ISO 22301
The operation of an organisation may be compromised by a number of unexpected events. IT failure, cyber attack, power outage, fire, natural disaster, supplier problem or even a pandemic could cause a disruption that could result in significant financial losses, customer losses or legal consequences.
Process
22301
International ISO 22301 helps organisations to prepare for these situations, minimise operating losses and restore their business processes as soon as possible. ISO 22301 certification demonstrates to its partners, clients and authorities that your organisation is able to handle unexpected events and has a well-functioning business continuity management system (BCMS).
What is ISO 22301?
ISO 22301:2019 is the world's leading standard for business continuity management (BCMS).
The purpose of the standard is to make the organisation
identify events that may endanger its functioning
assess their business impact
prepare for emergency situations
ensure the continuous functioning of critical business processes
quickly restore your services after an incident
regularly test and develop business continuity plans.
ISO 22301 applies not only to IT systems but also to the full functioning of the organisation, including human resources, infrastructure, suppliers, communication and customer service.
What is business continuity?
Business continuity means that an organisation can maintain or quickly restore its most important operational processes even in the event of exceptional events.
Such an event may include:
cyber attack (e.g. ransomware)
server shutdown
Internet or power outage
data loss
fire
flood or other natural disaster
loss of supplier
loss of key staff
pandemic
terrorist or other security incidents.
These events cannot always be prepared, but due planning can significantly reduce operating losses and financial losses.
ISO 22301 provides precisely this preparation.
Who is recommended for ISO 22301 certification?
ISO 22301 may be useful for virtually any organisation, but it is particularly recommended for those where the cessation of a service or production process may have significant business or social consequences.
In particular recommended:
IT providers
cloud service providers
Data centres
Financial institutions
insurance organisations
logistic enterprises
for production companies
healthcare providers
For pharmaceutical companies
for energy companies
For telecommunications service providers
public service providers
State and municipal organisations
companies operating critical infrastructure.
ISO 22301 is increasingly appearing in applications and in wholesale supplier requirements.
Why is business continuity important?
A lot of businesses think that a major incident can't happen to them. However, experience shows that unexpected events will eventually affect all organisations.
The question is not whether an extraordinary event occurs, but how prepared the organisation is to deal with it.
Using a properly functioning BCMS:
reduce the time of business losses
Minimum financial losses
to preserve client confidence
the contractual obligations may be fulfilled
The normal operation can be restored faster.
Benefits of ISO 22301 certification
The organisation can respond to exceptional events on the basis of predefined procedures.
Critical processes can be restored more quickly, so the operating failure will be less.
Customers can be sure that the organisation can provide its services in unexpected situations.
Many large companies and public procurement favour suppliers certified under ISO 22301.
The organisation understands better the risks of its operation and their business effects.
In many industries there is an increasingly important requirement for documented management of business continuity.
ISO 22301 is not just a certificate, it is a management system that increases the flexibility and adaptability of the organisation in the long term.
The organisation can respond to exceptional events on the basis of predefined procedures.
Critical processes can be restored more quickly, so the operating failure will be less.
Customers can be sure that the organisation can provide its services in unexpected situations.
Many large companies and public procurement favour suppliers certified under ISO 22301.
The organisation understands better the risks of its operation and their business effects.
In many industries there is an increasingly important requirement for documented management of business continuity.
ISO 22301 is not just a certificate, it is a management system that increases the flexibility and adaptability of the organisation in the long term.
Better preparedness for crisis situations
The organisation can respond to exceptional events on the basis of predefined procedures.
Shorter stop time
Critical processes can be restored more quickly, so the operating failure will be less.
Greater customer confidence
Customers can be sure that the organisation can provide its services in unexpected situations.
Competition advantage
Many large companies and public procurement favour suppliers certified under ISO 22301.
More effective risk management
The organisation understands better the risks of its operation and their business effects.
Support for legal and contractual compliance
In many industries there is an increasingly important requirement for documented management of business continuity.
More organisational resilience
ISO 22301 is not just a certificate, it is a management system that increases the flexibility and adaptability of the organisation in the long term.
Are you interested in a detailed offer?
Are you interested in a detailed offer?
Request a Quote →Key requirements of ISO 22301
ISO 22301 does not just require the creation of a business continuity plan (BCP). The standard requires a full management system to ensure that the organisation prepares for unexpected events, periodically review risks, test its plans and continuously improve its operation.
The following elements form the basis for an effective business continuity management system.
Business Impact Analysis (BIA)
Business Impact Analysis is one of the most important elements of ISO 22301.
The purpose of the BIA is to determine:
which processes are critical to the functioning of the organisation
the financial, operational or legal consequences of the loss of a particular process
how long can a service or process be stopped
What resources are needed to restore operation.
Based on the results of the BIA, the organisation shall determine which processes take precedence over an exceptional event.
Risk assessment
Business continuity is closely linked to risk management.
The organisation shall regularly assess the risks which may jeopardise its functioning.
