Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 22301 maturity assessment explained

ISO 22301 Maturity Assessment: The Complete Guide to 5 Levels

An ISO 22301 maturity assessment measures what a certificate cannot: not whether the business continuity management system meets ISO 22301:2019, but how far it has taken root. Two organisations can hold the same certificate, one with a continuity plan the risk manager updates before each audit and exercises annually because clause 8.5 says so, the other with recovery objectives that product owners argue about, suppliers assessed for their continuity, exercises that fail on purpose to find the gap, and directors who read the exercise report before the audit report.

A conformity audit reports both as compliant. A maturity assessment grades them. This guide sets out a five-level maturity scale for ISO 22301, the eight dimensions to score it on, the evidence that separates each level, how the assessment differs from a gap analysis and a readiness assessment, and how to use the result to set a target the standard itself never sets.

ISO 22301 maturity assessment: five levels across eight dimensions
Level 1 Initial · 2 Documented · 3 Operating · 4 Measured · 5 Embedded — scored separately for governance, BIA, risk, strategies, plans, exercising, suppliers and improvement.

ISO 22301 maturity assessment vs conformity audit

ISO 22301:2019 is a requirements standard: clauses 4.1 to 10.2 are met or not, and the certification audit reports nonconformities. It deliberately permits a system that is documented, operated and evidenced at the minimum to be certified — a business impact analysis done once, a strategy that follows it, plans that exist, an exercise that ran, an audit and a review. A maturity assessment adds the grading.

For each dimension it asks whether the requirement is met because a document says so, because people follow it, because the organisation measures and improves it, or because it is how decisions are made when no audit is due. The distinction matters because recovery in a real disruption tracks maturity, not certification. Our guide to the four types of ISO 22301 assessment places the maturity assessment among the gap analysis, self-assessment and readiness assessment.

The five levels of the ISO 22301 maturity assessment

Level Name How the BCMS behaves Typical evidence
1 Initial Continuity depends on individuals; plans exist for some areas, written after an incident or a customer request Isolated plans; no BIA; no exercise record
2 Documented The BCMS is written to the clause structure; BIA, risk assessment, strategies and plans exist as documents; exercising is planned Complete documented information under 7.5; first internal audit scheduled
3 Operating The processes run on a cycle: BIA reviewed, exercises held and reported, audits and reviews completed, corrective actions closed Dated cycle records; exercise reports with findings; management review minutes
4 Measured Performance is measured against objectives — recovery achieved versus RTO in exercises, plan currency, supplier assessment coverage — and drives change Metrics in 9.1; trend analysis; decisions traceable to data
5 Embedded Continuity is a design input for new products, sites, suppliers and systems; owners set and defend their own recovery objectives; exercises are designed to fail and do Change-management gates; product-owner sign-off of RTOs; exercise scenarios that escalate year on year

The eight dimensions scored

Dimension ISO 22301 clauses Level 2 looks like Level 4–5 looks like
Leadership and governance 5.1–5.3, 6.2 A signed policy and named roles Top management sets continuity objectives, funds them and reads exercise results before audits
Business impact analysis 8.2.2 A BIA spreadsheet dated once BIA refreshed on change and annually; dependencies mapped; RTO/RPO owned by process owners
Risk assessment 8.2.3 A risk register for disruption Risk treatment linked to strategy choices; threats reviewed with the BIA
Strategies and solutions 8.3 Strategies listed Each solution traceable to a BIA output; resource requirements costed and provided
Plans and procedures 8.4 Plans exist for the main sites Response structure, warning and communication, plans and recovery procedures current, accessible offline, with named alternates
Exercising and testing 8.5 One tabletop a year A programme escalating from walkthrough to live failover; reports with findings; findings closed and re-tested
Suppliers and dependencies 8.1, 8.2.2, 8.3 Key suppliers listed Supplier continuity assessed and contracted; dependencies exercised; ISO/TS 22318 practice
Monitoring, audit and improvement 8.6, 9.1–9.3, 10 Audit and review held once Documentation and capability evaluated (8.6); metrics trend; corrective actions verified effective

In an ISO 22301 maturity assessment, score each dimension separately before any average is taken. A BCMS at level 4 on plans and level 1 on suppliers is a level-1 system on the day a supplier fails, and an average of 2.5 hides that. Our guide to the supplier business continuity assessment covers the dimension that scores lowest most often.

Running the ISO 22301 maturity assessment

  1. Define the evidence rule per level. Level 3 requires a dated record of the cycle running; level 4 requires a measure and a decision it changed; level 5 requires a design-stage record. Write the rules down before scoring so two assessors reach the same level.
  2. Score from records, then interview. Documents set the ceiling — a dimension cannot exceed level 2 without cycle records — and interviews confirm whether the records describe behaviour.
  3. Test one dimension in the field. Ask a process owner their RTO and where the plan is; ask a supplier manager when the last continuity assessment was. The gap between paper and answer is the maturity finding.
  4. Plot the profile. Eight bars, not one number. Present the lowest dimension first.
  5. Set the target per dimension. Not every dimension needs level 5; a regulated firm may need level 4 on exercising and level 3 on governance. The target is a management decision the standard leaves to you.
  6. Re-assess annually, before management review, so the profile is an input to 9.3.

Reading the ISO 22301 maturity assessment result

Profile What it usually means First move
Level 2 across the board A documentation project that has not started operating; common six months before a first audit Run the cycle: exercise, audit, review — see the readiness assessment
High plans, low exercising Plans written to pass document review; never tested Exercise the worst plan first; expect it to fail
High BIA, low strategies Analysis done, money not spent Cost the resource requirements in 8.3 and take them to top management
High everything, low suppliers The most common certified profile Supplier continuity assessment for the top dependencies
Level 4–5 in pockets Maturity depends on one person or one site Standardise the practice into the process, not the person

Frequently asked questions

What is an ISO 22301 maturity assessment?
A graded assessment of how deeply a business continuity management system has taken root, scored on a five-level scale across eight dimensions, as distinct from a conformity audit that reports only whether ISO 22301:2019 requirements are met.

Does ISO 22301 define maturity levels?
No. ISO 22301 is a requirements standard and its 2019 edition, amended in 2024, has no maturity model. The scale here is a practitioner model; ISO 22313:2020 gives guidance on applying the requirements but does not grade them.

How is it different from a gap analysis?
A gap analysis compares the system against every requirement to plan the build; a maturity assessment grades an operating system on how well each requirement is met. Run the gap analysis before implementation and the maturity assessment after the first cycle.

What level do we need for certification?
Level 2 with the cycle records of level 3: documented information complete, plus an exercise, an internal audit and a management review completed. Certification does not require level 4 or 5.

How long does it take?
One to three days for a single-site organisation with records available, longer for multi-site groups where each site is profiled separately.

Where this leaves you

Run the ISO 22301 maturity assessment on eight dimensions, score from records before interviews, present the profile rather than the average, and set a target per dimension that reflects what a real disruption would test. The certificate says the system exists; the profile says whether it would work.

References

More on ISO 22301 assessment

To score where the BCMS stands clause by clause before profiling maturity, use the ISO 22301 Assessment Tool, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.