37 / 63ISO 22301 Business Continuity

ISO 22301 business continuity, with recovery targets your systems can actually hit

ISO 22301 business continuity for Canadian organisations, built so the business impact analysis and the infrastructure agree.

  • CCIE-led engineering behind the plan
  • Management system practice alongside
  • Canadian data residency available
THE WORK

ISO 22301 business continuity, three pillars, one operator.

One Canadian team runs the business impact analysis, builds the business continuity management system (BCMS), and proves the plan against the infrastructure you actually run.

  1. 1

    Business impact analysis

    Critical activities ranked and tolerable disruption periods agreed with the people who own them, then mapped through to the systems, suppliers and people each activity depends on.

  2. 2

    The management system

    Clauses 4 to 10 built: scope, policy, continuity strategy, plans, exercise programme, management review, and the records an ISO 22301 certification audit asks to see.

  3. 3

    Plans that hold

    Continuity plans exercised against the estate you actually run, not against a boardroom table. Where the agreed target and the infrastructure disagree, our engineers fix the infrastructure.

THE PROOF

Built to last. Evidence over promises.

OSFI expected full adherence to its operational resilience guideline by 2026-09-01, and that deadline has passed. ISO 22301 is the continuity planning standard most Canadian boards reach for when they have to show their work.

IN PRODUCTION

Continuity a Canadian regulator could test.

Our plan promised four hours for the order system. Nobody had asked whether the infrastructure could do four hours, and it couldn't. SMEnode found the gap in the first workshop, then fixed the platform instead of quietly editing the plan down to match it.

SMEnode · Engineering principle
  • CCIE Data Center
  • CCIE Security
  • CCDE Design
  • Canadian data residency
THE DEEP DIVE

ISO 22301 business continuity in Canada, made real.

I run this practice, so this is written by the engineer who'll own the gap between your plan and your platform, not a product page.

Most continuity plans promise what the estate can't deliver.

Most continuity plans get written by people who have no authority to change the systems the plan depends on. That's the problem in one sentence. A business impact analysis sets a tolerable period of disruption for each critical activity, and the plan then promises it. Almost nobody checks whether the estate can deliver it, and the certificate won't tell you, because ISO 22301 certifies that a business continuity management system exists and runs, not that your platform can come back inside the window you wrote down. Both things matter. Only one of them is what a customer experiences during an outage.

Where the risk actually sits.

Risk sits in three predictable places. A business impact analysis done with a consultant and a spreadsheet rather than with the people who own the critical activities, which produces numbers nobody will defend under pressure. Plans exercised only as tabletop discussions, so the first real test is a real incident. And suppliers whose own continuity arrangements nobody has ever asked about, which is where a surprising share of Canadian outages start.

The Canadian calendar, and what OSFI E-21 already expects.

The Canadian calendar makes this urgent for one sector in particular. OSFI published Guideline E-21, Operational Risk Management and Resilience, on 2024-08-22, began compliance checks on 2025-09-01, and expected full adherence by 2026-09-01 (source: OSFI, 2024). It calls for business continuity, disaster recovery and crisis management to sit inside one resilience framework, with scenario testing across all critical operations by 2027-09-01. E-21 names no standard, so ISO 22301 is one credible way to evidence it rather than a requirement. ISO 22301:2019 is still the current version of this continuity planning standard, and it now carries the 2024 climate amendment (source: ISO).

Control checklist
THE METHOD

How our BCMS and continuity planning work runs.

Four steps, and step 01 is the one that gets skipped. A business impact analysis is a series of uncomfortable conversations with the people who own each critical activity, and it produces numbers they'll stand behind. Done as a questionnaire it produces numbers nobody owns. We run it as workshops, we write down who agreed to what, and the output is short enough that an executive will read it.

  1. Step 01

    Run the impact analysis

    Critical activities identified with their owners, tolerable disruption periods agreed and recorded, and dependencies mapped through to the systems, suppliers and people each activity actually needs.

  2. Step 02

    Build the management system

    Scope, policy, continuity strategy, plans, exercise programme, management review, and the records a certification body will ask to see, sized so your team can keep it running.

  3. Step 03

    Close the capability gap

    Where the agreed target and the infrastructure disagree, our engineers fix the infrastructure. This is the step no continuity consultancy can offer, and it's why the plan stops being fiction.

  4. Step 04

    Exercise, then certify

    Real exercises against real systems, findings fed back into the plans, an internal audit, and stage 1 and stage 2 support with the accredited body that issues the certificate.

QUESTIONS

ISO 22301 questions, answered straight.

Answers first, including what the certificate does not prove. An architect takes the call, not a salesperson.

What they protect. ISO 27001 governs information security: who can reach data, how it's defended, how incidents get handled. ISO 22301 governs continuity of delivery: which activities matter, how long they can stop, and how you restart them. The clause structure is nearly identical, so holding one makes the second much cheaper. Most Canadian organisations we meet should do information security first, and we'll say if you're the exception.

No, and the difference decides who writes it. A disaster recovery plan covers technology: bringing systems back. A business continuity plan covers the business: how payroll runs, how orders get taken, where people work, what customers get told. Continuity is the wider document and recovery is one chapter of it. A plan that only covers technology leaves out the questions your operations team will actually be asked.

No. Certification comes from an accredited body, and the firm that builds your management system can't be the one that audits it. We build it, we prepare you, and we sit in the audit. Anyone offering to do both is selling you a certificate your customers will discount the moment they look at who signed it.

No, and this is the most useful thing on this page. The certificate proves you run a business continuity management system that identifies critical activities, sets targets and exercises plans. It doesn't prove your platform meets those targets, because that isn't what an auditor measures. We test both, and when the two disagree we'd rather rebuild the capability than lower the target on paper.

When no executive will own it, because continuity decisions are business decisions about what gets sacrificed first. When a major platform migration is already funded, since your dependencies and targets will both change. And when what you need is technology recovery rather than a management system, which is a smaller and cheaper piece of work, and we'll tell you if that's the honest answer.

We won't quote a range that means nothing without your scope. The bill has four parts: the accredited body's stage 1 and stage 2 audit, priced on headcount and number of sites; surveillance audits between recertifications; a copy of the standard from ISO; and your own team's time, which is usually the largest line. We size the first and the last with you before you commit.

LET'S CONNECT

A senior engineer replies within an hour, 24/7.