ISO 22301
The international standard for business continuity management
Reviewed 10 August 2026by Julian Russell, Managing Director
Overview
What is ISO 22301?
ISO 22301 is the international standard for business continuity management systems. It sets out how an organisation works out which of its activities matter most, how long it can survive without them, and what it will do when they stop.
ISO 22301 sets out how to prepare for, respond to and recover from disruption. It covers whatever might stop you operating: cyber attack, supplier failure, loss of premises, IT outage, extreme weather, key people being unavailable.
The standard is deliberately cause-agnostic. It does not ask you to predict what will go wrong. It asks you to understand what your organisation cannot do without, for how long, and what you will do when it happens.
That framing is what makes it useful. Plans built around specific scenarios tend to fail when something unanticipated occurs. Plans built around the recovery of critical activities work regardless of cause.
Business impact analysis
This is the core of the standard, and the part that produces the value.
A business impact analysis identifies your activities, determines which are critical, and establishes how quickly each must be restored before the consequences become unacceptable. Those conclusions produce two figures that drive everything else:
Recovery time objective (RTO). How long an activity can be unavailable before the impact is unacceptable.
Recovery point objective (RPO). How much data loss is tolerable, measured in time.
These figures often prompt uncomfortable conversations. An organisation whose IT is backed up nightly has an RPO of up to 24 hours, whether or not the business could actually survive losing a day of transactions. The analysis surfaces that mismatch, which is frequently the most valuable outcome of the whole exercise.
Exercising the plan
ISO 22301 requires you to exercise and test your continuity arrangements, and this is where most systems are weakest.
A continuity plan that has never been tested is a document, not a capability. Auditors look for evidence of exercises, the results, and what changed as a consequence. An exercise that identified no improvements is usually a sign that the exercise was not demanding enough.
Exercises do not have to be elaborate. A tabletop walkthrough with the relevant people, asking what they would actually do, reliably finds gaps: contact lists out of date, a critical system nobody has admin access to, a supplier with no alternative.
What ISO 22301 requires
The standard follows the common structure shared across ISO management system standards.
Context and interested parties, including regulatory and contractual continuity requirements.
Leadership. Top management commitment, a business continuity policy, and defined roles for incident response.
Planning. Risks and opportunities, and business continuity objectives.
Support. Resources, competence, awareness, communication and documented information.
Operation. Business impact analysis, risk assessment, continuity strategies and solutions, plans and procedures, and exercising and testing.
Performance evaluation. Monitoring, internal audit and management review.
Improvement. Nonconformity, corrective action and continual improvement.
A gap analysis will show how much of this you already have in place, and implementation support covers building the rest.
Who asks for it
Certification is most often driven by customers rather than regulators. Financial services, government, healthcare, utilities and critical supply chains increasingly require evidence that their suppliers can keep operating.
If you provide a service your customer depends on, continuity questions are likely to appear in their due diligence, and a certificate answers them faster than a questionnaire.
The 2024 climate change amendment
In February 2024, ISO amended 31 management system standards including ISO 22301, requiring organisations to determine whether climate change is a relevant issue in their context. For business continuity this is unusually concrete: flooding, heat, storm damage and their effects on premises, supply chains and staff availability are exactly the disruptions the standard exists to address.
Combining with ISO 27001
ISO 22301 and ISO 27001 are natural partners and are frequently held together.
Information security covers availability as one of its three pillars, alongside confidentiality and integrity, and the incident response and continuity requirements in ISO 27001 sit comfortably inside a fuller ISO 22301 system. If you hold ISO 27001, much of the groundwork exists.
What certification involves
Certification comes from an independent certification body accredited by UKAS, not from a consultancy. Assessment runs in two stages, with Stage 1 covering documentation and readiness and Stage 2 covering implementation.
Before either, you need a completed internal audit, a management review, and evidence that your continuity arrangements have actually been exercised. That last one cannot be produced retrospectively, so it is worth planning early.
IT service providers often pair ISO 22301 with ISO 20000-1, which includes its own service continuity requirements.
Why get certified
Key Benefits of ISO 22301
Resilience
Build organisational resilience to withstand and recover from disruptions.
Stakeholder Confidence
Demonstrate to clients and partners that your business can maintain critical services.
Risk Reduction
Identify threats and reduce the impact of incidents on your operations.
Regulatory Compliance
Meet contractual and regulatory requirements for business continuity.
How we work
Our Certification Process
Scope and context
Establishing which parts of the organisation the system covers, and what continuity requirements customers, regulators and contracts impose.
Business impact analysis
Identifying activities, determining which are critical, and establishing recovery time and recovery point objectives for each.
Risk assessment
Assessing what could disrupt the critical activities, and what controls reduce either likelihood or impact.
Continuity strategies and solutions
Deciding how each critical activity will be maintained or recovered within its objective, and what resources that requires.
Plans and procedures
Documented response and recovery plans, with roles, contact arrangements and decision authority clear enough to use under pressure.
Exercising and testing
Testing the arrangements, recording the results and acting on what they reveal. Certification requires evidence of this and it cannot be produced retrospectively.
Internal audit, review and certification
Internal audit and management review, then Stage 1 and Stage 2 audits with Equas in attendance.
Common questions
Frequently Asked Questions
The process of identifying your activities, determining which are critical, and establishing how quickly each must be restored before the consequences become unacceptable. It produces your recovery time and recovery point objectives, which drive every other decision in the system.
Ready for ISO 22301 Certification?
Get a free, no-obligation quote from our expert consultants. Backed by the Equas Guarantee.
