Auditen
Home / Frameworks / NIS2 / Business continuity and crisis management
NIS2 · Art. 21(2)(c)

Business continuity and crisis management

Business continuity and crisis management require organizations to ensure that essential services can be maintained or quickly restored following a significant cyber incident. This involves implementing technical recovery capabilities—such as backups—and organizational frameworks for managing disruptions and communicating during a crisis.

What it means

The intent is resilience rather than just prevention. While other NIS2 controls focus on stopping attacks, this requirement assumes that a failure will eventually occur and demands a structured plan to survive it with minimal impact on the delivery of essential services.

In practice, this covers two distinct but related areas: technical recovery (disaster recovery) and organizational response (crisis management). Technical recovery focuses on data integrity and system availability, while crisis management focuses on decision-making, personnel coordination, and external communication.

The scope is centered on "essential" functions. Organizations must identify which processes are critical to their operations and prioritize those for continuity planning, rather than attempting to apply the same recovery rigor to every non-critical internal system.

How to meet it

Evidence an auditor asks for

  • Copies of the current BCP/DRP documentation and the associated Business Impact Analysis.
  • Logs showing successful backup completions and records of periodic restoration tests (proving backups actually work).
  • Reports from recent crisis simulation exercises, including "lessons learned" and evidence that plans were updated based on those results.
  • A documented Crisis Management Team directory with contact details and defined escalation paths.

Common pitfalls

  • "Paper Compliance": Maintaining a detailed plan that has never been tested or is too generic to be actionable during a real emergency.
  • Confusing backups with recovery: Assuming that having data backups is the same as having a recovery process; without an orchestration plan, restoring terabytes of data can take longer than the RTO allows.
  • Ignoring dependencies: Failing to account for third-party vendors or cloud providers in the continuity plan, leaving a gap when a critical external service fails.