Skip to main content
Category: Resilience and Concentration

Continuity of Service

Also known as: Continuity of Services
Simply put

Continuity of service refers to a contractual expectation that services deemed important to a buyer are delivered without interruption, particularly across events such as contract expiration, transition, or handover to another provider. In this sense, it is a commitment written into an agreement obligating the provider to keep services running rather than letting them lapse. Note that the same phrase is also used in an unrelated employment-law sense, referring to an individual's uninterrupted period of employment, which is a distinct concept.

Formal definition

In the third-party and procurement context, continuity of service denotes a contractual provision under which a contractor recognizes that the services rendered are vital to the acquiring party and must be continued without interruption, including during transition periods. As reflected in U.S. federal acquisition clauses (for example FAR 52.237-3 and 48 CFR 2152.237-70), such clauses typically obligate the contractor to sustain performance and support an orderly handover to a successor provider to avoid service lapses. This clause-based obligation is narrower than an operational resilience program: it establishes a contractual commitment to uninterrupted delivery but does not, by itself, constitute business continuity or disaster recovery capability, nor does it guarantee that the provider possesses the operational means to meet the commitment. Its scope, enforceability, and specific transition obligations depend on the governing contract and jurisdiction; the federal clauses cited above apply to U.S. government procurement and are not universal across sectors or regions. Practitioners should distinguish this procurement usage from the separate employment-law meaning of "continuity of service" (or "continuous service"), which measures an employee's uninterrupted period of employment from their start date for benefit and entitlement purposes.

Why it matters

For organizations that depend on external providers for services they consider essential, the greatest exposure often arises not during steady-state delivery but at moments of transition: when a contract expires, when a provider is replaced, or when responsibilities are handed to a successor. A continuity of service clause addresses this exposure by making uninterrupted delivery a contractual obligation, so that a service does not simply lapse because an agreement ends or a provider exits. In U.S. federal acquisition, clauses such as FAR 52.237-3 express this expectation directly, stating that the contractor recognizes the services are vital and must be continued without interruption, including support for an orderly handover.

It is important, however, not to overstate what such a clause achieves. A continuity of service provision is a commitment on paper; it does not by itself establish that the provider has the operational capability to honor that commitment, and it is narrower than a business continuity or disaster recovery program. A buyer relying solely on this clause may find that contractual language obligates continued performance without guaranteeing the provider possesses the means to deliver it during a disruptive event. The clause's enforceability and specific transition obligations depend on the governing contract and jurisdiction.

Practitioners should also be alert to terminology overlap. The same phrase, "continuity of service" (or "continuous service"), carries an unrelated employment-law meaning, referring to an individual employee's uninterrupted period of employment measured from their start date for benefit and entitlement purposes. Conflating the two can create confusion in contracts, policies, and risk documentation, so the intended sense should be clear from context.

Who it's relevant to

Procurement and contract managers
Those drafting and negotiating agreements use continuity of service provisions to obligate providers to sustain delivery through contract expiration and transition. They should verify that the clause specifies transition and handover expectations clearly, and recognize that the clause commits the provider to uninterrupted delivery without, by itself, confirming the provider's operational ability to perform.
Third-party risk and resilience professionals
Practitioners assessing provider dependencies should treat a continuity of service clause as one contractual control, distinct from and narrower than a business continuity or disaster recovery program. They should confirm whether the provider actually possesses the operational means to meet the commitment rather than relying on the contractual language alone.
Federal and public-sector acquisition teams
Teams operating under U.S. government procurement encounter this obligation through clauses such as FAR 52.237-3 and 48 CFR 2152.237-70, which state that services vital to the acquiring party must be continued without interruption and support orderly handover. These clauses apply to U.S. government procurement and should not be assumed to apply universally across other sectors or jurisdictions.
Legal and compliance reviewers
Reviewers should distinguish the procurement usage of the term from the separate employment-law meaning of "continuity of service" (or "continuous service"), which measures an employee's uninterrupted period of employment from their start date for benefit and entitlement purposes. Clarifying which sense applies in a given document helps avoid confusion in contracts and policies.

Inside Continuity of Service

Service Continuity Obligations
Contractual commitments under which a third party agrees to maintain the availability of a service at defined levels, often expressed through service level agreements (SLAs), recovery time objectives, and recovery point objectives. These obligations typically address expected availability but may not, by themselves, guarantee performance during severe or prolonged disruptions.
Business Continuity Planning (BCP)
The third party's arrangements for sustaining critical business functions during a disruption. Continuity of service depends on a supplier's BCP being adequate, tested, and aligned with the customer's tolerance for outage, but a customer typically has limited direct visibility into how robust a supplier's plan actually is.
Disaster Recovery (DR)
The narrower technical capability to restore IT systems, data, and infrastructure after a disruptive event. DR is a component of, but distinct from, business continuity; DR addresses technology restoration while BCP addresses sustaining the broader business function. Continuity of service may depend on both.
Concentration and Dependency Considerations
The degree to which continuity is exposed to concentration risk, single-source dependency, or a single point of failure. These are distinct: concentration risk arises from reliance on a small number of providers, single-source dependency from reliance on one supplier for a given input, and a single point of failure from one component whose loss halts the service. Continuity assessments typically examine each separately.
Nth-Party Continuity Exposure
Continuity risk arising from the third party's own subcontractors and downstream providers (fourth-party and beyond). Visibility beyond the first tier is often limited, so continuity commitments made by a direct third party may rest on dependencies the customer cannot directly assess or influence.
Exit and Transition Arrangements
Provisions such as exit plans, data portability, transition assistance, and substitutability of the provider that support continuity when a relationship ends or a supplier fails. These address the ability to move to an alternative provider rather than the in-service resilience of the current one.
Testing, Attestation, and Verification
Evidence that continuity arrangements function, ranging from supplier self-attestation to independently verified test results. An attestation that plans exist is not the same as independent verification that they work, and point-in-time evidence can become stale as the supplier's environment changes.

