All frameworks
Certifiable standardGlobal

ISO 22301

ISO 22301:2019

ISO 22301 specifies requirements for a business continuity management system (BCMS): understanding what must not stop, planning for disruption, and exercising the plans. It is certified in the same three-year cycle as other ISO management-system standards.

Who it reaches

  • Organisations whose customers or regulators require demonstrated continuity capability: financial services, critical infrastructure, outsourcers.
  • Companies that want DORA and NIS2 continuity duties carried by a certified system.
  • Suppliers asked for a continuity certificate in tenders.

What the audit checks

  1. 01Stage 1 and Stage 2 certification audits, annual surveillance, recertification in year three.
  2. 02The auditor checks the business impact analysis, risk assessment, strategies, plans, exercise records and the management-system clauses.

A typical engagement

Durations are ranges seen in practice for a mid-sized organisation starting from a working security function; a first-time programme runs longer, a mature one shorter.

PhaseWeeks
Scope and business impact analysis3 to 6
Risk assessment and continuity strategies2 to 6
Plans, procedures and exercises6 to 16
Internal audit, management review, certification4 to 10

Evidence to have ready

  • Business impact analysis with recovery objectives
  • Continuity risk assessment
  • Continuity strategies and resource requirements
  • Business continuity plans and incident response structure
  • Exercise and test records with lessons learned
  • Supplier continuity arrangements
  • Awareness and training records
  • Internal audit and management review

Questions people ask

How is ISO 22301 different from the continuity control in ISO 27001?
ISO 27001 requires ICT readiness for business continuity as one control. ISO 22301 is a whole management system for continuity of the business, not only its information systems.

Go deeper