ISOQuality Systems MaturityStandard
ISO 22301:2019

Security and Resilience — Business Continuity Management Systems — Requirements

Specifies requirements for a business continuity management system: understanding the organisation, business impact analysis and risk assessment, continuity strategies and solutions, documented plans and procedures, and an exercise and evaluation programme.

LAST REVISED
October 2019
PRODUCT AREAS
Solid DoseSterileBiotechApiDevicesDistribution
SOURCE & PROVENANCE
ISSUING BODY
International Organization for Standardization
JURISDICTION
International
DOCUMENT ID
ISO 22301:2019
Official site — International Organization for Standardization

Always verify against the current published text before relying on it for a submission or inspection.

Scope & applicability

Any organisation, of any size or sector, and certifiable by accredited bodies. In regulated manufacturing it is the management-system frame around obligations GMP already implies — EU GMP Annex 11 requires continuity provisions for computerised systems supporting critical processes, and ISO 22301 is how an organisation builds and tests that at enterprise scale rather than system by system.

Key requirements

  • Business impact analysis establishing prioritised activities and their recovery time objectives
  • Risk assessment of disruption to prioritised activities, feeding continuity strategy selection
  • Documented business continuity plans with defined roles, activation criteria and communication arrangements
  • An exercise programme that tests the plans, and evaluation of continuity documentation and capability after disruption
  • Second edition (2019) cancels and replaces ISO 22301:2012; Amendment 1:2024 adds climate-action considerations

Implementation tips

  • Express recovery objectives in terms the operation understands — batches in flight and the point at which the manual fallback stops coping — rather than only in hours
  • A restore is a change to a validated system: plan for verification back into the validated state and reconciliation of the gap since the last good backup, not only for the system coming back up
CHECKING ACCESS

Checking your Professional access…

Where this control fails

live FDA enforcement
See all FDA enforcement →

Live FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.

ISO 22301:2019: frequently asked questions

Quick answers to common questions about ISO 22301:2019.

What is ISO 22301:2019?

ISO 22301:2019 — Security and Resilience — Business Continuity Management Systems — Requirements — is a standard issued by the International Organization for Standardization. Specifies requirements for a business continuity management system: understanding the organisation, business impact analysis and risk assessment, continuity strategies and solutions, documented plans and procedures, and an exercise and evaluation programme.

Who does ISO 22301:2019 apply to?

Any organisation, of any size or sector, and certifiable by accredited bodies. In regulated manufacturing it is the management-system frame around obligations GMP already implies — EU GMP Annex 11 requires continuity provisions for computerised systems supporting critical processes, and ISO 22301 is how an organisation builds and tests that at enterprise scale rather than system by system.

What are the key requirements of ISO 22301:2019?

ISO 22301:2019 requires, among other things: Business impact analysis establishing prioritised activities and their recovery time objectives; Risk assessment of disruption to prioritised activities, feeding continuity strategy selection; Documented business continuity plans with defined roles, activation criteria and communication arrangements; An exercise programme that tests the plans, and evaluation of continuity documentation and capability after disruption.

When was ISO 22301:2019 last updated?

The current version of ISO 22301:2019 dates from October 2019.