This article gives you a ready-to-use, annotated Business Continuity Plan (BCP) example you can copy and adapt now. The full sample plan appears in Section 3. Before you scroll there, here are three immediate next steps to put it to work:
- Assign a plan owner today. Name one person accountable for the BCP, its testing schedule, and its annual review. Without a named owner, the plan stalls.
- Run a focused Business Impact Analysis on your top three functions within two weeks. Use the sample BIA table in Section 4 as your starting point. Three functions are enough to reveal your most critical recovery priorities.
- Schedule a tabletop exercise within 30 days. A 90-minute tabletop with department heads exposes gaps faster than any document review.
The sample plan below follows the structure recommended by FEMA's Non-Federal Continuity Plan Template and is annotated throughout so you know exactly what to replace for your organization.
Table of Contents
- What is a Business Continuity Plan, and how does it differ from an Emergency Response Plan?
- A complete, copyable continuity plan example you can adapt now
- How to conduct a Business Impact Analysis and use the sample BIA table
- What recovery strategies should you map to each business function?
- How should you communicate during a business continuity incident?
- How do activation thresholds and command structures work in practice?
- How often should you test, exercise, and update your BCP?
- What appendices and operational checklists should your BCP include?
- How do you adapt this BCP example for your organization and get it live?
- When should you bring in a vCISO or continuity consultant?
- Key Takeaways
- The case for exercise-first continuity planning
- CisoSafe helps you build and test a BCP that actually works
- Authoritative U.S. resources and templates for continuity planning
What is a Business Continuity Plan, and how does it differ from an Emergency Response Plan?
A Business Continuity Plan is an organizational roadmap for maintaining essential operations during and after a disruption. It covers longer-term recovery: restoring systems, activating workarounds, and keeping revenue-generating and compliance-critical functions running. An Emergency Response Plan (ERP), by contrast, governs the first minutes and hours of an incident, focusing on life safety, evacuation, and first-responder coordination.
Ready.gov defines the BCP as the document that keeps the business running, while the ERP gets people out safely. Conflating the two is a common planning mistake. A law firm that treats its evacuation procedures as its entire continuity program has no plan for what happens on day three of a ransomware attack.
| Dimension | Business Continuity Plan (BCP) | Emergency Response Plan (ERP) |
|---|---|---|
| Primary focus | Operational continuity and recovery | Life safety and immediate incident response |
| Time horizon | Hours to weeks post-disruption | First minutes to hours of an incident |
| Primary owner | Operations, IT, or compliance leadership | Facilities, safety officer, or HR |
| Typical contents | BIA, recovery strategies, RTO/RPO, communications, delegations | Evacuation routes, warden assignments, first-responder contacts |
| Regulatory reference | FEMA CGC, NIST, SOC 2, HIPAA | OSHA Emergency Action Plan guidelines |
| Testing cadence | Annually at minimum; tabletop plus technical drills | Evacuation drills per OSHA requirements |
OSHA's Emergency Action Plan guidance specifies minimum ERP elements: evacuation procedures, designated wardens, employee accounting methods, and rescue duty assignments. Those elements belong in your ERP or as a BCP appendix, not in the body of the continuity plan itself. Keeping them separate prevents the BCP from becoming an unmanageable document that no one reads under pressure.
Industry guidance recommends testing your BCP at least annually, using a mix of tabletop exercises, technical restore drills, and full-scale simulations to identify gaps before a real disruption does.
A complete, copyable continuity plan example you can adapt now
The following is a filled, annotated BCP. Italicized annotations tell you what to replace. This structure follows the canonical headings from FEMA's Non-Federal Continuity Plan Template and incorporates practical examples drawn from the City of Boston's Business Continuity Plan Template.
Executive summary
[Organization Name] maintains this Business Continuity Plan to protect its ability to deliver [core services or products] during and after any significant disruption. This plan applies to all departments and activates when a disruption meets the thresholds defined in Section 7. The plan owner is [Name, Title], who is responsible for annual review, testing, and updates.
Purpose and scope
Purpose: To define the procedures, roles, and resources required to sustain [Organization Name]'s critical functions during a disruption lasting more than [4 hours / 24 hours — choose your threshold].
Scope: This plan covers all business units operating from [primary location(s)] and any remote workforce. It does not replace the Emergency Response Plan, which governs immediate life-safety actions.
Out of scope: Routine IT helpdesk incidents, minor service degradations below activation thresholds, and personal safety emergencies covered by the ERP.
