Maturity · UAE National Business Continuity Management Standard
Your business continuity measured against the UAE framework, translated into a costed action plan.
10 themes, a 5-level scale. And the action that moves each level to the next.
The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.
Maturity · UAE National Business Continuity Management Standard
10 themes, 5-level scale.
Nordhavn Industries
53 / 100
They measure their maturity with Datamensio
An example
This could be your situation.
Take one company as an example: three sites, three spreadsheets, no shared answer.
Nobody can consolidate.
Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.
Three weeks, a single base.
One AE/SCNS/NCEMA 7000:2021, Business Continuity Management Standard (United Arab Emirates) assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.
Two costs avoided before being committed.
A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.
What it saved them
- 3sites measured on the same base, instead of three questionnaires to reconcile
- 2duplicate actions caught before the spend
- 1committee report, with no manual rework
These figures are an example. They could be yours.
The standard imposes processes. Datamensio says where you stand.
01
The framework is already written
Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.
02
The score lands the same day
Online, by self-assessment link or in interview. Theme by theme, comparable over time.
03
The gap becomes a costed plan
Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.
04
Progress can be demonstrated
Campaign after campaign, against your target and against your own past. That is what your board asks for.
The maturity scale
One level, the next, and the action that links the two.
This mechanism, a level, the level above, and the action linking the two, is what turns a finding into a trajectory.
Does the exercise programme cover critical processes and result in tracked corrective actions?
- N1
No exercise has been conducted. Plans exist on paper and have never been tested.
- N2
Occasional exercises take place, often using the same scenario. Findings are discussed in the meeting but do not lead to formal follow up.
- N3
An annual programme covers the critical processes. Each exercise is followed by a report and corrective actions assigned to an owner.
- N4
Scenarios vary and include the crisis cell and critical suppliers. Corrective actions are closed on time and verified during the next exercise.
- N5
The programme is revised every year in light of incidents, business changes and national scenarios. Lessons feed updates to plans and the impact analysis, with traceability of revisions.
Action to move from L2 to L3
Set an annual exercise calendar covering every critical process, appoint a reporting lead for each exercise to produce a report within fifteen days, and put corrective action follow up on the agenda of the quarterly steering committee.
« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »

Director, CCI 94CCI Île-de-France
« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »

Maja SucekChief Operating Officer, Interreg Danube
Rarely on its own
Frameworks combine. Put several together to cover your business, or have the AI write yours.
Take your first measurement
What this framework covers
The UAE National Business Continuity Management Standard is the reference framework published by the National Emergency Crisis and Disasters Management Authority (NCEMA). It applies to federal and local government entities, as well as private organisations operating activities deemed sensitive or critical to the country. It follows the logic of the continuity lifecycle: policy and governance, business impact analysis, risk assessment, recovery strategies, documented plans, an exercise programme, review and improvement. Compliance is checked through audits conducted or mandated by the authority, with rating levels assigned to entities.
In practice, the set-up is hard to steer because it relies on data that ages quickly. Was the impact analysis redone since the last reorganisation, or does it date back to the file prepared for the previous audit? Are the maximum tolerable periods of disruption validated by business owners, or set by the continuity team in the absence of a response? Do exercises cover scenarios that are genuinely plausible for the site, or does the same scenario get repeated every year because it is easy to organise? These gaps do not show up in a binder of up to date plans.
One point of context comes up often: the UAE standard and ISO 22301 share a similar architecture, but they do not substitute for one another. The national framework adds its own expectations, notably the link to national crisis and emergency management arrangements, notification channels to the authority, and consideration of local risks. An organisation certified to ISO 22301 has a solid foundation, but has not thereby demonstrated alignment with UAE requirements. The reverse is also true.
The maturity assessment answers a different question from an audit. An audit concludes with a gap or a compliance finding against a requirement. The assessment places each practice on a progressive scale and indicates the action that moves it to the next level. For a group present across several sites or entities in the UAE, this view allows business units to be compared against each other, progress to be measured from one campaign to the next, and investment priorities to be decided.
Within Datamensio, the framework is ready to use. You can adapt it to your context: the AI adjusts the themes, questions and levels, or builds a variant from your own documents, continuity policy, existing plans or exercise reports.
Reference standard: AE/SCNS/NCEMA 7000:2021, Business Continuity Management Standard (United Arab Emirates)
The themes assessed
Continuity policy and governance
Existence of a policy approved by management, declared scope, roles and responsibilities, steering committee, resources allocated to the programme.
Regulatory framework and relationship with the authority
Identification of applicable obligations, designated points of contact, notification channels, follow up on recommendations from previous assessments.
Business impact analysis
Inventory of critical processes, maximum tolerable periods of disruption, recovery objectives, internal dependencies, sign off by process owners.
Risk assessment and scenarios
Identification of threats relevant to the site and sector, scenarios selected, likelihood and impact, link to identified national risks.
Continuity and recovery strategies
Options chosen by process, fallback sites, system redundancy, backup human resources, trade off between cost and recovery time.
Continuity and crisis management plans
Content and accessibility of plans, activation procedures, trigger thresholds, crisis cell, decision and deputisation chain.
Supply chain and critical suppliers
Mapping of essential suppliers, contractual continuity requirements, identified alternatives, verification of third party arrangements.
Crisis communication
Crisis directory, prepared messages, designated spokespersons, information to employees, customers and authorities, backup means if usual channels fail.
Training, awareness and exercises
Annual exercise programme, variety of scenarios, management participation, reports, follow up on corrective actions from exercises.
Monitoring, review and improvement
Programme performance indicators, internal audits, management review, updates after an incident or reorganisation, version history.
A short version of the framework is available for the online self-assessment.
Frequently asked questions
Does this assessment deliver compliance with the UAE standard?
No. Datamensio measures the maturity of your practices and prepares for the assessment carried out by the authority or a mandated body. You get a score by theme, the list of gaps and the action plan to address them, not a certificate.
What is the difference between this assessment and a compliance audit?
An audit checks whether a requirement is met and concludes with compliant or non compliant. The assessment places each practice on a five level scale and indicates the action that moves it up a level. The two are complementary: the assessment prepares, the audit validates.
We are already certified to ISO 22301. Does this assessment add anything?
Yes. The two frameworks share a similar architecture, but the UAE framework adds its own expectations, notably the link to national crisis management arrangements and notification channels to the authority. The assessment shows what is already covered by your management system and what still needs to be built for the local scope.
How long does the assessment take?
The short version can be completed in a single session by a continuity manager. The full version, run collaboratively, spans one to two weeks: most of the time goes into gathering input from process owners, IT and sites.
Can the framework be adapted to our organisation?
Yes. You can amend the questions, level wording and themes, or add your own. The AI generates a variant from your continuity policy and existing plans, and refines the levels using the CMMI method. The framework is yours.
Can several sites or entities be compared?
Yes. The assessment can be run as a campaign across as many entities as needed, with a benchmark between business units and against previous campaigns. Consolidated gaps feed a cross entity roadmap rather than a per site action plan.
What happens after the assessment?
The gap between the score obtained and the target generates the action plan. The AI groups it into a prioritised roadmap, and the service catalogue provides a solution for each item, with cost, timeframe and expected impact on the score. Reporting to management and entities takes place in a collaborative space branded to you.
Where is the data hosted?
In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.





