ISO 22301 Certification — Business Continuity Management
Ensure business resilience during disruptions.
Who this standard is for
Organisations that cannot afford to stop — financial services, healthcare, utilities, logistics — and those whose clients ask what happens when they do.
Sectors that most often certify
- Banking and fintech
- Insurance
- Healthcare
- Logistics
- Data centres and IT services
What the standard requires
- A business impact analysis that identifies prioritised activities and their timeframes
- Recovery time and recovery point objectives that the business has actually agreed
- Business continuity strategies and solutions that meet those objectives
- Documented continuity plans that a stranger could follow under pressure
- Exercise and testing programme, with the results feeding back into the plans
Evidence auditors typically ask for
- Business impact analysis and the method behind the prioritisation
- Continuity and recovery plans with named roles and contact arrangements
- Exercise reports, including what failed and what changed as a result
- Supplier and dependency assessments for critical services
- Post-incident reviews where real disruptions occurred
Common pitfall: Setting recovery objectives in the plan that the technical architecture cannot meet. The exercise exposes the gap; better to find it before the auditor does.
How certification works
- Choose the standard and scope
The scope statement decides what the certificate actually covers, so it is worth getting right before anything else. It names the activities, and the sites, that are being certified. - Submit your documentation
Your management system documentation is reviewed against the standard. Gaps are identified at this point rather than during the audit, which is where most delays otherwise occur. - Stage 1 audit
A readiness review. The auditor confirms that the system is documented, that internal audits and management review have taken place, and that you are ready to be assessed against practice. - Stage 2 audit
The implementation audit. The auditor tests whether the system described is the system being operated, by examining records and interviewing the people who do the work. - Certification and surveillance
Once any findings are closed, the certificate is issued and listed for verification. Certificates run on a three-year cycle with annual surveillance audits to keep them valid.
Pricing
| Annual certification | Three-year term |
|---|---|
| $2,100 / AED 7,712 per year | $5,670 total for three years |
Published prices, billed as a subscription. Certifying more than one standard together reduces the combined price. Final scope may affect the price where multiple sites or high headcount are involved.
Accreditation and verification
What gives a certificate its value is the body standing behind it. A certificate issued by a body accredited by an International Accreditation Forum member is listed on the IAF CertSearch global registry, where any client or procurement team can confirm it in seconds. Always ask which accreditation body sits behind a certificate, not just who issued it.
Frequently asked questions
How long does ISO 22301 certification take?
It depends on how ready your management system is and on the scope being certified. Once documentation is complete and reviewed, the two audit stages usually move quickly — gaps found at Stage 1 are the most common cause of delay.
Is ISO 22301 certification internationally recognised?
A certificate issued by a body accredited by an International Accreditation Forum member is internationally recognised, and anyone can confirm it on the IAF CertSearch global registry.
How long does the certificate stay valid?
Certificates run on a three-year cycle, subject to passing an annual surveillance audit. If surveillance is not carried out, the certificate can be suspended or withdrawn before the cycle ends.
Do we need a consultant?
Not necessarily. Many organisations prepare their business continuity management system in-house, particularly where processes are already documented. A consultant helps when time is short or the scope is complex, but is not a requirement for certification.
Related standards
- ISO 9001 — Quality Management Systems
- ISO 14001 — Environmental Management
- ISO 45001 — Occupational Health & Safety
- ISO 27001 — Information Security Management
- ISO 22000 — Food Safety Management