What it requires
ISO 22301 follows the same management system structure as ISO 27001: context, leadership, planning, support, operation, performance evaluation and improvement. The operational core is the business impact analysis, an assessment of disruption risks, continuity strategies, documented business continuity plans, and a programme of exercises and tests.
The current version
The current edition is ISO 22301:2019. Guidance for implementing it is in ISO 22313.
ISO 22301 and ISO 27001
ISO 27001 covers continuity only from the information security angle (Annex A 5.29 and 5.30). ISO 22301 covers the whole business: people, premises, suppliers and processes, not just IT. Because both share the same structure, many companies run them as an integrated management system with common policies, audits and management reviews.
Who needs it
It is common in financial services, critical infrastructure, logistics and service providers whose customers depend on their availability. DORA and NIS2 do not require certification, but ISO 22301 is a recognised way to structure the continuity measures they demand.




