Services / ISO 22301 certification
ISO 22301 business continuity certification, from $800
Show customers and regulators that you can keep critical services running through disruption, with a business continuity certificate audited by EUROTECH.
From $800Certified by EUROTECH

- Accredited by IAB and INTAQS
- Issuing certificates since 2004
- Online or on-site audits worldwide
- Verify any EUROTECH certificate
What ISO 22301 certification covers
ISO 22301 sets the requirements for a business continuity management system. Its purpose is simple to state: when something disrupts your organization, whether a fire, a cyber attack, a supplier failure, a pandemic or a power cut, you should be able to keep delivering your most important products and services, or restore them within a time your customers can accept.
The audit follows the logic of the standard. First the business impact analysis, which identifies your prioritized activities and how long each can be interrupted before the impact becomes unacceptable. Then the risk assessment of what could disrupt them. Then the continuity strategies and solutions, the plans and procedures, and the exercises that test whether those plans work.
The current edition is ISO 22301:2019. Like other management system standards, it was amended in 2024 to ask whether climate change is relevant to your organization, and for business continuity it often is, through weather events and supply chain effects.
- Stage 1 review of scope, business impact analysis, risk assessment and plans
- Stage 2 audit of strategies, plans, exercises and management system
- Certification decision and three-year certificate
- Certificate listed on verify.eurotechcertification.com
- Yearly surveillance audits and recertification
Recovery objectives are the numbers that make the system concrete. The maximum tolerable period of disruption sets the outer limit; the recovery time objective sets the target for resuming an activity; for information, the recovery point objective sets how much data loss is acceptable. The auditor checks that these numbers are agreed by management and drive the plans.
Scope choices and audit format
Some organizations certify their whole business; others start with the services customers rely on most, such as a payment platform, a contact centre, a data centre or a production site supplying a key customer. A narrower scope is quicker to certify, as long as it covers what your customers actually depend on.
Much of the ISO 22301 audit is documentary and interview based: impact analysis, risk assessment, plans, exercise reports and management review. That suits online auditing well. Where recovery depends on physical arrangements, such as an alternate site, generators, spare equipment or a second production line, the auditor may want to see them on site.
ISO 22301 sits well alongside ISO 27001, because incident response, backup and recovery and supplier management overlap. It also combines with ISO 9001 or ISO 14001 in an integrated system. An integrated audit avoids checking shared processes twice.
Dependencies deserve their own attention in the scope. A service may depend on an IT platform, a building, a few key people and two or three suppliers; if any one fails, the service fails. Mapping these dependencies is often the most valuable part of the work for our clients.
What decides the price
ISO 22301 certification with EUROTECH starts at $800. Audit time depends on the size and complexity of what is in scope.
- Number of people in the scope of the system
- Number of prioritized activities and their dependencies
- Sites, including recovery and alternate sites
- Critical suppliers your continuity depends on
- Integration with ISO 27001 or other management systems
We confirm audit days and all fees in a written quote. A current business impact analysis and records of at least one exercise make the audit shorter and more useful.
Suppliers who are critical to recovery can increase audit time, because the auditor needs to see how you know they can support you in a disruption, through contracts, their own continuity arrangements or joint exercises.
How ISO 22301 certification works with us

Step 1
Scope and quote
We agree the services and sites in scope and quote the ISO 22301 audit in writing.

Step 2
Stage 1 review
We review your impact analysis, risk assessment, strategies and plans, and list gaps.

Step 3
Stage 2 audit
The auditor tests plans against the impact analysis and reviews exercise results.

Step 4
Certificate and surveillance
After the decision you receive the ISO 22301 certificate, with yearly surveillance audits.
Disruption risks differ by region
We certify ISO 22301 for organizations in the USA, Europe, Asia and Africa, and the risk picture varies with location. Coastal sites face storms and flooding, some regions face earthquakes or wildfires, and others face unreliable power or long supply routes. Your risk assessment should reflect the sites you actually operate from and the suppliers you rely on.
Some sectors have regulatory continuity expectations, such as financial services, telecommunications, healthcare and critical infrastructure. In the European Union, for example, rules on digital operational resilience for financial entities and on network and information security for essential sectors include continuity and recovery duties. ISO 22301 does not replace those rules, but it gives you a recognised structure to meet them.
Customers in supply chains increasingly ask suppliers to show recovery time objectives for the services they buy. A certificate backed by tested plans answers that question with evidence.
What to expect during the audit
The auditor will test the link between the impact analysis and the plans. If the analysis says an activity must be restored within four hours, the plan must show how, with the people, technology, information and suppliers needed to achieve it, and an exercise should have tested it.
Exercise records are a key piece of evidence. The auditor will ask what scenarios you exercised, who took part, what went wrong and what you changed afterwards. An exercise that found problems and led to improvements is better evidence than one that went perfectly on paper.
Communication is tested too. The auditor will ask how you would warn staff, inform customers and speak to the media during an incident, who is authorized to do so and how contact details are kept current and available when normal systems are down.
Expect questions about the incident response structure: who declares a disruption, who leads the response, where the team meets if the main site is unavailable, and how decisions are recorded during the event.
Findings are graded as major or minor, and certification is decided on the evidence. You receive a written report explaining each finding.
Keeping the certificate
Business continuity plans go out of date quickly: people change roles, phone numbers change, systems are replaced and suppliers move. Review contact lists and plans on a fixed schedule and after any significant change, and run a programme of exercises over the three-year cycle that covers your prioritized activities.
If a real disruption happens, record how you responded and what you learned. Surveillance auditors value real incidents as evidence, because they show how the system performs under pressure. Keep internal audits and management reviews running, and update the impact analysis when your products, services or customers change.
Continual improvement in business continuity means smaller gaps over time: faster recovery in exercises, fewer single points of failure, clearer plans. Track these as objectives so management review sees progress, not only activity.
Questions buyers ask
How much does ISO 22301 certification cost?
With EUROTECH it starts at $800. People in scope, prioritized activities, sites, critical suppliers and integration set the final price.
What is a business impact analysis?
A structured analysis of which activities matter most, how long each can be interrupted and what resources they need to recover.
Do we need to run exercises before certification?
Yes. The standard requires exercising and testing, and the auditor expects to see results and the improvements that followed.
Can ISO 22301 be combined with ISO 27001?
Yes. Incident response, backup and recovery and supplier management overlap, so an integrated audit saves time.
Which version of ISO 22301 is current?
ISO 22301:2019, amended in 2024 to include consideration of climate change.
Can we certify only part of the business?
Yes, as long as the scope covers the products and services your customers depend on and is described clearly on the certificate.
Related services
- ISO 27001 certification
From $800
- ISO 28000 certification
From $800
- ISO 31000 assessment
From $800
Get a quote for ISO 22301 certification
Tell us your company, sites and the standard you need. We reply with a written quote and the audit plan.
Prefer to talk? Call +1 307 205 1833
Monday to Friday, 09:00 to 18:00 (US Mountain Time)
