ISO 22301 proves you keep running when something goes wrong
Customers reviewing supply chain risk and regulators asking about resilience both want to know how long you survive an outage. SIS checks which activities you must protect, how quickly you recover them, and whether you have tested the arrangements.
- !The supply chain risk review your customer sent asks for business impact analysis and tested recovery plans, not a policy.
- !Signed into an enterprise contract are recovery time and recovery point objectives nobody has ever actually measured.
- !A fire, flood or outage stopped operations and the recovery was improvised by whoever was in the building.
- !A regulator or supervisor has begun asking about operational resilience and impact tolerances for critical services.
- !You are single-sourced on a component or a site, and your buyer has just realised it.
- !The continuity plan was written three years ago, names people who have left, and has never been exercised.
ISO 22301 is the international standard for a business continuity management system. It sets out how an organisation identifies its priority activities, works out how quickly they must resume, arranges the resources to do that, and tests the arrangements.
A certification. An accredited certification body audits the continuity management system and issues the certificate; it is not an insurance product or a disaster recovery service.
Three-year certificate with annual surveillance audits; exercise and test records are examined at every visit, and recertification before expiry.
Financial institutions, technology and outsourcing providers, manufacturers on lean supply chains, utilities and public bodies asked to evidence resilience.
Industries that require ISO 22000 Certification
ISO 22301 is applicable across 23 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.
What ISO 22301 Actually Requires
An organisation must understand the requirements for ISO 22000 certification to implement it effectively.
The products, services and sites the system covers, and the interested parties - customers, regulators, insurers - whose continuity expectations shape what counts as unacceptable disruption.
Prioritised activities identified with the maximum period of tolerable disruption, recovery time objectives and the minimum service level acceptable during a disruption.
Threats to the resources those activities depend on assessed, and continuity strategies selected: alternate sites, stock buffers, second sources, standby capacity or manual workaround.
People, premises, technology, data, suppliers and utilities mapped to each priority activity, with contracts and standby arrangements in place before they are needed.
An incident response structure with defined authority to invoke, documented plans for each priority activity, and warning and communication procedures for staff, customers and authorities.
Plans exercised on a schedule with realistic scenarios, results honestly recorded, post-incident reviews carried out, and shortfalls fixed rather than noted for next year.
How ISO 22301 Certification Works
A clear, step-by-step process from your first call to a completed engagement.
Application & Proposal
We scope around the services you must be able to keep running, the sites and technology behind them, and any customer or supervisory obligation driving the certificate.
1–2 daysGap Review & Readiness
Impact analysis done department by department is the trap: everyone owns a box, nobody owns the service the customer actually buys. The plan exists; it has rarely been exercised against anything plausible.
1–2 weeksStage 1 + Stage 2 Audit
Stage 1 examines scope, impact analysis and recovery objectives. Stage 2 tests whether strategies actually deliver those objectives, and works through exercise reports, invocation records and supplier arrangements.
Scheduled around operationsCertificate Issued
Surveillance comes back for the exercise programme above everything else - what you tested since the last visit, and what the test broke. The certificate itself names the services covered.
Valid 3 yearsIndustries That Need ISO 22301
Commonly taken alongside
Not Sure Which Certification You Need?
Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.
Which sector best describes your organisation?
Name the service that cannot be down for a day
No web form will give you an honest number for this one. Audit duration turns on how many critical services you name, and that is a conversation, not a form field.
Get My Free Quote →What ISO 22301 Changes for Your Business
More than a certificate — a testimony that you have raised the bar and built customer confidence.
Supply chain reviews passed
Customers mapping concentration risk want impact analysis, recovery objectives and exercise records, and an accredited certificate answers most of that questionnaire in one line.
Recovery objectives you can commit
Contracts that specify recovery time and recovery point stop being a gamble, because the numbers came from analysis and have been tested.
Resilience expectations evidenced
Supervisors in several sectors now require tested recovery of critical services, and the standard provides the impact analysis and exercise evidence they ask for.
Dependencies brought into view
Mapping resources to activities regularly exposes a single supplier, one licence server or a lone engineer that nobody had recognised as critical.
Fewer decisions made under pressure
Defined invocation authority and prepared communication mean the first hour is executed rather than debated while customers are already calling.
Underwriters see tested arrangements
Documented impact analysis and rehearsed recovery give an underwriter something concrete to price at a business interruption renewal, rather than a broker’s assurance that you would cope.
Frequently Asked Questions
Straight answers to what buyers ask before they commit to ISO 22301.
How is ISO 22301 different from a disaster recovery plan?
What does the business impact analysis actually have to produce?
Do we have to run a full live exercise before certification?
Can we certify only part of the business?
Does ISO 22301 satisfy our regulator’s operational resilience requirements?
How long does certification take and what drives the timeline?
Certify business continuity management with SIS
An auditor who has sat through a real invocation asks better questions than one who has only read the plan. Have your last exercise report to hand when you call.
Get My Free Quote → WhatsApp Us