Skip to content

ISO 22301 · Business continuity

ISO 22301 Certification

Home

ISO 22301

The operation of an organisation may be compromised by a number of unexpected events. IT failure, cyber attack, power outage, fire, natural disaster, supplier problem or even a pandemic could cause a disruption that could result in significant financial losses, customer losses or legal consequences.

Process

Process

01

22301

International ISO 22301 helps organisations to prepare for these situations, minimise operating losses and restore their business processes as soon as possible. ISO 22301 certification demonstrates to its partners, clients and authorities that your organisation is able to handle unexpected events and has a well-functioning business continuity management system (BCMS).

What is ISO 22301?

ISO 22301:2019 is the world's leading standard for business continuity management (BCMS).

The purpose of the standard is to make the organisation

identify events that may endanger its functioning

assess their business impact

prepare for emergency situations

ensure the continuous functioning of critical business processes

quickly restore your services after an incident

regularly test and develop business continuity plans.

ISO 22301 applies not only to IT systems but also to the full functioning of the organisation, including human resources, infrastructure, suppliers, communication and customer service.

What is business continuity?

Business continuity means that an organisation can maintain or quickly restore its most important operational processes even in the event of exceptional events.

Such an event may include:

cyber attack (e.g. ransomware)

server shutdown

Internet or power outage

data loss

fire

flood or other natural disaster

loss of supplier

loss of key staff

pandemic

terrorist or other security incidents.

These events cannot always be prepared, but due planning can significantly reduce operating losses and financial losses.

ISO 22301 provides precisely this preparation.

Who It Is For

Who is recommended for ISO 22301 certification?

ISO 22301 may be useful for virtually any organisation, but it is particularly recommended for those where the cessation of a service or production process may have significant business or social consequences.

In particular recommended:

IT providers

cloud service providers

Data centres

Financial institutions

insurance organisations

logistic enterprises

for production companies

healthcare providers

For pharmaceutical companies

for energy companies

For telecommunications service providers

public service providers

State and municipal organisations

companies operating critical infrastructure.

ISO 22301 is increasingly appearing in applications and in wholesale supplier requirements.

Why is business continuity important?

A lot of businesses think that a major incident can't happen to them. However, experience shows that unexpected events will eventually affect all organisations.

The question is not whether an extraordinary event occurs, but how prepared the organisation is to deal with it.

Using a properly functioning BCMS:

reduce the time of business losses

Minimum financial losses

to preserve client confidence

the contractual obligations may be fulfilled

The normal operation can be restored faster.

Benefits

Benefits of ISO 22301 certification

The organisation can respond to exceptional events on the basis of predefined procedures.

Critical processes can be restored more quickly, so the operating failure will be less.

Customers can be sure that the organisation can provide its services in unexpected situations.

Many large companies and public procurement favour suppliers certified under ISO 22301.

The organisation understands better the risks of its operation and their business effects.

In many industries there is an increasingly important requirement for documented management of business continuity.

ISO 22301 is not just a certificate, it is a management system that increases the flexibility and adaptability of the organisation in the long term.

The organisation can respond to exceptional events on the basis of predefined procedures.

Critical processes can be restored more quickly, so the operating failure will be less.

Customers can be sure that the organisation can provide its services in unexpected situations.

Many large companies and public procurement favour suppliers certified under ISO 22301.

The organisation understands better the risks of its operation and their business effects.

In many industries there is an increasingly important requirement for documented management of business continuity.

ISO 22301 is not just a certificate, it is a management system that increases the flexibility and adaptability of the organisation in the long term.

Better preparedness for crisis situations

The organisation can respond to exceptional events on the basis of predefined procedures.

Shorter stop time

Critical processes can be restored more quickly, so the operating failure will be less.

Greater customer confidence

Customers can be sure that the organisation can provide its services in unexpected situations.

Competition advantage

Many large companies and public procurement favour suppliers certified under ISO 22301.

More effective risk management

The organisation understands better the risks of its operation and their business effects.

Support for legal and contractual compliance

In many industries there is an increasingly important requirement for documented management of business continuity.

More organisational resilience

ISO 22301 is not just a certificate, it is a management system that increases the flexibility and adaptability of the organisation in the long term.

Are you interested in a detailed offer?

Are you interested in a detailed offer?

Request a Quote →

Key requirements of ISO 22301

ISO 22301 does not just require the creation of a business continuity plan (BCP). The standard requires a full management system to ensure that the organisation prepares for unexpected events, periodically review risks, test its plans and continuously improve its operation.

The following elements form the basis for an effective business continuity management system.

Business Impact Analysis (BIA)

Business Impact Analysis is one of the most important elements of ISO 22301.

The purpose of the BIA is to determine:

which processes are critical to the functioning of the organisation

the financial, operational or legal consequences of the loss of a particular process

how long can a service or process be stopped

What resources are needed to restore operation.

Based on the results of the BIA, the organisation shall determine which processes take precedence over an exceptional event.

Risk assessment

Business continuity is closely linked to risk management.

The organisation shall regularly assess the risks which may jeopardise its functioning.

