Skip to content
DevTrios — Engineering Partner
ISO 22301:2019

Answer the Question Every Buyer Now Asks

What happens when you go down? ISO 22301 certifies that you have a tested answer rather than an optimistic one.

Outages, ransomware, supplier failures and infrastructure incidents have made continuity a procurement question rather than an IT one. Enterprise buyers and regulators increasingly want evidence that critical services can be recovered within a defined time — and they want it independently audited.

ISO 22301 works backwards from consequence. You determine which activities genuinely matter, how long they can be unavailable before real damage occurs, and what has to be in place to recover inside that window. Recovery time and recovery point objectives stop being guesses and become commitments you have tested.

  • Recovery objectives that are tested
  • Evidence for procurement and regulators
  • Plans your team has rehearsed
  • Stage 1 and Stage 2 support
DisruptionWithout a planWith ISO 22301RECOVERY TIME OBJECTIVENormalDown
Standard
ISO 22301:2019
Typical timeline
4–10 months
Certificate valid
3 years
Core outputs
BIA, RTO/RPO, tested plans
0

Clauses that define the system

0

Objectives set per activity: RTO & RPO

0

Years a certificate lasts

0

Surveillance audits in between

ISO 22301:2019 — the standard, not the sales pitch

Why this lands on your desk

Everyone Has a Plan Until It Is Tested

Continuity moved from an IT concern to a procurement question the moment buyers started depending on suppliers they cannot see inside.

A plan nobody has exercised

The document exists. It names people who have left, systems that were replaced, and a recovery time nobody has ever attempted. It has never been tested under any conditions.

False confidence, discovered at the worst moment

Dependencies nobody mapped

The critical process depends on a spreadsheet, a single supplier, or one person's knowledge. Nobody noticed, because it has never failed on a day when it mattered.

A single point of failure you cannot name

Commitments you cannot meet

Contracts promise availability and recovery times. Nobody has checked whether the architecture can actually deliver them, which makes them liabilities rather than assurances.

Contractual exposure, already signed

What ISO 22301 involves

Continuity That Has Actually Been Tested

An untested continuity plan is a document, not a capability. The exercising stage is where most of the value is found — and most of the surprises.

IN SCOPEProduct platformCustomer dataEngineeringCloud estateOut ofscopeA NARROW SCOPE THAT PASSES BEATS A WIDE ONE THAT STALLS

01 / 09

Scope & Context

Which services the certificate covers.

We define the products and services in scope and identify the interested parties whose continuity expectations matter — customers with contractual service commitments, regulators, and your own operations.

The roadmap

What the Next Few Months Actually Look Like

Ranges, not a single number. Where you land inside them depends almost entirely on what already exists on day one.

  1. Phase 01

    Week 0 · free

    Gap analysis

    We assess what you already do against the standard and hand back a prioritised plan with effort and dates against every gap. You keep it whether or not you continue with us.

    We doAssess, document, price the work

    You doA few hours of interviews

  2. Phase 02

    Weeks 1–3

    Scope, risk and the paper foundation

    Certification scope agreed, risk methodology set, and the mandatory documents drafted — including the Statement of Applicability, the document auditors scrutinise hardest.

    We doDraft everything, run the risk workshops

    You doDecisions on scope and risk appetite

  3. Phase 03

    Weeks 3–12

    Implementing the controls

    The longest phase and the one that varies most. Controls are built into your real systems rather than described in a document, with our engineers working alongside yours where the gaps are technical.

    We doBuild, configure, evidence

    You doAccess, and engineering time where unavoidable

  4. Phase 04

    Concurrent

    Training and awareness

    Role-based training so the people an auditor interviews can answer confidently, plus a mock interview session so nobody meets these questions for the first time in the room.

    We doDeliver training, run the dry run

    You doGet your team in the room

  5. Phase 05

    Min. 3 months in

    Operate, internal audit, management review

    The system must run long enough to produce real evidence — certification bodies generally expect around three months of operation before Stage 2. We run the mandatory internal audit and management review and close what they raise.

    We doInternal audit, review, remediation

    You doLeadership attendance at the review

  6. Phase 06

    Then 30–60 days

    Stage 1, Stage 2, certificate

    Stage 1 reviews documentation and readiness. Stage 2, typically 30 to 60 days later, tests whether you genuinely operate the system. We prepare the evidence pack and attend both with you.

    We doPrepare evidence, manage the auditor, handle findings

    You doBe available for interviews

Where you land in the range depends on your starting point, your scope, and how much evidence already exists. Anyone quoting a fixed number of weeks before seeing your estate is guessing.

How it runs

How We Run an ISO 22301 Programme

Continuity is a capability, not a document.

01

Scope & Gap

Which services are covered and what already exists.

02

Impact Analysis

Critical activities, dependencies and time-based impact.

03

Set Objectives

RTO and RPO agreed and checked against reality.

04

Design & Document

Strategies and plans that can be followed under pressure.

05

Exercise

Tested for real, and revised from what it exposes.

06

Certify

Stage 1, Stage 2, certificate — then surveillance.

THEN BACK TO 01 — EXERCISE, LEARN, REVISE

Industries

Where Resilience Is Being Audited

Wherever an outage in your service becomes an outage in your customer's service, someone is going to ask for evidence rather than assurance.

SaaS & Technology

Where enterprise security review is the single biggest drag on the sales cycle, and ISO 27001 is asked for by name.

Financial Services

Banking, payments and fintech, where supplier assurance is a regulatory expectation rather than a preference.

Health & Life Sciences

Patient and trial data carries obligations that buyers will not take on trust from an unaudited supplier.

