Photo: Unsplash
If you want to know how to get ISO 22301 certified, the practical path is to define a credible scope, close gaps, operate and test your business continuity management system (BCMS), complete internal assurance, and then pass Stage 1 and Stage 2 certification audits.
This guide covers:
- The complete ISO 22301 certification path, from gap analysis to certificate
- The owners, workflows, and evidence auditors commonly evaluate
- What happens during Stage 1 and Stage 2 audits
- How to maintain the BCMS through surveillance and continual improvement

GIF via GIPHY
Key takeaways
- Certification starts with a defensible scope. Scope drives the BIA, evidence population, audit duration, and claims you may make.
- Implementation means operation, not document production. Auditors commonly sample records showing that continuity processes work in practice.
- Exercises connect plans to reality. Timed technical recovery, decision-making, supplier response, and crisis communications reveal whether objectives are achievable.
- Stage 1 and Stage 2 have different purposes. Stage 1 evaluates readiness and documented system design; Stage 2 evaluates implementation and effectiveness.
- Certification requires ongoing maintenance. Surveillance audits, change management, new exercises, internal audits, management reviews, and corrective actions continue after certification.
ISO 22301 certification overview
ISO 22301 certification is an independent assessment of an organization’s BCMS against the standard. The resulting certificate applies to a defined scope; it does not mean that every part of a corporate group or every product is covered.
A typical journey follows this sequence:
- Define scope, sponsorship, and program governance
- Perform a gap analysis
- Implement required BCMS processes
- Operate the system and exercise continuity capabilities
- Complete internal audit and management review
- Select an accredited certification body
- Complete Stage 1 and address readiness findings
- Complete Stage 2 and address nonconformities
- Maintain the BCMS through surveillance and recertification
Timelines vary materially. Scope complexity, existing continuity maturity, number of locations, supplier dependencies, management-system experience, and availability of operating evidence all affect duration. A company with mature ISO 27001 governance may reuse some workflows, but ISO 22301 still requires continuity-specific analysis, strategy, planning, and exercise evidence.
Use the ISO 22301 compliance checklist as a companion project plan and the business continuity and disaster recovery plan template to structure response documentation.
Decide whether certification is the goal
Before allocating resources, clarify the business driver:
- Enterprise buyer or contract requirement
- Regulatory or sector assurance expectations
- Board-led operational resilience objective
- Need for a common continuity system across locations
- Desire for independent assurance and continual improvement
An organization may implement ISO 22301 without certification. Certification adds independent validation, audit cycles, and rules around scope and certification claims.
Step 1: Set scope and leadership
Start by identifying the products and services the BCMS will protect. Then trace the teams, locations, technology, data, facilities, and suppliers needed to deliver them.
Define the scope
Document:
- In-scope products and services
- Legal entities, sites, teams, and geographies
- Supporting activities and shared services
- Outsourced processes and critical suppliers
- Physical and technical boundaries
- Interfaces with out-of-scope functions
- Rationale for boundaries and exclusions
Avoid scoping only around the team running the program. If the certification claim concerns a SaaS product, the scope may need to account for engineering, cloud operations, support, incident communications, and critical providers involved in delivering that product.
Establish governance
Top management should approve the direction, assign resources, and participate in review. A BCMS program owner commonly coordinates implementation, while process and service owners remain responsible for BIAs, recovery objectives, plans, and exercises.
Create a responsibility model covering:
- Executive sponsor
- BCMS manager
- Product and service owners
- Engineering and IT recovery owners
- Crisis management and communications
- People operations and facilities
- Procurement and supplier management
- Internal audit
Evidence to retain: approved scope, business continuity policy, objectives, role descriptions, responsibility matrix, resource decisions, and governance minutes.
Step 2: Perform a gap analysis
Map each ISO 22301 requirement to your current process, evidence, owner, and implementation status. Classify gaps as:
- Missing: no process or control exists
- Informal: work happens but is not consistently defined or evidenced
- Partial: some teams, services, or requirements are covered
- Implemented: process operates and evidence is available
- Needs effectiveness validation: design exists but results are not yet proven
Build a remediation plan
For each gap, record:
- Requirement and expected outcome
- Current state and evidence reviewed
- Risk or audit impact
- Remediation action
- Accountable owner
- Due date and dependencies
- Acceptance criteria
- Closure evidence and reviewer
Prioritize foundational work. Scope, context, governance, and methods for BIA and risk assessment affect many downstream artifacts. Writing plans before understanding recovery priorities often creates rework.
Gap-analysis decision table
| Finding | Likely cause | Priority action | Closure evidence |
|---|---|---|---|
| Recovery targets vary without rationale | No common BIA method | Facilitate BIAs using approved criteria | Owner-approved BIA records |
| Plans name former employees | Weak review and change workflow | Assign plan owners and review triggers | Approved current plans and contact test |
| Supplier RTO is assumed | Incomplete third-party assurance | Review terms and test escalation | Supplier evidence and risk decision |
| Exercises have no objectives | Exercise program is informal | Define scenarios and success criteria | Exercise report against objectives |
| Management reviews are status-only | Required inputs are not structured | Introduce agenda, decisions, and actions | Minutes with assigned outputs |
If you already operate an ISMS, compare your practices with the ultimate ISO 27001 guide. Document control, competence, internal audit, management review, and corrective action may be integrated rather than duplicated.
