ISO 22301 implementation goes wrong in a predictable way: the documentation gets
written quickly, the business impact analysis gets rushed because it needs other people’s time, and
the exercise programme gets scheduled after the certification audit. This is a ten-step plan that
sequences it properly, with honest timings.
Before step one of ISO 22301 implementation: secure the time, not the budget
The scarce resource in ISO 22301 implementation is not money, it is access to operational
managers.
The business impact analysis requires structured time from the people who run the activities, and
they have day jobs. Get that access agreed by top management at the start, in writing, because clause
5.1 makes them accountable for resourcing the system and this is the resource that actually binds.
The ten steps of ISO 22301 implementation
- Gap analysis (2–3 weeks). The first move in any ISO 22301
implementation: score each clause, produce a costed action list.
This is what makes the remaining nine steps estimable. - Scope and context (2–3 weeks). Decide which products and services are in
scope — the decision that shapes everything downstream. Record context issues including climate
change, and interested parties with their legal and regulatory requirements. - Policy, roles and objectives (1–2 weeks). Short policy, documented response
roles with deputies, measurable objectives. - Business impact analysis (6–12 weeks). The long pole. Agree impact
categories and scales first, interview activity owners, derive MTPD, RTO, RPO and MBCO, map
dependencies, then validate with senior management. See our guide to the
business impact analysis. - Risk assessment (3–4 weeks, overlapping). The other half of clause 8.2. What could disrupt the
prioritized activities, and what will you do about it. - Strategies and solutions (4–8 weeks). Clause 8.3 — select options
that genuinely meet the RTOs, and cost them. This is where ISO 22301 implementation stops being a
documentation project and starts requiring investment decisions. - Plans and procedures (4–6 weeks). Response structure, activation criteria,
communication, recovery. See the
business continuity plan guide. - Competence and awareness (2–4 weeks, overlapping). Train the response
roles, not just the general population. - Exercise programme (2–4 months). At least one meaningful exercise, run and
evaluated, with changes made as a result. Cannot be compressed. - Internal audit, management review, certification. Both are prerequisites. See
the internal audit checklist and
ISO 22301 certification.
Start from drafted documents, not a blank page.
The ISO 22301 Toolkit supplies every document in this plan in editable Word and Excel — scope, policy, BIA and risk workbooks, strategy records, plans, exercise programme and audit set — so implementation becomes editing rather than authoring.
The three steps ISO 22301 implementation plans always underestimate
Step 4, the business impact analysis. Plans allow two weeks. It takes six to
twelve, because the time is other people’s and because the first pass usually has to be redone once
everyone realises the impact scales were applied inconsistently. Agreeing the scales before any
interview is the single highest-value hour in the project.
Step 6, strategies and solutions. This is where an honest ISO 22301 implementation
discovers that meeting the RTOs the business asked for requires capability the business has not
bought. That conversation is the point of the standard, but it needs to happen with months to spare,
not weeks.
Step 9, the exercise programme. Routinely scheduled after certification. It cannot
be: clause 8.5 requires the programme, 8.6 requires evaluation, and stage 2 will ask for the results.
Budget two to four months and start as soon as a first draft plan exists rather than waiting for
perfection.
ISO 22301 implementation alongside ISO 27001
If you already run ISO 27001, much of ISO 22301 implementation transfers: clauses 4, 5, 6, 7,
9 and 10 map across — same harmonized
structure, same document control, internal audit and management review machinery, and a risk
discipline your people already understand. Budget that saving against clause 8, which is almost
entirely continuity-specific and which no other standard prepares you for. Be careful of one trap:
ISO 27001 Annex A contains continuity controls, and teams sometimes assume those satisfy ISO 22301.
They do not — they address continuity of information security, which is a subset.
A third edition is in development
ISO 22301:2019 is the second edition, published in October 2019 and running to just 21 pages of requirements. It is now marked on iso.org as an International Standard to be revised, and a third edition, ISO/CD 22301, is under development at stage 30.60, close of comment period.
That is an early stage — earlier than a draft international standard — so publication is not imminent and the content will still change materially. There is nothing to act on yet, and any supplier telling you to prepare for edition 3 is selling something. What it does tell you is that a transition period is coming at some point, and organisations whose documentation is cleanly mapped to clauses handle those in weeks rather than months.
One change is already live. ISO 22301:2019/Amd 1:2024, the climate action amendment, adds climate change to the context requirements in clause 4.1 and to interested-party expectations in clause 4.2. For a business continuity system this is less of a bolt-on than it is elsewhere: physical climate risk is a disruption scenario, and most existing continuity plans already assume weather events without ever having recorded climate as a context issue.
A realistic total for ISO 22301 implementation
For a single-site organisation of a hundred to five hundred people with no existing certification,
nine to fifteen months from gap analysis to certificate is defensible. Six to nine is
achievable where ISO 27001 already exists and continuity practice is mature. Anything under six months
means either the scope is genuinely small or the exercise programme has been skipped — and the
exercise programme is the part an auditor will look at hardest.
References
- ISO 22301:2019 — the standard itself on iso.org.
- ISO 22313:2020 — guidance on the use of ISO 22301.
- ISO/TS 22317:2021 — guidelines for business impact analysis.
- ISO 22301:2019/Amd 1:2024 — the climate action amendment.
More on ISO 22301 and business continuity
- ISO 22301 certification
- ISO 22301 implementation guide — you are here
- ISO 22301 mandatory documents
- business impact analysis
- business continuity plan
- ISO 22301 internal audit checklist
All of these are covered by the ISO 22301 Toolkit. To score where you stand first, use the ISO 22301 Assessment Tool, or start with the free ISO 22301 templates.