Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Infographic asking is ISO 22301 worth it, showing 4,595 valid certificates worldwide and 107 in the United States

Is ISO 22301 Worth It? The Complete 2026 Cost-Benefit Case

Is ISO 22301 worth it? The honest answer splits in two: the business continuity management system behind it almost always pays for itself, and the certificate pays for itself only when a named customer, regulator, parent company or tender will actually read it. That distinction matters more here than for any other management system standard, because of a number almost nobody quotes.

At the end of 2024 there were 4,595 valid ISO 22301 certificates in the world, covering 11,387 sites, according to the ISO Survey 2024. In the United States there were 107. In Canada, ten. For comparison, the same survey counted 96,709 valid ISO/IEC 27001 certificates, 4,260 of them in the US, and 1,474,118 ISO 9001 certificates. So before you spend a dollar, understand the market you are buying into: business continuity certification is rare, and rarity cuts both ways.

Free gap assessment

Would your continuity programme survive an audit?

Score every clause of ISO 22301:2019, free, including the business impact analysis and exercise records most programmes fail on.

Run the free ISO 22301 gap assessment →  or  View premium report sample

Is ISO 22301 worth it for your situation? Start here

Five situations cover most of the people asking. Find yours before reading the cost section.

Your situationVerdictWhy
A customer, tender or parent company has asked for the certificate in writingYes, clearlyThe audit fee is a sales cost against a specific contract. Price the contract, not the standard.
You sell into EU financial services, or into UAE and Gulf government supply chainsProbably yesContinuity evidence is a standing question in those questionnaires, and the certificate answers it in one line.
You are regulated under DORA, NIS2 or a sector resilience ruleBuild the system, hold the certificateNone of those regimes require a certificate. They require a tested capability.
You already hold ISO/IEC 27001 and continuity keeps coming up in security reviewsYes, as an add-onAn integrated audit is the cheapest route to a second certificate. See the 20% cap below.
Nobody has asked, and you want the resilience benefitNo, not yetBuild to the standard, run the exercises, skip the audit until someone reads it.

What you are actually paying: the three-year number

Is ISO 22301 worth it at the price a registrar quotes? You cannot answer that from the first invoice. An accredited certification body sells auditor days, not certificates. The certificate lasts three years subject to annual surveillance, so the only budget that means anything is the cycle.

For a single-site organization of 26 to 65 people, the combined Stage 1 and Stage 2 audit typically runs four to five auditor days, and US accredited bodies generally charge $1,200 to $2,500 per auditor day in 2026. Two ratios in the accreditation rules set the rest: annual surveillance is about one third of the initial audit time, and recertification in year three about two thirds of a fresh initial audit. Budget two to two and a half times the initial fee for the full cycle. Our ISO 22301 certification cost breakdown works through the day tables, the day rates and the size bands.

Line itemTypical range, 26–65 people, single site
The standard (ISO 22301:2019, 21 pages, CHF 155; Amd 1:2024 is free)$190
ISO 22313:2020 guidance companion, optional but useful first time (CHF 225)$280
Documentation, written from scratch or from templates$99 – $30,000
Business impact analysis, internal hours40 – 80 hours of managers’ time
At least one exercise before Stage 2Half a day of the response team, or $2,000 – $5,000 for a live failover
Certification audit, Stage 1 + Stage 2$5,500 – $13,000
Surveillance, years two and three$2,000 – $5,000 each
Recertification, year four$4,000 – $9,000

Those are typical ranges drawn from published 2026 guidance by accredited certification bodies, not a quote. One warning specific to this standard: because there is no mandatory audit-day table for business continuity, two registrars can quote very different day counts for the same company and both be compliant. Ask each one to show you the day calculation.

Is ISO 22301 worth it when only 4,595 organizations hold the certificate?

This is the question the rest of the internet skips, and it is the one that decides the answer. Scarcity has two opposite effects on the return.

Against the certificate: in North America, almost no buyer has been trained to ask for it. With 107 certificates in the United States, a procurement team writing a supplier questionnaire has no realistic expectation that bidders hold one, so it rarely appears as a mandatory requirement. ISO 27001 certificates outnumber ISO 22301 certificates roughly forty to one in the US market, and that ratio is the whole story about which one procurement asks for first.

For the certificate: where it is asked for, there is almost no competition holding it. The largest national totals sit in the Gulf and in Europe rather than North America, which reflects where governments and regulators have pushed continuity down the supply chain. In a tender that scores certified resilience, being one of a handful of certified bidders is worth more than being one of thousands of ISO 9001 holders.

