Certifiable standard

ISO 22301

ISO 22301 is the international standard for business continuity management. It defines the requirements for a Business Continuity Management System (BCMS) that prepares an organisation for disruptions — from system failures and cyberattacks to the loss of a site — and ensures key processes are recovered within an acceptable time.

Start assessmentRead about the standard
31
controls in Guardiso
27
free-test questions
PL · EN
two languages

What is ISO 22301?

ISO 22301 specifies requirements for establishing, implementing, maintaining and continually improving a Business Continuity Management System (BCMS). The purpose of the system is to protect the organisation against disruptions, reduce their likelihood, prepare an effective response, and recover prioritised activities within a planned time and to a planned level. The current edition is ISO 22301:2019 (second edition, replacing the 2012 version); practical implementation guidance is provided by the companion standard ISO 22313.

The standard follows the harmonised management system structure (Annex SL) shared with ISO 27001 and ISO 9001: clauses 4-10 cover organisational context, leadership, planning, support, operation, performance evaluation and improvement. The heart of the standard is clause 8: business impact analysis (BIA), disruption risk assessment, continuity strategies and solutions, business continuity plans, and the exercise and testing programme.

Who is it for?

ISO 22301 certification is voluntary and available to any organisation, regardless of size or industry. It is most often implemented by organisations for which downtime means immediate losses or liability towards customers: IT and cloud service providers, data centres, financial institutions, essential service operators, logistics and manufacturing companies, and public administration bodies.

Business continuity is increasingly no longer just good practice but a legal or contractual requirement. The NIS 2 Directive (Article 21(2)(c)) requires essential and important entities to have measures for business continuity, backup management and disaster recovery, and crisis management. The DORA regulation (Articles 11-12) obliges financial entities to maintain an ICT business continuity policy and response and recovery plans. A BCMS implemented to ISO 22301 is the shortest path to demonstrating these requirements are met, as well as controls A.5.29 and A.5.30 of ISO/IEC 27001.

Key concepts: BIA, RTO, RPO

The foundation of a BCMS is the business impact analysis (BIA). In it, the organisation identifies prioritised activities — the processes whose disruption hits customers, finances, legal compliance and reputation fastest and hardest — and assesses how the impact escalates over time. The BIA produces the timing parameters: the maximum tolerable period of disruption (MTPD), the recovery time objective (RTO — how quickly the process must be running again) and the recovery point objective (RPO — how much data loss the organisation can accept).

Based on the BIA and the risk assessment, the organisation selects continuity strategies and solutions (for example infrastructure redundancy, an alternate site, remote work, alternative suppliers), and then documents business continuity plans (BCP) and ICT disaster recovery plans (DR). The whole system is validated by an exercise programme: from tabletop exercises to technical recovery tests measuring the times actually achieved against RTO and RPO.

Structure of the requirements

The auditable requirements cover clauses 4-10 and follow the PDCA cycle. Plan (clauses 4-7): understanding the context and interested-party requirements, the BCMS scope, the continuity policy and objectives, roles, competence, awareness and controlled documentation. Do (clause 8): the BIA and risk assessment, strategies and solutions, an incident response structure with warning and communication procedures, continuity plans, and the exercise and testing programme.

Check (clause 9): monitoring and measuring effectiveness, internal audits and a management review involving top management. Act (clause 10): handling nonconformities, corrective actions and continual improvement. The auditor expects a living system: the BIA updated after changes, exercises run to schedule, and lessons from exercises and real incidents visible in subsequent plan revisions.

What does certification look like?

The certificate is issued by an independent, accredited certification body. The certification audit has two stages: Stage 1 is a documentation and readiness review (scope, policy, BIA, strategies, plans), and Stage 2 verifies implementation — the auditor will trace selected critical processes from the BIA through the strategy to the plan and its test results, talk to the crisis team and review exercise records.

The certificate is valid for 3 years, with annual surveillance audits and full recertification before the end of the cycle. Implementation time depends on the organisation’s size and the maturity of existing practices — typically 3 to 9 months. It is best to schedule the audit after completing at least one full cycle: a BIA, implemented strategies, an exercise with lessons learned, an internal audit and a management review. ISO 22301 combines well with ISO/IEC 27001 in an integrated audit — a large share of the system documentation is common.

What are the benefits?

An implemented BCMS turns declarations about resilience into a verified, rehearsed organisational ability to survive a disruption.

  • Shorter and less costly downtime: recovery priorities, plans and rehearsed procedures instead of improvisation in a crisis.
  • Credibility with customers and regulators: the certificate answers business continuity questions in tenders, vendor questionnaires and SLA negotiations.
  • Fulfilment of NIS 2 (Article 21(2)(c)), DORA (Articles 11-12) and the ISO/IEC 27001 continuity controls (A.5.29, A.5.30) through one coherent effort.
  • Informed investment decisions: the BIA shows which processes genuinely require redundancy and where simpler solutions suffice.
  • Lower risk of losing customers after an incident thanks to prepared crisis communication and realistic recovery times.

How does Guardiso help?

Guardiso guides you through building a BCMS step by step — from the first self-assessment, through the BIA and plans, to the exercise programme and evidence for the auditor.

  • The full set of 31 ISO 22301 requirements (clauses 4-10) seeded automatically when you enable the standard — with descriptions, implementation statuses and owners.
  • The business continuity policy, BC/DR plans and crisis communication procedures generated from templates and tailored to your organisation.
  • A risk register covering disruption scenarios, linked to controls and treatment plans.
  • Recurring tasks that keep the system alive: annual BIA refresh, exercises to schedule, backup restore tests, contact list reviews.
  • Evidence collected in one place: exercise reports, DR test results, management review minutes — ready to show the auditor.
  • Cross-mapping to ISO 27001, NIS 2 and DORA — work done in the BCMS counts towards continuity requirements in related frameworks.
Official sources
01Select standard›02Complete the self assessment›03Close gaps in Guardiso
—
ISO 22301 readiness score
0/27 answered
The score updates live as you answer.

Other standards to assess

ISO 27001GlobalGDPREUNIS 2 (Polish KSC act)EU · PLSOC 2GlobalDORAEUTISAXAutomotiveISO 9001GlobalISO 42001 (AI)GlobalKRIPLPCI DSSGlobalNIST CSFUSANIST 800-53USAHIPAAUSACMMC 2.0USACyber EssentialsUKSOX ITGCUSABIO2NLEU AI ActEUISO 27701GlobalISO 14001GlobalISO 45001GlobalISO 13485MedicalIEC 62304MedicalMDREU · MedicalISO 14971MedicalDCB0129UKMiCAEUIEC 62443GlobalISO 21434Automotive
Browse all 30 standards