drj logo

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Name*
Zip Code*
Please enter a number from 0 to 100.
Strength indicator
I agree to the Terms of Service and Privacy Policy*
Yes, of course I want to receive emails from DRJ!

Already have an account? Log in

drj logo

Welcome to DRJ

Already registered user? Please login here

Login Form

Register
Forgot password? Click here to reset

Create new account
(it's completely free). Subscribe

x
Skip to content
Disaster Recovery Journal
  • EN ESPAÑOL
  • SIGN IN
  • SUBSCRIBE
  • THE JOURNAL
    • Why Subscribe to DRJ
    • Digital Edition
    • Article Submission
    • DRJ Annual Resource Directories
    • Article Archives
    • Career Spotlight
  • EVENTS
    • DRJ Spring 2026
    • DRJ Fall 2026 Call for Presentations
    • DRJ Scholarship
    • Other Industry Events
    • Schedule & Archive
    • Send Your Feedback
  • WEBINARS
    • Upcoming Webinars
    • On Demand
  • MENTOR PROGRAM
  • RESOURCES
    • New to Business Continuity?
    • White Papers
    • DR Rules and Regs
    • Planning Groups
    • DRJ Glossary of Business Continuity Terms
    • Careers
  • ABOUT
    • Advertise with DRJ
    • Board and Committees
      • Executive Council Members
      • Editorial Advisory Board
      • Career Development Committee
      • DEI
      • Glossary Committee
      • Rules and Regulations Committee

Meeting the Standard: The 3 Scenarios Encountered in Complying With BCM Standards

by Jon Seals | March 25, 2021 | | 0 comments

This post first appeared on the MHA Consulting website.

By RICHARD LONG

Many people are confused about what it means to comply with a business continuity standard and when a company should do this. There are three scenarios under which a company might be complying with a BCM standard—regulatory, contractual, and voluntary; in today’s blog, we’ll look at each one.

BCM Standards in Brief

A business continuity standard is a collection of actions, benchmarks and documentation that provide guidance and verification for creating an effective BCM program. Standards are devised by experts working for standards-making organizations, such as the Business Continuity Institute or the International Organization for Standardization. Many standards have BCM related components.

There are several main standards used for BCM:

  • National Fire Protection Act (NFPA) 1600
  • International Organization for Standardization ISO 22301
  • Federal Financial Institution Examination Council (FFIEC) IT Examination Handbook
  • Business Continuity Institute (BCI) Good Practice Guidelines
  • National Institute Standards Technology (NIST) 800

For a description of each standard, see this post by MHA Consulting CEO Michael Herrera.

To a comply with a given standard means to follow its provisions, in a provable, verifiable manner.

Let’s look at each scenario under which a company might be required to-or choose to-comply with a particular BCM standard.

Complying with BCM Standards for Regularity or Legal Reasons

The first of the three scenarios for complying with a BC standard is for regulatory or legal reasons: It’s mandated by the regulations governing your industry. If a company is found to be out of compliance with a required BC standard, it can face fines and other sanctions. In severe cases or long term lack of compliance, the business or its ability to perform services can be shutdown.

Compliance with a BC standard is commonly required in highly regulated industries such as finance and healthcare.

If you work in a BCM office in such a company, your obligation is to understand what standard(s) your company must follow and bring your BCM program into compliance with that standard’s provisions and benchmarks.

If you are audited, whether internally or by an external regulating authority such as FINRA, you need to be able to prove that you are following the required standard components.

The purpose of such standards is to ensure that your organization, most likely part of a critical sector of the economy, will be resilient, if and when a disaster occurs.

Complying for Contractual Reasons

The second scenario in which a company might strive to comply with a BCM standard is for contractual reasons.

This situation is becoming increasingly common in today’s world.

In this scenario, the organization must comply with a BC standard in order to meet the terms of a contract to which it is a signatory, often a contract to supply a critical good or service to another organization that must itself comply with a BC standard for legal reasons. Alternately, the customer company might simply insist on proof of compliance by the supplier to protect its operations, as part of a non-mandated commitment to resiliency.

