- Meaning
- Keeping the business running through disruption
- Aim
- Stay able to act, keep critical processes going
- Tools
- BCP, BCMS, DRP, backups
- Link to NIS2
- Resilience is a core aim
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is business continuity?
Business continuity is the umbrella term for the ability of an organisation to carry on working through larger disruptions – a cyberattack, a power cut, the loss of a data centre or of an important service provider – and to keep its critical business processes running, or get them running again, within an acceptable time. Where individual contingency documents set out concrete procedures, business continuity describes the overarching aim: that the organisation stays able to act throughout. At its centre sits the question of which processes are so important that their failure would be existential, and how long a standstill can be tolerated at most.
The building blocks
Business continuity is not achieved through a single tool but through several building blocks working together, each with a job of its own:
- BCP: the concrete, operational contingency plan for the business.
- BCMS: the overarching management system that keeps contingency plans current, tested and effective.
- DRP: the technical plan for Recovery of IT systems and data.
- Crisis management: steering and communication at leadership level.
Keeping the terms apart: the cluster at a glance
The five terms are often mixed up in daily use, even though each sits at a different altitude. The table below sorts them by focus and by the standard they relate to. In short: business continuity is the roof, and everything else works underneath it.
| Term | Focus | Related standard |
|---|---|---|
| Business continuity | Overall aim: the whole organisation stays able to act | ISO 22301 (framework) |
| BCP | Operational contingency plan: who does what when a process fails? | ISO 22301, clause 8.4 |
| BCMS | Management system: keeps plans current, tested and auditable | ISO 22301 (certifiable standard) |
| DRP | Technical IT recovery: systems, networks, data | ISO/IEC 27031 (ICT readiness) |
| Recovery | The concrete return of a system or data set to its intended state | ISO/IEC 27031, backup requirements |
Exercise, do not just plan
Plans that sit unread in a drawer help little when it matters. What counts are regular tests, emergency exercises and realistic scenarios – so that in a crisis every person knows their role and procedures hold up under pressure. Anyone who follows the all-hazards idea through exercises not only the cyberattack, but also power and supplier failures.
An example makes this tangible. At a mid-sized machinery manufacturer, ransomware encrypts the ERP system overnight; because a BCP exists that has been rehearsed several times, production switches in the morning, without long hesitation, to predefined emergency procedures on paper travellers, while the crisis team informs customers in parallel, notifies the competent authority within the NIS2 reporting chain, and the DRP restores the ERP from verified, network-isolated offline backups. The ability to deliver is preserved. That difference – hours instead of days – is often what decides, for a supplier, between contractual penalties and staying in the supplier pool.
Business continuity and NIS2
Resilience is not a nice-to-have but a duty. Article 21(2)(c) of the NIS2 Directive names business continuity, backup management, disaster recovery and crisis management expressly among the mandatory risk management measures; the directive has applied since 18 October 2024. What matters just as much is Article 20: the management body does not merely approve the measures, it has to oversee their implementation and can be held personally responsible – the point that turns business continuity from an IT topic into a board topic. If a notifiable disruption occurs, the staged reporting chain applies: an early warning within 24 hours, a fuller notification after 72 hours and a final report within one month. Article 34 sets minimum ceilings for fines of EUR 10 million or 2 % of total worldwide annual turnover for essential entities and EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts.
Registration itself is organised nationally: which body you register with, in what form and by which date follows from the law of the Member State in which you are established, not from the directive. In several Member States the first deadline has already passed, and a deadline that has expired does not remove the obligation.
What you actually have to do
- Identify the critical business processes and set the maximum tolerable downtime for each of them in a business impact analysis.
- Put the BCP, the DRP and the crisis roles in writing, and exercise them realistically at least once a year.
- Set up offline and immutable backups, and test the restore regularly – not just the backup run.
- Build the 24 and 72-hour reporting chain into the contingency plan, including a named contact for the authority designated in your Member State.
- Document the evidence in audit-proof form – exercise records, test reports, management approvals – and if you have not yet registered with the body designated in your country, start that now.
Frequently asked questions
What does business continuity mean?
Business continuity is the ability of an organisation to stay able to act through larger disruptions such as a cyberattack, a power cut or the loss of a data centre, and to keep its critical business processes running, or get them running again, within an acceptable time. It is the overarching aim under which individual contingency plans and the management of restart times work together. The framework is described in the standard ISO 22301.
Which tools belong to business continuity?
The main ones are the BCP as the operational contingency plan for the business, the BCMS as the steering management system along ISO 22301, and the DRP for the technical recovery of IT systems and data. These building blocks are rounded out by regularly tested offline backups, rehearsed crisis roles and a business impact analysis that sets out how long each process may be down before the loss becomes existential.
Why does business continuity matter for NIS2?
Article 21(2)(c) of the NIS2 Directive names business continuity, backup management, disaster recovery and crisis management expressly among the mandatory risk management measures, and Article 20 puts the management body personally on the hook for approving them and overseeing their implementation. The directive has applied since 18 October 2024. For a notifiable disruption the reporting chain runs to a 24-hour early warning, a 72-hour notification and a final report within one month. Article 34 sets a minimum ceiling for fines of EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and Member States may set higher amounts.
Further reading: ISO 22301 – business continuity management systems (standard overview)