ISO 22301 as a working programme

Enable ISO 22301 and its 25 controls, clauses 4 to 10, recur with an owner, a due date, a description, a recommendation and a default cadence: 20 yearly, 4 quarterly and 1 half-yearly.

ClauseControlDefault cadence
8.2.1Business impact analysis: priorities, dependencies and resource requirementsYearly
8.2.2Risk assessment of disruptionYearly
8.3Business continuity strategies and solutionsYearly
8.4Business continuity plans and proceduresYearly
8.5Exercise programme: an annual tabletop at minimum and a live test of one critical service a yearYearly
8.6Evaluation of business continuity documentation and capabilitiesYearly
9.1Monitoring, measurement, analysis and evaluationEvery 6 months
9.2 / 9.3Internal audit and management review of the BCMSYearly
5.1, 6.3, 10.1, 10.2Leadership, planning of changes, nonconformity and corrective action, continual improvementQuarterly

ISO 22301 is included from Pro (€99 a month), next to up to four other frameworks.

Continuity controls in your other frameworks

ISO 27001 A.5.29 and A.5.30Information security during disruption and ICT readiness for business continuity.
ISO 27001 A.8.13 and A.8.14Information backup and redundancy of information processing facilities.
NIS2 Art. 21(2)(c)Business continuity, backup management, disaster recovery and crisis management.
DORA Art. 11 and 12Response and recovery; backup, restoration and recovery procedures.

The incident register and its clocks

AreaWhat is recorded
Classification12 types (data breach, account takeover, ransomware, DDoS, phishing, insider, vendor, system failure, misconfiguration, lost device, physical, other) and 4 severities
PhasesInvestigating, contained, resolved, closed, with timestamps for detection, containment, eradication and resolution
TimelineEntries of type note, update, containment, communication, evidence and decision, each with who and when
ClocksGDPR Art. 33: notify within 72 hours of awareness. NIS2 Art. 23: early warning in 24 hours, notification in 72 hours, final report in one month
NotificationAuthority, report date and case reference, data subjects notified, and the Art. 33(3) fields: DPO contact, likely consequences, measures taken
LearningRoot cause, mitigation, lessons learned, forensic preservation note and the linked corrective-action task
  • The NIS2 significant-incident checker (Implementing Regulation (EU) 2024/2690) evaluates the answers against your entity type and turnover and stores the outcome with the incident.
  • The dashboard shows incidents by severity and the share of personal-data breaches reported within 72 hours over the last 12 months.
  • Running clocks appear in the "What needs you now" list with the time left or the time over.
  • On Enterprise, a public breach-report portal lets anyone report without an account; reports wait in a queue until an admin approves them into the register.

Plans, tests and policies on record

  • The compliance profile holds the links to your BC/DR plan, BIA and incident runbook, and the dates of the last BC/DR test and backup-restore test.
  • Prepare for Audit flags a BC/DR test or backup-restore test older than 12 months, a missing BC policy or BIA, and a missing exercise programme, BCMS audit or management review (Enterprise).
  • Policies have a business continuity category, versions, an approval step and staff acknowledgement; starter templates cover incident response and backup.
  • Critical suppliers sit in the vendor register with data access, review dates and contract-expiry alerts; systems in the asset inventory with owner, criticality and classification (Pro and Enterprise).