You've seen the template before.
The one that starts with "The purpose of this policy is to establish requirements for business continuity in accordance with applicable legal, regulatory, and contractual obligations..."
Fourteen pages. No one reads it. It lives in a folder called "Compliance Docs" that gets opened twice a year, once for the audit, once when someone accidentally clicks on it.
Then the incident happens.
Ransomware. Cloud outage. Supply chain failure. Fire alarm at 2am.
And the business continuity plan? The one that was going to save you?
Nobody can find it. And even if they could, it was written for an auditor, not for a human under stress.
That's the problem we're solving today.
Why Most BC/DR Policies Fail
Not because the content is wrong. Most templates cover the right clauses, the right structure, the right vocabulary.
They fail because:
- They're written for auditors, not for people. If the first sentence includes "in accordance with applicable legal requirements," you've already lost the reader.
- They don't name names. "Top management shall ensure..." doesn't mean anything if no one specific is accountable.
- They've never been tested. A plan that hasn't been exercised is a guess. And organisations don't survive on guesses.
- They sit in isolation. BC lives in one folder, DR lives in another, crisis comms lives in someone's head.
- They rot. Written once, approved once, forgotten until the next certification cycle.
Sound familiar?
What I Built And Why
I took the template I use in real consulting projects and ISO 22301 implementations and turned it into a free, downloadable BC/DR Policy.
But I didn't just publish a document. I rewrote the rules of what a policy template should feel like.
Here's what makes this one different:
1. It's Written for Humans
Short sentences. Active verbs. "We" and "you", not "the organisation" and "the user."
Every section is written so a department head on their first day can understand their role during a disruption.
From the template:
"Plans are useless if no one can find them during a crisis. Ours are: practical, accessible, specific, and tested."
That's not ISO-speak. That's operational reality.
2. It Has a Voice
Throughout the template, you'll find commentary sidebars: direct, practical guidance from Cyber Academy in the margins.
Things like:
"Most BIAs fail because they're done by IT in isolation. A BIA is a business exercise. If the CFO, Head of Ops, and Head of Sales haven't been in the room, your BIA is incomplete."
"If your exercises always go perfectly, they're not challenging enough. A good exercise should make people uncomfortable. That's the point."
"Logging a nonconformity without root cause analysis is paperwork. Doing root cause analysis without follow-up is theatre. Do both."
These sidebars are the difference between a generic template and a framework built by people who've actually done this.
3. It Maps to What Matters in 2026
Not just ISO 22301. This template references:
Standard / RegulationWhyISO 22301The backbone. BCMS requirements.ISO 27001BC and infosec are two sides of the same coin. Annex A controls A.5.29 and A.5.30 live here.NIS2Article 21 requires BC, backup management, and DR for essential and important entities. Article 20 makes management personally accountable.DORAArticles 11–12 require ICT BC and DR testing for financial entities.
4. It Names Roles, Not Abstractions
Instead of "Appropriate personnel shall be assigned responsibilities," the Roles section includes a table with one column called: "What They Actually Do."
Because "Top Management" doesn't mean anything until you write: "Show up at management reviews, not just sign them. If leadership ignores BC, so will everyone else."
5. Sections Are Called What They Are
- Section 5 isn't "Performance Evaluation." It's "Check It Works."
- Section 6 isn't "Improvement." It's "Fix What's Broken."
Still fully auditable against ISO 22301 clauses 4–10. But written so a human actually wants to keep reading past page two.
What's Inside
#SectionWhat It Covers1PurposeWhy this exists, in three sentences, not three paragraphs2ScopeWho this applies to. Spoiler: everyone.3Roles & ResponsibilitiesNamed, specific, with a "What They Actually Do" column4PolicyBIA, risk assessment, strategies, plans, incident response (3-tier table), comms, exercises (progressive table), DR, training5Check It WorksMonitoring, internal audit, management review6Fix What's BrokenNonconformities, root cause analysis, corrective actions7ComplianceEnforcement + NIS2/DORA management accountability8ReferencesTable explaining why each standard matters
Every placeholder is marked in purple italic so you know exactly what to customise.
Who This Is For
- BC managers building or rebuilding a BCMS from scratch
- CISOs and GRC leads who need a single integrated BC/DR policy, not separate silos
- Consultants implementing ISO 22301 for clients and tired of starting from zero every time
- Organisations preparing for NIS2 or DORA that need to demonstrate business continuity measures
- Anyone who's been through an audit and thought: "There has to be a better template than this."
👉 Download the BC/DR Policy Template - FreeUse it. Adapt it. Make it yours.
Delete the commentary sidebars before publishing or keep them as internal guidance for your team. Your call.
Want the Next One Before Anyone Else?
This template is the first piece of the official cyber academy documentation directory we're building.
Coming next: BIA template, exercise programme, documented information register, and more all in the same voice, the same quality, the same "built for humans" philosophy.
📩 Join the Cyber Academy ListWe'll email you when the next resource drops.No spam. No sequences. Just tools.You can unsubscribe from our communications at any time.Visit our Privacy Policy to learn more about our unsubscribe terms, our privacy policies, and our commitment to protecting and respecting privacy.
Want to Go Further?
A template is a starting line. Not a finish line.
If you want the methodology, the case studies, and the practice to build a BCMS that survives audits and real incidents:
- ISO 22301 Lead Implementer, the full certification programme
- ISO 27001 Lead Implementer, because BC and infosec are inseparable
- DORA Lead Manager, for financial sector digital resilience
- NIS2 Lead Implementer, for essential and important entities
All trainings: Certified or Refunded.
