ISO/IEC 27031:2025 — ICT Readiness for Business Continuity

Guidance on ICT readiness for business continuity, substantially revised in 2025. The technical layer beneath ISO 22301.

ISO and IEC. Guidance standard — not a certification standard.

What it is

ISO/IEC 27031 sets out the concepts, principles and framework for ICT Readiness for Business Continuity — the technical capability that has to exist beneath a continuity plan for that plan to mean anything.

It is a guidance standard, not a certifiable one. Organisations do not hold ISO/IEC 27031 certificates. It is used to build and validate ICT recovery capability, and it supports certification against ISO 22301 and ISO 27001 rather than substituting for either.

The second edition was published in May 2025, replacing the 2011 original after a fourteen-year gap. The revision is substantial rather than editorial. It moves from largely technical IT recovery planning to a broader resilience posture, anchors ICT readiness in management and governance with defined roles and accountabilities, addresses cloud and third-party service dependency explicitly, and extends the requirements to conditions of active cyber attack rather than assuming disruption is accidental.

Its practical contribution is connecting recovery objectives — Minimum Business Continuity Objective, Recovery Time Objective, Recovery Point Objective — to the infrastructure that has to deliver them.

Who it's for

Organisations whose continuity commitments depend on technology recovering to a promised standard.

Organisations implementing ISO 22301

Where 27031 provides the ICT detail the management system assumes but does not itself specify.

APRA-regulated entities and material service providers

Under CPS 230, tolerance levels for disruption have to be technically achievable, not just documented.

Critical infrastructure operators

Under SOCI Act risk management programme obligations covering ICT hazards.

Organisations heavily dependent on cloud and SaaS

Where a third-party outage propagates faster than most recovery plans assume, and the 2025 edition's treatment of extended digital supply chains is directly relevant.

Any organisation whose DR plan has never been genuinely tested

Which, in practice, is most of them.

Why implement it

  • It closes the gap between the DR plan and the continuity plan. Most organisations have both and have never reconciled them. Recovery objectives on paper frequently do not match what the infrastructure can deliver.
  • It tests RTO and RPO against reality. Stated recovery objectives are commonly aspirational. Verifying them is uncomfortable and valuable in equal measure.
  • It addresses cloud and third-party dependency. The 2025 edition explicitly covers hybrid infrastructure and SaaS dependency, where a supplier outage cascades quickly.
  • It assumes hostile conditions. Recovery during an active cyber attack differs from recovery after a hardware failure, and the revised standard addresses restoring services while an incident is still running.
  • It strengthens both certifications. It supports the continuity controls in ISO 27001 and the ICT layer of an ISO 22301 management system.

How implementation works

Six to twelve weeks as a standalone engagement, depending on estate complexity. Frequently delivered alongside ISO 22301, where dependency mapping serves both.

1. Establish continuity objectives

Take the prioritised activities and recovery objectives from the business impact analysis. Where none exists, that work comes first — ICT readiness cannot be designed against undefined requirements.

2. Map ICT dependencies

Systems, data, networks, cloud services and third parties supporting each prioritised activity. This routinely surfaces dependencies nobody had documented.

3. Validate RTO and RPO against capability

Compare what the business requires against what the infrastructure can actually deliver today, and quantify the gap. This is the step that most often changes an executive's view of their exposure, because stated objectives are usually aspirational.

4. Design and remediate

Recovery strategies, backup and replication design, failover procedures, and recovery runbooks written for use under pressure by whoever is on call at the time.

5. Test

Recovery capability that has never been exercised is an assumption. Testing should include recovery under adverse conditions, not only planned failover in business hours.

6. Integrate

With the ISO 22301 continuity programme and the ISO 27001 control set, so ICT readiness is maintained rather than assessed once.

How Soveriq helps

Soveriq maps the dependencies, tests stated recovery objectives against what the infrastructure can actually deliver, and quantifies the gap in terms an executive can act on. Where ISO 22301 is in scope, the dependency work serves both and is not duplicated.

We will not sell you an ISO 27031 certificate, because none exists.

What we will not do. Soveriq does not issue certificates, is not a certification body, and does not promise assessment outcomes.

What the engagement looks like

  • Module 01 — Gap analysis. ICT dependency mapping and validation of stated recovery objectives against actual capability.
  • Module 02 — Build. Recovery strategies, backup and replication design, failover procedures and recovery runbooks.
  • Module 05 — Continuous compliance, including the recurring test regime.

Modules 03 and 04 do not apply in the certification sense, because there is no certification audit against 27031. Where the work supports an ISO 22301 or ISO 27001 certification, those modules apply to that programme.

Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.

Common questions

Can we certify to ISO 27031?

No. It is a guidance standard. Organisations do not hold ISO/IEC 27031 certificates. It supports certification against ISO 22301 and ISO 27001 rather than substituting for either.

How is it different from ISO 22301?

ISO 22301 governs continuity of the business — which activities matter and how long they can be down. ISO 27031 addresses whether the technology can actually deliver on those commitments. The first sets the requirement; the second tests whether it is achievable.

What changed in the 2025 edition?

A great deal, after fourteen years without revision. It shifted from technical IT recovery planning to a broader resilience posture, anchored ICT readiness in governance with defined roles and accountabilities, addressed cloud and third-party dependency explicitly, and extended the requirements to conditions of active cyber attack rather than assuming disruption is accidental.

Our DR plan has never been tested. Where do we start?

With dependency mapping and validating your stated RTO and RPO against what the infrastructure can currently deliver. That comparison is usually the moment the exposure becomes concrete, and it is a better starting point than writing more plans.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope