ISO 22301 · Business Continuity

Get ISO 22301 certified and prove your business can survive disruption.

A cyber incident, a supplier failure or one long outage can stop a business that took years to build. ISO 22301 is the international standard for Business Continuity Management Systems (BCMS). Lexfield Digital Systems is an Irish consultancy that helps you plan for disruption, rehearse the recovery, and certify it. Business continuity is a founding specialism of our practice, not a line we added to a menu.

Certification is issued by an independent accredited certification body; our job is to get you through their audit first time. Looking for an auditor rather than a consultant? We will refer you to independent audit specialists.

Why ISO 22301

Disruption is not an if. Recovery should not be a hope.

Cyber incidents, supplier failures, outages, floods, key people leaving: something will eventually interrupt your business. The question customers, insurers and regulators increasingly ask is whether you have proven, in advance, that you can keep your critical services running. ISO 22301 is the recognised way to answer yes.

Win business that demands resilience

Tenders in finance, public services, healthcare and critical supply chains increasingly require evidence of business continuity arrangements. Certification answers the question before it is asked.

Know what actually matters

A business impact analysis tells you which activities your survival depends on, how quickly each must recover, and what that recovery genuinely requires. Most organisations are surprised by the answers.

Plans that work under pressure

The standard requires exercising: rehearsing your continuity plans until people know their roles. A plan that has never been exercised is a document, not a capability.

Strengthen every other standard

ISO 27001 requires continuity controls, and insurers and regulators reward demonstrated resilience. A BCMS reinforces your security posture, your insurance conversations and your board's confidence at once.

Working out your route? The first call is free and carries no obligation: clear, practical advice either way.

Book a free introductory call

Services

What our ISO 22301 consultancy includes

We do one thing here: implementation consultancy. Advisory and audit stay in separate hands, which is what keeps your certificate fully credible. When you need an auditor, we connect you with independent specialists.

Consultancy

Implementation and certification support

For organisations building a BCMS from scratch, formalising existing continuity arrangements, or preparing for certification.

  • Gap analysis against ISO 22301 with a prioritised roadmap
  • Business impact analysis (BIA): identifying your critical activities, recovery time objectives and the resources recovery depends on
  • Risk assessment focused on the disruptions that could actually stop you
  • Business continuity strategy and plan development, written so people can follow them mid-incident
  • Incident response structure: who decides, who communicates, who recovers
  • Exercise design and facilitation, from desktop walkthroughs to full scenario rehearsals, including cyber scenarios such as ransomware, prolonged outages and supplier failure
  • Integration with an existing ISO/IEC 27001 Information Security Management System (ISMS), so you run one management system, not two
  • Knowledge transfer throughout, so your team can run and exercise the BCMS without ongoing consultancy
  • Stage 1 and Stage 2 certification audit preparation, including liaison with your certification body

Two ways to work with us

Both are fixed-price. Pick the balance that suits your team, or move between them as the project runs.

Option 1 We build with you

We take the lead on drafting and building, and you review, decide and approve. The fastest route when your team is stretched.

Option 2 We coach, you build

Your team does the building while we guide, review and course-correct. More of the knowledge stays in-house, and the fee reflects the lighter touch.

Independence protects your certificate: certification bodies expect the people who build your management system and the people who audit it to be different, and that separation is what gives your certificate its value. We handle the building. When you need external audit services, including the internal audits the standard requires, we connect you with independent audit firms, so every part of your certification journey is covered and your certificate keeps its full credibility.

Process

From untested assumptions to proven recovery

  1. Gap analysis and scoping

    We review what continuity arrangements exist today, formal or informal, against every clause of the standard, and define a scope that covers what your survival actually depends on.

  2. Business impact analysis

    Together we identify your critical activities, how quickly each must be restored, what losing them costs by the hour or day, and which people, systems and suppliers recovery depends on. This becomes the factual foundation for everything that follows.

  3. Strategy and plans

    Continuity strategies and plans take shape around the impact analysis: realistic recovery options, clear decision authority, and documentation short enough to be usable during an actual incident.

  4. Exercise, audit and review

    We rehearse the plans with your team until the response is muscle memory. Then an independent auditor puts the system through the internal audit the standard requires; we help you engage one, close out findings, and guide the management review.

  5. Certification: Stage 1 and Stage 2

    We support you through both stages of the certification audit and stay with you through any findings, so the certificate lands and stays in place through surveillance audits.

Who you work with

Continuity is where this practice started

Business continuity is a founding specialism of Lexfield's consultancy, and because our consultants have hands-on experience designing, building and operating digital systems, our recovery advice is grounded in how systems actually fail and restart, not in theory.

  • Business continuity specialism Deep practitioner experience in business impact analysis, continuity planning and exercising, applied across the management system discipline all our standards share.
  • Auditor-trained consultants Lead Auditor training in ISO/IEC 27001 and ISO/IEC 42001 through certified training with SEQM, so your BCMS is built by people who know exactly how management systems are judged.
  • Systems we run ourselves We operate production infrastructure, so recovery time objectives, backups and failover are things we live with, not concepts we quote.
  • Built for small and medium businesses Fixed-scope engagements, plain-English deliverables, and plans sized so your team can actually maintain and exercise them.

The standard explained

What is ISO 22301?

