ISO 22301 Certification
The business continuity standard for organisations that must keep prioritised activities running through disruption and prove it.
- Standard
- ISO 22301:2019
- Indicative timeline
- 10-16 weeks, depending on scope and readiness
- Discipline
- Specialised Standards
- Assessment type
- Independent third-party assessment
The standard
Overview
ISO 22301:2019 sets requirements for a business continuity management system. It follows the harmonised clause structure and turns on two pieces of analysis: a business impact analysis that establishes prioritised activities and recovery time objectives, and a risk assessment of the disruptions that could stop them. Continuity strategies, resources and plans follow from that analysis.
Certification shows customers, insurers, regulators and boards that continuity arrangements are documented, resourced, exercised and reviewed. It is regularly asked for in public sector tenders and supply chain assurance, and the underlying analysis supports the operational resilience expectations UK financial services firms work to under FCA and PRA rules.
UKCert assesses in two stages. Stage 1 reviews scope, the business impact analysis, recovery objectives and plan structure. Stage 2 tests the incident response structure, communications, resource arrangements and the exercise and test records that show the plans have been used.
Who this is for
- Financial services firms with operational resilience obligations
- Suppliers to government, the NHS and critical national infrastructure
- Data centres, telecoms and managed service providers
- Manufacturers and logistics operators with single points of failure
- Organisations required to show continuity plans in tenders
What it gives you
Why organisations certify
What a certified ISO 22301:2019 assessment gives you once the certificate is issued.
Prioritised recovery
The business impact analysis establishes which activities matter most and how quickly they must return, so recovery effort follows priority rather than the loudest voice.
Tested, not theoretical
Plans must be exercised and the results acted on. Assessment examines the exercise programme, so continuity arrangements are proven before an actual disruption tests them.
Tender and contract evidence
Public sector and enterprise buyers ask for continuity evidence. A certificate with a defined scope answers the requirement without rewriting plans for each bid.
Supply chain resilience
Dependencies on suppliers, sites and systems are mapped, so single points of failure become visible and alternative arrangements can be agreed in advance.
Clear incident command
Roles, invocation thresholds, escalation and communication with staff, customers and regulators are defined in advance, which shortens the time lost deciding who decides.
Regulatory alignment
Impact tolerances, dependency mapping and scenario testing under UK operational resilience rules draw on the same analysis, so continuity work supports regulatory reporting.
Scope
What the assessment covers
The areas an assessor works through. Your final scope is confirmed in writing before any audit is booked.
- Business impact analysis and prioritised activities
- Recovery time and recovery point objectives
- Maximum tolerable period of disruption
- Business continuity strategies and solutions
- Incident response structure and invocation thresholds
- Warning and communication procedures
- Business continuity plans and recovery procedures
- Exercise and testing programme
How it runs
The assessment, stage by stage
From first enquiry to certificate. Each stage is agreed with you before it starts.
-
Scope and dependencies
We agree which activities, sites and services fall inside the management system, along with the suppliers and infrastructure they depend on, then set audit duration.
-
Stage 1 review
A review of the business impact analysis, risk assessment, recovery objectives, continuity strategies and plan structure, confirming the analysis genuinely supports the plans written from it.
-
Exercise evidence
The system needs completed exercises before Stage 2. Plans that have never been tested cannot demonstrate the review and improvement cycle the standard requires.
-
Stage 2 assessment
Auditors test the incident response structure, communication arrangements, resource availability and recovery procedures, interviewing plan owners and sampling exercise reports and post-incident reviews.
-
Certification decision
Nonconformities are graded major or minor and closed out. An independent reviewer takes the certification decision, and the certificate is issued with the agreed scope.
-
Surveillance and recertification
Annual surveillance examines exercises, incidents and changes since the last audit. A full recertification audit covers the whole system before the three-year certificate expires.
Questions
ISO 22301:2019 — frequently asked
Anything here that does not cover your situation, put it to an assessor rather than guessing at it.
Same discipline
Other schemes in Specialised Standards
Certifying against more than one standard?
Where you hold several standards, shared clauses are assessed once in a combined visit rather than as separate audits. Talk it through with an assessor before you decide what ISO 22301:2019 should sit alongside.