ISO 22301 is the international standard for business continuity management. It sets out how an organisation prepares for, responds to and recovers from disruption, and certification means an independent auditor has checked that the system works in practice. When you choose a cloud or hosting supplier, it is one of the clearest signs that they can keep running when something goes wrong.
Quick facts
- Full name: ISO 22301, Security and resilience – Business continuity management systems – Requirements.
- Editions: first published in 2012; the current edition was published in 2019.
- What it certifies: a business continuity management system (BCMS), not just a written plan.
- How certification works: an external audit by a certification body, followed by annual surveillance audits and recertification every three years.
- Related standards: ISO 22313 gives guidance on applying ISO 22301, and ISO/TS 22317 covers business impact analysis.
What is ISO 22301?
ISO 22301 defines the requirements for a business continuity management system. In plain terms, it is a structured way for an organisation to work out what could disrupt it, decide what must keep running, and make sure it can recover within agreed timescales.
The important word is system. A business continuity plan on its own is a document. ISO 22301 requires the plan to sit inside a management system with leadership ownership, defined responsibilities, regular exercises, measurement and continual improvement. That is what auditors check.
Key takeaway: ISO 22301 certification does not prove an organisation will never be disrupted. It proves it has a tested, audited way of handling disruption when it happens.
What does ISO 22301 actually require?
ISO 22301 follows the same high-level structure as other ISO management system standards, such as ISO 27001 and ISO 9001. Its requirements fall into seven areas.
| Area | What it means in practice |
|---|---|
| Context of the organisation | Understanding the business, its obligations and its stakeholders, and defining the scope of the system |
| Leadership | Senior management owns business continuity, sets policy and assigns responsibilities |
| Planning | Identifying risks and opportunities and setting business continuity objectives |
| Support | Providing the people, skills, awareness, communication and documentation the system needs |
| Operation | Business impact analysis, risk assessment, continuity strategies, written plans and regular exercises |
| Performance evaluation | Monitoring, internal audits and management reviews to check the system works |
| Improvement | Correcting problems and improving the system over time |
The operational heart of the standard is the business impact analysis. This identifies which activities matter most, how long the organisation can survive without them, and how much data it can afford to lose. Those answers become recovery time and recovery point objectives, explained in our guide to RTO vs RPO.
How is ISO 22301 different from ISO 27001?
The two standards are often held together, but they answer different questions.
| ISO 22301 | ISO 27001 | |
|---|---|---|
| Focus | Business continuity: keeping critical activities running through disruption | Information security: protecting the confidentiality, integrity and availability of information |
| Core question | Can you keep going, and recover, when something goes wrong? | Is information protected from unauthorised access, change or loss? |
| Typical disruptions | Outages, cyberattacks, supplier failure, loss of a building, pandemics | Data breaches, unauthorised access, malware, misuse of information |
| Key outputs | Business impact analysis, continuity strategies, tested recovery plans | Risk assessment, security controls, statement of applicability |

A provider certified to both has had its security controls and its ability to recover independently audited. For a hosting or cloud supplier, that combination matters because an outage or a cyberattack tests both at once.
Key takeaway: ISO 27001 shows a supplier protects your data. ISO 22301 shows it can keep delivering your service, and recover it, when something breaks.
How does ISO 22301 certification work?
- Gap analysis. The organisation compares its current practices with the standard.
- Build the system. It carries out a business impact analysis and risk assessment, then puts in place strategies, plans, roles and documentation.
- Exercise and review. Plans are tested, internal audits are run and senior management reviews the results.
- Stage 1 audit. A certification body reviews the documentation and readiness.
- Stage 2 audit. The auditor checks that the system operates effectively in practice.
- Surveillance audits. The certification body returns each year to confirm the system is maintained.
- Recertification. A full reassessment takes place every three years.

In the UK, buyers should check that the certification body is accredited, for example by UKAS, and that the scope of the certificate covers the service they are actually buying.
What should you check when a supplier claims ISO 22301?
| Check | Why it matters |
|---|---|
| Is it certified, or just ‘aligned with’ the standard? | Alignment is self-assessed. Certification means an independent audit |
| Who issued the certificate? | An accredited certification body gives the certificate credibility |
| Does the scope cover the service you are buying? | A certificate covering head office functions may not cover the platform hosting your systems |
| When was the last surveillance audit? | Certification must be maintained every year to remain valid |
| When were continuity plans last exercised? | Plans that are never tested often fail when they are needed |
| What recovery times does the supplier commit to? | Certification proves a process exists; your contract should state the outcomes you can expect |

Our guide to cloud security certifications and why compliance matters covers how ISO 22301 fits alongside ISO 27001, Cyber Essentials Plus and CSA STAR.
How does ISO 22301 apply at BlackBox Hosting?
BlackBox Hosting has been certified to ISO 22301 since 2020, with certification now issued by BSI. It sits alongside the company’s wider set of independently audited standards.
- Certified to ISO 27001, ISO 22301, ISO 20000-1, ISO 9001, ISO 14001, ISO 14068-1:2023, CSA STAR Level 2 and Cyber Essentials Plus, and listed on G-Cloud 14.
- UK data centres with a 99.999% uptime guarantee.
- Managed disaster recovery with replication down to a 1-second recovery point objective, and managed backup built on Veeam.
- 24/7 support from UK-based engineers.
“Every provider says they’re resilient. ISO 22301 is how you check. It means someone independent has looked at how we plan for disruption, how we test it and how we improve, and keeps coming back every year to make sure we still do.”
– Matt Burden, Founder & Managing Director, BlackBox Hosting
Looking for a resilient UK hosting partner?
Talk to a BlackBox engineer about hosting backed by ISO 22301 and ISO 27001 certification.
Talk to an expert Start a 30-day free trialFAQ: ISO 22301
ISO 22301 is the international standard for business continuity management systems. It sets out requirements for planning, establishing, operating, monitoring, reviewing and improving a system that helps an organisation prepare for, respond to and recover from disruption.
ISO 22301 focuses on business continuity, meaning keeping critical activities running and recovering from disruption. ISO 27001 focuses on information security, meaning protecting information from unauthorised access, change or loss.
No. ISO 22301 is a voluntary standard. However, customers, public sector buyers and regulated organisations often look for it as evidence that a supplier can maintain critical services.
Certification normally runs on a three-year cycle, with surveillance audits each year and a full recertification audit every three years.
A business impact analysis identifies an organisation's critical activities, the impact of disruption over time, and how quickly each activity must be restored. It is a core requirement of ISO 22301.
No. It shows that an organisation has a tested, audited system for managing disruption. Specific uptime and recovery commitments should be set out in your contract or service level agreement.
Yes. BlackBox Hosting has held ISO 22301 certification since 2020, with certification now issued by BSI, alongside ISO 27001, ISO 20000-1, CSA STAR Level 2 and Cyber Essentials Plus.
