Last verified: September 2026

What ISO 22301 actually asks of your exercise program

What ISO 22301's exercise clause asks of a business continuity management system — who it binds, what Clause 8.5 covers in substance, why it sets no frequency, why no source names an exercise type, and what a certification audit looks at.

ISO 22301

If your organisation is certified to ISO 22301, or tells its customers it conforms, you have probably been told the standard wants an annual exercise, or a tabletop, or a documented exercise schedule.

None of those appears in any published account of the standard that we found. What ISO 22301 asks of a conforming organisation is a program of exercises. It sets no frequency, and no source we found says it names an exercise type. That's more room than a date on a calendar, and it's harder to fill well.

What follows is what the exercise clause asks for in substance, who it binds, and what a certification audit looks at, including the parts that summaries most often get wrong.

How to read this guide. ISO 22301 is a copyrighted standard, sold by ISO and national standards bodies. Nothing on this page is quoted from it. Where we describe what a clause asks for, that is our characterisation, in our own words, cross-checked against certification bodies' published guidance and against the preview pages of the standard that are published free. We cite clause numbers and titles so you can find the text in your own copy. If you are implementing the standard, you need that copy.

Who this applies to

ISO 22301 is the international requirements standard for a business continuity management system (BCMS): what an organisation needs in place to keep delivering through a disruption, and to recover from one.¹ It is written to fit any organisation, or any part of one, and to be applied in proportion to the organisation's own circumstances and complexity.¹

**It is a voluntary standard.**¹ Its requirements sit in Clauses 4 to 10. They bind you when you claim to meet them, and certification is only one of four ways to make that claim. The standard itself lists the other three: declaring conformity yourself, having a customer or another interested party confirm it, or having an outside party confirm your own declaration.¹

Your situation What Clause 8.5 means for you
Certified to ISO 22301 A requirement, and an audited one. It is assessed at certification and again through the certificate's life. A gap is a nonconformity you are expected to correct.¹ ⁸
Claiming conformity without certification (for example, to a customer) A requirement for the claim to be true. Nobody audits it unless you or a customer arrange it.¹
Using ISO 22301 as a reference only No obligation. Clause 8.5 is a benchmark you can choose to follow.¹

If you want implementation guidance rather than requirements, that is a separate document: ISO 22313:2020 is the companion guidance on applying ISO 22301.⁹ ¹⁰ Its recommendations are not ISO 22301's requirements, and neither document is law.

Requirements at a glance

What the standard asks, in substance Where Cadence Applies to
A program of exercises, not a one-off event, that over time shows the organisation's business continuity arrangements work Clause 8.5, Exercise programme¹ ⁴ ⁷ Intervals the organisation plans. No frequency is set Organisations certified to the standard or claiming conformity
Exercises consistent with the organisation's business continuity objectives Clause 8.5⁴ ⁷ As above
Exercises built around a scenario, each with a stated purpose set in advance Clause 8.5⁴ ⁷ As above
Exercises that build the capability of the people who would respond Clause 8.5, with the response teams set up under 8.4.2¹ ⁴ ⁵ ⁷ As above
A written report after each exercise, whose findings are acted on Clause 8.5⁴ ⁶ As above
A separate, periodic evaluation of business continuity documentation and capabilities, including partners' and suppliers' Clause 8.6, Evaluation of business continuity documentation and capabilities¹ ⁴ ⁵ Periodic, and when things change, as certification-body guidance describes it As above
Findings carried into management review and corrective action Clauses 9.3 and 10.1¹ ⁵ As above

Our summary, not ISO's wording. Clause numbers and titles are from ISO's own contents page.¹ As of September 2026.

Clause 8.5, Exercise programme: what it asks for, in substance

This is our characterisation, built from certification bodies' guidance, not ISO's wording.⁴ ⁵ ⁶ ⁷ In substance, for an organisation certified to ISO 22301 or claiming conformity, Clause 8.5 asks for a planned, recurring program of exercises whose job is to show, over time, that its business continuity arrangements actually work.

  • Tied to the organisation's business continuity objectives. Exercises are chosen for what the organisation is trying to protect, not for what's convenient to rehearse.
  • Built around a scenario, with a purpose set in advance. Each exercise knows what it is trying to find out before it starts.
  • Aimed at people as well as plans. Exercises develop the people who would respond: how they work together, and what they know how to do when it counts.
  • Written up, and acted on. Each exercise ends in a report of what happened and what needs to change, and those findings feed improvement.
  • Recurring, on intervals the organisation plans. More on that below.

The unit is the program, not the exercise. No single exercise has to show that everything works. The program as a whole does that, over time. One certification body's guidance puts it explicitly: not everything has to be exercised every time, and coverage builds up across the program.⁴

Two things summaries get wrong about this clause

The title changed in 2019. In the 2012 edition, Clause 8.5 was titled Exercising and testing.² The 2019 edition retitled it Exercise programme,¹ and certification-body transition guidance describes the change as a new emphasis on a planned program and on teamwork.⁵ If your source calls 8.5 "Exercising and testing", it is describing a superseded edition.

It doesn't make executives take part. The 2012 edition expected top management to take an active part in exercising. According to certification-body guidance on the transition, the 2019 edition dropped that expectation.⁵ ⁹ Your own program may call for senior involvement. No source we found reads it into Clause 8.5. Whether the 2019 leadership clause keeps any exercise-related duty is a question for your copy of the standard.

8.5 is not 8.6: exercising and evaluating are separate clauses

A common shorthand describes the exercise clause as covering the schedule, the objectives, the scenarios and the evaluation. That list is a summary, not the standard's, and it merges two clauses.

Clause 8.5 runs the exercises and reports on them. Clause 8.6, Evaluation of business continuity documentation and capabilities, is a separate clause, new in 2019.¹ ⁵ In substance, it is a periodic judgement of whether the organisation's business continuity work still holds up: its impact analysis and risk assessment, and the strategies, solutions, plans and procedures built on them.⁴ ⁵ It also brings in partners' and suppliers' continuity capabilities,⁵ and its results feed management review under Clause 9.3.⁵

**Clause 8.4, Business continuity plans and procedures, is what gets exercised.**¹ It includes the response structure (8.4.2), warning and communication (8.4.3), the business continuity plans themselves (8.4.4) and recovery (8.4.5).¹ The teams set up under 8.4.2 are the people 8.5's exercises develop, and the plans in 8.4.4 are among the arrangements the program puts to work.

Keep the three apart and the standard reads cleanly. 8.4 builds the arrangements, 8.5 exercises them and reports, and 8.6 judges whether the whole body of work holds up.

How often: the standard sets no frequency

ISO 22301 sets no exercise frequency. A certified organisation exercises at intervals it plans itself, and certification-body guidance also names significant change as a trigger.⁴ ⁷

If you have been told "annual", or "at least once a year", that number didn't come from ISO 22301. It may be your own organisation's choice, a customer's contract, or another framework's rule. Those are all legitimate sources of a number. They just aren't this standard.

Don't borrow a cadence from somewhere else. Other frameworks set exercise intervals in their own words and for their own reasons. Those intervals belong to those instruments, not to this one.

What type of exercise: no source names one

No published account of Clause 8.5 that we found names an exercise type: not tabletop, not drill, not simulation, not full-scale.⁴ ⁷ So we make no claim either way. We don't say that ISO 22301 accepts a tabletop, and we don't say that it rules one out.

What the clause asks for, in substance, is set out above: a program, tied to your objectives, built on scenarios, developing your people, written up and acted on. Nothing we found settles which mix of exercise types does that for your organisation. That is your program's design, and whether it conforms is your auditor's assessment.

Guidance on exercise types, where it exists, sits in the companion documents: ISO 22313:2020, guidance on applying ISO 22301, and ISO 22398:2013, guidelines for exercises. Both are current as of September 2026.¹⁰ We haven't reviewed their contents for this guide.

What a certification audit looks at

This section describes certification as certification bodies describe it.⁸ The rules certification bodies themselves work to are in a separate, paywalled standard, which we haven't reviewed.

  • Initial certification is audited in two stages. Stage 1 checks that implementation is on track. Stage 2 checks that the standard has been fully implemented.⁸
  • A certificate runs for three years. Surveillance audits follow in years one and two, and a recertification audit in year three.⁸
  • Clause 8.5 is assessed for conformity like any other requirement. The documented evidence certification-body guidance ties to it is post-exercise reports.⁶ Behind those reports sits the improvement loop the auditor will also follow: monitoring and measurement (9.1), internal audit (9.2), management review (9.3), and nonconformity and corrective action (10.1).¹
  • Each certification body sets its own prerequisites for the initial audit. One we reviewed requires the system to have run for at least three months, with a management review and a full cycle of internal audits behind it.⁸ Check yours.

What we won't tell you is what an individual auditor prefers: how many exercises, of what type, or whether the same scenario can be run twice. None of that is written down in any published account we found. If you have been told it as a rule, ask where the rule is written.

ISO 22301 is not ISO 27001

The two standards are often discussed together, and they share a skeleton. Both follow ISO's common structure for management system standards, and ISO 22301's introduction names ISO/IEC 27001 as a standard it is designed to be consistent with.¹ ¹¹ Clauses 4 to 10 carry parallel headings.

Clause 8 is where they part. It is discipline-specific. "Clause 8.5" exists only in ISO 22301. ISO/IEC 27001:2022's Clause 8 runs from 8.1 to 8.3 and has no 8.5.¹¹ They are separate requirements standards, each assessed on its own terms. A requirement in one is not a requirement in the other, even where the wording sounds alike.

Which edition

ISO 22301:2019, the second edition, is current as of September 2026. It replaced the 2012 first edition.³ ISO describes the 2019 edition as clarifying the 2012 requirements rather than adding new ones, and as moving nearly all business-continuity-specific requirements into Clause 8.¹

It was amended in February 2024 by Amendment 1, Climate action changes, a one-page amendment that is part of the current standard.³

Where the standard is deliberately open

Naming these is more useful than papering over them. Your certification body may read them differently than a summary does, and some of them turn on wording we don't reproduce.

  • The intervals are yours. The standard expects exercising at planned intervals and sets no number. Certification-body guidance also names significant change as a trigger. Whether a significant change adds an exercise to your planned cycle, or can stand in for one, turns on the clause's exact wording. Check your copy.
  • The scenario wording varies between summaries. Certification bodies describe the scenario requirement in different words. Don't treat any one summary's adjective as the standard's.
  • No exercise type is named in any source we found. See above.
  • **The only 8.5 document the guidance pins is the post-exercise report.**⁶ Certification-body checklists we reviewed list no separate exercise program or schedule document for Clause 8.5. A schedule may be good practice, but we can't source it as a requirement.
  • Definitions are ISO's, and we don't restate them. ISO 22301 takes its terms from the vocabulary standard ISO 22300, which moved to a 2025 edition in November 2025.¹ ¹⁰ Use your copy for what "exercise" and "test" mean.
  • Whether an exercise must precede the initial audit isn't written down in any published account we found. It is your certification body's call, so ask.
  • Scale is proportionate, not tiered. The standard is meant to fit any organisation, applied in proportion to its circumstances.¹ It sets no size tiers.

Why the program should find things

For a conforming organisation, Clause 8.5's program is the start of a loop, not the end of one. Clause 8.6 periodically judges whether your business continuity work still holds up, and its results feed management review under 9.3. Clause 10 turns what you find into corrective action (10.1) and continual improvement (10.2).¹ ⁴ ⁵ All of that runs on what your exercises surface.

A program that only confirms the plan gives that loop nothing to work on. An exercise run to a fixed script tends to find what the script expected. One that adapts to what the people in it decide shows where the arrangements actually strain: a decision nobody owns, a handoff nobody planned, an assumption that fails at the second inject. Those are the findings an evaluation can weigh and an improvement can act on.

