BSI Standard 200-4 (final version 1.0, dated May 2023; successor to BSI Standard 100-4) describes how to establish and operate a business continuity management system (BCMS). Its tiered model allows a resource-efficient entry across three maturity levels: the Reactive BCMS for a fast, basic emergency response capability, the Build-up BCMS for gradual expansion, and the Standard BCMS as the full implementation. The Standard BCMS level is compliant with the requirements of ISO 22301:2019, the internationally certifiable BCMS standard (supplemented by Amendment 1 in 2024). IT emergency management (IT service continuity management, ITSCM) interlocks BCM with IT operations and the ISMS.
Cyber Resilience through Business Continuity Management
How to safeguard the continuity of your critical business processes with BSI Standard 200-4 and ISO 22301 – from the business impact analysis and backup strategies to crisis team exercises.
3Maturity levels in BSI Standard 200-4: Reactive, Build-up and Standard BCMS
3-2-1Rule of thumb for backups: three copies, two types of media, one copy at a different location
24 hEarly warning for significant incidents under Art. 23 NIS2
72 hIncident notification after becoming aware — final report no later than one month after the notification
Cyber resilience means not only preventing a severe IT outage but surviving it: ransomware incidents regularly paralyze organizations for weeks, and recovery often fails not because of the technology but because of a lack of preparation. Business continuity management (BCM) and IT emergency management provide the organizational framework for this – with clear metrics, robust recovery plans and regular exercises. With NIS2 and DORA, maintaining business operations has also evolved from a best practice into a minimum regulatory requirement. BSI Standard 200-4 and ISO 22301 provide the established methodology for implementing these requirements in a structured way.
The Essentials at a Glance
Six topic blocks — tap to expand.
Key metrics in detail: MTA, RTO, RPO
From the business impact analysis to the target values — and their comparison with what is actually achievable. Tap a metric.
- Defines how long a business process may be down at most; internationally known as MTPD.
- The starting point is the business impact analysis (BIA): it identifies time-critical business processes, their resources and potential single points of failure.
BIAMTPDtime-critical business processessingle points of failure
- The required recovery time objective of the supporting resources — derived from the maximum tolerable downtime of the business process.
recovery time objectiveresources
- Determines how old the most recent recoverable data set may be — and thus the backup frequency.
recovery point objectivebackup frequency
- What matters in practice: comparing the targets with the values that can actually be achieved (RTA/RPA).
- If the achievable values exceed the targets, there is a coverage gap — to be closed through technical measures or a defined minimum level of emergency operations (MBCO).
coverage gaptechnical measuresMBCO
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
BSI-Standard 200-4 Business Continuity Management
Methodological framework for a BCMS with a three-level entry model (Reactive, Build-up and Standard BCMS), BIA metrics (MTA, RTO, RPO) and exercise formats; the Standard BCMS level is compliant with ISO 22301:2019.
Maßnahmenkatalog Ransomware (Arbeitspapier, Version 1.0)
Preventive measures against ransomware, including offline backups, regular recovery tests and black-start planning, as well as plan reviews and exercises for incident preparedness.
ISO 22301:2019 Security and resilience – Business continuity management systems – Requirements
Internationally certifiable requirements standard for business continuity management systems; supplemented by Amendment 1:2024 (Climate action changes).
Richtlinie (EU) 2022/2555 (NIS2)
Art. 21(2)(c) requires business continuity including backup management, disaster recovery and crisis management; Art. 23 sets out the multi-stage reporting deadlines (24 h/72 h/1 month).
Verordnung (EU) 2022/2554 (DORA)
Art. 24–26 oblige financial entities to maintain a digital operational resilience testing programme, to test critical ICT systems annually and to conduct TLPT at least every three years; applicable since 17 January 2025.
Related Services
How resilient is your emergency management?
In a no-obligation initial consultation, we jointly assess where your BCM stands today – from the business impact analysis to your first crisis team exercise.