Home › Frameworks › ISO 22301

ISO 22301 compliance software for business continuity.

The ISO 22301 clauses as 25 recurring controls with evidence: business impact analysis, continuity strategies, plans, the exercise programme, internal audit and management review. Included from Pro, €99 a month.

At a glance

  • Clause 4: Context of the organisation: scope, interested parties, dependencies.
  • Clause 6: Planning: BIA, risk assessment, business continuity strategy and solutions.
  • Clause 8: Operation: BCP documentation, incident response procedures, communication, exercise programme.
  • Clause 9: Performance evaluation: monitoring, internal audit, management review.

On this page

  1. What is ISO 22301?
  2. Who needs to comply
  3. Key ISO 22301 controls covered by Dazr
  4. What auditors look for
  5. How Dazr helps with ISO 22301

What is ISO 22301?

ISO 22301:2019 (Business Continuity Management Systems). Any organisation whose customers, regulators or board demand provable business continuity: financial services, healthcare, utilities, manufacturing, B2B SaaS, ICT third parties.

Who needs to comply

  • Financial services and fintech (often combined with DORA)
  • Healthcare providers (often combined with NEN 7510 or HIPAA-equivalent)
  • Critical infrastructure: energy, water, transport
  • B2B SaaS with strict customer SLAs
  • ICT third parties supporting regulated entities

Key ISO 22301 controls covered by Dazr

Clause 4Context of the organisation: scope, interested parties, dependencies.
Clause 6Planning: BIA, risk assessment, business continuity strategy and solutions.
Clause 8Operation: BCP documentation, incident response procedures, communication, exercise programme.
Clause 9Performance evaluation: monitoring, internal audit, management review.
Clause 10Improvement: nonconformity, corrective action, continual improvement.

What auditors look for

ISO 22301 auditors sample three things: a current BIA with RTO and RPO per process, a BCP that has actually been tested in the past 12 months with documented findings, and management-review evidence. Dazr holds the cadence.

How Dazr helps with ISO 22301

Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. ISO 22301 is one of its eleven frameworks, included from Pro, €99 a month. In practice that means:

  • Link the business impact analysis, with RTO and RPO per process, and review it on cadence
  • Track BCP and DR test exercises as recurring controls with documented findings
  • Record critical suppliers in the vendor register with review and contract-expiry dates (Pro and Enterprise)
  • Log disruptions in the incident register alongside security incidents, with timestamps and lessons learned
  • Hand the auditor or supervisor a read-only view of the entire continuity programme

Back to the full Dazr Compliance overview › | Sign up free ›

ISO 22301 questions, answered.

How does ISO 22301 differ from ISO 27001?

ISO 27001 is information security; ISO 22301 is business continuity. They share clauses 4-10 management-system requirements, so a lot of governance evidence is shared. Dazr lets you enable both; the same management review covers both.

Do we need to test the BCP every year?

ISO 22301 requires that the BCP is exercised at intervals appropriate to the organisation; in practice most certifying bodies expect an annual full-scope exercise plus targeted tabletops. Dazr tracks the cadence and the evidence.

Does Dazr generate the BCP for us?

No. The BCP is your document. Dazr links to it and tracks the review cadence, exercise programme and incident activation history.

Where is data hosted?

European Union only. Workspace records are encrypted at rest with AES-256-GCM at the application layer; uploaded evidence files rely on the storage provider's at-rest encryption. Italian entity, EU jurisdiction.

Ready to start your ISO 22301 program?

ISO 22301 is included in Pro (€99/mo, up to five frameworks and five users) and Enterprise (€499/mo); self-serve via Mollie, excl. VAT, cancel any time. Free and Basic cover ISO 27001, GDPR and NIS2. Custom is the only tier on a contract, priced on request.