ISO 22301 certification has become a procurement question rather than a philosophical one, and the risk data explains the shift: business interruption ranked as the third biggest global business risk this year, named by 29% of surveyed risk professionals, while cyber incidents held the top spot for a fifth consecutive year at 42% (Source: Allianz Risk Barometer 2026).
Those two risks are increasingly the same risk. A ransomware event, a failed migration, and a regional grid problem all end the same way, with critical services unavailable and a customer asking how long the outage will last.
The old argument for certification was defensive and vague. Get certified, sleep better. That framing no longer survives a serious buyer conversation. What matters now is whether you can show, with evidence, that you know which activities are critical, how long they can be down, and what you will actually do when they stop.
Key Takeaways
- ISO 22301:2019 is the certifiable business continuity standard; ISO 22313 is guidance only.
- Certification proves a working management system, not guaranteed uptime.
- DORA and NIS2 turned continuity evidence into a regulatory obligation.
- The business impact analysis is where most implementations succeed or fail.
- Scope statements matter more than the certificate itself.
What ISO 22301 actually is
ISO 22301 sets the requirements for a business continuity management system, or BCMS. The current edition is ISO 22301:2019, published under the title Security and Resilience, Business Continuity Management Systems, Requirements. It replaced the 2012 version, which itself grew out of the British standard BS 25999.
One distinction trips people up constantly. ISO 22301 is the only standard in the business continuity family you can be audited and certified against. ISO 22313 and ISO/TS 22317 offer guidance on implementation and on business impact analysis specifically, but no certification body issues a certificate for them. If a vendor tells you they are “aligned with ISO 22313,” they have told you nothing verifiable.
The standard uses Annex SL, the shared high-level structure behind ISO 9001 and ISO 27001. That is a practical benefit rather than a bureaucratic one. If you already run a certified information security management system, the governance scaffolding, document control, internal audit programme, management review, and corrective action process carry over. Many organizations run all three under one integrated system with a single audit calendar.
In February 2024, ISO published an amendment, ISO 22301:2019/Amd 1:2024, adding climate change to the external issues an organization must consider when establishing context. A small textual change with real consequences for anyone whose facilities sit in a flood plain or a region with a strained power grid.
A fuller revision is coming. ISO/TC 292 has approved a project to develop the next edition, though there is no confirmed publication date and the 2019 edition remains the certifiable version. Nothing about that pending work is a reason to delay.
Why the pandemic-era case for certification aged badly
Around 2020 and 2021, almost every article on this subject made the same argument. A pandemic disrupted business, therefore certify. The reasoning was sound and the evidence was thin, usually a survey figure from a certification body about how certified companies feel about their own risk management.
The 2026 case is more concrete and less comfortable. Disruption has moved from rare and dramatic to frequent and expensive. Uptime Institute’s 2026 outage analysis found that 57% of operators said their most recent major outage cost more than $100,000, and for the second year running, one in five put the figure above $1 million (Source: Uptime Institute). Per-site outage frequency has been falling for five years. Cost per incident keeps climbing, because the incidents that still happen sit deeper in shared infrastructure.
That is the pattern worth planning against. Fewer failures, each one harder to contain, with dependencies that reach outside your own disaster recovery infrastructure and into a cloud region, a fibre route, or a single upstream provider your whole sector happens to share.
A continuity programme built for a building fire will not help you here. One built around dependency mapping will.
The clauses that carry the weight
The standard runs to ten clauses. Three of them decide whether your implementation is real or decorative.
Business impact analysis
Clause 8 requires a business impact analysis, and this is where most programmes quietly fail. The BIA asks you to identify your critical activities, map what each one depends on, and quantify how impact grows over time.
Out of it come the numbers everything else hangs on:
- MTPD, the maximum tolerable period of disruption before the damage becomes unacceptable
- RTO, the recovery time objective, how fast the activity must be back
- RPO, the recovery point objective, how much data loss you can absorb
The common failure is setting these numbers in a workshop rather than deriving them from evidence. An RTO of four hours that no one has costed, resourced, or tested is a wish. Auditors notice.
Risk assessment and continuity strategy
Once you know what must survive and how quickly, you choose how. Redundancy, alternate sites, manual workarounds, standby contracts, or accepting the risk with documented justification. The standard does not dictate the solution. It requires that the solution match the objective and that you can show the reasoning.
This is where continuity planning meets cyber risk management directly. If ransomware is your most likely disruption scenario, your continuity strategy has to survive an attacker who reached your backups too.
Exercising and testing
Clause 8.5 requires you to exercise your plans. Not review them. Exercise them.
Tabletop walkthroughs count, and they are the cheapest way to find that three people believe they hold the same authority. Full failover tests count for more. Either way, the requirement is documented results, including what failed, and evidence that the failures were fixed. A plan tested once at certification and never again will not survive the first surveillance audit.