Leadership, roles, and delegations of authority
| Role | Name | Backup | Authority |
|---|---|---|---|
| Crisis Management Team Lead | [Name] | [Backup Name] | Declares activation; authorizes emergency spend up to [$X] |
| IT Recovery Lead | [Name] | [Backup Name] | Initiates system failover; approves vendor escalation |
| Communications Lead | [Name] | [Backup Name] | Approves all external messaging |
| Facilities Lead | [Name] | [Backup Name] | Activates alternate site; manages access controls |
| Finance Lead | [Name] | [Backup Name] | Releases emergency funds; coordinates insurance notification |
Replace names and dollar thresholds. Document this table in a signed delegation-of-authority memo kept with the plan and in your secure cloud copy.
Recovery priorities and strategies
Recovery follows this priority sequence: life safety → critical IT systems → client-facing operations → internal support functions → non-critical administrative tasks.
IT: Primary recovery via cloud backup restoration to [cloud provider]. Hot-standby for payment systems; cold-site failover for internal file servers. Restore verification tested quarterly.
Workforce: Telework activated for all roles with VPN access. Cross-trained backups for [critical roles]. Succession documented in Appendix B.
Facilities: Alternate work site at [address]. Access credentials pre-provisioned. Vendor contact for site activation: [Name, phone].
Vendors: Critical vendors listed in Appendix C with contractual continuity clauses. Secondary suppliers identified for [top 3 vendor categories].
Finance: Emergency operating fund of [$X] pre-authorized. Insurance carrier notified within [24/48 hours] of activation. CFO or designee authorizes emergency procurement.
Communications
All external communications require approval from the Communications Lead before release. Internal notifications use [Slack / Teams / mass SMS platform]. A status page at [URL] is updated every [2 hours] during an active incident.
Activation rules
The plan activates when any of the following thresholds are met (see Section 7 for full criteria):
- Critical payment systems unavailable for more than 4 hours
- Confirmed data breach with evidence of exfiltration
- Facility inaccessible for more than 24 hours
- Key personnel loss affecting a significant portion of a critical function
Revision history
| Version | Date | Author | Summary of Changes |
|---|---|---|---|
| — | [Date] | [Name] | Initial plan creation |
| — | [Date] | [Name] | Updated vendor contacts; revised RTO for payment systems |
Update this table after every exercise, after any personnel change affecting the command structure, and after any major system change.
Pro Tip: The Smartsheet IC Business Continuity Plan Template provides a formatted Word/PDF version of this structure. Download it, paste your organization's details into the annotated fields, and you have a working draft in under two hours.
How to conduct a Business Impact Analysis and use the sample BIA table
The BIA is the analytical foundation of every effective BCP. It identifies which functions are critical, what happens financially and operationally if they fail, and how quickly they must be restored. RTO (Recovery Time Objective) defines the maximum tolerable downtime for a function. RPO (Recovery Point Objective) defines the maximum acceptable data loss, measured in time. Those two values drive every technology and staffing decision in your recovery strategy.

Sample BIA data table
| Business Function | RTO | RPO | Criticality | Function Owner | Key Dependencies |
|---|---|---|---|---|---|
| Payment processing | 4 hours | 1 hour | High | CFO | Payment gateway, banking API, ERP system |
| Client data access | 8 hours | 4 hours | High | IT Director | File server, VPN, Active Directory |
| Regulatory reporting | 24 hours | 24 hours | High | Compliance Officer | Reporting platform, audit logs |
| HR and payroll | 48 hours | 24 hours | Medium | HR Director | HRIS platform, payroll vendor |
| Internal communications | 8 hours | N/A | Medium | IT Director | Email server, messaging platform |
| Marketing and web | 72 hours | 48 hours | Low | Marketing Manager | CMS, hosting provider |
Populate this table with your actual functions. Add rows for every function that, if disrupted, would trigger a regulatory obligation, a client contract penalty, or a revenue loss your organization cannot absorb within 72 hours.
What recovery strategies should you map to each business function?
Recovery strategies must align directly to BIA outputs. Selecting a strategy that cannot meet your stated RTO is not a strategy; it is a gap. BCM Institute's guidance on continuity strategy is explicit: strategy selection is only valid when it demonstrably supports the recovery objectives identified in the BIA.
Workforce recovery
- Activate telework for all VPN-enabled roles within 2 hours of plan activation.
- Cross-train at least one backup for every critical-function role. Document cross-training completion in personnel files.
- Succession plan: if the primary function owner is unavailable, the named backup assumes authority automatically per the delegation memo.
Facilities recovery
- Pre-negotiate an alternate work site agreement. Confirm access credentials are current every six months.
