ISO 22301
ISO 22301 is an international standard that helps organizations prepare for, respond to, and recover from disruptive events such as outages, disasters, or other incidents that could interrupt normal operations. It sets out how to build and run a business continuity management system (BCMS) so that critical activities can continue or be restored within acceptable timeframes. An organization can be certified against ISO 22301 by an accredited certification body, though certification covers only the defined scope of the management system and does not guarantee that no disruption will ever occur.
ISO 22301 (current edition ISO 22301:2019, superseding ISO 22301:2012) specifies the structure and requirements for establishing, implementing, operating, monitoring, reviewing, maintaining, and continually improving a documented business continuity management system (BCMS). Note that the official designation is ISO 22301, not ISO/IEC 22301, as it is an ISO standard rather than a joint ISO/IEC deliverable. The standard is used to assess an organization's ability to meet its own business continuity needs and obligations, and it follows the harmonized management-system structure common to standards such as ISO 27001, which supports partial alignment and integration but does not make the standards equivalent. The 2019 edition has been updated by ISO 22301:2019/Amd 1:2024, which introduces climate-action changes to the management-system requirements. As with other certifiable management-system standards, conformity is confirmed through certification by an accredited certification body against the defined scope; certification attests to the BCMS as scoped and does not itself constitute an attestation report or provide assurance about matters outside that scope.
Why it matters
Disruptions to business operations, whether from natural disasters, technology outages, supply chain failures, or other incidents, can threaten an organization's ability to deliver its critical products and services. ISO 22301 matters because it gives organizations a recognized, systematic way to prepare for, respond to, and recover from such events, helping ensure that critical activities can continue or be restored within acceptable timeframes rather than relying on ad hoc responses when a crisis strikes.
For GRC professionals and their stakeholders, certification against ISO 22301 by an accredited certification body provides third-party evidence that a business continuity management system (BCMS) has been established and operates within a defined scope. This can support customer assurance, regulatory expectations, and contractual obligations related to resilience. However, it is important to understand the boundaries of what certification conveys: it attests to the BCMS as scoped and does not guarantee that no disruption will ever occur, nor does it provide assurance about matters outside the defined scope.
Because ISO 22301 follows the harmonized management-system structure shared by standards such as ISO 27001, organizations that already operate other management systems can often integrate business continuity into their existing governance rather than building it in isolation. This partial alignment supports efficiency, but it does not make the standards equivalent, each addresses distinct objectives and is certified against its own requirements.
Who it's relevant to
Inside ISO 22301
Common questions
Answers to the questions practitioners most commonly ask about ISO 22301.