Such risks may include:
IT system failures
cyber attacks
power outage
loss of Internet connection
supplier problems
loss of key staff
natural disasters
fire
epidemics
physical security incidents.
Based on the risk assessment, the necessary preventive and recovery measures may be established.
Business continuity strategy
Once the organisation has assessed critical processes and risks, it must develop a strategy to ensure that operations are maintained.
This may include, for example:
Use of spare servers
cloud infrastructure
regular data savings
alternative workplaces
Replacement order
Application of several suppliers
alternative communication channels.
The aim is to enable the organisation to maintain its most important services even if an unexpected event occurs.
Business Continuity Plan (BCP)
The Business Continuity Plan (BCP) shall specify in detail how to proceed in the event of an incident.
The plan usually includes:
responsibilities
how to notify incidents
decision-making processes
communication system
information to customers
steps in IT recovery
order of reopening critical processes
the process of returning to normal operation.
The plan should be simple, clear and enforceable in practice.
Practices and tests
A business continuity plan is only worth something if it works.
Therefore, ISO 22301 requires the organisation to regularly test and exercise its plans.
For example, testing may take place:
in the form of table practice
by simulation
with an IT reset test
with a communication test
full business continuity practice.
The experience gained during the exercises shall be documented and, if necessary, the plans adjusted.
Incidence management and crisis communication
In an unexpected event, rapid and organised response is crucial.
ISO 22301 therefore pays particular attention to:
to detect incidents
on the escalation of events
to inform the management
to inform staff
on communication with customers
relations with authorities
media management.
In many cases, appropriate communication is as important as technical recovery itself.
Documentation
ISO 22301 requires the organisation to maintain and keep up to date appropriate documented information.
These may include, for example:
business continuity policy
objectives
Business Impact Analysis
Risk assessment
Business continuity strategy
Business Continuity Plan
incident management procedures
Test reports
training documentation
management audits
internal audits.
Contact of ISO 22301 with other management systems
ISO 22301 is constructed according to Harmonized Structure (HS) and can therefore be incorporated with other ISO standards.
ISO/IEC 27001
ISO/IEC 27001 focuses on information security, while ISO 22301 ensures that, after a security incident, the organisation can quickly restore its operation.
The two standards together are particularly recommended for IT service providers, data centres and cloud providers.
ISO/IEC 27701
In the management of data protection incidents, ISO/IEC 27701 and ISO 22301 complement each other well.
In a data protection event, it is important not only to protect data, but also to restore business processes as soon as possible.
ISO 9001
ISO 9001 aims to improve customer satisfaction and processes.
ISO 22301 adds this by ensuring continuity of services in exceptional situations.
ISO/IEC 20000-1
IT service management and business continuity are closely linked.
A well-functioning IT service management system contributes significantly to the rapid recovery of critical IT services in the event of an incident.
ISO 22301 certification process
01
How much for ISO 22301 certification?
In each case, the cost of certification shall be determined on the basis of a specific offer.
The price is mainly influenced by the following factors:
the place of certification.
Why choose Clearlake Consulting Kft?
Benefits
internationally recognized accredited certificate
more than 10 years of audit experience
Hungarian-language contact person
fast quotation
competitive prices
Flexible appointment
on-site and remote audit options
Are you interested in a detailed offer?
Request a Quote →support throughout the whole certification process
Are you interested in a detailed offer?
Frequently Asked Questions
The certificate shall be valid for three years. During this period, an annual surveillance audit shall be required and a recertification audit shall be carried out at the end of the third year.
Yes. ISO 22301 requires the organisation to have documented business continuity plans to restore critical processes.
FAQ
No. It can also be useful for small and medium-sized enterprises, especially when providing IT services, critical suppliers or their clients expect high availability.
Yes. Part of the audit or, where the accreditation rules allow it, the whole audit may be conducted online.
Yes. ISO 22301 can be specially integrated, inter alia, with the following standards:
Integrated audit may reduce audit time and certification costs.
Depending on the organisation's preparedness, the certification process may be completed within a few weeks.
What organisations does ISO 22301 really benefit from?
ISO 22301 is particularly useful:
and any organisation where the continuity of the service is commercially critical.
Request a quote for ISO 22301 certification.
Would you like to prepare your organisation for the treatment of unexpected events and prove to your clients, partners or customers that your business is able to ensure continuity of your services?
Clearlake Consulting Kft. will help you find your best accredited certification partner and accompany you through the entire certification process. Whether it is a first certification, a change of certificate or an integrated audit, our expert team provides fast, flexible and professional support. Contact us today, ask for a personalised offer and obtain the ISO 22301 certificate, which increases your organisation's resilience, strengthens your clients' confidence and gives you a competitive advantage on the market!
Request a Quote
Get in touch with us and request an individual, no-obligation quote.
Request a Detailed Quote
Fill in our detailed quote request form — we prepare an individual offer based on your company data, the standards you select and a few questions about your processes.
Continue to tender →No obligation · Our reply within 1 working day