Can the business keep running when disruption happens?
Assess whether the organization can continue delivering its critical products and services during a disruption — governance, business impact analysis, recovery requirements, strategies, plans, crisis management, suppliers and exercising. Aligned to ISO 22301:2019 with Amendment 1:2024. Answer honestly — this is for your own visibility, not a test.
Ready to see where you stand?
You'll get a real, computed score across 13 business continuity domains — and any critical gap (a missing impact analysis, unapproved recovery requirements, unexercised plans) is called out on its own, even when the overall score looks strong.
Assessment methodology: aligned to the structure of ISO 22301:2019, Security and resilience — Business continuity management systems — Requirements, including Amendment 1:2024 (climate action changes), with ISO 22313:2020 as supporting guidance. Business continuity is assessed separately from disaster recovery; see the Disaster Recovery Readiness Assessment for technology recovery. This is a self-assessment, not a certification, a compliance determination or a prediction of any disruption.
See your full results
Enter your email to unlock your score, readiness tier, domain scores, critical gaps and recommended priorities.
- Overall score and readiness tier
- 13 domain scores
- Critical gaps, with ISO 22301 clause references
- Continuity gaps by domain: BIA, plans, crisis, suppliers, exercises
- Recommended next steps and an email copy
Your BCP Readiness Score
Domain scores
Weighted: Business Impact Analysis 12% · Business Continuity Plans 12% · Continuity Strategy 10% · Exercises & Testing 10% · Governance 8% · Risk & Continuity Requirements 8% · Supplier Continuity 8% · Crisis Management 7% · Communications 6% · Resource Requirements 5% · Performance Evaluation 5% · Continual Improvement 5% · Context & Scope 4%. Expand a domain to see the contributing questions, your answers and the ISO 22301 clauses they map to.
Your highest-priority business continuity gaps
Recommended next steps
Assessment methodology: aligned to the structure of ISO 22301:2019, Security and resilience — Business continuity management systems — Requirements, including Amendment 1:2024 (climate action changes), with ISO 22313:2020 as supporting guidance. Business continuity is assessed separately from disaster recovery; see the Disaster Recovery Readiness Assessment for technology recovery. Readiness tiers are My CISO Partner presentation bands, not ISO ratings. Framework references are crosswalks, not compliance determinations. Business continuity and disaster recovery are scored separately and never combined; a continuity requirement (for example a 4-hour recovery) that technology cannot meet is a continuity-to-technology recovery gap, surfaced by taking both.
Want the full picture?
Your free assessment identifies continuity gaps based on your responses. A full readiness review validates the business impact analysis, recovery requirements, supplier dependencies and the exercise record against ISO 22301, with evidence. 30 minutes. No obligation. No sales pitch.