Compyl

ISO 22301 Business Continuity Management: The Implementation Guide

August 11, 2026
Framework · ISO 22301

ISO 22301 Business Continuity Management: The Implementation Guide

By Compyl ResearchLast updated: August 11, 202612 min read

ISO 22301 is the international standard specifying requirements for a business continuity management system. The current edition, ISO 22301:2019, requires organizations to analyze disruption impacts, set recovery objectives, build continuity strategies and plans, exercise them, and improve continually. It is certifiable by accredited bodies on a three-year cycle, and a third edition is now in draft.

Key takeaways
  • The certifiable edition is ISO 22301:2019 (2nd edition, published 30 October 2019, 21 pages), amended by Amd 1:2024 “Climate action changes,” which is distributed free of charge.
  • A third edition is in development as ISO/CD 22301, registered March 2026 with its comment period closed on 10 May 2026. DIS and FDIS ballots remain, so 2019 stays the audit baseline for now.
  • ISO 22301 prescribes no recovery times. Your BIA sets MTPD, RTO, RPO and MBCO, and clause 8.6 requires you to prove the capability actually meets them.
  • Certification runs through an ISO/IEC 17021-1 accredited body: Stage 1, Stage 2, then annual surveillance across a three-year cycle. Audit days scale with headcount, sites and scope complexity, so published price ranges mean little without a scope statement.
  • It pairs directly with ISO 27001 Annex A 5.29 and 5.30, ISO/IEC 27031:2025, the NIST CSF 2.0 RECOVER function, and the yearly continuity testing DORA requires of EU financial entities.

What Is ISO 22301 and What Does It Require?

ISO 22301 is the international standard for a business continuity management system (BCMS). The current edition, ISO 22301:2019, “Security and resilience — Business continuity management systems — Requirements”, is a second edition published on 30 October 2019 and runs to 21 pages. Those 21 pages are what an accredited auditor holds you to.

It uses the harmonized high-level structure ISO applies across ISO 9001, ISO 14001 and ISO/IEC 27001: clauses 1 to 3 cover scope, references and terminology, and clauses 4 through 10 are the auditable requirements.

What ISO 22301 does not do is tell you how long you are allowed to be down. There are no prescribed recovery times, no mandated technology, no required plan template. It specifies a system for determining those answers yourself, evidencing the reasoning, and proving the resulting capability works.

Two things changed recently. ISO published ISO 22301:2019/Amd 1:2024, “Climate action changes,” distributed at no charge, which requires organizations to consider whether climate change is a relevant issue when determining the context of the BCMS. And the standard is being revised: ISO 22301:2019 now sits at stage 90.92, “International Standard to be revised,” with a third edition in the pipeline as ISO/CD 22301, registered as a committee draft on 12 March 2026 and with its comment period closed on 10 May 2026.

ISO 22301 at a glance, August 2026
  • Certifiable edition: ISO 22301:2019 (2nd edition, 30 October 2019, 21 pages, CHF 155).
  • Amendment: Amd 1:2024 “Climate action changes,” available at no cost.
  • Revision status: ISO/CD 22301 (3rd edition) at committee draft stage 30.60; DIS and FDIS ballots still ahead.
  • Guidance companion: ISO 22313:2020, “Guidance on the use of ISO 22301.”

Certificates against the 2019 edition remain valid. When a new edition publishes, accreditation bodies normally set a transition window in which certified organizations migrate at a surveillance or recertification audit, as ISO 27001 users saw between the 2013 and 2022 editions.

Who Needs ISO 22301, and What Drives Certification?

ISO 22301 is voluntary; no law requires the certificate. Four forces push organizations toward it: customer contracts, public tenders, regulatory expectations, and insurers who want evidence that recovery is engineered rather than hoped for.

Regulatory pressure is the fastest-growing driver. The EU’s Digital Operational Resilience Act, Regulation (EU) 2022/2554, has applied to financial entities since 17 January 2025 and requires an ICT business continuity policy, documented response and recovery plans, and yearly testing of those plans. NIS2 lists business continuity, backup management, disaster recovery and crisis management among its minimum security measures. Neither says “get certified to ISO 22301,” but both demand the machinery it specifies, and a certificate is the cheapest way to show a supervisor or customer that the machinery exists. If DORA is your driver, start with our explainer on the DORA regulation in the EU.

Where certification pays for itself

  • Regulated financial services, healthcare and critical infrastructure, where a supervisor will ask how recovery objectives were derived.
  • SaaS and managed service providers asked for RTO and RPO commitments in every security questionnaire, then asked for the evidence behind them.
  • Manufacturers and logistics operators with concentrated supplier dependencies, where the continuity question sits upstream of the data center.
  • Public-sector bidders, where certification is often a scored or pass/fail tender criterion.

One caveat on benchmarking. If you want to know how many organizations hold ISO 22301 certificates, the source has changed: ISO states that from 2025 onwards the ISO Survey is compiled directly from anonymized, aggregated data in IAF CertSearch, counting certificates from bodies accredited by International Accreditation Forum members. Earlier figures came from questionnaires sent to certification bodies, so treat pre-2025 and post-2025 counts as different series, not a trend line.

Be clear about what you are certifying: ISO 22301 governs continuity of prioritized activities across the whole organization, not just IT recovery — a distinction we unpack in business continuity versus disaster recovery.

What Do Clauses 4 to 10 of ISO 22301 Require?

The auditable content lives in clauses 4 to 10. Here is what each asks you to produce.

Clause 4 — Context of the organization

Determine internal and external issues relevant to continuity, identify interested parties and their requirements including legal and regulatory ones, and define the BCMS scope. Scope is the highest-leverage decision in the project: it fixes which products, services, sites and functions the auditor examines. Under Amd 1:2024 you must also consider whether climate change is relevant here.

Clause 5 — Leadership

Top management must demonstrate commitment, establish a business continuity policy, and assign roles, responsibilities and authorities. “Demonstrate” means artifacts: a signed policy, minuted decisions, resourcing evidence. An auditor who cannot find management fingerprints will write a finding however good the plans are.

Clause 6 — Planning

Address risks and opportunities for the BCMS itself and set measurable continuity objectives with plans to achieve them. Note the distinction from clause 8.2: clause 6 concerns risks to the management system, 8.2 concerns risks of disruption to prioritized activities.

Clause 7 — Support

Resources, competence, awareness, communication and documented information. Competence is the most under-evidenced requirement — you need records showing the people named in your plans are trained for the roles assigned.

Clause 8 — Operation

The engine room, and roughly half the implementation effort: operational planning and control, business impact analysis and risk assessment, continuity strategies and solutions, plans and procedures, an exercise program, and evaluation of documentation and capabilities.

Clauses 9 and 10 — Performance evaluation and improvement

Monitoring, measurement, analysis and evaluation; internal audit; management review; nonconformity, corrective action and continual improvement. A certification body cannot recommend certification until it has seen at least one completed internal audit and one management review, which is why these clauses set the floor on your timeline.

How Do You Run the BIA and Risk Assessment?

Clause 8.2 requires two distinct analyses that implementers routinely collapse into one. The business impact analysis asks how bad it gets, and how fast, if an activity stops. The risk assessment asks what could plausibly stop it. The BIA comes first, because it tells you which activities are worth assessing risk against.

What the BIA has to establish

A conforming BIA identifies the activities supporting delivery of your products and services, assesses impacts over time of not performing them, sets prioritized timeframes for resuming them, and identifies each activity’s dependencies and resources — people, data, infrastructure, facilities, suppliers and finance.

ISO publishes a dedicated technical specification: ISO/TS 22317:2021, “Guidelines for business impact analysis”, a 36-page second edition published in November 2021 and confirmed in 2025. Usefully, it does not prescribe a uniform process for performing a BIA; it gives direction for a formal, documented process adaptable to the organization’s needs, resources and constraints. There is no single approved template you are failing to use.

Five practices that keep a BIA honest

  1. Analyze activities, not departments. “Claims payment” is an activity with a measurable outage impact. “The claims department” is an org chart box.
  2. Use fixed time buckets and one impact scale. Score financial, regulatory, reputational and safety impact at 4 hours, 24 hours, 3 days, 1 week and 1 month. Consistency beats precision.
  3. Challenge RTO inflation. Every owner believes theirs is the critical process. Require impact evidence for a tight target, and make the cost of meeting it visible.
  4. Map dependencies both ways. An activity with a four-hour RTO that depends on a supplier with a two-day recovery commitment has that RTO on paper only.
  5. Date and version it. Clause 8.2 requires the BIA and risk assessment to be reviewed at planned intervals and after significant change.