So the test is not whether business continuity matters — it obviously does. The test is whether anyone in your sales or regulatory path reads certificates. If yes, the certificate is cheap. If no, the system without the audit gives you most of the benefit.

Where the return actually comes from

Strip out the certificate and ask whether ISO 22301 is worth it as a piece of work. Three parts of the standard earn their keep on their own.

The business impact analysis, not the certificate

Clause 8.2.2 requires a business impact analysis, and it is both the largest internal cost of the project and the only part that changes decisions. Done properly it forces you to name every prioritized activity, put a recovery time objective on it and justify that number. Most organizations discover two things: some systems they pay to protect do not need it, and some they assumed were fine have no route back. Our guide to the business impact analysis covers what survives an auditor’s question, and that work pays whether or not you ever certify.

Free business impact analysis

How long can each activity really be down?

Rate the impact of an outage over time, set RTOs and maximum tolerable periods of disruption, map the people, systems and suppliers behind each activity, and get a recovery sequence back, free.

Run the free business impact analysis →  or  View premium report sample

The exercise program

Clause 8.5 requires an exercise program, and a Stage 2 auditor will not accept a plan that has never been tested. This is the requirement that turns a document set into a capability, and the external deadline of a certification audit is, in practice, what gets the first exercise scheduled.

Regulatory cover, with a caveat

DORA, Regulation (EU) 2022/2554, has applied to EU financial entities since 17 January 2025. Article 11 requires them to adopt and regularly review an ICT business continuity policy and to test their continuity and recovery plans at least yearly. NIS2 lists business continuity, backup management, disaster recovery and crisis management among its minimum measures in Article 21(2)(c). Neither instrument requires an ISO 22301 certificate anywhere in its text. A conforming BCMS satisfies the substance of both, and the certificate is useful evidence rather than a legal requirement.

Is ISO 22301 worth it for a small business?

Run the arithmetic on a 15-person professional services firm with one office and three client-facing services. Certification audit at two and a half to three days: roughly $3,500 to $8,500. Surveillance at $1,500 to $3,500 a year. Documentation from a template pack rather than a consultant: under $200. One tabletop exercise: half a day of five people’s time. Internal effort for the BIA, risk assessment, strategies and plans: 80 to 150 hours from a blank page, considerably less from templates.

Call it $12,000 to $18,000 of cash and internal time across three years. That is worth it if a single client contract turns on it, or if one avoided outage would cost more. It is not worth it as a marketing gesture to a customer base that has never mentioned continuity. For a firm that small, the sequence that works is: do the BIA, write the plans, run one exercise, then revisit certification when a questionnaire asks. Asking is ISO 22301 worth it at 15 people usually means asking whether one specific client is worth $12,000.

Is ISO 22301 worth it if you already hold ISO 27001?

This is the strongest case in the whole decision, and the savings are capped by rule rather than by negotiation.

Under IAF MD 11:2023, the mandatory document for integrated management system audits, a certification body calculates the audit time for each standard separately and adds them to get a starting point T, then adjusts. Clause 2.1.2 is explicit: where the adjustment results in a reduction, “it shall not exceed 20% from the starting point T.” Clause 2.1.3 requires the starting point and the justification to be documented, so you are entitled to see both.

The practical consequence: adding ISO 22301 to an existing ISO 27001 certification will not cost half of a standalone audit, whatever a salesperson implies. It will cost the standalone calculation less at most 20%. That is still the cheapest second certificate available, and the overlap in the documentation is larger than the overlap in the audit: context, leadership, risk, competence, internal audit and management review are shared clauses. Our comparison of ISO 27001 vs ISO 22301 sets out what each one actually covers.

When ISO 22301 is not worth it

Anyone asking is ISO 22301 worth it deserves the cases where the answer is no. These five come up most often.

  • Nobody has asked for it, and you have no tender pipeline that scores resilience. Build the system; skip the audit.
  • You have no tested recovery capability yet. Certifying an untested BCMS produces nonconformities and a bill for a follow-up visit.
  • Your real exposure is a single cloud provider you cannot fail away from. Fix the architecture first; a certificate over an unrecoverable dependency is worse than nothing, because it creates a documented false assurance.
  • You are shopping on price and someone has offered you an unaccredited certificate. It will fail the first supplier questionnaire that asks which accreditation body stands behind it.
  • A different standard is the actual gate. If customers are asking for security assurance, ISO 27001 or SOC 2 comes first.