- Maintain a physical access kit (keys, badge codes, generator fuel contacts) at a secure off-site location.
- Vendor contact for site activation must be reachable 24/7; verify this annually.
Vendor and supply chain recovery
- Include continuity clauses in all critical vendor contracts: require vendors to provide their own BCP on request and to notify you within [4/8/24 hours] of any disruption affecting your services.
- Identify a secondary supplier for each of your top five vendor categories. Document contact information in Appendix C.
- Run an annual vendor cybersecurity assessment to confirm your critical suppliers' recovery capabilities match your RTO requirements.
Finance recovery
- Pre-authorize an emergency operating fund sufficient to cover [30/60/90 days] of critical operating costs.
- Document insurance policy numbers, carrier contacts, and claim-filing procedures in Appendix C.
- Establish a secondary banking relationship so payment operations can continue if your primary bank's systems are unavailable.
Pro Tip: Technology choices must be validated against your RTO, not assumed. If your cloud backup provider promises a 4-hour restore but you have never tested it, your actual RTO is unknown. Run a full restore from offsite backups into an isolated environment at least once per year and record the actual elapsed time. That number is your real RTO baseline.
How should you communicate during a business continuity incident?
Consistent, timely communication preserves stakeholder trust and reduces operational confusion. Pre-approved templates and a single status page eliminate the delays caused by drafting messages under pressure. The FEMA Continuity Guidance Circular treats communications as a core continuity capability, not an afterthought.
Notification sequence
- Hour 2: — Communications Lead posts first customer status update (Template B below) and updates the status page.
Template A: Employee notification
Subject: [ORGANIZATION NAME] Business Continuity Plan Activated
Team, we have activated our Business Continuity Plan due to [brief description of disruption]. Your department recovery lead will contact you within the next 60 minutes with specific instructions. If you have not heard from your lead by [time], contact [backup contact name and number]. Our status page is live at [URL]. Continue to monitor it for updates every two hours.
Template B: Customer status update
Subject: Service Update from [Organization Name]
We are currently experiencing [brief, non-technical description of disruption] affecting [specific service(s)]. Our team is actively working to restore full service. Current estimated restoration time: [time or "to be confirmed"]. We will post updates at [status page URL] every two hours. If you have an urgent need, contact [dedicated support line or email].
Template C: Regulator notification checklist
- Identify the applicable regulatory body and notification deadline (e.g., HIPAA breach notification: 60 days from discovery; SEC material incident: 4 business days).
- Draft notification using the regulator's required format or your legal counsel's template.
- Include: incident date and discovery date, nature of the disruption, data or systems affected, immediate containment actions taken, and point of contact.
- Log the notification date, method, and recipient in the incident record.
How do activation thresholds and command structures work in practice?
Activation must be rule-based. A plan that requires a judgment call at 2:00 AM from an executive who is unreachable will not activate in time. Pre-defined thresholds remove ambiguity and compress response time. Clear pre-defined activation criteria are essential; lacking them delays response and increases impact.
Activation thresholds (sample)
| Trigger Event | Threshold | Activating Authority |
|---|---|---|
| Critical payment system outage | Unavailable > 4 hours | Crisis Management Team Lead or designee |
| Confirmed data breach with exfiltration | Any confirmed exfiltration | Crisis Management Team Lead; legal counsel notified immediately |
| Facility inaccessibility | Inaccessible > 24 hours | Facilities Lead; CMT Lead confirms activation |
| Key personnel loss | > 25% of a critical function unavailable | HR Director escalates to CMT Lead |
| Severe weather or natural disaster | Government-declared emergency affecting operations | CMT Lead activates automatically |
Incident command roles
| Role | Primary Responsibility | Decision Authority |
|---|---|---|
| Crisis Management Team (CMT) Lead | Overall incident command; external communications approval | Declares activation; authorizes emergency spend |
| IT Recovery Lead | System failover; vendor escalation; restore verification | Approves technical recovery decisions |
| Communications Lead | Internal and external messaging; status page management | Approves all public statements |
| Facilities Lead | Alternate site activation; physical access | Authorizes facility-related spend |
| Finance Lead | Emergency fund release; insurance notification | Authorizes emergency procurement |
| Legal/Compliance Lead | Regulatory notifications; contract review | Approves regulatory filings |
Sample delegation-of-authority clause
For organizations in energy or industrial sectors, the incident response structure for energy operations provides additional command-and-control guidance specific to regulated environments. A well-designed incident response plan template can also serve as the operational companion to your BCP activation procedures.
How often should you test, exercise, and update your BCP?
Test at least annually, and use a mix of tabletop exercises, technical restore drills, and full-scale simulations. A plan that has never been tested is a hypothesis. Industry frameworks including DRI and FEMA recommend annual testing as the minimum cadence to identify deficiencies and improve response maturity.
Sample testing metrics table
| Exercise Type | Frequency | Key Metric | Target | Last Result | Owner |
|---|---|---|---|---|---|
| Tabletop exercise | Annually (minimum) | Gaps identified and closed | 100% of gaps assigned | [Date / Result] | CMT Lead |
| Technical restore drill | Quarterly | Restore success rate | 100% | [Date / Result] | IT Recovery Lead |
| Full-scale simulation | Every 2–3 years | Actual RTO vs. target RTO | Within 10% of target | [Date / Result] | CMT Lead |
| Notification test | Semi-annually | Time to notify all staff | < 60 minutes | [Date / Result] | Communications Lead |
| Vendor contact verification | Annually | % of contacts reachable | 100% | [Date / Result] | Facilities Lead |
Post-exercise action log template
| Finding | Severity | Corrective Action | Owner | Due Date | Status |
|---|---|---|---|---|---|
| [e.g., Backup restore took longer than the 4-hour RTO] | High | Upgrade to hot-standby replication for payment systems | IT Recovery Lead | [Date] | Open |
| [e.g., Communications Lead backup was unreachable] | Medium | Update contact list; assign second backup | HR Director | [Date] | Open |
Annual review triggers
Review and update the BCP whenever any of the following occur, in addition to the scheduled annual review:
- A key personnel change in any CMT role
- A major system upgrade, cloud migration, or new vendor onboarding
- A completed exercise that reveals RTO/RPO gaps
- A regulatory change affecting notification obligations
- An actual plan activation
Pro Tip: Run your annual restore drill from offsite backups into an isolated environment, not into production. This validates both the backup integrity and the restore procedure without risking live data. Record the actual elapsed time and compare it to your stated RTO. If the gap is more than 20%, your recovery strategy needs revision before the next exercise.
What appendices and operational checklists should your BCP include?
Appendices are the operational toolkit that makes a BCP executable under pressure. A plan without current appendices forces teams to hunt for contact numbers and vendor credentials during an active incident, which is exactly when that time cannot be spared. Keep appendices current, secured, and accessible from multiple locations.
Storage and access guidance
Store the BCP in three locations: a secure cloud folder (with role-based access controls), a printed copy in your Emergency Operations Center or designated secure cabinet, and a USB drive kept off-site or with the CMT Lead. Grant edit rights only to the plan owner and designated deputies. All other CMT members receive view-only access. Review access permissions annually and revoke access for any departed personnel within 24 hours of their departure.

Security templates and audit-ready assets can provide pre-formatted versions of vendor lists, inventory formats, and backup verification logs that slot directly into these appendices.
How do you adapt this BCP example for your organization and get it live?
Adopt the sample plan by running a 60–90 day implementation sprint with clear milestones. The goal is a signed, tested plan, not a perfect document. A plan that is 80% complete and has been through one tabletop is more valuable than a 100% complete plan that has never been exercised.
Implementation timeline
Days 1–10: Assign the plan owner. Distribute the sample BCP template to department heads. Schedule BIA interviews for the top 10 functions.
Days 11–30: Complete BIA interviews. Populate the BIA data table. Identify RTO/RPO gaps between current capabilities and targets. Draft recovery strategies for the three highest-criticality functions.
Days 31–45: Complete the full BCP draft using the annotated example above. Route for legal and compliance review. Incorporate regulatory-specific requirements (see below).
Days 46–60: Obtain executive sign-off and formal plan promulgation. Distribute to all CMT members. Store in all three designated locations.
Days 61–90: Run the first tabletop exercise. Log findings. Assign corrective actions. Schedule the first technical restore drill.
When should you bring in a vCISO or continuity consultant?
Hire external help when internal bandwidth, technical capability, or independence is insufficient to produce a credible, tested plan. Most organizations underestimate how much specialized knowledge goes into a BIA facilitation, a realistic restore drill, or a regulatory-compliant plan review.
Signs you need external support
- No BCP has been tested in the past 18 months, or no BCP exists.
- Your IT team cannot confirm whether current backups can meet stated RTOs.
- Your organization has complex vendor dependencies across multiple jurisdictions.
- A regulatory audit, SOC 2 assessment, or HIPAA review is approaching and continuity documentation is incomplete.
- A recent incident revealed that activation thresholds were unclear or that the command structure broke down.
- Leadership lacks confidence in the plan's accuracy after a personnel change.