Regulation stopped treating continuity as optional
For a decade, business continuity certification was a commercial differentiator. In the EU, it has become adjacent to a legal requirement.
The Digital Operational Resilience Act has applied since 17 January 2025, covering roughly 22,000 EU financial entities plus the ICT providers serving them. DORA requires documented ICT risk management, tested recovery procedures, third-party oversight, and tight incident reporting, with initial notification of major incidents due within hours rather than days. Its second annual Register of Information cycle closed in March 2026, and supervisors in several member states have signalled that register deficiencies are an enforcement priority.
NIS2 works differently and reaches wider. It covers essential and important entities across eighteen sectors, pushes security obligations down through supply chains, and carries penalties up to €10 million or 2% of global turnover, with personal liability for management bodies. National transposition laws are now in force across most EU jurisdictions.
Neither regulation names ISO 22301. That matters less than it sounds. Both demand exactly what a certified BCMS produces: documented critical functions, tested recovery, evidence of management oversight. If you already hold the certificate, you are not compliant by default, but you have most of the artefacts an examiner will ask for. If you supply EU financial entities or covered infrastructure operators, expect the questionnaire regardless of where you are based.
How the certification process works
Certification follows a predictable path, and the timeline is usually driven by your readiness rather than the auditor’s.
You build the management system first: scope, policy, BIA, risk assessment, continuity strategies and plans, an internal audit programme, and at least one management review. Most certification bodies expect the system to have been operating for around three months before they will audit it, with a full internal audit cycle completed.
The audit itself runs in two stages. Stage 1 is a documentation and readiness review, checking that the system exists and that you understand your own scope. Stage 2 is the substantive audit, testing whether people actually follow the process and whether your evidence holds up. Findings are raised, you close them, and a certification decision follows.
Certificates run for three years, maintained through annual surveillance audits and a full recertification audit at the end of the cycle. Costs are not publicly standardized and vary considerably with headcount, number of sites, and scope complexity, so treat any quoted figure as specific to that provider.
One practical note. The internal audit requirement is not a formality you can satisfy with a colleague signing a template. It is one of the more useful parts of the standard, because it is the only mechanism that finds problems before an external auditor or a real incident does.
What certification buys you, and what it does not
Certification opens doors. Public procurement processes across the EU and elsewhere award scoring weight for accredited management system certificates. Enterprise vendor security reviews move faster when the answer to the continuity section is a certificate plus a scope statement. Insurers and lenders read it as evidence of governance maturity. And the implementation work itself usually surfaces dependencies nobody had documented.
What it does not buy is uptime. A certificate confirms that a management system exists and functions, not that your systems will stay up. Certified organizations have outages. The standard’s claim is narrower and more honest: you will have decided in advance what matters, and you will have practised the response.
Two failure modes are worth watching for.
The first is the narrow scope statement. A certificate covering one product line in one facility can be presented as though it covers the company. Read the scope on any certificate a supplier shows you, including your own.
The second is documentation drift. Plans written for the audit, filed, and left to decay while the architecture underneath them changes. If your disaster recovery planning documents still reference a data centre you exited last year, the certificate is measuring paperwork.
Where to start without committing to certification
You do not need an auditor to get most of the value.
Pick your three most critical business activities. For each one, write down what it depends on, including the external providers, and how long it can be unavailable before the consequences become serious. Then ask a harder question: where exactly does the redundancy sit? If your secondary systems share a power feed, a fibre route, or a cloud region with the primary, the redundancy is on paper only.
Run a two-hour tabletop against a realistic scenario, ideally one involving a provider you cannot control. Write down what broke.
That exercise costs almost nothing and tells you whether certification would formalize something you already do or force you to build it from scratch. Both answers are useful. Only one of them means you are ready to book an auditor.
Conclusion
ISO 22301 certification is a governance instrument, not an insurance policy. It gives you a repeatable way to decide what your organization cannot afford to lose, how quickly it must come back, and who makes the call under pressure. The certificate signals that an independent auditor checked the work. The value sits in the work.
If you operate in a regulated sector, the calculation has already been made for you, and the question is whether you build the evidence now or under supervisory deadline. If you do not, treat the standard as a structure to borrow from rather than a badge to buy. Start with the business impact analysis on your three most critical activities. Whatever that exercise turns up will tell you more about your resilience than any certificate on the wall.
Read Next
More on continuity, infrastructure, and resilience from Coruzant:
- The Contact Center Crossroads: The On-Premise vs Cloud Showdown
- Guide to Portable Cloud Integration with Local Software Systems
- vRealize Infrastructure Navigator for Virtual Management










