An ISO 22301 assessment is any structured comparison of a business continuity management system against ISO 22301:2019 — and there are four distinct kinds, run at different times for different decisions, that get called by one name and confused with each other. A gap analysis is run before the build to plan it. A self-assessment scores every requirement of clauses 4 to 10 with a reference to where it is met and can run at any point. A readiness assessment is run last, on an operating system, against the six clauses that fail audits. A maturity assessment grades how deeply an operating system has taken root on a five-level scale. Pick the wrong one and the result answers a question nobody asked: a maturity profile on a system that has not exercised yet, or a readiness check on a BCMS whose business impact analysis is two years old. This guide sets out the four types of ISO 22301 assessment, what each decides, when to run it, who should run it, what it produces, and how the four fit into one certification cycle.

The four types of ISO 22301 assessment
| Type | Question it answers | When | Scope | Output |
|---|---|---|---|---|
| Gap analysis | What do we have to build, and in what order? | Before implementation; again on a new edition of the standard | All requirements, clauses 4–10, weighted by dependency | Prioritised work plan |
| Self-assessment | Where is each requirement met, how was that verified, and what concerns us? | During the build; before stage 1; between audits | Every requirement, clause 8 at sub-clause level | Evidence index with areas of concern |
| Readiness assessment | Would we pass stage 1 and stage 2 next month? | After one full cycle, before booking the audit | Six clauses: 8.2, 8.3, 8.4, 8.5, 9.2, 9.3 | Ready / partial / not ready with a close-out plan |
| Maturity assessment | How deeply has the BCMS taken root, and where is it thin? | After the first cycle; annually before management review | Eight dimensions on a five-level scale | Maturity profile and per-dimension targets |
ISO 22301 assessment type 1: the gap analysis
The gap analysis compares an organisation’s current arrangements — often no BCMS at all, or a set of IT disaster-recovery plans — against every requirement of ISO 22301:2019 to produce the implementation plan. Its trap is equal weighting: scoring clause 8.2, the business impact analysis and risk assessment, as one gap among thirty when everything under 8.3 and 8.4 is derived from it. Score dependency, and surface the time-gated clauses — 8.5 exercising, 9.2 internal audit, 9.3 management review — that set the certification date because they cannot be closed on paper. Our guide to the ISO 22301 gap analysis sets out the weighting.
ISO 22301 assessment type 2: the self-assessment
The self-assessment follows the standard’s own structure, clause by clause, with three columns per requirement: the reference in your system, how it was verified, and whether it is an area of concern. It is the gap analysis before the build, the progress record during it and the evidence index the stage 1 auditor follows, and it is the natural record for clause 8.6’s evaluation of business continuity documentation and capabilities. Its rules are that every reference must be openable, that verification is by someone other than the author, and that for 8.5, 9.2, 9.3 and 10.1 the reference must be a dated record. Our guide to the ISO 22301 self-assessment covers the scoring.
ISO 22301 assessment type 3: the readiness assessment
The readiness assessment is narrower and later. It assumes the BCMS has been built and has operated for a cycle, and checks the six clauses that produce most first-audit findings: BIA and risk assessment current (8.2), strategies traceable to the BIA (8.3), plans current and accessible (8.4), an exercise run and reported (8.5), an internal audit completed (9.2) and a management review held (9.3). Each is scored ready, partial or not ready with an evidence reference, one item per check is verified in the field, and the audit is booked only when the three time-gated checks have happened. Our guide to the ISO 22301 readiness assessment covers the six checks.
ISO 22301 assessment type 4: the maturity assessment
The maturity assessment grades an operating BCMS on how well each requirement is met rather than whether it is: five levels — initial, documented, operating, measured, embedded — across eight dimensions, from leadership to suppliers to improvement. It is the only one of the four that produces a target the standard does not set, and its most useful output is the profile, not the average: a system at level 4 on plans and level 1 on supplier continuity is a level-1 system on the day a supplier fails. Our guide to the ISO 22301 maturity assessment covers the scale and dimensions.
