Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Compliance13 services in this practice area

Certify Business Continuity

ISO 22301 Business Continuity Management Certification

ISO 22301 is the standard for business continuity management. We help you plan for disruption, test your response, and certify that you can keep critical operations running.

See the engagement path, 6 phasesSee the full Compliance service index

Overview

ISO 22301 sets out how to run a business continuity management system, or BCMS: the plans and controls that keep your critical services alive through outages, disasters, and other shocks. It matters because customers and regulators want proof you can recover, not just a promise. We help you understand what your business cannot afford to lose, build recovery plans that actually work, and test them before a real event does.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the ISO 22301 engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Business Impact Analysis. We set the BCMS scope, then run a business impact analysis to find your critical activities and how long they can be down. Activities: Define the BCMS scope and critical services; Interview process owners on dependencies; Set maximum tolerable downtime for each activity; Map upstream suppliers and single points of failure. Hands over Business Impact Analysis Report. Phase 2, Continuity Risk Assessment. We assess the threats to those critical activities and agree which ones need continuity strategies. Activities: Identify disruption scenarios per critical activity; Score likelihood and impact of each threat; Assess current resilience and workarounds; Agree which risks need continuity strategies. Hands over Continuity Risk Register. Phase 3, Continuity Strategy and Plans. We design recovery strategies and write clear continuity plans with defined recovery time and recovery point objectives. Activities: Select recovery strategies for each critical activity; Set RTO and RPO targets with the business; Write continuity and disaster recovery plans; Define crisis roles and escalation paths. Hands over Business Continuity Plan Set. Phase 4, Exercising and Testing. We run tabletop and live exercises to prove the plans work and to train the people who will use them. Activities: Design exercise scenarios against real threats; Run tabletop walkthroughs with the crisis team; Conduct a live failover or recovery test; Capture lessons and update the plans. Hands over Exercise and Test Report. Phase 5, Internal Audit and Review. We audit the BCMS against the standard and hold a management review to confirm it is fit for purpose. Activities: Audit the BCMS against ISO 22301 clauses; Review exercise results and open actions; Log nonconformities and corrective actions; Run the management review with leadership. Hands over Internal Audit Report and Management Review Record. Phase 6, Certification and Maintenance. We support the certification audit and help you keep plans current as your business changes. Activities: Prepare evidence for Stage 1 and Stage 2 audits; Support auditor interviews and site visits; Close audit findings raised; Set the annual exercise and plan review cycle. Hands over ISO 22301 Certificate. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and Business Impact Analysis

We set the BCMS scope, then run a business impact analysis to find your critical activities and how long they can be down.

What Happens In This Phase

  • Define the BCMS scope and critical services
  • Interview process owners on dependencies
  • Set maximum tolerable downtime for each activity
  • Map upstream suppliers and single points of failure

The Handover

Business Impact Analysis Report

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and Business Impact Analysis

    We set the BCMS scope, then run a business impact analysis to find your critical activities and how long they can be down.

    OutputBusiness Impact Analysis Report

    Activities

    • Define the BCMS scope and critical services
    • Interview process owners on dependencies
    • Set maximum tolerable downtime for each activity
    • Map upstream suppliers and single points of failure
  2. 02

    Continuity Risk Assessment

    We assess the threats to those critical activities and agree which ones need continuity strategies.

    OutputContinuity Risk Register

    Activities

    • Identify disruption scenarios per critical activity
    • Score likelihood and impact of each threat
    • Assess current resilience and workarounds
    • Agree which risks need continuity strategies
  3. 03

    Continuity Strategy and Plans

    We design recovery strategies and write clear continuity plans with defined recovery time and recovery point objectives.

    OutputBusiness Continuity Plan Set

    Activities

    • Select recovery strategies for each critical activity
    • Set RTO and RPO targets with the business
    • Write continuity and disaster recovery plans
    • Define crisis roles and escalation paths
  4. 04

    Exercising and Testing

    We run tabletop and live exercises to prove the plans work and to train the people who will use them.

    OutputExercise and Test Report

    Activities

    • Design exercise scenarios against real threats
    • Run tabletop walkthroughs with the crisis team
    • Conduct a live failover or recovery test
    • Capture lessons and update the plans
  5. 05

    Internal Audit and Review

    We audit the BCMS against the standard and hold a management review to confirm it is fit for purpose.

    OutputInternal Audit Report and Management Review Record

    Activities

    • Audit the BCMS against ISO 22301 clauses
    • Review exercise results and open actions
    • Log nonconformities and corrective actions
    • Run the management review with leadership
  6. 06

    Certification and Maintenance

    We support the certification audit and help you keep plans current as your business changes.

    OutputISO 22301 Certificate

    Activities

    • Prepare evidence for Stage 1 and Stage 2 audits
    • Support auditor interviews and site visits
    • Close audit findings raised
    • Set the annual exercise and plan review cycle

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Built by SecureRoot

TrustGrid

Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the ISO 22301 scope, running left to right in three stages. Stage one, what we run, 7 tools and techniques: Jira, Confluence, ServiceNow, Microsoft Purview, Fusion Framework System, Archer, Smartsheet. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: ISO 22301:2019, ISO 22313, ISO/IEC 27031, NIST SP 800-34, ISO 31000.

What We Run

7 tools

  • Jira
  • Confluence
  • ServiceNow
  • Microsoft Purview
  • Fusion Framework System
  • Archer
  • Smartsheet

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • ISO 22301:2019
  • ISO 22313
  • ISO/IEC 27031
  • NIST SP 800-34
  • ISO 31000
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Business impact analysis report
  • Business continuity plans
  • Exercise and test reports
  • BCMS policy set
  • Certification audit support

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

What is a business impact analysis?

It is the study that finds your critical activities, how quickly they must recover, and what they depend on. Everything else in the BCMS builds on it.

What are RTO and RPO?

Recovery time objective is how fast you must restore a service. Recovery point objective is how much data you can afford to lose. We help you set both realistically.

How often should we test our continuity plans?

At least once a year, and after any major change. Regular exercises are also what the auditor looks for, so we build a testing schedule with you.

Keep Moving Through Compliance

Service 3 of 13 in this practice area