What a vCISO or continuity consultant delivers
A structured engagement typically covers:
- Plan drafting and review: — A complete BCP draft, regulatory alignment review, and executive-ready documentation.
A typical engagement runs 60–90 days for initial plan development and first exercise, with ongoing advisory support on a retainer basis. Deliverables include a tested plan, documented RTO/RPO values, trained teams, and a post-exercise action log with assigned owners and due dates.
Key Takeaways
A tested, owned, and regularly updated Business Continuity Plan is the difference between a disruption your organization manages and one that manages your organization.
| Point | Details |
|---|---|
| Copy the sample plan now | Use the annotated BCP in Section 3 as your starting draft; replace italicized fields with your organization's specifics. |
| Run a focused BIA first | Identify RTO and RPO for your top three critical functions before finalizing any recovery strategy. |
| Test within 30 days | Schedule a tabletop exercise within 30 days of plan completion; an untested plan is an assumption, not a program. |
| Validate backups against RTO | Run a full restore from offsite backups annually and record actual elapsed time; if it exceeds your RTO, revise the strategy. |
| Secure and maintain appendices | Store the plan in three locations, verify contact rosters twice per year, and update after every personnel or system change. |
| CisoSafe for implementation support | CisoSafe provides vCISO-led BIA facilitation, plan drafting, tabletop facilitation, and restore validation for regulated U.S. organizations. |
The case for exercise-first continuity planning
Most organizations treat the BCP as a documentation project. They invest weeks in formatting, approval chains, and version control, then file the plan and return to it twelve months later, usually because an auditor asked for it. That sequence is backwards.
The plan's value is not in its length or its formatting. It is in whether the people named in it know what to do, whether the technology actually meets the stated RTOs, and whether the activation thresholds are specific enough to trigger a response at 2:00 AM without a committee meeting. None of those things can be confirmed by reading the document. They can only be confirmed by running the exercise.
The practical implication: run the tabletop before the plan is perfect. A 70% complete plan that has been exercised will reveal the gaps that matter. A 100% complete plan that has never been tested will reveal them during an actual incident, which is the worst possible time. Prioritize activation rules, restore validation, and clear delegations of authority over comprehensive prose. Those three elements determine whether the plan works. Everything else is supporting documentation.
CisoSafe helps you build and test a BCP that actually works
For regulated organizations that need a tested, audit-ready Business Continuity Plan without the overhead of a full-time hire, CisoSafe delivers exactly that. As a Houston-based vCISO firm serving law firms, energy operators, oil and gas companies, and compliance-sensitive organizations across the United States, CisoSafe leads BIA facilitation, drafts and reviews BCP documentation against HIPAA, SOC 2, CMMC, and FINRA requirements, facilitates tabletop exercises, and validates backup restores against your stated RTOs.

A typical engagement runs 60–90 days: BIA completion and plan drafting in the first 45 days, tabletop facilitation and restore validation in the final phase. You receive a signed, tested plan, documented RTO/RPO values, trained teams, and a post-exercise action log with assigned corrective actions. Ongoing retainer support keeps the plan current as your systems, personnel, and regulatory obligations evolve.
If your organization has no tested BCP, a regulatory review approaching, or an incident that exposed gaps in your current plan, the next step is a direct conversation. Request a consultation with CisoSafe to scope a BCP engagement for your organization.
Authoritative U.S. resources and templates for continuity planning
| Resource | Publisher | Best For | Access |
|---|---|---|---|
| Non-Federal Continuity Plan Template | FEMA | Any U.S. organization; canonical BCP structure with all core headings | Free download |
| Continuity Guidance Circular (CGC) Template | FEMA | Organizations needing multi-year strategic continuity planning and TT&E guidance | Free download |
| Business Continuity Plan (Ready.gov) | Ready.gov / DHS | Small and mid-size businesses starting their first BCP; plain-language format | Free download |
| Business Continuity Plan Template | City of Boston | Municipal organizations and public agencies; includes essential functions table and crisis communication templates | Free download |
| Emergency Action Plan Guidelines | OSHA | Drafting or separating the ERP from the BCP; minimum EAP elements for OSHA compliance | Free download |
| IC Business Continuity Plan Template | Smartsheet | Formatted Word/PDF template for immediate use; follows multi-step BCP development process | Free download |
| Business Continuity Strategy Design | Riskonnect | Practitioners designing incident response structures and translating BIA outputs into recovery tactics | Free article |
| What Is Business Continuity Strategy? | BCM Institute | Understanding how to align recovery strategies directly to BIA outputs and RTO/RPO targets | Free article |
