Overview
ISO 22301:2019 is the international standard for a Business Continuity Management System (BCMS): a documented, tested way of keeping critical operations running through a disruption and recovering the rest in a planned order rather than an improvised one.
In India, demand for this certificate is largely commercial rather than a direct legal mandate. It tends to arrive through vendor due diligence: clients that are themselves regulated, such as banks, NBFCs and insurers, are expected to manage outsourcing and continuity risk on their own book, and some push a version of that expectation down to the critical suppliers they depend on. An ISO 22301 certificate is one of the clearer ways a vendor can answer that ask with evidence rather than a written promise. We frame it that way deliberately, as an expectation you may be asked to satisfy in diligence, not a rule any regulator applies to your business directly, unless your own entity is itself RBI-, SEBI- or IRDAI-regulated.
A BCMS is more than an incident-response document. Getting certified means running a Business Impact Analysis (BIA) that identifies which processes are actually critical and how long the business can survive without each one, building continuity strategies for the ones that matter, and then testing those strategies through exercises rather than filing them and hoping. NABCB — India’s own national accreditation body, operating under the Quality Council of India — accredits certification bodies for ISO 22301 as a standalone management-system scheme, so an NABCB-accredited certificate carries recognised standing both in India and, through NABCB’s membership of the IAF Multilateral Recognition Arrangement, internationally.
CapEasy prepares the BCMS itself — the BIA, the continuity and recovery strategies, the plans and the exercise programme — and gets the file audit-ready. The certification decision and the certificate itself always come from an independent, NABCB-accredited (or equivalent IAF-MLA-signatory) certification body; we do not issue or award it.
Who it’s for
- IT and BPO service providers whose clients include banks, NBFCs, insurers or other RBI/SEBI/IRDAI-regulated entities, where continuity is now a standing item in vendor due diligence
- Data centre, cloud and managed-services businesses where an outage at your end becomes an outage at a client’s end
- Companies bidding for government or PSU IT contracts where a BCMS is named as a differentiator alongside ISO 27001
- Businesses that already run ISO 27001 and want to extend the same management-system discipline to operational continuity rather than just information security
- Any operations-heavy business — logistics, manufacturing, critical back-office functions — that has never formally tested what happens if a key process stops
Eligibility & requirements
- Top management commitment and a documented continuity policy, since a BCMS that nobody at the top owns rarely survives its first audit
- A completed Business Impact Analysis covering every process in scope, with a Maximum Tolerable Period of Disruption and a Recovery Time Objective set for each
- A risk assessment for the threats that could trigger disruption, feeding into continuity and recovery strategies for the processes the BIA marked critical
- Documented continuity plans and an incident response structure, not just a policy statement
- At least one exercise or test of the plans, with the results and any corrective actions on record before the certification audit
- Management review of the BCMS at planned intervals, and an internal audit completed before the external audit
- For scope involving third parties — data centres, connectivity providers, key suppliers — evidence that their continuity arrangements were considered in the plan
How CapEasy handles it
- Scoping and gap analysis: define which sites, processes and services sit inside the BCMS, then assess the current state against ISO 22301:2019’s requirements
- Business Impact Analysis: work through every in-scope process to set impact tolerances, Recovery Time Objectives and Recovery Point Objectives
- Risk assessment: identify the disruption scenarios relevant to the business and rank them
- Continuity strategy and plan development: build the recovery strategies, incident response structure and continuity plans the BIA calls for
- Documentation build-out: policy, procedures, plans and the records the standard requires as evidence, structured for audit
- Exercise the plans: run at least one test (a walkthrough, simulation or live exercise) and record what worked and what needs fixing
- Internal audit and management review: close any nonconformities found internally before the external audit sees them
- Certification audit — Stage 1 documentation review followed by Stage 2 on-site (or remote, where the certification body permits) assessment by the NABCB-accredited certification body, then three years of certification with annual surveillance audits
Documents you’ll typically need
- A list of processes, sites and services you want inside the BCMS scope
- Existing incident response, disaster recovery or crisis management documents, if any already exist
- Details of critical suppliers and third-party dependencies (data centres, cloud providers, key vendors)
- Prior outage or incident records, where available, to ground the risk assessment in what has actually happened
- Org chart and named owners for continuity roles, so the plan assigns responsibility to real people
- Any existing ISO 27001 or other management-system documentation, since a BCMS commonly shares structure and evidence with an existing ISMS
CapEasy is a private consultancy and is not affiliated with any government authority. We help you assess eligibility and prepare and file your application; eligibility and approval depend on your specifics and the relevant department’s discretion.



