ISO 22301

Business Continuity Management Systems

Understand the threats to your business, protect it from costly disruptions and keep it trading.

amtivo feefo rating

Get Started Today

Enter your details below to get started on
your journey to certification.

What Is ISO 22301 Certification?

ISO 22301:2019 is an internationally recognised standard for Business Continuity Management Systems (BCMS) that provides a framework for organisations to continue delivering services and products during a disruption.

The standard guides businesses on how to handle disruptions effectively. It sets up a framework for creating, implementing, maintaining, and improving a management system to help protect against, reduce the chance of, and recover from disruptions.

ISO 22301 emphasises the need to develop and track business continuity management processes and encourages continual organisational improvement based on audits and performance measurements. It includes a framework for BCMS policies, personnel, management processes and documented controls.

Achieving certification builds confidence among customers, partners and stakeholders by showing a commitment to maintaining service and product delivery regardless of disruptions.

 

ISO 22301 Certification

What Are the Benefits of ISO 22301?

Establish a BCMS

Establish
a BCMS

Win more business

Win More
Business

Stakeholder confidence

Build Stakeholder
Confidence

Minimise downtime

Minimise
Downtime

Competence in tenders

Establish Competence
in Tenders

Build client confidence

Build Client
Confidence

Competitive advantage

Stand Out
from Competitors

Keep critical functions operating

Keep Critical
Functions Operating

Better-Reputation

Safeguard Your
Reputation

Shorter recovery time

Shorten
Recovery Time

Safeguard operational capabilities

Safeguard
Operational Capabilities

Safeguard financial stability

Protect Your
Financial Stability

Key Requirements of ISO 22301

The ISO 22301 standard outlines a number of requirements that organisations must meet to demonstrate their commitment to business continuity management. These include:

tick-icon

Business Continuity Management

Organisations must implement a systematic approach to identify, assess, and manage potential threats and their impacts, for the continuity of critical business functions.

tick-icon

Contextual Understanding

Understand your internal and external contexts and their impact on continuity, identifying externally engaged departments and vulnerable teams.

tick-icon

Leadership Commitment

Secure commitment from all management levels to business continuity aligned with strategic goals, ensuring each has a continuity plan.

tick-icon

Risk Identification and Management

Identify and address risks that could disrupt business operations, including natural disasters, software failures, and external threats like data breaches and ransomware.

tick-icon

Continual Improvement

Regularly evaluate and improve your business continuity system after changes, such as new staff, expanded offerings, and updated safety regulations.

tick-icon

Safety Culture

Cultivate awareness of health and safety risks among all employees, including regular safety training, cyber security training, and emergency response procedures.

tick-icon

Operational Risk Controls

Establish accessible measures for daily operations and maintain preparedness for emergencies or disruptions to minimise negative impacts.

tick-icon

Employee Involvement

Involve employees in business continuity decisions using diverse data collection methods, like forums and interviews, to enhance retention and morale.

tick-icon

Regulatory Compliance

Maintain preparedness for and compliance with evolving industry-specific regulations and standard practices to maintain business continuity during disruptions.

Why You Should Choose British Assessment Bureau

Our experts are with you at every step of your certification journey.
  • UKAS-accredited certification services – Your certification comes with the coveted Crown & Tick mark, which proves it has the strength and security of government backing. Find out more about our UKAS accreditation.

  • Expert support – Our auditors are with you every step of the way and our team is available online to offer support when you need it.

  • 5-star Feefo customer satisfaction – Our customers are so happy with our service that 97% have given us 4- or 5-star reviews. We are proud to hold an “Exceptional” Feefo rating – awarded to businesses achieving a rating of at least 4.5 for over ten years.

  • Flexible payment options – Pay for your certification monthly or all at once, whichever works best for your organisation.

Why you should choose British Assessment Bureau

How to Become ISO 22301 Certified

Achieving certification and starting to win new business is straightforward, and our expert team will help you at every stage. Our in-house Client Success Team will be in touch to explain the process and help you plan for your Stage 1 assessment.

STEP 1
STEP 2
STEP 3
STEP 4
Stage 1 assessment – identifying gaps

There’s no pressure for the first assessment – many of our clients are surprised by what their business already has in place. A report will highlight the steps you need to take to achieve your certification.

Stage 2 assessment – in-depth review

When you’re ready, our auditor will complete a full assessment to establish whether your management systems and processes meet the standard’s requirements. A critical part of your Stage 2 assessment will be reviewing real examples of the delivery of your products and services.

Auditor’s recommendations

You’ll be advised of the Auditor’s recommendations on the day, which our compliance department will ratify, and your certification will be issued following the decision, subject to compliance with the standard.

SUCCESS! Certification issued

We’ll help you keep up to date. ISO certification’s excellent reputation is driven by its requirement for ongoing assessments and continual improvement, so we’ll keep in touch and arrange annual assessments to keep your certification up to date.