Public Sector & Defence

Frameworks and tenders that list certification as a pass-or-fail eligibility criterion before scoring begins.

Retail & E-Commerce

Payment data, large supply chains, and sustainability criteria appearing in more and more supplier scorecards.

Professional & Legal

Client confidentiality, continuity obligations, and the quality assurance that panel appointments increasingly require.

Working across

United KingdomEuropean UnionUnited StatesUAE & GCCAustralia & NZRemote worldwide
Who it's for

ISO 22301 Is For You If This Is True

Tick what applies.

00 OF 06

Worth understanding before an incident forces the issue.

How we engage

Fixed Scope. Fixed Fee. No Surprises.

Compliance consultancy has a reputation for open-ended day rates and a bill that grows with the project. We price the work after the gap analysis, when both of us know what it involves.

What you get

  • A free gap analysis before you commit to anything
  • A fixed implementation fee, quoted once the scope is known
  • Senior consultants doing the work, not supervising juniors
  • Documentation written for your business, never a template pack
  • We attend Stage 1 and Stage 2 with you
  • Support through the surveillance years, not just to the certificate

What we will not do

  • Sell you a certificate — an accredited body issues that, independently
  • Bill by the hour for work we should have scoped properly
  • Promise certification in a number of weeks the standard does not allow
  • Hand over a policy binder and disappear before the audit
  • Take commission for recommending a certification body
  • Claim an ISO certificate makes you compliant with a law it does not cover

We implement. An accredited body certifies.

ISO/IEC 17021-1 requires the certifying body to be independent of the consultancy that designed your management system. We build the continuity management system and run the exercises; an accredited certification body audits it and issues the certificate.

  • We build the BIA, the strategies, the plans and the exercise programme
  • An independent accredited certification body audits and certifies you
  • We help you select that body at no markup
  • Accredited certification is what regulators and enterprise procurement expect to see
Why Devtrios

Plans Built By People Who Run Production Systems

We operate infrastructure ourselves. Recovery objectives are only credible when someone has checked whether the architecture can actually meet them.

Recovery objectives checked against architecturePlans written for 3amExercises that find real gapsIntegrates with ISO 27001We stay for surveillance

WE DO NOT WRITE PLANS NOBODY TESTS

AnalyseExerciseCertify

Trusted by startups, enterprises, and governments worldwide

Technology Stack

The stack behind the platforms we build.

We choose tools for the outcome they deliver, not for the trend they follow.

Frontend

8 tools
React
Next.js
TypeScript
Tailwind CSS
Vue.js
Angular
Sass
Vite
Based on 0+ verified client reviews
4.9/ 5.0
4.9 on Google, 5.0 on Clutch and GoodFirms
0%
Client Satisfaction
0+
Verified Reviews
0%
Client Retention

“Knowledgeable, professional, and responsive — Devtrios added real value at every step of our project and delivered exactly what we needed.”

C
Connie Woo
Founder, Fintech Startup
Ratings & Reviews

Where Our Clients Rate Us 5 Stars

Our clients don't just work with us, they recommend us — 4.9 on Google, 5.0 on Clutch and GoodFirms. Every badge below links straight to the profile it comes from. Independent reviews keep pointing to the same three things: strong technical expertise, clear communication, and delivery you can rely on.

Recognised on

Verified reviews
Our Services
FAQ

Frequently Asked Questions

Everything you might want to know before we talk. Still unsure? A quick call clears it up.

Ask us anything

Disaster recovery is a subset. DR typically addresses restoring IT systems and data after a technical failure. ISO 22301 covers the continuity of the business itself — people, premises, suppliers, communications and processes, as well as technology. A company can have excellent IT failover and still be unable to operate because nobody defined who makes decisions, how customers are told, or how work continues while systems are down.

Recovery time objective is how quickly a critical activity must be restored before the impact becomes unacceptable. Recovery point objective is how much data loss is tolerable, expressed as a time window — an RPO of one hour means losing at most an hour of data. Both come out of the business impact analysis, and both should be validated against what your architecture can genuinely deliver. A stated RTO that the infrastructure cannot meet is worse than having none, because it appears in contracts.

Typically four to ten months. The business impact analysis usually takes longest, because it requires input from across the business rather than from IT alone. Exercising also has to be scheduled and completed before certification, since the auditor will want evidence that plans have been tested rather than merely written.

Yes, and the overlap is substantial. ISO 27001's Annex A already requires ICT readiness for business continuity, so organisations holding it have part of the groundwork in place. Both share the harmonised management system structure, so context, leadership, competence, internal audit and management review are common. Combined audits are routine.

The standard requires exercising and testing, but it does not mandate a specific form for every exercise. A proportionate programme usually mixes tabletop exercises, walkthroughs of specific plans, and technical tests of critical recovery capability. What is not acceptable is a plan that has never been tested in any form — that is a reliable audit finding, and more importantly it is how organisations discover undocumented dependencies during a real incident.

Certification body fees for an SME are typically a few thousand pounds in year one with lower surveillance fees after. Implementation depends on the number of critical services in scope and how much analysis already exists. The business impact analysis is the largest single piece of work. We fix our implementation fee after the gap analysis.

Free gap analysis

Find out whether your plan would hold

The gap analysis reviews what continuity capability you actually have, where the untested assumptions are, and what certification would involve. At no cost.

Contact

Start Your Next Project with Devtrios

Tell us about your idea or business needs. Our team will review your requirements and get back to you within one business day with a clear plan, timeline, and a free consultation call.

Contact Information
info@devtrios.com+44 7470 801776
Avenue Road, SE25 4DX, London, United Kingdom
Connect With Us

Let's Discuss Your Project