Guide

Germany Business Continuity: BSI 200-4, ISO 22301 & DORA

A practitioner guide to Germany BCM using BSI Standard 200-4, ISO 22301, IT-Grundschutz/ISMS synergies and DORA for in-scope EU financial entities.

Germany combines the international ISO 22301 framework with a strong national information-security and continuity ecosystem led by the Bundesamt für Sicherheit in der Informationstechnik (BSI). BSI Standard 200-4 provides a practical Business Continuity Management approach and replaced the older BSI 100-4 emergency-management standard. Organisations in the EU financial sector must also consider DORA where they are in scope. German practitioners often need BCM to work closely with IT-Grundschutz, ISMS, crisis management, outsourcing and cyber resilience.

Germany BCM reference map

ReferencePrimary usePractical focus
ISO 22301:2019International BCMS requirements baselineManagement system, BIA, strategies, plans, exercises, performance and improvement
BSI Standard 200-4German BCM implementation guidancePractical BCMS development, BIA, continuity concepts and synergy with information security / crisis management
IT-Grundschutz / BSI 200-seriesInformation-security management and protectionUseful interfaces between ISMS assets, risk, controls and BCM dependencies
DORA – Regulation (EU) 2022/2554In-scope EU financial entities and ICT risk ecosystemICT risk management, continuity/recovery, incident reporting, resilience testing and ICT third-party risk; applies since 17 Jan 2025
NIS2 / German transposition where applicableCovered essential/important entities depending on current national implementationCybersecurity/risk-management obligations that may interact with continuity; verify entity-specific legal applicability

BSI Standard 200-4: staged BCM implementation

BSI 200-4 was designed as a practical route into BCM and provides staged approaches commonly described as Reactive BCMS, Advanced BCMS and Standard BCMS. That allows an organisation to establish urgent minimum continuity capability first, then deepen analysis, governance and assurance toward a comprehensive BCMS. The value of the staged approach is prioritisation: organisations with immature continuity do not have to wait for a perfect enterprise programme before protecting their most time-critical services.

StagePractical intentionExample outputs
Reactive BCMSCreate minimum ability to respond to serious disruption quicklyInitial scope/priorities, core response organisation, basic continuity arrangements, urgent plans
Advanced BCMSExpand systematic BCM depth and coverageBroader BIA, strategy, dependencies, exercises, governance and integration
Standard BCMSEstablish a comprehensive mature BCM system aligned with recognised requirementsFull programme governance, assurance, performance measurement, continual improvement and mapping to ISO 22301 as appropriate

BCM + ISMS: use shared data, not duplicate inventories

German organisations using IT-Grundschutz or another ISMS already maintain valuable information about assets, systems, owners, dependencies and security controls. BCM adds a different question: what business outcome must continue, how does impact change over time, what minimum capacity is required and how quickly must dependencies recover? A good integration reuses asset/dependency data but keeps the business-impact and recovery-objective logic explicit.

Shared objectISMS questionBCM question
ApplicationHow is confidentiality, integrity and availability protected?When is the application required for minimum business service, and what RTO/RPO must recovery demonstrate?
SupplierWhat security and contractual controls apply?Can the supplier recover inside the service requirement, and what substitute/exit exists?
SiteWhich physical/security risks apply?What happens to critical services if the site is unavailable and what alternate capacity exists?
Identity platformHow is privileged/access risk controlled?Can responders and alternate sites authenticate during a major outage or cyber recovery?
DataHow is it classified/protected?What data loss is tolerable, what is authoritative, and how is restored data reconciled?

DORA for German / EU financial entities

DORA lays down uniform digital operational resilience rules for a wide range of EU-regulated financial entities and has applied since 17 January 2025. It covers ICT risk governance, continuity and recovery policies, incident handling/reporting, digital operational-resilience testing and ICT third-party risk. BCM teams should not treat DORA as an “IT-only” project: important business functions, dependencies, recovery objectives, crisis communications and third parties all connect directly to service continuity.

