Continuity of Operations Plan: Components, Sites, and Testing

A continuity of operations plan, commonly called a COOP, is the document an organization follows to keep its most critical functions running when a flood, cyberattack, pandemic, or other disruption makes normal operations impossible. Under federal policy, executive branch agencies must be able to resume their most important functions within 12 hours of a disruption and sustain them for at least 30 days. That benchmark shapes everything else in the plan, from how records are stored to where staff report when the primary building is unavailable.

If you are building a plan, the work breaks down into a predictable sequence: figure out which functions must survive, measure what losing them would cost, document who takes charge and where they work, protect the records and systems they depend on, and prove through exercises that the plan actually works.

The Federal Framework Behind the Plan

Presidential Policy Directive 40 sets national continuity policy and directs FEMA to coordinate continuity activities across the executive branch. FEMA implements that mandate through Federal Continuity Directive 1, which sets the requirements every executive branch department and agency must meet, and Federal Continuity Directive 2, which details how agencies identify and categorize their mission essential functions.1Federal Emergency Management Agency. Federal Continuity Directive 1 – Federal Executive Branch National Continuity Program and Requirements2Federal Emergency Management Agency. Federal Continuity Directive 2

For state and local governments, nonprofits, and private-sector infrastructure operators, FEMA publishes a Continuity Guidance Circular. It is not mandatory outside the federal executive branch, but organizations building a program from scratch commonly use it as their reference.3Federal Emergency Management Agency. Continuity Guidance Circular

Identifying Essential Functions

Every part of the plan flows from one question: what does this organization absolutely have to keep doing during a crisis? Federal agencies answer that by sorting their work into three tiers.

Mission Essential Functions (MEFs) are the activities tied directly to the agency’s core statutory mission. Primary Mission Essential Functions (PMEFs) are a smaller subset of MEFs that must run continuously because they support National Essential Functions such as maintaining economic stability or providing for the national defense. Not every agency has PMEFs. Essential Supporting Activities (ESAs) are the behind-the-scenes work — network administration, for example — that keeps MEFs running but does not independently accomplish the mission.4Federal Emergency Management Agency. Federal Continuity Directive – Federal Executive Branch Essential Functions Risk Identification and Management

PMEFs carry the tightest recovery window: continuous or resumed within 12 hours, and maintained for up to 30 days or until normal operations restart.5Federal Emergency Management Agency. Federal Continuity Directive 1 Agencies must review their MEFs and PMEFs every two years to make sure the categorization still matches how the organization actually operates.

Measuring the Cost of Downtime

Before you can protect essential functions, you need to know what happens if each one goes down. A business impact analysis (BIA) answers that by measuring the consequences of losing specific processes for different lengths of time. Department heads and subject matter experts walk through their operations and identify the supporting systems, external dependencies, legal obligations, and manual workarounds for each process.

Three metrics anchor the analysis:

  • Maximum Tolerable Downtime (MTD) is the total time a function can be offline before the organization suffers serious, potentially irreversible harm.
  • Recovery Time Objective (RTO) is the target for how quickly you need the function running again. The RTO must fall within the MTD; if your MTD is 24 hours and your RTO is 48, the math does not work.
  • Recovery Point Objective (RPO) is the maximum data loss you can absorb, measured in time from the last good backup. An RPO of four hours means backups must run at least every four hours.

The more critical the function, the closer these targets need to be to zero. Once you have MTD, RTO, and RPO figures for every essential function, you can tier your systems by criticality and put resources where failure would hurt the most. The analysis also surfaces hidden dependencies, such as a minor vendor or internal process whose failure cascades across multiple essential functions.

Core Components Every Plan Must Contain

Orders of Succession

Leadership gaps during a crisis can paralyze an organization. The plan documents a formal order of succession naming the specific individuals who step into leadership roles if the primary officeholder is unreachable, incapacitated, or dead. FCD-1 requires every agency to maintain succession lists for all key positions.1Federal Emergency Management Agency. Federal Continuity Directive 1 – Federal Executive Branch National Continuity Program and Requirements The list should go at least three deep for each position, and successors should ideally be geographically dispersed so that a single event cannot take out the entire chain.

Delegations of Authority

An order of succession puts someone in the chair. A delegation of authority gives them the legal power to act once they are there, including signing contracts, obligating funds, and making policy decisions. The delegation document specifies the conditions that trigger it, the scope and limits of the authority transferred, and when it reverts to the original officeholder.1Federal Emergency Management Agency. Federal Continuity Directive 1 – Federal Executive Branch National Continuity Program and Requirements Without clear delegations, a successor holds the title but lacks the authority to make decisions in the first hours after a disaster.