For the risk assessment half, ISO 22301 expects a process consistent with ISO 31000 that identifies, analyzes and evaluates the risk of disruption to prioritized activities and their resources. This is where concentration risk surfaces: single sites, single cloud regions, key-person dependencies, and one supplier behind several supposedly independent activities.

What Do RTO, RPO, MTPD, and MBCO Mean?

Four metrics carry most of the weight in a BCMS, and confusing them is the most common reason plans fail on contact with a real incident. ISO 22301 defines them in clause 3; NIST SP 800-34 Rev. 1 (May 2010) gives compatible, freely quotable definitions.

Metric Question it answers Definition Worked example: online order intake
MTPD / MTD
Maximum tolerable period of disruption (ISO) or maximum tolerable downtime (NIST)
At what point does the outage become unsurvivable? NIST: “the total amount of time the system owner/authorizing official is willing to accept for a mission/business process outage or disruption and includes all impact considerations.” 72 hours. Beyond that, contractual penalties and churn cause damage the business cannot absorb.
RTO
Recovery time objective
How fast must we be back? NIST: “the maximum amount of time that a system resource can remain unavailable before there is an unacceptable impact on other system resources, supported mission/business processes, and the MTD.” Because the RTO must ensure the MTD is not exceeded, it is normally shorter. 8 hours, leaving headroom below the 72-hour MTPD for verification and backlog clearance.
RPO
Recovery point objective
How much data can we afford to lose? NIST: “the point in time, prior to a disruption or system outage, to which mission/business process data can be recovered… after an outage.” 15 minutes, which dictates transaction log shipping rather than nightly backups.
MBCO
Minimum business continuity objective
What does “working” mean while we are degraded? ISO 22301: the minimum level of services or products that is acceptable to the organization to achieve its business objectives during a disruption. Queue orders for the top 20 accounts by revenue, manual pricing, no self-service returns.

The MBCO is the metric most often skipped, and the one that makes an exercise meaningful. Without it a recovery test has a binary pass condition — up or not — and the team never rehearses the degraded-but-trading state real incidents produce.

Two disciplines to enforce. RTO and RPO belong to business activities, so technical targets for the systems underneath must be tighter: restoring an application precedes data validation and backlog processing. And never publish an RTO you have not demonstrated — a contractual number that has never survived an exercise is a liability, not a control.

How Do You Choose Continuity Strategies and Write Plans?

Clause 8.3 requires you to identify and select continuity strategies and solutions from the BIA and risk assessment outputs, determine the resources they need, and implement them. Clause 8.4 then requires plans and procedures that manage a disruption and recover within the timeframes the BIA set.

Choosing strategies

Strategy options fall into a few patterns: duplicate the capability (active-active regions, a second production line), hold standby capacity (warm site, contracted surge staff), degrade gracefully to the MBCO (manual workarounds, reduced product set), transfer the activity (third-party fulfilment, mutual aid), or accept the loss where impact does not justify investment. The choice is economic: solution cost against the impact the BIA quantified.

ISO/TC 292 publishes targeted guidance for each stage, worth scanning before buying consulting: ISO/TS 22331:2018 on continuity strategy (revision in progress as ISO/CD 22331), ISO/TS 22332:2021 on developing plans and procedures, and ISO/TS 22318:2021 on supply chain continuity management.

Writing plans people can actually use

Clause 8.4 breaks into a response structure with defined teams and activation authority, warning and communication procedures, the continuity plans themselves, and recovery arrangements. The recurring failure mode is length: plans written to impress an auditor are useless at 3 a.m., while plans written for 3 a.m. satisfy auditors comfortably.

Practical rules: name roles, not individuals, and keep a contact roster on an update schedule. Define the activation trigger and who has authority to pull it. Put the first 60 minutes on the first page. Keep an offline copy, because a plan that exists only inside the system you are recovering is not a plan. And cover the cyber scenario explicitly — ransomware invalidates the “fail over to the warm site” assumption when the warm site is encrypted too, which we unpack in business continuity planning in cyber security. Our business continuity best practices guide covers the habits that keep plans current.

How Often Do You Have to Exercise and Test?

Clause 8.5 requires an exercise program that validates continuity strategies and solutions over time, and clause 8.6 requires evaluation of the suitability, adequacy and effectiveness of continuity documentation and capabilities at planned intervals. ISO 22301 sets no fixed frequency — you define and justify the intervals, and auditors test that justification.

ISO’s dedicated guidance is ISO 22398:2013, “Guidelines for exercises”, which recommends good practice for planning, conducting and improving exercise projects. For terminology that maps onto technical testing, NIST SP 800-84 (September 2006) is the clearest free reference:

  • Tabletop exercises are “discussion-based exercises where personnel meet in a classroom setting or in breakout groups to discuss their roles during an emergency,” with a facilitator presenting scenarios. No equipment is deployed.
  • Functional exercises let personnel “validate their operational readiness for emergencies by performing their duties in a simulated operational environment.”
  • Tests are “evaluation tools that use quantifiable metrics to validate the operability of an IT system or system component in an operational environment.”

A defensible cadence

Annual is the de facto floor set by adjacent regimes, which makes it the interval auditors expect unless you argue otherwise. NIST SP 800-53 requires federal agencies to exercise or test contingency plans and incident response capabilities at least annually, and DORA requires financial entities to test ICT continuity and recovery plans at least yearly. A practical program layers frequencies rather than relying on one annual event:

  1. Continuous or monthly: automated backup restore verification. NIST CSF 2.0 subcategory PR.DS-11 requires that “backups of data are created, protected, maintained, and tested,” and RC.RP-03 requires verifying backup integrity before using it for restoration.
  2. Quarterly: a 90-minute tabletop on a fresh scenario, rotating cyber, supplier failure, site loss and key-person unavailability.
  3. Annually: at least one functional exercise that actually recovers a prioritized activity and measures achieved recovery time against the stated RTO.
  4. After every exercise and real incident: a documented report feeding clause 10 corrective actions. Exercises that never change a plan are theater, and auditors recognize the pattern.

Record the gap between target and achieved recovery time every time. That single metric — RTO variance — is the most persuasive evidence of BCMS effectiveness you can put in front of a board.

How Does ISO 22301 Certification Work, and What Does It Cost?

Certification is performed by an independent body accredited against ISO/IEC 17021-1:2015, which sets competence, consistency and impartiality requirements for bodies that audit and certify management systems. ISO itself does not issue certificates, and “self-certification” is not certification.

The certification path

  1. Buy and read the standard. ISO 22301:2019 is CHF 155 in PDF and ePub; Amd 1:2024 is free. ISO 22313:2020 guidance is a separate purchase, worth it for a first implementation.
  2. Gap assessment. Map current practice against clauses 4–10 and produce a remediation plan with owners and dates.
  3. Build the BCMS. Scope, policy, BIA, risk assessment, strategies, plans, competence records and documented information.
  4. Operate it. Run at least one exercise, one internal audit and one management review. This is the non-compressible part of the timeline.
  5. Stage 1 audit. The certification body reviews documentation, scope and readiness, and identifies anything that would block Stage 2.
  6. Stage 2 audit. Assessment of implementation and effectiveness, sampling records against every clause.
  7. Certification decision, then a three-year cycle. Surveillance audits in years one and two, and recertification before the certificate expires.

What actually drives the cost

Certification body quotes are priced on audit days, and audit days scale with employees in scope, number of sites, complexity of the activities covered and shift patterns. That is why published price ranges mean little without your scope: a single-site 60-person SaaS business and a 5,000-person multinational differ by orders of magnitude for the same certificate. Get three quotes, and check each prices the same scope statement.

The honest budget has five lines: standards purchase (small and fixed); external gap assessment (optional); internal labor to run the BIA and write plans (almost always the largest line and almost always underestimated); certification body fees for Stage 1, Stage 2 and annual surveillance; and continuity solution investment — the redundant capacity, contracts and tooling your strategy commits you to. Only the last two recur, and aggressive RTOs make the solution line dwarf the audit line.

How Does ISO 22301 Fit With ISO 27001, NIST CSF, and DORA?

Almost nobody implements ISO 22301 in isolation. It lands on top of an existing security program, and the overlap is large enough that duplicated work is the main avoidable cost.

ISO/IEC 27001

ISO/IEC 27001:2022 already contains two Annex A controls that reach into continuity: 5.29, information security during disruption, and 5.30, ICT readiness for business continuity. They require you to maintain information security during disruption and build ICT readiness from continuity objectives — but they do not require a full BCMS. ISO 22301 is what puts a BIA behind those controls. Because both standards share the harmonized clause structure, context, leadership, competence, internal audit and management review can be run once and evidenced twice. If ISO 27001 is your starting point, our complete guide to ISO 27001 certification covers that side.

On the ICT side, ISO/IEC 27031:2025 is newly relevant. Published 16 May 2025 as a second edition and retitled “Cybersecurity — ICT readiness for business continuity,” it replaced the withdrawn 2011 version and now explicitly addresses dependencies on third-party services such as cloud providers.

NIST Cybersecurity Framework 2.0

NIST CSF 2.0, published 26 February 2024, supplies a recovery vocabulary that maps onto ISO 22301 plans. Its RECOVER function requires that recovery actions are “selected, scoped, prioritized, and performed” (RC.RP-02), that restored asset integrity is verified and normal operating status confirmed (RC.RP-05), and that “the end of incident recovery is declared based on criteria” (RC.RP-06). Most continuity plans define activation criteria and forget stand-down criteria.

Operational resilience regulation

DORA and NIS2 have pushed continuity from an IT concern to a board-supervised obligation in the EU, and comparable operational resilience expectations exist in UK and US financial supervision. Regulators want impact tolerances for important business services, evidence of testing, and named accountable executives — all by-products of a conforming BCMS.

The commercial case has strengthened too. According to IBM’s 2026 Cost of a Data Breach Report, the global average breach cost reached USD 4.99 million, a 12% increase year over year and a record high, driven partly by lost business costs — exactly the variable a tested continuity capability compresses.

Frequently asked questions

Is ISO 22301 mandatory?
No. ISO 22301 is a voluntary standard, and no law requires the certificate itself. However, regulations such as DORA and NIS2 require the underlying capabilities, and customers and public tenders increasingly ask for certification as evidence, which makes it commercially close to mandatory in some sectors.
What is the difference between ISO 22301 and a disaster recovery plan?
A disaster recovery plan restores technology. ISO 22301 specifies a management system covering all prioritized business activities, including people, facilities, suppliers and manual workarounds. Disaster recovery is one strategy option produced by an ISO 22301 program, not a substitute for it.
How long does ISO 22301 certification take?
The floor is set by evidence, not paperwork. Before a Stage 2 audit you must have completed at least one exercise, one internal audit and one management review, and your BIA must be documented and reviewed. Organizations with mature incident and backup practices move faster than those starting from scratch.
Does ISO 22301 tell you what your RTO should be?
No. The standard requires you to determine prioritized timeframes for resuming activities through the business impact analysis, document the justification, and validate through exercises that the capability meets them. Any consultant quoting standard ISO 22301 recovery times is inventing them.
Can ISO 22301 be certified alongside ISO 27001?
Yes, and it is common. Both use ISO’s harmonized high-level structure, so context, leadership, competence, documented information, internal audit and management review can be run as single processes. Many certification bodies offer combined audits, which reduces total audit days versus certifying separately.
What is the MBCO and why does it matter?
The minimum business continuity objective is the minimum level of products or services acceptable to the organization during a disruption. It defines what degraded-but-operating looks like, which turns exercises from binary up-or-down tests into realistic rehearsals of how the business actually runs mid-incident.

Run Your ISO 22301 BCMS in Compyl

Compyl keeps your BIA, recovery objectives, continuity plans, exercise records and corrective actions in one system, and maps them against the ISO 27001, NIST CSF and DORA controls they already satisfy so you evidence once and attest many times. Built by CISOs who have run the audit and the incident.

Request a demo →

About this guide. By Compyl Research. Last updated August 11, 2026. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.


Monitoring thousands of environments daily
By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies