
A business continuity plan template for a small business needs twelve parts: plan control, scope, roles and succession, contact lists, business impact analysis results, continuity strategies, manual workarounds, how the plan is activated, a communications plan, a pointer to IT recovery, an exercise schedule and a revision record. Copy the template below, fill it in with the people who run each process, and exercise it before you rely on it.
We build and exercise plans like this in our business continuity planning work. The sections follow Ready.gov's business continuity plan outline and NIST's contingency planning guide, scaled for a company with one or two sites and no full-time continuity staff. Restoring servers and data belongs in a separate IT disaster recovery plan template; the two documents should reference each other.
What is a business continuity plan?
NIST defines it as a predetermined set of instructions or procedures describing how an organization's business processes will be sustained during and after a significant disruption. Its examples of such processes are payroll and customer service, which is the right level of detail: the plan is written around work, not around equipment.
NIST also says a plan may be scoped to the functions a business treats as priorities. That is the sensible start for a small company. Write the plan for the handful of processes that would cost you money, customers or a legal deadline within days, then widen it. The plan answers who decides, where people work, how customers reach you, what runs by hand while systems are down, and in what order things come back. For where continuity ends and recovery begins, see business continuity vs disaster recovery.
What should a business continuity plan template include?
Copy this table into a document, keep the section numbers, and replace the sample entries with your own. The sample entries are illustrations, not recommendations for your business.
| Section | What to fill in | Sample entry |
|---|---|---|
| 1. Plan control | Company name, plan owner, version, who approved it and when, last review date | Version 1.2, approved by the managing director in January, reviewed every January |
| 2. Scope, objectives and assumptions | Sites, processes and events the plan covers, what it aims to protect, and what it assumes still works | Covers the office and the warehouse; assumes cell service and home internet are available |
| 3. Roles, authority and succession | Who activates the plan, who leads, who approves spending, who speaks for the company, and a deputy for each | Operations manager activates; the controller deputizes and approves emergency spending |
| 4. Contact lists | Team members with work and personal numbers, key customers, vendors and contractors with emergency numbers | Printed list in each manager's bag, refreshed quarterly |
| 5. Business impact analysis results | Critical processes, the damage over time if each stops, maximum tolerable downtime, recovery targets and dependencies | See the worksheet below |
| 6. Continuity strategies | How each critical process keeps going: another site, remote work, a second supplier, cross-trained staff | Office staff work from home; a second carrier account is kept active |
| 7. Manual workarounds | The forms, printed lists and supplies needed to work by hand, and where they are kept | Paper order pads and last week's printed price list in the office safe |
| 8. Activation and incident management | How a problem is reported, who is alerted, the criteria for activating the plan, damage assessment and the first-hour checklist | Activate when the office or the order system is unavailable for more than two hours |
| 9. Communications plan | Audiences, who contacts each, channels and prepared messages | See the communications table below |
| 10. IT recovery reference | Where the IT disaster recovery plan lives, the agreed recovery order and the IT emergency contact | IT recovery plan, section 5; the IT provider's emergency line |
| 11. Training and exercises | Orientation for new staff, tabletop and functional exercises, with dates and owners | Tabletop each spring; phone forwarding tested each quarter |
| 12. Maintenance and revision record | Review schedule and triggers, open corrective actions, distribution list and a dated log of changes | Review after any move, major system change or exercise |
Ready.gov's outline also covers a step that is easy to miss: deciding where copies live. It suggests printed copies where the team will gather, and an electronic copy on a secure site the team can reach if company servers are down. A plan stored only on the file server is unavailable in the outage it was written for.
How do you run the business impact analysis?
The business impact analysis (BIA) tells you which processes matter most and how quickly each must return. Ready.gov describes it as predicting the consequences of a disruption and gathering the information needed to develop recovery strategies. The impacts it asks you to weigh are lost or delayed sales and income, increased expenses such as overtime and expediting, regulatory fines, contractual penalties, customer dissatisfaction and delays to new business plans.
NIST breaks the work into three steps that suit a small company too: decide which processes are critical and how long each can be down, identify the resources each one needs, and set recovery priorities. Three definitions from NIST keep the numbers honest:
- Maximum tolerable downtime (MTD): the total time leadership will accept a process being down, counting every impact.
- Recovery time objective (RTO): the longest a system can stay unavailable before the impact becomes unacceptable. NIST notes the RTO normally has to be shorter than the MTD, because work must also be caught up after the system returns.
- Recovery point objective (RPO): the point in time to which data can be recovered, which sets how much recent work you could lose.
Use one row per process, and interview the person who runs it, not only the IT provider. The sample entries are illustrative.
| Field | What to record | Sample entry |
|---|---|---|
| Process and owner | The business activity and the person accountable for it | Taking customer orders; sales manager |
| Peak periods | When an outage hurts most | Monday mornings and the last week of each quarter |
| Impact over time | What happens after four hours, one day, three days and one week, in money, customers and obligations | One day: orders slip to competitors. One week: key accounts at risk |
| Maximum tolerable downtime | Agreed by leadership | One business day |
| RTO and RPO | For each system the process depends on | Order system: four hours and one hour |
| People and skills | Minimum staff and who can cover | Two order takers; one cross-trained back-office clerk |
| Systems and data | Applications, files and devices | Order system, phones, price list |
| Suppliers and outside services | Who you depend on, and their emergency contacts | Internet provider, phone provider, order system vendor |
| Workaround | How the process runs by hand, and for how long | Phone orders on paper forms, entered later; workable for two days |
What does a sample business continuity plan look like?
This illustrative planning example is for a fictional 40-person wholesale distributor with an office and a warehouse. It is not a client, it describes no real result, and every target is a placeholder for numbers your own process owners agree.
| Critical process | Owner | Maximum tolerable downtime | Continuity strategy | Manual workaround |
|---|---|---|---|---|
| Customer orders | Sales manager | One business day | Order takers work from home on company laptops | Paper order forms and a printed price list |
| Customer service phones | Office manager | Four hours | Main number forwarded to mobile phones from the phone provider's portal | Callback list kept on paper |
| Picking and shipping | Warehouse lead | Two business days | Second carrier account kept active; two staff trained on each role | Pick lists printed from the last daily export |
| Invoicing and collections | Controller | Five business days | Accounting system reachable from any managed laptop | Invoices issued late from shipping records |
| Payroll | Controller | Until the next pay date | Payroll provider's portal used from any device | Repeat the last payroll and adjust next cycle |
The rest of the sample plan, in brief: the operations manager activates the plan and the controller is deputy; the warehouse lead keeps the vendor list; IT recovery follows the separate IT plan, with the order system restored first; staff hear about activation by group text from a printed phone list. Every one of those choices is something your own team should decide and write down.
How should the plan handle communications?
| Audience | Who contacts them | Channel | When | What they need |
|---|---|---|---|---|
| Staff | Operations manager | Group text from the printed phone list | Within 30 minutes of activation | Where to work, what is affected, the next update time |
| Customers with open orders | Sales manager | Phone, then a prepared email | Same day | Expected delays and how to place orders now |
| Suppliers and carriers | Warehouse lead | Phone | Same day | Changed pickup or delivery plans |
| Insurer | Controller | Claims line | As soon as damage is known | Policy number and a description of the event |
| IT provider | Operations manager | Emergency line | Immediately | What is down and what the business needs first |
| Regulators, authorities or affected people | Owner, with counsel | As the rule requires | When a law or contract requires notice, such as after a data breach | Facts confirmed by counsel |
Write the first message for each audience now, while nobody is under pressure, and store it with the plan.
What does a business continuity policy template need?
If a customer or insurer asks for a business continuity policy as well as a plan, keep it to one page:
- Purpose: the company keeps a business continuity plan so its critical processes continue during a disruption.
- Scope: all sites, staff, critical processes and key suppliers.
- Commitments: a named plan owner keeps the plan current; process owners review their impact analysis entries every year; the plan is exercised at least once a year and after major changes; copies are kept offline; gaps found in exercises get an owner and a date.
- Roles: leadership approves downtime tolerances and budget; the plan owner runs reviews and exercises; process owners maintain their sections; the IT provider maintains the technology recovery sections.
- Review: leadership reviews and re-approves the policy every year.
Who maintains the plan, and how do you test it?
One named person in the business owns the plan. Ready.gov's template says the business continuity team leader keeps the master copy, and the owner's job is to schedule reviews and exercises and sign off on the results, not to do every task. Process owners keep their own rows current, and the IT provider keeps the recovery order and technical contacts current.
