ISO 22301 Business Continuity Management – Withstand Disruption. Keep Operating. Build Resilience.
CONSUVATION GmbH guides you in building an effective business continuity management system according to ISO 22301:2019 – from the Business Impact Analysis through to successful certification. With more than 25 years of consulting experience, our own correlation matrix, and 100% senior consultants. For the DACH region and international clients.
How Mature Is Your Business Continuity Management?
Find out in 30 seconds where your company stands on business continuity management according to ISO 22301 – free & without registration.
ISO 22301 Maturity Check
Based on ISO 22301:2019As of: June 2026Reviewed by CONSUVATION experts
At a Glance
What Is ISO 22301?
ISO 22301 is the world's leading standard for business continuity management (BCM). It defines how organisations prepare for, withstand and recover from disruptions – in order to maintain critical business processes.
The current version ISO 22301:2019 is a genuine certification standard (Type A). Core elements are the Business Impact Analysis (BIA), a risk assessment, continuity strategies, and documented, tested contingency plans (BCP).
Since the 2024 climate change amendment, organisations must also consider the impact of climate change on their business continuity – relevant, for example, to supply chains and site risks.
🏆 CONSUVATION – Business Continuity as a Cross-Cutting Discipline
Our consultants combine BCM expertise with practical experience from ISO 27001, risk management and critical infrastructure projects. This cross-cutting perspective makes us an experienced partner for integrating ISO 22301 into your existing management systems in the DACH region.
ISO 22301:2019 – Standard Structure
The Foundations of Business Continuity Management
ISO 22301 requires a documented management system with clearly defined core elements – from analysing critical processes to regularly exercising contingency plans.
Element 1
Business Impact Analysis (BIA)
Identification of critical business processes and evaluation of the impact of a disruption over time. Provides the basis for recovery time objectives (RTO) and maximum tolerable periods of disruption (MTPD).
Basis for RTO/MTPD
Element 2
Risk Assessment
Systematic identification and evaluation of threats to business continuity – from cyberattacks to natural events and supply chain failures.
Risk-Based Approach
Element 3
Continuity Strategies
Selecting suitable strategies for pre-disruption, active disruption and recovery – aligned with the timeframes established in the BIA and contractual obligations.
Before, During, After Disruption
Element 4
Contingency Plans & Tests
Documented business continuity plans (BCP) with clear roles and escalation pathways. Regular exercises and tests ensure that plans actually work when needed.
BCP & Exercise Programme
Element 5
BCM Process Model
Documented end-to-end processes for identifying, evaluating, planning and monitoring business continuity risks – visualised as a flowchart and directly applicable in day-to-day operations.
Documented & Visualised
Type A
Certification Standard
Genuine certification is possible: ISO 22301 is a Type A management system standard with binding requirements. Accredited certification bodies assess the BCMS in a two-stage audit (Stage 1 & 2) and confirm conformity – the certificate is valid for three years.
Our Tool
The CONSUVATION BCM Process Model with Policies & Working Materials
Rather than just a collection of policies, we deliver a documented and visualised process model including ready-made policies, BIA templates and exercise guides that translates the requirements of ISO 22301 into a repeatable, auditable workflow – from identifying critical processes through to effectiveness verification.
Our Approach
From Business Impact Analysis to a Certified BCMS
Structured, predictable and without surprises – our proven approach follows the ISO 22301 BCM process and results in a system that genuinely works when it matters.
01
Initial Consultation & Scoping
Free initial consultation, defining the scope, identifying critical business processes and stakeholders, creating a project plan.
02
Business Impact Analysis
Identifying critical processes, evaluating the impact of disruptions, establishing recovery time objectives (RTO) and maximum tolerable periods of disruption.
03
Risk Assessment
Identifying and evaluating threats to business continuity, deriving protection requirements, creating a risk register.
04
Developing Continuity Strategies
Selecting suitable strategies for pre-disruption, active disruption and recovery, clarifying resource requirements.
