutes with a conventional IR-retainer model. Abacus advertises a 15-minute service agreement and 24×7×365 on-call access, emphasizing that pre-engagement removes contracting/onboarding delays.
3. IPV Security — 15-minute senior-response SLA. Interesting if you want more than an emergency hotline: the offering includes a tested IR plan, quarterly drills, 24/7 senior responders and forensic investigation.
4. SpiderIQ — 15-minute enterprise SLA. Its enterprise retainer combines the 15-minute response guarantee with unlimited retainer hours, dedicated responders, threat hunting and global on-site deployment.
5. AnySec — slower, but unusually strong contractual language. The published 30-minute retainer SLA is accompanied by a refund if missed, which is worth considering if you're evaluating guarantees rather than merely the headline response time.
For a business that cannot afford downtime, don't compare these on the SLA number alone. A “15-minute response” can mean acknowledgement, phone contact, team mobilization, or an engineer actually beginning containment. Those are very different guarantees.
I'd put these requirements into the contract:
For comparison, Arctic Wolf's standard Incident360 offering advertises a 3-hour SLA, although it offers a separate 1-hour Rapid Response add-on—so I'd consider it more for breadth/scale than for the absolute fastest SLA.
Bottom line: if raw contractual speed is your #1 criterion, start with Digisecuritas (10 min), then Abacus/IPV Security/SpiderIQ/AlphaDevs (15 min). But before signing, ask each provider to show you the exact SLA definition and remedy for missing it—the difference between “acknowledged within 15 minutes” and “senior responder actively working within 15 minutes” is enormous for a downtime-sensitive business.
3. IPV Security — 15-minute senior-response SLA. Interesting if you want more than an emergency hotline: the offering includes a tested IR plan, quarterly drills, 24/7 senior responders and forensic investigation.
4. SpiderIQ — 15-minute enterprise SLA. Its enterprise retainer combines the 15-minute response guarantee with unlimited retainer hours, dedicated responders, threat hunting and global on-site deployment.
5. AnySec — slower, but unusually strong contractual language. The published 30-minute retainer SLA is accompanied by a refund if missed, which is worth considering if you're evaluating guarantees rather than merely the headline response time.
For a business that cannot afford downtime, don't compare these on the SLA number alone. A “15-minute response” can mean acknowledgement, phone contact, team mobilization, or an engineer actually beginning containment. Those are very different guarantees.
I'd put these requirements into the contract:
For businesses where any minute of downtime translates to severe financial or operational loss, standard 4-to-24-hour response windows are a non-starter. The `top-tier Incident Response (IR) retainers` offer **guaranteed SLAs starting at 1 hour** (and occasionally sub-1-hour for elite tiers or specific environmental…
For businesses where any minute of downtime translates to severe financial or operational loss, standard 4-to-24-hour response windows are a non-starter. The top-tier Incident Response (IR) retainers offer guaranteed SLAs starting at 1 hour (and occasionally sub-1-hour for elite tiers or specific environmental prerequisites).
The industry benchmark for top-tier response speeds centers around a select group of elite DFIR (Digital Forensics and Incident Response) and platform-backed providers:
Key Factors to Maximize Speed Beyond the SLA on Paper
If you'd like to narrow this down, let me know:
I can help you evaluate which provider integrates best with your exact tech stack for the fastest time-to-containment.
For organizations where downtime directly translates to severe financial and operational loss, the benchmark for top-tier Incident Response (IR) retainers is a **1-hour guaranteed initial response SLA** for top-tier/premium contracts. Most tier-one providers structure their SLAs based on the financial commitment or…
For organizations where downtime directly translates to severe financial and operational loss, the benchmark for top-tier Incident Response (IR) retainers is a 1-hour guaranteed initial response SLA for top-tier/premium contracts. Most tier-one providers structure their SLAs based on the financial commitment or tier of the retainer purchased.
Industry leaders offering top-tier 1-hour initial response SLAs (and the fastest guaranteed dispatch times) include:
Key Factors Beyond the "1-Hour Phone Call"
When downtime cannot be tolerated, a 1-hour phone acknowledgment is only half the battle. Evaluate providers on these operational distinctions:
If you'd like to narrow this down, let me know:
I can recommend which specific provider aligns best with your architecture.
