Glossary · NIS2

Business Continuity

The Article 21(c) measure requiring backup management, disaster recovery, and crisis management to keep services running during and after incidents.

Explained in depth: The 10 NIS2 security requirements

Article 21(2)(c) requires entities to have business continuity measures, explicitly naming backup management, disaster recovery, and crisis management. The goal is that a significant incident, whether a ransomware attack or a data centre fire, does not translate into prolonged loss of the essential or important service the entity provides. A defensible implementation typically includes a business impact analysis identifying critical services and their tolerable downtime, documented recovery time and recovery point objectives, tested backups kept isolated from production (offline or immutable), a disaster recovery plan, and a crisis management organisation with defined roles that has actually been exercised.

Why it matters

Untested backups and paper-only continuity plans are among the most common audit findings, and among the most expensive gaps when ransomware hits. Under NIS2, "we had backups but they were encrypted too" is both an operational disaster and a compliance failure.

Used in

See also

← All glossary terms