Moving forward, two factors are likely to increase the use of contractual language requiring a supplier to comply with a certain BC standard: The increasing intricacy of companies’ supply chains, and the growing awareness on the part of customer companies that their operations are only as secure as those of their critical suppliers.

Voluntary Compliance

The third scenario under which a company might commit itself to following a BC standard is that of voluntary compliance, where the company decides to follow a standard not because it has to but because it wants to.

Why would a company voluntarily undertake such a rigorous and challenging project?

The answer is, because its leaders want an objective and best practices guide to ensure it is in a position to ride through the inevitable shocks and impacts of contemporary business life. And who understand that complying with a good BC standard is one of the best ways of doing that.

Moreover, savvy executives understand that in today’s world, being able to truthfully claim that one’s company is ISO 22301–certified, or whatever it might be, is a strong selling point. It demonstrates a level of preparedness and resilience that can make the difference to potential customers, even in the absence of contractual language requiring such certification.

However, a company doesn’t have to go “all the way” with a BC standard to derive significant value from it. The main BCM standards are repositories of great advice. They provide a framework any organization can leverage to strengthen its BC position. Even following only a portion of their provisions can make a make a big difference in a company’s resilience.

Following the law, meeting one’s contractual obligations, and creating a selling point are all compelling reasons to comply with a BC standard.

Just as compelling—if not more so—is the simple motive of corporate self-care: the company looking after itself to protect its operations, its stakeholders, and its future. One of the best ways of doing this is by voluntarily complying with a BC standard, to whatever degree makes sense.

Three Scenarios But a Single Purpose

There are five main business continuity standards: NFPA 1600, ISO 22301, FFIEC, the BCI Good Practice Guidelines, and NIST 800. There are three scenarios under which a company might commit itself to complying with one of these standards: because it is has to in order to meet a government regulation, because it is required to in order to fulfill a contract with a customer, or because it does so voluntarily, to make itself more resilient.

Whatever the motive for complying with a standard, the underlying purpose is the same: meeting benchmarks laid out by experts in order to make the organization more resilient, more robust, more capable of weathering the disasters and impacts that are an inevitable part of business life.

Further Reading

For more information on complying with BCM standards and compliance and other hot topics in BC and IT/disaster recovery, check out these recent posts from MHA Consulting and BCMMETRICS:

  • Standard Time: The Best Time to Choose a Business Continuity Standard Is Right Now
  • How to Go from Adopting a BC Standard to Knowing What to Do to Comply with It
  • Beyond Compliance: Other Good Reasons to Gather Your BC Program Metrics
  • BCM by the Numbers: The Metrics That Matter Most
  • Rating Your BC Skills: Little White Lies Can Create Ticking Time Bombs
  • Standard Issue: Is Your BCM Standard Making Things Worse?

Related Content

  1. Disaster Recovery Journal
    Continuity of Operations Does Not Mean Business Continuity
  2. Disaster Recovery Journal
    Standard Time: The Time to Choose a Standard Is Now
  3. Crisis Management Training and Exercises: Preparing Your Team

Recent Posts

Maturity Model: How Compliance Drives Data Resilience

February 9, 2026

FirstNet: Built with and for First Responders in Any Winter Storm

February 6, 2026

Cowbell Launches in Australia, Bringing AI-Powered Cyber Protection Backed by the Financial Strength of Zurich

February 6, 2026

Cologix Expands Ashburn Presence With Strategic Land Acquisition, Supporting $5B Long-Term Northern Virginia Growth Plan

February 5, 2026

Cayosoft and XMS Solutions Selected by U.S. Department of War Agency to Modernize ICAM Operations for Mission Resilience

February 5, 2026

Security Experts Struggle to Keep Pace With AI Threats as 90% Report at Least One Security Incident in the Past Year

