4.4 Gap Analysis & the BCMS Implementation Methodology

Key Takeaways

  • A gap analysis answers three questions in order — what is the current state, what is the desired state, and what is the difference between them — and the third answer is the input that sizes the implementation project.
  • Gap analysis is not an internal audit: it runs before the BCMS exists, produces gaps rather than nonconformities, requires no auditor independence, and carries no corrective-action obligation under Clause 10.1.
  • PECB teaches BCMS implementation through its IMS2 Methodology, a phased project approach running from initiation through planning, implementation, monitoring, and continual improvement.
  • A defensible gap analysis is clause-by-clause across ISO 22301 Clauses 4 to 10, scores each requirement on a maturity scale, and records the objective evidence that justifies the score.
  • The gap register converts directly into the implementation roadmap: each gap becomes a work package with an owner, an effort estimate, a dependency, and a target date.
Last updated: August 2026

Chapters 2 and 3 established the context, scope, leadership, and policy. Section 4.1 set the objectives. A question remains that the standard itself never answers, because ISO 22301 specifies what a conforming BCMS must contain and never how to get there: given an organization that has none of this today, in what order do you build it, and how do you know how much work it is?

That is what the implementation methodology and the gap analysis are for. Both appear explicitly in the PECB Domain 3 knowledge statements — "Knowledge of the principal approaches and methodology used to implement a BCMS" and "Knowledge of the gap analysis to determine the current state, the desired state, and the difference between the two" — and both are habitually under-studied because neither has a clause number to revise from.


1. Initiating the Implementation Project

Before methodology comes mandate. A BCMS implementation that begins with a consultant writing policy drafts, rather than with an approved project, fails predictably: it has no budget line, no decision forum, and no authority to compel departmental participation in the BIA.

The initiation phase produces four artefacts:

ArtefactPurposeTypical owner
Business caseJustifies the investment in terms the board recognises — regulatory obligation, customer contractual demand, tender eligibility, quantified disruption exposure from historical incidentsSponsor / Lead Implementer
Project charterFormally authorises the project; names the sponsor, the project manager, the scope boundary, the budget envelope, and the target certification dateTop management
Governance structureEstablishes the Business Continuity Steering Committee, its meeting cadence, and its escalation authority (see Section 3.1)Top management
Preliminary gap analysisSizes the work, tests the feasibility of the target date, and converts the charter's ambition into a costed planLead Implementer

Note the sequencing dependency: the charter authorises the gap analysis, and the gap analysis then corrects the charter's assumptions. A charter that fixes a certification date before anyone has measured the gap is committing to a date on no evidence, and it is the single most common cause of BCMS projects that miss Stage 2 readiness.

Choosing an implementation approach

Three approaches recur in practice, and the exam expects you to be able to justify a choice rather than name a favourite:

  • Full-scope simultaneous implementation. All in-scope activities are addressed in one programme. Fastest to certification and cheapest per unit of scope, but requires sustained resource commitment and high organizational maturity.
  • Phased implementation by business unit or site. A pilot unit is taken to full conformity, lessons are harvested, and the pattern is replicated. Slower and more expensive overall, but de-risks method errors and builds internal competence. Preferred where the organization has no prior management system.
  • Integrated implementation alongside an existing management system. Where ISO 9001, ISO 14001, or ISO/IEC 27001 is already certified, the shared Annex SL clauses — context, leadership, planning, support, performance evaluation, improvement — are extended rather than duplicated (see Section 1.3). Substantially the cheapest route where it is available.

PECB's IMS2 Methodology

PECB teaches implementation through its own IMS2 Methodology (Integrated Implementation Methodology for Management Systems and Standards), and the course learning objectives state that participants will "initiate and plan the implementation of a BCMS based on ISO 22301, by utilizing PECB's IMS2 Methodology and other best practices."

IMS2 is a phased project methodology whose sequence mirrors the structure of this guide and of the standard itself:

  1. Initiation — mandate, business case, charter, governance, preliminary gap analysis
  2. Planning — context, scope, policy, objectives, risk and opportunity treatment, resourcing, documented information (Clauses 4-7)
  3. Implementation — BIA, risk assessment, strategies and solutions, plans and procedures, exercising (Clause 8)
  4. Monitoring and measurement — metrics, internal audit, management review (Clause 9)
  5. Continual improvement and certification — nonconformity treatment, improvement, certification audit (Clause 10 and beyond)

The examinable point is not the trademark. It is that a BCMS is implemented as a governed project with phases, gates, and deliverables, and that the phase sequence follows the clause sequence for a reason: you cannot scope what you have not contextualised, and you cannot build continuity solutions for activities you have not yet prioritised in the BIA.


2. The Gap Analysis: Three Questions in Order

A gap analysis is deceptively simple in structure and frequently botched in execution.

StepQuestionOutput
1. Current stateWhat do we actually have today, evidenced?Baseline assessment per requirement
2. Desired stateWhat does conformity require of this organization, given its scope and context?Target maturity per requirement
3. The differenceWhat specifically is missing, and how much work is it?Gap register — the project's real backlog

The failure mode is stopping at step one. An assessment that reports "we score 2.1 out of 5 on Clause 8" has described a current state and called it a gap analysis. It has not defined the target, so it cannot state the difference, so it cannot size a project.

Determining the current state honestly

The evidence standard matters more than the questionnaire. For each requirement, record what was seen, not what was claimed:

  • Documented information reviewed — the actual policy, procedure, register, or plan, with its version and approval date
  • Interviews — with the process owner, not only with the person sponsoring the project
  • Observation — does the mass notification system actually reach staff? has the alternate site ever been occupied?
  • Records — evidence that the process has operated, not merely that it is written down

The distinction between a documented process and an operating process is the same distinction Stage 1 and Stage 2 certification audits draw (Section 11.1). An organization with excellent documentation and no records is far from certifiable, and a gap analysis that scores it on documentation alone will understate the project by months.

Defining the desired state

The desired state is not "5 out of 5 everywhere." ISO 22301 requires conformity, not maximum maturity, and over-specifying the target inflates the project and wastes capital. Set the target as:

  • Conformity for every "shall" in Clauses 4 through 10 that applies within the declared scope — this is non-negotiable and binary
  • Proportionate maturity beyond conformity, driven by the organization's risk appetite, regulatory exposure, and customer commitments

An organization subject to DORA or APRA CPS 230 will set a higher target for exercising and third-party dependency management than a domestic manufacturer with no regulatory continuity obligation, even though both must merely conform to Clause 8.5.

A clause-by-clause gap analysis instrument

ClauseRequirement (abbreviated)Current maturityEvidence seenTargetGapEffort
4.1Internal and external issues determined2Informal SWOT in strategy deck; not maintained3Formalise and schedule review of context profileS
4.2Interested parties and their requirements1None3Build stakeholder requirements matrixM
5.2BC policy established and communicated3Policy v1.2 approved, published on intranet3None
6.2Measurable BC objectives set1Aspirational statements only, not measurable3Define SMART objectives with owners and monitoringM
8.2.2BIA conducted0None4Full BIA across in-scope activitiesXL
8.2.3Risk assessment conducted2Enterprise risk register exists but is not disruption-focused4Disruption-specific assessment aligned to BIA outputsL
8.4.4Business continuity plans documented1Two legacy IT DR runbooks, untested since 20234Develop BCPs for all prioritised activitiesXL
8.5Exercising and testing programme0None4Multi-year progressive exercise programmeL
9.2Internal audit programme1Quality internal audit exists; no BCMS scope3Extend audit programme to BCMS clausesM
9.3Management review0None3Establish review cadence, inputs, and outputsS
10.1Nonconformity and corrective action2Corrective action process exists in QMS3Extend to BCMS findingsS

A five-point maturity scale (0 = absent, 1 = ad hoc, 2 = partially documented, 3 = documented and conforming, 4 = operating with records, 5 = optimised and improving) is sufficient. What makes the instrument defensible is the evidence column, which is what a certification body will effectively re-perform at Stage 1.


3. From Gap Register to Implementation Roadmap

The gap register is not a report to be filed. Each gap becomes a work package:

FieldWhy it is required
OwnerA named individual; a gap owned by "the business" is not owned
Effort estimateSized in person-days, not T-shirt sizes, once the gap is understood
DependencyThe BIA gates strategy selection; strategy gates plan development; plans gate exercising
Target dateBack-planned from the certification date, not forward-planned from today
Clause referencePreserves the audit trail from requirement to remediation

Three dependency rules govern sequencing and are examinable:

  1. Clause 8.2.2 (BIA) precedes Clause 8.3 (strategies). You cannot select continuity solutions for activities whose recovery priorities and time objectives are unknown.
  2. Clause 8.3 (strategies) precedes Clause 8.4 (plans). A plan documents how an approved strategy is executed; drafting plans first produces documents nobody has funded the resources to honour.
  3. Clauses 9.2 and 9.3 (internal audit and management review) precede Stage 1. A certification body will check that at least one full cycle of each has occurred. This is the single most common reason organizations are refused progression to Stage 2, and because internal audit and management review can only audit a BCMS that has operated for a period, they must be scheduled backwards from the certification date with real operating time in front of them.

The roadmap is then presented to the steering committee as a re-baselined plan, and — critically — the charter's original certification date is revised against evidence rather than defended.


4. Gap Analysis Is Not an Internal Audit

Candidates conflate these constantly, and Domain 3 and Domain 5 both test the boundary.

DimensionGap analysisInternal audit (Clause 9.2)
WhenBefore the BCMS exists; repeatable during implementationAfter the BCMS is operating
PurposeSize the work and plan the projectDetermine conformity and effectiveness
Against whatThe standard and a chosen target maturityThe organization's own requirements and ISO 22301
OutputGaps and work packagesNonconformities, OFIs, and conformity findings
IndependenceNot required; usually run by the implementerRequired — auditors must not audit their own work
Obligation createdProject scopeCorrective action under Clause 10.1
Required by ISO 22301NoYes

The consequence that matters: a finding in a gap analysis creates no Clause 10.1 corrective-action obligation, whereas a nonconformity raised in an internal audit does. And because the Lead Implementer typically runs the gap analysis, that same person is disqualified from auditing the clauses they remediated — the independence rule in Section 10.2.


5. Worked Implementation Scenario: A Regional Insurer's Re-Baselined Roadmap

Context. A regional insurer with 900 staff across three sites holds ISO/IEC 27001 certification. The board approves a charter targeting ISO 22301 certification in nine months, driven by a broker consortium that has made certification a panel-eligibility condition.

Gap analysis findings. The Lead Implementer scores all of Clauses 4-10 against evidence:

  • Clauses 4, 5, 7, and parts of 9 and 10 score 3 or above — the ISO/IEC 27001 management system already satisfies context, leadership, competence, documented information, and corrective action, needing only scope extension. Estimated effort: 25 person-days.
  • Clause 6.2 scores 1. Objectives exist but are not measurable. Effort: 10 days.
  • Clause 8.2.2 scores 0. No BIA has ever been performed across 46 in-scope activities. Effort: 90 days.
  • Clause 8.4.4 scores 1. Two IT runbooks, last tested in 2023, cover none of the business activities. Effort: 110 days.
  • Clause 8.5 scores 0. No exercise programme. Effort: 45 days.

The difference. Roughly 280 person-days of remediation — but the binding constraint is not effort, it is dependency and elapsed time. The BIA must complete before strategies can be selected; strategies before plans; plans before the first exercise; and internal audit plus management review must then run over an operating BCMS before Stage 1.

Outcome. The Lead Implementer re-baselines to fourteen months and presents the dependency chain to the steering committee, showing that a nine-month date would deliver documented plans that had never been exercised and no completed internal audit cycle — an organization that would be refused progression from Stage 1 to Stage 2. The board accepts the revised date and notifies the broker consortium. Certification is achieved in month thirteen with two minor nonconformities and no majors.

The value delivered was not the assessment. It was the difference — quantified early enough to correct a commitment made without evidence.


6. PECB Exam Warning Traps & Implementation Pitfalls

[!WARNING] Trap 1 (Gap analysis is not required by ISO 22301): No clause of ISO 22301 mandates a gap analysis. It is an implementation best practice PECB expects you to know and apply — but an organization that never performed one is not thereby nonconforming. An organization that never performed an internal audit (Clause 9.2) is.

[!WARNING] Trap 2 (The three-part definition): If asked what a gap analysis determines, the complete answer is current state, desired state, and the difference between the two. An option describing only the current-state assessment is the most attractive distractor.

[!WARNING] Trap 3 (Target state is conformity, not maximum maturity): Setting every requirement to maturity 5 is a planning error that inflates cost and delays certification. The desired state is conformity with every applicable "shall", plus proportionate maturity where risk and obligations justify it.

[!WARNING] Trap 4 (Independence carries forward): The person who ran the gap analysis and remediated the gaps cannot later audit those clauses under Clause 9.2. Plan the internal audit resource — a trained second auditor, a peer from another site, or an external contractor — during initiation, not two months before Stage 1.

[!WARNING] Trap 5 (Sequencing is not preference): BIA before strategies before plans before exercises is a dependency, not a stylistic choice. Exam scenarios that show an organization drafting business continuity plans before completing the BIA are describing a nonconformity against Clause 8.3 and 8.4, because the plans cannot be traceable to prioritised activities and their recovery time objectives.

Loading diagram...
Gap Analysis Logic and Its Conversion into a Dependency-Sequenced Roadmap
Test Your Knowledge

A Lead Implementer presents a 40-page report scoring every clause of ISO 22301 against the organization's present capability on a five-point maturity scale, supported by document references and interview notes. The steering committee asks how long implementation will take and the Lead Implementer cannot answer. What is missing from the analysis?

A
B
C
D
Test Your Knowledge

An organization's board fixes a certification date nine months out in the project charter, before any assessment has been performed. The subsequent gap analysis shows no BIA exists across 46 in-scope activities and no exercise programme has ever run. What is the Lead Implementer's correct response?

A
B
C
D
Test Your Knowledge

Which statement correctly distinguishes a BCMS gap analysis from an internal audit conducted under ISO 22301 Clause 9.2?

A
B
C
D