ISO 22301
ISO 22301 is an international standard that sets out how an organization should build and run a Business Continuity Management System (BCMS), which is a structured way to prepare for, respond to, and recover from disruptions. It provides a framework to plan, establish, implement, operate, monitor, review, maintain, and continually improve that system. Organizations can be certified against ISO 22301 to demonstrate that their business continuity practices meet the standard's requirements.
ISO 22301 is the international standard specifying the structure and requirements for implementing and maintaining a Business Continuity Management System (BCMS). The current edition, ISO 22301:2019 (second edition), sits within the ISO family covering security and resilience and defines requirements to plan, establish, implement, operate, monitor, review, maintain, and continually improve a documented management system that enables an organization to develop and sustain business continuity capability. It is a certifiable requirements standard, meaning an organization's BCMS can be independently audited and certified as conforming to its clauses. In a security leadership context, a virtual or fractional CISO typically supports readiness against ISO 22301 by advising on governance, risk, and program design; certification itself is granted by an accredited certification body, and accountability for maintaining the BCMS and the underlying continuity decisions remains with the client organization and its officers.
Why it matters
Disruptions to operations can come from many directions, and organizations increasingly need a structured, repeatable way to prepare for and recover from them rather than relying on ad hoc plans. ISO 22301 matters because it provides an internationally recognized framework for building a Business Continuity Management System (BCMS), giving leaders a defined structure to plan, establish, implement, operate, monitor, review, maintain, and continually improve their continuity capability. Because it is a certifiable requirements standard, conformance can be independently audited, which allows an organization to demonstrate to customers, partners, and regulators that its continuity practices meet a defined external benchmark rather than internal assertion alone.
Who it's relevant to
Inside ISO 22301
Common questions
Answers to the questions practitioners most commonly ask about ISO 22301.