.png)
.png)

ISO 22301
Framework Name
ISO/IEC 22301
Type
Voluntary
Region / Jurisdiction
Global
Enforcing Body / Certifying Party
International Organization for Standardization (ISO), with certification issued by independent, accredited certification bodies
Penalty / Consequence of Non-Compliance
No legal penalty. The consequence is commercial: losing out on contracts or tenders that require demonstrated business continuity capability, particularly in financial services, critical infrastructure, and government-adjacent sectors
What It Is & Why It Matters
ISO 22301 sets requirements for a Business Continuity Management System (BCMS), a structured way for an organization to prepare for, respond to, and recover from disruptive events, whether that's a cyberattack, a natural disaster, a key supplier failing, or a major IT outage. Rather than a one-off disaster recovery document sitting in a drawer, it requires an ongoing system: identifying which activities are truly critical, how quickly each must recover, and having a tested plan ready before disruption hits, not improvised during it. A 2024 amendment added a specific requirement to consider climate change as a source of disruption, reflecting how much more prominent climate-related risk (extreme weather, supply chain disruption from climate events) has become in resilience planning since the base standard was published in 2019.
It matters because business continuity has moved from a nice-to-have to something regulators increasingly expect evidence of directly. The EU's DORA regulation for financial services and the NIS2 directive for critical infrastructure both require organizations to demonstrate real operational resilience, and ISO 22301 certification is one of the clearest ways to show that capability to a regulator or a customer, even though holding the certification doesn't by itself satisfy either law. It also shares the same high-level structure as ISO 27001 and ISO 9001, so organizations that already hold one of those find it noticeably easier to add this one.
Who Needs It
- You are a financial services company navigating DORA's operational resilience requirements and want a certifiable way to demonstrate readiness
- You operate in critical infrastructure and need to show NIS2-aligned resilience to regulators or partners
- Customers or partners have asked how you'd continue operating through a major outage or disaster, not just how you prevent one
- You already hold ISO 27001 and want to extend your management system to cover operational resilience, not just information security