Who needs it
It suits providers of essential services, such as banks and hospitals, and their critical suppliers. Regulators and large clients often expect tested continuity plans.
The steps
- A gap assessment compares current practice with the requirements.
- Top management approves the scope, the policy and the objectives.
- A business impact analysis and risk assessment set recovery priorities and times.
- Processes run long enough to produce evidence for the auditor.
- An internal audit and a management review are completed.
- Stage 1 and Stage 2 audits by the certification body lead to the certificate.
Cost drivers
Headcount, the number of sites and the scope of the system drive most of the cost. Existing practice matters, because every gap takes staff time and outside support to close. Audit days are set by the certification body from headcount and complexity under accreditation rules. Exercises and tests of the plans take staff time each year. Surveillance audits follow in each of the two years after certification.
Timeline
Time depends on size, scope and readiness. Small organisations with sound practice often finish in four to six months. Larger or multi-site organisations commonly need nine to twelve months. A certificate runs for three years before recertification.
Certification
Certificates are issued by certification bodies accredited to ISO/IEC 17021-1. Your implementer and your auditor are always different, so the audit stays independent.


