Skip to main content
Category: Business Continuity

ISO 22301

Also known as: ISO 22301:2019, Business Continuity Management Systems standard, BCMS standard, ISO 22301 (Security and resilience)
Simply put

ISO 22301 is an international standard that helps organizations prepare for, respond to, and recover from disruptive events such as outages, disasters, or other incidents that could interrupt normal operations. It sets out how to build and run a business continuity management system (BCMS) so that critical activities can continue or be restored within acceptable timeframes. An organization can be certified against ISO 22301 by an accredited certification body, though certification covers only the defined scope of the management system and does not guarantee that no disruption will ever occur.

Formal definition

ISO 22301 (current edition ISO 22301:2019, superseding ISO 22301:2012) specifies the structure and requirements for establishing, implementing, operating, monitoring, reviewing, maintaining, and continually improving a documented business continuity management system (BCMS). Note that the official designation is ISO 22301, not ISO/IEC 22301, as it is an ISO standard rather than a joint ISO/IEC deliverable. The standard is used to assess an organization's ability to meet its own business continuity needs and obligations, and it follows the harmonized management-system structure common to standards such as ISO 27001, which supports partial alignment and integration but does not make the standards equivalent. The 2019 edition has been updated by ISO 22301:2019/Amd 1:2024, which introduces climate-action changes to the management-system requirements. As with other certifiable management-system standards, conformity is confirmed through certification by an accredited certification body against the defined scope; certification attests to the BCMS as scoped and does not itself constitute an attestation report or provide assurance about matters outside that scope.

Why it matters

Disruptions to business operations, whether from natural disasters, technology outages, supply chain failures, or other incidents, can threaten an organization's ability to deliver its critical products and services. ISO 22301 matters because it gives organizations a recognized, systematic way to prepare for, respond to, and recover from such events, helping ensure that critical activities can continue or be restored within acceptable timeframes rather than relying on ad hoc responses when a crisis strikes.

For GRC professionals and their stakeholders, certification against ISO 22301 by an accredited certification body provides third-party evidence that a business continuity management system (BCMS) has been established and operates within a defined scope. This can support customer assurance, regulatory expectations, and contractual obligations related to resilience. However, it is important to understand the boundaries of what certification conveys: it attests to the BCMS as scoped and does not guarantee that no disruption will ever occur, nor does it provide assurance about matters outside the defined scope.

Because ISO 22301 follows the harmonized management-system structure shared by standards such as ISO 27001, organizations that already operate other management systems can often integrate business continuity into their existing governance rather than building it in isolation. This partial alignment supports efficiency, but it does not make the standards equivalent, each addresses distinct objectives and is certified against its own requirements.

Who it's relevant to

Business continuity and resilience managers
Professionals responsible for continuity planning use ISO 22301 as a framework to establish, operate, and continually improve a BCMS, helping ensure critical activities can continue or be restored within acceptable timeframes after a disruption.
GRC and compliance teams
Because ISO 22301 shares the harmonized management-system structure used by standards such as ISO 27001, GRC teams can pursue partial alignment and integrated governance across systems, while recognizing that certification covers only the defined scope and does not make the standards equivalent.
Auditors and certification bodies
Accredited certification bodies assess an organization's BCMS against ISO 22301 requirements within a defined scope. Auditors should work from the current edition (ISO 22301:2019) and account for ISO 22301:2019/Amd 1:2024, which introduces climate-action changes now in force.
Customers and procurement teams evaluating suppliers
Organizations relying on third parties can treat ISO 22301 certification as third-party evidence of a scoped BCMS, while understanding that it does not guarantee freedom from disruption or provide assurance about matters outside the certified scope.

Inside ISO 22301

Business Continuity Management System (BCMS)
ISO 22301 specifies requirements for establishing, implementing, maintaining, and continually improving a management system to protect against, reduce the likelihood of, prepare for, respond to, and recover from disruptions. Like ISO 27001, its certifiable requirements are structured across management-system clauses rather than a fixed control catalogue.
Correct designation
The standard is designated ISO 22301 (not ISO/IEC 22301). It is issued by ISO alone rather than jointly with IEC, which distinguishes its numbering convention from the ISO/IEC 27000-series family.
Current version and amendment
The current edition is ISO 22301:2019, updated by ISO 22301:2019/Amd 1:2024, which introduces climate-action changes to the management-system requirements. When citing the standard's requirements, specify the edition and applicable amendment, since normative text depends on the version in force.
Certification outcome
As with ISO 27001, conformity to ISO 22301 is demonstrated through certification issued by an accredited certification body against the management-system requirements, not through an attestation report. A certificate covers only the defined scope of the BCMS.
Relationship to security frameworks
ISO 22301 addresses business continuity and is distinct from SOC 2 and ISO 27001. Availability-related concerns overlap conceptually with the optional Availability category of the SOC 2 Trust Services Criteria and with continuity-related ISO 27001 Annex A controls, but the frameworks are separate and satisfying one does not satisfy another.