How to Become ISO 22301 Certified

Achieving certification and starting to win new business is straightforward, and our expert team will help you at every stage. Our in-house Client Success Team will be in touch to explain the process and help you plan for your Stage 1 assessment.

STEP 1
Stage 1 assessment – identifying gaps

There’s no pressure for the first assessment – many of our clients are surprised by what their business already has in place. A report will highlight the steps you need to take to achieve your certification.

STEP 2
Stage 2 assessment – in-depth review

When you’re ready, our auditor will complete a full assessment to establish whether your management systems and processes meet the standard’s requirements. A critical part of your Stage 2 assessment will be reviewing real examples of the delivery of your products and services.

STEP 3
Auditor’s recommendations

You’ll be advised of the Auditor’s recommendations on the day, which our compliance department will ratify, and your certification will be issued following the decision, subject to compliance with the standard.

STEP 4
SUCCESS! Certification issued

We’ll help you keep up to date. ISO certification’s excellent reputation is driven by its requirement for ongoing assessments and continual improvement, so we’ll keep in touch and arrange annual assessments to keep your certification up to date.

Our ISO 22301 support services

Discover the ISO 22301 standard

Learn more about ISO 22301:2019 and improve your Business Continuity Management System with our expert insights.

ISO 22301 training courses

Improve your business continuity and resilience with our comprehensive ISO 23301 training courses.

ISO 22301 requirements

Understand the key requirements for achieving ISO 22301 certification for your BCMS.

ISO 22301 FAQs

How much does ISO 22301 certification cost?

The cost of ISO 22301 certification is quoted on a fixed-fee basis, so you won’t have to worry about unexpected additional expenses.

The price of your certification will depend on:

  • Your organisation’s total size
  • The sector you operate in
  • The number of locations you operate from

We promise no hidden costs and transparent pricing at each step.

Get started with ISO certification.

What is ISO 22301 for business continuity management?

ISO 22301 for business continuity management is an international standard that provides a framework for organisations to plan, implement, monitor, maintain and continually improve a Business Continuity Management System (BCMS).

ISO 22301 aims to ensure that businesses can continue to operate during or after a disruption and minimise the impact on their critical functions.

The standard involves:

  • Identifying potential threats and assessing their impact on business operations.
  • Determining the effects of disruption on various business functions and prioritising them for recovery.
  • Developing, implementing and maintaining strategies and procedures to ensure the continuity of critical functions.
  • Allocating necessary resources to support business continuity efforts, such as personnel, technology and financial assets.
  • Ensuring that employees are aware of their roles and responsibilities in business continuity activities.
  • Regularly testing and exercising business continuity plans to validate their effectiveness and identify areas for improvement.
  • Continually monitoring the BCMS and reviewing performance to ensure it remains effective and aligned with organisational objectives.
  • Implementing changes and improvements to improve the BCMS over time.
Why is ISO 22301 important?

ISO 22301 offers a structured approach to support business continuity during and after disruptions. This international standard helps organisations identify and manage potential threats, minimising the impact of disruptions on business operations in the event of a disaster.

Implementing ISO 22301 allows businesses to:

  • Safeguard that critical functions and operations remain active during disruptions.
  • Proactively identify, assess and mitigate potential risks.
  • Show customers, partners and regulators that the business is well-prepared for unexpected events.
  • Meet necessary legal, regulatory and contractual obligations.
  • Allocate resources efficiently to reduce downtime and financial losses.
  • Stand out from competitors by demonstrating a strong commitment to business continuity.
What are the ISO 22301 requirements?

ISO 22301 lays out specific requirements for establishing a Business Continuity Management System. This standard ensures that an organisation can effectively prepare for, respond to and recover from disruptive incidents. This ensures overall resilience and business continuity.

These requirements are structured into the following clauses:

  • Clause 1: Scope – Defines the intended outcomes and scope of the standard to verify that its intended outcomes are met.
  • Clause 2: Normative References – Lists essential documents that are necessary for the application of the standard.
  • Clause 3: Terms and Definitions – Defines the terms used throughout the standard to ensure consistency and understanding.
  • Clause 4: Context of Organisation – Organisations must understand internal and external issues, as well as the needs and expectations of stakeholders that may impact business continuity.
  • Clause 5: Leadership – Emphasises the role of stakeholders in demonstrating commitment, establishing a business continuity policy, and defining roles and responsibilities within the BCMS.
  • Clause 6: Planning – Involves identifying risks and opportunities, setting business continuity objectives and planning to address these.
  • Clause 7: Support – Provide the necessary resources and ensure that the necessary information is clearly documented and maintained.
  • Clause 8: Operations – Focuses on implementing processes to meet business continuity objectives, including business impact analysis, risk assessment and developing and implementing business continuity plans and procedures.
  • Clause 9: Performance Evaluation – Involves monitoring, measuring and evaluating the effectiveness of the BCMS, including conducting internal audits and management reviews.
  • Clause 10: Improvement – Covers continual improvement of the BCMS by addressing nonconformities, implementing corrective actions and seizing opportunities for improvement.

