Posted on Aug 10, 2026
Every 911 center is one bad day away from finding out how good its continuity plan really is.
A wildfire jumps a ridge line and the evacuation zone now includes your dispatch floor. A hurricane takes down the fiber path feeding your building. A water main breaks two floors
above the comm center. A ransomware incident locks up the county network on a Friday
afternoon. None of these scenarios are hypothetical, and none of them care whether your continuity of operations plan is current.
What has changed is what a good answer looks like. In the legacy 911 world, continuity planning
was largely a physical problem solved with physical answers: a backup building, a diesel
generator, a set of alternate trunk lines, and a binder of phone numbers. Next Generation 911
changes the math. When call delivery rides on an IP-based Emergency Services IP Network
rather than dedicated copper into one specific building, the location of your call takers becomes
far less important than the design of your network and the quality of your routing policies.
That is a genuine operational upgrade, but it is not automatic. Resilience in an NG911 environment is something you architect, document, and test. This guide from NGA walks through what actually fails during a disaster, what modern continuity looks like when it works, and how 911 authorities and PSAP directors can build a continuity plan that holds up on the worst day of the year.
Legacy 911 architecture created a hard dependency between a call and a building. Selective
routers delivered calls over dedicated trunks to a specific PSAP at a specific address. If that
address became unusable, the options were limited and slow: activate a backup center, ask the
carrier to reroute trunks, or fall back to a ten-digit administrative line and hope the public found it.
NG911 decouples the call from the building. Calls are routed by policy rather than by hard-wired
circuit. An i3-based system uses functional elements such as the Emergency Call Routing
Function and the Policy Routing Function to decide, in real time, where a call should land. That
decision can account for time of day, current call volume, PSAP status, or an explicit continuity
condition that a supervisor has activated.
In practice, this means a PSAP can be evacuated without the public losing access to 911. The
calls keep arriving. They simply arrive somewhere else, or at someone else's workstation.
NENA's guidance on virtual PSAP management makes this point directly: where an agency has
virtualized its call handling, continuity of operations can mean continuing to function off site
rather than relocating an entire workforce to a second physical facility.
The catch is that policy-based rerouting only works if the policies exist before the emergency,
the receiving agencies have agreed to accept the traffic, and someone has tested the whole
chain end to end. Capability on paper is not the same as capability under load.
State COOP templates, including the planning guides published by state 911 offices in Wisconsin and Nebraska, tend to converge on the same core scenarios. They are worth thinking about separately because each one breaks something different.
traffic is severed. A single backhoe, a washed-out bridge carrying conduit, or a failed
aggregation point can do it. Diversity of physical path matters more here than diversity of
building.
A useful test of any plan: pick one of the four, then trace exactly who does what in the first
fifteen minutes. If the answer depends on one person's memory or one vendor's phone number, the plan has a gap.
The clearest recent illustration comes out of western North Carolina. When Hurricane Helene
devastated the region in 2024, a 911 center in Madison County lost connectivity entirely.
Because the state had already moved to a shared ESInet, the state 911 Board was able to
reroute that county's 911 calls to another call center roughly 220 miles away, and keep them
there for about a month while local infrastructure was rebuilt. Connectivity back into the ESInet
was later restored using a broadband public safety network connection.
Two details in that story matter more than the headline. First, the rerouting was possible
because the architecture already supported it. Nobody built that capability during the storm.
Second, the receiving PSAP was far enough away to be outside the disaster footprint. North
Carolina's 911 Board has since formalized this thinking in its resiliency guidance, pairing PSAPs
with partner agencies in different regions on the logic that a nearby backup is worth very little
when the event is regional.
The state has also layered in lower-tech redundancy that tends to get overlooked in
modernization conversations, including satellite phones and rugged push-to-talk radios
distributed to PSAPs ahead of hurricane season. Resilience is not only an architecture question.
Sometimes it is a question of whether the supervisor on duty can reach the neighboring county
when everything else is dark.
The most interesting development in this space pushes the concept further. In February 2026,
the North Carolina 911 Board, the Washington D.C. Office of Unified Communications, and
Johnston County 911 completed a first-of-its-kind proof of concept that delivered live 911 calls
across state lines.
The exercise validated three things simultaneously: policy-based call routing, interoperability
between separate ESInets, and continuity of operations spanning two jurisdictions hundreds of
miles apart. In other words, a catastrophic regional event no longer has to be answered from
inside the same region, or even the same state.
That is a meaningful shift in how 911 authorities can think about mutual aid. The traditional model assumed a neighboring county would absorb overflow. An interoperable model allows a
state to build relationships with distant partners chosen specifically because they share no
common risk profile, no common weather system, and no common power grid.
Federal attention has followed the same trend line. Major 911 outages affecting multiple states
have increased as agencies have begun transitioning to NG911 platforms, and in July 2026 the
FCC adopted updated reliability rules aimed squarely at that problem.
For continuity planners, the substance matters more than the rulemaking history. The direction
of travel includes expectations around automatic switchover to geographically diverse facilities,
interoperability between ESInets, clearer definitions of which providers are accountable for
critical NG911 pathways, and more visibility for state and local 911 authorities into the reliability
of the systems they depend on. There is also a process by which authorities can raise identified
deficiencies and receive a response within a defined window.
The practical takeaway is that geographic diversity and documented failover are no longer
differentiators that sophisticated agencies pursue voluntarily. They are becoming the baseline
expectation, and agencies that can evidence them will be in a considerably better position
during their next contract cycle or after-action review.
Most PSAPs have a COOP document. Fewer have one that reflects current architecture, current
staffing, and current partner agreements. The following areas are where plans most often drift
out of date.
hazards in your region. If a single hurricane, wildfire complex, earthquake fault, or grid
operator can affect you and your backup at the same time, you need a more distant partner.
telecommunicators can take calls from an alternate site or from home, verify it on a normal Tuesday. Test credentials, headsets, CAD access, mapping, recording, supervisor visibility, and bandwidth. Recording and quality assurance obligations do not pause during a disaster.
notification, and post-incident support belong in the plan alongside the network diagrams.
revision. NENA's operational guidance emphasizes exactly this loop of status reporting,
after-action review, and mitigation of future disruptions.
The agencies that came through recent disasters with 911 service intact were not lucky. They
had made specific decisions in advance: shared or regional ESInet architecture, geographically
separated core components, pre-negotiated partner agreements, and staff who had practiced
the failover before they needed it.
For 911 authorities evaluating NG911 systems, that suggests a different set of procurement
questions. Not just whether a platform is i3 conformant, but where its core elements physically
live, how failover is triggered and how quickly, whether it can hand traffic to a neighboring
ESInet, how remote call taking is secured and licensed, and what the provider is contractually obligated to do at three in the morning during a regional emergency.
Continuity of operations has quietly become one of the strongest arguments for NG911
modernization. Better location data and multimedia capability get most of the attention, and
they deserve it. But the ability to lose a building and not lose 911 is the kind of capability that
only proves its value once, and by then you cannot go back and buy it.
If your continuity plan has not been opened since your last accreditation cycle, that is the place
to start. Pull it out, read it against the system you actually operate today, and find the gap
before the weather does.
Contact NGA to learn more about their NG911 platform and how it provides the foundation for the next generation of emergency communications technology.