Management system
ISO 22301 — Business Continuity Management
Continuity planning fails in one of two ways: a plan that was never exercised, or a plan built on an assumption about recovery time that nobody checked with the business. ISO 22301 exists to prevent both.
- Standard
- ISO 22301:2019
- Starts from
- Business impact analysis
- Clause structure
- Annex SL
- Objectives set
- RTO · RPO
What ISO 22301 requires
ISO 22301:2019 specifies a business continuity management system — a BCMS. It starts from a business impact analysis: which activities deliver your products and services, what happens as each hour of disruption passes, and how long each can be interrupted before the damage is unacceptable. That analysis produces the recovery objectives everything else is built against.
From there the standard requires you to select continuity strategies proportionate to those objectives, document plans and response structures, and — the requirement organisations most often under-do — exercise and test them, then feed what you learn back in.
ISO 22301 shares the harmonised clause structure used by ISO/IEC 27001 and ISO 9001. Context, leadership, planning, support, operation, evaluation and improvement are common ground, so an organisation already running an ISMS is adding a discipline to an existing management system rather than starting a second one.
What it will ask of you
Most of the effort here is not the security team’s. It is time from the people who actually run the activities, which is the thing to plan for.
A business impact analysis
Which activities deliver your products and services, what they depend on, and what happens as each hour of disruption passes. Everything else is built on this.
Recovery objectives somebody signed
RTOs and RPOs agreed by the people who own the consequences, not assumed by IT. An assumed recovery time is the most common finding in this standard.
Plans that name people
Response and recovery plans with named roles and explicit decision authority — a plan that names a job family has not decided who picks up the phone.
Exercises, and honest records of them
The requirement organisations most often under-do. An exercise that surfaced nothing was not an exercise, and the record should say what did not work.
Why organisations hold it
- Customer contracts and tenders increasingly require demonstrable continuity arrangements, not a statement that you have some.
- It replaces an assumed recovery time with one agreed by the business and tested against reality.
- It supports ISO/IEC 27001 directly — availability is an information security property, and Annex A expects continuity to be addressed.
- Exercises surface the dependencies nobody documented, which is usually the finding with the highest value.
Where we come in, and where we stop
As with ISO/IEC 27001, an accredited certification body assesses the system and we may not — the same clause of ISO/IEC 17021-1 applies.
Ours
- Scope, context and the obligations the BCMS has to satisfy
- Running the business impact analysis with the activity owners
- Disruption risk assessment, aligned to your existing risk method
- Continuity strategy with costed options, and the plans themselves
- Designing and facilitating the exercise programme
- Internal audit, management review and certification readiness
An accredited certification body
- Stage 1 and Stage 2 assessment
- Issuing the certificate and running surveillance
How we build it
As with ISO/IEC 27001, certification is assessed by an independent accredited certification body over a Stage 1 and Stage 2 audit.
- 01Scope and contextWhich products and services the BCMS covers, and the obligations — regulatory, contractual, customer — it has to satisfy.
- 02Business impact analysisPrioritised activities, their dependencies, and agreed recovery time and recovery point objectives, signed off by the people who own the consequences.
- 03Risk assessmentThe disruption scenarios that could realistically stop those activities, assessed against the same method as your information security risk work.
- 04Continuity strategy and plansOptions chosen against the recovery objectives and their cost, then written into response and recovery plans with named roles and decision authority.
- 05Exercising and testingFrom tabletop walkthroughs to live tests, with the records the standard requires and an honest account of what did not work.
- 06Internal audit and readinessInternal audit, management review and the evidence pack for a certification body, when certification is the goal.
What you get from us
- Business impact analysis with agreed RTOs and RPOs
- Disruption risk assessment aligned to your existing risk method
- Continuity strategy with costed options
- Response and recovery plans that name people, not job families
- Exercise programme, exercise records and lessons-learned actions
- Internal audit and certification readiness where certification is in scope
Common questions
Do we need ISO 22301 if we hold ISO 27001?
Not necessarily. ISO/IEC 27001 requires you to address continuity for information security, which for many organisations is enough. Pursue ISO 22301 when a customer or regulator asks for it specifically, or when disruption of your operations — not just your data — is the risk that matters.
Can it be certified?
Yes, by an accredited certification body, on the same Stage 1 and Stage 2 pattern as ISO/IEC 27001. Some organisations implement it without certifying and use it purely as an internal discipline.
How is this different from disaster recovery?
Disaster recovery is largely about technology restoration. ISO 22301 covers the business: people, premises, suppliers, communications and decision-making. IT recovery is one input to it, and on its own is the commonest gap we find.
How long does implementation take?
Four to eight months for a mid-sized organisation. The business impact analysis is the long pole, because it needs time from the people who run the activities rather than from the security team.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
SOC 2 Type 2 Readiness
Evidence that your controls ran for months, not that they existed on a date — the report enterprise procurement usually means.
ISO/IEC 27701 — Privacy Information Management
Turn privacy from a policy document into a management system, with the records a regulator or an enterprise buyer will ask to see.
Related insights
Certification
Stage 1 and Stage 2: what each audit tests, and why Stage 1 is not a rehearsal
One checks that you are ready to be audited. The other is the audit. Both feed the certification decision.
Certification
Major and minor nonconformities, and the six-month clock behind one of them
A minor is a finding. A major starts a clock — and if it runs out, Stage 2 happens again.
Certification
Why management systems fail in year two, not year one
Everyone survives the certification audit. The surveillance audit is the honest one.