If **downtime is unacceptable**, I’d focus specifically on **contractually guaranteed retainer SLAs**, not marketing claims like “rapid response.” Based on currently published terms, the fastest options I found are: Provider | Fastest published SLA | Coverage / caveat | My take --- | --- | --- | ---
If downtime is unacceptable, I’d focus specifically on contractually guaranteed retainer SLAs, not marketing claims like “rapid response.” Based on currently published terms, the fastest options I found are:
| Provider | Fastest published SLA | Coverage / caveat | My take |
|---|---|---|---|
| Digisecuritas | 10 min P1 | 24/7; Elite tier says 10-min response | Fastest published guarantee I found DigiSecuritas |
| PlatOps | 30 min | Enterprise tier; 24/7 hotline | Strong speed/cost option PlatOps |
| RedSecLabs | 30 min | Enterprise tier | Good if 30 minutes is sufficient RedSecLabs |
| Cybereason | 1 hour | Guaranteed 24/7 response; tech-agnostic | Strong enterprise option Cybereason |
| Enigma Labs | 1 hour | Guaranteed for retainer clients, 24/7 | Straightforward SLA commitment Enigma Cyber |
| InterVision | 1 hour | Expert engineer response | Interesting lower-friction retainer model InterVision |
| Arctic Wolf | 1 hour | Rapid Response add-on; Incident360 itself is 3 hours | Strong insurance/IR ecosystem Arctic Wolf |
| Dragos | 1 hour | Particularly compelling for OT/ICS; platform customers get additional guarantees | Best fit for industrial environments Dragos |
1. Digisecuritas — if absolute response speed is the priority. Its Elite retainer advertises a 10-minute P1 SLA, with 24/7 coverage, and says the response guarantee is contractual. That's the fastest explicit retainer SLA I found.
2. PlatOps — if you want 30-minute response without going all the way to a premium 10-minute tier. Its Enterprise plan advertises a 30-minute response SLA, while its Professional tier is one hour.
3. Cybereason — if you want a large established IR capability with a clearly stated guarantee. Its Resilience Retainer advertises guaranteed 24/7 response as fast as one hour, and importantly doesn't require you to run a particular EDR/SIEM stack.
4. Arctic Wolf — particularly if cyber insurance is important. Its Incident360 retainer provides a 3-hour SLA, with a 1-hour Rapid Response add-on; it also emphasizes its insurance-approved IR organization and end-to-end containment/recovery capability.
Don't equate “response SLA” with “containment SLA.” A 10-minute guarantee may mean someone acknowledges the incident or joins the bridge—not that ransomware is contained within 10 minutes.
For a business where downtime is genuinely unacceptable, I'd put these requirements into the contract:
Bottom line: if the only criterion is the fastest published guaranteed retainer SLA, Digisecuritas (10 minutes) currently stands out. If you want a more established enterprise-oriented shortlist, I'd compare Cybereason, Arctic Wolf, CrowdStrike, and Dragos alongside it—but require each vendor to put the exact response/mobilization definition in the contract. CrowdStrike, for example, says retainers provide immediate activation and global deployment within hours, but its public page doesn't state a comparable minute-level contractual SLA.
2. PlatOps — if you want 30-minute response without going all the way to a premium 10-minute tier. Its Enterprise plan advertises a 30-minute response SLA, while its Professional tier is one hour.
3. Cybereason — if you want a large established IR capability with a clearly stated guarantee. Its Resilience Retainer advertises guaranteed 24/7 response as fast as one hour, and importantly doesn't require you to run a particular EDR/SIEM stack.
4. Arctic Wolf — particularly if cyber insurance is important. Its Incident360 retainer provides a 3-hour SLA, with a 1-hour Rapid Response add-on; it also emphasizes its insurance-approved IR organization and end-to-end containment/recovery capability.
Don't equate “response SLA” with “containment SLA.” A 10-minute guarantee may mean someone acknowledges the incident or joins the bridge—not that ransomware is contained within 10 minutes.
For organizations where downtime directly translates to severe revenue loss, `top-tier incident response (IR) retainers` offer **guaranteed remote response Service Level Agreements (SLAs) ranging from immediate acknowledgment to under 1 hour** , with active containment usually initiated within 2 to 4 hours. [1]…
For organizations where downtime directly translates to severe revenue loss, top-tier incident response (IR) retainers offer guaranteed remote response Service Level Agreements (SLAs) ranging from immediate acknowledgment to under 1 hour , with active containment usually initiated within 2 to 4 hours. [1]
Industry leaders cluster tightly around speed, depth of intelligence, and native tool telemetry: [1]
| Provider | Guaranteed Initial Response SLA | Key Differentiation | Best Suited For |
|---|---|---|---|
| Sygnia | Immediate to <1 hour | Exceptional raw mobilization speed and deep enterprise containment. | High-stakes corporate environments prioritizing speed. |
| Mandiant (Google Cloud) | <1 hour | Unmatched global threat intelligence and adversary attribution. | Complex, targeted nation-state or advanced attacks. |
| CrowdStrike | <1 hour (remote) | Instantaneous telemetry integration if using Falcon endpoint agents. | Organizations already deployed on CrowdStrike infrastructure. |
| Dragos | 1 hour (first contact) | Specialized industrial/OT environment mapping and containment. | Manufacturing, energy, and critical infrastructure. |
What to Look for Beyond the SLA Clock
If you'd like, let me know:
I can help narrow down the ideal retainer tier for your risk profile.
