Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Part of Compliance13 services in this practice area

Certify Business Continuity

ISO 22301 Business Continuity Certification

ISO 22301 is the certifiable standard for business continuity management. We help you work out what your business cannot afford to lose, build recovery plans that hold up, and test them before a real disruption does.

See the engagement path, 6 phasesSee the full Compliance service index

Overview

ISO 22301 sets out how to run a business continuity management system: the analysis, plans and exercises that keep critical services running through outages, cyber incidents and other shocks, and bring them back within agreed times. It matters because customers, auditors and regulators increasingly want proof of recovery rather than a promise, and because Indian regulated entities already carry continuity duties, including the business continuity and disaster recovery chapters of the RBI's 2026 Directions and the recovery expectations in SEBI's cyber resilience framework. We help Indian companies build the business impact analysis, recovery strategies and exercise programme a certification audit expects, working remotely across India from our Greater Noida and Kanpur offices.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the ISO 22301 engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Business Impact Analysis. We set the BCMS scope, then run a business impact analysis to find your critical activities and how long they can be down. Activities: Define the BCMS scope and critical services; Interview process owners on dependencies; Set maximum tolerable downtime for each activity; Map upstream suppliers and single points of failure. Hands over Business Impact Analysis Report. Phase 2, Continuity Risk Assessment. We assess the threats to those critical activities and agree which ones need continuity strategies. Activities: Identify disruption scenarios per critical activity; Score likelihood and impact of each threat; Assess current resilience and workarounds; Agree which risks need continuity strategies. Hands over Continuity Risk Register. Phase 3, Continuity Strategy and Plans. We design recovery strategies and write clear continuity plans with defined recovery time and recovery point objectives. Activities: Select recovery strategies for each critical activity; Set RTO and RPO targets with the business; Write continuity and disaster recovery plans; Define crisis roles and escalation paths. Hands over Business Continuity Plan Set. Phase 4, Exercising and Testing. We run tabletop and live exercises to prove the plans work and to train the people who will use them. Activities: Design exercise scenarios against real threats; Run tabletop walkthroughs with the crisis team; Conduct a live failover or recovery test; Capture lessons and update the plans. Hands over Exercise and Test Report. Phase 5, Internal Audit and Review. We audit the BCMS against the standard and hold a management review to confirm it is fit for purpose. Activities: Audit the BCMS against ISO 22301 clauses; Review exercise results and open actions; Log nonconformities and corrective actions; Run the management review with leadership. Hands over Internal Audit Report and Management Review Record. Phase 6, Certification and Maintenance. We support the certification audit and help you keep plans current as your business changes. Activities: Prepare evidence for Stage 1 and Stage 2 audits; Support auditor interviews and site visits; Close audit findings raised; Set the annual exercise and plan review cycle. Hands over ISO 22301 Certificate. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and Business Impact Analysis

We set the BCMS scope, then run a business impact analysis to find your critical activities and how long they can be down.

What Happens In This Phase

  • Define the BCMS scope and critical services
  • Interview process owners on dependencies
  • Set maximum tolerable downtime for each activity
  • Map upstream suppliers and single points of failure

The Handover

Business Impact Analysis Report

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and Business Impact Analysis

    We set the BCMS scope, then run a business impact analysis to find your critical activities and how long they can be down.

    OutputBusiness Impact Analysis Report

    Activities

    • Define the BCMS scope and critical services
    • Interview process owners on dependencies
    • Set maximum tolerable downtime for each activity
    • Map upstream suppliers and single points of failure
  2. 02

    Continuity Risk Assessment

    We assess the threats to those critical activities and agree which ones need continuity strategies.

    OutputContinuity Risk Register

    Activities

    • Identify disruption scenarios per critical activity
    • Score likelihood and impact of each threat
    • Assess current resilience and workarounds
    • Agree which risks need continuity strategies
  3. 03

    Continuity Strategy and Plans

    We design recovery strategies and write clear continuity plans with defined recovery time and recovery point objectives.

    OutputBusiness Continuity Plan Set

    Activities

    • Select recovery strategies for each critical activity
    • Set RTO and RPO targets with the business
    • Write continuity and disaster recovery plans
    • Define crisis roles and escalation paths
  4. 04

    Exercising and Testing

    We run tabletop and live exercises to prove the plans work and to train the people who will use them.

    OutputExercise and Test Report

    Activities

    • Design exercise scenarios against real threats
    • Run tabletop walkthroughs with the crisis team
    • Conduct a live failover or recovery test
    • Capture lessons and update the plans
  5. 05

    Internal Audit and Review

    We audit the BCMS against the standard and hold a management review to confirm it is fit for purpose.

    OutputInternal Audit Report and Management Review Record

    Activities

    • Audit the BCMS against ISO 22301 clauses
    • Review exercise results and open actions
    • Log nonconformities and corrective actions
    • Run the management review with leadership
  6. 06

    Certification and Maintenance

    We support the certification audit and help you keep plans current as your business changes.

    OutputISO 22301 Certificate

    Activities

    • Prepare evidence for Stage 1 and Stage 2 audits
    • Support auditor interviews and site visits
    • Close audit findings raised
    • Set the annual exercise and plan review cycle

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Built by SecureRoot

TrustGrid

Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the ISO 22301 scope, running left to right in three stages. Stage one, what we run, 7 tools and techniques: Jira, Confluence, ServiceNow, Microsoft Purview, Fusion Framework System, Archer, Smartsheet. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: ISO 22301:2019, ISO 22313, ISO/IEC 27031, NIST SP 800-34, ISO 31000.

What We Run

7 tools

  • Jira
  • Confluence
  • ServiceNow
  • Microsoft Purview
  • Fusion Framework System
  • Archer
  • Smartsheet

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • ISO 22301:2019
  • ISO 22313
  • ISO/IEC 27031
  • NIST SP 800-34
  • ISO 31000
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Business impact analysis report
  • Business continuity plans
  • Exercise and test reports
  • BCMS policy set
  • Certification audit support

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

What is a business impact analysis, and why does everything start there?

A business impact analysis identifies your critical activities, how quickly each must be restored after a disruption, and what they depend on: people, systems, suppliers, premises and data. It puts numbers on the cost of downtime, so recovery priorities come from the business rather than from IT preference. Everything else in a business continuity management system builds on it. Recovery strategies are chosen to meet the timescales it sets, plans are written for the activities it ranks highest, and exercises test those plans. Auditors read it first, because a plan that does not trace back to an analysis is usually a plan written around whatever was convenient. We run the analysis with the people who own each activity rather than from a template, since only they know what actually breaks when a system or site is unavailable. The analysis is also the document to revisit when the business changes, because a new product or site quietly changes what matters most.

What do RTO and RPO mean in practice?

The recovery time objective is how quickly an activity or system must be working again after a disruption. The recovery point objective is how much data you can afford to lose, which in practice sets how often you replicate or back up. Both are business decisions with technical consequences and costs: a four-hour recovery time and a fifteen-minute recovery point need very different architecture from a two-day target. The common failure is setting ambitious objectives that the infrastructure cannot meet, which an exercise exposes immediately and an auditor treats as a gap. We help you set objectives your organisation can actually achieve, document the gap where current capability falls short, and plan the investment needed to close it rather than quietly writing a number nobody can meet. We also record the assumptions behind each objective, such as which staff and suppliers must be available, so a later exercise tests the whole dependency rather than the technology alone. Auditors look for that traceability.

How often should continuity plans be tested?

At least once a year, and after any significant change to your systems, sites, suppliers or organisation. Regular exercising is what the standard expects and what auditors examine, and it is the only reliable way to discover that a call tree is out of date, a backup does not restore or a recovery runbook assumes a person who has left. Most organisations use a mix: a tabletop walkthrough with the people who would make decisions, a technical failover test of critical systems, and a full simulation less often. Every exercise should produce findings, owners and corrective actions that feed the next review. We design an exercise schedule proportionate to your risk, facilitate the sessions and write the reports certification auditors will ask to see. Where an exercise reveals that an objective cannot be met, we record it as a finding with a remediation plan rather than quietly relaxing the target, because an unexplained change of objective is exactly what a certification auditor probes.

Does ISO 22301 replace our disaster recovery plan?

No, it puts the disaster recovery plan in context. Disaster recovery is the technical restoration of systems and data; business continuity covers the whole organisation, including people, premises, suppliers, communications and the decisions leadership must make while services are degraded. ISO 22301 provides the management system around both: the analysis that sets priorities, the strategies chosen to meet them, plans and exercises, incident response structure, and management review. In practice we keep your existing disaster recovery runbooks and connect them to the recovery objectives the business impact analysis sets, adding the non-technical parts that are usually missing, such as who declares an incident, who speaks to customers and regulators, and how work continues while systems are unavailable. We also make sure the plans name deputies for every role, since the person who normally decides is often the person who is unreachable during the disruption. Auditors and real incidents both find single points of human failure quickly, and so does a well-run exercise.

How long does ISO 22301 certification take?

For most Indian organisations, four to six months to a first certificate, following our phases. Scoping and the business impact analysis take two to three weeks, the continuity risk assessment one to two, strategies and plans three to four, exercising and testing two to three, and the internal audit and management review one to two, before the certification body's two-stage audit. Organisations that already run ISO 27001 move faster, because the management system, risk process, internal audit and document control already exist and only continuity-specific content is added. What usually stretches the timeline is exercising, since tests need the right people and windows, and remediation after the first exercise. We confirm a timeline after the business impact analysis, when the scale of recovery work is clear. Booking the certification body early matters too, because audit slots are often several weeks out and a late booking can add a month to an otherwise finished programme.

Who issues the certificate, and what does the work cost?

An accredited certification body issues the ISO 22301 certificate after its own two-stage audit, and it must stay independent of whoever built your management system. SecureRoot is not a certification body; we prepare you and support you through the audit. We do not publish a price for this work, because scope drives it: the number of critical activities, sites and business units, how many recovery strategies need designing or testing, whether an ISO 27001 management system already exists to build on, and how much of the analysis and documentation you produce yourselves. The certification body's fee and your team's time during exercises sit outside our fee. We scope first, then give you a fixed price in writing for the work we will do. Where you already hold ISO 27001, a combined audit usually reduces certification body days and keeps one set of management reviews, which lowers both cost and internal effort.

Keep Moving Through Compliance

Service 3 of 13 in this practice area