Answer the Question Every Buyer Now Asks
What happens when you go down? ISO 22301 certifies that you have a tested answer rather than an optimistic one.
Outages, ransomware, supplier failures and infrastructure incidents have made continuity a procurement question rather than an IT one. Enterprise buyers and regulators increasingly want evidence that critical services can be recovered within a defined time — and they want it independently audited.
ISO 22301 works backwards from consequence. You determine which activities genuinely matter, how long they can be unavailable before real damage occurs, and what has to be in place to recover inside that window. Recovery time and recovery point objectives stop being guesses and become commitments you have tested.
- Recovery objectives that are tested
- Evidence for procurement and regulators
- Plans your team has rehearsed
- Stage 1 and Stage 2 support
- Standard
- ISO 22301:2019
- Typical timeline
- 4–10 months
- Certificate valid
- 3 years
- Core outputs
- BIA, RTO/RPO, tested plans
Clauses that define the system
Objectives set per activity: RTO & RPO
Years a certificate lasts
Surveillance audits in between
ISO 22301:2019 — the standard, not the sales pitch
Everyone Has a Plan Until It Is Tested
Continuity moved from an IT concern to a procurement question the moment buyers started depending on suppliers they cannot see inside.
A plan nobody has exercised
The document exists. It names people who have left, systems that were replaced, and a recovery time nobody has ever attempted. It has never been tested under any conditions.
False confidence, discovered at the worst moment
Dependencies nobody mapped
The critical process depends on a spreadsheet, a single supplier, or one person's knowledge. Nobody noticed, because it has never failed on a day when it mattered.
A single point of failure you cannot name
Commitments you cannot meet
Contracts promise availability and recovery times. Nobody has checked whether the architecture can actually deliver them, which makes them liabilities rather than assurances.
Contractual exposure, already signed
Continuity That Has Actually Been Tested
An untested continuity plan is a document, not a capability. The exercising stage is where most of the value is found — and most of the surprises.
01 / 09
Scope & Context
Which services the certificate covers.
We define the products and services in scope and identify the interested parties whose continuity expectations matter — customers with contractual service commitments, regulators, and your own operations.
What the Next Few Months Actually Look Like
Ranges, not a single number. Where you land inside them depends almost entirely on what already exists on day one.
- Phase 01
Week 0 · free
Gap analysis
We assess what you already do against the standard and hand back a prioritised plan with effort and dates against every gap. You keep it whether or not you continue with us.
We doAssess, document, price the work
You doA few hours of interviews
- Phase 02
Weeks 1–3
Scope, risk and the paper foundation
Certification scope agreed, risk methodology set, and the mandatory documents drafted — including the Statement of Applicability, the document auditors scrutinise hardest.
We doDraft everything, run the risk workshops
You doDecisions on scope and risk appetite
- Phase 03
Weeks 3–12
Implementing the controls
The longest phase and the one that varies most. Controls are built into your real systems rather than described in a document, with our engineers working alongside yours where the gaps are technical.
We doBuild, configure, evidence
You doAccess, and engineering time where unavoidable
- Phase 04
Concurrent
Training and awareness
Role-based training so the people an auditor interviews can answer confidently, plus a mock interview session so nobody meets these questions for the first time in the room.
We doDeliver training, run the dry run
You doGet your team in the room
- Phase 05
Min. 3 months in
Operate, internal audit, management review
The system must run long enough to produce real evidence — certification bodies generally expect around three months of operation before Stage 2. We run the mandatory internal audit and management review and close what they raise.
We doInternal audit, review, remediation
You doLeadership attendance at the review
- Phase 06
Then 30–60 days
Stage 1, Stage 2, certificate
Stage 1 reviews documentation and readiness. Stage 2, typically 30 to 60 days later, tests whether you genuinely operate the system. We prepare the evidence pack and attend both with you.
We doPrepare evidence, manage the auditor, handle findings
You doBe available for interviews
Where you land in the range depends on your starting point, your scope, and how much evidence already exists. Anyone quoting a fixed number of weeks before seeing your estate is guessing.
How We Run an ISO 22301 Programme
Continuity is a capability, not a document.
Scope & Gap
Which services are covered and what already exists.
Impact Analysis
Critical activities, dependencies and time-based impact.
Set Objectives
RTO and RPO agreed and checked against reality.
Design & Document
Strategies and plans that can be followed under pressure.
Exercise
Tested for real, and revised from what it exposes.
Certify
Stage 1, Stage 2, certificate — then surveillance.
THEN BACK TO 01 — EXERCISE, LEARN, REVISE
Where Resilience Is Being Audited
Wherever an outage in your service becomes an outage in your customer's service, someone is going to ask for evidence rather than assurance.
SaaS & Technology
Where enterprise security review is the single biggest drag on the sales cycle, and ISO 27001 is asked for by name.
Financial Services
Banking, payments and fintech, where supplier assurance is a regulatory expectation rather than a preference.
Health & Life Sciences
Patient and trial data carries obligations that buyers will not take on trust from an unaudited supplier.
