ISO 22301
The certifiable business continuity management system standard for preparing for, responding to, and recovering from disruption. Tracking it does not claim that ControlFrame or any customer holds ISO 22301 certification.
2019 (Amd 1:2024) · ISO 22301:2019 · published 2024-02-23
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
ISO 22301 is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Licensed standard — purchase from ISO or a national member body and obtain software-use rights before verbatim ingestion.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Business continuity policy · Business impact analysis · Continuity strategies and procedures · Exercise and evaluation · Continual improvement
- Applies to
- all sectors · critical infrastructure · financial services · healthcare · global
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-28
- Pending change
- ISO has opened development of the third edition as ISO/CD 22301. The 2019 edition with Amendment 1:2024 remains the published standard.Expected: Publication date unannounced
03Version ledger
| 2012 | Superseded | date not published |
| 2019 (Amd 1:2024) | Current edition · supersedes 2012 | 2024-02-23 |
05Change history
06Related frameworks
- Shared Assessments SIG2026 annual release
Also applies to all sectors · The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.
- ASD Essential EightMaturity Model (November 2023)
Also applies to critical infrastructure · The Australian Signals Directorate's prioritized baseline of eight cyber mitigations, implemented through maturity levels zero to three. Independent assessment may be required by policy or contract, but the model is not a universal certification scheme.
Also applies to financial services · The widely used internal-control framework for operations, reporting, and compliance, including internal control over financial reporting. It supplies evaluation criteria; it is not a certification and SOX does not create a fixed IT-control catalog.
- HITRUST CSFv11.8.0
Also applies to healthcare · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.