Skip to main content
FRAMEWORK

Business continuity, not just incident response.

ISO 22301 is the certifiable standard for business continuity. It specifies a Business Continuity Management System — the same harmonized clause structure as ISO 27001 — built around a business impact analysis, a risk assessment, continuity strategies, documented plans, and an exercise programme that proves the plans work before you need them. Its scope is any disruption: a flood, a supplier collapse, a pandemic, a power failure. Cyber is one cause among many.

That breadth is the point, and it is also why cyber incident response and business continuity so often end up as two plans that have never met. The incident responder knows how to contain a ransomware event; the continuity plan knows the recovery time objective for the order system; nobody has checked that the second is achievable given the first. The exercise that would reveal the gap is the one that keeps getting postponed.

Who it applies to

Any organization whose customers, regulators or insurers need assurance that it can keep operating through disruption — which, as supply chains tighten and regulators lean on resilience, is an expanding set. It is sector-neutral and, like 27001, arrives when someone asks for the certificate. Financial entities under DORA will recognize most of it already.

Where 22301 meets DORA and NIS2

The overlap is substantial and it runs in both directions. DORA requires financial entities to test their digital operational resilience and to maintain ICT business continuity and response and recovery plans; NIS2 lists business continuity and crisis management among its required risk-management measures. A 22301 management system gives both of those a structure and an evidence trail — and the exercise programme 22301 demands is, in practice, the same testing discipline DORA asks for. The mechanism is a single continuity record per critical process: its impact analysis, its recovery objectives, the plan that delivers them, and the last exercise that proved it. The 22301 auditor, the DORA supervisor and the NIS2 authority each read their own view of that record. None of them get a different answer.

What it asks, in operating terms

Read as an operating requirement rather than a standard document, 22301 reduces to a handful of standing asks — each answerable from live state, not reconstructed before the recertification visit.

ISO 22301 requirements · how TruSecure answers them
What the standard asksWhere it is answered
Know which processes matter and how long they can be downBusiness impact analysis · recovery objectives per process
Assess disruption risk, cyber and otherwiseRisk register · shared with 27005 and the enterprise feed
Hold plans that are current, owned and findableContinuity plans · versioned, owner and review date per plan
Exercise the plans, and record what the exercise foundExercise log · findings tracked to verified closure
Show DORA and NIS2 the same continuity evidencePer-regime exports · same record, each framework in its own shape

What you'd actually look at

In the dashboard, every figure opens on click to the process, the plan and the person behind it. This excerpt is what a continuity file is made of:

BCMS file · excerptSample data
Critical processes
8 · recovery objectives set for each
Plans current
8/8 · reviewed within the cycle
Last exercise
ransomware scenario · 2 findings, 1 closed
Also read by
DORA · NIS2
Auditor export
sealed · sha256:5f92...a7c0

Where teams usually start

With a demo walked through by TruSecure — your critical processes and their recovery objectives in one place, a single plan opened to its last exercise and what it found, the same record answering 22301, DORA and NIS2. The certificate itself comes from an accredited certification body; TruSecure prepares and maintains the evidence, and holds no certification of its own yet. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

ISO 22301 is a certifiable Business Continuity Management System standard covering resilience to any organizational disruption, not cyber incidents specifically. It overlaps with DORA's digital operational resilience testing requirements.