ISO 22301 certification demonstrates that an organisation’s business continuity
management system meets the international standard. This guide covers the audit stages, what makes
this standard different from the other management system standards, how long it takes, and where
first attempts come unstuck.
What ISO 22301 certification proves
Certification is an independent audit of your business continuity management system against
ISO 22301:2019, carried out by an accredited
certification body, resulting in a certificate over a defined scope: legal entity, sites, and the
products and services covered.
The scope of ISO 22301 certification matters more than in most standards, and it is worth getting right early.
A certificate covering “IT services at the Manchester office” is not a certificate covering the
business, and sophisticated customers read the scope before they read the logo. Because ISO 22301
certification is frequently bought to satisfy a customer, a tender or a regulator, a scope drawn too
narrowly to be useful is a wasted project. Draw it around the products and services your customers
actually depend on.
The stages of ISO 22301 certification
- Gap analysis. The cheapest step in ISO 22301 certification: score current
practice against each clause before an external auditor does it for you. - Implementation. Scope, policy, business impact analysis, risk assessment,
continuity strategies, plans, and the exercise programme. - Exercise the plans. Clause 8.5 requires an exercise programme, and clause 8.6
requires evaluation of your documentation and capabilities. Both need to have genuinely run. - Internal audit and management review. Prerequisites of ISO 22301 certification,
not follow-up activities. - Stage 1 audit. A documentation and readiness review: scope, policy, the BIA, the
risk assessment, and whether the exercise programme exists in fact rather than on paper. - Stage 2 audit. The full assessment on site, sampling records and testing whether
people named in the plans know what they are supposed to do. - Nonconformity closure, then surveillance annually and
recertification on a three-year cycle.
Everything stage 1 asks to see, already written.
The ISO 22301 Toolkit covers the scope and policy, BIA and risk assessment workbooks, continuity strategies, plan templates, the exercise programme and the full internal audit set — each mapped to the clause it satisfies.
What makes ISO 22301 certification different
Most management system standards are audited by reading records. This one is audited by testing
whether a capability exists. Clause 8.5 requires an exercise programme, and clause 8.6 requires you
to evaluate your business continuity documentation and capabilities against your own requirements.
An auditor will ask when you last exercised a plan, what went wrong, and what you changed as a
result — and “nothing went wrong” is the answer that invites a longer conversation, because an
exercise that surfaces no issues was not a real test.
The second difference is that the plans have to work for people who are not in the room. An
auditor may pick a name from a call tree and ask that person what they would do. This is why
ISO 22301 certification is difficult to fake in a way that, say, a documentation-heavy standard is
not.
How long ISO 22301 certification takes
Six to twelve months is realistic from a standing start for a single-site
organisation, and nine to eighteen where there are multiple sites, complex supply chains or
regulatory overlay. The pacing item is almost never the writing. It is the business impact analysis,
which requires time from operational managers across the business, and the exercise programme, which
needs at least one meaningful exercise run and evaluated before the audit.
If you already hold ISO 27001, expect a genuine saving: clauses 4, 5, 7, 9 and 10 share the
harmonized structure, and the risk assessment discipline transfers. What does not transfer is clause
8, which is almost entirely specific to continuity.
What drives the cost of ISO 22301 certification
- Audit days, which scale with headcount, sites and the complexity of the
ISO 22301 certification scope. - Scope breadth — more products and services in scope means more prioritized
activities to examine. - Internal time on the BIA, which is the largest hidden cost and the one most
often left out of the business case. - Exercises, particularly if they involve taking systems offline or standing down
staff for a day. - Consultancy and documentation effort, the latter reducible with a template set.
A third edition is in development
ISO 22301:2019 is the second edition, published in October 2019 and running to just 21 pages of requirements. It is now marked on iso.org as an International Standard to be revised, and a third edition, ISO/CD 22301, is under development at stage 30.60, close of comment period.
That is an early stage — earlier than a draft international standard — so publication is not imminent and the content will still change materially. There is nothing to act on yet, and any supplier telling you to prepare for edition 3 is selling something. What it does tell you is that a transition period is coming at some point, and organisations whose documentation is cleanly mapped to clauses handle those in weeks rather than months.
One change is already live. ISO 22301:2019/Amd 1:2024, the climate action amendment, adds climate change to the context requirements in clause 4.1 and to interested-party expectations in clause 4.2. For a business continuity system this is less of a bolt-on than it is elsewhere: physical climate risk is a disruption scenario, and most existing continuity plans already assume weather events without ever having recorded climate as a context issue.
Why first attempts at ISO 22301 certification fail
- A business impact analysis that was never validated by the business. Recovery
time objectives set by the continuity manager alone do not survive an auditor asking the process
owner whether they agree. - Plans that have never been exercised, or exercised once as a tabletop with no
evaluation record. - Strategies that do not match the BIA. If the BIA says four hours and the strategy
delivers two days, clause 8.3 is not met — and this mismatch is remarkably common. - Dependencies not mapped, particularly suppliers and outsourced IT.
- A scope so narrow it excludes the activities customers care about.
- No internal audit or management review yet.
References
- ISO 22301:2019 — the standard itself on iso.org.
- ISO 22313:2020 — guidance on the use of ISO 22301.
- ISO/TS 22317:2021 — guidelines for business impact analysis.
- ISO 22301:2019/Amd 1:2024 — the climate action amendment.
More on ISO 22301 and business continuity
- ISO 22301 certification — you are here
- ISO 22301 implementation guide
- ISO 22301 mandatory documents
- business impact analysis
- business continuity plan
- ISO 22301 internal audit checklist
All of these are covered by the ISO 22301 Toolkit. To score where you stand first, use the ISO 22301 Assessment Tool, or start with the free ISO 22301 templates.