Free checklist

The ISO 22301 readiness checklist for growing companies

Forty-two plain-English checks covering what an ISO 22301 auditor will look at, from the business impact analysis through continuity strategies, plans, exercises and the audit itself. Written for companies without a resilience department.

Get the checklist

Enter your name and work email and your personal copy of the checklist activates right here, ready to tick off and print. Your progress saves as you go and is shared with us, so any follow-up starts from where you actually are. No mailing list.

Tick items off as you go: your progress saves automatically and helps us tailor any follow-up conversation. Anything you cannot tick is a conversation worth having.

1. Scope and context

Continuity starts with knowing which interruptions actually hurt.

2. Leadership and policy

Plans written by one person and read by nobody fail their first real test.

3. Business impact analysis

The BIA is to ISO 22301 what the risk assessment is to ISO 27001: the engine.

4. Risk assessment

What could take you down, and what you decided to do about it.

5. Continuity strategies and solutions

A strategy per prioritised activity, proportionate to how fast it must return.

6. Plans and procedures

Written for the person on duty at two in the morning, not for the author.

7. Exercising and testing

The clause auditors probe hardest, because untested plans are fiction.

8. Monitoring, internal audit and management review

The clauses that prove the BCMS runs, rather than merely exists.

9. Certification audit preparation

What makes the certification body's visit boring, which is the goal.

What to do with the gaps

Anything unticked is normal: that is what a gap analysis is for. If you want a prioritised, fixed-price plan for closing them, book a free introductory call or try the cost calculator to get a tailored estimate. The ISO 22301 consultancy page explains how we work.