20 certification schemes

ISO 22301:2019

ISO 22301 Certification

The business continuity standard for organisations that must keep prioritised activities running through disruption and prove it.

Standard
ISO 22301:2019
Indicative timeline
10-16 weeks, depending on scope and readiness
Discipline
Specialised Standards
Assessment type
Independent third-party assessment

The standard

Overview

ISO 22301:2019 sets requirements for a business continuity management system. It follows the harmonised clause structure and turns on two pieces of analysis: a business impact analysis that establishes prioritised activities and recovery time objectives, and a risk assessment of the disruptions that could stop them. Continuity strategies, resources and plans follow from that analysis.

Certification shows customers, insurers, regulators and boards that continuity arrangements are documented, resourced, exercised and reviewed. It is regularly asked for in public sector tenders and supply chain assurance, and the underlying analysis supports the operational resilience expectations UK financial services firms work to under FCA and PRA rules.

UKCert assesses in two stages. Stage 1 reviews scope, the business impact analysis, recovery objectives and plan structure. Stage 2 tests the incident response structure, communications, resource arrangements and the exercise and test records that show the plans have been used.

Who this is for

  • Financial services firms with operational resilience obligations
  • Suppliers to government, the NHS and critical national infrastructure
  • Data centres, telecoms and managed service providers
  • Manufacturers and logistics operators with single points of failure
  • Organisations required to show continuity plans in tenders

What it gives you

Why organisations certify

What a certified ISO 22301:2019 assessment gives you once the certificate is issued.

Prioritised recovery

The business impact analysis establishes which activities matter most and how quickly they must return, so recovery effort follows priority rather than the loudest voice.

Tested, not theoretical

Plans must be exercised and the results acted on. Assessment examines the exercise programme, so continuity arrangements are proven before an actual disruption tests them.

Tender and contract evidence

Public sector and enterprise buyers ask for continuity evidence. A certificate with a defined scope answers the requirement without rewriting plans for each bid.

Supply chain resilience

Dependencies on suppliers, sites and systems are mapped, so single points of failure become visible and alternative arrangements can be agreed in advance.

Clear incident command

Roles, invocation thresholds, escalation and communication with staff, customers and regulators are defined in advance, which shortens the time lost deciding who decides.

Regulatory alignment

Impact tolerances, dependency mapping and scenario testing under UK operational resilience rules draw on the same analysis, so continuity work supports regulatory reporting.

Scope

What the assessment covers

The areas an assessor works through. Your final scope is confirmed in writing before any audit is booked.

  • Business impact analysis and prioritised activities
  • Recovery time and recovery point objectives
  • Maximum tolerable period of disruption
  • Business continuity strategies and solutions
  • Incident response structure and invocation thresholds
  • Warning and communication procedures
  • Business continuity plans and recovery procedures
  • Exercise and testing programme

How it runs

The assessment, stage by stage

From first enquiry to certificate. Each stage is agreed with you before it starts.

  1. Scope and dependencies

    We agree which activities, sites and services fall inside the management system, along with the suppliers and infrastructure they depend on, then set audit duration.

  2. Stage 1 review

    A review of the business impact analysis, risk assessment, recovery objectives, continuity strategies and plan structure, confirming the analysis genuinely supports the plans written from it.

  3. Exercise evidence

    The system needs completed exercises before Stage 2. Plans that have never been tested cannot demonstrate the review and improvement cycle the standard requires.

  4. Stage 2 assessment

    Auditors test the incident response structure, communication arrangements, resource availability and recovery procedures, interviewing plan owners and sampling exercise reports and post-incident reviews.

  5. Certification decision

    Nonconformities are graded major or minor and closed out. An independent reviewer takes the certification decision, and the certificate is issued with the agreed scope.

  6. Surveillance and recertification

    Annual surveillance examines exercises, incidents and changes since the last audit. A full recertification audit covers the whole system before the three-year certificate expires.

Questions

ISO 22301:2019 — frequently asked

Anything here that does not cover your situation, put it to an assessor rather than guessing at it.

Ask a question

Ten to sixteen weeks is typical, depending on the number of sites and how much business impact analysis already exists. The pacing constraint is usually the exercise programme: plans have to be tested and the results reviewed before Stage 2, and getting senior people into a scenario exercise takes scheduling. Organisations with mature incident management move faster.

Certificates are valid for three years. Surveillance audits run annually and a full recertification audit takes place before expiry. Validity depends on completing surveillance, closing nonconformities and keeping the system live: plans reviewed, exercises run, and changes to sites, suppliers or services reflected in the analysis. Dormant plans are the most common finding at renewal.

No. ISO 22301 is voluntary. Some sectors carry duties that overlap with it, including Civil Contingencies Act 2004 obligations for Category 1 and 2 responders and the operational resilience requirements the FCA and PRA apply to financial services firms. None of those regimes requires ISO 22301, but it provides a structure they recognise.

Surveillance samples rather than repeating the full assessment. Each visit covers exercises completed since the last audit, any real incidents and their post-incident reviews, changes to prioritised activities or dependencies, plan maintenance, internal audit and management review. Evidence that exercises produced actions, and that those actions were completed, is examined every year.

Disaster recovery deals with restoring IT systems and data. ISO 22301 covers the whole organisation: people, premises, suppliers, information and equipment, prioritised by the business impact analysis. IT recovery objectives sit inside it as one set of resources among several. A capable disaster recovery function is useful evidence but does not by itself satisfy the standard.

Certifying against more than one standard?

Where you hold several standards, shared clauses are assessed once in a combined visit rather than as separate audits. Talk it through with an assessor before you decide what ISO 22301:2019 should sit alongside.