Requirements - Non-Functional Profile - NF06 - Disaster Recovery & Business Continuity

Disaster Recovery & Business Continuity. There should be clear requirements (commensurate with service levels) around DR & BC (and a pragmatic approach taken with regards DR/BC events planned for). Continuity plans and supporting documentation should reflect the requirements, technical & architecture constraints etc.

Requirement description

This requirement is about ensuring the service can continue operating, or be recovered, following a significant disruption.

The solution should have clearly defined Disaster Recovery (DR) and Business Continuity (BC) requirements that are appropriate for the service criticality and agreed service levels. Recovery arrangements should be documented, understood, achievable and aligned to the actual architecture.

In simple terms:
The organisation knows how the service will continue or recover during major incidents, and there is evidence that the plans are realistic and aligned to the solution design.

Scoring rubric table – NF06 Disaster Recovery & Business Continuity

Score What it looks like Typical evidence Key gaps / risks
0 No evidence that DR or BC requirements have been defined. No documented recovery approach exists. No continuity plans, recovery procedures, architecture recovery documentation or ownership. Significant risk of prolonged outage, failure to recover critical services and unmanaged operational impact.
1 Limited evidence that DR and BC have been considered. Recovery arrangements are largely informal or based on assumptions. Draft notes, informal discussions, supplier statements or undocumented recovery expectations. High-risk gaps. Recovery responsibilities, dependencies and recovery methods are unclear.
2 Some elements of the DR and BC requirement are met. Recovery arrangements exist for parts of the solution but coverage is incomplete. Partial continuity plans, infrastructure recovery documentation, some dependency analysis or supplier commitments. Significant notable gaps in scope, testing, ownership, documentation or recovery coverage.
3 Much of the requirement is met. Recovery requirements are documented and linked to the solution architecture. Key recovery processes have been identified. DR strategy, continuity plans, operational runbooks, dependency mapping, architecture documentation and evidence of limited testing or tabletop exercises. Notable gaps remain in coverage, validation, documentation currency or supplier recovery arrangements. Mitigating action is required.
4 Most of the requirement is met with good levels of evidence. Recovery expectations, responsibilities and processes are documented, maintained and periodically reviewed. Approved DR and BC plans, recovery objectives, governance reviews, test reports, maintained recovery procedures and dependency analysis. Minor gaps only. Residual risks are documented, understood and actively managed.
5 Comprehensive evidence that the requirement is met and exceeds expectations in several areas. DR and BC capability is mature, governed and continuously improved. Regular recovery exercises, defined improvement actions, operational playbooks, supplier assurance evidence, governance reporting and measurable recovery outcomes. Minimal gaps. Recovery capability is routinely validated and refined through lessons learned.

What assessors should look for

  1. Defined recovery requirements
    Evidence that recovery expectations have been documented and are proportionate to service criticality.
  2. Documented continuity and recovery plans
    Recovery procedures, continuity plans, escalation routes and supporting operational artefacts.
  3. Alignment to architecture
    Evidence that DR and BC arrangements reflect the actual technical design, dependencies and constraints.
  4. Ownership and governance
    Clear accountability for maintaining, reviewing and approving continuity arrangements.
  5. Testing and validation
    Evidence that recovery plans have been exercised, tested or otherwise validated.
  6. Third-party and dependency coverage
    Critical suppliers, shared services and integrations are included within recovery planning.

What separates a 3 from a 4 or 5

A score of 3 normally indicates that documented recovery arrangements exist and there is a credible recovery approach. However, there are still notable weaknesses such as untested plans, incomplete dependency analysis, outdated documentation or gaps in service coverage.

A score of 4 requires evidence that plans are actively maintained, reviewed and tested, and that recovery arrangements reflect the architecture and operating model.

A score of 5 requires evidence that Disaster Recovery and Business Continuity are embedded within operational governance. Recovery exercises are performed regularly, lessons learned drive improvements, supplier assurance is in place and there is strong evidence that recovery objectives can be achieved under realistic scenarios.

Suggested evidence examples (not SAF-mandated artefacts):

  • Disaster Recovery Strategy
  • Business Continuity Plan
  • Service continuity requirements
  • Recovery runbooks
  • Major incident procedures
  • Dependency maps
  • DR test reports
  • Tabletop exercise outcomes
  • Supplier continuity assurances
  • Risk assessments and remediation plans

Updated: 07 August 2026 (SAF Version 1.1)