From emergency plan to an audit-ready BCMS.
From one single data base, your business-continuity management system aligned with BSI 200-4 and ISO 22301 — consistent, branded and audit-ready. No double maintenance, no document sprawl.

Trusted by companies and organizations







A management system that holds together
The engine derives every document from one data base — with evidence, consistency and verifiability.
Single source of truth
Maintain organisation, processes, BIA, risks and measures once — every document stays consistent.
Consistent by design
Derived values like MTPD/RTO are derived from a single source — consistent across all documents.
Audit-ready at a click
The norm-coverage matrix proves coverage per clause — ISO 22301, ISO 27001, BSI 200-4.
Grows with you
Three maturity levels: start reactive, build up to the full BCMS — without data loss.
Start where you are — grow without migration
Nica is structured along the three maturity levels of BSI standard 200-4 and grows with your organisation.
Quick start: detection, immediate measures, emergency organisation, reporting paths, crisis manual.
- IT emergency manual
- Crisis manual & reporting paths
- Norm coverage matrix (reactive)
Plus: BIA, risk analysis, continuity strategies, BCP/recovery plan, measure plan.
- Everything in Reactive
- BIA & derived RTO/MTPD
- BCP, recovery & measure plan
Plus: management system aligned with ISO 22301 / BSI 200-4 — policy, objectives, exercise programme, internal audits, management review.
- Everything in Build-up
- BC policy, objectives & metrics
- Exercise programme & management review
Recovery times that fit together
Calibrate the scale first, then assess: the permissible RTO is derived from the MTPD with a safety buffer — consistent across all processes.
- Calibration, assessment scheme & assessment
- RTO/MTPD with a traceable derivation
- Criticality per process on one source

Make dependencies visible
Risks, processes, resources and plans as a network — derived from capture. Single points of failure and findings can be overlaid.
- Risks → processes → resources → plans
- SPOF and findings overlay
- Derived view, no double maintenance

Gaps are named, not hidden
Checked continuously in the background: every finding comes with a rationale, norm reference and a jump to the spot. “Explainable, not magic.”
- Findings grouped by criticality
- Norm reference per finding (ISO 22301 / BSI 200-4)
- Direct jump to the affected spot

A complete output catalogue
All documents in German, professionally typeset, in tenant branding. Higher maturity levels add to the previous ones.
- Emergency manual
- Crisis management manual
- Norm coverage matrix
- Alerting & contact card
- Incident log
- Scenario quick cards
- Management summary
- Crisis-room activation checklist
- Continuity provisioning concept
- BIA report
- Business continuity plan (BCP)
- Recovery / restoration plan
- BCM measure plan
- Recovery sequence
- Supplier & fallback overview
- Risk assessment report
- BC policy
- BC objectives & metrics
- Test & exercise concept
- Management review
Audit-ready — not “certified”
Nica supports conformity and produces audit-ready evidence. The software is not a substitute for formal certification by an accredited body — it brings you demonstrably into the audit-ready state.
BSI 200-4 & ISO 22301
Structured along the three maturity levels of the BSI standard, with reference to ISO 22301.
ISO 27001 & IT-Grundschutz
Reference to Annex A controls and the elemental threats.
NIS-2 / BSIG & GDPR
Evidence and reporting reference integrated; GDPR reference for data-protection incidents.
More solutions
One platform, several starting points — choose the right entry.
Common questions about the BCMS
More questions? Contact us directly — we respond straightforwardly.
See your BCMS in a demo
Tell us briefly what it's about. We'll show you the engine live — from the data base to the finished document set.
Capture once. The whole BCMS. Audit-ready.
See in a free demo how one data base produces your audit-ready management system.