What is the difference between business continuity and disaster recovery?
Disaster recovery is the technology slice: restoring systems, data and infrastructure after a failure. Business continuity is the whole business: keeping critical activities running, or restoring them fast enough, whatever the cause of disruption, including people, premises, suppliers and communications. A disaster recovery plan is one component of a business continuity management system, not a substitute for it.
How long does ISO 22301 certification take?
Typically four to eight months for a small or medium organisation, and faster if you already run ISO/IEC 27001, since the management system machinery is shared. The business impact analysis and the first exercise cycle are usually the pacing items, because they involve your people, not just documents.
How much does ISO 22301 certification cost?
Consultancy costs are broadly comparable to ISO/IEC 27001 implementations, and materially lower if you are extending an existing certified management system. The certification body's audit fees are separate and quoted by them. We work fixed-scope and fixed-price: one number after a scoping conversation, before you commit. If the scope changes mid-engagement, the price is re-agreed with you before any extra work happens, never discovered on an invoice.
Is ISO 22301 required by law?
No, certification is voluntary. But resilience obligations are tightening: financial services face rules such as the European Union's Digital Operational Resilience Act (DORA), and critical sectors face the NIS2 directive on network and information security. ISO 22301 does not replace those legal obligations, but it builds the continuity capability and evidence they rest on.
We already have a continuity plan. Why is that not enough?
A plan nobody has exercised, that was written for the business as it looked three years ago, fails exactly when you need it. The standard's value is the system around the plan: current impact analysis, rehearsed people, audited arrangements and a review cycle that keeps everything alive. That difference is what an auditor, an insurer or a customer is really checking for.
Who issues the certificate?
An independent accredited certification body, after a two-stage audit. We never certify our own work. We prepare you for the certification audit, help you choose a certification body, and help you engage an independent auditor for the internal audits the standard requires.
How often should we exercise the plans?
A full scenario exercise at least annually, with lighter walkthroughs whenever plans, people or systems change significantly. The standard expects an exercise programme rather than a one-off, and the debrief matters as much as the exercise itself: every run produces improvements, which is what an auditor wants to see and, more importantly, what makes the real incident survivable.
Can you help us build continuity capability without going for certification?
Yes. Certification is the right goal when customers or tenders ask for it; robust, exercised plans are the right goal always. We deliver the same discipline either way, using the standard as the benchmark, and you can add the certification step later: the work already done is the head start.