What is ISO 22301?
ISO 22301:2019 is the international standard for a Business Continuity Management System (BCMS). It sets the requirements for identifying what an organisation must keep running, analysing the impact of disruption, selecting continuity strategies, documenting and exercising plans, and improving continuity capability over time. The standard is published by ISO and sits in the same Annex SL family as ISO 27001 and ISO 9001, so the management-system machinery is shared.
The technical core of the standard is the business impact analysis (BIA) — the disciplined exercise of establishing which activities are priority, how quickly each must be recovered (RTO), how much data loss is tolerable (RPO), and the maximum tolerable period of disruption (MTPD). Continuity strategies are selected to meet those objectives, not the other way around, and an exercise programme proves the plans work before a real disruption tests them for you.
Two things carry the ISO 22301 name in practice. An organisation certifies its BCMS through a Stage 1 / Stage 2 audit by an accredited certification body. An individual earns a PECB credential — Foundation, Lead Implementer, or Lead Auditor — that proves they can build or audit that system. This guide covers both, because in most Australian programmes the first step is training the person who will own the work.
Who needs ISO 22301 certification in Australia?
Business continuity moved from a shelved binder to a supervised obligation in Australia between 2022 and 2025. The audiences with a concrete reason to certify — or to train:
- APRA-regulated entities under CPS 230 — banks, insurers, and super funds must identify critical operations, set tolerance levels for disruption, and maintain tested continuity plans from 1 July 2025. ISO 22301 is the recognised method behind every one of those requirements.
- Critical-infrastructure operators under the SOCI Act — responsible entities across energy, water, transport, communications, health, and food must run a risk management program covering all hazards that could disrupt asset availability. A BCMS is the operational system behind that obligation.
- Risk, resilience, and GRC professionals — Business Continuity Manager, Resilience Manager, and Operational Risk roles are hiring across financial services, utilities, health, and government. The PECB Lead Implementer credential is the recognised qualification for that work, and it pairs naturally with ISO 31000 risk management.
- Any organisation exposed to natural disaster or cyber outage — bushfire, flood, and cyclone seasons are operational realities here, and a single ransomware event can take operations down for days. Continuity planning is how those exposures become recoverable rather than existential.
The shorthand: if a regulator supervises your continuity, if your customers cannot tolerate you being down for days, or if you want a career in resilience, ISO 22301 is the standard to build on.
Industries that need ISO 22301 in Australia
Four sectors generate most Australian ISO 22301 demand: APRA-regulated financial services, critical infrastructure under the SOCI Act, health and essential services, and technology businesses with concentrated supplier dependencies. The pressure arrives differently in each, but the answer is the same management system.
Financial services under APRA CPS 230
CPS 230 replaced the old CPS 232 continuity standard and raised the bar substantially: critical operations must be identified, tolerance levels for the maximum disruption to each must be set and board-approved, continuity plans must be credible and systematically tested, and material service providers must be managed for continuity risk. The mapping to ISO 22301 is direct — the BIA produces the critical-operations register and the recovery objectives the tolerance levels are set against, and the exercise programme is the testing regime APRA expects to see evidence of. Banks, insurers, superannuation trustees, and the fintechs that serve them are all hiring for exactly this skill set.
Critical infrastructure under the SOCI Act
The Security of Critical Infrastructure Act now covers eleven sectors — energy, water, communications, transport, health care, food and grocery, data storage, and more. Responsible entities must maintain a Critical Infrastructure Risk Management Program addressing all-hazards risks to asset availability, and report significant cyber incidents to the ACSC within 12 hours. A BCMS is the operational machinery behind the availability component of that program, and the incident and emergency response structures ISO 22301 requires are what make those reporting timelines achievable. Teams building this capability often pair the implementer track with incident response certification.
Health, utilities, and essential services
Service interruption in these sectors carries public consequence, not just commercial cost. Hospitals, pathology networks, aged care, water utilities, and local government all operate services where the recovery time objective is measured in hours and the community notices when it is missed. ISO 22301 gives these organisations a defensible, auditable basis for their recovery commitments — and gives the state regulators and departments that oversee them a recognised framework to assess against.
Technology and supplier-dependent organisations
Cloud concentration, single-source logistics, and managed service providers create failure points outside direct control. The 2024–25 run of major SaaS, telco, and payments outages made the lesson explicit: your continuity is only as good as your most fragile dependency. ISO 22301's continuity-strategy and supplier requirements are how those dependencies get planned for rather than discovered mid-incident. SaaS companies also find enterprise procurement increasingly asks for continuity evidence alongside ISO 27001 — the two certificates are frequently audited together.
