Skip to main content

infosecacademy Eğitim Danışmanlık Hizmetleri

ISO 22301:2019 consulting

ISO 22301 consulting: business continuity that survives a real incident

We build a Business Continuity Management System whose recovery objectives are set with operations, whose plans are tested against plausible scenarios, and whose output doubles as evidence for NIS2 and DORA. Led personally by an ISO 22301 Lead Auditor who has run continuity programmes in banking, insurance, port operations and manufacturing.

ISO 22301:2019Business impact analysisNIS2 Art. 21(2)(c)DORA
In brief

What is ISO 22301?

ISO 22301 is the international requirements standard for a Business Continuity Management System (BCMS). The current edition is ISO 22301:2019. It requires an organisation to identify its critical activities through a business impact analysis, set recovery objectives, establish continuity strategies and plans, and exercise and test them regularly. Under NIS2 it is the most direct evidence base for the business continuity and crisis management measure in Article 21(2)(c).

Why it matters

What ISO 22301 gives your organisation

Operational assurance

Critical services continue through a crisis rather than stopping with it.

Customer and partner trust

A demonstrable, tested capability rather than an untested intention.

Regulatory alignment

Meets NIS2 Article 21(2)(c) and supports DORA ICT continuity requirements for financial entities.

Financial protection

Revenue loss from interruption is contained by plans that activate quickly and predictably.

Real priorities

Critical points in business processes identified and threats analysed — not assumed.

A tested plan

Exercise reports and corrective actions prove the plan works, not just that it exists.

How we deliver

From impact analysis to tested plans

The aim is not only the certificate, but a continuity capability that survives the first real incident.

  1. Current state analysis

    Business processes, risks and existing plans assessed against the standard.

  2. Business continuity policy

    A policy designed to ISO 22301 and approved by management, with scope and objectives.

  3. Business impact analysis and risk assessment

    Critical activities identified, recovery time and recovery point objectives set with operations, risks prioritised.

  4. Strategy and plan development

    Emergency response, crisis management, communication and recovery plans prepared.

  5. Exercises and testing

    Scenario-based exercises, from tabletop to technical recovery tests, with documented exercise reports.

  6. Internal audit and management review

    A full cycle before certification, with corrective actions closed.

  7. Certification support and improvement

    Support through the certification audit and regular revision afterwards.

Engagement summary

Standard
ISO 22301:2019
Delivered as
Word and Excel; version-controlled, metadata cleaned, document IDs applied
Language
English by default for EU clients; Turkish available
Reusable as evidence for
NIS2 Article 21(2)(c), DORA, ISO/IEC 27001 continuity controls

Our approach

  • Exercises designed around scenarios that are plausible for your sector
  • Recovery objectives set with operations, not imposed on them
  • Direct reuse of the output as NIS2 and DORA evidence where applicable
  • Integration with an existing ISMS under one risk method and audit programme
  • Project management that minimises the load on your team
What you receive

What you hold at the end of the engagement

  • BCMS scope and context analysis
  • Business continuity policy and objectives
  • Business impact analysis with RTO and RPO per critical activity
  • Continuity risk assessment and treatment plan
  • Continuity strategies and resource requirements
  • Crisis management and communication plan
  • Business continuity and IT disaster recovery plans
  • Exercise programme, scenarios and exercise reports
  • Corrective action plans from exercises
  • Internal audit report
  • Management review pack
  • NIS2 / DORA evidence mapping
Frequently asked questions

Questions we are asked

What is the difference between a BIA and a risk assessment?

A business impact analysis asks what happens to the organisation over time if an activity stops, and so sets how quickly it must be recovered. A risk assessment asks what could cause it to stop and how likely that is. ISO 22301 requires both; the BIA sets recovery objectives, the risk assessment drives the measures that reduce the likelihood of needing them.

How does ISO 22301 relate to NIS2?

NIS2 Article 21(2)(c) requires business continuity, including backup management, disaster recovery and crisis management. An ISO 22301 system — with its BIA, plans and exercise reports — is the most direct evidence that this measure is implemented and working.

Is a plan enough, or do we need exercises?

A plan that has never been exercised is an intention, not a capability. The standard requires exercising and testing, and auditors look for exercise reports and the corrective actions that followed. We design exercises around scenarios that are actually plausible for your sector.

Can ISO 22301 be combined with ISO/IEC 27001?

Yes, and it usually should be. The two share context, risk method, document control, internal audit and management review. We build them as one integrated system with standard-specific annexes, which reduces documentation and audit days.

Let us start with a scoping conversation

Thirty to forty-five minutes is usually enough to establish scope, a realistic timeline, and whether we are the right people for the work.