ISO 22301
Business Continuity Management Systems
ISO 22301:2019 at a glance
- Current edition
- ISO 22301:2019 - Security and resilience — Business continuity management systems — Requirements
- Published
- 2019
- Status
- Published (under revision)
- Type of standard
- Management system standard
- Certifiable
- Yes — organizations can be certified by an accredited body
- Previous edition
- ISO 22301:2012
- Official ISO page
- View ISO 22301:2019 on iso.org
- Last verified
Overview
The certifiable business continuity management system standard. Current edition is ISO 22301:2019 with Amendment 1:2024 (climate action); a revision is in preparation at committee draft stage.
ISO 22301:2019, Security and resilience — Business continuity management systems — Requirements, is the second edition and replaces ISO 22301:2012. Its requirements are generic and intended to apply to any organization or part of an organization, regardless of type, size or nature, though the extent of application depends on the organization's operating environment and complexity.
It uses the harmonized management system structure, so the familiar clauses on context, leadership, planning, support, operation, performance evaluation and improvement all appear and integrate with ISO 9001, ISO/IEC 27001 and ISO/IEC 20000-1 systems. The business continuity substance sits in the operation clause.
The analytical foundation is the business impact analysis (BIA) combined with a risk assessment. The BIA determines the activities that support the provision of products and services, the impacts over time of not performing them, the prioritised timeframes for resuming them at a specified minimum acceptable capacity, and the resources those activities need. The risk assessment identifies and evaluates the risks of disruption to prioritised activities and their resources. Together these produce the requirements that continuity strategies and solutions must satisfy — the recovery time and recovery point expectations that later appear in plans.
From that analysis the organization identifies and selects business continuity strategies and solutions covering stabilising, continuing, resuming and recovering prioritised activities, and mitigating and managing impacts. It then implements the solutions and establishes a response structure with defined roles, authority to invoke, and thresholds for activation. Business continuity plans and procedures must define communication arrangements, including with interested parties and where relevant with emergency responders and the media, and must be specific about who does what.
The standard requires an exercise and testing programme: continuity arrangements must be exercised and tested to a defined programme, with exercises consistent with the scope and objectives, results formally reviewed, and improvements made. This clause is where certification audits often concentrate, because plans that have never been exercised are the most common weakness in a continuity programme. Performance evaluation additionally requires the organization to evaluate business continuity procedures and capabilities, and to review them after a disruption.
Amendment 1:2024 added climate action wording to the context and interested-parties clauses, in line with the change made across ISO management system standards.
Certification is available through accredited certification bodies, following a two-stage initial audit, surveillance during the certificate cycle and recertification. It is frequently requested in financial services, technology, healthcare and public sector supply chains, and is used to satisfy customer and regulatory expectations on operational resilience. The related guidance standard ISO 22313 explains how to apply ISO 22301's requirements, and other members of the ISO 22300 family cover organizational resilience, BIA guidance, business continuity strategy, and the development and management of continuity plans.
A revision of ISO 22301 is in preparation and has reached committee draft stage. Until a new edition is published, ISO 22301:2019 with Amendment 1:2024 remains the standard for certification.
Purpose
To specify requirements to implement, maintain and improve a management system to protect against, reduce the likelihood of the occurrence of, prepare for, respond to and recover from disruptions when they arise.
Key Benefits
- Provides a certifiable framework for preparing for and recovering from disruption
- Business impact analysis produces defensible, prioritised recovery timeframes
- Requires exercising and testing, so plans are validated rather than assumed to work
- Establishes a clear incident response structure with defined invocation authority
- Integrates with ISO/IEC 27001, ISO/IEC 20000-1 and ISO 9001 through the shared structure
- Widely recognised in financial services, technology and public sector supply chains
- Supports regulatory and customer expectations on operational resilience
- Extends continuity thinking to suppliers and the resources prioritised activities depend on
- Supported by ISO 22313 guidance and the wider ISO 22300 family
Key Requirements
- Determine the context of the organization and the needs and expectations of interested parties, including legal and regulatory requirements
- Define the scope of the business continuity management system, including the products and services included
- Demonstrate top management leadership, establish a business continuity policy and assign roles
- Address risks and opportunities and set business continuity objectives
- Provide resources, ensure competence and awareness, and manage communication and documented information
- Conduct a business impact analysis to determine prioritised activities, impacts over time and resource requirements
- Determine prioritised timeframes for resuming activities at a specified minimum acceptable capacity
- Conduct a risk assessment of disruption to prioritised activities and their resources
- Identify, select and implement business continuity strategies and solutions
- Establish a response structure with defined roles, responsibilities and authority to invoke
- Establish warning and communication procedures, including with interested parties
- Document business continuity plans and procedures for stabilising, continuing, resuming and recovering activities
- Establish and implement an exercise and testing programme and evaluate the results
- Evaluate business continuity documentation and capabilities, including after a disruption
- Monitor, measure, analyse and evaluate the BCMS, conduct internal audits and management reviews
- Manage nonconformities and corrective action and continually improve the BCMS
- Address climate change as a context issue in accordance with Amendment 1:2024
Who Needs This Standard?
Organizations whose disruption would materially affect customers, the public or their own viability — financial services, insurance, healthcare providers, technology and cloud providers, telecoms, utilities, transport and logistics, manufacturers with concentrated supply chains, and public sector bodies. It concerns business continuity and resilience managers, risk and compliance functions, IT disaster recovery teams, and organizations facing regulatory operational resilience requirements or customer continuity assurance in contracts.
Where to get ISO 22301
The full text of ISO 22301 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 22301 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.
Get our free implementation resources
Send me the implementation checklist for ISO 22301, plus an alert when this standard is revised, withdrawn or replaced. Free, no account needed.
We'll only email you about this standard. Unsubscribe anytime.
Need help getting certified?
Certificates for ISO 22301 are issued by accredited certification bodies, not by ISO itself. Tell us what stage you are at and we will put you in touch with people who work with this standard — implementation support, audit or training. Free and no obligation.
Get help with ISO 22301 certification
In a hurry? You can also compare provider quotes on CertBetter (affiliate link — we earn a commission, and it stays free for you).