Quick answer

ISO 22301 is the international standard for a business continuity management system (BCMS): a structured, auditable program ensuring your organization can continue operating through disruptions, from IT outages to supplier failures to physical events. It requires business impact analysis, continuity strategies, documented plans, and, critically, regular exercising. Certification proves operational resilience to customers and regulators, and it's increasingly requested where NIS 2 and DORA have made continuity a legal expectation.

The core components

  • Business impact analysis (BIA): which processes matter most, how fast they must recover (RTO), and how much data loss is tolerable (RPO). The BIA is the foundation everything else derives from.
  • Risk assessment for disruptions: what can plausibly take your critical processes down, shared territory with your security risk register.
  • Continuity strategies and plans: documented, owned procedures for maintaining and recovering operations, including crisis communication.
  • Exercising and testing: the standard's teeth. Plans must be exercised regularly, results recorded, and improvements fed back. An unexercised plan is a document, not a capability, and auditors treat it that way.
  • Management system machinery: leadership commitment, internal audit, and continual improvement, familiar from every ISO management standard.

Who pursues certification

  • Suppliers to continuity-sensitive customers: financial sector (where DORA makes resilience contractual), critical infrastructure, healthcare, and public sector all push continuity requirements down their supply chains.
  • Companies whose sales stall on the continuity questionnaire section: a certificate answers pages of "describe your backup strategy and recovery testing" in one line.
  • Organizations that experienced a disruption and want the discipline institutionalized rather than dependent on memory.

Relationship to your security program

Continuity overlaps heavily with the availability side of security: backups, redundancy, incident response, and disaster recovery live in both. The efficient move is one integrated program where continuity controls cross-map into ISO 27001, NIS 2, and DORA requirements simultaneously; see running it on OptiTech.

See OptiTech in action

Get a personalized walkthrough of automated compliance for your team. No commitment required.