ISO 22301 Certification in USA

Been asked for an ISO 22301 certificate? Talk to an assessor, not a salesperson. Contact IAS and ask what ISO 22301 certification would mean for your scope, and what your first audit would actually look at.

Most business continuity programs fail in the same place. The plan exists. It is written, approved, filed, and never used. Then something happens on a Tuesday afternoon, and nobody can find the call list.

ISO 22301 is the international standard for business continuity management systems. IAS audits organizations against it and issues certificates to those that meet the requirements. This page explains what ISO 22301 certification involves: what the audit looks for, what a certificate means, and where applicants usually get caught out.

✓ Accredited certification body | ✓ US-based audit teams | ✓ Clear scope, clear findings | ✓ No consultancy conflict

Who IAS is, and who assesses IAS

IAS is a certification body. We audit management systems and issue certificates. We are not a regulator, and we do not write the standard.

A certification body needs to be checked by someone else. Otherwise the certificate is just our opinion of you. IAS is accredited by UQAS. UQAS is the accreditation body that assesses how IAS works: our auditor competence records, our impartiality controls, our decision-making process, our complaints handling.

That accreditation is an assessment of IAS. It says something about how we run audits. It says nothing about your organization, and it is not an endorsement of any company we certify. Your certificate rests on your own audit evidence and nothing else.

The accreditation chain for ISO 22301: UQAS accredits IAS, IAS audits and certifies the client organization, and the client's own evidence supports it
The accreditation chain for ISO 22301: UQAS accredits IAS, IAS audits and certifies the client organization, and the client’s own evidence supports its certificate.

If you want the mechanics of how a certification body is supposed to behave, our certification process and audit procedure pages set out the steps we follow. The ISO certification in the USA overview lists the other standards our US teams audit against, and the IAS blog carries longer pieces on individual clauses.

What ISO 22301 certification actually asks for

The standard is shorter than people expect. It asks you to work out what your organization must keep doing, how long it can afford to stop, what could stop it, and what you will do when something does.

In practice that means a small number of linked things:

  • A defined scope. Which sites, which services, which functions.
  • A business impact analysis that produces recovery time objectives you can defend.
  • A risk assessment tied to those same activities, not a generic register.
  • Documented continuity strategies and procedures.
  • Exercises and tests, with records.
  • Performance evaluation, internal audit, management review, and corrective action.

The last three bullets are where audits are won and lost. Documentation is easy to produce. Evidence that the documentation has been used is not. The same pattern shows up in every system standard we assess, from ISO 14001 environmental certification to ISO 45001 occupational health and safety certification.

Why testing is the spine of the whole thing

Clause 8.5 of ISO 22301 requires you to exercise and test your continuity arrangements. Not once, at some point. On a program, at planned intervals, in a way that is consistent with the scope and objectives you set yourself.

An auditor reading your plan learns what you intend. An auditor reading your exercise records learns what happens when you try. Those are different documents, and the second one is far more useful.

A plan that has never been exercised has a predictable set of faults. Contact numbers are stale. The named deputy left last year. The recovery site needs a VPN certificate nobody renewed. The plan assumes the finance team can work from home, and the finance team’s application is pinned to one office. None of that appears on paper. All of it appears within twenty minutes of a real exercise.

This is the single most common nonconformity we raise in an ISO 22301 audit. The system is designed. It is not rehearsed.

Exercise types, and what each one can prove

Not every exercise needs to take a data center offline. Different formats prove different things, and mixing them over a cycle is more convincing than repeating one format forever.

Exercise typeWhat it provesWhat it cannot proveTypical evidence
Tabletop discussionPeople know their roles and the decision sequenceThat the technology worksScenario pack, attendance, decision log
Plan walkthroughThe document is current, readable, and completeThat anyone can act on it under pressureMarked-up plan, list of corrections raised
Call tree / notification testContact data is accurate and reachableThat responders can actually do the workTimestamps, reach rate, unreachable list
Technical recovery testSystems restore within the stated objectiveThat the business process resumes end to endRestore logs, elapsed time vs RTO
Full simulation or failoverThe whole chain holds under realistic conditionsThat a different scenario would holdObserver notes, timeline, deviations recorded

The column that auditors read most closely is the last one. An exercise without a record is an exercise that did not happen, as far as the audit is concerned.

What good evidence looks like, and what weak evidence looks like

We see both every week. The difference is rarely effort. It is usually honesty.

AreaStrong evidenceWeak evidence
Business impact analysisRecovery objectives traced to named activities and agreed by the ownersA spreadsheet where every process is rated “critical”
Exercise programA schedule covering different scenarios and formats across the yearOne tabletop, run the month before the audit
Exercise outcomeFindings logged, owners assigned, changes made to the planA report saying the exercise was successful
Failure handlingAn exercise that went badly, recorded as it went, with fixes trackedNo exercise has ever found a problem
DependenciesSupplier and IT dependencies mapped to the activities that need themA vendor list with no recovery commitments
Management reviewMinutes showing continuity performance was discussed and decided onAgenda item with no recorded outcome

Read row four twice. An exercise log with no problems in it is a warning sign, not a strength. Exercises exist to surface faults. A program that never finds any is either too easy or not being recorded properly.

The ISO 22301 certification pathway

The route to a certificate is the same for every applicant, whatever the size of the organization, and it follows the same sequence as our ISO 20000 IT service management certification and ISO 22000 food safety certification work.

The ISO 22301 certification pathway from application and scope agreement through the Stage 1 readiness review, the Stage 2 audit, findings and correct
The ISO 22301 certification pathway from application and scope agreement through the Stage 1 readiness review, the Stage 2 audit, findings and corrective action, the certification decision, and the surveillance and recertification cycle that follows.

Application and scope. You tell us what you want certified. We agree the sites, activities, and boundaries in writing. Vague scopes cause arguments later, so we push for precision here.

Stage 1. A readiness review. We look at your documented system, your BIA, your risk assessment, your internal audit results, and your exercise schedule. We tell you plainly whether Stage 2 is worth booking. Being told to wait is not a failure; it is cheaper than failing Stage 2.

Stage 2. The main audit. We interview people, follow activities through, and test the system against real evidence. Exercise records get close attention.

Findings and correction. Nonconformities are written up with the clause and the evidence. You investigate the cause and submit corrective action. We verify it.

Certification decision. Taken by someone independent of the audit team. That separation is part of what UQAS assesses.

Surveillance and recertification. Periodic audits through the cycle, then a full reassessment. Between visits, we expect the exercise program to keep running.

Who does what

Applicants sometimes expect the auditor to help build the system. We cannot. A certification body that designs your management system cannot then judge it. Our associate partners page explains how that separation works.

TaskYour organizationIAS
Define scopeProposes itReviews, challenges, records it
Build the BCMSOwns it entirelyDoes not design or advise
Run exercisesPlans, runs, recordsReviews the records
Fix nonconformitiesFinds the cause, actsVerifies the action closed the gap
Train your staffSelects and booksDelivers open training separately from audits
Decide on the certificateProvides evidenceDecides, independently of the audit team
Use of the markApplies the logo rulesMonitors correct use

What ISO 22301 certification proves

A certificate — BCMS certification, in the shorthand many buyers use — says that on the audit dates, within the stated scope, a sampled examination found your business continuity management system conforming to ISO 22301.

That is a real statement, and it is a narrow one. What was assessed: your documented system, the evidence available on those dates, and the sample of activities, sites, and records we selected. What was not assessed: everything outside the scope on the certificate, every site we did not visit, every process we did not sample, and the future.

A certificate is not a guarantee. It does not promise that you will recover from the next incident, that your recovery objectives will be met, or that no disruption will hurt you. It records conformity with a standard, at a point in time, against a sample. Anyone reading your certificate should read the scope line on it before drawing conclusions.

A note on law

No statement here should be read as describing legal obligations anywhere. ISO 22301 is a voluntary standard. Nothing here states what any statute, regulator, contract, or authority requires of you.

Whether continuity arrangements are legally required in your sector is a question for your own legal advisers. We audit against the standard. We do not give legal advice, and this page is not a substitute for it.

Common reasons ISO 22301 certification stalls at Stage 2

  • Recovery objectives with no basis. An RTO of four hours, chosen because it sounded responsible, with nothing behind it.
  • A plan written by one person. The people named in it have never read it.
  • Scope that does not match reality. The certificate scope says three sites; the BIA covers one.
  • Exercises that avoid the hard scenario. Everyone tests the power cut. Almost nobody tests losing a key supplier.
  • Internal audit run by the author of the system. Independence fails immediately.
  • No corrective action trail. Findings raised, never closed.

Our FAQ page covers general process questions, the ISO certification process article walks through the wider sequence, and the refund policy sets out what happens to fees if an application is withdrawn.

Keeping it alive between audits

Certification is a cycle, not a finish line. The organizations that hold up well at surveillance are the ones that kept exercising after the certificate arrived.

The continuity improvement cycle: plan and maintain arrangements, exercise and test them, record findings honestly, correct the plan, and feed results
The continuity improvement cycle: plan and maintain arrangements, exercise and test them, record findings honestly, correct the plan, and feed results into management review.

The loop is simple. Exercise, record what broke, fix the plan, review at management level, schedule the next exercise. Skip the “record what broke” step and the whole loop stops working. Organizations running several standards at once often fold this review into the one they already hold, such as ISO 50001 energy management certification.

Training the people who will run it

Two roles matter most. Someone has to audit the system internally, and someone has to be competent to lead an external-style assessment of it.

IAS delivers ISO 22301 lead auditor training and ISO 22301 internal auditor training in the USA. Both sit within the wider ISO lead auditor training catalogue. Dates appear on the training schedule. People new to management systems often start with ISO foundation training before taking an auditor course, and internal audit teams that already cover quality can add ISO 9001 internal auditor training. If continuity sits alongside information security in your organization, teams often pair it with ISO 27001 certification or ISO 9001 certification work.

Frequently asked questions

How long does ISO 22301 certification take?

It depends on how much of the system already exists and how honest your gap analysis was. The pacing item is almost always the exercise record. If you have never run an exercise, build that program before booking Stage 2.

Do we need a consultant for ISO 22301 certification?

No. Many organizations build the system themselves. If you use a consultant, that consultant cannot be IAS. We audit; we do not design your system.

Is IAS accredited?

Yes. IAS is accredited by UQAS. That accreditation covers how IAS operates as a certification body, and it is not an endorsement of any organization we certify.

What is the minimum exercise we need before Stage 2?

There is no fixed minimum in the standard. There is a test of adequacy: the exercises must match the scope and objectives you set. A single tabletop covering one scenario rarely does for a multi-site scope.

Can a single site be certified rather than the whole company?

Yes, provided the scope is stated accurately and the activities inside it can stand on their own. The scope line on the certificate must not imply more than was audited.

What happens if an exercise fails?

Nothing bad, if you recorded it and acted on it. A documented failure with a tracked fix is stronger evidence than a flawless report. Hiding it is the problem.

Does ISO 22301 certification cover our suppliers?

No. It covers your management system, including how you identify and manage supplier dependencies. It does not certify the suppliers themselves.

Who decides whether we pass?

An independent decision-maker at IAS, not the audit team. Separating audit from decision is a core impartiality control.

Will the certificate satisfy a customer or tender requirement?

That is for the customer to say. We can tell you what the certificate states. We cannot promise how a third party will read it.

Can we combine this with another management system audit?

Often, yes, where scopes and sites overlap. Ask when you apply so the audit program can be planned as one exercise. See system certification for the range we cover.

Does the certificate expire?

It runs on a cycle with surveillance audits and a full recertification at the end. Miss the surveillance audits and it does not stay valid.

Where can I read more before applying?

Start with ISO certification requirements and how to get ISO certification, then look at about IAS and the IAS gallery if you want to see how audits and courses actually run.

Ready to test what you have built? Send us your scope and your exercise records. Start your ISO 22301 certification assessment and we will tell you honestly whether you are ready for Stage 2.