ISO 22301:2019
ISO 22301:2019 Business Continuity Management Systems Requirements.
ISO 22301:2019 is a compliance framework from International with 7 domains and 57 controls that map to 126 other frameworks. The largest domains are Operation, ISO 22301:2019 (19 controls), Context of the organization, ISO 22301:2019 (8 controls), Performance evaluation, ISO 22301:2019 (8 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Context of the organization, ISO 22301:2019
| Code | Title |
|---|---|
| iso-22301-2019::4.1 | Understanding the organization and its context |
| iso-22301-2019::4.2 | Understanding the needs and expectations of interested parties |
| iso-22301-2019::4.2.1 | General |
| iso-22301-2019::4.2.2 | Legal and regulatory requirements |
| iso-22301-2019::4.3 | Determining the scope of the business continuity management system |
| iso-22301-2019::4.3.1 | General |
| iso-22301-2019::4.3.2 | Scope of the business continuity management system |
| iso-22301-2019::4.4 | Business continuity management system |
Improvement, ISO 22301:2019
| Code | Title |
|---|---|
| iso-22301-2019::10.1 | Nonconformity and corrective action |
| iso-22301-2019::10.2 | Continual improvement |
Leadership, ISO 22301:2019
| Code | Title |
|---|---|
| iso-22301-2019::5.1 | Leadership and commitment |
| iso-22301-2019::5.2 | Policy |
| iso-22301-2019::5.2.1 | Establishing the business continuity policy |
| iso-22301-2019::5.2.2 | Communicating the business continuity policy |
| iso-22301-2019::5.3 | Roles, responsibilities and authorities |
Operation, ISO 22301:2019
| Code | Title |
|---|---|
| iso-22301-2019::8.1 | Operational planning and control |
| iso-22301-2019::8.2 | Business impact analysis and risk assessment |
| iso-22301-2019::8.2.1 | General |
| iso-22301-2019::8.2.2 | Business impact analysis |
| iso-22301-2019::8.2.3 | Risk assessment |
| iso-22301-2019::8.3 | Business continuity strategies and solutions |
| iso-22301-2019::8.3.1 | General |
| iso-22301-2019::8.3.2 | Identification of strategies and solutions |
| iso-22301-2019::8.3.3 | Selection of strategies and solutions |
| iso-22301-2019::8.3.4 | Resource requirements |
| iso-22301-2019::8.3.5 | Implementation of solutions |
| iso-22301-2019::8.4 | Business continuity plans and procedures |
| iso-22301-2019::8.4.1 | General |
| iso-22301-2019::8.4.2 | Response structure |
| iso-22301-2019::8.4.3 | Warning and communication |
| iso-22301-2019::8.4.4 | Business continuity plans |
| iso-22301-2019::8.4.5 | Recovery |
| iso-22301-2019::8.5 | Exercise programme |
| iso-22301-2019::8.6 | Evaluation of business continuity documentation and capabilities |
Performance evaluation, ISO 22301:2019
| Code | Title |
|---|---|
| iso-22301-2019::9.1 | Monitoring, measurement, analysis and evaluation |
| iso-22301-2019::9.2 | Internal audit |
| iso-22301-2019::9.2.1 | General |
| iso-22301-2019::9.2.2 | Audit programme(s) |
| iso-22301-2019::9.3 | Management review |
| iso-22301-2019::9.3.1 | General |
| iso-22301-2019::9.3.2 | Management review input |
| iso-22301-2019::9.3.3 | Management review outputs |
Planning, ISO 22301:2019
| Code | Title |
|---|---|
| iso-22301-2019::6.1 | Actions to address risks and opportunities |
| iso-22301-2019::6.1.1 | Determining risks and opportunities |
| iso-22301-2019::6.1.2 | Addressing risks and opportunities |
| iso-22301-2019::6.2 | Business continuity objectives and planning to achieve them |
| iso-22301-2019::6.2.1 | Establishing business continuity objectives |
| iso-22301-2019::6.2.2 | Determining business continuity objectives |
| iso-22301-2019::6.3 | Planning changes to the business continuity management system |
Support, ISO 22301:2019
| Code | Title |
|---|---|
| iso-22301-2019::7.1 | Resources |
| iso-22301-2019::7.2 | Competence |
| iso-22301-2019::7.3 | Awareness |
| iso-22301-2019::7.4 | Communication |
| iso-22301-2019::7.5 | Documented information |
| iso-22301-2019::7.5.1 | General |
| iso-22301-2019::7.5.2 | Creating and updating |
| iso-22301-2019::7.5.3 | Control of documented information |
Your Compliance Coverage
If you comply with ISO 22301:2019, you already cover:
NIST SP 800-161 Rev 1
98%
56 controls mapped
Compare →SOC 2
98%
56 controls mapped
Compare →NIST Cybersecurity Framework 2.0
96%
55 controls mapped
Compare →+ 123 more: NIST SP 800-53 Rev 5 (93%), ISO 27002:2022 (89%)
See all 126 mapped frameworks ↓Maps to 126 other frameworks
What is ISO 22301:2019 and who does it apply to?
ISO 22301:2019 is a compliance framework from International with 7 domains and 57 controls. ISO 22301:2019 Business Continuity Management Systems Requirements. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO 22301:2019 actually require?
ISO 22301:2019 has 57 controls organised across 7 domains. The largest domains are Operation, ISO 22301:2019 (19 controls), Context of the organization, ISO 22301:2019 (8 controls), Performance evaluation, ISO 22301:2019 (8 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO 22301:2019 do I already cover?
ISO 22301:2019 maps to 126 other compliance frameworks. The top mapping partners are NIST SP 800-161 Rev 1 (98% coverage), SOC 2 (98% coverage), NIST Cybersecurity Framework 2.0 (96% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement ISO 22301:2019?
Start your ISO 22301:2019 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 22301:2019 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 57 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required