ISO 22301

Continuity you can prove: impact analysis, recovery objectives and tested plans, not a binder on a shelf.

Universal core · ISO 22301:2019, Business continuity management systems

Issued by

ISO

Region

International

Effective

First published 2012; current edition 2019

Oversight

Certified by accredited bodies on a three-year cycle

Applies when

Any organisation that must demonstrate it can survive disruption

In the catalog

Curated, versioned & cross-mapped

The obligation, plainly.

ISO 22301 turns business continuity from a document into a management system: business-impact analysis, recovery time and point objectives, continuity strategies, and, critically, exercises that prove the plans work.

For regulated organisations the demand is sharper: supervisors and customers both ask for evidence of testing, not intentions. The standard's discipline of exercising and post-exercise action is where most programmes fail.

Where programmes are tested.

01

Business-impact analysis

Which processes matter, what they depend on, and how long the organisation can survive without them.

02

Recovery objectives

RTOs and RPOs set deliberately, owned, and traceable to the strategies that meet them.

03

Exercising and testing

Scheduled tests with recorded results, and gaps turned into tracked actions.

Curated once, evidenced continuously.

  • Continuity requirements map to the BCP/DR module: plans, test schedules and results live on the same graph as the risks they mitigate.
  • Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
  • Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
  • Every attestation carries maker/checker, and every action lands in an append-only audit trail.

ISO 22301, asked plainly.

The questions compliance teams actually ask before an adoption decision or an audit.

What is the difference between a BCP and ISO 22301?

A business continuity plan is a document; ISO 22301 is a management system around it: impact analysis, recovery objectives, strategies, exercises and improvement. The standard exists because untested plans fail, and it makes the testing non-optional.

What are RTO and RPO?

Recovery time objective is how quickly a process must be restored after disruption; recovery point objective is how much data loss is tolerable, measured in time. ISO 22301 expects both to be set deliberately through business-impact analysis and proven through exercises against real results.

Do regulators require ISO 22301?

Rarely by name, but supervisory expectations for operational resilience, including business-continuity guidelines in regimes like the CBN's, echo its shape. Certification is the cleanest way to evidence a continuity capability that customers and supervisors will both accept.

How often should continuity plans be tested?

The standard requires exercising at planned intervals; in regulated practice that means at least annually per critical process, with results recorded and gaps turned into tracked actions. An untested plan is treated by auditors as no plan.

Where it connects.

The full catalog
Carried by these modules
Who answers to it

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.