{"id":7411,"date":"2020-03-10T12:26:07","date_gmt":"2020-03-10T11:26:07","guid":{"rendered":"https:\/\/brandcompliance.com\/iso-22301-2\/"},"modified":"2026-07-21T15:33:40","modified_gmt":"2026-07-21T13:33:40","slug":"iso-22301","status":"publish","type":"page","link":"https:\/\/brandcompliance.com\/en\/services\/iso-22301\/","title":{"rendered":"ISO 22301 certification"},"content":{"rendered":"<p>Disruptive incidents can affect your organization\u2019s employees, locations, IT systems, suppliers and ability to deliver products and services. An effective business continuity management system provides a structured approach for preparing for, responding to and recovering from these disruptions.<\/p>\n<p><img decoding=\"async\" class=\"alignright size-medium\" src=\"http:\/\/brandcompliance.com\/wp-content\/uploads\/2023\/03\/AdobeStock_484083612-300x169.jpeg\" alt=\"ISO 22301 business continuity management system\" width=\"300\" height=\"169\" \/><\/p>\n<p>ISO 22301 certification provides independent confirmation that your organization\u2019s business continuity management system meets the applicable requirements of the standard. Brand Compliance assesses whether the management system has been established, implemented, maintained and continually improved.<\/p>\n<p>Would you like to discuss the certification scope, audit process and expected audit time for your organization? <a href=\"https:\/\/brandcompliance.com\/en\/contact\/meet-brand-compliance\/\">Schedule an introductory meeting<\/a>.<\/p>\n<h2>What is ISO 22301?<\/h2>\n<p>ISO 22301 is the internationally recognized requirements standard for business continuity management systems. A business continuity management system is also referred to as a BCMS.<\/p>\n<p>The standard provides a framework for identifying potential disruptions, determining their possible impact and establishing arrangements for responding to disruptive incidents. The objective is to enable the organization to continue delivering prioritized products and services at an acceptable predefined capacity during a disruption and to recover its activities in a controlled manner.<\/p>\n<p>ISO 22301 can be applied by organizations of any size and in any industry. How the requirements are applied depends on factors such as the organization\u2019s activities, operating environment, dependencies, interested parties and the complexity of its products and services.<\/p>\n<h2>ISO 22301 certification and accreditation<\/h2>\n<p>Brand Compliance provides ISO 22301 certification outside the scope of its accreditation by the Dutch Accreditation Council (RvA), registration C 548. ISO 22301 certificates issued by Brand Compliance therefore do not carry the RvA accreditation mark. Further information is available on our page about <a href=\"https:\/\/brandcompliance.com\/en\/certification-body\/accreditations\/\">accreditations and conditions<\/a>.<\/p>\n<h2>Benefits of ISO 22301 certification<\/h2>\n<p>ISO 22301 certification can provide several benefits to organizations that want to manage business continuity systematically:<\/p>\n<ul>\n<li><strong>Greater insight into critical activities:<\/strong> A business impact analysis provides insight into prioritized activities, required resources and dependencies.<\/li>\n<li><strong>Defined recovery priorities:<\/strong> The organization establishes timeframes and objectives for resuming prioritized activities following a disruption.<\/li>\n<li><strong>A structured response to disruptions:<\/strong> Documented plans and procedures clarify responsibilities, communication arrangements and the actions required during an incident.<\/li>\n<li><strong>Regularly evaluated continuity arrangements:<\/strong> Exercises and tests provide information about whether business continuity plans and procedures remain suitable and effective.<\/li>\n<li><strong>Attention to supply chain dependencies:<\/strong> The BCMS considers relevant dependencies on suppliers, service providers, utilities, technology and other external resources.<\/li>\n<li><strong>Greater stakeholder confidence:<\/strong> Certification demonstrates that the organization manages business continuity through a structured management system that has been independently assessed.<\/li>\n<li><strong>Alignment with contractual requirements:<\/strong> Certification may be relevant where customers, contracting authorities or other interested parties impose business continuity requirements.<\/li>\n<\/ul>\n<p>Certification cannot guarantee that disruptions will not occur or that every activity will continue without interruption. It provides independent confirmation that the organization has established and implemented a management system for managing business continuity.<\/p>\n<h2>ISO 22301 requirements<\/h2>\n<p>ISO 22301 requires an organization to establish, implement, maintain and continually improve a business continuity management system. The precise application of the requirements depends on the organization\u2019s context, risks, activities and continuity objectives.<\/p>\n<p>Important elements of a BCMS include:<\/p>\n<ul>\n<li>understanding the organization and its context;<\/li>\n<li>determining the needs and expectations of relevant interested parties;<\/li>\n<li>defining the scope of the business continuity management system;<\/li>\n<li>establishing a business continuity policy and measurable objectives;<\/li>\n<li>assigning responsibilities and authorities;<\/li>\n<li>addressing risks and opportunities relating to the BCMS;<\/li>\n<li>providing appropriate resources, competence and awareness;<\/li>\n<li>managing communication and documented information;<\/li>\n<li>conducting a business impact analysis and risk assessment;<\/li>\n<li>selecting business continuity strategies and solutions;<\/li>\n<li>establishing business continuity plans and procedures;<\/li>\n<li>conducting exercises and evaluating continuity arrangements;<\/li>\n<li>monitoring, measuring and evaluating the performance of the BCMS;<\/li>\n<li>conducting internal audits and management reviews;<\/li>\n<li>addressing nonconformities and continually improving the BCMS.<\/li>\n<\/ul>\n<h3>Business impact analysis and risk assessment<\/h3>\n<p>A business impact analysis identifies the organization\u2019s activities and evaluates the consequences of a disruption over time. It provides a basis for determining which activities should be prioritized, the resources and dependencies required for these activities and the timeframes within which they should be resumed.<\/p>\n<p>The organization must also assess the risks of disruptions to its prioritized activities. The business impact analysis and risk assessment have different purposes but are used together when determining appropriate business continuity strategies and solutions.<\/p>\n<h3>Business continuity strategies, plans and exercises<\/h3>\n<p>Based on the outcomes of the business impact analysis and risk assessment, the organization selects strategies and solutions for maintaining and recovering prioritized activities. These may relate to employees, locations, technology, information, equipment, suppliers, transport, utilities and financial resources.<\/p>\n<p>The organization must establish plans and procedures for responding to disruptions. These arrangements should describe matters such as roles, responsibilities, escalation, internal and external communication, warning and notification, incident response and the continuation or recovery of prioritized activities.<\/p>\n<p>Business continuity plans and procedures must be exercised and evaluated at planned intervals. The results provide input for corrections, improvements and changes to the BCMS.<\/p>\n<h2>ISO 22301 and NIS2<\/h2>\n<p>The NIS2 Directive requires relevant entities to take appropriate and proportionate technical, operational and organizational measures to manage cybersecurity risks. These measures include business continuity, such as backup management, disaster recovery and crisis management.<\/p>\n<p>A business continuity management system based on ISO 22301 can provide a structured approach to these continuity-related measures. It can help an organization identify critical activities, establish recovery priorities, manage dependencies and evaluate continuity arrangements.<\/p>\n<p>ISO 22301 certification does not demonstrate that an organization fully complies with NIS2. The NIS2 Directive also contains requirements relating to subjects such as risk analysis, incident handling, supply chain security, vulnerability handling, cybersecurity training, access control and incident reporting. Further information about these requirements is available in <a href=\"https:\/\/eur-lex.europa.eu\/eli\/dir\/2022\/2555\/oj\/eng\" rel=\"noopener\">Directive (EU) 2022\/2555<\/a>.<\/p>\n<p>ISO 22301 and ISO 27001 can complement each other. ISO 22301 focuses on the continuity of prioritized products and services, while <a href=\"https:\/\/brandcompliance.com\/en\/services\/iso-27001-certification\/\">ISO 27001 certification<\/a> focuses on managing information security risks and preserving the confidentiality, integrity and availability of information.