Step 3: Implement the BCMS
Implementation should create an end-to-end system in which analysis drives capability.
Understand context and interested parties
Identify business, technology, supplier, market, regulatory, and environmental issues that affect continuity. Maintain relevant obligations from customers, contracts, authorities, policies, and other interested parties.
Conduct business impact analyses
Work with owners of prioritized activities to evaluate impact over time. Common outputs include:
- Maximum tolerable disruption
- Recovery time objective
- Recovery point objective where data is relevant
- Minimum acceptable service level
- Peak periods and deadlines
- Required people, technology, data, facilities, and suppliers
- Upstream and downstream dependencies
Require owner approval. Record assumptions and resolve conflicts where multiple services depend on the same limited recovery resource.
Assess disruption risks
Assess scenarios that could interrupt prioritized activities. Consider cyber incidents, cloud or network outages, supplier failures, workforce unavailability, facility loss, utility interruption, data corruption, and communications failure.
Risk treatment should have an owner and decision. Accepted gaps—such as a supplier recovery commitment that does not meet the organization’s target—should be visible to appropriate leadership.
Select and implement strategies
Choose continuity solutions based on the BIA and risk assessment. Options may include:
- Redundant infrastructure or regional failover
- Segregated backups and tested restoration
- Alternate suppliers or emergency contracts
- Cross-training and succession arrangements
- Remote operations or alternate facilities
- Manual workarounds and reduced-service modes
Document why a strategy was selected, what objective it supports, its assumptions, funding, residual risk, and validation method.
Develop plans and communications
Plans should define activation, authority, roles, immediate actions, recovery sequence, dependencies, communications, workarounds, validation, and return to normal. Keep technical procedures in maintained runbooks and reference them from the continuity plan.
Create a crisis communication workflow with audiences, channel alternatives, approvers, spokespersons, templates, and recording requirements. Customers and authorities may have different timing and content needs; map applicable obligations instead of relying on one generic notice.
Implementation evidence: approved methods, completed BIAs, risk register, strategy decisions, continuity plans, runbooks, contact records, supplier assessments, communication templates, and training materials.
Step 4: Operate and test the BCMS
Auditors need evidence that the BCMS has operated. Begin collecting records as soon as each process goes live.
Train relevant people
Provide role-appropriate competence and awareness. General staff may need to know notification and safety expectations. Crisis leaders need decision practice. Technical owners need to execute and document recovery. Alternates should also participate.
Retain training content, attendance or completion, competence evaluation where relevant, and follow-up for missed training.
Run an exercise program
Use exercises that match risk and maturity:
- Contact and notification tests
- Facilitated tabletop scenarios
- Technical backup restoration
- Cloud failover or service recovery
- Crisis communications simulations
- Supplier or cross-organization exercises
- End-to-end operational simulations
Set objectives and success criteria before each exercise. For example, “validate recovery” is vague; “restore the priority service from protected backups, validate transaction integrity, and make it available to the operations team within the approved RTO” is measurable.
Capture credible records
Auditors commonly look for:
- Approved exercise plan and scenario
- Objectives, scope, and participants
- Actual timestamps and system logs
- Decisions and communications
- Results against RTO, RPO, and minimum service levels
- Observations and after-action report
- Corrective actions, owners, dates, and closure
Do not hide exercise failures. A disciplined improvement workflow is stronger evidence than an unrealistic perfect result.
Operate routine controls
Complete scheduled BIA and plan reviews, contact validation, supplier monitoring, metric reporting, risk reviews, and document updates. Use change triggers for new products, material architecture changes, acquisitions, office moves, and supplier replacement.
Step 5: Audit and review internally
Before certification, evaluate the BCMS through internal audit and management review.
Conduct the internal audit
Create an audit program covering ISO 22301 requirements and the BCMS scope. Auditors should be objective and competent. Sample operating records rather than checking only that documents exist.
A useful vertical sample traces one priority service through:
- Scope and interested-party requirement
- BIA impact and recovery objective
- Disruption risk and strategy
- Plan and recovery procedure
- Exercise result
- Finding and corrective action
Record criteria, scope, method, samples, findings, conclusions, and distribution. Address nonconformities through correction, cause analysis, corrective action, and effectiveness review.
Complete management review
Top management should review required inputs such as:
- Changes affecting the BCMS
- Performance against objectives
- Exercise and incident outcomes
- Audit findings and corrective actions
- Risk and BIA changes
- Supplier performance
- Resource adequacy
- Improvement opportunities
Retain evidence of decisions, resource changes, priorities, and assigned actions. Complete the review early enough to address significant outputs before Stage 1.
