Guides · Template · 8 min read
A business continuity plan that fits on two pages
A copy-and-fill continuity plan template for a 50 to 500-person company: critical activities, maximum tolerable downtime, the call list, four scenario sheets, and the review rhythm that keeps it from going stale. Mapped to ISO 22301 and NIS2 Article 21(2)(c).
Published 10 September 2026
Most continuity plans fail for the same reason: they are too long to be read on the worst day of the company's life. Forty pages of scope, governance and appendices, written once by someone who has since left, stored on the file server that is currently encrypted.
A plan that works is two pages, printed, and known to exist. Everything below is what earns a place on those pages. What follows is the template we would hand a 60-person logistics company, and it satisfies NIS2 Article 21(2)(c) and the operational core of ISO 22301 without a consulting project.
Page one, block 1 — the four activities you cannot stop
Not departments. Activities, in the words your staff use. For each, three figures and one name.
| Activity | Max tolerable downtime | Depends on | Owner |
|---|---|---|---|
| Take and confirm customer orders | 4 hours | ERP, email, one phone line | Name, mobile |
| Dispatch and deliver | 1 day | TMS, drivers, fuel card | Name, mobile |
| Invoice and collect | 3 days | ERP, accounting, bank access | Name, mobile |
| Pay staff and suppliers | 5 days | Bank access, payroll | Name, mobile |
Four rows is a constraint, not a simplification. If everything is critical, nothing gets restored first, and the argument about priority happens during the outage instead of before it. Maximum tolerable downtime is the figure that makes the plan real: it is what tells you whether a two-day restore is acceptable or a business-ending event.
Page one, block 2 — the call list
One table, printed, on paper, held by at least three people at home. Mobile numbers, not extensions. Personal email addresses as a fallback, because corporate email is the thing most likely to be unavailable.
- Who declares a crisis and runs it, plus their deputy. One name each, no committees.
- IT provider: contract number, out-of-hours number, the escalation name.
- Cyber and property insurer: policy number, 24/7 claims line, notification deadline in hours.
- Bank: relationship manager and the fraud line.
- Authority: national CSIRT or competent authority, and the data protection authority.
- The three clients who must be called personally, and by whom.
- Whoever is allowed to speak publicly — exactly one person, named.
Page one, block 3 — the fallbacks, in one line each
- If the main system is down, we operate on: (the paper form, the spreadsheet, the phone).
- If the premises are unusable, we work from: (address, or explicitly from home).
- If email is down, we reach each other on: (channel, off the corporate identity).
- Backups live at: (location, offline or immutable copy), last successful restore test: (date).
- Cash: we can meet payroll for (number) weeks without new receipts.
Page two — four scenario sheets, six lines each
Four scenarios cover the overwhelming majority of what actually stops mid-sized companies. Each gets six lines: first move, who is called, what we tell clients, what we operate on meanwhile, what tells us it is over, and where the timeline is recorded.
- 01Cyberattack or ransomware. First move: isolate, do not reboot, disconnect backups. The 24-hour and 72-hour reporting clocks start when you become aware.
- 02Cash crunch — a major client pays 30 days late or fails. First move: 13-week cash view, freeze non-essential commitments, call the bank before you need it, and stage supplier conversations in order of leverage.
- 03Supplier or logistics failure. First move: name the single-source dependency, activate the pre-identified alternative, tell affected clients before they notice.
- 04Key person unavailable. First move: open the documentation for their two critical processes — which is why those two processes must be written down while the person is still here.
What makes it survive contact with reality
Three habits, and they are the whole difference between a plan and a document.
- It is printed, and three people have it at home. A plan reachable only through the systems it protects is not a plan.
- It has a review date on its face, six months out, with an owner. ISO 22301 calls this the management review; in practice it is a calendar entry that somebody honours.
- It gets rehearsed once. Ninety minutes, one scenario, the real people, timed, and the outcome written down with a date. The rehearsal is what converts the plan from theory into memory — and it is the artefact an insurer, a client or an auditor actually asks to see.
Where this maps, if someone asks
| Block | ISO 22301 | NIS2 Article 21(2) |
|---|---|---|
| Critical activities and downtime | Clause 8.2, business impact analysis | (a) risk analysis |
| Call list and who declares | Clause 8.4.2, incident response structure | (b) incident handling |
| Fallbacks and backups | Clause 8.4.4, continuity and recovery | (c) continuity, backup, disaster recovery |
| Supplier dependency | Clause 8.2.2, supply chain | (d) supply chain security |
| Rehearsal and review date | Clause 8.5, exercising and testing | (f) effectiveness assessment |
That is the whole plan. Two pages, five references, no binder. The hard part was never the writing — it is knowing which of the lines above are currently blank, and keeping score.
Your reading
Fifteen questions. A score out of 100, and the three exposures costing you the most points.
A plan nobody scores decays quietly. The Diagnostic puts a number on the gap between the plan you have written and the plan you could actually run.