ISO 22301: Business Continuity Management System
We implement your Business Continuity Management System, run the business impact analysis, design recovery strategies, test the plans, and prepare you for certification through our partner (a certification body accredited by an IAF MLA signatory accreditation body). ISO 22301 business continuity management gives your organisation the structure to manage disruptions and demonstrate resilience to regulators and customers.
Overview
ISO 22301 is the international standard for business continuity management. The ISO 22301 standard for business continuity management specifies requirements for a Business Continuity Management System (BCMS) that helps organisations of all sizes plan for, respond to, and recover from disruptions. Certification proves your organisation can keep critical activities running, and recover within defined time objectives, when disruption hits. Regulators, insurers, and enterprise customers increasingly treat it as a baseline expectation.
We deliver the business impact analysis to identify which activities are critical and what downtime they can tolerate. From that foundation we define recovery time and recovery point objectives, design continuity and recovery strategies, and document the plans and procedures your teams will actually use under pressure. We then run exercises to validate those plans and monitor effectiveness before the certification audit. Implementation of a working BCMS, not a set of theoretical policies, is what certification bodies look for.
The Stage 1 and Stage 2 audits are conducted by our partner certification body, accredited by an IAF MLA signatory. We prepare you for both and support you through corrective actions so the ISO 22301 business continuity management certification process is an outcome of a working system, not a paper exercise. The certification body will look for evidence of a genuine commitment to business continuity from top management through to operational teams.
What’s included
- BCMS scope, context, and continuity policy
- Business impact analysis (BIA) and risk assessment
- Recovery time objectives (RTO) and recovery point objectives (RPO)
- Business continuity and recovery strategies and plans and procedures
- Exercise and testing programme
- Internal audit and management review
- Certification through our partner certification body, accredited by an IAF MLA signatory
How we work
-
01
Business impact analysis
We identify critical activities, map their dependencies, and establish acceptable downtime. RTOs and RPOs are set from evidence, not assumption, so the plans that follow are grounded in what the organisation can actually survive. Stakeholder input at this stage is essential: the people running critical processes know the dependencies that a top-down analysis misses.
-
02
Strategy and plans
We design continuity and recovery strategies and produce the documented plans and procedures your teams need. Plans are written to be usable under stress, not read in a quiet office. The goal is to reduce the likelihood of a disruptive incident becoming a crisis, and to minimize the impact when one does occur.
-
03
Exercise and validate
We design and facilitate tabletop and scenario exercises to test the plans, identify gaps, and capture improvement actions. Exercise reports form part of the evidence base for the certification audit. The ISO 22301 standard requires you to monitor and review the effectiveness of your BCMS, and exercises are the primary mechanism for doing that.
-
04
Certification audit
Our partner certification body, accredited by an IAF MLA signatory, conducts the Stage 1 and Stage 2 audits. We support you throughout and manage any corrective action requests to closure. The lead auditor conducting the certification process will confirm the BCMS meets the 22301 business continuity management system requirements.
What you get
- Business impact analysis and risk assessment
- Continuity policy, recovery strategies, and documented plans and procedures
- Exercise reports and improvement action log
- Internal audit and management review records
- Accredited ISO 22301 certificate (issued by the partner)
Frequently asked questions
How is ISO 22301 different from a disaster recovery plan?
Disaster preparedness through a disaster recovery plan typically focuses on restoring IT systems after an incident response event. ISO 22301 governs the whole organisation: people, processes, facilities, suppliers, and technology, managed as a continually improving system with defined objectives, tested plans, and regular management review. The ISO 22301 standard for business continuity management also requires governance from top management and formal stakeholder accountability that a standalone recovery plan does not.
Do the plans actually need to be tested?
Yes. ISO 22301 requires you to exercise and test your continuity arrangements and retain the evidence. We design and facilitate the exercises and produce the documentation your certification auditor will review. Conformity with this requirement is something the lead auditor specifically checks during the Stage 2 audit.
Who typically needs ISO 22301 certification?
Financial services firms, critical infrastructure operators, managed service providers, and businesses where a customer or regulator has made continuity certification a contract or licence requirement. Organizations of all sizes in sectors where information security and operational resilience are audited together often pursue ISO 22301 alongside ISO 27001. If enterprise procurement is asking for it, that is sufficient reason to start.
What does the ISO 22301 certification process involve?
The ISO 22301 certification process follows the same two-stage model as other ISO management system standards. Stage 1 is a documentation review conducted by the certification body. Stage 2 is an on-site assessment where the lead auditor confirms the BCMS is implemented and effective. We prepare you for both stages and support you through any findings. The certificate is issued by our partner certification body, accredited by an IAF MLA signatory, once the auditor confirms compliance.
Credentials held by our team










How ready is your security and compliance?
Answer 15 quick questions across the controls auditors actually check, and get an instant readiness score with tailored next steps. No call required.
Ready to simplify security and compliance?
Pick a service, book a scope call, or ask a question. Whatever order works.