Who runs each ISO 22301 assessment
| Type | Best run by | Independence needed | Typical effort |
|---|---|---|---|
| Gap analysis | BCMS owner with a consultant or an experienced internal auditor | Low — it is a planning exercise | 2–5 days |
| Self-assessment | BCMS owner scores; second person verifies a sample | Medium — verification must not be by the author | 1–3 days |
| Readiness assessment | Internal auditor from another function or an external assessor | High — the value is field verification the owner cannot do objectively | 1–2 days |
| Maturity assessment | Internal audit, a second-line risk function or an external assessor | High — grading is judgement and needs distance | 1–3 days per site |
How the four fit one certification cycle
- Month 0: gap analysis. Weighted plan; time-gated clauses scheduled first.
- Months 1–6: self-assessment as the build record. The reference column fills in; concerns become the work list.
- Months 4–8: the cycle runs. Exercise, internal audit, management review, corrective actions — the records the next two assessments depend on.
- Month 8–9: readiness assessment. Six checks; book stage 1 only on all-ready.
- Stage 1 and stage 2. The self-assessment is the evidence index the auditor follows.
- Year 2 onward: maturity assessment annually before management review; self-assessment refreshed before each surveillance audit; gap analysis again when the third edition of ISO 22301 — at committee-draft stage in 2026 — is published.
Our guide to ISO 22301 certification covers the audit stages the assessments prepare for.
Choosing the right ISO 22301 assessment
| Situation | Assessment | Why |
|---|---|---|
| No BCMS; board wants certification | Gap analysis | You need the plan and the date, not a score |
| BCMS half-built; consultant leaving | Self-assessment | The reference column is the handover |
| Certification body asking for dates | Readiness assessment | Six checks decide whether the date holds |
| Certified for two years; regulator asks how resilient you are | Maturity assessment | The certificate cannot answer that question; the profile can |
| New edition of the standard published | Gap analysis against the new text | Clause changes need a plan, not a profile |
| Surveillance audit in three months | Self-assessment refresh | Concerns become corrective actions before the auditor finds them |
Frequently asked questions
What is an ISO 22301 assessment?
A structured comparison of a business continuity management system against ISO 22301:2019. Four types exist: the gap analysis (plan the build), the self-assessment (clause-by-clause evidence index), the readiness assessment (six checks before the audit) and the maturity assessment (five-level grading of an operating system).
Which one do we need first?
If there is no BCMS, the gap analysis. If the BCMS exists, the self-assessment — its reference column tells you within a day whether you are planning a build or preparing an audit.
Is the certification audit an assessment?
It is the third-party assessment the four internal types prepare for: stage 1 reviews documentation and readiness, stage 2 tests implementation and effectiveness. None of the four replaces it.
Does ISO 22301 require any of these?
Not by name. Clause 8.6 requires evaluation of continuity documentation and capabilities, 9.1 requires evaluation of BCMS performance and effectiveness, and 9.2 requires an internal audit — the self-assessment and maturity assessment are the usual evidence for the first two.
Can one tool do all four?
A clause-by-clause tool covers the gap analysis and the self-assessment directly and supplies the evidence index the readiness and maturity assessments start from; the last two add field verification and grading on top.
Where this leaves you
Name the ISO 22301 assessment you are running before you run it. Gap analysis to plan, self-assessment to build and index, readiness assessment to decide the audit date, maturity assessment to set the target the standard never sets — in that order, on one cycle, each producing a different record. The confusion between them costs months; the sequence costs a few days a year.
References
- ISO 22301:2019 — Security and resilience — Business continuity management systems — Requirements — Second edition, October 2019, with Amd 1:2024; ISO/CD 22301 (third edition) is under development.
- ISO 22313:2020 — Guidance on the use of ISO 22301 — Guidance on applying each clause the assessments score.
More on ISO 22301 assessment
- ISO 22301 assessment: the four types — you are here
- ISO 22301 gap analysis
- ISO 22301 self-assessment
- ISO 22301 readiness assessment
- ISO 22301 maturity assessment
- Supplier business continuity assessment
The ISO 22301 Assessment Tool covers the gap analysis and the self-assessment clause by clause and supplies the evidence index the other two start from, or start with the free templates.