Guidance on ICT readiness for business continuity, substantially revised in 2025. The technical layer beneath ISO 22301.
ISO/IEC 27031 sets out the concepts, principles and framework for ICT Readiness for Business Continuity — the technical capability that has to exist beneath a continuity plan for that plan to mean anything.
It is a guidance standard, not a certifiable one. Organisations do not hold ISO/IEC 27031 certificates. It is used to build and validate ICT recovery capability, and it supports certification against ISO 22301 and ISO 27001 rather than substituting for either.
The second edition was published in May 2025, replacing the 2011 original after a fourteen-year gap. The revision is substantial rather than editorial. It moves from largely technical IT recovery planning to a broader resilience posture, anchors ICT readiness in management and governance with defined roles and accountabilities, addresses cloud and third-party service dependency explicitly, and extends the requirements to conditions of active cyber attack rather than assuming disruption is accidental.
Its practical contribution is connecting recovery objectives — Minimum Business Continuity Objective, Recovery Time Objective, Recovery Point Objective — to the infrastructure that has to deliver them.
Organisations whose continuity commitments depend on technology recovering to a promised standard.
Where 27031 provides the ICT detail the management system assumes but does not itself specify.
Under CPS 230, tolerance levels for disruption have to be technically achievable, not just documented.
Under SOCI Act risk management programme obligations covering ICT hazards.
Where a third-party outage propagates faster than most recovery plans assume, and the 2025 edition's treatment of extended digital supply chains is directly relevant.
Which, in practice, is most of them.
Six to twelve weeks as a standalone engagement, depending on estate complexity. Frequently delivered alongside ISO 22301, where dependency mapping serves both.
Take the prioritised activities and recovery objectives from the business impact analysis. Where none exists, that work comes first — ICT readiness cannot be designed against undefined requirements.
Systems, data, networks, cloud services and third parties supporting each prioritised activity. This routinely surfaces dependencies nobody had documented.
Compare what the business requires against what the infrastructure can actually deliver today, and quantify the gap. This is the step that most often changes an executive's view of their exposure, because stated objectives are usually aspirational.
Recovery strategies, backup and replication design, failover procedures, and recovery runbooks written for use under pressure by whoever is on call at the time.
Recovery capability that has never been exercised is an assumption. Testing should include recovery under adverse conditions, not only planned failover in business hours.
With the ISO 22301 continuity programme and the ISO 27001 control set, so ICT readiness is maintained rather than assessed once.
Soveriq maps the dependencies, tests stated recovery objectives against what the infrastructure can actually deliver, and quantifies the gap in terms an executive can act on. Where ISO 22301 is in scope, the dependency work serves both and is not duplicated.
We will not sell you an ISO 27031 certificate, because none exists.
What we will not do. Soveriq does not issue certificates, is not a certification body, and does not promise assessment outcomes.
Modules 03 and 04 do not apply in the certification sense, because there is no certification audit against 27031. Where the work supports an ISO 22301 or ISO 27001 certification, those modules apply to that programme.
Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.
No. It is a guidance standard. Organisations do not hold ISO/IEC 27031 certificates. It supports certification against ISO 22301 and ISO 27001 rather than substituting for either.
ISO 22301 governs continuity of the business — which activities matter and how long they can be down. ISO 27031 addresses whether the technology can actually deliver on those commitments. The first sets the requirement; the second tests whether it is achievable.
A great deal, after fourteen years without revision. It shifted from technical IT recovery planning to a broader resilience posture, anchored ICT readiness in governance with defined roles and accountabilities, addressed cloud and third-party dependency explicitly, and extended the requirements to conditions of active cyber attack rather than assuming disruption is accidental.
With dependency mapping and validating your stated RTO and RPO against what the infrastructure can currently deliver. That comparison is usually the moment the exposure becomes concrete, and it is a better starting point than writing more plans.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope