Certification planner / ISO 22301
How do you get ISO 22301 certification?
Business continuity management system: business impact analysis, disruption scenarios and recovery plans. Answer the questions, and we'll map out the stages, timeline and documents you need to prepare for your business, with the reasoning behind each one.
ISO 22301 certification steps
- Scope and gap analysisDefine the certification scope and locations, and identify the gaps between your current practices and the standard.
- Leadership, policy and objectivesTop management commitment, policy, roles and measurable objectives.
- Risks and standard-specific analysesRisks and opportunities; depending on the standard, environmental aspects, information security risks or business impact analysis.
- DocumentationPrepare, approve and publish procedures, work instructions, forms and lists tailored to your business.
- Implementation and recordsOperate the system; build up records such as training, calibration, suppliers and corrective actions.
- Internal audit and management reviewAudit the system yourself, close the findings and conduct the management review.
- Certification auditStage 1 (documentation) and Stage 2 (implementation) audits by an accredited body, followed by the certificate.
Documents required for ISO 22301
The mandatory set from the KaliteGO library. Each one is generated as docx/xlsx, filled in with your company details.
DD.1Context DocumentDD.2Scope and Boundaries DocumentDD.4Leadership Management DocumentFR.1Context (Internal and External Issues) FormFR.21Business Continuity Team and Responsibilities FormFR.22Business Continuity Exercise Report FormFR.30Training Attendance and Evaluation FormFR.4Meeting Minutes FormFR.5Internal Audit ReportFR.6Goal and Objective Tracking FormFR.71Business Continuity Strategy and Solution Selection FormFR.8Corrective Action FormFR.9Performance Monitoring and Tracking Form.LS.1Current Documents and Revision Tracking ListLS.14Legal and Other Requirements ListLS.2Interested Parties and Stakeholder Analysis List.LS.25Post-Incident Evaluation (After-Action Review) ReportLS.5External Communication ListLS.6Internal Communication ListLS.7Corrective Action Tracking ListPL.1Internal Audit PlanPL.13Business Continuity Plan (BCP)PL.4Backup PlanPL.6Business Continuity Impact Analysis PlanPL.7Business Continuity Exercise PlanPO.33Business Continuity PolicyPR.1Control of Documented Information and Records ProcedurePR.14Training and Awareness Management ProcedurePR.18Information Security Business Continuity ProcedurePR.2Risk and Opportunity Management ProcedurePR.4Communication Management ProcedurePR.6Internal Audit ProcedurePR.61Business Impact Analysis (BIA) and Disruption Risk Assessment ProcedurePR.7Management Review Procedure.PR.8Improvement, Nonconformity and Corrective Action ProcedureTL.6Emergency, Crisis Management and Business Recovery Work InstructionŞM.01Organization Chart
Frequently asked questions
How long does ISO 22301 certification take?
For most SMEs, 4–9 months. The timeline depends on your headcount, locations and current practices. The system needs to run long enough to generate records (usually 2–3 months), followed by an internal audit, a management review and the certification body's Stage 1 and Stage 2 audits.
Which documents are required for ISO 22301?
The standard explicitly requires certain documented information: scope, policy, objectives, procedures and records. The KaliteGO library has 37 document templates for ISO 22301; the planner explains which of them your business needs, and why.
Does KaliteGO issue the certificate?
No. The certificate is issued by an accredited certification body following the audit. KaliteGO gets you ready for the audit: documents, records, internal audit and management review.
Can I prepare without a consultant?
Yes. Most small and medium-sized businesses can prepare with a guided roadmap and ready-made templates. Consultants also use KaliteGO to manage multiple clients.