For NIA-aligned organisations in Qatar

Business continuity software for NIA-aligned organisations in Qatar

The platform Qatari banks, telcos and public-sector bodies use to run NIA business-continuity evidence and a full ISO 22301 BCMS from one dataset. Native §8.4.4 plans. PDPPL-aware incident timelines. Audit-ready PDFs in one click.

Who it’s for

Built for the Qatari continuity team

Qatar’s continuity obligations arrive from two directions at once — NIA’s business-continuity expectations and a privacy law with a hard notification clock. The platform is shaped around running both from one dataset.

Qatari bank

Head of Continuity

Produce NIA business-continuity evidence and an ISO 22301 BCMS without maintaining two parallel programmes and two sets of documents.

  • One dataset, two frameworks
  • §8.4.4 native fields, §8.5 activation log
  • Evidence an examiner can sample

Telco / energy

BCM Manager

Prove that recovery plans work across a large, distributed workforce — and that the people named in them can actually be reached when it matters.

  • Call-tree drills with independent verification
  • Exercise programme with coverage rollup
  • Improvement actions traced to closure

Public sector

CISO

Move continuity off SharePoint and Excel into something an information security committee will approve, with data isolation you can describe in one sentence.

  • Schema-per-tenant data isolation
  • 5-role RBAC with department scoping
  • Audit log on every mutation
What’s different

Four things no peer ships

Mechanics, not slideware — each of these is exercised by the integration test suite.

Schema-per-tenant data isolation

Every customer gets their own Postgres schema, entered via SET LOCAL search_path inside a transaction. Cross-tenant access is impossible by construction — different schemas, not row-level filters. Castellan, Fusion, Origami, LogicManager, Quantivate and 6clicks all use row-level. For a committee that wants to see the schema list, that is the difference between a yes and a no.

MTPD derived, not typed

Maximum tolerable period of disruption is calculated from the impact-over-time matrix and each category's intolerability threshold, so it moves when the analysis moves. Peer platforms ask an analyst to type a number into a box, which is why MTPD and RTO so often contradict each other in an audit sample.

Call-tree drills that verify independently

When a relay reports reaching someone, the platform contacts that person separately to confirm it happened. Self-reported cascade tests are the norm across the market; independent verification turns a drill into evidence, and surfaces the stale phone number before the incident does rather than during it.

Programme coverage rollup

The annual exercise programme tracks which continuity themes have genuinely been exercised. Passing and partial exercises contribute their theme tags to the programme's union; failed ones do not. The view shows covered versus required in real time, instead of a spreadsheet reconstructed the week before a review.

Regulatory fit

Where BCMStack sits in Qatar

An honest scope statement is more useful than a compliance claim. Here is what the platform does and does not cover.

NIA v2.1 — continuity domain

Continuity planning, testing and incident-response evidence in NIA-shaped form. NIA is a broad cybersecurity framework; BCMStack covers its continuity surface, not its network or application domains.

ISO 22301 — full BCMS

The complete clause-8 lifecycle: BIA, strategy, plans with native §8.4.4 fields, §8.4.5 phased recovery, §8.5 activation evidence, and the ISO 22398 exercise programme.

PDPPL — the 72-hour clock

Structured PII and exposure fields on incidents, with configurable notification timers that escalate before the duty to the NDPO lapses. The platform records and warns; it does not file for you.

Pricing

Published, not “contact sales”

$30K–60K per year

Mid-market annual contract value, scaling with users and modules. Enterprise BCM platforms typically land at $80K–250K once required platform seats and implementation services are included — and quote only after a sales call.

Implementation

Live inside a quarter

Weeks 1–2

Foundation

  • Tenant provisioned, SSO discussion
  • Departments, sites, vendors, applications imported
  • Roles mapped to your governance model

Weeks 3–6

Analysis & plans

  • BIA with derived MTPD per process
  • Plans rebuilt in native §8.4.4 shape
  • Dependencies mapped to apps and vendors

Weeks 7–12

Validate

  • First exercise run on the platform
  • Call-tree drill with verified contact
  • Programme coverage and evidence pack
FAQ

Frequently asked questions

What business continuity software do organisations in Qatar use?

+

Qatari organisations subject to the NIA framework need business continuity software that produces NIA-shaped evidence alongside a working ISO 22301 BCMS, rather than a generic BCM tool. BCMStack is built for that overlap: ISO 22301 §8.4.4 plan fields are discrete database columns rather than free text, business impact analysis derives MTPD automatically from impact-tolerance thresholds instead of asking someone to type a number, every plan activation is captured as a structured §8.5 log entry, and call-tree drills verify contact independently rather than trusting a relay's self-report. Each customer's data sits in its own database schema, not a shared table with tenant filters.

Does BCMStack map to the Qatar NIA framework?

+

BCMStack covers the business-continuity and incident-management surface of NIA v2.1 — the continuity planning, testing and incident-response evidence NIA expects — and pairs it with a full ISO 22301 BCMS in the same dataset, so you are not maintaining two parallel programmes. NIA is a broader cybersecurity framework; BCMStack does not attempt to cover its non-continuity domains. Many Qatari organisations run BCMStack for continuity alongside a wider GRC platform for the rest.

How does BCMStack handle PDPPL and the 72-hour breach clock?

+

Incidents carry structured PII and data-exposure fields, an auditable status history, and configurable notification timers. A Qatari organisation running the PDPPL 72-hour notification duty to the NDPO can arm that clock at classification time and receive escalating warnings before it lapses, with the same engine that drives regulator SLA timers elsewhere in the platform. BCMStack records and escalates the obligation — it does not file on your behalf.

Where is BCMStack data hosted for Qatari customers?

+

Each customer gets a dedicated Postgres schema, with EU jurisdiction as the default for the GCC region and file storage on Cloudflare R2 under EU jurisdiction. Cross-tenant access is impossible by construction — separate schemas, not row-level filters. In-Qatar data residency is not shipped today; for customers with an explicit residency obligation we provision a dedicated database project in the closest supported region. Raise it before you sign so we can be precise about what is and is not available.

Does BCMStack support Arabic?

+

Not yet. The interface and exports are English today. Arabic UI with right-to-left layout is on the roadmap and is a known requirement for parts of the Qatari public sector — if bilingual output is a procurement condition for you, tell us during evaluation rather than after, because it changes the timeline.

Can BCMStack replace SharePoint and Excel for BCM in Qatar?

+

That is the most common migration we see. Process and vendor inventories import by CSV, business continuity plans are rebuilt in the native ISO 22301 §8.4.4 shape, and the first exercise usually runs on the platform inside the first month. The change most teams notice is not the plan editor — it is that evidence stops being assembled by hand the week before an audit.

Book a 20-minute demo

Tell us your organisation, which frameworks you answer to, and where your continuity workflow lives today. We’ll show you the platform working against a representative Qatari dataset and answer the questions your information security committee will ask.

Request a demo

We aim to respond within one business day.