Such risks may include:

IT system failures

cyber attacks

power outage

loss of Internet connection

supplier problems

loss of key staff

natural disasters

fire

epidemics

physical security incidents.

Based on the risk assessment, the necessary preventive and recovery measures may be established.

Business continuity strategy

Once the organisation has assessed critical processes and risks, it must develop a strategy to ensure that operations are maintained.

This may include, for example:

Use of spare servers

cloud infrastructure

regular data savings

alternative workplaces

Replacement order

Application of several suppliers

alternative communication channels.

The aim is to enable the organisation to maintain its most important services even if an unexpected event occurs.

Business Continuity Plan (BCP)

The Business Continuity Plan (BCP) shall specify in detail how to proceed in the event of an incident.

The plan usually includes:

responsibilities

how to notify incidents

decision-making processes

communication system

information to customers

steps in IT recovery

order of reopening critical processes

the process of returning to normal operation.

The plan should be simple, clear and enforceable in practice.

Practices and tests

A business continuity plan is only worth something if it works.

Therefore, ISO 22301 requires the organisation to regularly test and exercise its plans.

For example, testing may take place:

in the form of table practice

by simulation

with an IT reset test

with a communication test

full business continuity practice.

The experience gained during the exercises shall be documented and, if necessary, the plans adjusted.

Incidence management and crisis communication

In an unexpected event, rapid and organised response is crucial.

ISO 22301 therefore pays particular attention to:

to detect incidents

on the escalation of events

to inform the management

to inform staff

on communication with customers

relations with authorities

media management.

In many cases, appropriate communication is as important as technical recovery itself.

Documentation

ISO 22301 requires the organisation to maintain and keep up to date appropriate documented information.

These may include, for example:

business continuity policy

objectives

Business Impact Analysis

Risk assessment

Business continuity strategy

Business Continuity Plan

incident management procedures

Test reports

training documentation

management audits

internal audits.

Contact of ISO 22301 with other management systems

ISO 22301 is constructed according to Harmonized Structure (HS) and can therefore be incorporated with other ISO standards.

ISO/IEC 27001

ISO/IEC 27001 focuses on information security, while ISO 22301 ensures that, after a security incident, the organisation can quickly restore its operation.

The two standards together are particularly recommended for IT service providers, data centres and cloud providers.

ISO/IEC 27701

In the management of data protection incidents, ISO/IEC 27701 and ISO 22301 complement each other well.

In a data protection event, it is important not only to protect data, but also to restore business processes as soon as possible.

ISO 9001

ISO 9001 aims to improve customer satisfaction and processes.

ISO 22301 adds this by ensuring continuity of services in exceptional situations.

ISO/IEC 20000-1

IT service management and business continuity are closely linked.

A well-functioning IT service management system contributes significantly to the rapid recovery of critical IT services in the event of an incident.

Process

ISO 22301 certification process

01

01

How much for ISO 22301 certification?

In each case, the cost of certification shall be determined on the basis of a specific offer.

The price is mainly influenced by the following factors:

the place of certification.

Why choose Clearlake Consulting Kft?

Benefits

Benefits

internationally recognized accredited certificate

more than 10 years of audit experience

Hungarian-language contact person

fast quotation

competitive prices

Flexible appointment

on-site and remote audit options

Are you interested in a detailed offer?

Request a Quote →
Process

support throughout the whole certification process

01

Are you interested in a detailed offer?

FAQ

Frequently Asked Questions

The certificate shall be valid for three years. During this period, an annual surveillance audit shall be required and a recertification audit shall be carried out at the end of the third year.

Yes. ISO 22301 requires the organisation to have documented business continuity plans to restore critical processes.

FAQ

FAQ

No. It can also be useful for small and medium-sized enterprises, especially when providing IT services, critical suppliers or their clients expect high availability.

Yes. Part of the audit or, where the accreditation rules allow it, the whole audit may be conducted online.

Yes. ISO 22301 can be specially integrated, inter alia, with the following standards:

Integrated audit may reduce audit time and certification costs.

Depending on the organisation's preparedness, the certification process may be completed within a few weeks.

Who It Is For

What organisations does ISO 22301 really benefit from?

ISO 22301 is particularly useful:

and any organisation where the continuity of the service is commercially critical.

Request a quote for ISO 22301 certification.

Would you like to prepare your organisation for the treatment of unexpected events and prove to your clients, partners or customers that your business is able to ensure continuity of your services?

Clearlake Consulting Kft. will help you find your best accredited certification partner and accompany you through the entire certification process. Whether it is a first certification, a change of certificate or an integrated audit, our expert team provides fast, flexible and professional support. Contact us today, ask for a personalised offer and obtain the ISO 22301 certificate, which increases your organisation's resilience, strengthens your clients' confidence and gives you a competitive advantage on the market!

Contact

Request a Quote

Get in touch with us and request an individual, no-obligation quote.

Telephone
+36 30 5036549

Request a Detailed Quote

Fill in our detailed quote request form — we prepare an individual offer based on your company data, the standards you select and a few questions about your processes.

Continue to tender →

No obligation · Our reply within 1 working day