22301
ISO 22301:2019 · Business continuity management system

ISO 22301BCMS

Keep critical operations running through outages, cyber incidents, supply disruptions and crises — and prove it to clients, regulators and insurers.

SCHEME CARD · INFORMATION SECURITY
ISO 22301Business continuity management system · 2019
Who it's for
Banks & fintech, it & data centres and more
Audit model
Stage 1 + Stage 2 + surveillance
Certificate validity
3 years
Typical timeline
8–12 weeks
Listed in public registerCombines with ISO/IEC 27001, ISO 9001
3 yrscertificate validity, with annual surveillance audits
2audit stages — documentation review, then on-site assessment
8–12weeks from application to certificate, typical timeline
1business day to a fixed offer after your application
Why companies certify

Who needs ISO 22301— and when

ISO 22301 defines how an organisation identifies its critical activities, assesses the impact of disruption and plans recovery within agreed timeframes. Certification gives clients, regulators and insurers evidence that continuity is tested, not just written down.

Often required by financial regulators, outsourcing clients and critical-infrastructure customers, and supports DORA and NIS2 resilience requirements.

INDUSTRIES WE CERTIFY TO ISO 22301

Banks & fintechIT & data centresTelecomLogisticsManufacturingEnergy & utilities
Not sure whether ISO 22301 fits? Our auditors run a short diagnostic review and suggest the scheme — or a combination of two or three — that answers your customers' requirements.
Inside the standard

What the audit examines

01Business impact analysis

Critical activities, dependencies and recovery objectives (RTO / RPO).

02Risk assessment

Threats of disruption identified and treated.

03Continuity strategies

Resources and solutions for recovery selected.

04Plans & procedures

Incident response and recovery plans documented.

05Exercising & testing

Plans tested on realistic scenarios.

06Supplier continuity

Critical suppliers covered by continuity arrangements.

What the audit covers

Requirements,clause by clause

ISO 22301 is audited against these requirement areas. Open each one to see what auditors look for in your company.

Clause 4Context of the organisation+
Interested parties, internal and external issues, and how the scope of the system is defined.
Clause 5Leadership+
Top management commitment, a policy that fits the business, roles and responsibilities.
Clause 6Planning+
Risks and opportunities identified and addressed; measurable objectives with plans to reach them.
Clause 7Support+
Resources, competence and awareness, communication, control of documented information.
Clause 8Operation+
How processes are planned, controlled and delivered day to day.
Clauses 9–10Evaluation & improvement+
Monitoring, internal audits, management review — and how nonconformities become corrective actions.
Benefits

What ISO 22301certification gives you

  • Critical operations recover within agreed timeframes
  • Evidence for regulators, clients and insurers
  • Support for DORA and NIS2 resilience requirements
  • Lower impact of incidents and outages
  • Tested plans instead of documents on a shelf
  • Integrates with ISO/IEC 27001 and ISO 9001
Integrated audit

Hold more than one standard? One audit.

ISO 22301 shares its structure with ISO/IEC 27001, ISO 9001. We audit them together — one team, one visit, one report.

−25%audit days on average
1lead auditor for all standards
The path to certificate

Five steps from application to ISO 22301

Scroll the steps — the bar shows where you are in the process. Every step has a named coordinator and a fixed timeline.

STEP 1 / 5 · Application & offer
STEP 11 business day
Application & offer

You send a short application; a coordinator sizes the audit and sends a fixed offer.

→ Offer with audit plan
STEP 21–2 days
Stage 1 audit

Documentation review and readiness check — remote or on site. Gaps are listed, not penalised.

→ Readiness report
STEP 3By calculation
Stage 2 audit

On-site assessment of implementation and effectiveness with a team that knows your sector.

→ Audit report
STEP 45–10 days
Decision & certificate

Independent certification decision; the certificate is issued and entered into the public register.

→ ISO 22301 certificate
STEP 5Annual
Surveillance & renewal

Annual surveillance keeps the certificate in force; re-certification in year three.

→ Certificate maintained
Readiness check

Are you readyfor Stage 1?

Tick what you already have. You do not need a perfect system to apply — you need a working one.

Your readiness
0%

Based on the items ticked on the left. Indicative — the Stage 1 audit gives the formal picture.

Apply for ISO 22301 →
FAQ · ISO 22301

Questions companiesask before certifying

Did not find yours? Call us — a coordinator answers within the same business day.

+38 (044) 332-30-76
How is ISO 22301 different from a disaster recovery plan?+
A DR plan covers IT recovery. ISO 22301 covers the whole organisation — people, sites, suppliers and processes — and requires the plans to be maintained, tested and improved.
Do we need to run a full-scale exercise?+
No. The programme can start with tabletop exercises and build up; auditors look for exercises proportionate to your risks and evidence of lessons learned.
Does it help with DORA or NIS2?+
Yes. Both require business continuity and resilience arrangements; a certified BCMS is strong evidence for them.
Related schemes

Often certifiedtogether

Get certifiedto ISO 22301

Send an application — we define scope and audit duration, and issue a fixed offer within one business day.

  • Auditors with experience in your industry
  • Fixed price — no surprises after Stage 1
  • Certificate listed in the public register
By sending the form you agree to the processing of the data for preparing a quotation.