05
Creating & Exercising Contingency Plans
Documenting business continuity plans, defining roles and escalation pathways, conducting exercises and tests.
06
Audit & Certification
Conducting an internal audit and management review, supporting the certification audit (Stage 1 & 2), establishing continual improvement.
ISO 22301 & Other Standards
How ISO 22301 Relates to Other Standards
ISO 22301 integrates seamlessly with existing management systems – the shared High-Level Structure across ISO standards makes this possible. CONSUVATION connects business continuity with your established standards.
ISO 22301 → ISO 27001
Information security incidents are one of the most common causes of business disruption. ISO 27001 provides the technical and organisational measures, while ISO 22301 ensures operations continue even in a worst-case scenario.
ISMSIncident ResponseIntegration
ISO 22301 → ISO 31000
The risk assessment within the BCMS follows the methodology of ISO 31000. Companies already applying ISO 31000 can use their established risk methodology directly for business continuity risks.
Risk MethodologyBusiness RisksPDCA
ISO 22301 → NIS2: Implementing Resilience Requirements
Article 21 of NIS2 explicitly requires affected companies to implement business continuity measures – including backup management, disaster recovery and crisis management. An ISO-22301-compliant BCMS provides the structured, audit-ready implementation rather than isolated point measures. Together with the KRITIS-Dachgesetz (CER Directive), it covers key resilience obligations.
NIS2 Art. 21Critical InfrastructureCER Directive
ISO 22301 → DORA
The EU's DORA regulation requires financial institutions to maintain robust incident response and business continuity management. ISO 22301 covers essential parts of these requirements and simplifies demonstrating DORA compliance.
DORAFinancial SectorResilience
ISO 22301 → TISAX
TISAX ISA requires automotive suppliers to provide evidence of availability and recovery for production and information environments. An established BCMS per ISO 22301 directly delivers usable evidence for the TISAX assessment.
TISAX ISAAutomotiveAvailability
ISO 22301 → CADIS
CADIS (Cybersecurity Assessment for Defence Industry Suppliers) also assesses contingency and continuity capability for defence suppliers in its modules. ISO 22301 provides the structured foundation to meet these requirements verifiably.
CADISDefence IndustryContingency Capability
ISO 22301 → IEC 27031 (IT Disaster Recovery)
IEC 27031 focuses on IT recovery after disruptions. ISO 22301 embeds these technical recovery plans within an overarching, organisation-wide continuity management framework.
IT DRRecoveryIEC 27031
ISO 22301 → ISO 9001 (QMS)
Both standards follow the same High-Level Structure and PDCA cycle. Organisations with an established QMS can incorporate BCM requirements into their integrated management system with significantly less effort.
QMSHLSIntegration
Core Elements
What Makes Effective Business Continuity Management According to ISO 22301
ISO 22301 demands more than a contingency manual sitting in a drawer – it's about lived resilience, clear responsibilities and regularly tested plans.
Context
Context of the Organisation
Identifying critical products and services, defining the scope of the BCMS, involving the expectations of relevant stakeholders.
Leadership
Top Management Commitment
Senior leadership actively takes responsibility for business continuity, provides resources, and assigns clear roles for crisis situations.
Analysis
Business Impact Analysis & Risk Assessment
Systematically capturing critical processes and their dependencies, evaluating the impact of disruptions, prioritising risks.
Planning
Continuity Plans (BCP)
Creating documented response and recovery plans for critical processes, clearly defining responsibilities and escalation pathways.
Operation
Exercises & Tests
Regularly exercising contingency plans in realistic scenarios, identifying weaknesses, feeding findings back into the plans.
Evaluation
Monitoring & Continual Improvement
Regularly evaluating BCMS effectiveness through internal audits and management review, systematically tracking incidents, incorporating lessons learned.
Implementation Checklist
ISO 22301 – What Belongs to an Effective BCMS?
