All frameworks
ISOCertification · resilience

ISO 22301 compliance

Keep running when things go wrong.

ISO 22301 is the international standard for a Business Continuity Management System (BCMS) — the discipline of protecting against, preparing for, responding to and recovering from disruption so your critical products and services keep running within tolerable time frames. It's certifiable by an accredited body, and shares the same management-system spine (clauses 4–10) as ISO 27001 and ISO 42001.

Start from the basics

The standard

ISO 22301:2019 — Business Continuity Management Systems

Who needs it

Any organisation whose customers, regulators or contracts ask 'are you business-continuity certified?' — especially in financial services, critical infrastructure, healthcare, SaaS and outsourcing/BPO, or anyone operating under resilience mandates such as DORA or sector regulators.

24h→0

downtime, planned for

The basics

What is ISO 22301?

A management system, not a checklist: you establish context and scope, set a business continuity policy and objectives, and run the operational core of Clause 8 — a Business Impact Analysis and risk assessment, continuity strategies and solutions, business continuity plans, an exercise programme, and ongoing evaluation.

The Business Impact Analysis (BIA) is the heart of it: for each prioritized activity you determine how long you can tolerate it being down (MTPD), how fast you must recover it (RTO), how much data loss is acceptable (RPO), and the dependencies and resources it relies on.

The 2019 edition (with Amendment 1:2024, which adds climate-change considerations) is verified through an initial Stage 1 and Stage 2 audit, then annual surveillance and a full recertification every three years.

Why it matters

What ISO 22301 does for your business

It's asked for by name

Business continuity is a standard line item in enterprise and financial-sector RFPs and security questionnaires. A 22301 certificate answers it in one attachment.

It turns chaos into a plan

When a site, system or supplier goes down, the difference between a controlled response and a scramble is having tested plans and known recovery targets.

It reuses what you have

If you already run ISO 27001 or 42001, the clause 4–10 spine transfers directly — you're extending an existing management system, not starting over.

What it covers

Understand & prioritise

Context, scope, and a Business Impact Analysis that sets MTPD, RTO and RPO for each prioritized activity.

Strategise & plan

Continuity strategies and solutions, a response structure, and usable business continuity plans.

Exercise & validate

A programme of exercises and tests that proves your plans work — with formal post-exercise improvement.

Evaluate & improve

Monitoring, internal audit, management review and corrective action keep the BCMS living.

The hard way

A BCMS is a lot to stand up by hand: a BIA with recovery objectives for every critical activity, a risk assessment, continuity strategies, plans that are actually usable in a crisis, an exercise schedule you keep to, and a full audit trail across clauses 4–10 — all kept current as the business changes.

The easier way, with Compliance One

  • Ships the full ISO 22301 clause 4–10 requirement library (incl. the 2024 climate-change amendment), enabled by default with a Statement of Applicability.
  • Includes a native Business Impact Analysis register — capture each activity's MTPD, RTO, RPO, minimum capacity, dependencies and resources — plus an exercise & test scheduler with due-date timers.
  • Pre-fills the mandatory documents: BC policy, context & scope, BIA and risk assessment, continuity strategies, business continuity plans, exercise programme, internal audit, management review and corrective action.
  • Cross-maps to ISO 27001 (A.5.29/A.5.30 ICT readiness & business continuity) and NIS2 (business continuity & incident handling), so evidence carries across your programmes.

Do it once, reuse it everywhere. Evidence you collect for ISO 22301is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.

Common questions

Is ISO 22301 certifiable like ISO 27001?
Yes — it's a certifiable management-system standard. An accredited body runs a Stage 1 and Stage 2 audit, then annual surveillance audits and a three-yearly recertification.
We already have ISO 27001 — how much extra work?
Less than you'd expect. Clauses 4–10 are shared Annex SL text, and 27001's A.5.29/A.5.30 already touch business continuity. Compliance One cross-maps the overlap, so you extend rather than restart.
What's the difference between MTPD, RTO and RPO?
MTPD is the longest an activity can be down before impacts become unacceptable; RTO is your target to recover it within that window; RPO is the maximum tolerable data loss. The platform's BIA register captures all three per activity.
What changed in the 2024 amendment?
Amendment 1:2024 adds climate-action considerations — you now determine whether climate change is a relevant issue in your context (4.1) and account for interested parties' climate-related requirements (4.2). Our content is on the current text.

Ready to tackle ISO 22301?

See exactly how Compliance One maps ISO 22301 to your environment in a 30-minute walkthrough — and how much of it we handle for you.