Run a readiness review
Confirm that:
- Scope and claims are consistent
- Required documents are current and approved
- Operating records cover the scoped processes
- Internal audit has covered the BCMS
- Management review is complete
- Material findings are addressed
- Evidence can be retrieved efficiently
- interviewees understand their roles and actual practices
Step 6: Complete the Stage 1 audit
Select a competent, accredited certification body and verify that its accreditation covers the intended service. Align early on scope wording, locations, audit timing, remote or onsite activity, and required information.
Stage 1 commonly evaluates whether the organization is ready for Stage 2. The auditor may review:
- BCMS scope and organizational context
- Policy, objectives, roles, and leadership involvement
- BIA and disruption risk methods and outputs
- Key documented processes
- Internal audit and management review
- Site-specific conditions and audit planning information
- Whether implementation appears sufficiently mature
Treat Stage 1 as a substantive audit, not document submission. Ensure process owners are available to explain how the system works.
The certification body will provide findings or areas requiring attention. Assign each item an owner, root cause where appropriate, action, due date, and evidence. Confirm what must be closed before Stage 2 and how closure will be reviewed.
Step 7: Complete the Stage 2 audit
Stage 2 evaluates implementation and effectiveness across the certification scope. Auditors commonly interview leaders and process owners, sample records, trace services through the BCMS, and evaluate whether plans and exercises support approved objectives.
Prepare owners to answer from actual practice:
- What are you accountable for?
- How was this recovery objective established?
- What changed after the last exercise?
- Where is the current plan and how is it accessed during outage?
- What happens when a supplier cannot meet the target?
- How are corrective actions verified?
Keep an evidence index, but do not script misleading answers or create records retroactively. If evidence is unavailable or a process failed, explain the facts and improvement action.
Respond to findings
Certification audit findings may require correction and corrective action within specified timeframes. Follow the certification body’s classification and closure process.
A strong response typically includes:
- Clear statement of the issue
- Immediate correction or containment
- Proportionate root-cause analysis
- Corrective action addressing systemic cause
- Owner and completion date
- Evidence of implementation
- Effectiveness check
Certification is issued after the certification body completes its review and decision process, assuming requirements are met and findings are resolved as required.
Maintain ISO 22301 certification
The certificate is not the end of the program. Certification bodies commonly conduct surveillance audits during the certification cycle and a recertification audit before renewal.
Maintain the BCMS by:
- Reviewing context, scope, obligations, BIAs, risks, and plans after change
- Running the approved exercise program
- Measuring objectives and performance
- Investigating incidents and near misses
- Completing internal audits and management reviews
- Closing corrective actions and checking effectiveness
- Maintaining competence and awareness
- Controlling public certification claims
Use surveillance preparation as a health check, not an annual evidence scramble. A monthly or quarterly governance rhythm can keep overdue actions, changed dependencies, test results, and emerging risks visible.
For organizations subject to EU financial-sector requirements, coordinate the BCMS with relevant operational resilience workflows in the DORA compliance guide. ISO 22301 certification does not itself demonstrate compliance with every legal requirement.
Prepare for certification with SecureSlate
SecureSlate helps teams move from gap analysis to maintained certification:
- Map ISO 22301 requirements to owners and evidence
- Track implementation tasks and readiness gaps
- Centralize policies, BIAs, risks, plans, and exercise records
- Manage internal audits, findings, and corrective actions
- Reuse governed evidence across ISO 27001 and related frameworks
- Monitor the BCMS after certification
Get started for free: Create your SecureSlate account
FAQ: ISO 22301 certification
How long does ISO 22301 certification take?
It depends on scope, maturity, resources, complexity, and how much operating evidence already exists. Plan enough time to implement, exercise, audit, review, and improve the BCMS before the certification audits.
How much does ISO 22301 certification cost?
Costs vary based on organization size, scope, locations, audit duration, certification body, travel, consulting support, and remediation needs. Request scoped proposals and budget for implementation and ongoing maintenance, not only the external audit.
Do we need a consultant?
No. A competent internal team may implement the BCMS. External expertise may help with unfamiliar requirements, facilitation, or independent readiness review, but process owners still need to operate the system.
What is the difference between Stage 1 and Stage 2?
Stage 1 generally reviews documented system design and readiness for the full audit. Stage 2 evaluates implementation and effectiveness across the certification scope through interviews, sampling, and operating evidence.
What evidence do auditors want most?
Auditors commonly value traceable, current records: approved BIAs, risk and strategy decisions, exercised plans, measured recovery results, competence records, internal audits, management reviews, incidents, and verified corrective actions.
Disclaimer (legal note)
SecureSlate is not a law firm, and this article does not constitute or contain legal advice or create an attorney-client relationship. When determining your obligations and compliance with respect to relevant laws, regulations, contracts, and standards, you should consult qualified legal and professional advisers.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds
