Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 22301 Implementation — guide from Governance Docs

How to Implement ISO 22301: A Ten-Step Plan

ISO 22301 implementation goes wrong in a predictable way: the documentation gets
written quickly, the business impact analysis gets rushed because it needs other people’s time, and
the exercise programme gets scheduled after the certification audit. This is a ten-step plan that
sequences it properly, with honest timings.

Before step one of ISO 22301 implementation: secure the time, not the budget

The scarce resource in ISO 22301 implementation is not money, it is access to operational
managers.
The business impact analysis requires structured time from the people who run the activities, and
they have day jobs. Get that access agreed by top management at the start, in writing, because clause
5.1 makes them accountable for resourcing the system and this is the resource that actually binds.

The ten steps of ISO 22301 implementation

  1. Gap analysis (2–3 weeks). The first move in any ISO 22301
    implementation: score each clause, produce a costed action list.
    This is what makes the remaining nine steps estimable.
  2. Scope and context (2–3 weeks). Decide which products and services are in
    scope — the decision that shapes everything downstream. Record context issues including climate
    change, and interested parties with their legal and regulatory requirements.
  3. Policy, roles and objectives (1–2 weeks). Short policy, documented response
    roles with deputies, measurable objectives.
  4. Business impact analysis (6–12 weeks). The long pole. Agree impact
    categories and scales first, interview activity owners, derive MTPD, RTO, RPO and MBCO, map
    dependencies, then validate with senior management. See our guide to the
    business impact analysis.
  5. Risk assessment (3–4 weeks, overlapping). The other half of clause 8.2. What could disrupt the
    prioritized activities, and what will you do about it.
  6. Strategies and solutions (4–8 weeks). Clause 8.3 — select options
    that genuinely meet the RTOs, and cost them. This is where ISO 22301 implementation stops being a
    documentation project and starts requiring investment decisions.
  7. Plans and procedures (4–6 weeks). Response structure, activation criteria,
    communication, recovery. See the
    business continuity plan guide.
  8. Competence and awareness (2–4 weeks, overlapping). Train the response
    roles, not just the general population.
  9. Exercise programme (2–4 months). At least one meaningful exercise, run and
    evaluated, with changes made as a result. Cannot be compressed.
  10. Internal audit, management review, certification. Both are prerequisites. See
    the internal audit checklist and
    ISO 22301 certification.

Start from drafted documents, not a blank page.

The ISO 22301 Toolkit supplies every document in this plan in editable Word and Excel — scope, policy, BIA and risk workbooks, strategy records, plans, exercise programme and audit set — so implementation becomes editing rather than authoring.

Explore the ISO 22301 Toolkit →

The three steps ISO 22301 implementation plans always underestimate

Step 4, the business impact analysis. Plans allow two weeks. It takes six to
twelve, because the time is other people’s and because the first pass usually has to be redone once
everyone realises the impact scales were applied inconsistently. Agreeing the scales before any
interview is the single highest-value hour in the project.

Step 6, strategies and solutions. This is where an honest ISO 22301 implementation
discovers that meeting the RTOs the business asked for requires capability the business has not
bought. That conversation is the point of the standard, but it needs to happen with months to spare,
not weeks.

Step 9, the exercise programme. Routinely scheduled after certification. It cannot
be: clause 8.5 requires the programme, 8.6 requires evaluation, and stage 2 will ask for the results.
Budget two to four months and start as soon as a first draft plan exists rather than waiting for
perfection.

ISO 22301 implementation alongside ISO 27001

If you already run ISO 27001, much of ISO 22301 implementation transfers: clauses 4, 5, 6, 7,
9 and 10 map across — same harmonized
structure, same document control, internal audit and management review machinery, and a risk
discipline your people already understand. Budget that saving against clause 8, which is almost
entirely continuity-specific and which no other standard prepares you for. Be careful of one trap:
ISO 27001 Annex A contains continuity controls, and teams sometimes assume those satisfy ISO 22301.
They do not — they address continuity of information security, which is a subset.

A third edition is in development

ISO 22301:2019 is the second edition, published in October 2019 and running to just 21 pages of requirements. It is now marked on iso.org as an International Standard to be revised, and a third edition, ISO/CD 22301, is under development at stage 30.60, close of comment period.

That is an early stage — earlier than a draft international standard — so publication is not imminent and the content will still change materially. There is nothing to act on yet, and any supplier telling you to prepare for edition 3 is selling something. What it does tell you is that a transition period is coming at some point, and organisations whose documentation is cleanly mapped to clauses handle those in weeks rather than months.

One change is already live. ISO 22301:2019/Amd 1:2024, the climate action amendment, adds climate change to the context requirements in clause 4.1 and to interested-party expectations in clause 4.2. For a business continuity system this is less of a bolt-on than it is elsewhere: physical climate risk is a disruption scenario, and most existing continuity plans already assume weather events without ever having recorded climate as a context issue.

A realistic total for ISO 22301 implementation

For a single-site organisation of a hundred to five hundred people with no existing certification,
nine to fifteen months from gap analysis to certificate is defensible. Six to nine is
achievable where ISO 27001 already exists and continuity practice is mature. Anything under six months
means either the scope is genuinely small or the exercise programme has been skipped — and the
exercise programme is the part an auditor will look at hardest.

References

More on ISO 22301 and business continuity

All of these are covered by the ISO 22301 Toolkit. To score where you stand first, use the ISO 22301 Assessment Tool, or start with the free ISO 22301 templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.