
Why ISO 22301 matters
Customers, regulators and insurers increasingly ask one question: *if something goes wrong, how quickly can you recover?* ISO 22301:2019 is the international standard for Business Continuity Management Systems (BCMS). It gives you a structured, auditable way to prove your organisation can keep delivering through disruption — whether that is a cyber incident, a supplier failure, a natural disaster or a key-person dependency.
Unlike an ad-hoc disaster recovery document, a BCMS is a management system: it has policy, objectives, defined roles, measured performance and continual improvement built in. That is what makes it certifiable — and what makes the certificate meaningful to your customers.
The 13-step implementation roadmap
Phase 1 — Direction and analysis (Steps 1–5)
- Obtain top management commitment. Without an accountable executive sponsor, allocated budget and an approved BCMS policy, the programme stalls at the first competing priority. Assign roles and responsibilities formally.
- Define BCMS scope, interested parties and business context. Which locations, departments, products and services are in scope? What do regulators, customers and contracts require of you? Document internal and external issues that affect continuity.
- Conduct the Business Impact Analysis (BIA). Identify your critical processes, their dependencies and resources, and assess the financial, operational and regulatory impact of disruption over time. The BIA determines your business priorities — everything downstream depends on it being honest.
- Perform a business continuity risk assessment. Identify potential threats and vulnerabilities, assess likelihood and impact, and determine the risk level for each disruption scenario.
- Define recovery objectives. For every critical process set the RTO (Recovery Time Objective), RPO (Recovery Point Objective), MTPD (Maximum Tolerable Period of Disruption) and WRT (Work Recovery Time). These numbers drive every strategy and investment decision that follows.
Phase 2 — Build the capability (Steps 6–9)
- Develop business continuity strategies. Evaluate options — alternate sites, cloud redundancy, manual workarounds, supplier diversification — and select cost-effective strategies that actually meet the recovery objectives from Step 5.
- Develop BCMS documentation. Create the policies, procedures, plans and templates, aligned clause-by-clause with ISO 22301 requirements.
- Implement the plans. Business continuity plans, disaster recovery plans, the crisis management plan and the communication plan with contact lists. A plan that exists only as a document is a finding waiting to happen.
- Training and awareness. Train employees on their roles, responsibilities and the plans themselves. The goal is a culture of resilience, not a binder on a shelf.
Phase 3 — Prove and improve (Steps 10–13)
- Exercise and testing. Run mock drills and tabletop exercises, test the plans against realistic scenarios, and update them based on lessons learned. Auditors will ask for exercise records and the changes that resulted.
- Internal audit. Verify compliance with ISO 22301 across the whole BCMS, conducted by auditors independent of the areas audited. Identify gaps and improvement areas before the certification body does.
- Management review. Leadership reviews BCMS performance and effectiveness, and confirms the system remains suitable, adequate and aligned with the business.
- Corrective actions and continual improvement. Address nonconformities and gaps, then keep improving the BCMS continuously — certification is the start of the cycle, not the end.
How long does it take?
For a small or mid-sized organisation with executive support, expect 4 to 9 months from kickoff to certification audit. The most common delay is not documentation — it is waiting on recovery-strategy decisions (Step 6) that require budget, and on exercising (Step 10), which organisations postpone because operations are busy. Book the certification body early; their lead times are often four to eight weeks.
How IcyberWave can help
We support organisations from gap assessment to certification: BIA facilitation, recovery strategy design, plan development, exercising, internal audit and Stage 1/Stage 2 preparation. If you are starting from zero, our [ISO 27001 audit checklist](/blog/iso-27001-audit-checklist) shows the audit-evidence mindset that applies equally to a BCMS — and our [ITGC guide](/blog/itgc-controls-comprehensive-guide-it-auditors) covers the IT controls your recovery capability depends on. [Talk to us](/contact) about scoping your ISO 22301 programme.
