Business Continuity Plan
A Business Continuity Plan (BCP) is a documented set of procedures that describes how an organization will keep its essential operations running, or restore them quickly, when faced with a major disruption such as a cyber attack, flood, or supply chain failure. Its purpose is to sustain mission-critical services and processes during and after an incident. A BCP is a planning and preparedness tool rather than a legal requirement in itself, though specific laws, contracts, or standards may require organizations in certain sectors to maintain one.
A Business Continuity Plan is the documentation of a predetermined set of instructions or procedures describing how an organization's mission/business processes will be sustained, and how critical services or processes are maintained, restored, or recovered, following a disruptive event. It functions as an organization-wide strategic framework addressing the safeguards and recovery procedures needed to continue essential operations under adverse conditions such as cyber attacks, natural events, or supply chain failures. A BCP should be distinguished from narrower recovery constructs (for example, a disaster recovery plan focused on IT systems) as it addresses business processes at large; scope, triggers, and required elements vary by organization, sector, and any applicable contractual or regulatory obligations. Where a BCP is mandated, the specific requirements derive from the governing law, standard, or agreement rather than from the concept itself, and readers should verify obligations against the current authoritative source applicable to their jurisdiction and sector.
Why it matters
A major disruption — whether a cyber attack, a flood, or a supply chain failure — can halt the delivery of an organization's essential services with little warning. A Business Continuity Plan matters because it moves an organization from ad hoc, reactive responses toward a predetermined set of procedures for sustaining or quickly restoring mission-critical operations. Without such planning, organizations generally face longer outages, greater uncertainty about roles and priorities during a crisis, and slower recovery of the processes their customers, patients, or stakeholders depend on.
The BCP is also significant because of what it is not. It is a preparedness and planning instrument, not a legal obligation in its own right. Depending on the sector and jurisdiction, specific laws, contracts, or voluntary standards may require an organization to maintain a continuity capability, but the concept of a BCP itself carries no inherent legal force. Where an obligation does exist, the required scope and content flow from the governing rule or agreement rather than from the general idea of continuity planning. Compliance teams should therefore treat the plan both as an operational resilience tool and as a possible point of intersection with contractual or regulatory requirements.
Because disruption scenarios and applicable requirements differ widely by organization and sector, the value of a BCP depends heavily on how well its assumptions, triggers, and priorities match the organization's actual risk profile. A plan that identifies the right mission-critical processes and realistic recovery steps supports resilience; one that is generic or untested may offer limited protection when an incident occurs.
Who it's relevant to
Inside BCP
Common questions
Answers to the questions practitioners most commonly ask about BCP.

