- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Archlight is a vCISO / ISO 27001 consultancy based in Minneapolis, MN, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Framework Cross-Industry Management Systems
ISO 22301
ISO 22301 is the international standard for a business continuity management system (BCMS). It asks an organization to work out which products and services matter most, how quickly each must be recovered, what resources that depends on, and then to build, exercise, and maintain plans that make recovery achievable. The current edition is ISO 22301:2019.
A revision is under way in ISO/TC 292; a committee draft was registered in March 2026, so a new edition is expected but not yet published (verify status before citing a date).
On paper, the standard expects a BCMS scope and policy, a business impact analysis, a risk assessment, a documented continuity strategy, business continuity plans and procedures (including incident response and communications), an exercise and testing program with results, and the usual management system records: objectives, competence, internal audits, management review, and corrective actions.
Who has to comply
Voluntary. Common in financial services, outsourcing and managed service providers, data centers, logistics, and any organization whose customers or regulators ask for evidence of continuity capability. Some sector regulators accept ISO 22301 certification as supporting evidence for their own resilience rules but rarely mandate it outright.
What the assessor asks to see
Scope and policy; context and interested parties, including legal and regulatory requirements; business impact analysis with recovery time and recovery point objectives; risk assessment and treatment; continuity strategy and resource requirements; business continuity plans, incident response structure, and communication procedures; exercise and test schedule with post-exercise reports; supplier and outsourcing continuity arrangements; awareness and competence records; performance monitoring; internal audit and management review records; corrective actions.
Where the requirement sits: 5.2 policy; 7.5 documented information; 8.2 BIA; 8.4 BC plans; 8.5 exercise programme
Revision in progress
ISO/TC 292 approved a project to revise ISO 22301. The committee draft (ISO/CD 22301) was registered on March 12, 2026 with comments closing May 10, 2026. A companion revision of the guidance standard ISO 22313 has also started.
Until the new edition is published and an accreditation transition period is announced, ISO 22301:2019 remains the certifiable edition.
What AllyMatter does here
Controls the BC plans and proves staff acknowledgment.
AllyMatter publishes this site.
Assessors
Who assesses ISO 22301
Accredited certification body accredited to ISO/IEC 17021-1 for business continuity management systems. Accredited by National accreditation bodies under the Global ACI (formerly IAF) multilateral arrangement, such as ANAB, UKAS, DAkkS, JAS-ANZ.
Public register of assessors: https://www.iafcertsearch.org/
No firm has claimed a ISO 22301 assessor listing yet. Claim yours →
Consultants
Who helps with ISO 22301
A mature consultant ecosystem exists, often overlapping with information security and risk consultancies. Implementers facilitate the business impact analysis and risk assessment workshops, draft the strategy and plans, design and run exercises, train plan owners, and prepare the organization for the certification audit. First-time engagements typically take four to nine months.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- BEMO is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Coral Esecure is a vCISO / ISO 27001 consultancy based in New Jersey, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Cycore is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Genius GRC is a vCISO / ISO 27001 consultancy based in Woodstock, GA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Illumen is a vCISO / ISO 27001 consultancy based in Pacific Northwest, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Neutral Partners is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Securis360 is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Soter Advisory is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Testpros is a vCISO / ISO 27001 consultancy based in Reston, VA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- TrustedCISO is a vCISO / ISO 27001 consultancy based in Remote, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Software
Tools for ISO 22301
Tools that name this framework in their own material.
Related reading
- The ISO 22301 requirements explainedRequirement-by-requirement read of the business continuity management system, written by the people who audit it.Schellman
- ISO 22301 certification: business continuity managementCertification body's account of scope-setting, the business impact analysis and how the audit cycle runs.DNV
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for ISO 22301
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of ISO 22301 in AllyMatter
Approve the policies ISO 22301 asks for, keep every version, and record a named acknowledgment from each person who has to read them.