Overview
EN ISO 22301:2019 - Security and resilience: Business continuity management systems (BCMS) - Requirements specifies a management-system framework to protect organisations from disruptive incidents, reduce likelihood of occurrence, prepare for, respond to and recover from disruptions. Published by CEN and identical to ISO 22301:2019, this European standard replaces EN ISO 22301:2014 and is applicable to organisations of any type, size or sector. The standard can be used to assess an organisation’s ability to meet its own business continuity needs and obligations.
Keywords: EN ISO 22301:2019, ISO 22301, business continuity management, BCMS, security and resilience
Key Topics and Requirements
EN ISO 22301:2019 defines generic, auditable requirements to implement, maintain and improve a BCMS. Core technical topics include:
- Context and scope: Understanding organisational context, interested parties and defining the BCMS scope (Clause 4).
- Leadership and governance: Senior management commitment, business continuity policy and assigned roles and responsibilities (Clause 5).
- Planning: Risk and opportunity assessment, business continuity objectives and change planning (Clause 6).
- Support: Resource allocation, competence, awareness, communication and documented information control (Clause 7).
- Operation: Business impact analysis (BIA), risk assessment, selection and implementation of continuity strategies, plans, procedures, response structure and recovery actions (Clause 8).
- Exercise and testing: Programme to exercise plans and evaluate capabilities (Clauses 8.5–8.6).
- Performance evaluation and improvement: Monitoring, internal audit, management review, nonconformity handling and continual improvement (Clauses 9–10).
These requirements are intentionally generic so organisations tailor them to their operating environment and complexity.
Practical Applications
- Develop or improve an organisation-wide Business Continuity Management System (BCMS).
- Conduct Business Impact Analysis (BIA) and risk assessments to prioritise critical services.
- Design and implement continuity strategies, recovery plans, communication and incident response structures.
- Create exercise, testing and review programmes to validate readiness and resilience.
- Assess preparedness for regulatory, contractual or stakeholder continuity obligations.
Keywords: business impact analysis, continuity plans, incident response, recovery strategies
Who Uses This Standard
- Business continuity managers and risk officers
- Senior leadership responsible for resilience and governance
- Compliance, audit and legal teams evaluating continuity obligations
- Small-to-large enterprises, public sector bodies and critical infrastructure operators
Related Standards
EN ISO 22301:2019 is produced by ISO/TC 292 (Security and resilience) and endorsed by CEN. Organisations often integrate it with other management-system standards (e.g., ISO management systems for risk, information security and quality) to align resilience, security and operational continuity strategies.