The ISO 22301 certification timeline runs six to twelve months for most single-site organisations, and the thing that decides where you land in that range is almost never your document set. It is how long it takes to produce evidence that your business continuity plans have been exercised, evaluated and corrected — because that evidence cannot be written in a weekend, and an auditor will ask for it on day one of Stage 2.
That is what makes ISO 22301 different from ISO 9001 or ISO 14001. Those standards will accept a young management system that is running correctly. ISO 22301 asks you to prove a capability you hope never to use, and the only proof it accepts is a record of you having rehearsed it. This guide sets out the ISO 22301 certification timeline phase by phase, what actually sets the floor, how certification bodies decide your audit days, and the four things that reliably add months.
The realistic ISO 22301 certification timeline, phase by phase
The schedule below is a typical range for an organisation starting from a standing start — no BCMS, some disaster recovery documentation, and one person who can give the project real time each week. Phases overlap in practice; the durations are working effort, not calendar isolation.
| Phase | Typical duration | What must exist when it ends |
|---|---|---|
| Scope, context, leadership (clauses 4–5) | 3–6 weeks | Defined BCMS scope, interested parties, policy, assigned roles, signed-off objectives |
| Business impact analysis and risk assessment (8.2) | 4–8 weeks | Prioritised activities with recovery time objectives, a documented BIA method, a risk assessment tied to disruption |
| Strategies and solutions (8.3) | 3–6 weeks | Selected strategies with resource requirements, and a decision trail showing why |
| Plans and procedures (8.4) | 4–8 weeks | Incident response structure, warning and communication, business continuity plans, recovery procedures |
| Exercise programme (8.5) and evaluation (8.6) | 6–12 weeks | At least one completed exercise, a post-exercise report, corrective actions raised and closed |
| Internal audit (9.2) and management review (9.3) | 3–4 weeks | A full-scope internal audit, findings, and a management review covering every required input |
| Stage 1 audit | 1 day typical, then a 2–6 week gap | Documentation review, readiness judgement, list of areas of concern for Stage 2 |
| Stage 2 audit and certification decision | 2–5 days on site, decision 2–6 weeks later | Evidence of implementation, nonconformities closed, independent review and decision |
Add those up and you get roughly 24 to 44 weeks. Six months is achievable and nine is more common. Anything under four months means either a very narrow scope or a BCMS you inherited and are now formalising.
What actually sets the ISO 22301 certification timeline floor
Four clauses do most of the work, and none of them can be compressed by hiring more writers.
Clause 8.2 — the business impact analysis. The BIA is not a survey. It has to produce prioritised activities with recovery time objectives that the people who own those activities actually agree to. In practice that means workshops with operations, finance and IT, then a round of challenge when someone claims their process must be back in four hours. Rushed BIAs are the single most common Stage 2 finding, because the auditor only has to ask one process owner whether they recognise the number next to their name. If your recovery targets are still vague, work through RTO and RPO before you start the analysis.
Clause 8.5 — the exercise programme. You need a programme, not one event: a documented plan for how and how often you will exercise, plus at least one completed exercise with a written outcome before Stage 2. A tabletop is acceptable for a first cycle. The practical constraint is diary time — getting the incident management team in a room, running the scenario, writing it up, and then closing whatever the exercise exposed adds six to twelve weeks that no amount of budget removes. Our guide to running a business continuity exercise covers the scenario design and the write-up.
Clause 8.6 — evaluation of business continuity documentation and capabilities. This clause is frequently missed entirely, because it did not exist under the withdrawn 2012 edition, where the equivalent requirement sat at 9.1.2. It asks you to evaluate your BC documentation and capabilities at planned intervals and after changes or exercises. If your toolkit or gap assessment does not mention 8.6, it is built on the 2012 clause map and you will discover the hole at Stage 2.
Clauses 9.2 and 9.3 — internal audit and management review. Both must be complete before Stage 2, and the management review has to cover the specific inputs the standard lists, including exercise results. This is a three-to-four week block that people routinely forget to schedule, then discover their executives cannot meet for a month.
Stage 1, Stage 2 and the gap between them
Accredited certification runs in two stages under ISO/IEC 17021-1. Stage 1 is largely a documentation and readiness review; Stage 2 tests implementation.
There is no fixed interval between them. Clause 9.3.1.2.4 of ISO/IEC 17021-1 says the gap is set by the client’s need to resolve areas of concern identified at Stage 1 and by the certification body’s own arrangements — and it allows the certification body to repeat all or part of Stage 1, which in practice means cancelling your Stage 2 date. Two to six weeks is normal, and that gap is the piece of the ISO 22301 certification timeline you have the least control over. If Stage 1 finds your exercise programme has not run, expect the longer end or a reschedule.
After Stage 2 the decision is made by someone who was not on the audit team. Clause 9.5.2 requires that major nonconformities are closed before that decision, and minor ones have an accepted corrective action plan. Then clause 9.1.3.3 starts the clock on the maintenance cycle: your first surveillance audit must be no more than twelve months from the certification decision date, and surveillance runs at least once per calendar year outside recertification years. The certificate itself runs a three-year cycle.
How certification bodies work out your audit days
Here is something that surprises buyers comparing quotes: for ISO 22301 there is no published audit-day table to compare them against.
For quality, environmental and occupational health and safety systems, audit duration comes from a mandatory accreditation document — the old IAF MD 5, now carried by Global ACI as TECH-3-004, whose scope is stated in its title as quality, environmental and occupational health and safety management systems only. Information security has its own table in ISO/IEC 27006. Business continuity has neither. Certification bodies apply the same methodology by analogy: effective number of personnel, number of sites, complexity, and the risk profile of what you do.
