Skip to content

ISO 22301

During disruption, the rehearsed plan counts.

Connect BIA, recovery strategies, BC plans, exercises and management review under ISO 22301 to the same processes, assets and owners that support ISMS, DSMS and AIMS.

ISO 22301, NIS2, DORA and KRITIS-DG use the same BC evidence
4 standards
The BIA feeds strategies, plans and exercises
1 BIA
BSI standard 200-4 in the same workspace as ISO 22301
200-4

One control, several standards

Do the work once, satisfy it everywhere

Standards overlap far more than they differ. A control entered once is mapped to every framework whose requirement it answers, so the second audit inherits the evidence from the first.

One control, entered once, satisfies a requirement in each of the standards listed below.

One control

Supplier & third-party due diligence

  • ISO 22301Requirement satisfied
  • ISO 27001Requirement satisfied
  • NIS2Requirement satisfied
  • GDPRRequirement satisfied
  • BSI IT-GrundschutzRequirement satisfied

From control to policy

Where a control ends up

A control is not a line in a register. It belongs to a management system, and it is carried by the policies and procedures your people actually read, so it flows through both.

One control feeds the four management systems, which in turn carry it into the policies and procedures listed below.

One control

Supplier & third-party due diligence

Management systems

  • BCMSBusiness continuity
  • ISMSInformation security
  • DSMSData protection
  • AIMSAI governance

Policies and procedures

  • Information security policy
  • Supplier policy
  • Continuity plan

What changes for your team

01

BCMS as a peer to your ISMS, not a side project

ISO 22301 sits alongside the ISMS, the DSMS and the AIMS in KaitoSec, on one data model. A risk identified in the ISMS becomes a BC scenario, a critical asset feeds both control selection and recovery planning, the management review covers all four. No parallel registers, no silo handovers.

02

The path to certification is plannable

Stage 1 examines your documentation, Stage 2 the implementation in practice, followed by annual surveillance audits in a three-year cycle. KaitoSec shows per requirement which evidence stands and where gaps remain, so you set the audit date based on maturity.

03

Plans tested before reality tests them

Plan and run tabletop walkthroughs, functional tests and full-scale simulations. Capture findings, lessons learned and follow-up actions, then link them back to the BC plan that was tested. ISO 22301, NIS2 and DORA evidence is generated by the work, not compiled after it.

The workflow

01

BIA and risk assessment as one step (clause 8.2)

The standard requires both as the foundation: understanding impact and assessing continuity risks. You run the BIA at process, service or asset level, assess risks on the same object and define RTO, RPO, MTPD and MBCO per process. Registers and objects are the same as in the ISMS, nothing is entered twice.

02

Strategies with a justified selection (clause 8.3)

BIA results become continuity requirements, from which you derive strategies and solutions. Each option documents cost, feasibility and resource needs, because the standard requires a justified selection, not just an outcome.

03

Plans and procedures for the real event (clause 8.4)

BC plans capture roles, activation, communication and decision authority. Versioning, approval, distribution and acknowledgement run in the same workflow as policies. That way, every role knows its part before it is needed.

04

Plans are only worth as much as the last exercise (clause 8.5)

The standard requires an ongoing exercise programme with defined objectives, from tabletop walkthroughs through functional tests to full-scale exercises. Findings and follow-up actions are documented directly on the tested plan; the exercise history is fully evidenced at audit.

05

Performance evaluation and management review (clauses 9.1 to 9.3)

Metrics, internal audit and management review are separate obligations in the standard. KaitoSec brings exercise results, incidents and review decisions together in one place; every improvement stays traceable to its trigger.

FAQ

Do we have to certify against ISO 22301 to use the BCMS?

No. The BCMS module works with or without a certification goal. If you pursue ISO 22301, you connect requirements, BIA, plans, exercises and reviews. For other obligations, suitable evidence can be reused where your scope genuinely supports it.

How does ISO 22301 relate to NIS2 and DORA?

NIS2 Article 21 explicitly requires business continuity and crisis management. DORA expects financial entities to maintain digital operational resilience including ICT business continuity policies. A BCMS aligned to ISO 22301 satisfies both, plus produces the evidence supervisory authorities expect. KaitoSec maps ISO 22301 requirements to NIS2 measures and DORA articles on one data model.

What is the difference between a BC plan and a disaster recovery plan?

A BC plan covers the overall response: which processes keep going, who decides, how the organisation communicates, how the business escalates. A disaster recovery plan covers the technical restoration of systems. KaitoSec carries both and keeps the relationships explicit, so neither plan drifts from the other.

How often should BC plans be tested?

ISO 22301, NIS2 and DORA all expect regular testing, typically at least annually for critical plans and more often for high-impact processes. KaitoSec schedules, documents and tracks exercises in the same place as the plans themselves, so the cadence is provable without manual record-keeping.

We already run an ISMS. What changes if we add the BCMS?

The asset register, the risk register and the policy library stay in place; the BCMS extends them with BIA, recovery strategies, BC plans, exercises and crisis activation. Your ISBs work in the same workspace, your management review covers both systems, and audit evidence compiles from one source. Our BCM knowledge hub covers BIA, recovery strategies and exercises in depth.