Certify Business Continuity
ISO 22301 Business Continuity Management Certification
ISO 22301 is the standard for business continuity management. We help you plan for disruption, test your response, and certify that you can keep critical operations running.
See the engagement path, 6 phasesSee the full Compliance service index
Overview
ISO 22301 sets out how to run a business continuity management system, or BCMS: the plans and controls that keep your critical services alive through outages, disasters, and other shocks. It matters because customers and regulators want proof you can recover, not just a promise. We help you understand what your business cannot afford to lose, build recovery plans that actually work, and test them before a real event does.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the ISO 22301 engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Business Impact Analysis. We set the BCMS scope, then run a business impact analysis to find your critical activities and how long they can be down. Activities: Define the BCMS scope and critical services; Interview process owners on dependencies; Set maximum tolerable downtime for each activity; Map upstream suppliers and single points of failure. Hands over Business Impact Analysis Report. Phase 2, Continuity Risk Assessment. We assess the threats to those critical activities and agree which ones need continuity strategies. Activities: Identify disruption scenarios per critical activity; Score likelihood and impact of each threat; Assess current resilience and workarounds; Agree which risks need continuity strategies. Hands over Continuity Risk Register. Phase 3, Continuity Strategy and Plans. We design recovery strategies and write clear continuity plans with defined recovery time and recovery point objectives. Activities: Select recovery strategies for each critical activity; Set RTO and RPO targets with the business; Write continuity and disaster recovery plans; Define crisis roles and escalation paths. Hands over Business Continuity Plan Set. Phase 4, Exercising and Testing. We run tabletop and live exercises to prove the plans work and to train the people who will use them. Activities: Design exercise scenarios against real threats; Run tabletop walkthroughs with the crisis team; Conduct a live failover or recovery test; Capture lessons and update the plans. Hands over Exercise and Test Report. Phase 5, Internal Audit and Review. We audit the BCMS against the standard and hold a management review to confirm it is fit for purpose. Activities: Audit the BCMS against ISO 22301 clauses; Review exercise results and open actions; Log nonconformities and corrective actions; Run the management review with leadership. Hands over Internal Audit Report and Management Review Record. Phase 6, Certification and Maintenance. We support the certification audit and help you keep plans current as your business changes. Activities: Prepare evidence for Stage 1 and Stage 2 audits; Support auditor interviews and site visits; Close audit findings raised; Set the annual exercise and plan review cycle. Hands over ISO 22301 Certificate. Each phase begins from the artefact the phase before it produced.
Phase 01 Scoping and Business Impact Analysis
We set the BCMS scope, then run a business impact analysis to find your critical activities and how long they can be down.
What Happens In This Phase
- Define the BCMS scope and critical services
- Interview process owners on dependencies
- Set maximum tolerable downtime for each activity
- Map upstream suppliers and single points of failure
The Handover
Business Impact Analysis Report
The next phase starts from this.
Phase 01 Scoping and Business Impact Analysis
We set the BCMS scope, then run a business impact analysis to find your critical activities and how long they can be down.
What Happens In This Phase
- Define the BCMS scope and critical services
- Interview process owners on dependencies
- Set maximum tolerable downtime for each activity
- Map upstream suppliers and single points of failure
The Handover
Business Impact Analysis Report
The next phase starts from this.
- 01
Scoping and Business Impact Analysis
We set the BCMS scope, then run a business impact analysis to find your critical activities and how long they can be down.
OutputBusiness Impact Analysis ReportActivities
- Define the BCMS scope and critical services
- Interview process owners on dependencies
- Set maximum tolerable downtime for each activity
- Map upstream suppliers and single points of failure
- 02
Continuity Risk Assessment
We assess the threats to those critical activities and agree which ones need continuity strategies.
OutputContinuity Risk RegisterActivities
- Identify disruption scenarios per critical activity
- Score likelihood and impact of each threat
- Assess current resilience and workarounds
- Agree which risks need continuity strategies
- 03
Continuity Strategy and Plans
We design recovery strategies and write clear continuity plans with defined recovery time and recovery point objectives.
OutputBusiness Continuity Plan SetActivities
- Select recovery strategies for each critical activity
- Set RTO and RPO targets with the business
- Write continuity and disaster recovery plans
- Define crisis roles and escalation paths
- 04
Exercising and Testing
We run tabletop and live exercises to prove the plans work and to train the people who will use them.
OutputExercise and Test ReportActivities
- Design exercise scenarios against real threats
- Run tabletop walkthroughs with the crisis team
- Conduct a live failover or recovery test
- Capture lessons and update the plans
- 05
Internal Audit and Review
We audit the BCMS against the standard and hold a management review to confirm it is fit for purpose.
OutputInternal Audit Report and Management Review RecordActivities
- Audit the BCMS against ISO 22301 clauses
- Review exercise results and open actions
- Log nonconformities and corrective actions
- Run the management review with leadership
- 06
Certification and Maintenance
We support the certification audit and help you keep plans current as your business changes.
OutputISO 22301 CertificateActivities
- Prepare evidence for Stage 1 and Stage 2 audits
- Support auditor interviews and site visits
- Close audit findings raised
- Set the annual exercise and plan review cycle
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
Built by SecureRoot
TrustGrid
Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.
What Is Examined, and What it Is Measured Against
Map
Map of the ISO 22301 scope, running left to right in three stages. Stage one, what we run, 7 tools and techniques: Jira, Confluence, ServiceNow, Microsoft Purview, Fusion Framework System, Archer, Smartsheet. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: ISO 22301:2019, ISO 22313, ISO/IEC 27031, NIST SP 800-34, ISO 31000.
What We Run
7 tools
- ServiceNow
- Microsoft Purview
- Fusion Framework System
- Archer
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
5 standards
Deliverables
What You Receive
- Business impact analysis report
- Business continuity plans
- Exercise and test reports
- BCMS policy set
- Certification audit support
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
What is a business impact analysis?
It is the study that finds your critical activities, how quickly they must recover, and what they depend on. Everything else in the BCMS builds on it.
What are RTO and RPO?
Recovery time objective is how fast you must restore a service. Recovery point objective is how much data you can afford to lose. We help you set both realistically.
How often should we test our continuity plans?
At least once a year, and after any major change. Regular exercises are also what the auditor looks for, so we build a testing schedule with you.
Keep Moving Through Compliance
Service 3 of 13 in this practice area
Practice Area
More in Compliance
- ISO 27001Build and certify your information security management system.
- ISO 27701Extend your ISMS into a privacy information management system.
- ISO 42001Govern your AI systems with the first AI management standard.
- DPDP ActGet ready for India's Digital Personal Data Protection Act.
- PCI DSSProtect cardholder data and pass your PCI assessment.
- HIPAAProtect health information and meet HIPAA requirements.
- SOC 2Earn a SOC 2 report your customers can trust.
- CCPAMeet California's consumer privacy requirements.
- GDPRMeet Europe's data protection standard with confidence.
- NEN 7510Certify information security for Dutch healthcare.
- EU AI ActPrepare for Europe's risk-based AI regulation.
- Third Party Risk Assessment (TPRM)Understand and manage the risk your vendors bring.