Management System Certification

ISO 22301 – Business Continuity Management System

Know exactly what you will do when the site, the system or the supplier goes down.

  • ISO 22301
  • Recognised internationally

About ISO 22301

What is ISO 22301?

ISO 22301:2019 specifies requirements for a Business Continuity Management System (BCMS) — the discipline of identifying what your organisation must keep running, how quickly it must be restored, and what you will actually do to make that happen when normal operations are disrupted.

The system is anchored in two analyses. The Business Impact Analysis establishes, for each prioritised activity, the maximum tolerable period of disruption, the recovery time objective and the recovery point objective. The risk assessment then examines what could cause that disruption. Continuity strategies and plans are selected to close the gap between the two — with the resources, people and dependencies they require identified in advance rather than improvised during an incident.

The requirement that distinguishes a real BCMS from a document set is exercising. Plans must be tested — through tabletop walkthroughs, simulations or full failover — and the results must feed back into the plans. Auditors look for exercise reports with honest findings. A plan that has never failed an exercise has usually never been genuinely exercised.

Who needs this?

  • IT and BPO organisations with contractual uptime and recovery commitments to clients
  • Banks, NBFCs, insurers and payment operators under regulatory continuity requirements
  • Manufacturers with single-source dependencies or concentrated production sites
  • Healthcare, utilities, telecom and other essential service providers
  • Logistics and supply chain operators exposed to route, port or weather disruption
  • Any organisation whose clients audit their disaster recovery arrangements

Why organisations certify

Key benefits of ISO 22301

What certification actually returns, stated specifically rather than generically.

Credibility

Certification shows clients and regulators that your recovery commitments were analysed and tested, not asserted in a contract clause.

Market Access

Continuity certification is a standing requirement in financial services, IT outsourcing and critical-infrastructure contracts.

Risk Reduction

Impact analysis exposes single points of failure — one supplier, one server room, one qualified operator — while there is still time to address them.

Operational Efficiency

Documented recovery priorities stop the most expensive failure mode of any crisis: capable people spending the first hours deciding who decides.

Customer Trust

Clients evaluating vendor concentration risk treat a tested BCMS as a material differentiator during renewal.

Regulatory Compliance

Supports RBI, SEBI, IRDAI and DPDP-related resilience expectations with structured, auditable evidence.

How it works

Our process for ISO 22301

Every stage has a defined purpose, a realistic duration and a stated output.

  1. 01

    Application & Quotation

    2–3 working days

    You submit an application form covering scope, headcount, sites and shift pattern. We review complexity, confirm audit-day allocation against accreditation rules and issue a fixed quotation.

  2. 02

    Contract & Audit Planning

    1 week

    On acceptance we appoint a lead auditor with verified technical competence for your sector, agree audit dates and share the audit plan in advance.

  3. 03

    Stage 1 — Readiness Review

    1 day (typical)

    A documentation and readiness assessment: scope confirmation, review of your management system documents, internal audit and management review evidence, and identification of anything that would block Stage 2.

  4. 04

    Stage 2 — Certification Audit

    2–5 days (scope dependent)

    On-site assessment of the system in operation. We sample processes, interview staff, examine records and raise findings graded as major, minor or opportunity for improvement.

  5. 05

    Corrective Action & Decision

    2–4 weeks

    You close out any nonconformities with root-cause analysis and evidence. An independent certification decision-maker — not the audit team — reviews the file and grants certification.

  6. 06

    Certificate Issue

    3–5 working days

    A three-year certificate is issued and your organisation is listed on our public certified-client directory for verification by your customers.

  7. 07

    Surveillance & Recertification

    Annual

    Surveillance audits at 12 and 24 months confirm the system remains effective. A full recertification audit is completed before the three-year expiry.

Preparation

Documents required

What we will ask to see. Having these ready before Stage 1 is the single biggest factor in a certification that runs to schedule.

  • Completed and signed application form
  • Certificate of incorporation / business registration
  • Organisation chart and scope statement
  • Management system manual or equivalent documented information
  • Documented processes, procedures and work instructions
  • Internal audit reports covering the full scope
  • Management review minutes
  • Records of corrective actions and continual improvement
  • Applicable legal and regulatory licences for your activity
  • Business continuity policy and BCMS scope
  • Business Impact Analysis with MTPD, RTO and RPO per prioritised activity
  • Continuity risk assessment and treatment records
  • Business continuity strategies and solution justification
  • Business continuity and incident response plans with defined roles
  • Crisis communication plan and contact directories
  • Exercise and testing programme, exercise reports and lessons learned
  • Supplier and outsourced-service continuity assurance records

Not sure whether your scope is right?

Scope is the single thing most often got wrong, and it appears verbatim on your certificate. We will review yours before you apply, at no charge — it costs us less than fixing it at recertification.

Talk to a specialist

Common questions

ISO 22301 — frequently asked questions

Direct answers, including where the honest answer is inconvenient for us.

The standard requires exercising at planned intervals and after significant change, without prescribing a frequency. Common practice is at least annually for each critical plan, with a mix of tabletop and technical exercises. What we assess is whether the programme is justified against your risk profile and whether findings were acted on.

No. Disaster recovery restores IT systems and is a subset of continuity. ISO 22301 covers the whole organisation — people, premises, suppliers, communications and process workarounds — including situations where IT is fine and something else has failed.

Yes, and the fit is natural. ISO 27001:2022 control 5.30 addresses ICT readiness for business continuity, which ISO 22301 develops in full. Organisations frequently certify both under one integrated audit programme.

Question not answered here? Ask a certification specialist — we answer technical questions without requiring an enquiry first.

Talk to us

Talk to a certification expert

Tell us your scope and headcount and we will send a fixed quotation for ISO 22301 with the audit-day calculation shown.

  • Quotation within 2–3 working days
  • IAF MD 5 audit-day calculation included
  • Full three-year cycle cost, not just the first audit
  • Your details are used only to answer this enquiry

Including contractors and shift staff — this sets your audit days.

Tell us your scope, whether design is included, and any deadline you are working to.

Your details are used only to answer this enquiry. We do not sell or share them.

Next step

Ready to certify to ISO 22301?

We will scope it honestly, show you the calculation behind the price, and tell you plainly if the timeline you need is not achievable.