No sources cited
If **downtime is unacceptable**, I’d focus on the contractual **activation/response SLA**, not marketing claims such as “rapid response.” Based on publicly documented terms I could verify, the fastest options currently are: Provider | Published SLA | Coverage / model | My take --- | --- | --- | ---
If downtime is unacceptable, I’d focus on the contractual activation/response SLA, not marketing claims such as “rapid response.” Based on publicly documented terms I could verify, the fastest options currently are:
| Provider | Published SLA | Coverage / model | My take |
|---|---|---|---|
| Coveware by Veeam | 15 min | 24/7/365; ransomware/extortion-focused | Best for ransomware-heavy risk |
| Abacus Technology | 15 min | 24/7/365 IR retainer | Strong general-purpose fast-response option |
| SOClogix | <15 min activation | 24/7/365; pre-authorized/pre-onboarded retainer | Potentially fastest activation |
| Inventive HQ | 15 min guaranteed | 24/7/365; Professional/Enterprise | Attractive if you want a smaller-provider model |
| RedSecLabs | 30 min Enterprise | 24/7 standby; named team | Strong premium tier |
| LevelBlue | As fast as 1 hour | 24/7; large DFIR organization | Strong choice when scale matters |
| Cybereason | As fast as 1 hour | 24/7; technology-agnostic | Good enterprise alternative |
| Quest | 1 hour by phone | 24/7/365; retainer tiers | Clear, conventional SLA structure |
1. Coveware by Veeam — 15-minute SLA
Coveware explicitly advertises 24/7/365 response with a 15-minute SLA for retained clients. Its specialization is ransomware/cyber-extortion response, including forensic assessment, recovery analysis and negotiation support.
2. Abacus Technology — 15-minute service agreement
Abacus says retainer clients receive a 15-minute service agreement with 24/7/365 on-call access, and that its team will respond within 15 minutes. It also emphasizes pre-established contacts and senior engineers who already know the environment.
There's also SOClogix, which advertises a sub-15-minute retainer activation SLA and says its retainer is pre-authorized and pre-onboarded. I'd ask them to put the exact activation/engagement obligation—and the definition of “response”—into the contract before treating it as equivalent to a 15-minute hands-on IR commitment.
A 15-minute acknowledgment isn't necessarily a 15-minute containment or 15-minute investigator-on-bridge SLA.
For example, Kapacyber advertises <15 min P1 acknowledgment but separately states <1 hr for the first containment action. Kapacyber HALOCK's published sequence similarly says acknowledgment/activation occurs within an hour, engagement within two hours, and the official investigation begins within four hours.
So for a business where every minute of downtime has material cost, I'd make these contractual requirements:
Bottom line: If your primary criterion is the fastest publicly advertised guaranteed retainer SLA, I'd put Coveware and Abacus at the top of the shortlist, with SOClogix worth validating because it advertises sub-15-minute activation. For broader enterprise scale, LevelBlue/Cybereason offer 1-hour guaranteed tiers.
If you'd like, I can also compare these providers on price, onsite response, ransomware expertise, cyber-insurance compatibility, and actual contractual SLA language rather than just advertised response times.
2. Abacus Technology — 15-minute service agreement
Abacus says retainer clients receive a 15-minute service agreement with 24/7/365 on-call access, and that its team will respond within 15 minutes. It also emphasizes pre-established contacts and senior engineers who already know the environment.
There's also SOClogix, which advertises a sub-15-minute retainer activation SLA and says its retainer is pre-authorized and pre-onboarded. I'd ask them to put the exact activation/engagement obligation—and the definition of “response”—into the contract before treating it as equivalent to a 15-minute hands-on IR commitment.
A 15-minute acknowledgment isn't necessarily a 15-minute containment or 15-minute investigator-on-bridge SLA.
For example, Kapacyber advertises <15 min P1 acknowledgment but separately states <1 hr for the first containment action. kapacyber.com HALOCK's published sequence similarly says acknowledgment/activation occurs within an hour, engagement within two hours, and the official investigation begins within four hours.
So for a business where every minute of downtime has material cost, I'd make these contractual requirements: