ISO 22301 certification cost in 2026 lands between roughly $2,500 and $13,000 for most small and mid-sized organizations, before you count the internal hours that go into the business impact analysis and the exercises the auditor will want to see evidence of. The range is wide because certification bodies do not sell ISO 22301 as a product. They sell auditor days, and for business continuity there is a wrinkle that ISO 9001 and ISO 14001 buyers never meet: no accreditation rule tells the registrar exactly how many days your audit should take.
This guide breaks the number into the buckets that show up on invoices — the standard, the build, the certification audit and the three-year cycle — then explains how a registrar arrives at a day count without a mandatory table to lean on, and what the third edition now in committee draft will add to the bill.
What ISO 22301 certification cost actually buys you
You are buying an audit and a certificate, not a plan. An accredited certification body sends auditors to verify that your business continuity management system meets ISO 22301:2019, and if it does, issues a certificate valid for three years subject to annual surveillance. ISO writes the standard and certifies nobody, so every quote comes from a registrar. The full process, from application to certificate, is covered in our pillar guide to ISO 22301 certification; this post is only about the money.
The initial assessment is split in two. Stage 1 is a documentation and readiness review, usually one day and often partly remote. Stage 2 is the full audit against every clause, where the auditor traces the BIA, the risk assessment, the strategies, the plans and the exercise records back to the requirement that produced them. The auditors themselves have to meet ISO/IEC TS 17021-6:2014, the competence specification for BCMS certification, which is one reason ISO 22301 day rates sit at the upper end of the market: fewer auditors qualify.
Two different things are called ISO 22301 certification
Search for the price and half the results are quoting something else. Training providers sell “ISO 22301 certification” to individuals — a lead implementer or lead auditor course with an exam — for roughly $400 to $2,900. That is a personal credential; it does not certify your organization. Organizational ISO 22301 certification cost is what a registrar charges to audit your BCMS and issue a certificate in the company’s name, which is the figure tender evaluators and DORA-regulated customers ask for. If a quote looks suspiciously low, check which of the two you were sent.
How certification bodies calculate the audit fee
For quality, environmental and health-and-safety systems, audit duration is fixed by IAF MD 5:2023, the mandatory document every accredited registrar has to apply. There is no equivalent mandatory table for business continuity. What MD 5 says, in clause 0.5, is that although it is set up for QMS, EMS and OH&SMS, “a number of elements may be used for other ISO/IEC 17021-1 based certification schemes” — and in practice most accredited registrars use its QMS table as the starting point for an ISO 22301 audit, then adjust for the things that make continuity harder to audit.
The starting point works on effective number of personnel — everyone working inside the certified scope, including shift workers and part-timers as full-time equivalents. Table QMS 1 turns that into a combined Stage 1 plus Stage 2 duration:
| Effective personnel in scope | Starting audit days (Stage 1 + Stage 2) |
|---|---|
| 1–5 | 1.5 |
| 6–10 | 2 |
| 11–15 | 2.5 |
| 16–25 | 3 |
| 26–45 | 4 |
| 46–65 | 5 |
| 66–85 | 6 |
| 86–125 | 7 |
| 126–175 | 8 |
| 176–275 | 9 |
| 276–425 | 10 |
From there the registrar adjusts. For a BCMS the additions that matter are the number of sites and recovery locations to visit, the number of prioritized activities in scope (every product or service line with its own RTO adds evidence to sample), critical suppliers that carry part of your recovery, and whether your exercise program has actually run. Reductions are available for a mature system or a very small single site, but MD 5 caps any reduction at 30 percent of the table figure, and the audit delivered should not be less than 80 percent of the calculated time.
Multiply the final day count by the day rate and you have the certification audit fee. That is the whole formula, and a registrar that will not show you its day calculation is hiding the only number that matters.
Two ratios from the same document set the rest of the ISO 22301 certification cost cycle. Annual surveillance is about one third of the initial audit time, and the recertification audit in year three is about two thirds of what a fresh initial audit would be. Neither is likely to drop below one auditor day, which is why the smallest companies pay proportionally more.
ISO 22301 certification cost by company size in 2026
Accredited certification bodies in the US market typically charge between $1,200 and $2,500 per auditor day in 2026; UK registrars publish roughly £850 to £1,500. Applying those day rates to the table above, plus the application and certificate fees most registrars add, gives the ISO 22301 certification cost ranges below. They are typical figures drawn from published 2026 guidance by accredited certification bodies and consultancies, not a quote — pricing varies by country, scope and registrar.
| Scope | Starting days | Certification audit (Stage 1 + Stage 2) | Annual surveillance audit |
|---|---|---|---|
| 1–10 people, single site | 1.5–2 | $2,500 – $6,000 | $1,200 – $2,500 |
| 11–25 people, single site | 2.5–3 | $3,500 – $8,500 | $1,500 – $3,500 |
| 26–65 people, one or two sites | 4–5 | $5,500 – $13,000 | $2,000 – $5,000 |
| 66–125 people, multi-site or multiple product lines | 6–7 | $8,000 – $18,000 | $2,500 – $6,000 |
| 126+ people, multi-site, outsourced recovery | Quote-driven | $15,000 – $35,000+ | $5,000 – $12,000+ |
Headcount is a weaker predictor of ISO 22301 certification cost than it is for ISO 9001. A 40-person fintech with six prioritized services, a cloud provider in scope and a warm standby site can draw more audit days than a 120-person single-site manufacturer with two products, because the auditor is sampling recovery capability, not people. Describe your scope in those terms when you ask for quotes and the quotes will be comparable.
For a company of 10 to 25 people, a realistic all-in first-year ISO 22301 certification cost — standard, implementation effort, at least one exercise and the certification audit — is $8,000 to $20,000. If an accredited certificate is offered for dramatically less, ask which accreditation body the registrar holds and check its public register before you sign. Unaccredited certificates exist in this market and fail the first supplier questionnaire that asks for the accreditation mark.
The costs that never appear on the registrar’s invoice
Most people budget the audit and are then surprised by everything around it. These are the parts of ISO 22301 certification cost that get missed:
- The standard itself. ISO 22301:2019 is CHF 155 from the ISO Store, about US$190 at current rates, for 21 pages. The 2024 climate action amendment, Amd 1, is free, and your auditor will expect to see climate change considered in your context review. ISO 22313:2020, the guidance companion, is another CHF 225 and is worth it for a first-time implementer.
- The business impact analysis. Clause 8.2.2 is the single largest internal cost in the whole project and the one most often left out of the business case. A defensible BIA for a 25-person company takes 40 to 80 hours of managers’ time across every function, because the auditor will ask how each RTO was justified. Our guide to the business impact analysis covers what holds up under that question.
- Exercises. Clause 8.5 requires an exercise program, and a Stage 2 auditor will not accept a plan that has never been tested. A tabletop costs a half day of the response team’s time; a switchover or failover test of a real system can cost $2,000 to $5,000 in staff and provider time per run. Budget at least one before Stage 2.
- Documentation. ISO 22301 has a defined set of mandatory documents and records. Written from a blank page they take 80 to 150 hours; a consultant charges $5,000 to $30,000 to write them for you. A template pack is the middle route — our ISO 22301 Toolkit (88 templates, $99) covers the full document set including the BIA, risk assessment, strategies, plans and exercise records, mapped clause by clause.
- Corrective action time. Every nonconformity raised at Stage 2 has to be closed before the certificate is issued. A major finding can add a follow-up visit at a full day rate. The cheapest insurance against that is a proper internal audit two months before the registrar arrives.
ISO 22301 certification cost across the three-year cycle
The certificate lasts three years, so the honest budget is the cycle, not the first invoice. Using the mid-point of the 26–65 person row above — five audit days at $1,800 a day, or $9,000 for the initial audit — the cycle looks like this:
| Year | Audit | Basis | Typical fee |
|---|---|---|---|
| Year 1 | Stage 1 + Stage 2 | 5 days | $9,000 |
| Year 2 | Surveillance | About 1/3 of initial (1.5–2 days) | $3,000 – $3,500 |
| Year 3 | Surveillance | About 1/3 of initial (1.5–2 days) | $3,000 – $3,500 |
| Year 4 | Recertification | About 2/3 of initial (3–3.5 days) | $5,500 – $6,500 |
The rule of thumb that holds across registrars: budget 2 to 2.5 times the initial audit fee for the full three-year cycle, then add the recertification audit when the cycle restarts. Registrars will quote all three years up front if you ask, and the ones that do are easier to compare.
Two decisions move this number more than negotiation does. The first is scope: certifying one business unit or one critical service line cuts the personnel count and the sampling, and is a legitimate, common choice as long as the certificate says so. The second is integration. If you already hold ISO 27001, most registrars will audit ISO 22301 in the same visit, sharing the clauses the two standards have in common; our comparison of ISO 27001 vs ISO 22301 covers the overlap. In fee terms a combined audit typically saves 15 to 25 percent against two separate visits.
The third edition of ISO 22301 and what it will cost
ISO 22301:2019 is at ISO stage 90.92, “to be revised”, and the replacement, ISO/CD 22301 Edition 3, is at committee draft stage with its comment period closing as of September 2026. A committee draft still has to pass a Draft International Standard ballot and a final draft before publication, so a third edition is realistically a 2027 or later event, followed by a transition period that ISO and the IAF have set at three years for every recent management-system revision. Treat all of that as anticipated, not scheduled: ISO has published no date.
The ISO 22301 certification cost pattern from the ISO 27001 and ISO 9001 transitions is consistent and worth planning around now. If the transition audit lands on a recertification, it costs almost nothing extra, because a recertification already covers every clause. If it lands on a surveillance visit, registrars add roughly half a day to a day and a half per site to cover the changed requirements.
A standalone transition audit outside the normal cycle typically runs $3,000 to $10,000. If you are certifying for the first time in 2026, you will almost certainly transition at your first recertification in 2029, which is the cheap route — one more reason not to delay a decision on cost grounds.
Do you need the certificate, or just the system?
Some of the demand behind an ISO 22301 project is regulatory rather than contractual, and regulators do not require the certificate. DORA Article 11 requires financial entities to maintain and test an ICT business continuity policy; NIS2 Article 21(2)(c) lists business continuity, backup management and disaster recovery among the minimum measures. Both are satisfied by a working BCMS, certified or not.
The practical test is who will read the certificate. If tenders, financial-services customers or a parent company ask for it, the audit fee pays for itself with the first contract it unblocks. If nobody has asked, build the system to the standard and hold the certification decision until someone does. The cost of the audit does not change much between 2026 and 2027; the cost of an untested recovery plan does.
FAQ: ISO 22301 certification cost
How much does ISO 22301 certification cost for a small business?
For a single-site company of 10 to 25 people, the certification audit itself typically costs $3,500 to $8,500 in 2026, with surveillance at $1,500 to $3,500 a year. All-in first-year cost including the standard, implementation effort and one exercise is usually $8,000 to $20,000.
Why did two registrars quote very different day counts for the same company?
Because there is no mandatory audit-time table for business continuity. Registrars use the IAF MD 5 QMS table as a starting point and then apply their own adjustments for sites, prioritized activities, suppliers and recovery locations. Ask each one for its day calculation and its justification; MD 5 requires the registrar to record and provide it as part of the contract.
Is ISO 22301 more expensive than ISO 27001 to certify?
Usually not. ISO 27001 audit time comes from its own table in ISO/IEC 27006-1, which gives more auditor days for the same headcount than the MD 5 QMS table because of the 93 Annex A controls the auditor has to sample, so the certification fee for ISO 22301 is typically somewhat lower. The internal cost is a different story: the BIA and exercise program are heavier internal work than most ISO 27001 controls. Our ISO 27001 certification cost breakdown gives the comparison figures.
Will the third edition of ISO 22301 make certification more expensive?
Not materially. Day rates and the audit-time method are unlikely to change. The extra cost is the one-off transition — free at a recertification, half a day to a day and a half per site at a surveillance, or $3,000 to $10,000 standalone — plus the internal work of updating documents to the new clause text once it is published.
Whatever the registrar’s number turns out to be, the part of ISO 22301 certification cost you control is the build. Start from a complete, clause-mapped document set and put the saved hours into the BIA and the exercises, the two places a Stage 2 auditor spends the days you are paying for. The ISO 22301 Toolkit gives you that starting point for $99, and the ISO 22301 gap analysis guide tells you how far from Stage 1 you already are.