Home / Insights / ISO 22301: why the recurring cost outweighs the first one
ContinuityGuide
ISO 22301: why the recurring cost outweighs the first one
Most continuity budgets fund the implementation project and the first audit, then stop. That is the wrong place to stop for any management system, and it is a worse place to stop for this one.
Published 5 August 2026Reviewed 5 August 20265 minute read
In brief
Certification runs on a three-year cycle: initial audit, surveillance in years one and two, recertification in year three.1 The certificate is the start of an operating cost, not the end of a project.
Continuity carries a heavier recurring profile than most standards, because two of its core activities, exercising and keeping the impact analysis current, only produce evidence by being repeated.
We do not publish price ranges, and certification-body fees are not ours to state. What follows is the shape of the recurring commitment and who each part is paid to, which is the part budgets actually get wrong.
Three different payees, one budget line
Recurring cost is usually presented as a single number. It is three, and they behave differently.
| Paid to | For | How it varies |
|---|---|---|
| The certification body | Surveillance audits through the cycle and the recertification audit at the end of it. | Audit duration is calculated under mandatory rules rather than negotiated. The day rate differs between bodies; the number of days should not differ much.2 |
| A consultant, where used | Exercise design and facilitation, impact-analysis refresh, internal audit, and management review support. | Entirely a matter of what you keep in-house. This single choice moves the recurring number more than any other. |
| Nobody (internal cost) | The time your own people spend running exercises, updating plans and attending reviews. | Real, and usually unbooked. It is the line most often missing from the comparison entirely. |
What this means for your organisation
A quotation that blends all three is not comparable with one that separates them. Ask any bidder which lines are theirs, which are the certification body’s, and which are yours. ExSolution does not set certification-body fees and does not issue certificates.
Why continuity is heavier than most
For many management systems, maintenance between audits is largely documentary. Continuity is not, because the standard requires an exercising and testing programme, internal audit and management review, and a business impact analysis that remains current as the organisation changes.3
Two of those cannot be satisfied by a document review.
- Exercising. The evidence is the exercise itself, and a credible programme is more than one tabletop a year. It extends to scenario tests, supplier and failover checks, and the management time to run them and act on the findings. An exercise designed so it cannot fail will not turn up anything, and that absence of findings should itself be treated as a warning sign.
- Impact analysis currency. The analysis is only as good as the organisation it describes. New sites, restructures, changed suppliers and departed staff all invalidate parts of it, and none of those events announces itself to the continuity programme.
This is the line organisations underestimate most, and it is the reason a continuity certificate decays faster than a quality one when the programme goes quiet. Keeping that cadence running is the core of business continuity consultancy under ISO 22301 and NCEMA 7000.
What raises the bar in the UAE
Regulated firms carry obligations that make demonstrated capability the test rather than documented capability. DIFC and ADGM rules require continuity arrangements to be kept up to date and regularly tested; the Central Bank requires banks to review and test their plans at least annually, with results reported to the Board.4
NCEMA 7000 is a UAE national standard. Its application depends on the organisation’s mandate, supervising authority and contractual obligations rather than the emirate in which an office is registered. It applies to UAE federal and government entities, and may extend through government or contractual requirements to suppliers, contractors and partners.
The practical consequence is that a buyer or supervisor is likely to ask when you last tested the plan, not when you were certified. A programme that stops after the certificate cannot answer that question well.
What decay actually costs
A system that has not been exercised, whose impact analysis is two years old, and whose plans name people who have left does not coast quietly to its next audit. It arrives with findings, and closing findings under time pressure costs more than maintenance would have: in fees, in internal disruption, and occasionally in the certificate itself.
The pattern we see is consistent: organisations that budget the recurring programme from the start run it at a steady cadence and spend less. Those that treat certification as a finish line pay twice, once to certify and again to rebuild what was allowed to lapse. That is an observation from our engagements rather than a measured claim.
Budgeting the full cycle
- Budget across the whole cycle, not the first year: surveillance, recertification, exercising, impact-analysis refresh, internal audit and management review, and awareness for new starters.
- Decide early what is run in-house and what is outsourced, and price both ways before committing.
- Ask every bidder to separate their fees from certification-body fees and from your own internal effort.
- Size the programme to the risks that matter, not to what will impress an auditor. A system sized for the audit tends to cost more to run and deliver less in practice.
Sources and references
All accessed 5 August 2026. ISO standards are copyright protected, so clause text is not reproduced here.
- ISO/IEC 17021-1:2015, clauses 9.1.3.2 and 9.1.3.3: the three-year certification cycle, surveillance at least once each calendar year except in recertification years, and the first surveillance audit no later than 12 months after the certification decision. An industry-specific scheme may set a different cycle.
- IAF MD 5:2023, Determination of Audit Time, retained under Global Accreditation Cooperation Incorporated (Global ACI), which succeeded IAF and ILAC from 1 January 2026. Audit time is calculated from effective personnel numbers, which the document states is not the sole consideration, adjusted for sites, shifts, scope, complexity and outsourcing.
- International Organization for Standardization, ISO 22301:2019: the requirements standard for business continuity management systems, currently published.
- DFSA GEN 5.3.23; ADGM FSRA GEN 3.3.33; Central Bank of the UAE, Operational Risk Standards C 163/2018, Article 7. None of these names ISO 22301 or any other standard.
Read next
If a quotation covers the project but not the cycle, that gap is worth closing before it is approved.
Discuss a continuity requirement