+359 887 407 840 office@escert.com Stara Zagora · Sofia · Plovdiv
BGEN

ISO 22301 certification for business continuity

We carry out accredited certification of business continuity management systems to ISO 22301 in Bulgaria through CERTIND S.A. For this standard, the body is accredited by IAS, USA (No. MSCB-320). The standard answers one question: how quickly, and in what order, the organization keeps working when something stops. The audit is conducted in Bulgarian, and you will receive a tailored quote within two hours.

  • AccreditationIAS, USA · No. MSCB-320
  • Focusrecovery time
  • Auditin Bulgarian, at your premises
Operator monitoring a running production line

The standard at a glance

What is ISO 22301?

ISO 22301 is the international standard setting out the requirements for a business continuity management system. It requires an organization to identify the threats that could disrupt its operations, to assess what it stands to lose in a disruption and to prepare a predictable response — regardless of its size and the nature of the threats.

The standard was developed on the basis of the British BS 25999-2:2007 and replaces it entirely. It includes requirements for analysing, assessing and treating risks to the business and for applying controls against them. The aim is high organizational resilience and an effective response to an event that disrupts operations.

At its core is the business impact analysis: which processes cannot stop, how quickly they must be restored and how much data or output can acceptably be lost. The strategies, plans and resources follow from this — not the other way round.

The standard applies to all types of organizations — financial, insurance, healthcare, telecommunications, IT and others — and is fully compatible with ISO 9001 and ISO/IEC 27001. With an integrated system, the combined audit is usually shorter than separate ones.

Who ISO 22301 is for

  • IT and telecoms Services where downtime is counted in minutes and is visible to every customer.
  • Finance and insurance Activities with regulatory requirements for resilience and reporting.
  • Healthcare Organizations where a disruption affects people, not just revenue.
  • Manufacturing and logistics Chains in which a stoppage at one link stops all the others.

ISO 22301 · the three phases

Before, during and after a disruption

Continuity is not a plan in a drawer but three sets of decisions made in advance. The auditor checks all three — with evidence, not intentions.

  • 1Before — preparation

    Impact analysis: which processes are critical, how quickly they must be restored and what data loss is acceptable. The strategies and resources follow from this.

  • 2During — the response

    Who declares an emergency and with what authority, which plans are activated, and how employees, customers and authorities are notified.

  • 3After — recovery and lessons learned

    A procedure for returning to normal operations, an evaluation of what worked, corrective actions and updated plans.

What the auditor looks for in each of the three

  1. 1Impact analysisCritical processes with a defined recovery time and acceptable data loss.
  2. 2Selected strategiesSolutions that meet those times — a backup site, a supplier, manual operation.
  3. 3Plans and responsible personsNamed individuals, with deputies and with phone numbers that someone has checked.
  4. 4ExerciseA record of testing the plan and what it showed.
  5. 5Review and improvementManagement decisions taken as a result of the exercise or of a real incident.

The exercise is a mandatory part: a plan that has never been tested counts at the audit as an intention, not as a capability.

ISO 22301 · quick check

Are you ready for a disruption?

Six questions to help you judge where to start. Your answers stay in your browser — no one else sees them.

1Do you know which of your processes are critical?Those that cannot stop without causing serious harm.
2Have you defined an acceptable recovery time?For each critical process — in hours or days.
3Do you know which resources they depend on?People, premises, systems, data, suppliers.
4Is there someone to declare an emergency?A named person, with clear authority and a deputy.
5Have you run an exercise of the plan?At least once, with a record of what worked.
6Do you check your suppliers?What you do if a key supplier stops.

How ISO 22301 certification works

The process is the same for every organization and follows ISO/IEC 17021-1, the international standard for certification bodies. Only the audit duration differs — it depends on the number of employees, the sites and the complexity of the activity.

The process in detail
  1. 01 Enquiry and quoteYou describe your activity, number of employees and sites. You receive a quote with the scope, audit duration and price.within 2 hours during business hours
  2. 02 Contract and audit planOnce the contract is signed, we agree the dates, the scope and the audit team.dates that suit you
  3. 03 Stage 1 — readiness reviewThe auditor reviews the scope, the impact analysis, the recovery times, the risk assessment and the plans, and assesses whether the system is ready.documents, scope, readiness
  4. 04 Stage 2 — on-site auditThe audit checks readiness on site — how the plans work, what the exercise showed, how communication is organized and what records all of this has left.in Bulgarian, at your premises
  5. 05 Corrective actionsIf nonconformities are found, you are given a deadline to correct them and submit evidence.only if needed
  6. 06 Decision and certificateAn independent certification decision and issue of the certificate by CERTIND S.A.accredited by IAS (No. MSCB-320)

What the price of ISO 22301 certification depends on

The price of the certificate is not fixed, because it is calculated from several factors, including the audit days your organization requires, which are determined under the mandatory document IAF MD 5.

ISO certification pricing
  • Complexity and sector

    How many critical processes there are and how dependent they are on systems and suppliers.

  • Number of sites

    Sites and centres in scope, including backup ones.

  • Number of employees

    Full-time and part-time staff.

  • Number and type of standards

    When combined in a single audit with ISO/IEC 27001 or ISO 9001, the audit is usually shorter.

What is not included in the certification price

A consultant to implement the system is a separate cost. A certification body cannot provide consultancy to the organizations it certifies — this is an impartiality requirement under ISO/IEC 17021-1.

A tailored quote for your organization

Describe your activity, number of employees and sites — within two hours during business hours you will receive a quote with scope and price.

Exact quote within 2 hours

Questions and answers

Frequently asked questions about ISO 22301

Answers to the questions our clients ask most often before certification.

Didn’t find an answer? Call us — we will answer right away. +359 887 407 840 office@escert.com

Is ISO 22301 certification accredited?

Yes, but not by RENAR. For ISO 22301, CERTIND S.A. is accredited by IAS, USA (No. MSCB-320) to ISO/IEC 17021-1. Accreditation documents.

How does ISO 22301 differ from a disaster response plan?

A plan describes what we do when something happens. The standard requires us to know in advance which processes are critical, how quickly they must be restored and what resources they need — and to have tested this.

Do we need a backup office or data centre?

Not necessarily. The strategy is chosen according to the acceptable recovery time. For some processes this is a backup site; for others, a contract with a supplier, manual operation or deferred execution.

Can it be combined with ISO/IEC 27001?

Yes, and it is a common combination. Information security and continuity use a shared risk assessment and shared records. See ISO/IEC 27001.

How long is the certificate valid?

Three years. Surveillance audits are carried out in the second and third years, and after the end of the cycle comes recertification, which keeps the certificate valid.

ISO 22301 · Free quote

ISO 22301 certification

Describe your activity, the organization’s locations, number of employees and types of standards — within two hours during business hours you will receive a quote with the scope, audit duration and an all-inclusive price.

  • AccreditationIAS, USA · No. MSCB-320
  • Auditin Bulgarian, at your premises
  • Quotewithin 2 hours during business hours