ISO Certifications

ISO 22301 — Business Continuity Management

Implementation and certification-readiness support for a Business Continuity Management System — evidence that your organisation can keep critical operations running through disruption.

Book a consultation
ISO 22301 business continuity management system implementation
12-16 weeks Indicative timeline — varies with scope, size, sites and shifts
ISO Governing body / standard owner
Advisory Consulting, training & audit readiness
What this covers
ISO 22301BCMSBusiness ContinuityResilience

What ISO 22301 is and why buyers ask for it

ISO 22301 is the international standard for a Business Continuity Management System (BCMS). Certification confirms, through an independent audit, that your organisation has a tested framework to keep its critical activities running — and to recover them quickly — when something goes wrong, whether that is an IT outage, a cyber incident, a supplier failure or a physical disruption.

Resilience has become a procurement question. Buyers in financial services, regulated industries and any sector that depends on continuous service increasingly ask suppliers to prove they can keep operating through disruption, rather than simply promising they can. ISO 22301 provides that proof. It is part of the ISO Certifications portfolio and complements information security work such as ISO 27001, since continuity and cyber resilience are so closely linked.

What the certification audit covers

Certification follows the same two-stage assessment as other ISO management systems. The audit examines how your BCMS works in practice, including:

  • A business impact analysis that identifies your critical activities and the consequences of their disruption
  • A risk assessment of the threats to those activities
  • Continuity strategies and plans, including recovery time objectives
  • Exercising and testing of those plans, and how you learn from the results

Surveillance audits across the three-year cycle confirm the system is maintained and improved, not left on a shelf.

Climate change: since ISO’s February 2024 climate action amendment (ISO 22301:2019/Amd 1:2024), the standard requires you to determine whether climate change is a relevant issue for your organisation, and notes that interested parties can have climate-related requirements. Certification audits include it.

How ABS helps

We prepare you for the certification audit in five steps, tailored to ISO 22301:

  • Scope and gap assessment — we agree the scope of your business continuity management system and assess what you already have against the standard, so you know exactly what to close.
  • Implementation — we help you carry out the business impact analysis and risk assessment, develop continuity strategies and plans with recovery objectives, and run the exercises that test them.
  • Internal audit and management review — we help you run the internal audit and management review the standard requires, so the system has a record of operating before the audit.
  • Readiness check — a pre-assessment, approached the way an auditor would approach it, highlights anything still to close.
  • Audit support — we support you through the certification body’s Stage 1 and Stage 2 audits and help you close any findings.

Typical timeline

For most organisations, ISO 22301 certification takes around 12–16 weeks from kick-off, depending on the complexity of your operations and how much continuity planning already exists. Larger or multi-site organisations take longer. Each engagement begins with a fixed-price scoping call and a proposal within 24 hours.

Common questions

What is a Business Continuity Management System (BCMS)?

A BCMS is the management system ISO 22301 certifies: a structured way of identifying your critical activities, understanding the risks to them, and putting tested plans in place to keep them running — or restore them quickly — when disruption hits.

What is the difference between ISO 22301 and disaster recovery?

Disaster recovery usually refers specifically to restoring IT systems and data. ISO 22301 is broader: it covers continuity of the whole organisation’s critical activities — people, facilities, suppliers and processes as well as technology. Disaster recovery is one part of a wider business continuity management system.

Who needs ISO 22301?

Organisations where downtime is costly or where customers and regulators expect proven resilience — financial services, IT and cloud providers, healthcare, manufacturing and public services. It is increasingly requested in tenders as evidence that a supplier can keep delivering through disruption.

How does ISO 22301 relate to ISO 27001?

ISO 27001 includes business-continuity considerations for information security, but ISO 22301 is the dedicated, certifiable standard for business continuity across the organisation. The two integrate well and share the common management-system structure, so many organisations certify both.

How long does ISO 22301 certification take?

For most organisations, ISO 22301 certification takes around 12–16 weeks from kick-off, depending on the complexity of your operations and how much continuity planning already exists. Larger or multi-site organisations take longer.

What does ABS do, and what does the certification body do?

ABS prepares you for certification: we agree the scope of your business continuity management system, assess the gaps, help you implement it, support your internal audit and management review, check readiness and support you through the audits. The certification body, an independent, accredited organisation you choose, carries out the Stage 1, Stage 2 and surveillance audits, makes the certification decision and issues the certificate.

How long is an ISO 22301 certificate valid?

Three years. The certification body carries out surveillance audits in the first and second years, and a recertification audit before the three-year cycle ends.

Which edition of ISO 22301 is current, and is there a transition?

The current edition is ISO 22301:2019, with the climate change amendment added in 2024. There is no transition under way.

More services

Related services

ISO Certifications / 01 ISO 9001 quality management system documentation review

ISO 9001 — Quality Management

The world's most widely adopted standard for quality management systems.

ISO 9001QMSQuality Management
Get a quote
ISO Certifications / 02 ISO 27001 information security management implementation

ISO 27001 — Information Security Management

Globally recognised certification for information security management systems (ISMS).

ISO 27001ISMSInformation Security
Get a quote
ISO Certifications / 03 Industrial facility managing environmental impact under ISO 14001

ISO 14001 — Environmental Management

The international standard for environmental management systems and measurable sustainability.

ISO 14001EMSEnvironmental Management
Get a quote

Get started

Ready to get certified?

Get a free, fixed-price quote within one business day. No obligation, no sales pressure, no follow-up spam — just a clear path to certification.

Book a 30-min consultation
24-hour response time Fixed price, multi-currency Consulting & audit readiness Remote & on-site delivery
Call us