📋 Organisational Measures
🏛️Define and document the scope of the BCMS
📜Adopt a business continuity policy
👤Define roles & responsibilities (crisis team, BC manager)
🔍Create a Business Impact Analysis and risk register
📋Define recovery time objectives (RTO) and maximum tolerable periods of disruption
🎓Introduce a training and awareness programme
🔄Establish regular exercises and tests
📊Conduct regular management reviews
🔧 Operational & Methodological Measures
🔐Introduce a risk identification methodology for business continuity
🛡️Define continuity strategies for pre-, active and post-disruption
🔒Document and distribute business continuity plans (BCP)
💾Document and test backup and recovery procedures
📡Set up early-warning indicators for critical business processes
🚨Define and test an escalation and crisis communication process
☁️Check integration into existing management systems (ISO 27001, ISO 31000, ISO 9001, TISAX, CADIS)
⚡Cover NIS2 resilience requirements (Article 21) through the BCMS
ISO 22301 Business Continuity Consulting From a Single Source
From the Business Impact Analysis to successful certification – everything from a single source, with senior consultants and our own correlation matrix.
01
ISO 22301 Gap Analysis
Systematic comparison of current state vs. target state against the requirements of ISO 22301:2019: what exists, what's missing, what needs to be prioritised – clearly documented with a measures plan.
ISO 22301:2019Gap Analysis
02
Business Impact Analysis (BIA)
Identifying critical business processes, evaluating the impact of disruptions, establishing recovery time objectives (RTO) and maximum tolerable periods of disruption.
BIARTOCritical Processes
03
Business Continuity Management System Setup
Complete build-up according to ISO 22301: governance, roles, risk assessment, continuity strategies, contingency plans and documentation.
BCMSGovernanceBCP
04
Integration Into Existing Management Systems
Linking the BCMS with ISO 27001, ISO 31000, ISO 9001, TISAX and CADIS – a consistent resilience framework instead of isolated point solutions. We also use the BCMS to structurally demonstrate NIS2 resilience requirements (Article 21).
ISMSTISAXCADISNIS2
05
Continuity Strategies & Contingency Plans
Developing concrete strategies for pre-disruption, active disruption and recovery, creating documented business continuity plans (BCP).
BCPStrategies
06
Exercises & Tests
Planning and conducting realistic exercise scenarios, verifying the effectiveness of contingency plans, deriving improvement measures from test results.
ExercisesTests
07
ISO 22301 Certification Preparation
Support from documentation through to the certification audit (Stage 1 & 2): system analysis, internal audit, management review – prepared to withstand audit scrutiny.
CertificationAudit
08
Ongoing Support & Recertification
Ongoing support for BCM operations: regular exercises, updating the BIA and risk registers, support for recertification after three years.
RecertificationContinual Improvement
Frequently Asked Questions
ISO 22301 – Frequently Asked Questions
What is ISO 22301?
ISO 22301 is the international standard for business continuity management systems (BCMS). It specifies requirements that enable organisations to prepare for, respond to and recover from disruptions – regardless of industry or company size.
Can a company be certified to ISO 22301?
Yes. ISO 22301 is a certifiable Type A management system standard. Accredited certification bodies assess the BCMS in a two-stage audit and confirm conformity – the certificate is valid for three years.
How long does it take to build a BCMS according to ISO 22301?
Depending on maturity level and company size, building a basic BCMS to certification readiness typically takes 4 to 8 months. If other management systems are already in place, synergies can significantly shorten this timeframe.
What is a Business Impact Analysis (BIA)?
The Business Impact Analysis identifies critical business processes and evaluates the impact of a disruption over time. It provides the basis for recovery time objectives (RTO) and maximum tolerable periods of disruption – the cornerstone of every BCMS.
How are ISO 22301 and Germany's KRITIS-Dachgesetz or NIS2 related?
Germany's KRITIS-Dachgesetz and the underlying EU CER Directive require operators of critical infrastructure to demonstrate concrete resilience measures. Article 21 of NIS2 explicitly requires measures to maintain operations – including backup management, disaster recovery and crisis management. An ISO-22301-compliant BCMS already covers key parts of these requirements in a structured way and provides audit-ready evidence.
