Compliance
ISO 22301
ISO 22301 business continuity management system
ISO 22301 is the international standard for a business continuity management system (BCMS). It specifies requirements for planning, establishing, implementing, operating, monitoring, and continually improving an organisation's capability to keep critical business functions running, or to recover them within an agreed timeframe, when disruptive incidents occur.
Why ISO 22301 matters in a Microsoft estate
ISO 22301 matters because customers, resellers, and procurement teams need evidence that controls are defined, operated, and reviewable. A useful glossary definition should help a reader connect the term to audit preparation, policy work, or repeatable assurance activity.
How ISO 22301 shows up in practice
Those incidents can include a cyber attack, a data centre outage, a supplier failure, a pandemic, or a physical incident affecting premises or staff. The standard's central discipline is the business impact analysis (BIA). It forces the organisation to identify its time-critical activities, quantify the maximum tolerable period of disruption for each, and set a recovery time objective (RTO) and recovery point objective (RPO) accordingly. All of this then drives the actual continuity and disaster recovery plans, resourcing decisions, and testing schedule, rather than starting from the plans themselves. A BCMS built to ISO 22301 requires evidence of regular exercising, ranging from tabletop walkthroughs to full simulated failovers.
This is because an untested continuity plan is treated by auditors as unproven rather than merely unlikely to work. The standard explicitly requires post-exercise and post-incident lessons-learned to feed back into plan revisions. For organisations running significant workloads in Microsoft 365 and Azure, ISO 22301 scope inevitably intersects with cloud dependency risk. A BIA has to account for what happens when Exchange Online, SharePoint, Teams, or an Azure region becomes unavailable. A mature BCMS will document the organisation's reliance on Microsoft's own service health and shared-responsibility model, its use of Microsoft 365 Backup or third-party backup for Exchange, SharePoint, and OneDrive data, and realistic tenant-level recovery procedures. This matters because Microsoft's platform-level resilience does not itself constitute the customer's business continuity plan for its own data and processes.
Certification follows the same three-year cycle with annual surveillance audits as other ISO management system standards. Because ISO 22301 shares Annex SL structure with ISO 9001 and ISO/IEC 27001, organisations already certified to one of those often extend an existing integrated management system rather than building a continuity programme from scratch. It is increasingly requested in supplier due diligence and cyber insurance underwriting for organisations providing services deemed operationally critical to their customers, such as MSPs managing a client's core Microsoft 365 tenant or Azure infrastructure. This is because a customer's own regulatory obligations, particularly in financial services under operational resilience regimes, effectively require assurance that their critical suppliers can withstand and recover from disruption.