ISO 22301 – Business continuity
ISO 22301 describes how a company stays able to operate when something fails. That does not just mean IT. It also means the fire in the production hall, the loss of the only supplier, the flu going round the team or the blocked access road to the plant.
The standard does not ask for catalogues of possible disasters. It asks about the processes you genuinely cannot do without. Then it asks how quickly those have to be running again. That sounds simple. In practice this is exactly where most systems become sloppy.
Who it applies to
- Companies whose customers want dependable delivery capability written into the contract
- Businesses with critical dependencies: one site, one supplier, one person, one machine
- Organisations within the scope of the NIS 2 rules that have to show they can keep operating – see NIS 2 consulting
- Service providers expected to commit to recovery times for their clients
Where it usually goes wrong
The impact analysis is estimated instead of gathered
The business impact analysis is produced at a desk. Somebody fills in a table because the standard calls for one. Nobody talks to the operating departments while doing it. The result reads as complete and is guesswork all the same.
That shows up quickly in the audit. The analysis says a process may be down for two days. Ask in the accounts department and the answer is: after four hours nothing works here any more. Discrepancies like this shift the entire plan. Target times, resources and costs all follow from them. Ten honestly surveyed processes are worth more than sixty estimated ones.
Recovery times with no reality check
Target times are readily set at ambitious levels. Four hours to recovery sounds good, particularly to customers. Only the technology in place rarely delivers it. Restoring the backup alone takes longer than that. Spare parts have lead times. And the one person who knows the process goes on holiday too.
In a real incident a plan like that is worthless. It assumes conditions that do not exist in the business. So we test every target time against two questions: what can the technology do today? Who is available to do it? An honest target time of 24 hours carries further than an attractive one of four.
Plans are never exercised
The contingency plans are complete, structured and approved. It is just that nobody has ever run through whether they work. That is precisely what the standard requires. It is the point that is missing most often.
Exercises rarely uncover anything dramatic. They uncover the mundane, and in a real incident that costs just as much. Phone lists are out of date. Only one person has the access. The password is in the safe, and the safe is locked. You find these things in a two-hour tabletop exercise. Without an exercise you find them on the worst possible day.
Relationship to NIS 2 and information security
Staying able to operate through a failure is not purely a continuity topic. It is also a requirement in the NIS 2 environment. Anyone who has to provide evidence there will not get past recovery, crisis communication and emergency organisation in any case.
In the same way, ISO 22301 overlaps with ISO/IEC 27001. The information security standard requires availability as a protection objective and deals with continuity in controls of its own. Both standards draw on the same analyses and the same plans.
Our advice: if you are tackling both, plan them together. One shared impact analysis, one set of plans, one exercise calendar. Built separately, you end up with two systems that contradict each other. More under NIS 2 consulting.
How we support you
We start with the operating departments, not with the standard. In conversation we establish which processes are genuinely critical and at what point it starts to hurt. Out of that comes an impact analysis based on statements rather than assumptions.
We then reconcile the target times with the technology and the staffing you actually have. Only then do strategies and plans take shape. More under Building a management system.
Finally we run an exercise with you and examine the system in the internal audit. Those belong together, see Internal audits & gap analyses.
Who handles this at our end
Marion Rammé – IRCA certified and registered QMS / EMS / OHSMS Lead Auditor #01194927, with ISO 22301 in her competence profile
To be honest: this standard is covered by one person here. For ISO 9001 or ISO 45001 we are more broadly staffed. If you need continuous cover, we will tell you beforehand. The team in detail
Related standards
- ISO/IEC 27001 – information security, with a large overlap in content
- ISO 31000 – risk management, provides the methodological basis
- ISO 9001 – quality management, same underlying structure and often already in place
Frequently asked questions
How long does it take to reach certification?
Reckon on six to twelve months. The effort lies less in the writing than in the gathering. The impact analysis needs conversations in every area, and those cost appointments. If you already run a management system, you are usually finished sooner.
What does it cost?
Projects of this kind typically run between 10,000 and 50,000 euros. The deciding factors are company size, the number of sites and the number of critical processes. The certification body's fees come on top.
We already have an IT contingency plan. Is that not enough?
No, it covers only part of it. ISO 22301 asks about the whole business. That includes staff, buildings, suppliers, machinery and communication. An IT contingency plan is a good component within that, but only one.
How often do plans have to be exercised?
The standard gives no fixed number. What works well is an exercise calendar with at least one exercise a year for each critical process. Much of it can be done as a tabletop exercise. That costs two hours and almost always produces findings.
Is it worth it for a small business?
Building the system is almost always worth it, the certificate not necessarily. Small businesses often have the hardest dependencies, because everything hangs on a few people. Whether you need a certificate depends solely on your customers. We will tell you honestly in the initial conversation.
Let us talk about it
The first conversation is free and without obligation.