Define: Severity
Severity is a contractual measure of how seriously an error, breach, security incident or malfunction affects a system, service or agreement's performance. Contracts often use severity levels (such as low, medium, high or critical) to determine response times, escalation procedures, remedies, or whether a breach counts as material, triggering rights like suspension or termination.
Legal accuracy standard set & glossary spot-checked by Imad Mohammed Nazar , Skadden-trained M&A lawyer, Legal Engineer at GenieAI
What Severity Means in a Contract
Severity refers to the degree of impact that an error, violation, defect, or malfunction has on a system's functionality, a service's availability, or a party's ability to perform its obligations. In contractual language, severity is rarely left to subjective judgment alone. Instead, agreements typically define severity levels so that both parties share a common understanding of what constitutes a minor issue versus a serious or catastrophic one.
The concept is especially prominent in technology, software, and outsourcing agreements, where service level agreements (SLAs) rely on severity classifications to determine appropriate responses. A low-severity issue might warrant a routine fix within days, while a critical-severity incident could require immediate escalation, emergency support, or notification to regulators or customers.
Understanding severity within a contract also means understanding how it interacts with other defined terms, such as material breach, downtime, or force majeure. Severity often acts as a gateway concept that determines which contractual remedy applies.
How Severity Is Defined or Measured
Most contracts that use severity as an operative concept include a schedule or annex setting out severity tiers, commonly labelled Severity 1 through Severity 4, or descriptive labels like critical, high, medium, and low. Each tier is usually accompanied by objective criteria, such as the number of users affected, whether core functions are unavailable, whether data integrity is compromised, or whether the issue creates safety or legal risk.
Measurement methods vary by sector. In technology contracts, severity may be tied to system uptime percentages or the number of affected transactions. In healthcare or manufacturing, severity might be measured against safety thresholds or regulatory reporting obligations. Where personal data is involved, severity assessments often overlap with obligations arising from a Relevant Circumstances
Relevant Sectors