BSI 200-4 · ISO 22301 Business Continuity Management (BCMS)

From emergency plan to an audit-ready BCMS.

From one single data base, your business-continuity management system aligned with BSI 200-4 and ISO 22301 — consistent, branded and audit-ready. No double maintenance, no document sprawl.

See maturity levels
Single source of truthAudit-ready at a clickHosted in Germany
app.nica-software.de
BCM cockpit with maturity, open points and norm coverage

Trusted by companies and organizations

KämperCretschmarFAG-SchuleHitkoHermann-Emanuel-BerufskollegVoglerGymnasium PanketalHerder-Schule
More than an emergency plan

A management system that holds together

The engine derives every document from one data base — with evidence, consistency and verifiability.

Single source of truth

Maintain organisation, processes, BIA, risks and measures once — every document stays consistent.

Consistent by design

Derived values like MTPD/RTO are derived from a single source — consistent across all documents.

Audit-ready at a click

The norm-coverage matrix proves coverage per clause — ISO 22301, ISO 27001, BSI 200-4.

Grows with you

Three maturity levels: start reactive, build up to the full BCMS — without data loss.

Maturity levels

Start where you are — grow without migration

Nica is structured along the three maturity levels of BSI standard 200-4 and grows with your organisation.

Reactive
“Emergency plan”

Quick start: detection, immediate measures, emergency organisation, reporting paths, crisis manual.

  • IT emergency manual
  • Crisis manual & reporting paths
  • Norm coverage matrix (reactive)
Ideal for SMEs & schools
Standard
“BCMS”

Plus: management system aligned with ISO 22301 / BSI 200-4 — policy, objectives, exercise programme, internal audits, management review.

  • Everything in Build-up
  • BC policy, objectives & metrics
  • Exercise programme & management review
Ideal for certification & growing compliance needs
Licensing per tenant and maturity level — contact us for a quote.
Business impact analysis

Recovery times that fit together

Calibrate the scale first, then assess: the permissible RTO is derived from the MTPD with a safety buffer — consistent across all processes.

  • Calibration, assessment scheme & assessment
  • RTO/MTPD with a traceable derivation
  • Criticality per process on one source
app.nica-software.de
Recovery times that fit together
Dependency & impact graph

Make dependencies visible

Risks, processes, resources and plans as a network — derived from capture. Single points of failure and findings can be overlaid.

  • Risks → processes → resources → plans
  • SPOF and findings overlay
  • Derived view, no double maintenance
app.nica-software.de
Make dependencies visible
Findings & consistency

Gaps are named, not hidden

Checked continuously in the background: every finding comes with a rationale, norm reference and a jump to the spot. “Explainable, not magic.”

  • Findings grouped by criticality
  • Norm reference per finding (ISO 22301 / BSI 200-4)
  • Direct jump to the affected spot
app.nica-software.de
Gaps are named, not hidden
Generated documents

A complete output catalogue

All documents in German, professionally typeset, in tenant branding. Higher maturity levels add to the previous ones.

1Reactive
  • Emergency manual
  • Crisis management manual
  • Norm coverage matrix
  • Alerting & contact card
  • Incident log
  • Scenario quick cards
  • Management summary
  • Crisis-room activation checklist
2Build-up+ adds on
  • Continuity provisioning concept
  • BIA report
  • Business continuity plan (BCP)
  • Recovery / restoration plan
  • BCM measure plan
  • Recovery sequence
  • Supplier & fallback overview
3Standard+ adds on
  • Risk assessment report
  • BC policy
  • BC objectives & metrics
  • Test & exercise concept
  • Management review
Evidence & compliance

Audit-ready — not “certified”

Nica supports conformity and produces audit-ready evidence. The software is not a substitute for formal certification by an accredited body — it brings you demonstrably into the audit-ready state.

BSI 200-4 & ISO 22301

Structured along the three maturity levels of the BSI standard, with reference to ISO 22301.

ISO 27001 & IT-Grundschutz

Reference to Annex A controls and the elemental threats.

NIS-2 / BSIG & GDPR

Evidence and reporting reference integrated; GDPR reference for data-protection incidents.

FAQ

Common questions about the BCMS

More questions? Contact us directly — we respond straightforwardly.

The emergency plan is the reactive entry. The BCMS adds BIA, risk analysis, continuity strategies, an exercise programme and the management review — a management system aligned with BSI 200-4 / ISO 22301.
Yes. Norm-coverage matrix and document control (version, approval, distribution, history) are built for it. Unconfirmed assumptions are flagged rather than treated as decisions.
Nica brings you into the audit-ready state and produces the necessary evidence. Formal certification is done by an accredited body — the software doesn't replace it.
Values like MTPD/RTO are derived from the BIA and have exactly one source. A change applies everywhere — consistent by design, derived from a single source.
The generated documentation is aligned with BSI 200-4 and covers key NIS2 evidence requirements — suitable for regulated organizations as well. Formal certification is performed by an accredited body.
In line with the GDPR in data centres in Germany, incl. DPA. We discuss data residency and tenant separation in detail on request.
Contact

See your BCMS in a demo

Tell us briefly what it's about. We'll show you the engine live — from the data base to the finished document set.

Email
[email protected]
+49 211 17520849
Mon–Fri 9:00 – 16:00
Nica Software GmbH
Reisholzer Bahnstraße 41, Düsseldorf
Request a demo

Capture once. The whole BCMS. Audit-ready.

See in a free demo how one data base produces your audit-ready management system.

Single source of truth • Norm coverage aligned with BSI 200-4 / ISO 22301 • Hosted in Germany