Free checklist
The ISO 22301 readiness checklist for growing companies
Forty-two plain-English checks covering what an ISO 22301 auditor will look at, from the business impact analysis through continuity strategies, plans, exercises and the audit itself. Written for companies without a resilience department.
Tick items off as you go: your progress saves automatically and helps us tailor any follow-up conversation. Anything you cannot tick is a conversation worth having.
1. Scope and context
Continuity starts with knowing which interruptions actually hurt.
2. Leadership and policy
Plans written by one person and read by nobody fail their first real test.
3. Business impact analysis
The BIA is to ISO 22301 what the risk assessment is to ISO 27001: the engine.
4. Risk assessment
What could take you down, and what you decided to do about it.
5. Continuity strategies and solutions
A strategy per prioritised activity, proportionate to how fast it must return.
6. Plans and procedures
Written for the person on duty at two in the morning, not for the author.
7. Exercising and testing
The clause auditors probe hardest, because untested plans are fiction.
8. Monitoring, internal audit and management review
The clauses that prove the BCMS runs, rather than merely exists.
9. Certification audit preparation
What makes the certification body's visit boring, which is the goal.
What to do with the gaps
Anything unticked is normal: that is what a gap analysis is for. If you want a prioritised, fixed-price plan for closing them, book a free introductory call or try the cost calculator to get a tailored estimate. The ISO 22301 consultancy page explains how we work.