ISO 22301 is the business continuity management standard.
In plain English, it’s about proving your business can keep operating (or recover fast) when something goes wrong — cyber incident, power outage, supplier failure, staff shortage, site access issues, or a major disruption.
For many clients and buyers, ISO 22301 is reassurance: you won’t fall apart under pressure.
What ISO 22301 actually is (no jargon)
ISO 22301 is a framework for building a Business Continuity Management System (BCMS).
That means you:
- identify what parts of the business are critical
- understand what would stop you delivering
- plan how you respond and recover
- test the plans
- improve continuously
It’s not a “plan on a shelf”. It’s a working system.
Who ISO 22301 is for
ISO 22301 is relevant for any business, but it’s especially useful if you:
- deliver time-critical services
- operate 24/7 or with on-call response
- have key clients who demand resilience
- rely on suppliers, subcontractors, or specific systems
It’s common in security, facilities management, construction supply chains, IT, and any business handling sensitive or high-risk contracts.
Why businesses implement ISO 22301
1) Winning tenders and supply chain work — More buyers want evidence you can maintain service during disruption.
2) Reducing downtime — A tested plan reduces chaos and speeds up recovery.
3) Clear roles and decisions under pressure — When something happens, people know who does what.
4) Protecting revenue and reputation — Continuity is often the difference between “we recovered” and “we lost the client”.
What you need to pass ISO 22301
You don’t need a massive binder. You need a system that matches how you operate.
Typically you’ll need:
- BCMS scope, policy and objectives
- Business Impact Analysis (BIA)
- risk assessment and treatment
- continuity strategies (how you keep critical activities going)
- response and recovery plans
- communications plan
- exercising/testing programme
- internal audits and management review
- corrective actions and continual improvement
What makes ISO 22301 audits fail
The usual issues are:
- BIA done as a tick-box exercise
- plans that don’t reflect real operations
- no evidence of testing/exercises
- supplier dependencies not considered
- actions identified but not followed through
The fix: keep it practical, test it, and capture evidence.
How long does ISO 22301 take?
At CAW:
- systems can be built within 48 hours
- typically delivered in 72 hours
Certification timing depends on the certification body’s audit schedule, but the system build and prep doesn’t need to drag on.
Why CAW
- 100% pass rate
- fastest turnaround in the country
- at least 50% cheaper than other UK consultancies
- ISO consultancy package price: £999
CTA
If you want a business continuity system that’s practical, auditable, and actually usable when things go wrong, message us. We’ll tell you exactly what you need (and what you don’t), then get you audit-ready fast.

Leave a comment