Skip to content
New · AI governance: inventory your AI systems, check the controls, certify ISO 42001.See it
ISO 22301

ISO 22301: business continuity you can exercise, not just document

Run a business continuity management system where the impact analysis, the risk assessment, the plans and the exercise records are dated evidence, the recovery capabilities are checked automatically, and the certification audit runs where the evidence lives.

What is ISO 22301?

ISO 22301 is the international standard for a business continuity management system, a BCMS, with 2019 as its current edition. It follows the same high-level structure as ISO 27001, so the two integrate, and it asks an organization to do a specific sequence of things: understand its context and the needs of interested parties; set the scope of the BCMS and secure leadership commitment; run a business impact analysis to find the activities that must continue, the maximum tolerable period of disruption and the recovery objectives for each; assess the risks of disruption to those activities; choose continuity strategies and resources; write continuity and recovery plans and the procedures for warning, communication and response; exercise and test the plans on a planned program; and evaluate performance and improve through internal audit, management review and corrective action. Certification is issued by an accredited certification body after a Stage 1 readiness review and a Stage 2 audit, with surveillance audits in the three-year cycle. Buyers in financial services, healthcare and critical infrastructure ask for it, and DORA and customer third-party programs increasingly expect continuity evidence from suppliers.

In one paragraph

ISO 22301:2019 is the international standard for a business continuity management system, a BCMS. It requires an organization to understand what it must keep running and how quickly, to assess the threats to those activities, to put strategies and plans in place to continue and recover, and to exercise and improve them. Certification is issued by an accredited certification body after a two-stage audit, and buyers in finance, healthcare and critical services ask for it alongside ISO 27001.

Who it's for

Companies whose customers depend on them staying up: SaaS with contractual availability commitments, suppliers to regulated industries, and anyone asked for continuity evidence under DORA or a customer's third-party risk program.

With Viglyn

How Viglyn runs ISO 22301

  • The business impact analysis and risk assessment run in the risk module, with activities, recovery objectives and dependencies linked to the controls and vendors that support them
  • Continuity and recovery plans held as controlled documents, with owners, review dates and a full audit trail
  • Recovery capability checked automatically where it can be: backup configuration and retention, replication, infrastructure redundancy and restore tests in your cloud accounts
  • Exercise and test records, post-exercise reviews and corrective actions as dated evidence, so the program is demonstrably run
  • Shared clauses with ISO 27001, and shared evidence with DORA and SOC 2's availability criteria; Stage 1 and Stage 2 run inside Viglyn with scoped auditor access
Straight answers

The ISO 22301 questions that decide it

How long does ISO 22301 take?

Three to six months is typical when an ISO 27001 management system exists, because the shared clauses carry over. The business impact analysis and the first full exercise cycle set the pace; Viglyn's practitioners run the analysis with you rather than hand you a template.

How much does ISO 22301 cost with Viglyn?

ISO 22301 counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. The certification body's fee is separate and paid by you directly; we take no commission.

Can we run ISO 22301 with ISO 27001?

Yes, and most teams do. The two share their structure and much of their evidence: asset and supplier inventories, risk assessment, backups, incident response. In Viglyn one evidence base maps across both, and every plan includes at least two frameworks.

FAQ

More ISO 22301 questions

What is a business impact analysis?
The analysis that identifies the activities your organization must keep running, what depends on them, how long each can be down before the impact becomes intolerable, and the recovery time and recovery point objectives that follow. It is the foundation the rest of the BCMS is built on, and Viglyn holds it as structured, dated evidence.
How often do we have to exercise the plans?
The standard requires a planned exercise program consistent with the scope and objectives of the BCMS, with exercises that test the plans and the people in them and a review after each. Most certified organizations exercise critical plans at least yearly, and Viglyn tracks the schedule and the records.
Is ISO 22301 relevant to DORA?
Very. DORA's ICT business continuity and response and recovery requirements line up with the BCMS, and a certified system gives a financial entity and its suppliers a structured way to evidence them. The same records serve both in Viglyn.

See ISO 22301 run on your stack

A 30-minute walkthrough with your systems and your framework. No commitment.