A plan is validated by exercising it. Ready.gov's outline lists orientation, tabletop and full-scale exercises, and Ready.gov also publishes exercise materials, including a situation manual and a facilitator and evaluator handbook. A starting schedule for a small company:
| Exercise | What it proves | Suggested frequency | Record to keep |
|---|---|---|---|
| Contact list check | The numbers and people are current | Quarterly | Date checked and corrections made |
| Notification drill | A message reaches every person on the list | Twice a year | Time taken to reach everyone |
| Tabletop exercise | Roles, decisions and communications hold up in a realistic scenario | Yearly, and after a real incident | Notes, gaps found, owners and dates |
| Workaround test | A manual process or remote working day actually works | Yearly for each critical workaround | What worked, what failed, fixes |
| IT recovery test | Systems return within their recovery targets | Per the IT recovery plan | Measured times against each RTO |
Update the plan after every exercise, and after any office move, new system or change of key staff.
How does NetSys help with business continuity plans?
We work through the impact analysis with your process owners, document priorities and fallback procedures, and help exercise the plan; your leadership approves downtime tolerances, staffing decisions and anything outside the technical scope. A tabletop checks decisions and responsibilities, and a technical recovery test checks selected systems; we agree the scenario, the participants and the evidence before each one. Backup changes, recovery infrastructure and remediation are scoped separately, and we can start with a review of a plan you already have. We work from one office in Brooklyn, on site across New York City, Long Island, Westchester, the Hudson Valley, North Jersey and Fairfield County, CT, and remotely elsewhere.
Want a second opinion on a draft? Book a call and walk us through your critical processes and recovery targets.
Frequently asked questions
What does a business continuity plan template cover?
It covers how critical work continues during a disruption: who decides, how people are reached, where they work, which processes run by hand, how customers and suppliers are told, and in what order operations return. The impact analysis inside it sets the downtime each process can tolerate, and the IT recovery plan it points to covers restoring systems and data.
Who should maintain the business continuity plan?
A named owner in the business, usually the owner or head of operations, keeps the master copy, schedules reviews and exercises and signs off on results. Each process owner maintains their own impact analysis entries and workarounds, and the IT provider maintains the technology recovery details. Review the whole plan at least once a year.
How do we validate a business continuity plan?
Exercise it. Start with a contact list check and a tabletop exercise, then test individual workarounds such as phone forwarding or a remote working day, and test IT recovery against each system's RTO. Record what failed, assign an owner and a date to each gap, and exercise again after the fix.
What is the difference between a business continuity plan and a disaster recovery plan?
A business continuity plan keeps the business working: people, places, suppliers, customers and manual workarounds. A disaster recovery plan restores the technology: systems, data and the order they return. The continuity plan sets the priorities the recovery plan has to meet, so write both and have each point to the other.
Is there a business continuity plan template in PDF?
Ready.gov publishes a short business continuity plan outline as a PDF. The tables on this page can be copied into a document and saved as a PDF too. Whatever format you use, keep a printed copy and an electronic copy that does not depend on your own servers.
Is there a standard for business continuity management?
Yes. ISO 22301 is the international standard for business continuity management systems, the management framework around plans like this one. As of October 2026, ISO lists the 2019 edition as current and due for revision. Most small companies need a working plan first; adopt the full standard if a customer or contract asks for it.
Sources and further reading
- Ready.gov: Business Continuity Plan (PDF): plan sections, exercises, and where to keep copies, checked October 2026.
- Ready.gov: Business continuity plan page: the exercise situation manual and facilitator and evaluator handbook, checked October 2026.
- Ready.gov: Business Impact Analysis: the impacts to assess, checked October 2026.
- NIST SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems: the business continuity plan definition, the three impact analysis steps, and MTD, RTO and RPO, checked October 2026.
- ISO 22301:2019, Business continuity management systems: scope and revision status, checked October 2026.
Related reading
ComparisonBusiness Continuity vs Disaster Recovery: How the Two Plans Differ
Read Article
Disaster RecoveryIT Disaster Recovery Plan Template, With a Filled-In Example
Read Article
Disaster RecoveryHurricane Season IT Checklist for NY, NJ & Florida Businesses
Read ArticleAlso on this topic: The CrowdStrike Outage: 5 Business Continuity Lessons From a Global Meltdown
Discuss business continuity planning for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.
