← ISO and SOC Certifications

ISO 22301

Security and resilience — Business continuity management systems. Updated: September 29, 2026.

ISO 22301 certifies a business continuity management system: the capability to keep delivering at an acceptable level when something goes badly wrong. For anyone doing infrastructure work it is the standard that most directly overlaps with what we build, because it is the one that insists the plan be tested.

What It Requires

Where It Meets the Infrastructure

Directly. Disaster recovery planning is the technical implementation of what 22301 requires at the business level, and backup and recovery is where the recovery point objective becomes a real number. An organisation that has done that work honestly — with restores actually tested and timed — is much of the way to the evidence 22301 asks for.

The gap for most technical teams is the other direction: 22301 is a business continuity standard, not an IT one. It asks about premises, people, suppliers and communications, not only systems. A perfect DR plan with no answer for “the office is inaccessible and nobody knows who calls the customers” does not satisfy it.

Who Needs It

Financial services, healthcare, utilities, logistics and anyone in a regulated sector where resilience is supervised. Also increasingly requested in supply-chain questionnaires by large customers who have realised their own continuity depends on yours.

Getting Certified

Same structure as the other management system standards, with one addition worth planning for: you need evidence of exercises having been run before an auditor will certify. That cannot be compressed — a test programme has to have actually happened, which puts a floor under the timeline regardless of how good your documentation is.

Written from an infrastructure perspective. We are not a certification body, an audit firm or a legal adviser, and this is not legal advice. Standards are revised on a cycle — confirm the current edition before you commit.