Realistic, adaptive exercises are one of the most direct ways to generate that learning, and the post-exercise reports that carry it forward. Which mix of exercises does that for your objectives is still your program's design.

What Crewcible produces that maps to it

Crewcible is built for the exercise itself: designing it, running it, and capturing what came out of it. Crewcible exercises are discussion-based. A single exercise, of any kind, isn't a program. Within your program, three outputs line up against the substance of the clause.

The scenario and its purpose. Clause 8.5, in substance, asks for exercises built around a scenario and tied to your business continuity objectives. Global Library scenarios are ready to run, and a scenario built for your own organisation takes hours, not weeks. That makes it practical to choose each exercise for what your objectives say needs exercising, rather than for what is already on the shelf. Crewcible scenarios are designed to support that part of the clause.

The people. The clause is about developing the people who respond, not just checking the plan. AI-suggested injects respond to what the crew actually decides, so the exercise follows the crew instead of a script. The facilitator decides what gets released and when, so the judgement stays with your people. AI enabled, human led.

The post-exercise report. The one piece of evidence certification-body guidance ties to Clause 8.5 is the post-exercise report, and the clause expects its findings to be acted on. Crewcible captures decisions and reasoning per participant and per inject as the exercise runs. After-action output and an improvement plan come out of the exercise, rather than being reconstructed a week later. That output is designed to support the post-exercise report your program needs. What goes into the report, and what you do about it, stays your call. Either way, your next management review has a record to work from, not a recollection.

Crewcible is built by experts who have supported crisis situations and exercises in the world's largest organizations.

No Global Library scenario is built around ISO 22301, and the standard is cross-industry. So start from the Global Library and pick the disruption closest to your own business continuity objectives.


Standards references current as of September 2026. ISO 22301 content on this page is our characterisation, not a quotation of the standard. This guide is scheduled for re-verification by March 2027.

¹ ISO 22301:2019, Security and resilience — Business continuity management systems — Requirements: ISO's official preview (cover, contents, foreword, introduction and Clauses 1–3.8), as distributed free by an ISO national member body. Clause numbers and titles are taken from its contents page. The foreword, introduction and scope are paraphrased. Clause bodies from 4 onwards are not in the preview.

² ISO 22301:2012, official preview, contents page only, for the 2012 clause title.

³ ISO national member-body catalogue records: ISO 22301:2019 (edition, approval date, status, and the edition it replaced) and ISO 22301:2019/Amd 1:2024 (publication date and length).

⁴ An accredited certification body's ISO 22301:2019 implementation guide (2024). Secondary source. Used to corroborate our characterisation of Clauses 8.5 and 8.6.

⁵ The same certification body's 2012-to-2019 transition guide (2021). Secondary source. Used for the 2012-to-2019 changes, the creation of Clause 8.6, supplier evaluation, and the change to top management's role in exercising.

⁶ The same certification body's ISO 22301 checklist (2021), including its clause-by-clause list of the documented information it expects for certification. Secondary source.

⁷ A certification firm's explainer on ISO 22301 requirements (updated April 2026). Secondary source, used to corroborate the characterisation of Clause 8.5.

⁸ Certification-body descriptions of the certification process: an accredited certification body's ISO 22301 certification page, and a second certification body's ISO 22301 product sheet (2023). Secondary sources. Audit stages, cycle and prerequisites are described as those bodies describe them. Prerequisites differ between certification bodies.

⁹ A certification body's commentary on the 2019 revision (2019). Secondary source. Used for the change to top management's role and for the split between ISO 22301 (what is required) and ISO 22313 (how to meet it).

¹⁰ ISO national member-body catalogue records, for status only. Contents not reviewed: ISO 22313:2020, ISO 22398:2013, and ISO 22300 (the 2021 edition, withdrawn in November 2025 on publication of the 2025 edition).

¹¹ ISO/IEC 27001:2022, official preview (contents and introduction), as distributed free by an ISO national member body, and its catalogue record.

READINESS STARTS BEFORE THE CRISIS.

Put your team to the test.

Build your first scenario and turn preparation into measurable progress.

Explore pricing →Request a demo →