ISO 22301 is the international standard for business continuity management systems (BCMS). It provides a structured framework to help organisations prepare for, respond to, and recover from disruptive incidents such as cyber attacks, system failures, supply chain disruption, natural events, or loss of key facilities.
ISO 22301 certification demonstrates that an organisation can continue delivering critical products and services during disruption and recover within defined timeframes.
What is ISO 22301?
ISO 22301 is an international standard published by the International Organization for Standardization. It sets out the requirements for establishing, implementing, maintaining, and continually improving a business continuity management system.
The standard focuses on resilience, ensuring organisations can protect critical activities, minimise downtime, and respond effectively when incidents occur. It is suitable for organisations of all sizes and sectors.
What does ISO 22301 cover?
ISO 22301 requires organisations to take a structured, risk-based approach to continuity planning. Key areas include:
- Understanding organisational context and critical activities
- Business impact analysis (BIA)
- Risk assessment and threat identification
- Business continuity strategies and solutions
- Business continuity and disaster recovery plans
- Incident response and crisis management
- Testing, exercising, and training
- Monitoring, review, and continual improvement
The emphasis is on preparedness and proven recovery capability, not just written plans.
Who is ISO 22301 for?
ISO 22301 is particularly relevant for organisations where disruption could cause significant operational, financial, or reputational damage, including:
- Technology and digital service providers
- Financial and professional services
- Healthcare and critical services
- Utilities and infrastructure operators
- Logistics and supply chain organisations
- Any organisation with contractual uptime or resilience obligations
It is often required by clients, regulators, insurers, or sector frameworks.
ISO 22301 requirements explained
To achieve ISO 22301 certification, an organisation must demonstrate:
Leadership and planning
- A documented business continuity policy
- Clear roles and responsibilities
- Management commitment to resilience
Business impact analysis and risk assessment
- Identification of critical products and services
- Maximum tolerable periods of disruption (MTPD)
- Recovery time objectives (RTOs) and recovery point objectives (RPOs)
Continuity strategies and plans
- Strategies to maintain or restore operations
- Business continuity plans and disaster recovery plans
- Crisis communication arrangements
Support and competence
- Training and awareness
- Document control and communication processes
Testing and improvement
- Regular testing and exercising of plans
- Internal audits and management review
- Continual improvement based on test results and incidents
Auditors place strong emphasis on evidence that plans are tested and realistic.
How to get ISO 22301 certified
The certification process typically includes:
- Defining the scope of the BCMS
- Conducting a business impact analysis
- Identifying threats and continuity risks
- Developing continuity strategies and plans
- Training staff and testing plans
- Completing an internal audit and management review
- Passing a Stage 1 and Stage 2 certification audit
ISO 22301 certification requires active participation from leadership and operational teams.
How long does ISO 22301 certification take?
Indicative timeframes are:
- Small organisations: 8–16 weeks
- Medium organisations: 3–5 months
- Large or complex organisations: 5–9 months+
Timelines depend on organisational complexity, number of critical services, and maturity of existing continuity arrangements.
How much does ISO 22301 certification cost?
Indicative total costs (initial certification):
- Small organisations:
£4,000–£10,000 | $5,000–$13,000 | €4,500–€12,000 - Medium organisations:
£10,000–£25,000 | $13,000–$35,000 | €12,000–€30,000 - Large or complex organisations:
£25,000–£50,000+ | $35,000–$70,000+ | €30,000–€60,000+
Costs vary based on scope, number of critical activities, audit duration, and preparation approach.
Benefits of ISO 22301 certification
Organisations typically achieve:
- Reduced downtime during incidents
- Faster, more controlled recovery
- Clear roles and decision-making during crises
- Improved confidence from customers and stakeholders
- Stronger compliance with resilience requirements
- Better integration between IT, operations, and leadership
The greatest value comes from regular testing and continual improvement of continuity plans.
Common ISO 22301 mistakes to avoid
- Treating continuity planning as an IT-only activity
- Failing to define realistic recovery objectives
- Producing plans that are not tested
- Poor integration with suppliers and third parties
- Lack of staff awareness and training
Auditors expect continuity arrangements to be practical, tested, and embedded into organisational culture.
ISO 22301 certification FAQs
No. ISO 22301 is voluntary, but it is frequently required by regulators, clients, insurers, or contractual frameworks.
No. While IT recovery is important, ISO 22301 covers all critical business activities, including people, facilities, suppliers, and communications.
Certification is typically valid for three years, with regular surveillance audits.
Yes. ISO 22301 integrates well with ISO 27001, ISO 9001, and ISO 45001 within an integrated management system.
Next steps
If you are considering ISO 22301 certification:
- Identify critical products and services
- Carry out a business impact analysis
- Define realistic recovery objectives
- Decide whether to prepare internally or use external support
- Plan realistic costs and timescales
ISOcertified.net provides detailed guidance on ISO 22301 certification, including continuity planning, testing, audits, and ongoing resilience management.