Glossary · Term

Business continuity explained

Business continuity is the ability of an organisation to stay able to act through disruption and to keep its critical processes running.

At a glance
Meaning
Keeping the business running through disruption
Aim
Stay able to act, keep critical processes going
Tools
BCP, BCMS, DRP, backups
Link to NIS2
Resilience is a core aim
Updated
June 2026
Editorial team
Compliance Compass

What is business continuity?

Business continuity is the umbrella term for the ability of an organisation to carry on working through larger disruptions – a cyberattack, a power cut, the loss of a data centre or of an important service provider – and to keep its critical business processes running, or get them running again, within an acceptable time. Where individual contingency documents set out concrete procedures, business continuity describes the overarching aim: that the organisation stays able to act throughout. At its centre sits the question of which processes are so important that their failure would be existential, and how long a standstill can be tolerated at most.

The building blocks

Business continuity is not achieved through a single tool but through several building blocks working together, each with a job of its own:

Keeping the terms apart: the cluster at a glance

The five terms are often mixed up in daily use, even though each sits at a different altitude. The table below sorts them by focus and by the standard they relate to. In short: business continuity is the roof, and everything else works underneath it.

TermFocusRelated standard
Business continuityOverall aim: the whole organisation stays able to actISO 22301 (framework)
BCPOperational contingency plan: who does what when a process fails?ISO 22301, clause 8.4
BCMSManagement system: keeps plans current, tested and auditableISO 22301 (certifiable standard)
DRPTechnical IT recovery: systems, networks, dataISO/IEC 27031 (ICT readiness)
RecoveryThe concrete return of a system or data set to its intended stateISO/IEC 27031, backup requirements

Exercise, do not just plan

Plans that sit unread in a drawer help little when it matters. What counts are regular tests, emergency exercises and realistic scenarios – so that in a crisis every person knows their role and procedures hold up under pressure. Anyone who follows the all-hazards idea through exercises not only the cyberattack, but also power and supplier failures.

An example makes this tangible. At a mid-sized machinery manufacturer, ransomware encrypts the ERP system overnight; because a BCP exists that has been rehearsed several times, production switches in the morning, without long hesitation, to predefined emergency procedures on paper travellers, while the crisis team informs customers in parallel, notifies the competent authority within the NIS2 reporting chain, and the DRP restores the ERP from verified, network-isolated offline backups. The ability to deliver is preserved. That difference – hours instead of days – is often what decides, for a supplier, between contractual penalties and staying in the supplier pool.

Business continuity and NIS2

Resilience is not a nice-to-have but a duty. Article 21(2)(c) of the NIS2 Directive names business continuity, backup management, disaster recovery and crisis management expressly among the mandatory risk management measures; the directive has applied since 18 October 2024. What matters just as much is Article 20: the management body does not merely approve the measures, it has to oversee their implementation and can be held personally responsible – the point that turns business continuity from an IT topic into a board topic. If a notifiable disruption occurs, the staged reporting chain applies: an early warning within 24 hours, a fuller notification after 72 hours and a final report within one month. Article 34 sets minimum ceilings for fines of EUR 10 million or 2 % of total worldwide annual turnover for essential entities and EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts.

Registration itself is organised nationally: which body you register with, in what form and by which date follows from the law of the Member State in which you are established, not from the directive. In several Member States the first deadline has already passed, and a deadline that has expired does not remove the obligation.

What you actually have to do

Frequently asked questions

What does business continuity mean?

Business continuity is the ability of an organisation to stay able to act through larger disruptions such as a cyberattack, a power cut or the loss of a data centre, and to keep its critical business processes running, or get them running again, within an acceptable time. It is the overarching aim under which individual contingency plans and the management of restart times work together. The framework is described in the standard ISO 22301.

Which tools belong to business continuity?

The main ones are the BCP as the operational contingency plan for the business, the BCMS as the steering management system along ISO 22301, and the DRP for the technical recovery of IT systems and data. These building blocks are rounded out by regularly tested offline backups, rehearsed crisis roles and a business impact analysis that sets out how long each process may be down before the loss becomes existential.

Why does business continuity matter for NIS2?

Article 21(2)(c) of the NIS2 Directive names business continuity, backup management, disaster recovery and crisis management expressly among the mandatory risk management measures, and Article 20 puts the management body personally on the hook for approving them and overseeing their implementation. The directive has applied since 18 October 2024. For a notifiable disruption the reporting chain runs to a 24-hour early warning, a 72-hour notification and a final report within one month. Article 34 sets a minimum ceiling for fines of EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and Member States may set higher amounts.

Further reading: ISO 22301 – business continuity management systems (standard overview)

Resilience

How long would your operation survive an outage?

With Compliance Compass you set the tolerable downtime for each process, link BCP, BCMS and DRP, and keep the business impact analysis, exercise dates and NIS2 reporting deadlines in one place.