<\/p>\n<h2>ISO 22301 certification process<\/h2>\n<p>Before applying for certification, your organization must have established and implemented a business continuity management system. Brand Compliance subsequently performs an independent certification audit.<\/p>\n<p>You can also read more about the general process from application and application review to the proposal, agreement and audit planning in our article about the <a href=\"https:\/\/brandcompliance.com\/en\/docs\/certification-process-step-by-step\/\">certification process step by step<\/a>.<\/p>\n<h3>Preparing for ISO 22301 certification<\/h3>\n<ol>\n<li><strong>Obtain the current ISO 22301 standard.<\/strong><br \/>\nPurchase an official copy of <a href=\"https:\/\/www.nen.nl\/en\/nen-en-iso-22301-2019-en-265249\" rel=\"noopener\">NEN-EN-ISO 22301:2019<\/a> from NEN or another national standards body. The applicable climate action amendment must also be considered.<\/li>\n<li><strong>Schedule an introductory meeting.<\/strong><br \/>\nDuring a <a href=\"https:\/\/brandcompliance.com\/en\/contact\/meet-brand-compliance\/\">non-binding introductory meeting<\/a>, the intended certification scope, audit process, expected audit time and relevant organizational characteristics can be discussed.<\/li>\n<li><strong>Establish and implement the BCMS.<\/strong><br \/>\nEstablish a business continuity management system that meets the applicable ISO 22301 requirements. The BCMS must be appropriate to the organization\u2019s context, activities, products, services and continuity needs.<\/li>\n<li><strong>Conduct the business impact analysis and risk assessment.<\/strong><br \/>\nIdentify prioritized activities, possible impacts, dependencies, required resources and risks of disruption. Use the results to determine appropriate business continuity strategies and solutions.<\/li>\n<li><strong>Establish and exercise business continuity plans.<\/strong><br \/>\nDocument the arrangements for responding to disruptions and continuing or recovering prioritized activities. Exercise and evaluate these arrangements at planned intervals.<\/li>\n<li><strong>Conduct internal audits.<\/strong><br \/>\nConduct internal audits to determine whether the BCMS conforms to the applicable requirements and has been effectively implemented and maintained. Read more about <a href=\"https:\/\/brandcompliance.com\/en\/docs\/internal-audit\/\">conducting an internal audit<\/a>.<\/li>\n<li><strong>Perform the management review.<\/strong><br \/>\nTop management must review the continuing suitability, adequacy and effectiveness of the BCMS. The management review provides a basis for decisions about changes, resources and improvement opportunities.<\/li>\n<\/ol>\n<h3>Stage 1 and Stage 2 certification audit<\/h3>\n<ol start=\"8\">\n<li><strong>Complete the Stage 1 certification audit.<\/strong><br \/>\nDuring Stage 1, the auditor assesses the documented information relating to the BCMS, the organization\u2019s understanding of the standard and its readiness for Stage 2. The auditor also evaluates whether important elements, such as the scope, business impact analysis, risk assessment, internal audits and management review, have been addressed.<\/li>\n<li><strong>Complete the Stage 2 certification audit.<\/strong><br \/>\nDuring Stage 2, the auditor assesses the implementation and effectiveness of the BCMS against the applicable ISO 22301 requirements. Audit evidence may be obtained through interviews, observations and the review of documents and records.<\/li>\n<\/ol>\n<p>If nonconformities are identified during the certification audit, the organization must address them within the applicable timeframe. A nonconformity means that a requirement from the standard or the organization\u2019s own management system has not been fulfilled.<\/p>\n<h3>Certification decision and ISO 22301 certificate<\/h3>\n<ol start=\"10\">\n<li><strong>Receive the certification decision.<\/strong><br \/>\nFollowing completion of the audit process and any required follow-up, the audit results are independently reviewed. If the certification decision is positive, Brand Compliance issues the ISO 22301 certificate.<\/li>\n<\/ol>\n<p>The certificate forms part of a three-year certification cycle. Surveillance audits are conducted during this cycle to assess whether the BCMS continues to meet the applicable requirements. A recertification audit is conducted before the end of the cycle. Read more about <a href=\"https:\/\/brandcompliance.com\/en\/docs\/certification-cycle\/\">the certification cycle<\/a>.<\/p>\n<h2>What does ISO 22301 certification cost?<\/h2>\n<p>The cost of establishing and implementing a business continuity management system is separate from the cost of certification. Implementation costs may include purchasing the standard, training employees, allocating internal capacity, conducting exercises and engaging an external consultant if the organization chooses to do so.<\/p>\n<p>The cost of ISO 22301 certification depends on factors such as:<\/p>\n<ul>\n<li>the intended certification scope;<\/li>\n<li>the effective number of personnel within the scope;<\/li>\n<li>the number and location of sites;<\/li>\n<li>the nature and complexity of the organization\u2019s activities;<\/li>\n<li>the criticality of products, services and activities;<\/li>\n<li>the number and complexity of relevant dependencies;<\/li>\n<li>the use of shift work;<\/li>\n<li>outsourced processes and external service providers;<\/li>\n<li>the applicable legal, regulatory and contractual context;<\/li>\n<li>the extent to which the BCMS is integrated with other management systems.<\/li>\n<\/ul>\n<p>Certification costs may include the application review, audit preparation, the Stage 1 and Stage 2 certification audits, reporting, the certification decision, certificate fees, administration and travel expenses.<\/p>\n<p>There is no standard duration for an ISO 22301 certification process. The total lead time depends on the organization\u2019s preparation, the availability of auditors, the size and complexity of the organization and any follow-up required after the audit. Read more about <a href=\"https:\/\/brandcompliance.com\/en\/docs\/how-long-iso-certification\/\">how long ISO certification takes<\/a>.<\/p>\n<p>Would you like an indication of the expected audit time and certification costs for your organization? <a href=\"https:\/\/brandcompliance.com\/en\/contact\/meet-brand-compliance\/\">Schedule an introductory meeting<\/a>.<\/p>\n<h2>Which version of ISO 22301 applies?<\/h2>\n<p>The current certifiable edition is ISO 22301:2019, Security and resilience, Business continuity management systems, Requirements. Organizations must also consider <a href=\"https:\/\/www.iso.org\/standard\/88412.html\" rel=\"noopener\">ISO 22301:2019\/Amd 1:2024<\/a>, which adds climate change considerations to the management system requirements.<\/p>\n<p>ISO is developing a third edition of ISO 22301. This new edition is currently still at the committee draft stage and cannot yet be used as the basis for certification. Until a new edition has been published and the applicable transition arrangements have been determined, organizations should continue to use ISO 22301:2019 and Amendment 1:2024.<\/p>\n<p>Further information about the current edition and the development status of the standard is available on the <a href=\"https:\/\/www.iso.org\/standard\/75106.html\" rel=\"noopener\">official ISO 22301 page<\/a>.<\/p>\n<h2>Start your ISO 22301 certification journey<\/h2>\n<p>Would you like to have your business continuity management system independently assessed against ISO 22301? During an introductory meeting, we discuss the intended certification scope, the audit process, the expected audit time and the information required for a proposal.<\/p>\n<p><a href=\"https:\/\/brandcompliance.com\/en\/contact\/meet-brand-compliance\/\"><strong>Schedule an introductory meeting<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Disruptive incidents can affect your organization\u2019s employees, locations, IT systems, suppliers and ability to deliver products and services. An effective business continuity management system provides&#8230;<\/p>\n","protected":false},"author":1,"featured_media":17427,"parent":16202,"menu_order":2,"comment_status":"closed","ping_status":"closed","template":"layouts\/diensten-layout.php","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-7411","page","type-page","status-publish","has-post-thumbnail","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/pages\/7411","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/comments?post=7411"}],"version-history":[{"count":6,"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/pages\/7411\/revisions"}],"predecessor-version":[{"id":26932,"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/pages\/7411\/revisions\/26932"}],"up":[{"embeddable":true,"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/pages\/16202"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/media\/17427"}],"wp:attachment":[{"href":"https:\/\/brandcompliance.com\/en\/wp-json\/wp\/v2\/media?parent=7411"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}