Information Security Certification

ISO 22301 Certification

Business Continuity Management System

What is ISO 22301?

ISO 22301 specifies requirements for a business continuity management system (BCMS), enabling organisations to prepare for, respond to and recover from disruptive incidents.

Benefits of Certification

  • โœ”Protect operations from disruption
  • โœ”Reduce downtime and financial impact
  • โœ”Meet regulatory and client resilience requirements
  • โœ”Protect reputation and stakeholder confidence
  • โœ”Improve organisational resilience

Scope

For organisations of any size that need to plan, establish and improve their ability to continue operating during disruptions.

Who it applies to

  • โ—IT & software / SaaS
  • โ—BPO & shared services
  • โ—Financial & professional services
  • โ—Telecommunications
  • โ—Healthcare & data processors
  • โ—E-commerce & cloud providers
โœ“

What the scope covers

  • โ–ธInformation security risk assessment and treatment
  • โ–ธAccess control and cryptography
  • โ–ธAsset, supplier and cloud security
  • โ–ธIncident management and business continuity
  • โ–ธPhysical and operational security
  • โ–ธStatement of Applicability (Annex A controls)

Key Requirements

  • โ–ธBusiness impact analysis (BIA)
  • โ–ธRisk assessment and treatment
  • โ–ธBusiness continuity strategies and plans
  • โ–ธIncident response structure
  • โ–ธExercising and testing programmes
  • โ–ธPerformance evaluation and improvement

Certification Process

  1. 1

    Application & Quotation

    Submit your details and receive a tailored, fixed-price quotation based on scope, sites and headcount.

  2. 2

    Gap Analysis (Optional)

    An optional pre-audit review identifies gaps between your current practices and the standard.

  3. 3

    Stage 1 Audit

    Documentation review to confirm your management system is designed and ready for assessment.

  4. 4

    Stage 2 Audit

    On-site (or remote) assessment of the implementation and effectiveness of your system.

  5. 5

    Certification Decision

    An independent technical review leads to the certification decision and issue of your certificate.

  6. 6

    Surveillance & Renewal

    Annual surveillance audits maintain your certification over the three-year cycle before recertification.

Documents Required

  • ๐Ÿ“„Company registration / incorporation details
  • ๐Ÿ“„Organisation chart and list of sites
  • ๐Ÿ“„Scope statement of activities
  • ๐Ÿ“„Management system manual / documented information
  • ๐Ÿ“„Key policies and procedures relevant to the standard
  • ๐Ÿ“„Records demonstrating implementation (audits, reviews, training)

Frequently Asked Questions

How long does ISO 22301 certification take?

Typical timelines range from 4 to 12 weeks depending on the size of your organisation, the number of sites and how mature your existing management system is.

How long is a ISO 22301 certificate valid?

Certificates are issued for a three-year cycle, subject to successful annual surveillance audits, after which recertification renews the cycle.

Can the audit be conducted remotely?

Yes. Where appropriate, UKCTL can conduct Stage 1 and parts of Stage 2 remotely, combined with on-site verification as required.

Is ISO 22301 certification accredited?

UKCTL issues accredited certificates recognised internationally, giving your customers and stakeholders confidence in the assessment.

Get ISO 22301 certified with UKCTL

Apply Now