ISO 22301
ISO 22301 is the international standard for Business Continuity Management Systems (BCMS). It gives you a structured way to prepare for, respond to and recover from disruptive incidents.
Who it applies to
Any organisation needing formal business continuity management — commonly financial services, healthcare, critical infrastructure, essential suppliers.
How ISO-STANDARD.app helps with ISO 22301
10 in-depth articles
The Business Impact Analysis: the heart of ISO 22301
Without a real BIA, everything else in your BCMS is guessing. This is where recovery objectives actually come from.
The purpose
Identify prioritised activities, their dependencies, and the impact over time of their disruption. This drives every recovery decision.
MTPD, RTO, RPO
Maximum Tolerable Period of Disruption, Recovery Time Objective, Recovery Point Objective. Set them from the BIA, not from IT preferences.
Interdependencies
Activities depend on people, technology, information, suppliers, facilities. The BIA maps them so recovery plans have concrete targets.
Refresh cycle
Annual as minimum; more often for high-change organisations. Old BIAs make bad plans.
How ISO-STANDARD.app helps with ISO 22301
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 22301 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 22301 shape.
Risk assessment vs Business Impact Analysis: not the same
One tells you what could go wrong; the other tells you what happens if it does. You need both.
Risk assessment
Identifies threats and vulnerabilities. Aligns with your general ISO 27001 or 31000 risk process where possible.
BIA
Identifies impact of loss regardless of cause. Threat-agnostic — 'if this activity stops for 3 days, what happens?'
Feeding each other
Risk assessment tells you which threats need controls. BIA tells you which activities need recovery capability. Together they scope your BCMS.
Audit-ready traceability
Every recovery capability should trace back to a BIA-identified activity. Every treatment should trace back to a risk.
How ISO-STANDARD.app helps with ISO 22301
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 22301 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 22301 shape.
Running tabletop exercises that actually improve things
The exercises that improve capability are the ones with real scenarios and post-exercise action tracking.
Scenario realism
Base scenarios on your BIA activities and your risk assessment. Generic disaster scenarios train muscle but not judgement.
Participants
The people who'd actually respond — including business, not just IT. Executives too, for the decisions only they can make.
Post-exercise report
Documented findings with owners and dates. This is the input to next year's BCMS improvement plan.
Frequency
At least annually for the whole BCMS; quarterly or more for critical scenarios. Muscle memory decays.
How ISO-STANDARD.app helps with ISO 22301
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 22301 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 22301 shape.
DR vs BC: how ISO 22301 uses both
Disaster recovery is IT-centric. Business continuity is business-centric. 22301 wants both in a coherent BCMS.
Disaster recovery
IT service and infrastructure recovery. RTO/RPO for systems. Owned by IT.
Business continuity
Continuing critical business activities during and after disruption. Owned by business functions with IT as an enabler.
The BCMS umbrella
22301 doesn't distinguish sharply — it wants a Business Continuity Management System that covers both.
Integration
The DR runbook is a component of the wider BC plan. Test them together, not in isolation.
How ISO-STANDARD.app helps with ISO 22301
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 22301 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 22301 shape.
ISO 22301 vs operational resilience frameworks (UK/EU financial)
22301 is the foundation. UK PRA/FCA operational resilience and DORA operational resilience test go further.
ISO 22301 as base
You need a BCMS. 22301 gives you the shape.
Operational resilience additions
Impact tolerances for important business services, mapping of resources supporting each service, severe-but-plausible scenario testing.
DORA specifics
For EU financial entities, DORA adds prescriptive testing (including TLPT), reporting timelines and third-party regime.
A shared programme
The overlap is 70%+. Run one programme, tag artefacts to multiple frameworks, evidence once.
How ISO-STANDARD.app helps with ISO 22301
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 22301 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 22301 shape.
Supplier and third-party dependencies in ISO 22301
Your continuity is only as good as your suppliers'. Assess and rehearse the dependencies.
Identification
The BIA lists supplier dependencies for each activity. Rank by criticality.
Assessment
Critical suppliers should have their own BCMS or equivalent. Ask for evidence — 22301 certificate, BC test summary, exit plan.
Contract terms
Reciprocal notification obligations, cooperation in exercises, exit clauses. Not boilerplate — negotiated.
Substitutability
Critical suppliers you can't substitute in RTO time are a governance issue. Escalate to executive/board.
How ISO-STANDARD.app helps with ISO 22301
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 22301 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 22301 shape.
Management review of the BCMS
22301 requires management review at planned intervals. It's a real meeting, not a governance ritual.
Inputs
Status of actions from prior reviews, changes in external and internal issues, exercise findings, non-conformities, opportunities for improvement, resource needs.
Outputs
Decisions and actions on continual improvement of the BCMS and any need for changes.
Frequency
Typically annual; often quarterly for regulated organisations. Documented minutes.
Escalation
Sits within wider ISO 27001 / 9001 / 42001 management review where possible. Fewer meetings, coherent decisions.
How ISO-STANDARD.app helps with ISO 22301
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 22301 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 22301 shape.
Setting the scope of your BCMS
Scope decisions echo through every plan and exercise. Get them wrong and the BCMS bites your worst-case scenario.
Products and services in scope
Which lines of business the BCMS covers. Excluded scope must be defensible.
Locations and legal entities
Every site and entity that hosts in-scope activities.
Interested parties
Customers, regulators, employees, suppliers, insurers. Each has expectations the BCMS should acknowledge.
Change management
New product line, new location, acquisition = scope review. Not annual — event-driven.
How ISO-STANDARD.app helps with ISO 22301
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 22301 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 22301 shape.
Crisis communications: the plan you hope you never need
22301 wants documented, tested crisis communications. In an actual event, this is what customers and press remember.
Audiences
Employees, customers, regulators, suppliers, media, shareholders. Different messages, different channels.
Pre-drafted templates
Templates for common scenarios accelerate response. Legal review during peace, not during crisis.
Authority to communicate
Named individuals authorised to speak publicly. Escalation path documented.
Exercises
Communications rehearsals are separate from technical DR exercises. Both matter.
How ISO-STANDARD.app helps with ISO 22301
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 22301 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 22301 shape.
Getting ISO 22301 certified: a realistic timeline
9–15 months from zero for a mid-sized organisation. Faster if you have ISO 27001 already.
Months 1–3
Scope, BIA, risk assessment, stakeholder engagement. Executive sponsor confirmed.
Months 4–8
Plans developed, tested, adjusted. Documentation catalogue built. Exercises delivered.
Months 9–12
Internal audit, management review, corrective actions. Certification body Stage 1 audit.
Months 12–15
Stage 2 audit, findings closed, certificate issued. Surveillance audits annually.
How ISO-STANDARD.app helps with ISO 22301
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 22301 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 22301 shape.
Ready to evidence ISO 22301?
Load the pre-mapped controls, capture evidence continuously, and publish your ISO 22301 posture to buyers on demand.
Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.