Essential Records

Every organization depends on records that cannot be recreated from scratch: contracts, financial databases, personnel files, engineering drawings, licensing documents. The plan must identify these records, categorize them by storage type (electronic or physical, on-site or off-site), and establish procedures for reaching them from an alternate location.1Federal Emergency Management Agency. Federal Continuity Directive 1 – Federal Executive Branch National Continuity Program and Requirements The BIA drives this work. If a function has a four-hour RTO, its records must be accessible in under four hours, which usually means cloud-based or mirrored storage rather than a filing cabinet in the basement.

Personnel Requirements

Each essential function maps to the people who perform it. The plan identifies which staff must report during a continuity activation, where they should report, and what their specific responsibilities are. Contact information, including personal phone numbers, emergency email addresses, and out-of-area contacts, goes into a roster that response teams can reach immediately. Position descriptions should be detailed enough that someone stepping into an unfamiliar role can understand what is expected without a lengthy briefing.

Where People Work When the Primary Site Is Gone

Alternate Operating Facilities

If the primary workplace is damaged, flooded, or otherwise unusable, the plan must have a pre-identified alternate facility ready. Selecting one involves more than finding empty office space. The location needs reliable power, physical security, room for continuity personnel, and the hardware and software to support essential functions. It must be far enough from the primary site that a single regional disaster will not take out both locations, but close enough that staff can realistically reach it.

FCD-1 requires that life support provisions at the alternate facility, including food, water, medical services, and power, be available in quantities sufficient to sustain at least 30 days of operations, with the ability to extend beyond that for prolonged events like a pandemic.5Federal Emergency Management Agency. Federal Continuity Directive 1

Telework as a Continuity Strategy

Physical relocation is not always the fastest option. Telework has become a core continuity strategy, and federal guidance treats it as either the primary approach or a backup depending on the function. Agencies must assess which essential functions can be performed remotely, make sure IT systems have enough capacity for a surge, protect information security at home locations, provide access to essential records and communication tools, and notify every employee of their telework eligibility before an activation happens rather than during the scramble afterward.6Federal Emergency Management Agency. Telework – An Essential Component of Continuity Planning

Interoperable Communications

A plan is useless if the people executing it cannot talk to each other. Continuity communications systems must connect different departments, agencies, and external partners through multiple redundant channels, so that if one fails another takes over. That typically means a mix of satellite phones, secure radio, redundant internet connections, and backup email systems. FCD-1 requires that these capabilities be maintained and ready for sustained use of no less than 30 days.5Federal Emergency Management Agency. Federal Continuity Directive 1 Regular testing separates communication plans that work in reality from ones that only work on paper.

Connecting the Plan to IT Contingency Planning

A COOP addresses the organizational mission. An IT contingency plan addresses the information systems that support it. NIST Special Publication 800-34 provides the federal framework for linking these together, on the premise that a modern organization cannot sustain its essential functions if its networks, databases, and applications are down.7National Institute of Standards and Technology. Contingency Planning Guide for Federal Information Systems (SP 800-34 Rev 1)

NIST distinguishes several plan types that work together during a disruption. An Information System Contingency Plan focuses on recovering a specific system, either at the current location or an alternate one. A Disaster Recovery Plan focuses on relocating IT operations to an alternate location after a major disruption with long-term effects. A Business Continuity Plan focuses on sustaining business processes that are not mission essential, and is often activated alongside the COOP.

A COOP activation may trigger several of these plans at once. The COOP directs which essential functions run and where; the DRP and ISCPs handle bringing the technology behind those functions back online. When organizations draft these plans in isolation, so that the IT team writes the contingency plan while the operations team writes the COOP and nobody compares notes, the gaps surface at the worst possible time. NIST categorizes systems by impact level (low, moderate, high) so organizations can match IT recovery investment to the criticality of the functions those systems support.

Testing, Training, and Exercises

A continuity plan that has never been tested is really just a guess about what might work. FCD-1 requires agencies to validate their continuity capabilities through a structured program of tests, training, and exercises. The core requirements include an annual exercise for continuity personnel to demonstrate familiarity with plans and procedures, mandatory annual participation for headquarters continuity staff and components that support MEFs or PMEFs, and a biennial exercise for reconstitution and devolution teams.1Federal Emergency Management Agency. Federal Continuity Directive 1 – Federal Executive Branch National Continuity Program and Requirements

Exercises range in complexity. Tabletop exercises walk participants through a scenario in a discussion format and are relatively low-cost, useful mainly for identifying planning gaps. Functional exercises simulate an activation, with staff performing their continuity roles in real time but without physical relocation. Full-scale exercises involve actual movement of personnel and equipment to the alternate facility. Each type reveals different weaknesses. Tabletops expose flawed assumptions, functional exercises expose coordination breakdowns, and full-scale exercises expose logistical and infrastructure failures.