Common questions

Answers to the questions practitioners most commonly ask about Continuity of Service.

Is continuity of service the same as disaster recovery?
No. Continuity of service is the broader objective of maintaining delivery of critical services from a third party through disruption, spanning people, processes, facilities, technology, and supplier dependencies. Disaster recovery is typically a narrower, IT-focused discipline concerned with restoring systems, data, and infrastructure after an outage. Disaster recovery is generally a component that supports continuity of service, not a synonym for it; a supplier can have credible technical recovery capabilities yet still fail to maintain service if operational, staffing, or upstream dependencies are not addressed.
If a supplier provides a business continuity plan, does that guarantee continuity of service?
Not on its own. A documented plan is an attestation of intent and design, not evidence that service will actually be sustained under real conditions. Plans can be outdated, untested, or scoped to scenarios that differ from an actual disruption. Independent verification, evidence of exercises or invocations, and validation that the plan covers the specific services you rely on typically provide more assurance than the existence of a document. A plan also does not, by itself, confirm that the supplier's own critical dependencies are covered.
How should continuity of service expectations be reflected in contracts?
In many programs, continuity expectations are addressed through provisions such as required recovery objectives, maintenance and testing of continuity plans, notification obligations during disruption, rights to review or audit continuity evidence, and remedies for failure to sustain service. The specific terms typically depend on the criticality of the service and the assessed risk tier. Contractual language sets expectations but does not by itself ensure performance, so it is generally paired with ongoing monitoring and evidence review.
How do you assess continuity of service beyond the direct third party?
Direct assessment usually covers the immediate supplier, but continuity can depend on fourth-party or Nth-party providers whose failure could interrupt the service. Visibility beyond the first tier is often limited and typically relies on the supplier disclosing its own critical dependencies and their continuity arrangements. Where feasible, programs may map concentration risk, single-source dependencies, and single points of failure across tiers, while recognizing that assurance generally weakens the further you move from the direct relationship.
How often should continuity of service arrangements be reviewed?
Point-in-time evidence can become stale as a supplier's operations, dependencies, and staffing change, so continuity arrangements are typically reviewed on a recurring basis, often aligned to the service's criticality or risk tier. Reviews may also be triggered by events such as a supplier's own disruption, significant changes in its operating model, or changes in your reliance on the service. The appropriate cadence generally varies by program and by how critical the service is.
What is often overlooked when relying on a supplier's continuity capabilities?
Common gaps include treating recovery of technology as equivalent to sustaining the full service, assuming an untested plan will perform under actual conditions, and overlooking upstream or Nth-party dependencies. Continuity of service also does not inherently address other risk domains such as information security, financial stability, or geopolitical exposure unless those are separately assessed. Concentration risk and single points of failure that sit outside the direct supplier are also frequently missed because visibility into those layers is often limited.

Common misconceptions

Business continuity and disaster recovery are the same thing, so a supplier with a DR plan has continuity covered.
They are distinct. Disaster recovery typically addresses restoration of IT systems and data, while business continuity addresses sustaining the broader business function. A supplier may have technical recovery capability yet still lack the operational, staffing, or process arrangements needed to keep delivering the service.
An SLA guaranteeing high availability ensures continuity of service.
An SLA is a contractual commitment, often with associated remedies or credits, but it does not itself guarantee that the service will remain available during severe disruption. Remedies compensate for failure rather than prevent it, and continuity ultimately depends on the supplier's underlying resilience and dependencies.
A supplier's attestation that it has a tested continuity plan means the plan will work.
Self-attestation confirms a plan is claimed to exist and to have been tested, but it is not independent verification of effectiveness. Attestations are self-reported, may not reflect current conditions, and can become stale as the supplier's systems, staff, and subcontractors change.

Best practices

Distinguish and separately assess business continuity and disaster recovery in supplier evaluations, confirming both that critical functions can be sustained and that supporting technology can be restored within tolerances that match your risk tier.
Where feasible, seek independent verification or evidence of continuity testing rather than relying solely on supplier self-attestation, and treat point-in-time evidence as time-limited by reassessing on a defined cycle.
Analyze concentration risk, single-source dependency, and single point of failure as distinct exposures, and map how the supplier's own subcontractors and downstream providers could affect continuity beyond the first tier.
Translate continuity expectations into specific contractual terms, including availability commitments, recovery objectives, testing rights, and reporting obligations, while recognizing that contractual remedies compensate for rather than prevent disruption.
Establish exit, transition, and substitutability arrangements, such as data portability and transition assistance, so that continuity can be maintained if a supplier fails or the relationship ends.
Calibrate the depth of continuity assessment and monitoring to the criticality of the service and the applicable regulatory expectations, which may differ across regions and sectors.
Promotional banner for the Penetration Report Template Kit