Most business continuity programmes fail their certification audit on the same two things: an exercise that never happened, and a business impact analysis nobody has revisited since it was written. Neither is expensive to fix. Both are invisible until someone scores you clause by clause.
This assessment works through every clause of ISO 22301:2019, from context to continual improvement, and adds a certification-readiness section for the evidence a certification body will actually ask to see. It is free, it saves as you go, and you can stop and come back to it.
What this is, and what it is not
This is the tool. If you want the reading first, we have it: how to run an ISO 22301 gap analysis, a walkthrough of clauses 4 to 10, the five maturity levels, and the certification roadmap. Come back here when you want a score rather than an explanation.
What it is not is a certification audit, and it is not the internal audit that clause 9.2 requires. It is the honest self-scoring that tells you whether either of those is worth booking yet.
What this assessment covers
64 assessable items: every clause of the standard, plus seven checks on certification readiness.
| Domain | Items | What it asks about |
|---|---|---|
| Clause 4 — Context | 7 | Internal and external issues, climate change relevance, interested parties, legal and contractual requirements, scope |
| Clause 5 — Leadership | 4 | Top management commitment, the policy and its communication, roles and authorities |
| Clause 6 — Planning | 5 | Risks and opportunities for the BCMS, objectives and how they will be achieved, planning changes |
| Clause 7 — Support | 8 | Resources, competence, awareness, communication, and the documented information controls |
| Clause 8 — Operation | 22 | BIA and risk assessment, strategies and solutions, response structure, plans, recovery, exercising, and the 8.6 evaluation |
| Clause 9 — Performance evaluation | 7 | Monitoring and measurement, internal audit programme, management review inputs and outputs |
| Clause 10 — Improvement | 4 | Nonconformity, corrective action, documentation, continual improvement |
| Certification readiness | 7 | Scope and body, Stage 1 and Stage 2 evidence, audit coverage, management review, exercise, open actions |
Clause 8 is where certification is won or lost
Twenty-two of the 64 items sit in Clause 8, because that is where the standard stops being a management system and starts being business continuity. It is scored at the level an auditor reads it:
- 8.2.2 — the BIA has four parts, and the one usually thin is dependencies. Knowing an activity must resume in four hours is useless if nobody mapped what it depends on to do so.
- 8.3.2 — strategy options must cover protecting, stabilising, mitigating and recovering. Most organisations jump to recovery and never consider the other three.
- 8.3.5 — implementation. A selected strategy is not an implemented one. The gap between the two is where audits find real exposure.
- 8.4.2 — response structure is scored in four parts, including whether teams have the delegated authority to act. A team that must find a director before it can spend money is not a response team.
- 8.4.5 — recovery, the forgotten half. Most plans cover getting to a workaround and say nothing about coming back from it.
- 8.6 — evaluation of your documentation and capabilities, which the 2019 edition brought to the front and which is separate from internal audit.
How the scoring works
| Status | Weight | Means |
|---|---|---|
| Not started | 0% | No policy, process or activity exists |
| Planned | 25% | Agreed and scheduled, nothing in place yet |
| Partially implemented | 50% | In place for part of the scope, or applied inconsistently |
| Implemented, not evidenced | 75% | Operating as intended, but you could not prove it today |
| Implemented and evidenced | 100% | Operating as intended, with records an auditor can sample |
| Not applicable | — | A justified exclusion, removed from the score |
Business continuity punishes the “implemented, not evidenced” row harder than most standards, because the evidence is the capability. A plan nobody has exercised is a document, and an auditor will treat it as one.
Free score, or the full report
The assessment and your overall score are free. The full report is a one-off $39 and gives you every clause with your status and notes, the score broken down by clause, a prioritised gap list, and the specific documents from the ISO 22301 Toolkit that close each gap — as a PDF and a working Excel file.
How long does it take?
About 30 minutes. Clause 8 takes the longest and deserves to; the rest moves quickly if you know your management system. Answers save as you go.
Gap assessment, internal audit, certification audit
- Gap assessment — you, scoring yourself, with nothing riding on the answer. Start here.
- Internal audit — required by clause 9.2, must cover every clause before certification, and must be done by someone independent of the work being audited.
- Certification audit — Stage 1 reviews your documentation, Stage 2 tests whether the system actually operates. An accredited body, on a three-year cycle with surveillance visits.
What to do with your score
Below 40% — you are pre-BIA. Scope and business impact analysis first; nothing downstream is meaningful without them.
40–70% — usually documented but untested. Run an exercise, then fix what it exposes. That single step moves more clauses than any amount of writing.
Above 70% — check the certification-readiness section specifically. Audit coverage, a completed management review and a reported exercise are what decide whether Stage 2 goes ahead.
Frequently asked questions
Is this assessment really free?
Yes. Every clause, your section breakdown and your overall score cost nothing. The $39 full report is optional and adds the per-clause detail and document mapping.
Which edition does it assess?
ISO 22301:2019, including Amendment 1:2024, which added climate change to clauses 4.1 and 4.2. Certification bodies check for that amendment, so there is a question on it.
Is a third edition coming?
ISO 22301:2019 has completed systematic review and is marked for revision, with a committee draft in progress. No publication date is fixed, and the 2019 edition plus Amendment 1 remains the certifiable baseline. We will update this assessment when the new edition lands.
Do I need ISO 27001 first?
No. They are independent, though they share the same management system shape, so an organisation certified to one finds the other considerably easier. ISO 27001’s own continuity controls point at the work this assessment covers.
Is a high score the same as being certified?
No. Only an accredited certification body can certify you, after a two-stage audit. This tells you how that audit is likely to go.
Can I use this for a client?
Yes. Consultants use it as a first-meeting structure. Run one assessment per client organisation.
What happens to my answers?
They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.