It's asked for by name
Business continuity is a standard line item in enterprise and financial-sector RFPs and security questionnaires. A 22301 certificate answers it in one attachment.
Keep running when things go wrong.
ISO 22301 is the international standard for a Business Continuity Management System (BCMS) — the discipline of protecting against, preparing for, responding to and recovering from disruption so your critical products and services keep running within tolerable time frames. It's certifiable by an accredited body, and shares the same management-system spine (clauses 4–10) as ISO 27001 and ISO 42001.
The standard
ISO 22301:2019 — Business Continuity Management Systems
Who needs it
Any organisation whose customers, regulators or contracts ask 'are you business-continuity certified?' — especially in financial services, critical infrastructure, healthcare, SaaS and outsourcing/BPO, or anyone operating under resilience mandates such as DORA or sector regulators.
24h→0
downtime, planned for
The basics
A management system, not a checklist: you establish context and scope, set a business continuity policy and objectives, and run the operational core of Clause 8 — a Business Impact Analysis and risk assessment, continuity strategies and solutions, business continuity plans, an exercise programme, and ongoing evaluation.
The Business Impact Analysis (BIA) is the heart of it: for each prioritized activity you determine how long you can tolerate it being down (MTPD), how fast you must recover it (RTO), how much data loss is acceptable (RPO), and the dependencies and resources it relies on.
The 2019 edition (with Amendment 1:2024, which adds climate-change considerations) is verified through an initial Stage 1 and Stage 2 audit, then annual surveillance and a full recertification every three years.
Why it matters
Business continuity is a standard line item in enterprise and financial-sector RFPs and security questionnaires. A 22301 certificate answers it in one attachment.
When a site, system or supplier goes down, the difference between a controlled response and a scramble is having tested plans and known recovery targets.
If you already run ISO 27001 or 42001, the clause 4–10 spine transfers directly — you're extending an existing management system, not starting over.
Context, scope, and a Business Impact Analysis that sets MTPD, RTO and RPO for each prioritized activity.
Continuity strategies and solutions, a response structure, and usable business continuity plans.
A programme of exercises and tests that proves your plans work — with formal post-exercise improvement.
Monitoring, internal audit, management review and corrective action keep the BCMS living.
A BCMS is a lot to stand up by hand: a BIA with recovery objectives for every critical activity, a risk assessment, continuity strategies, plans that are actually usable in a crisis, an exercise schedule you keep to, and a full audit trail across clauses 4–10 — all kept current as the business changes.
Do it once, reuse it everywhere. Evidence you collect for ISO 22301is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.
See exactly how Compliance One maps ISO 22301 to your environment in a 30-minute walkthrough — and how much of it we handle for you.