The statistics your business case should not rest on

Is ISO 22301 worth it because of what an outage would cost? Possibly, but not for the reason most vendor pages give. Business continuity is sold on frightening numbers, and the most famous one does not hold up. The claim that 40% of businesses never reopen after a disaster is repeated on hundreds of vendor pages and attributed to FEMA; attempts to trace it to an original study come up empty, and the published research finds much lower and much more varied outcomes. If your business case leans on it, expect a CFO to find that out.

Two figures are defensible. The Federal Reserve’s 2021 Small Business Credit Survey found that 63% of small firms reporting disaster-related losses were forced to close temporarily — temporary closure, which is precisely what a recovery plan shortens. And the Uptime Institute Annual Outage Analysis 2026, drawing on its Global Data Center Survey 2025, reports that 57% of respondents put the cost of their most recent major outage above $100,000, and for the second year running one in five put it above $1 million. Note the caveat: that population is data center and IT operators, and the survey says nothing about whether any of them held a certificate.

Timing: there is no transition cliff to wait out

ISO 22301:2019 is Edition 2, published October 2019, 21 pages, and now sits at ISO stage 90.92 — “International Standard to be revised”. The replacement, ISO/CD 22301 Edition 3, is a committee draft at stage 30.60, close of comment period. A committee draft still has a Draft International Standard ballot and a final draft ahead of it, so publication is realistically 2028 or later, followed by a transition period. Treat that as anticipated, not scheduled — ISO has published no date.

That is unusually comfortable news for anyone weighing up whether ISO 22301 is worth it this year. Unlike ISO 9001 and ISO 14001, whose 2026 editions come with dated transition milestones and a transition bill, anyone certifying to ISO 22301 in 2026 will almost certainly meet the third edition at a recertification audit, where every clause is examined anyway and the incremental cost is close to zero. Waiting buys nothing. Our ISO 22301 certification timeline covers how long the project itself takes.

How to make the return larger

  • Scope deliberately. Clause 4.3 requires you to document the scope and explain any exclusions. One critical service line or one business unit is a legitimate, common scope, and it cuts personnel count, sites and sampling. It has to be honest — exclusions cannot hide a dependency the scope relies on.
  • Ask for the day calculation before you sign. There is no mandatory table for business continuity, so the calculation is the registrar’s own.
  • Quote the whole cycle. Ask for years one to four in one proposal; registrars that will not are the expensive ones later.
  • Run the internal audit two months early. Every nonconformity closed before Stage 2 is a day of follow-up you do not pay for.
  • Buy the documents, not the document writing. A consultant writing your set from scratch is the largest avoidable line in the budget.

FAQ

Is ISO 22301 certification mandatory anywhere?

No law or regulation we are aware of requires the certificate itself. DORA and NIS2 require a tested continuity capability, and some national and sector frameworks — the UAE’s own national BCM standard among them — push business continuity onto government bodies and their suppliers. Contracts and tenders, not statutes, are what make an ISO 22301 certificate compulsory in practice.

How long does the certificate last?

Three years, subject to annual surveillance audits. Miss a surveillance visit and the certificate can be suspended, which is why the cycle cost matters more than the first invoice.

Can we certify part of the organization?

Yes. Clause 4.3 expects a defined scope with documented exclusions. Certifying one service line is normal and is the biggest single lever on the price, provided the certificate states the scope plainly and the excluded parts are not load-bearing for the included ones.

Is ISO 22301 worth it if we already have a disaster recovery plan?

A DR plan is one output of a BCMS, not a substitute for it. The standard adds the analysis that decides what the plan should protect and how fast, the exercise program that proves it works, and the management review that keeps it current. If your DR plan was written once and never tested against a business impact analysis, the gap is exactly what the standard closes.

The bottom line

Is ISO 22301 worth it? Build the management system regardless — the business impact analysis and the exercise program change decisions and shorten outages. Buy the certificate when a customer, a tender or a parent company will read it, or when you already hold ISO 27001 and can add it inside one audit visit. In a market with 4,595 certificates worldwide, scarcity means the certificate is both rarely demanded and rarely matched — which is why the answer depends on your buyers rather than on the standard.

If you have decided to build it, our ISO 22301 Toolkit ($99, 75+ templates) covers the full documented-information set — scope, BIA, risk assessment, strategies, plans, exercise records and the internal audit pack — mapped clause by clause, so the documentation line in the budget above stops being the largest one. The full picture of what the standard asks for is in our pillar guide to ISO 22301 business continuity management.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.