HomeFrameworksCross-Industry Management SystemsISO 22301

Framework  Cross-Industry Management Systems

ISO 22301

ISO 22301 is the international standard for a business continuity management system (BCMS). It asks an organization to work out which products and services matter most, how quickly each must be recovered, what resources that depends on, and then to build, exercise, and maintain plans that make recovery achievable. The current edition is ISO 22301:2019.

A revision is under way in ISO/TC 292; a committee draft was registered in March 2026, so a new edition is expected but not yet published (verify status before citing a date).

On paper, the standard expects a BCMS scope and policy, a business impact analysis, a risk assessment, a documented continuity strategy, business continuity plans and procedures (including incident response and communications), an exercise and testing program with results, and the usual management system records: objectives, competence, internal audits, management review, and corrective actions.

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedBC plan v5by name, on record
Clause 7.5 Handledwith AllyMatter
Keep Going the Modern WayYour continuity plans, acknowledged by the people who run them
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every response team member on record
Who read which version, and when
03
Hand the registrar the trail
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

Voluntary. Common in financial services, outsourcing and managed service providers, data centers, logistics, and any organization whose customers or regulators ask for evidence of continuity capability. Some sector regulators accept ISO 22301 certification as supporting evidence for their own resilience rules but rarely mandate it outright.

What the assessor asks to see

Scope and policy; context and interested parties, including legal and regulatory requirements; business impact analysis with recovery time and recovery point objectives; risk assessment and treatment; continuity strategy and resource requirements; business continuity plans, incident response structure, and communication procedures; exercise and test schedule with post-exercise reports; supplier and outsourcing continuity arrangements; awareness and competence records; performance monitoring; internal audit and management review records; corrective actions.

Where the requirement sits: 5.2 policy; 7.5 documented information; 8.2 BIA; 8.4 BC plans; 8.5 exercise programme

Revision in progress

ISO/TC 292 approved a project to revise ISO 22301. The committee draft (ISO/CD 22301) was registered on March 12, 2026 with comments closing May 10, 2026. A companion revision of the guidance standard ISO 22313 has also started.

Until the new edition is published and an accreditation transition period is announced, ISO 22301:2019 remains the certifiable edition.

What AllyMatter does here

Controls the BC plans and proves staff acknowledgment.

AllyMatter publishes this site.

Assessors

Who assesses ISO 22301

Accredited certification body accredited to ISO/IEC 17021-1 for business continuity management systems. Accredited by National accreditation bodies under the Global ACI (formerly IAF) multilateral arrangement, such as ANAB, UKAS, DAkkS, JAS-ANZ.

Public register of assessors: https://www.iafcertsearch.org/

No firm has claimed a ISO 22301 assessor listing yet. Claim yours →

Consultants

Who helps with ISO 22301

A mature consultant ecosystem exists, often overlapping with information security and risk consultancies. Implementers facilitate the business impact analysis and risk assessment workshops, draft the strategy and plans, design and run exercises, train plan owners, and prepare the organization for the certification audit. First-time engagements typically take four to nine months.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

ArchlightMinneapolis, MN, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Archlight is a vCISO / ISO 27001 consultancy based in Minneapolis, MN, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
BEMOUSANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
BEMO is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Control and FunctionDenver, CO, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Coral EsecureNew Jersey, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Coral Esecure is a vCISO / ISO 27001 consultancy based in New Jersey, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
CycoreMiami, FL, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Cycore is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Genius GRCWoodstock, GA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Genius GRC is a vCISO / ISO 27001 consultancy based in Woodstock, GA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
IllumenPacific Northwest, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Illumen is a vCISO / ISO 27001 consultancy based in Pacific Northwest, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Neutral PartnersMiami, FL, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Neutral Partners is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Securis360Pittsburgh, PA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Securis360 is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Soter AdvisoryUSANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Soter Advisory is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
TestprosReston, VA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Testpros is a vCISO / ISO 27001 consultancy based in Reston, VA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
TrustedCISORemote, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
TrustedCISO is a vCISO / ISO 27001 consultancy based in Remote, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Related reading

  1. The ISO 22301 requirements explainedRequirement-by-requirement read of the business continuity management system, written by the people who audit it.Schellman
  2. ISO 22301 certification: business continuity managementCertification body's account of scope-setting, the business impact analysis and how the audit cycle runs.DNV

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for ISO 22301

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of ISO 22301 in AllyMatter

Approve the policies ISO 22301 asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.