Public Sector & Defence
Frameworks and tenders that list certification as a pass-or-fail eligibility criterion before scoring begins.
Retail & E-Commerce
Payment data, large supply chains, and sustainability criteria appearing in more and more supplier scorecards.
Professional & Legal
Client confidentiality, continuity obligations, and the quality assurance that panel appointments increasingly require.
Working across
ISO 22301 Is For You If This Is True
Tick what applies.
00 OF 06
Worth understanding before an incident forces the issue.
Fixed Scope. Fixed Fee. No Surprises.
Compliance consultancy has a reputation for open-ended day rates and a bill that grows with the project. We price the work after the gap analysis, when both of us know what it involves.
What you get
- A free gap analysis before you commit to anything
- A fixed implementation fee, quoted once the scope is known
- Senior consultants doing the work, not supervising juniors
- Documentation written for your business, never a template pack
- We attend Stage 1 and Stage 2 with you
- Support through the surveillance years, not just to the certificate
What we will not do
- Sell you a certificate — an accredited body issues that, independently
- Bill by the hour for work we should have scoped properly
- Promise certification in a number of weeks the standard does not allow
- Hand over a policy binder and disappear before the audit
- Take commission for recommending a certification body
- Claim an ISO certificate makes you compliant with a law it does not cover
We implement. An accredited body certifies.
ISO/IEC 17021-1 requires the certifying body to be independent of the consultancy that designed your management system. We build the continuity management system and run the exercises; an accredited certification body audits it and issues the certificate.
- We build the BIA, the strategies, the plans and the exercise programme
- An independent accredited certification body audits and certifies you
- We help you select that body at no markup
- Accredited certification is what regulators and enterprise procurement expect to see
Plans Built By People Who Run Production Systems
We operate infrastructure ourselves. Recovery objectives are only credible when someone has checked whether the architecture can actually meet them.
Recovery objectives checked against architecture◆Plans written for 3am◆Exercises that find real gaps◆Integrates with ISO 27001◆We stay for surveillance
WE DO NOT WRITE PLANS NOBODY TESTS
Trusted by startups, enterprises, and governments worldwide










































































































The stack behind the platforms we build.
We choose tools for the outcome they deliver, not for the trend they follow.
Frontend
8 tools“Knowledgeable, professional, and responsive — Devtrios added real value at every step of our project and delivered exactly what we needed.”
Where Our Clients Rate Us 5 Stars
Our clients don't just work with us, they recommend us — 4.9 on Google, 5.0 on Clutch and GoodFirms. Every badge below links straight to the profile it comes from. Independent reviews keep pointing to the same three things: strong technical expertise, clear communication, and delivery you can rely on.
Recognised on
Verified reviewsFrequently Asked Questions
Everything you might want to know before we talk. Still unsure? A quick call clears it up.
Ask us anythingDisaster recovery is a subset. DR typically addresses restoring IT systems and data after a technical failure. ISO 22301 covers the continuity of the business itself — people, premises, suppliers, communications and processes, as well as technology. A company can have excellent IT failover and still be unable to operate because nobody defined who makes decisions, how customers are told, or how work continues while systems are down.
Recovery time objective is how quickly a critical activity must be restored before the impact becomes unacceptable. Recovery point objective is how much data loss is tolerable, expressed as a time window — an RPO of one hour means losing at most an hour of data. Both come out of the business impact analysis, and both should be validated against what your architecture can genuinely deliver. A stated RTO that the infrastructure cannot meet is worse than having none, because it appears in contracts.
Typically four to ten months. The business impact analysis usually takes longest, because it requires input from across the business rather than from IT alone. Exercising also has to be scheduled and completed before certification, since the auditor will want evidence that plans have been tested rather than merely written.
Yes, and the overlap is substantial. ISO 27001's Annex A already requires ICT readiness for business continuity, so organisations holding it have part of the groundwork in place. Both share the harmonised management system structure, so context, leadership, competence, internal audit and management review are common. Combined audits are routine.
The standard requires exercising and testing, but it does not mandate a specific form for every exercise. A proportionate programme usually mixes tabletop exercises, walkthroughs of specific plans, and technical tests of critical recovery capability. What is not acceptable is a plan that has never been tested in any form — that is a reliable audit finding, and more importantly it is how organisations discover undocumented dependencies during a real incident.
Certification body fees for an SME are typically a few thousand pounds in year one with lower surveillance fees after. Implementation depends on the number of critical services in scope and how much analysis already exists. The business impact analysis is the largest single piece of work. We fix our implementation fee after the gap analysis.
Find out whether your plan would hold
The gap analysis reviews what continuity capability you actually have, where the untested assumptions are, and what certification would involve. At no cost.
Start Your Next Project with Devtrios
Tell us about your idea or business needs. Our team will review your requirements and get back to you within one business day with a clear plan, timeline, and a free consultation call.