After-action reviews matter as much as the exercises themselves. Documenting what worked, what failed, and what needs revision is how each iteration of the plan gets stronger.

Activation, Devolution, and Reconstitution

Activation begins when a designated official determines that conditions are severe enough to shift from normal operations to continuity status. That decision rests on the nature of the disruption, its expected duration, and whether the primary facility and staff remain available. Notification systems then push alerts to employees, telling them their status and required actions. Continuity roster staff receive specific instructions to report to the alternate facility, begin telework, or stand by. If physical relocation is necessary, the Emergency Relocation Group moves to the pre-identified alternate site and designated successors assume their roles.

Devolution and reconstitution are commonly confused, and the distinction matters because they happen under very different conditions.

Devolution is the transfer of statutory authority and operational responsibility from an organization’s primary staff and facilities to pre-designated staff at a different location. It applies when the primary facility or leadership team is completely unavailable, not merely inconvenienced. The devolution site takes over essential functions using its own designated Emergency Relocation Group.8Federal Deposit Insurance Corporation. Continuity of Operations (COOP) Briefing Agencies must exercise their devolution procedures at least every two years.1Federal Emergency Management Agency. Federal Continuity Directive 1 – Federal Executive Branch National Continuity Program and Requirements

Reconstitution is the process of returning to normal, sustainable operations once leadership determines the organization can safely resume its regular posture. That might mean moving back into the original facility, establishing a new permanent home, or changing how certain functions are performed going forward. The reconstitution plan includes a structured handoff of authorities and records custody from the continuity team back to regular staff.8Federal Deposit Insurance Corporation. Continuity of Operations (COOP) Briefing

Sector-Specific Requirements Outside the Federal Executive Branch

FCD-1 and FCD-2 are mandatory for federal executive branch agencies. If you are outside that scope, different rules apply.

Financial Institutions

Banks and other regulated financial institutions face continuity planning requirements through their federal examiners. The Federal Financial Institutions Examination Council publishes a Business Continuity Management booklet that examiners use to evaluate how institutions manage risks to the availability of critical financial products and services.9Federal Financial Institutions Examination Council. FFIEC Information Technology Examination Handbook Business Continuity Management Examiners use the booklet as a benchmark during safety and soundness reviews, and institutions that fall short face supervisory consequences.

Healthcare Providers

The HIPAA Security Rule requires covered entities to maintain a contingency plan for electronic protected health information. The standard has three required implementation specifications: a data backup plan to create and maintain retrievable copies of ePHI, a disaster recovery plan to restore lost data, and an emergency mode operations plan to keep critical processes running while protecting ePHI security during a crisis.10Department of Health and Human Services. Security Standards – Administrative Safeguards Two additional specifications, testing and revision procedures and an applications/data criticality analysis, are addressable, meaning covered entities must implement them or document why an alternative approach provides equivalent protection.

Private-Sector Standards

Private organizations outside regulated industries are not federally required to maintain a COOP, but several recognized standards provide a framework. NFPA 1600, the Standard on Continuity, Emergency, and Crisis Management, was adopted by the Department of Homeland Security as a voluntary consensus standard for emergency preparedness. In 2024, NFPA consolidated it with related standards into NFPA 1660, the Standard for Emergency, Continuity, and Crisis Management: Preparedness, Response, and Recovery.11NFPA. NFPA 1660 Standard Development

Corporate officers and directors also carry a fiduciary duty of care that extends to disaster preparedness. The duty requires them to act as a reasonably prudent person would under similar circumstances, which includes making a reasonable effort to monitor and prepare for foreseeable risks. Courts apply the business judgment rule when evaluating executive liability, but that protection evaporates when the claim is based on a failure to act at all. A board that never considered continuity planning does not get the benefit of the doubt reserved for informed business decisions that simply turned out badly.

Where Most Plans Fall Apart

The common failure pattern is not a missing section or an unfilled template field. It is the gap between what the plan says and what people actually know how to do. An organization writes a 200-page plan, files it, and never exercises it. Staff listed on the continuity roster have never practiced their roles. Contact lists go stale because nobody updates them when people leave. The alternate facility was inspected once and has not been checked since the lease on its backup generator expired.

The other persistent weakness is treating continuity planning as a one-time project rather than an ongoing program. Essential functions shift as organizations evolve. Technology dependencies change. Key personnel move on. A plan written three years ago for a pre-cloud IT environment may be worse than useless, because it creates false confidence that the organization is prepared when it is not. The biennial review cycle required under federal directives exists precisely because plans decay. Organizations outside the federal mandate would do well to adopt the same discipline.