MedTech Terms
    The authoritative reference
    All terms

    ISO 22301

    Standard for business continuity management systems.

    Reviewed by Christian Espinosa, Founder, Blue Goat CyberLast reviewed May 5, 2026

    Definition

    ISO 22301 specifies requirements to plan, establish, implement, operate, monitor, review, maintain, and continually improve a business continuity management system. Increasingly relevant for MedTech given EO supply, semiconductor, and contract-manufacturer disruptions.
    What the regulation says
    The FDA encourages manufacturers to implement robust quality management systems that include elements of business continuity, as outlined in 21 CFR Part 820, Quality System Regulation. While ISO 22301 is not directly mandated, its principles align with the FDA's expectations for ensuring product availability and addressing potential supply chain disruptions. The EU MDR (Regulation (EU) 2017/745) also implicitly supports business continuity through requirements for risk management and supply chain oversight, particularly in Annex I, General Safety and Performance Requirements, which emphasizes uninterrupted availability of devices.

    What this means in practice

    Hospital procurement teams and FDA shortage staff are both paying more attention to BCMS evidence from critical-device manufacturers.

    Examples

    • A MedTech manufacturer uses ISO 22301 to develop a plan for continuing production of life-sustaining devices during a regional power outage, including redundant power sources and alternative manufacturing sites.
    • Following an ISO 22301 framework, a company establishes agreements with multiple suppliers for critical components to prevent shortages caused by a single supplier's disruption.
    • A MedTech company simulates a cybersecurity attack as part of its ISO 22301 testing, identifying weaknesses in its data recovery and operational resumption procedures.
    Common pitfalls
    • A common pitfall is treating ISO 22301 compliance as a checkbox exercise rather than integrating it deeply into the overall quality management system.
    • Another mistake is failing to regularly test and update the business continuity plan, rendering it ineffective during an actual disruption.
    • Organizations often overlook the importance of communication strategies during a crisis, leading to confusion and delayed responses.
    • Some companies incorrectly assume that simply having an off-site backup for data constitutes a comprehensive business continuity plan.

    Frequently asked questions

    ISO 22301 is a critical component of an organization's overall risk management strategy, specifically addressing the risks associated with disruptions to operations. It helps MedTech companies identify potential threats and implement controls to mitigate their impact on product availability and patient safety.
    Grouped by theme

    Primary references

    3 sources
    Link health: 3 verified· last checked 2026-06-20
    ISO·2IEC·1
    1. 1
      ISO 22301
      Verified
      ISOiso.org
    2. 2
      ISO Standards Catalogue - Health
      Verified
      ISOiso.org
    3. 3
      IEC Webstore - Medical Equipment
      Verified
      IECwebstore.iec.ch

    Inline markers like [1] jump to the matching reference above.