Glossary · Term

BCP explained

A BCP (business continuity plan) is the contingency plan that keeps the business running through disruption or outage.

At a glance
Meaning
Business continuity plan (contingency plan)
Purpose
Keep the business running through disruption
Contents
Critical processes, roles, restart
Related
BCMS, DRP
Updated
June 2026
Editorial team
Compliance Compass

What is a BCP?

The business continuity plan is the operational heart of contingency planning: a concrete, documented script for how an organisation keeps its most important processes going through larger disruptions – a cyberattack, a power cut, the loss of a data centre or of a key supplier. Where Business continuity describes the overarching aim, the BCP translates that aim into concrete instructions: it sets out who does what in which order, which fallback arrangements are switched to, and how communication runs until normal operations return.

What a BCP contains

A robust BCP rests on a business impact analysis carried out beforehand and typically contains the following parts:

An example: at a regional energy supplier the central billing system fails after a cyberattack. The BCP takes effect at once: the call centre switches to predefined manual procedures, a named emergency coordinator prioritises recovery, and the communication templates for customers and for the competent authority are ready to hand. The supplier stays able to act instead of improvising in the middle of chaos.

BCP, DRP and BCMS

The BCP is part of a larger system: the BCMS steers contingency planning at the higher level and keeps the plans current, while the DRP handles the technical side: Recovery of IT systems and data. The BCP is therefore wider than the DRP, but more concrete than the BCMS.

BCP and NIS2

Article 21(2)(c) of the NIS2 Directive requires measures for business continuity, backup management, disaster recovery and crisis management; the directive has applied since 18 October 2024. A tested and regularly exercised BCP is the practical core of that – and important evidence if a supervisory authority examines your resilience. Article 34 sets a minimum ceiling for fines of EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and Member States may set higher amounts.

Further reading: ISO 22301 – the international standard for business continuity management

Frequently asked questions

What is a business continuity plan?

A business continuity plan (BCP) is a concrete, documented contingency plan that keeps critical business processes running through disruptions such as a cyberattack, a power cut or the loss of a data centre. It sets out who does what in which order, which fallback arrangements are switched to, and how communication runs until normal operations return. The BCP rests on a business impact analysis of the most important processes, carried out beforehand.

What is the difference between a BCP and a DRP?

The BCP secures the business as a whole, including people, sites and processes, while the DRP (disaster recovery plan) covers the technical recovery of IT systems and data specifically. The DRP is therefore a sub-plan within the broader business continuity planning. The BCP is thus wider in scope than the DRP, but more concrete than the overarching BCMS.

Does NIS2 require a BCP?

Article 21(2)(c) of the NIS2 Directive requires measures for business continuity, backup management, disaster recovery and crisis management, but it names no BCP as such; the directive has applied since 18 October 2024. In practice a tested business continuity plan is the usual and demonstrable way to meet those duties. Article 34 sets a minimum ceiling for fines of EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and Member States may set higher amounts.

Resilience

Have a plan before it happens

Compliance Compass supports contingency planning and the evidence for it – so that critical processes never come to a stop.