An ISO 22301 maturity assessment measures what a certificate cannot: not whether the business continuity management system meets ISO 22301:2019, but how far it has taken root. Two organisations can hold the same certificate, one with a continuity plan the risk manager updates before each audit and exercises annually because clause 8.5 says so, the other with recovery objectives that product owners argue about, suppliers assessed for their continuity, exercises that fail on purpose to find the gap, and directors who read the exercise report before the audit report.
A conformity audit reports both as compliant. A maturity assessment grades them. This guide sets out a five-level maturity scale for ISO 22301, the eight dimensions to score it on, the evidence that separates each level, how the assessment differs from a gap analysis and a readiness assessment, and how to use the result to set a target the standard itself never sets.

ISO 22301 maturity assessment vs conformity audit
ISO 22301:2019 is a requirements standard: clauses 4.1 to 10.2 are met or not, and the certification audit reports nonconformities. It deliberately permits a system that is documented, operated and evidenced at the minimum to be certified — a business impact analysis done once, a strategy that follows it, plans that exist, an exercise that ran, an audit and a review. A maturity assessment adds the grading.
For each dimension it asks whether the requirement is met because a document says so, because people follow it, because the organisation measures and improves it, or because it is how decisions are made when no audit is due. The distinction matters because recovery in a real disruption tracks maturity, not certification. Our guide to the four types of ISO 22301 assessment places the maturity assessment among the gap analysis, self-assessment and readiness assessment.
The five levels of the ISO 22301 maturity assessment
| Level | Name | How the BCMS behaves | Typical evidence |
|---|---|---|---|
| 1 | Initial | Continuity depends on individuals; plans exist for some areas, written after an incident or a customer request | Isolated plans; no BIA; no exercise record |
| 2 | Documented | The BCMS is written to the clause structure; BIA, risk assessment, strategies and plans exist as documents; exercising is planned | Complete documented information under 7.5; first internal audit scheduled |
| 3 | Operating | The processes run on a cycle: BIA reviewed, exercises held and reported, audits and reviews completed, corrective actions closed | Dated cycle records; exercise reports with findings; management review minutes |
| 4 | Measured | Performance is measured against objectives — recovery achieved versus RTO in exercises, plan currency, supplier assessment coverage — and drives change | Metrics in 9.1; trend analysis; decisions traceable to data |
| 5 | Embedded | Continuity is a design input for new products, sites, suppliers and systems; owners set and defend their own recovery objectives; exercises are designed to fail and do | Change-management gates; product-owner sign-off of RTOs; exercise scenarios that escalate year on year |
The eight dimensions scored
| Dimension | ISO 22301 clauses | Level 2 looks like | Level 4–5 looks like |
|---|---|---|---|
| Leadership and governance | 5.1–5.3, 6.2 | A signed policy and named roles | Top management sets continuity objectives, funds them and reads exercise results before audits |
| Business impact analysis | 8.2.2 | A BIA spreadsheet dated once | BIA refreshed on change and annually; dependencies mapped; RTO/RPO owned by process owners |
| Risk assessment | 8.2.3 | A risk register for disruption | Risk treatment linked to strategy choices; threats reviewed with the BIA |
| Strategies and solutions | 8.3 | Strategies listed | Each solution traceable to a BIA output; resource requirements costed and provided |
| Plans and procedures | 8.4 | Plans exist for the main sites | Response structure, warning and communication, plans and recovery procedures current, accessible offline, with named alternates |
| Exercising and testing | 8.5 | One tabletop a year | A programme escalating from walkthrough to live failover; reports with findings; findings closed and re-tested |
| Suppliers and dependencies | 8.1, 8.2.2, 8.3 | Key suppliers listed | Supplier continuity assessed and contracted; dependencies exercised; ISO/TS 22318 practice |
| Monitoring, audit and improvement | 8.6, 9.1–9.3, 10 | Audit and review held once | Documentation and capability evaluated (8.6); metrics trend; corrective actions verified effective |
In an ISO 22301 maturity assessment, score each dimension separately before any average is taken. A BCMS at level 4 on plans and level 1 on suppliers is a level-1 system on the day a supplier fails, and an average of 2.5 hides that. Our guide to the supplier business continuity assessment covers the dimension that scores lowest most often.
Running the ISO 22301 maturity assessment
- Define the evidence rule per level. Level 3 requires a dated record of the cycle running; level 4 requires a measure and a decision it changed; level 5 requires a design-stage record. Write the rules down before scoring so two assessors reach the same level.
- Score from records, then interview. Documents set the ceiling — a dimension cannot exceed level 2 without cycle records — and interviews confirm whether the records describe behaviour.
- Test one dimension in the field. Ask a process owner their RTO and where the plan is; ask a supplier manager when the last continuity assessment was. The gap between paper and answer is the maturity finding.
- Plot the profile. Eight bars, not one number. Present the lowest dimension first.
- Set the target per dimension. Not every dimension needs level 5; a regulated firm may need level 4 on exercising and level 3 on governance. The target is a management decision the standard leaves to you.
- Re-assess annually, before management review, so the profile is an input to 9.3.
Reading the ISO 22301 maturity assessment result
| Profile | What it usually means | First move |
|---|---|---|
| Level 2 across the board | A documentation project that has not started operating; common six months before a first audit | Run the cycle: exercise, audit, review — see the readiness assessment |
| High plans, low exercising | Plans written to pass document review; never tested | Exercise the worst plan first; expect it to fail |
| High BIA, low strategies | Analysis done, money not spent | Cost the resource requirements in 8.3 and take them to top management |
| High everything, low suppliers | The most common certified profile | Supplier continuity assessment for the top dependencies |
| Level 4–5 in pockets | Maturity depends on one person or one site | Standardise the practice into the process, not the person |
Frequently asked questions
What is an ISO 22301 maturity assessment?
A graded assessment of how deeply a business continuity management system has taken root, scored on a five-level scale across eight dimensions, as distinct from a conformity audit that reports only whether ISO 22301:2019 requirements are met.
Does ISO 22301 define maturity levels?
No. ISO 22301 is a requirements standard and its 2019 edition, amended in 2024, has no maturity model. The scale here is a practitioner model; ISO 22313:2020 gives guidance on applying the requirements but does not grade them.
How is it different from a gap analysis?
A gap analysis compares the system against every requirement to plan the build; a maturity assessment grades an operating system on how well each requirement is met. Run the gap analysis before implementation and the maturity assessment after the first cycle.
What level do we need for certification?
Level 2 with the cycle records of level 3: documented information complete, plus an exercise, an internal audit and a management review completed. Certification does not require level 4 or 5.
How long does it take?
One to three days for a single-site organisation with records available, longer for multi-site groups where each site is profiled separately.
Where this leaves you
Run the ISO 22301 maturity assessment on eight dimensions, score from records before interviews, present the profile rather than the average, and set a target per dimension that reflects what a real disruption would test. The certificate says the system exists; the profile says whether it would work.
References
- ISO 22301:2019 — Security and resilience — Business continuity management systems — Requirements — Second edition, October 2019, with Amd 1:2024; a third edition is at committee-draft stage (ISO/CD 22301).
- ISO 22313:2020 — Guidance on the use of ISO 22301 — Guidance on applying the requirements.
- ISO/TS 22318:2021 — Guidelines for supply chain continuity management — The supplier dimension.
More on ISO 22301 assessment
- ISO 22301 maturity assessment — you are here
- ISO 22301 assessment: the four types
- ISO 22301 readiness assessment
- ISO 22301 self-assessment
- ISO 22301 gap analysis
- Supplier business continuity assessment
To score where the BCMS stands clause by clause before profiling maturity, use the ISO 22301 Assessment Tool, or start with the free templates.