ISO 22301:2019 is the international standard for Business Continuity Management Systems (BCMS), published by the International Organization for Standardization (ISO). It specifies how an organisation should plan, establish, implement, operate, monitor, review, maintain and continually improve its ability to protect against, prepare for, respond to and recover from disruption. It follows the same Clause 4 to 10 structure as ISO/IEC 27001 and ISO/IEC 42001, so it integrates naturally with both. Certification means an accredited certification body has independently confirmed your continuity arrangements meet the standard.

In practice, a BCMS under ISO 22301 must include the following:

  • A business impact analysis A documented assessment of which activities are critical, the impact over time of losing them, and the recovery time objectives (how quickly each activity must be restored) the business commits to.
  • A risk assessment for disruption Identification of the disruptions that could realistically stop critical activities, from cyber incidents and outages to supplier failure and loss of premises or people.
  • Continuity strategies and plans Chosen recovery options and documented plans covering incident response, communications, workarounds and restoration, usable by real people mid-incident.
  • Defined roles and authority Who declares an incident, who decides, who communicates internally and externally, and who does the recovering, agreed before the day it matters.
  • An exercise programme Regular, planned exercising of the plans, from desktop walkthroughs to scenario rehearsals, with lessons captured and fed back into the plans.
  • Audit, review and improvement Internal audits, management reviews and corrective action, so continuity capability keeps pace as the business, its systems and its suppliers change.

The three questions the BIA answers

The business impact analysis is the foundation stone of the BCMS: every strategy and plan inherits its answers.

What first?

Which activities are critical, and in what order they come back. When everything is down, the plan already knows the priority.

By when?

Impacts grow over time, so each activity gets a recovery time objective: the deadline the business has agreed it can stand.

To what level?

Recovery starts at a minimum acceptable level, agreed in advance, so good enough for now is a decision rather than an argument.

The plans you end up with

Business continuity is a small family of documents with distinct jobs, sized to your organisation:

Incident management plan

The first hours: assess what happened, declare an incident, stand up the response team and start communicating.

Business continuity plan

Keeps critical activities running while the disruption lasts: workarounds, alternative resources and the order of recovery.

Disaster recovery plan

Restores the technology: systems, infrastructure and data, in the sequence the BIA prioritised.

Communications plan

Who says what to staff, customers, suppliers and regulators, so the message is decided before the pressure arrives.

Regulation

Resilience is becoming a legal expectation

European regulation increasingly expects organisations to prove they can withstand and recover from disruption, rather than assume it. ISO 22301 does not replace these laws, and it builds exactly the capability and evidence they look for: a tested, documented, continually improving ability to keep operating. We help you map which obligations apply to you and how far your BCMS carries you.

NIS2

The EU's Network and Information Security Directive places incident handling, business continuity and crisis management duties on essential and important entities across a wide range of sectors.

DORA

The Digital Operational Resilience Act requires financial entities, from banks and insurers to funds and their critical ICT providers, to manage ICT risk and test their operational resilience.

FAQ

Questions we hear most often

What is the difference between business continuity and disaster recovery?

Disaster recovery is the technology slice: restoring systems, data and infrastructure after a failure. Business continuity is the whole business: keeping critical activities running, or restoring them fast enough, whatever the cause of disruption, including people, premises, suppliers and communications. A disaster recovery plan is one component of a business continuity management system, not a substitute for it.

How long does ISO 22301 certification take?

Typically four to eight months for a small or medium organisation, and faster if you already run ISO/IEC 27001, since the management system machinery is shared. The business impact analysis and the first exercise cycle are usually the pacing items, because they involve your people, not just documents.

How much does ISO 22301 certification cost?

Consultancy costs are broadly comparable to ISO/IEC 27001 implementations, and materially lower if you are extending an existing certified management system. The certification body's audit fees are separate and quoted by them. We work fixed-scope and fixed-price: one number after a scoping conversation, before you commit. If the scope changes mid-engagement, the price is re-agreed with you before any extra work happens, never discovered on an invoice.

Is ISO 22301 required by law?

No, certification is voluntary. But resilience obligations are tightening: financial services face rules such as the European Union's Digital Operational Resilience Act (DORA), and critical sectors face the NIS2 directive on network and information security. ISO 22301 does not replace those legal obligations, but it builds the continuity capability and evidence they rest on.

We already have a continuity plan. Why is that not enough?

A plan nobody has exercised, that was written for the business as it looked three years ago, fails exactly when you need it. The standard's value is the system around the plan: current impact analysis, rehearsed people, audited arrangements and a review cycle that keeps everything alive. That difference is what an auditor, an insurer or a customer is really checking for.

Who issues the certificate?

An independent accredited certification body, after a two-stage audit. We never certify our own work. We prepare you for the certification audit, help you choose a certification body, and help you engage an independent auditor for the internal audits the standard requires.

How often should we exercise the plans?

A full scenario exercise at least annually, with lighter walkthroughs whenever plans, people or systems change significantly. The standard expects an exercise programme rather than a one-off, and the debrief matters as much as the exercise itself: every run produces improvements, which is what an auditor wants to see and, more importantly, what makes the real incident survivable.

Can you help us build continuity capability without going for certification?

Yes. Certification is the right goal when customers or tenders ask for it; robust, exercised plans are the right goal always. We deliver the same discipline either way, using the standard as the benchmark, and you can add the certification step later: the work already done is the head start.

Get started

Find out what your business could actually survive.

The first call is free and carries no obligation. We will tell you honestly where your continuity arrangements stand and whether ISO 22301 certification makes sense for you now, later, or not at all.

Book a free introductory call