February 5, 2026

Archives

  • February 2026 (27)
  • January 2026 (61)
  • December 2025 (45)
  • November 2025 (58)
  • October 2025 (78)
  • September 2025 (65)
  • August 2025 (59)
  • July 2025 (70)
  • June 2025 (54)
  • May 2025 (59)
  • April 2025 (91)
  • March 2025 (57)
  • February 2025 (47)
  • January 2025 (73)
  • December 2024 (82)
  • November 2024 (41)
  • October 2024 (87)
  • September 2024 (61)
  • August 2024 (65)
  • July 2024 (48)
  • June 2024 (55)
  • May 2024 (70)
  • April 2024 (79)
  • March 2024 (65)
  • February 2024 (73)
  • January 2024 (66)
  • December 2023 (49)
  • November 2023 (80)
  • October 2023 (67)
  • September 2023 (53)
  • August 2023 (72)
  • July 2023 (45)
  • June 2023 (61)
  • May 2023 (50)
  • April 2023 (60)
  • March 2023 (69)
  • February 2023 (54)
  • January 2023 (71)
  • December 2022 (54)
  • November 2022 (59)
  • October 2022 (66)
  • September 2022 (72)
  • August 2022 (65)
  • July 2022 (66)
  • June 2022 (53)
  • May 2022 (55)
  • April 2022 (60)
  • March 2022 (65)
  • February 2022 (50)
  • January 2022 (46)
  • December 2021 (39)
  • November 2021 (38)
  • October 2021 (39)
  • September 2021 (50)
  • August 2021 (77)
  • July 2021 (63)
  • June 2021 (42)
  • May 2021 (43)
  • April 2021 (50)
  • March 2021 (60)
  • February 2021 (16)
  • January 2021 (554)
  • December 2020 (30)
  • November 2020 (35)
  • October 2020 (48)
  • September 2020 (57)
  • August 2020 (52)
  • July 2020 (40)
  • June 2020 (72)
  • May 2020 (46)
  • April 2020 (59)
  • March 2020 (46)
  • February 2020 (28)
  • January 2020 (36)
  • December 2019 (22)
  • November 2019 (11)
  • October 2019 (36)
  • September 2019 (44)
  • August 2019 (77)
  • July 2019 (117)
  • June 2019 (106)
  • May 2019 (49)
  • April 2019 (47)
  • March 2019 (24)
  • February 2019 (37)
  • January 2019 (12)
  • ARTICLES & NEWS

    • Business Continuity
    • Disaster Recovery
    • Crisis Management & Communications
    • Risk Management
    • Article Archives
    • Industry News

    THE JOURNAL

    • Digital Edition
    • Advertising & Media Kit
    • Submit an Article
    • Career Spotlight

    RESOURCES

    • White Papers
    • Rules & Regulations
    • FAQs
    • Glossary of Terms
    • Industry Groups
    • Business & Resource Directory
    • Business Resilience Decoded
    • Careers

    EVENTS

    • Fall 2025
    • Spring 2026

    WEBINARS

    • Watch Now
    • Upcoming

    CONTACT

    • Article Submission
    • Media Kit
    • Contact Us

    ABOUT DRJ

    Disaster Recovery Journal (DRJ) is the leading resource for business continuity, disaster recovery, crisis management, and risk professionals worldwide. With a global network of more than 138,000 practitioners, DRJ delivers essential insights through two annual conferences, a quarterly digital magazine, weekly webinars, and a rich library of online resources at www.drj.com. Our mission is to empower resilience professionals with the knowledge, tools, and connections they need to protect their organizations in a fast-changing world. Join our community by attending our events, subscribing to our publications, and following us on social media.

    LEARN MORE

    LINKEDIN AND TWITTER

    Disaster Recovery Journal is the leading publication/event covering business continuity/disaster recovery.

    Follow us for daily updates

    LinkedIn

    @drjournal

    Newsletter

    The Journal, right in your inbox.

    Be informed and stay connected by getting the latest in news, events, webinars and whitepapers on Business Continuity and Disaster Recovery.

    Subscribe Now
    Copyright 2026 Disaster Recovery Journal
    • Terms of Use
    • Privacy Policy

    Register to win a Free Pass to DRJ Spring 2026 | The Future Runs on Resilience

    Leave your details below for a chance to win a free pass to DRJ Spring 2026 | The Future Runs on Resilience. The winner will be announced on February 13. Join us for DRJ's 74th Conference!
    Enter Now