Frameworks · ISO 22301:2019
ISO 22301: certify your business continuity management system.
We prepare and support your organization to certify ISO 22301:2019 — with a continuity system that is tested and sustained.
Who it applies to
ISO 22301 applies to organizations that need to guarantee the continuity of critical services in the face of incidents and to demonstrate it to customers, regulators or their own leadership.
What the framework requires
The standard requires establishing a Business Continuity Management System (BCMS): analyzing impact, defining strategies and plans, and testing them periodically.
Clauses 4–10
Impact analysis (BIA)
Strategies and plans
Tests and exercises
Risks of not acting
- Stopping critical services without a tested recovery plan.
- Not sizing the business impact of an interruption.
- Failing customer or regulator continuity requirements.
- Depending on informal knowledge during an incident.
The i-Prot proposal
We implement the BCMS: impact analysis, strategies, continuity and recovery plans, and tests. We prepare the organization for the certification audit, integrated into the CGF cycle.
How we work with this framework
Assessment and scope
Impact analysis (BIA)
Strategies and plans
Tests and exercises
Certification and improvement
Deliverables
- Gap analysis
- Implementation plan
- Controls matrix
- System documentation
- Evidence
- Internal audit
- Management review
- Roadmap
How it connects with CGF
CGF uses ISO 22301 as a source of requirements. This framework mainly covers the Assess, Design, Operate & measure, and Improve stages of the cycle.
See the CGF methodology →
Complyze and ISO 22301
Complyze centralizes the BIA, the continuity plans, the test results and the evidence, with the BCMS status visible over time.
Frequently asked questions
Ready to certify ISO 22301?
Tell us your context and we’ll propose a tailored path to certification.
By submitting you accept our privacy policy.