Organisations can build a framework by following these structured clauses, which not only support compliance but also improve their capability to remain operational during crises. This structured approach helps achieve a clear and comprehensive method for business continuity management.

How does my organisation start implementing ISO 22301?

Implementing ISO 22301 involves the Plan, Do, Check, Act (PDCA) cycle, which provides a systematic approach for establishing, maintaining and continually improving a BCMS. This iterative process ensures that businesses can effectively plan for potential disruptions, implement measures to deal with them, monitor the effectiveness of these measures and take actions to address any issues.

Here’s how to get started:

Plan

  • Assess your external environment and understand the needs and expectations of stakeholders.
  • Identify potential risks and opportunities.
  • Set clear business continuity objectives and determine the resources needed to achieve them.

Do

  • Put the plan into action by developing and implementing your BCMS and making necessary process changes.
  • Ensure all team members are aware of their roles and responsibilities within the BCMS.

Check

  • Regularly monitor and measure the effectiveness of your business continuity processes.
  • Conduct tests of your business continuity plans and analyse the results to ensure they are functioning as intended.

Act

  • Take corrective and preventive actions based on the insights gained from monitoring and testing.
  • Continually refine and improve your BCMS by addressing deficiencies and implementing best practices.
What are the benefits of ISO 22301?

  • Protect your organisation’s reputation – Keep services and operations running, even when unexpected events occur. 
  • Reduce costs – Minimise costs associated with unplanned downtime and recovery efforts by having a well-structured response plan.
  • Train employees on their roles in business continuity – Ensure they are well-prepared to act during disruptions.
  • Strengthen measures to protect critical data and information – Reduce the risk of data loss during incidents.
  • Improve coordination across different departments and functions – Ensure a unified response to challenges.
  • Establish quick and effective response mechanisms – Respond quickly and reduce downtime.

Contact us to find out how ISO 22301 can benefit your business.

How to get ISO 22301 certification

When you achieve your ISO 22301 certification with British Assessment Bureau, your certification will be accredited by UKAS (United Kingdom Accreditation Service).

Our UKAS-accredited ISO 22301 certificates all come with the coveted ‘Crown & Tick’ mark, underlining the security that only comes from Government-backed certification.

How long does it take to get ISO 22301 certification?

Achieving ISO 22301 certification typically takes 6 to 12 months. The timeline may vary depending on factors such as your organisation’s size and complexity, your BCMS and the available resources.

The process usually includes an initial assessment and planning phase, the implementation of the BCMS, internal audits and reviews, and the certification audit. Your organisation’s readiness and stakeholders’ commitment can influence the time it takes to complete.

With effective planning and management, your business can streamline the process and successfully achieve certification.

Get a personalised quote and find out how long it will take for your organisation to become certified.

What ISO 22301 training should I do?

We offer a range of ISO 22301 training courses that can help you gain knowledge and effectively implement business continuity management within your organisation.

Our training options include:

ISO 22301 Course – Free Introduction Training

  • Introduces the basics of ISO 22301 and the importance of business continuity management.
  • Ideal for individuals new to business continuity who want to gain a foundational understanding of ISO 22301.

ISO 22301 Awareness – Online and Classroom Training

  • Provides a deeper understanding of the ISO 22301 standard, including key concepts, requirements and benefits.
  • Ideal for anyone looking to expand their knowledge of business continuity principles and how to align with ISO 22301, available in flexible online and classroom formats.

ISO 22301 Certification Training – Implementing ISO 22301

  • Equips you with the knowledge and tools needed to implement ISO 22301 within your organisation effectively.
  • Ideal for professionals responsible for developing, implementing and managing an ISO 22301-compliant Business Continuity Management System.

Explore our ISO 22301 training courses and find the right one to advance your expertise in business continuity management.

Sign Up to Our Newsletter

Enter your details below to stay up to date with all the latest certification news and expert insights.

Related Standards

ISO 9001

ISO 9001 is an internationally recognised standard for quality management, helping businesses across industries improve the quality of their products and services.

ISO 14001

ISO 14001 is a globally recognised standard for Environmental Management Systems, helping organisations improve sustainability & reduce environmental impact.

ISO 27001

Discover ISO 27001, the global standard for information security management, safeguarding data integrity, confidentiality, and availability.

ISO 45001

Discover ISO 45001, the international standard for Occupational Health and Safety Management Systems. Learn how ISO 45001 helps businesses improve safety.

ISO 42001

Learn about ISO 42001, the first international standard outlining the requirements for Artificial Intelligence Management Systems (AIMS).

Cyber Essentials

Cyber Essentials is a UK scheme for cyber security, helping organisations improve their cyber security framework.

PAS 2030

Read about PAS 2030 and discover why it's important to implement quality practices for energy efficiency installations.