Mapping ISO 22301 to Australian regulation
ISO 22301 is not Australian law, but it is the management-system structure most often used to satisfy Australian resilience obligations. The table summarises how the standard maps to the regulation Aegentra is most often asked about.
| Regulation or framework | What it requires | How ISO 22301 helps |
|---|---|---|
| APRA CPS 230 (from 1 July 2025) | Identify critical operations, set board-approved tolerance levels for disruption, maintain and systematically test continuity plans, manage material service provider risk. | The BIA produces the critical-operations register and the MTPD/RTO figures tolerance levels are set against. The exercise programme is the testing regime APRA expects evidence of. |
| SOCI Act (CIRMP obligations) | Responsible entities across eleven sectors must run an all-hazards Risk Management Program covering asset availability, and report significant cyber incidents to the ACSC within 12 hours (others within 72). | A BCMS is the operational system behind the availability component of the CIRMP. ISO 22301's incident and emergency response structures make the reporting timelines achievable. |
| ASIC licensee obligations (RG 104) | AFS licensees must maintain adequate risk management systems and resources, which ASIC reads to include continuity of critical business functions. | A documented, exercised BCMS is the standard evidence base for the continuity component of licensee risk management. |
| ISO 27001:2022 Annex A (5.29, 5.30) | Information security during disruption, and ICT readiness for business continuity — controls every certified ISMS must address. | ISO 22301 supplies the BIA and recovery objectives those controls assume exist. Combined ISMS + BCMS audits are common and cost-efficient. |
| Government procurement and the PSPF | Commonwealth and state tenders increasingly require suppliers of critical services to evidence continuity capability, not just assert it. | Certification is the accepted third-party evidence. A certificate scoped to the contracted service answers the tender question in one line. |
| Directors' duties (Corporations Act s 180) | Care and diligence obligations that governance guidance increasingly reads to include oversight of foreseeable operational and cyber disruption. | A board-endorsed, exercised BCMS is contemporaneous evidence that disruption risk was governed, not discovered. |
The pattern across all six items is the same: ISO 22301 is rarely a literal requirement, but it is almost always the most efficient documentary answer to a regulator, an auditor, or a procurement team that asks "show me your continuity capability."
How long does ISO 22301 certification take?
For an Australian SMB starting from scratch, the realistic plan is 12–16 weeks of readiness followed by the Stage 1 / Stage 2 audit. The long pole is the business impact analysis — it needs workshops across every business unit, and the recovery objectives it produces drive everything downstream. Rushing the BIA is the single most common cause of a continuity programme that fails its first real disruption.
If you already operate an ISO 27001 ISMS, plan 8–12 weeks. The Annex SL machinery — document control, internal audit, management review, corrective action — carries across, and your incident response capability gives the continuity plans a head start. Combined ISMS + BCMS surveillance audits then keep the ongoing cost down.
As with every certifiable standard, audit bookings need 6–10 weeks of lead time with Australian certification bodies. Book Stage 2 at the start of readiness, not the end.
How much does ISO 22301 certification cost in Australia?
Individual PECB training (Aegentra Academy)
- ISO 22301 Foundation — from $600 + GST
- ISO 22301 Lead Implementer — from $980 + GST
- ISO 22301 Lead Auditor — from $980 + GST
Every price includes the official PECB exam voucher, one free resit within 12 months, and 12 months of myPECB access — there is no separate exam fee. eLearning delivery (recorded lectures and scenario quizzes over the same material) is $80 more per course.
Organisational certification
Ranges are typical for an Australian SMB of 10–50 staff. An existing ISO 27001 ISMS pulls the readiness figure toward the bottom of the range because the management-system machinery is already in place.
| Component | Typical AUD | Frequency |
|---|---|---|
| Greenfield BCMS readiness | $30,000–$60,000 | Once |
| Add-on readiness (existing ISO 27001 ISMS) | $18,000–$35,000 | Once |
| Stage 1 + Stage 2 certification audit | $10,000–$20,000 | Once (every 3 years) |
| Annual surveillance | Starting at $2,500 | Year 1 + Year 2 |
| Three-year re-certification | $8,000–$16,000 | Year 3 |
The certification process, step-by-step
- 01Scope and context
Define which products, services, and sites the BCMS covers, who the interested parties are (regulators, customers, communities), and secure top-management commitment and the continuity policy.
- 02Business impact analysis
Workshop every business unit to establish priority activities, the impact of disruption over time, and the recovery objectives — RTO, RPO, and MTPD — for each. This register drives every later decision.
- 03Risk assessment
Assess the threats that could disrupt priority activities — natural hazard, cyber, supplier failure, people loss — and their likelihood and consequence. ISO 31000 methodology slots in directly here.
- 04Continuity strategies and solutions
Select strategies that meet the recovery objectives: alternate sites, cloud failover, manual workarounds, supplier redundancy, cross-trained staff. Cost each option against the MTPD it protects.
- 05Plans and procedures
Write the business continuity plans, incident response structure, and emergency response procedures. Separate artefacts, separate triggers — a plan nobody can find or follow at 2am is documentation, not capability.
- 06Exercise programme
Design and run exercises — from desktop walkthroughs to full simulations — and act on what they expose. ISO 22301 treats exercising as a requirement of the implementation, not an optional extra.
- 07Internal audit and management review
An independent reviewer audits the BCMS against every ISO 22301 requirement; leadership reviews performance, exercise results, and improvement actions. Both are mandatory before the certification body arrives.
- 08Stage 1 audit
Documentation review by an accredited certification body — scope, BIA, policy, plans, and exercise records. Typically 1–2 days, often remote. Gaps found here are corrected before Stage 2.
- 09Stage 2 audit and certificate
The effectiveness audit — evidence sampled against the standard, exercise records examined, staff interviewed. On a clean result the three-year certificate issues, with annual surveillance in years one and two.
Choosing a PECB ISO 22301 course
PECB structures ISO 22301 the same way as its other management-system schemes: Foundation (overview), Lead Implementer (the practitioner tier — the one your internal continuity owner needs), and Lead Auditor (for internal audit, assurance, and certification-body careers). All three are delivered Self-Study or eLearning, with instructor-led instructor-led organisational delivery scoped on request.
| Course | Best for | Effort and exam | Price (+ GST) |
|---|---|---|---|
| ISO 22301 Foundation | Anyone new to business continuity — the concepts, terminology, and BCMS requirements. 14 CPD credits, 200+ pages of material. | 10–15 hours self-paced. One-hour multiple-choice exam, two domains, 70% pass mark. | $600 + GST Self-Study / $680 + GST eLearning |
| ISO 22301 Lead Implementer | Whoever will build and run the BCMS — BIA, strategies, plans, exercising, and audit preparation, via PECB's IMS2 methodology. 31 CPD credits, 450+ pages. | 35–45 hours self-paced. Three-hour open-book exam, seven domains, 70% pass mark. | $980 + GST Self-Study / $1,060 + GST eLearning |
| ISO 22301 Lead Auditor | Auditors and assurance professionals — Stage 1 and Stage 2 activities, findings, and audit programme management under ISO 19011 and ISO/IEC 17021-1. 31 CPD credits, 400+ pages. | 35–45 hours self-paced. Three-hour open-book exam, seven domains, 70% pass mark. | $980 + GST Self-Study / $1,060 + GST eLearning |
The Lead Implementer course is the one most Australian buyers need — it covers the BCMS end-to-end and is the natural next step for anyone who has already done ISO 27001 Lead Implementer, since the Annex SL structure is shared. For the leadership layer above the BCMS — decision-making and communication when the disruption is live — see the crisis management certification guide.
Aegentra Academy is an official PECB authorised training partner in Australia (verifiable on the PECB partner directory). Every enrolment includes the official PECB exam voucher and a free resit within 12 months. Online and instructor-led delivery is available in Melbourne and Sydney.
ISO 22301 vs CPS 230 vs the SOCI Act
These three are not substitutes — they are complementary. CPS 230 and the SOCI Act are regulatory instruments that impose obligations directly on the entities they cover. ISO 22301 is a voluntary management system standard that gives you the auditable method to meet those obligations and prove it.
CPS 230 applies to APRA-regulated entities — banks, insurers, superannuation trustees — and took effect on 1 July 2025. It is outcome-focused: critical operations identified, tolerance levels set, plans tested, providers managed. It does not tell you how. ISO 22301 is the how — the BIA, strategy selection, and exercise discipline that produce those outcomes in a form an auditor can verify.
The SOCI Act applies by sector and asset class, not by regulator, and its Risk Management Program obligation is all-hazards — cyber, physical, supply chain, personnel, and natural hazard. A BCMS built on ISO 22301 covers the availability dimension of every one of those hazard classes with a single, coherent system rather than five parallel documents.
Practical advice: if you are subject to either regime, build the BCMS first and let compliance fall out of it — the reverse order produces paperwork that fails its first real outage. And if you already hold ISO 27001, run the programmes together: shared structure, combined audits, and one management review covering both security and continuity.