German terminology users search for

German termPractical English equivalent / context
Business Continuity Management (BCM)Business continuity management
NotfallmanagementEmergency/contingency management; older BSI 100-4 terminology appears in legacy material
GeschäftsfortführungsplanungBusiness continuity / continuation planning
Geschäftsfortführungsplan / NotfallplanContinuity/emergency plan depending on context
Business-Impact-Analyse (BIA)Business impact analysis
Wiederanlauf / WiederherstellungRestart/recovery concepts
KrisenmanagementCrisis management
Informationssicherheitsmanagement (ISMS)Information security management system
BCM-VorlagenBCM templates

Worked Germany example: manufacturer with IT-Grundschutz data

A manufacturer already maintains application and infrastructure assets in its ISMS. BCM maps the customer-order fulfilment service across ERP, warehouse automation, plant staff, a logistics supplier and identity/network services. The BIA shows that a four-hour ERP RTO alone is insufficient because warehouse automation requires a specialist supplier with an eight-hour callout. The continuity strategy therefore adds a controlled manual dispatch mode, pre-authorised supplier escalation and local data needed to sustain priority shipments. The same dependency map supports both security and continuity conversations without pretending the two disciplines have identical objectives.

Germany practitioner checklist

  • Use ISO 22301 when an internationally recognised BCMS requirements baseline or certification path is needed.
  • Use BSI Standard 200-4 for German public guidance and practical alignment with IT-Grundschutz / organisational resilience.
  • Identify whether the organisation is an in-scope DORA financial entity; if so, connect BCM/DR evidence to ICT risk, testing, incident and third-party controls.
  • Map old BSI 100-4 / “Notfallmanagement” terminology when migrating legacy plans and inventories.
  • Integrate BCM and ISMS data models while keeping business-impact and recovery requirements distinct.
  • Publish German-language terminology and templates if German operational teams will use the programme during an incident.
  • Verify current national/EU legal applicability before labelling guidance “mandatory.”

Official references and further reading

BSI Standard 200-4: practical German terminology

German termOperational meaning / relation
Business Continuity Management (BCM)Management discipline for establishing and maintaining continuity capability
NotbetriebEmergency/degraded operation that keeps priority activity running at a defined level
Wiederanlaufzeit (WAZ)Time from interruption to the start of emergency operation; used in BSI terminology
Wiederherstellungszeit (WHZ)Time from interruption until normal operation is restored
Maximal tolerierbare AusfallzeitMaximum tolerable period of disruption; recovery timing should be set inside this boundary
NotfallvorsorgePreparedness/precautionary continuity arrangements before an emergency

German programmes often need a terminology crosswalk when legacy Notfallmanagement records, international ISO language and technology RTO/RPO terms coexist. Preserve the original approved meaning instead of mechanically renaming every field.

DORA Article 11/12 topics for in-scope financial entities

TopicPractical evidence
ICT business continuity policyApproved policy integrated with overall business continuity where appropriate
Critical or important functionsMapped functions, supporting processes, third parties and information assets
BIA alignmentICT design/redundancy linked to severe-disruption impact analysis
Response/recovery plansDocumented containment, recovery, communication and crisis mechanisms
TestingICT continuity and response/recovery plans tested at least yearly and after substantive changes for relevant systems
Cyber scenarios / switchoverTesting plans include cyberattack and primary-to-redundant switchovers where required
Backups / restorationScope/frequency based on criticality/confidentiality, periodic testing and protected restoration
Segregated recoveryOwn-system backup restoration uses physically/logically segregated systems protected from corruption/unauthorised access

Germany implementation example

A manufacturer aligns BSI 200-4 BCM with its information-security management system. The business process analysis identifies a time-critical production service; technology records show an ERP recovery dependency; facilities records show compressed air and specialist tooling; supplier records reveal a single-source component. BCM uses the shared asset/dependency data, but keeps business impact, emergency-operation capacity and return-to-normal requirements distinct from cybersecurity risk scoring.