Certifiable standardGlobal
ISO 22301
ISO 22301:2019
ISO 22301 specifies requirements for a business continuity management system (BCMS): understanding what must not stop, planning for disruption, and exercising the plans. It is certified in the same three-year cycle as other ISO management-system standards.
Who it reaches
- Organisations whose customers or regulators require demonstrated continuity capability: financial services, critical infrastructure, outsourcers.
- Companies that want DORA and NIS2 continuity duties carried by a certified system.
- Suppliers asked for a continuity certificate in tenders.
What the audit checks
- 01Stage 1 and Stage 2 certification audits, annual surveillance, recertification in year three.
- 02The auditor checks the business impact analysis, risk assessment, strategies, plans, exercise records and the management-system clauses.
A typical engagement
Durations are ranges seen in practice for a mid-sized organisation starting from a working security function; a first-time programme runs longer, a mature one shorter.
| Phase | Weeks |
|---|---|
| Scope and business impact analysis | 3 to 6 |
| Risk assessment and continuity strategies | 2 to 6 |
| Plans, procedures and exercises | 6 to 16 |
| Internal audit, management review, certification | 4 to 10 |
Evidence to have ready
- Business impact analysis with recovery objectives
- Continuity risk assessment
- Continuity strategies and resource requirements
- Business continuity plans and incident response structure
- Exercise and test records with lessons learned
- Supplier continuity arrangements
- Awareness and training records
- Internal audit and management review
Questions people ask
- How is ISO 22301 different from the continuity control in ISO 27001?
- ISO 27001 requires ICT readiness for business continuity as one control. ISO 22301 is a whole management system for continuity of the business, not only its information systems.