Common questions

Answers to the questions practitioners most commonly ask about ISO 22301.

Is the standard correctly cited as ISO/IEC 22301?
No. The official designation is ISO 22301, without the "/IEC" prefix. The "ISO/IEC" joint designation applies to standards developed jointly by ISO and the International Electrotechnical Commission, such as ISO/IEC 27001. ISO 22301 is an ISO standard and should be cited as such. When referencing it precisely, use ISO 22301 and specify the edition, such as ISO 22301:2019, since requirements depend on the version in force.
Does ISO 22301:2019 remain unchanged, or has it been updated?
The 2019 edition has been amended. ISO 22301:2019/Amd 1:2024 introduced climate-action changes and is now in force. When citing the standard, specify both the edition and any applicable amendment, since the normative requirements you are held to depend on the current published text rather than the base 2019 document alone. Confirm the exact wording against the current standard, as amendment details vary and should not be paraphrased from memory.
How does ISO 22301 relate to ISO 27001 when both are being implemented?
The two address different objectives: ISO 22301 specifies requirements for a business continuity management system, while ISO 27001 specifies requirements for an information security management system. Both follow the ISO management system structure (clauses 4 through 10), which typically allows organizations to align common elements such as leadership, context, and continual improvement. In most engagements, however, each standard is certified separately against its own scope, and satisfying one does not automatically satisfy the other. Confirm the specific mapping opportunities against the current text of each standard.
How should an organization define the scope of its business continuity management system under ISO 22301?
Scope is typically established during the context and planning phases, informed by the organization's objectives, interested parties, and the products and services it must be able to continue delivering. As with other ISO management system standards, certification covers only the defined scope; activities, sites, or services excluded from that scope are not covered by the resulting certificate. Scope decisions depend on the organization and should be documented so that boundaries are clear to the certification body and to relying parties.
What role does a business impact analysis play in an ISO 22301 implementation?
A business impact analysis and a risk assessment typically underpin the prioritization of activities and the determination of continuity requirements within the management system. The specific methodology, criteria, and outputs depend on the organization's context and scope rather than a single prescribed approach. Confirm the precise requirements and terminology against the current edition and any applicable amendment, since the exact wording governs what a certification body will assess.
What outcome does ISO 22301 certification produce, and what are its limitations?
ISO 22301 certification is issued by an accredited certification body against the management system standard and results in a certificate, not a report or attestation. The certificate covers only the defined scope of the business continuity management system and reflects conformity assessed at the time of the audit and through subsequent surveillance. It does not guarantee that disruptions will not occur or that recovery objectives will always be met in practice; it indicates that a management system meeting the standard's requirements has been established and assessed. Maintenance typically depends on ongoing surveillance and recertification cycles set by the certification body.

Common misconceptions

The standard is designated ISO/IEC 22301, matching the ISO/IEC 27001 naming pattern.
The correct designation is ISO 22301. It is an ISO standard and does not carry the IEC prefix used by jointly developed standards such as ISO/IEC 27001.
Holding an ISO 27001 certificate or a SOC 2 report demonstrates business continuity conformity equivalent to ISO 22301.
The frameworks are distinct. Mapping between them may be partial at best, and conformity to one does not automatically demonstrate conformity to ISO 22301. A SOC 2 report attests only to the controls and period covered, and an ISO 27001 certificate covers only its defined ISMS scope.
Referencing ISO 22301:2019 alone reflects the current normative requirements.
ISO 22301:2019 has been updated by Amendment 1:2024 introducing climate-action changes now in force. Practitioners should reference the edition together with the applicable amendment when citing requirements.

Best practices

Cite the standard correctly as ISO 22301 without the IEC prefix, and specify the edition and amendment (for example, ISO 22301:2019 as amended by Amd 1:2024) whenever referencing its requirements.
Account for the climate-action changes introduced by ISO 22301:2019/Amd 1:2024 when reviewing or updating an existing BCMS against the current normative text.
Clearly define and document the scope of the BCMS, recognising that any certificate covers only that defined scope and does not guarantee freedom from disruption.
Keep ISO 22301 activities distinct from, but aligned with, related efforts under ISO 27001 or SOC 2, treating any cross-framework mapping as partial rather than assuming equivalence.
Confirm that certification is pursued through an accredited certification body and treat the outcome as a certification, not an attestation report.
Use qualified, scope-dependent language in internal and external communications, since continuity outcomes depend on the certification body, scope, and version in force.