What does bind them is ISO/IEC 17021-1 clause 9.1.4. They must have a documented procedure for determining audit time; must consider the requirements of the standard, the complexity of your management system, your technological and regulatory context, outsourcing, and the results of prior audits; and must record the duration and its justification. Clause 9.1.4.4 adds a detail worth knowing when you read a quote — time spent by technical experts, translators, interpreters, observers and auditors-in-training does not count toward the audit duration.
So ask any certification body two questions: how many auditor days are you proposing for Stage 1 and Stage 2, and what is the documented justification. A body that cannot answer the second one is quoting from habit, and audit days set both the cost and the back end of your ISO 22301 certification timeline. The day count also drives the fee, which is broken down in our guide to ISO 22301 certification cost.
ISO 22301 certification timeline by organisation size
Size matters less than the number of prioritised activities and sites in scope. A 400-person company with one revenue-critical service can certify faster than a 60-person company with eight.
| Profile | Preparation to Stage 2 | Stage 2 on site | Total to certificate |
|---|---|---|---|
| Single site, under 50 staff, one critical service | 4–7 months | 2 days | 5–8 months |
| Single site, 50–250 staff, several services | 6–9 months | 2–3 days | 7–11 months |
| Two to five sites, 250–1,000 staff | 8–12 months | 3–5 days | 10–15 months |
| Regulated or multi-country, complex supply chain | 10–15 months | 5 days or more | 12–18 months |
These are typical ranges, not quotes. Multi-site programmes are sampled, so the on-site days rise more slowly than the site count — but the preparation time rises faster, because each site needs its own plans and its own exercise evidence.
Four things that blow the ISO 22301 certification timeline out
A scope that swallowed the whole company. The fastest certifications scope the BCMS around the services whose loss would actually hurt, then extend later. Scoping everything at once multiplies the BIA, the plans and the exercises simultaneously.
Plans that were written but never exercised. This is the classic four-month delay. The documentation is immaculate, Stage 1 passes, and Stage 2 asks for the exercise report. There is none, and now you need a scenario, a diary slot with the executive team, a write-up and a corrective action cycle.
A major nonconformity you cannot close quickly. ISO/IEC 17021-1 clause 9.5.3.2 is unforgiving: if the certification body cannot verify that corrections and corrective actions for any major nonconformity have been implemented within six months of the last day of Stage 2, it must conduct another Stage 2 before recommending certification. A missing exercise programme or an unsigned BIA is exactly the kind of finding that takes longer than people expect.
An assessment tool built on the wrong edition. Gap tools that cite clause 5.4, 9.1.1 or 9.1.2 are mapped to ISO 22301:2012, which was superseded in 2019. They will tell you that you are ready while clause 8.6 has never been looked at. A quick check before you start: run a ISO 22301 gap analysis against the 2019 clause list and confirm 6.3, 8.2.3 and 8.6 all appear.
Should you wait for the next edition?
No. A third edition of ISO 22301 is in development with ISO/TC 292, but as of September 2026 it sits at committee draft stage 30.60 — close of comment period. From there it still has to pass DIS and FDIS ballots, which normally takes well over a year, and a published revision then carries a multi-year transition window in which existing certificates remain valid. The current requirements standard is ISO 22301:2019, edition 2, published October 2019, now with one amendment: ISO 22301:2019/Amd 1:2024, which adds climate change to the context requirements in clause 4.1 and to interested party expectations in 4.2. Build to that. Waiting costs you a certification cycle to avoid a transition audit that is typically handled in a surveillance visit.
ISO 22301 certification timeline: frequently asked questions
Can we certify in three months? Only if the BCMS already exists in substance and you are formalising it — plans in use, an exercise already run, recovery objectives agreed. From nothing, three months does not leave room for an exercise cycle plus internal audit plus management review, and a certification body that promises it is not planning an accredited audit.
Does having ISO 27001 shorten the ISO 22301 certification timeline? Yes, by roughly one to three months. Clauses 4 through 10 share the harmonised management system structure, so your context, leadership, competence, documented information, internal audit and management review processes transfer directly. Annex A control 5.29 and the 5.30 ICT readiness control also give you a starting point. What does not transfer is clause 8 — the BIA, strategies, plans and exercises are entirely new work. See ISO 27001 vs ISO 22301 for where the two actually overlap.
How long does the certificate last? Three years, maintained by surveillance audits. The first one must fall within twelve months of the certification decision date, and there must be at least one in each calendar year that is not a recertification year. Recertification happens before the three years expire.
What is the single most common reason a Stage 2 slips? Exercise evidence. Not policy, not risk registers — the absence of a completed exercise with a written outcome and closed actions.
Do we need a full live failover test before certification? No. The standard requires an exercise programme consistent with the scope and the objectives, and a structured tabletop with the right people, a realistic scenario and an honest write-up satisfies a first-cycle audit. What it does not accept is a plan that has never been tested in any form.
Where to start
The controllable part of an ISO 22301 certification timeline is the documentation cycle — the weeks lost drafting a BIA method, an incident response structure and a management review agenda from a blank page. If you want that compressed, the ISO 22301 Toolkit covers the BCMS document set mapped to the 2019 clauses, so the project time goes into the BIA workshops and the exercise instead of into formatting. For the audit mechanics themselves, our guide to how ISO 22301 certification works walks through the stages in detail.
Plan for nine months, protect the exercise date in the diary before anything else, and the ISO 22301 certification timeline tends to look after itself.