ISO 22301 is the business continuity management standard.
In plain English, it’s about proving your business can keep operating (or recover fast) when something goes wrong — cyber incident, power outage, supplier failure, staff shortage, site access issues, or a major disruption.
For many clients and buyers, ISO 22301 is reassurance: you won’t fall apart under pressure.
What ISO 22301 actually is (no jargon)
ISO 22301 is a framework for building a Business Continuity Management System (BCMS).
That means you:
– identify what parts of the business are critical
– understand what would stop you delivering
– plan how you respond and recover
– test the plans
– improve continuously
It’s not a “plan on a shelf”. It’s a working system.
Who ISO 22301 is for
ISO 22301 is relevant for any business, but it’s especially useful if you:
– deliver time-critical services
– operate 24/7 or with on-call response
– have key clients who demand resilience
– rely on suppliers, subcontractors, or specific systems
It’s common in security, facilities management, construction supply chains, IT, and any business handling sensitive or high-risk contracts.
Why businesses implement ISO 22301
1) Winning tenders and supply chain work
More buyers want evidence you can maintain service during disruption.
2) Reducing downtime
A tested plan reduces chaos and speeds up recovery.
3) Clear roles and decisions under pressure
When something happens, people know who does what.
4) Protecting revenue and reputation
Continuity is often the difference between “we recovered” and “we lost the client”.
What you need to pass ISO 22301
You don’t need a massive binder. You need a system that matches how you operate.
Typically you’ll need:
– BCMS scope, policy and objectives
– Business Impact Analysis (BIA)
– risk assessment and treatment
– continuity strategies (how you keep critical activities going)
– response and recovery plans
– communications plan
– exercising/testing programme
– internal audits and management review
– corrective actions and continual improvement
What makes ISO 22301 audits fail
The usual issues are:
– BIA done as a tick-box exercise
– plans that don’t reflect real operations
– no evidence of testing/exercises
– supplier dependencies not considered
– actions identified but not followed through
The fix: keep it practical, test it, and capture evidence.
How long does ISO 22301 take?
At CAW:
– systems can be built within 48 hours
– typically delivered in 72 hours
Certification timing depends on the certification body’s audit schedule, but the system build and prep doesn’t need to drag on.
Why CAW
– 100% pass rate
– fastest turnaround in the country
– at least 50% cheaper than other UK consultancies
– ISO consultancy package price: £999
CTA
If you want a business continuity system that’s practical, auditable, and actually usable when things go wrong, message us. We’ll tell you exactly what you need (and what you don’t), then get you audit-ready fast.

Leave a comment