GlossaryCompliance operations

ISO 22301

Short answer

ISO 22301 is the international standard for a business continuity management system (BCMS). It sets out how an organisation prepares for, responds to and recovers from disruptions, and it can be certified by an accredited body, in the same way as ISO 27001.

What it requires

ISO 22301 follows the same management system structure as ISO 27001: context, leadership, planning, support, operation, performance evaluation and improvement. The operational core is the business impact analysis, an assessment of disruption risks, continuity strategies, documented business continuity plans, and a programme of exercises and tests.

The current version

The current edition is ISO 22301:2019. Guidance for implementing it is in ISO 22313.

ISO 22301 and ISO 27001

ISO 27001 covers continuity only from the information security angle (Annex A 5.29 and 5.30). ISO 22301 covers the whole business: people, premises, suppliers and processes, not just IT. Because both share the same structure, many companies run them as an integrated management system with common policies, audits and management reviews.

Who needs it

It is common in financial services, critical infrastructure, logistics and service providers whose customers depend on their availability. DORA and NIS2 do not require certification, but ISO 22301 is a recognised way to structure the continuity measures they demand.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub