Business backup: ISO 27001, ISO 22301 and NIS2 requirements
In brief
A practical guide to business backups and their relationship with ISO 27001, ISO 22301 and NIS2. It covers backup policies, RPO/RTO objectives, restore testing, compliance evidence and tools with no additional licence cost, including their terms of use and limitations.
A business needs to know which data it protects, how much data it can afford to lose and how quickly it can restore its critical operations. Successfully completing a backup job is only part of that answer.
ISO/IEC 27001 does not require a particular software brand or the purchase of a commercial edition. A free tool can support backup requirements if its licence permits the intended use and its implementation addresses the business's needs and risks. Evidence of execution and successful restoration is also necessary.
For management, the management system coordinator and the IT team, the key question is the same: if the ERP system, a server or production files were lost today, could the business resume operations within the acceptable timeframe?
What do standards and legislation require for backups?
The frameworks below have different scopes. A business should first identify which requirements apply to it, then organise the corresponding controls and evidence.
ISO/IEC 27001:2022
- Relevant reference: Annex A, control A.8.13 on information backup; related controls A.5.29, A.5.30 and A.8.14
- Practical implications: Backups of information, software and systems, with regular testing in accordance with a policy. Links to information security during disruption and ICT readiness for business continuity.
- Source: [1]
ISO/IEC 27002:2022
- Relevant reference: Implementation guidance for control 8.13
- Practical implications: Supports the design of backup scope, frequency, retention, protection and testing. It is a guidance standard, not a standalone certification standard.
- Source: [2]
ISO 22301:2019
- Relevant reference: Clauses 8.2.2, 8.3, 8.4 and 8.5
- Practical implications: Business impact analysis, selection of strategies, continuity plans and exercises. Backup forms part of the recovery solution.
- Source: [3]
GDPR — Regulation (EU) 2016/679
- Relevant reference: Article 32
- Practical implications: Appropriate security measures based on risk, the ability to restore availability and access to personal data in a timely manner, and regular evaluation of those measures.
- Source: [4]
Greek Law 5160/2024 — transposition of NIS2
- Relevant reference: Article 15(2)(c)
- Practical implications: For entities within scope, business continuity measures include backup management and disaster recovery.
- Source: [5]
Greek Joint Ministerial Decision 1689/2025, Government Gazette Series B 2186/6 May 2025
- Relevant reference: Article 25(1), particularly points (d)–(g)
- Practical implications: Specifies requirements for a written backup policy and procedures, automated backups based on criticality and policy, access protection and periodic sample restore tests.
- Source: [6]
Under ISO 27001, the selection of necessary controls is linked to risk assessment and risk treatment and documented in the Statement of Applicability (SoA). Installing a backup tool supports specific controls; certification assesses the information security management system as a whole.
NIS2 applies to essential and important entities falling within its legal scope. Their suppliers may have contractual cybersecurity obligations without automatically becoming entities subject to NIS2. Scope is determined using the legislation's criteria and the guidance issued by Greece's National Cybersecurity Authority [7].
Meeting backup requirements is one part of compliance with each framework. It does not replace the other organisational and technical obligations.
RPO and RTO: how much data and downtime can you tolerate?
Two objectives help management and IT translate business needs into technical specifications:
- RPO — Recovery Point Objective: the maximum acceptable data loss, expressed as a period of time. An RPO of four hours means that the business accepts losing up to four hours of data.
- RTO — Recovery Time Objective: the target time for restoring a function or service after a disruption.
If the ERP system has an RPO of four hours, a single daily backup will generally be insufficient. If the RTO is four hours but a restore test takes two days, the recovery solution or business arrangements need to change.
These objectives are determined by the criticality, business impacts and dependencies of each function. Applying the same backup schedule to every system may leave the most critical data inadequately protected.
Example from a manufacturing business
In a manufacturing SME, restoring the ERP system may depend on the database, application server, authentication service and available software licences. Production may also require CAD drawings, CNC programs, equipment configurations and quality control records.
In an illustrative exercise, with both RPO and RTO set at four hours, the business restores the ERP system in an isolated environment. It checks recent transactions, opens the application using an authorised account and confirms that a test transaction document can be issued.
If the service is restored in six hours, the exercise records a deviation from the RTO, even if all files have been recovered. If transactions from the last seven hours are missing, there is also a deviation from the RPO. These findings lead to specific corrective actions.
Seven points for a documented backup process
The following is a practical checklist, not an exhaustive list of certification requirements. Assessment considers the process, the solution's capabilities and configuration, and its effectiveness.
1. An approved policy and clear responsibilities
The policy defines what is backed up, when, where backups are stored, how long they are retained and who checks execution. It identifies the responsible person and a deputy, and covers failure handling and a testing schedule.
Evidence: an approved policy, allocated responsibilities and a documented review.
2. Documented scope and dependencies
Record servers, virtual machines, workstations, databases, cloud services, files and critical configurations. Exclusions need justification and an assessment of the associated risk.
For ERP systems and databases, agree with the application provider on a method for creating a consistent backup and on the restoration procedure. Simply copying open database files does not demonstrate that the application will work.
Evidence: a system inventory, mapping to backup jobs and application restoration instructions.
3. Frequency based on recovery objectives
Align scheduling with the RPO and assess whether the infrastructure can achieve the RTO. Consider data volume, connection speed, available equipment and the sequence of recovery activities.
Evidence: approved objectives, job settings and measurements from tests.
4. Appropriate retention and version history
Multiple restore points help when deletion or corruption is detected after a delay. Retention periods depend on recovery needs, applicable obligations and the type of data.
Distinguish operational backup from the archive used for long-term document retention. An obligation to retain specific transaction records does not automatically justify keeping all personal data in every backup indefinitely.
Evidence: retention rules, available restore points and an expiry or deletion procedure.
5. Copies that withstand a shared failure or attack
The 3-2-1-1-0 rule is a useful design practice:
- 3 copies in total, including the production data.
- 2 different storage media or technologies.
- 1 copy outside the primary site.
- 1 offline or immutable copy.
- 0 errors in verification checks and tests.
This combination is not a universal numerical requirement of ISO standards. The business selects and documents an appropriate architecture based on its risks.
A copy stored on the same NAS and accessible with the same deletion permissions may be lost alongside production data. RAID provides disk redundancy but does not replace backup. A snapshot is not automatically immutable: appropriate capabilities and protection settings are necessary.
Evidence: a storage architecture diagram, isolation or immutability settings, and successful recovery from the protected copy.
6. Protection of access and encryption keys
Apply least-privilege access rights, appropriate account separation and multifactor authentication where supported. Select encryption appropriate to data sensitivity and the risks of storage and transfer.
Keys must remain available when the primary systems are unavailable. Losing them may make a correctly stored backup unusable. Immutability protects against modification or deletion; confidentiality requires separate controls.
Evidence: access rights, protection settings, a key management procedure and controlled emergency access.
7. Monitoring and actual restore tests
Define who receives failure alerts, when they review them and how each problem is resolved. Test restoration of files, applications and critical services as appropriate to the environment.
For example, an SME might schedule quarterly file restore tests and an annual exercise to recover a critical service. This is an illustrative schedule, not a universal ISO minimum. Critical systems or significant changes may require more frequent testing.
Backup integrity checks, successful file retrieval and operational service recovery test different things. A green job status does not, by itself, demonstrate that the ERP system can operate.
Evidence: logs, alert handling records, test results and corrective actions.
Free backup tools: what does the licence permit?
The label “Free” is not sufficient grounds for a business installation. Check the exact edition, its licence, the permitted operating environment and the conditions for services provided by third parties.
For example, AOMEI presents Backupper Standard [8] among its home-use editions and distinguishes its business editions. Hasleo Backup Suite Free [9] excludes business use in its edition comparison. Assuming that every free application is permitted on a company computer can therefore lead to an unsuitable choice.
A significant distinction applies to Veeam Free and Community products: section 1.17.2 of the Licensing Policy [10] permits use within the business's own production environment but imposes restrictions on use for services to third parties. These restrictions include support and consulting services for existing installations of those editions. Permission for internal use should therefore not be treated as authorisation for an external provider to serve clients.
Open-source licences generally permit commercial use while retaining obligations that depend on the licence and how the software is used or distributed. Keep the applicable terms in the software register and recheck them before installation or a change in service arrangements.
Business backup tools: licences, uses and limitations
This overview is based on manufacturers' public documentation. It is not an independent performance test or a certification of suitability. The options address different needs and are not fully interchangeable.
Veeam Agent for Microsoft Windows Free
- Licence and business use: Free, subject to Veeam Free/Community terms
- Primary use: System, volume or file backups on Windows
- Limit or consideration: Check the edition and the management capabilities you need. Restrictions on services to third parties apply.
- Source: [11]
Veeam Backup & Replication Community Edition
- Licence and business use: Free for the business's own use, subject to the applicable terms
- Primary use: Virtual machines, agents and other supported workloads
- Limit or consideration: Up to 10 workloads under the licensing rules. Limits for NAS and other objects require specific checking.
- Source: [12]
Veeam Backup for Microsoft 365 Community Edition
- Licence and business use: Free, subject to Free/Community terms
- Primary use: Supported Microsoft 365 data
- Limit or consideration: Limits of 10 user accounts, 10 Teams teams and 1 TB of SharePoint data, aggregated across all organisations. The edition's terms apply.
- Source: [13]
UrBackup
- Licence and business use: Open source, AGPLv3+
- Primary use: Centralised file and system image backups on supported platforms
- Limit or consideration: Check operating system and file system support for image backups. Storage and administration need to be planned.
- Source: [14]
Duplicati
- Licence and business use: The core is available under MIT; separately licensed components also exist
- Primary use: Encrypted file backups to local or remote destinations
- Limit or consideration: It does not provide a full system image. Additional management services have separate plans and terms.
- Source: [15]
Kopia
- Licence and business use: Open source, Apache 2.0 [17]
- Primary use: Encrypted file and directory backups
- Limit or consideration: It is not a full image backup tool. Policies, access and keys need to be organised.
- Source: [16]
Proxmox Backup Server
- Licence and business use: Open source, AGPLv3; optional subscriptions
- Primary use: Proxmox VE environments and supported client-based backups
- Limit or consideration: Infrastructure and technical administration are necessary. A subscription adds enterprise repository access and support services, depending on the plan.
- Source: [18]
Synology Active Backup
- Licence and business use: No additional licence for the relevant packages on a compatible Synology NAS
- Primary use: Computers, servers and VMs; separate packages for Microsoft 365 [20] and Google Workspace [21]
- Limit or consideration: A NAS must be purchased and managed. Scale depends on the model, capacity and performance requirements.
- Source: [19]
Windows Server Backup / wbadmin
- Licence and business use: A feature of an appropriately licensed Windows Server
- Primary use: Backup and restoration in Windows Server environments
- Limit or consideration: The overall solution requires additional planning for monitoring, isolation and application recovery.
- Source: [22]
No additional licence cost does not mean no overall cost. Budget for storage, equipment, connectivity, administration time, testing, support and any cloud data retrieval charges.
The need for support with a defined response time should also be assessed separately. Commercial free editions and open-source tools do not automatically include a contractual production support SLA.
Microsoft 365 and Google Workspace: what should you check?
File synchronisation alone is not an independent backup strategy: it may propagate deletion or corruption to every synchronised device.
Cloud services offer different recovery mechanisms, including version history, recycle bins and retention policies. Dedicated backup solutions also exist, including Microsoft 365 Backup [23], with recovery capabilities for supported Exchange, OneDrive and SharePoint data.
Evaluate the actual capabilities of the service or subscription:
- Which data and objects are covered?
- How long do restore points remain available?
- Who can delete data, backups or policies?
- Are the RPO and RTO objectives achieved?
- Has recovery of the data the business needs been tested?
This assessment determines the need for an additional or independent solution. There is no universal requirement for every business to purchase a particular third-party tool.
What evidence should be available?
An organised evidence pack connects each requirement to implementation and results:
- Responsibilities and rules: An approved backup policy, a responsible person and a deputy
- Coverage and priorities: A system inventory, dependencies, RPO/RTO objectives and justified exclusions
- Execution and failures: Job settings, logs, alerts and evidence that problems were resolved
- Backup protection: Access rights, encryption where required, key protection and an isolated copy
- Effectiveness: Restore records, recovery time, completeness checks and operational confirmation
- Lawful use and improvement: Licence terms, periodic reviews and completed corrective actions
A restore test record should include, at a minimum, the system, scenario, backup restore point, start and completion times, actual data loss, operational checks, outcome and outstanding actions.
Reports and screenshots should demonstrate the controls without exposing passwords, encryption keys or unnecessary personal data.
Frequently asked questions about backup and compliance
Can a business support ISO 27001 with free backup software?
Yes, provided that the tool is permitted for the specific use, meets protection and recovery requirements, and its effectiveness is documented. A free licence neither demonstrates nor rules out compliance.
Is a daily backup to an external drive sufficient?
It depends on the RPO, version history, and the drive's protection and isolation. A permanently connected drive accessible through a compromised account may be affected by the same attack.
Is 3-2-1-1-0 mandatory?
It is an architectural good practice, not a universal numerical ISO requirement. Specific regulatory or contractual requirements should be assessed separately. The business must justify that its chosen solution addresses the relevant risks.
Does a successful backup mean that the RTO has been achieved?
No. Recovery time includes activities such as making infrastructure available, retrieving data, restoring dependencies and checking operation. A timed test is necessary.
Does losing personal data always require notification?
Loss or unavailability may constitute a personal data breach. Notification to the supervisory authority and communication to affected individuals are assessed against the different risk criteria in GDPR Articles 33 and 34. Backup helps recovery but does not automatically negate a breach. The EDPB guidelines on personal data breaches provide relevant guidance [24].
From backup policy to operational readiness
Start with three specific actions: record critical systems, approve recovery objectives and perform a restore test for a critical service. The results will identify which gaps need priority attention.
For support in organising the management system, assessing gaps and connecting policy, risks and evidence, contact Certway [25]. The assessment can provide a basis for an action plan and testing programme, in cooperation with IT personnel and in accordance with the applicable licensing terms.
Contact: support@certway.gr · +30 213 038 1235
This overview is based on the primary sources listed at the end of the article and public documentation checked on 11 October 2026. Before selecting or installing a product, confirm the capabilities and terms of the specific edition. The practical recommendations and examples should be adapted to each business's needs.
Sources and official documentation
- ISO/IEC 27001:2022: https://www.iso.org/standard/27001
- ISO/IEC 27002:2022: https://www.iso.org/standard/75652.html
- ISO 22301:2019: https://www.iso.org/standard/75106.html
- GDPR — Regulation (EU) 2016/679: https://eur-lex.europa.eu/eli/reg/2016/679/oj
- Greek Law 5160/2024 — transposition of NIS2: https://cyber.gov.gr/wp-content/uploads/2024/12/ENOTHTA_5_%CE%9D%CE%9F%CE%9C%CE%9F%CE%98%CE%95%CE%A3%CE%99%CE%91_fek_a_195_2024-5160-2024-1.pdf
- Greek Joint Ministerial Decision 1689/2025, Government Gazette Series B 2186/6 May 2025: https://cyber.gov.gr/wp-content/uploads/2025/05/20250202186.pdf
- Greece's National Cybersecurity Authority — NIS2 scope: https://cyber.gov.gr/nis2-scope/
- AOMEI Backupper — edition comparison: https://www.aomeitech.com/ab/comparison.html
- Hasleo Backup Suite Free: https://www.easyuefi.com/backup-software/backup-suite-free.html
- Veeam Licensing Policy, section 1.17.2: https://www.veeam.com/legal/licensing-policy.html
- Veeam Agent for Microsoft Windows Free: https://www.veeam.com/products/free/microsoft-windows.html
- Veeam Backup & Replication Community Edition: https://www.veeam.com/products/free/backup-recovery.html
- Veeam Backup for Microsoft 365 Community Edition: https://helpcenter.veeam.com/docs/vbo365/guide/vbo_licensing.html
- UrBackup: https://www.urbackup.org/features.html
- Duplicati: https://github.com/duplicati/duplicati
- Kopia: https://kopia.io/docs/
- Kopia — source code and Apache 2.0 licence: https://github.com/kopia/kopia
- Proxmox Backup Server: https://pbs.proxmox.com/docs/introduction.html
- Synology Active Backup: https://www.synology.com/en-global/dsm/feature/active-backup-business/physical-server
- Synology Active Backup for Microsoft 365: https://www.synology.com/en-global/dsm/feature/active_backup_office365
- Synology Active Backup for Google Workspace: https://www.synology.com/en-global/dsm/feature/active_backup_google_workspace
- Windows Server Backup / wbadmin: https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wbadmin
- Microsoft 365 Backup: https://learn.microsoft.com/en-us/microsoft-365/backup/backup-overview
- EDPB — guidelines on personal data breaches: https://www.edpb.europa.eu/system/files/documents/2022-01/edpb_guidelines_012021_pdbnotification_adopted_en.pdf
- Certway — contact: https://www.certway.gr/