Enquire Us

What is ISO 22301?

ISO 22301 is the international requirements standard for business continuity management systems. Unlike guidance documents, it is genuinely certifiable by an accredited certification body. This page explains what it asks for and how certification works.

Definition and publisher

ISO 22301 is an international standard published by the International Organization for Standardization. Its full title is Security and resilience, Business continuity management systems, Requirements, and the current edition is ISO 22301:2019.

The standard specifies requirements for a business continuity management system, usually shortened to BCMS. A BCMS is the set of policies, analysis, plans, roles and review activity through which an organisation prepares for disruption, keeps its most important activities running at an acceptable level during disruption, and recovers within a period it has decided in advance is tolerable.

ISO 22301 is written as requirements rather than as recommendations. That distinction matters, because it is what makes the standard auditable and therefore certifiable. It sits in the same category as ISO/IEC 27001 and ISO 9001, not in the same category as guidance documents such as ISO 31000.

Who it applies to

ISO 22301 is deliberately sector neutral and size neutral. The standard applies to any organisation that decides it needs to demonstrate resilience, and its requirements are scaled to the organisation’s context, risk profile and complexity. In practice, adoption clusters around a few situations:

  • Organisations delivering services under contracts that require documented continuity arrangements, which is common in outsourcing, IT services, logistics and facilities management.
  • Regulated sectors, particularly banking, insurance, telecommunications, healthcare and utilities, where continuity of critical services is a supervisory expectation.
  • Suppliers to government and to critical infrastructure operators, who are asked to evidence recovery capability as part of vendor assurance.
  • Organisations that have experienced a serious disruption and need to restructure the response rather than repeat it.

Structure and key requirements

ISO 22301 follows the harmonised structure that ISO applies across its management system standards, so the clause numbering will look familiar to anyone who has implemented ISO/IEC 27001 or ISO 9001. The requirement clauses cover:

  • Context of the organisation. Understanding internal and external issues, interested parties and their requirements, and defining the scope of the BCMS.
  • Leadership. Top management commitment, the business continuity policy, and assignment of roles, responsibilities and authorities.
  • Planning. Addressing risks and opportunities and setting business continuity objectives.
  • Support. Resources, competence, awareness, communication and documented information.
  • Operation. The technical core of the standard, containing business impact analysis and risk assessment, business continuity strategies and solutions, business continuity plans and procedures, and the exercising and testing programme.
  • Performance evaluation. Monitoring, measurement, analysis and evaluation, internal audit and management review.
  • Improvement. Nonconformity, corrective action and continual improvement.

Within the operation clause, the business impact analysis is what drives everything else. It identifies the organisation’s activities, the impact over time of not performing them, and from that derives two figures that shape the whole system: the maximum tolerable period of disruption for each activity and the recovery time objective set within it. Recovery point objectives are set for data. Only once these are agreed can strategies and solutions be chosen sensibly, whether that means alternate sites, standby capacity, alternative suppliers, cross trained staff or manual workarounds.

Plans must be documented, assigned to named roles, and exercised. Exercising is a requirement, not an optional extra, and the standard expects the results of exercises to feed back into the plans.

How certification actually works

Because ISO 22301 is a requirements standard, certification is available and works exactly as it does for other ISO management system standards. The steps are:

  • The organisation implements the BCMS, runs at least one cycle of internal audit and management review, and produces the records the auditor will need to see.
  • It appoints an independent certification body. The certification body should be accredited for ISO 22301 by a national accreditation body that is a signatory to the International Accreditation Forum multilateral recognition arrangement, which is what makes the certificate recognised outside the country of issue.
  • Stage 1 audit. The certification body reviews documentation, scope, business impact analysis and readiness, and identifies anything that would prevent a successful Stage 2.
  • Stage 2 audit. The auditor tests implementation in practice, sampling evidence, interviewing staff and reviewing exercise records.
  • Any nonconformities are closed, and the certificate is issued. The certificate is valid for three years, subject to annual surveillance audits, with a recertification audit before the three years expire.

Guidance documents support implementation without replacing the requirements. ISO 22313 provides guidance on using ISO 22301, and ISO/TS 22317 gives detailed guidance specifically on business impact analysis. Neither is certifiable in its own right.

How Univate supports ISO 22301

Univate implements business continuity management systems for organisations in the Gulf, Africa, South East Asia and the United States. Engagement components typically include:

  • Scope definition and context analysis, agreeing which entities, sites and services the BCMS covers before any documentation is written.
  • Business impact analysis workshops with activity owners, producing maximum tolerable periods of disruption, recovery time objectives and recovery point objectives that the business actually accepts.
  • Risk assessment aligned to the organisation’s wider risk framework so that continuity risk is not managed in isolation.
  • Strategy selection and gap closure, including alternate site, supplier and resourcing options assessed against cost.
  • Drafting of the policy, the BCMS documentation, incident response structure and the continuity plans themselves.
  • Design and facilitation of the exercise programme, from table top exercises through to live recovery tests.
  • Internal audit, management review preparation, and support through the Stage 1 and Stage 2 audits with the client’s chosen certification body.

Where an organisation operates in the United Arab Emirates, the BCMS is commonly built so that it satisfies both ISO 22301 and the national business continuity requirements that apply locally, avoiding two parallel systems.

Frequently asked questions about ISO 22301

Is ISO 22301 certifiable?

Yes. ISO 22301 is written as auditable requirements, so an accredited certification body can audit a business continuity management system against it and issue a certificate. This is different from guidance documents such as ISO 31000, which are not certifiable.

How long is an ISO 22301 certificate valid?

An ISO 22301 certificate is valid for three years, subject to annual surveillance audits by the certification body. A recertification audit is required before the three year period ends.

What is a business impact analysis under ISO 22301?

A business impact analysis identifies the organisation’s activities, assesses the impact over time of not performing them, and establishes the maximum tolerable period of disruption and the recovery time objective for each. It is the analysis from which continuity strategies, solutions and plans are derived.

What is the difference between ISO 22301 and ISO 22313?

ISO 22301 contains the requirements against which an organisation is audited and certified. ISO 22313 is guidance on implementing those requirements and is not itself certifiable.

Does ISO 22301 require plans to be tested?

Yes. The standard requires an exercising and testing programme so that continuity procedures are validated, and it expects the results of exercises to be evaluated and used to improve the plans and the wider management system.

How does ISO 22301 relate to ISO/IEC 27001?

Both use the same harmonised management system structure, so context, leadership, planning, support, performance evaluation and improvement work the same way and can share documentation, internal audit and management review. The difference is subject matter: ISO/IEC 27001 governs information security risk and controls, while ISO 22301 governs continuity of prioritised activities during disruption.

Preparing for ISO 22301 certification or rebuilding continuity plans that were never exercised? Speak to the Univate business continuity team.

Univate Global delivers ISO certifications, data privacy compliance, and cybersecurity frameworks across 9 markets.