ISO 22301: business continuity you can exercise, not just document
Run a business continuity management system where the impact analysis, the risk assessment, the plans and the exercise records are dated evidence, the recovery capabilities are checked automatically, and the certification audit runs where the evidence lives.
What is ISO 22301?
ISO 22301 is the international standard for a business continuity management system, a BCMS, with 2019 as its current edition. It follows the same high-level structure as ISO 27001, so the two integrate, and it asks an organization to do a specific sequence of things: understand its context and the needs of interested parties; set the scope of the BCMS and secure leadership commitment; run a business impact analysis to find the activities that must continue, the maximum tolerable period of disruption and the recovery objectives for each; assess the risks of disruption to those activities; choose continuity strategies and resources; write continuity and recovery plans and the procedures for warning, communication and response; exercise and test the plans on a planned program; and evaluate performance and improve through internal audit, management review and corrective action. Certification is issued by an accredited certification body after a Stage 1 readiness review and a Stage 2 audit, with surveillance audits in the three-year cycle. Buyers in financial services, healthcare and critical infrastructure ask for it, and DORA and customer third-party programs increasingly expect continuity evidence from suppliers.
ISO 22301:2019 is the international standard for a business continuity management system, a BCMS. It requires an organization to understand what it must keep running and how quickly, to assess the threats to those activities, to put strategies and plans in place to continue and recover, and to exercise and improve them. Certification is issued by an accredited certification body after a two-stage audit, and buyers in finance, healthcare and critical services ask for it alongside ISO 27001.
Companies whose customers depend on them staying up: SaaS with contractual availability commitments, suppliers to regulated industries, and anyone asked for continuity evidence under DORA or a customer's third-party risk program.
How Viglyn runs ISO 22301
- The business impact analysis and risk assessment run in the risk module, with activities, recovery objectives and dependencies linked to the controls and vendors that support them
- Continuity and recovery plans held as controlled documents, with owners, review dates and a full audit trail
- Recovery capability checked automatically where it can be: backup configuration and retention, replication, infrastructure redundancy and restore tests in your cloud accounts
- Exercise and test records, post-exercise reviews and corrective actions as dated evidence, so the program is demonstrably run
- Shared clauses with ISO 27001, and shared evidence with DORA and SOC 2's availability criteria; Stage 1 and Stage 2 run inside Viglyn with scoped auditor access
The ISO 22301 questions that decide it
How long does ISO 22301 take?
Three to six months is typical when an ISO 27001 management system exists, because the shared clauses carry over. The business impact analysis and the first full exercise cycle set the pace; Viglyn's practitioners run the analysis with you rather than hand you a template.
How much does ISO 22301 cost with Viglyn?
ISO 22301 counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. The certification body's fee is separate and paid by you directly; we take no commission.
Can we run ISO 22301 with ISO 27001?
Yes, and most teams do. The two share their structure and much of their evidence: asset and supplier inventories, risk assessment, backups, incident response. In Viglyn one evidence base maps across both, and every plan includes at least two frameworks.
More ISO 22301 questions
What is a business impact analysis?
How often do we have to exercise the plans?
Is ISO 22301 relevant to DORA?
See ISO 22301 run on your stack
A 30-minute walkthrough with your systems and your framework. No commitment.