How does ISO 22301 relate to TISAX and CADIS?
TISAX ISA requires automotive suppliers to provide evidence of availability and recovery for production and information environments. CADIS also assesses contingency and continuity capability for defence suppliers across several modules. An established BCMS per ISO 22301 directly delivers usable evidence for both assessment procedures.
Is ISO 22301 worthwhile even without ISO 27001 or ISO 31000?
Yes. ISO 22301 is independently applicable and helps every company prepare systematically for disruptions – regardless of whether other management systems already exist. If ISO 27001, ISO 31000 or a QMS are already in place, the BCMS can be integrated directly into them.
Our ISO 22301 Solutions
A Complete Solution for Every Company Size
Project plan, BIA templates, training portal, exercise programme and an external business continuity officer – all from a single source. Scalable for small, medium and large enterprises.
The 6 Building Blocks of Our Complete ISO 22301 Solution
🏛️
Business Continuity Management System
Foundation & Steering
📋
BIA & Risk Register
Critical Processes Captured
🔄
BCM Process Model
Policies & Working Materials
🎓
Training Portal
DE & EN, with test
🧪
Exercise Programme
Tests & Effectiveness Checks
👤
External BC Officer
Remote + optional on-site
Small Business · up to 50 Employees
ISO 22301 STARTER
Entry-level solution for small companies. Includes all essential building blocks for a first functioning business continuity management system – pragmatic, fast and cost-efficient.
✔Business Continuity Management System basics
✔BCM process model with policies & working materials
Complete ISO 22301 solution for mid-sized companies – including exercise programme, training portal and an external business continuity officer on demand.
Maximum solution for complex organisations – with an individual project structure plan, on-site support, certification preparation, and integration with ISO 27001, ISO 31000 or NIS2/critical infrastructure regulations.
✔All PROFESSIONAL services
✔Individual project structure plan
✔External business continuity officer (remote + on-site)
✔Integration with ISO 27001 / ISO 31000 / TISAX / CADIS / NIS2 & critical infrastructure regulations
All packages include an individual project plan tailored to your company. Remote guidance included – on-site appointments available on request.
Schedule a Consultation Now →
Our Expertise
Business Continuity Management as a Cross-Cutting Discipline – Experience That Counts
CONSUVATION exclusively employs senior consultants. With more than 25 years of consulting experience in information security, risk management and crisis management, we are among the most experienced business continuity consultancies in the DACH region.
Our consultants bring BCM experience from numerous ISO 27001, ISO 31000 and critical infrastructure projects. They combine this practice-proven knowledge with the requirements of ISO 22301:2019 to develop a BCMS that genuinely works when it matters.
As active members of ISO working groups, we bring insider knowledge that flows directly into your business continuity implementation.
Our Tool: ISO 22301 Correlation Matrix
CONSUVATION has developed its own correlation matrix for business continuity requirements, mapping all relevant standards – ISO 22301, ISO 27001, ISO 31000, ISO 9001 and NIS2/critical infrastructure regulations. This allows us to spot synergies immediately and produce a complete gap analysis in the shortest possible time – without duplicate work, with maximum standard coverage.
25+
Years of Experience
Type A
Certifiable Standard
ISO
Working Group Members
100%
Senior Consultants
ISO 22301:2019
Experienced business continuity management consultants – from the Business Impact Analysis to successful certification
CISA · CISM · CRISC · CGEIT
The most renowned ISACA certifications – from IT audit to IT governance to business continuity management
ISO 27001 · ISO 31000 · NIS2/Critical Infrastructure
Integrated resilience framework for all related standards – in one project, without duplicate work
Cross-Cutting Experience for Over 25 Years
Business continuity experience from information security, risk management and crisis management projects
Get Started Now
Ready for Business Continuity Management According to ISO 22301?
Get advice from an experienced CONSUVATION consultant – free, non-binding and without empty phrases.