ISO 22301 certification in Angola
ISO 22301 is the international business continuity standard. It prepares the organisation to keep critical activities running through a disruption.

What ISO 22301 is
ISO 22301 is built on business impact analysis, disruption risk assessment, recovery time objectives, continuity and recovery plans, and exercises to test those plans.
How we prepare the certification
- 01AssessmentReview of the current situation against the standard's requirements and identification of the gaps to close.
- 02Scope and contextDefinition of the certification scope, interested parties and applicable legal requirements.
- 03Process and risk mapProcess design, assignment of owners and assessment of the associated risks and opportunities.
- 04DocumentationPolicy, procedures, instructions and records written for the actual operation, not generic templates.
- 05Training and roll-outTeam training and day-to-day roll-out of the system, with evidence of real use.
- 06Internal auditInternal audit run by network auditors, recording non-conformities and corrective actions.
- 07Pre-auditSimulation of the certification audit and closure of the final gaps, ahead of the independent DQS audit.
Preparing and certifying are separate functions
Export Lab handles the assessment, system design, documentation, training and internal audit. The certification audit is conducted independently by DQS. That separation is what makes the certificate credible to clients, regulators and international partners.
The Angolan context
Power failures, communication outages, logistics disruption or IT incidents affect operations in concrete ways. Business continuity defines, before the incident, who decides, what keeps running and how fast recovery happens.
Cost and timeline: what makes them vary
We do not publish list prices for ISO 22301, because the effort is not the same in two different organisations. The investment always has two separate components: preparation, delivered by Export Lab, and the certification audit, billed by the certification body.
What drives cost: Number of critical processes and locations, depth of the business impact analysis, supplier and infrastructure dependencies, and the resources required by the chosen continuity strategies.
What drives the timeline: Timeline is set by the business impact analysis, defining recovery strategies and, above all, running the exercises and tests the audit needs to assess.
After the initial assessment, scope, schedule and price are presented in writing, before any commitment.
What your company gains
- Critical activities and recovery times defined.
- Plans that are tested, not just written.
- Incident response with assigned roles.
Frequently asked questions
- Who needs ISO 22301?
- Organisations where disruption has immediate material impact: banking, telecoms, energy, logistics, healthcare, shared services and suppliers with contracted service levels.
- Is ISO 22301 mandatory in Angola?
- ISO 22301 is voluntary. Some regulated sectors have continuity requirements imposed by the regulator or by clients; the standard gives them an auditable framework.
- How much does ISO 22301 certification cost?
- There is no list price. The figure follows from scope and starting point — specifically: Number of critical processes and locations, depth of the business impact analysis, supplier and infrastructure dependencies, and the resources required by the chosen continuity strategies. Preparation and the certification audit are billed separately, the latter by the certification body.
- How long does ISO 22301 implementation take?
- We do not quote fixed timelines before the assessment. Timeline is set by the business impact analysis, defining recovery strategies and, above all, running the exercises and tests the audit needs to assess. A realistic schedule is set out in the proposal.
- Who issues the certificate? Does Export Lab also certify?
- No. Export Lab prepares and implements; the ISO 22301 certification audit is conducted independently by DQS. Whoever prepares cannot certify, and that separation is what gives the certificate value with clients and regulators.
- What happens after certification?
- Three-year cycle with annual DQS audits. Maintenance requires regular plan testing, updating the impact analysis when the business changes, and recording lessons from exercises.
- Is an IT disaster recovery plan enough?
- No. IT recovery is one component. ISO 22301 requires business continuity: people, facilities, suppliers, stakeholder communication and resumption priorities derived from the impact analysis, not just systems restoration.
1 network specialist in this area
Independent network consultants specialising in Business Continuity and ISO 22301.