Keep reading
FAQs
ISO 22301 certification is earned two different ways. An organisation certifies its business continuity management system: build and operate the BCMS, complete an internal audit and management review, then pass a two-stage external audit — in Australia, use a JAS-ANZ accredited certification body. An individual certifies their own competence instead, by completing a Foundation, Lead Implementer or Lead Auditor course, passing the exam, and applying with the professional experience each credential level requires.
Both forms of ISO 22301 certification run on a three-year cycle. An organisation’s BCMS certificate is valid for three years, with surveillance audits in years one and two — the first within twelve months of the certification decision — and a full recertification audit before it expires. PECB individual certifications are also valid for three years, maintained by submitting continuing professional development hours and paying the annual maintenance fee; Foundation-level certificates require neither.
The best ISO course is the one that matches the standard your organisation works to and the role you will hold. Foundation suits people who need the vocabulary and the requirements; Lead Implementer suits those who will build and run the management system; Lead Auditor suits those who will audit it. Business continuity points to ISO 22301, information security to ISO/IEC 27001, and AI management to ISO/IEC 42001. No single course is best for everyone.
ISO 22301 certification is independent confirmation that an organisation’s business continuity management system meets ISO 22301:2019, the international standard titled Security and resilience — Business continuity management systems — Requirements. An accredited certification body audits the BCMS in two stages and issues a certificate if it conforms. ISO writes the standard but certifies no one. Separately, individuals can hold PECB credentials proving personal competence in implementing or auditing a BCMS — a different thing from certifying the organisation.
No. ISO 22301 is voluntary. APRA CPS 230 and the SOCI Act impose binding continuity and resilience obligations on regulated entities, but neither mandates certification. In practice, ISO 22301 is the recognised methodology behind those obligations — a certified BCMS is the cleanest documentary evidence that your continuity capability meets the supervised standard, and the framework tenders and procurement teams increasingly name.
Disaster recovery is the IT subset — restoring systems, data, and infrastructure after failure. Business continuity is the whole-of-organisation discipline: identifying priority activities, analysing the impact of disruption, setting recovery objectives (RTO, RPO, MTPD), selecting continuity strategies, and exercising plans so the organisation keeps operating. ISO 22301 governs the full BCMS; DR plans sit inside it as one set of solutions.
No. They are independent standards, and either can be certified first. They share the Annex SL high-level structure, so if you already operate an ISO 27001 ISMS, the management-system machinery — document control, internal audit, management review — carries across, and combined audits are common. Many Australian organisations run both, because the disruptions they plan for (ransomware, outages, supplier failure) are frequently the same events.
Foundation ($600 + GST) is the two-day-equivalent overview for anyone new to business continuity or joining an existing programme. Lead Implementer ($980 + GST) is the practitioner tier for whoever will build and run the BCMS — the business impact analysis, continuity strategies, plans, and exercise programme. Lead Auditor ($980 + GST) suits internal auditors, assurance professionals, and anyone heading toward certification-body work.
Foundation is a one-hour multiple-choice exam across two competency domains. Lead Implementer and Lead Auditor are three-hour open-book exams — mixed multiple-choice and scenario-based questions across seven competency domains. All have a 70% pass mark and are remotely proctored, so you can sit them from anywhere in Australia. Every Aegentra enrolment includes the official exam voucher and one free resit within 12 months.
None to train or sit the exam. After passing, you can apply for the Provisional Implementer credential. Implementer requires two years of experience (one in business continuity management) plus 200 hours of project activity; Lead Implementer requires five years (two in BCM) plus 300 hours; Senior Lead Implementer requires ten years (seven in BCM) plus 1,000 hours. All tiers require signing the PECB Code of Ethics and PECB approval of the application; the Lead Auditor ladder mirrors this with audit hours.
CPS 230, effective 1 July 2025, requires APRA-regulated entities to identify critical operations, set tolerance levels for disruption, maintain credible business continuity plans, test them systematically, and manage service provider risk. ISO 22301 provides the method: the business impact analysis produces the critical-operations register and recovery objectives that tolerance levels are set against, and the exercise programme satisfies the testing obligation. Certification is not compliance with CPS 230, but a well-run BCMS is the defensible basis for it.
Organisational certification follows the standard three-year cycle — annual surveillance audits in years one and two, then a full re-certification audit in year three. Organisations holding ISO 27001 typically combine the surveillance visits. Individual PECB credentials are maintained through annual CPD reporting and the maintenance fee rather than re-examination.