
Survive disruption. Reassure boards.Prove Resilience.
Going it alone takes most businesses 6 months. Our clients certify in as little as 4–8 weeks.
ISO 22301 is the audited evidence your board, insurer and enterprise clients need that you can keep trading through cyber attacks, outages and supply-chain shocks. Done-for-you, fixed fee.
- No hidden costs, ever
- Dedicated Australian consultant
- Quick quote in 24 hours
Part of the global IMSM network
CPS 230
maps to APRA operational-risk obligations
SOCI Act
critical-infrastructure resilience evidence
500+
Australian businesses certified
100%
certification success rate
Four drivers reshaping operational resilience in Australia
APRA CPS 230
Banks, insurers and super funds must identify critical operations, set tolerance levels and test disruption scenarios, exactly what 22301's BIA and exercising deliver.
SOCI Act / CIRMP
Operators in energy, water, transport, data storage, healthcare and food must maintain a Critical Infrastructure Risk Management Program backed by structured continuity evidence.
Cyber & climate
From ransomware and cloud outages to floods and fires, boards now demand proof that critical services can be restored within defined recovery times.
Tender-ready
Federal procurement panels, major-bank vendor programs and Tier-1 corporate supply chains increasingly set ISO 22301 as a prequalification condition for award.
Tell us your situation and headcount, we'll scope your fixed fee within 24 hours.
Get my fixed-fee quote →What ISO 22301 certification involves
ISO 22301:2019 is a tested system for identifying your critical operations, setting recovery targets and rehearsing your response before disruption strikes, so one framework satisfies APRA CPS 230, the SOCI Act, your board, your insurer and enterprise buyers at once.
Business Impact Analysis
Identify critical operations, dependencies and the cost of downtime to prioritise what must recover first.
RTO/RPO recovery objectives
Set defined recovery-time and recovery-point targets and tolerance levels for each critical service.
BCP & communications plans
Document recovery procedures, escalation paths and stakeholder comms ready to activate under pressure.
Testing & exercising
Run tabletop and live exercises that produce the evidence auditors, regulators and insurers recognise.
Supplier & dependency mapping
Assess service providers and single points of failure so third-party shocks don't take you down.
A living BCMS
Embed monitoring, internal audit and continual improvement so plans stay current as your operations change.
What ISO 22301 does for your business
Meet CPS 230 & SOCI obligations
One audited BCMS satisfies financial-services and critical-infrastructure resilience duties.
Demonstrate board-level due diligence
Give directors an externally audited evidence trail that their duty of care was discharged, aligned with the ASX Corporate Governance Principles, exactly the proof that matters if a disruption is later scrutinised.
Faster recovery after disruption
Tested recovery and continuity plans restore critical services within defined recovery times.
Win government & enterprise tenders
Certification unlocks federal, state and corporate panels that increasingly demand continuity evidence.
Reduce insurance premiums
Documented, tested plans strengthen cyber, business-interruption and D&O cover negotiations.
Strengthen supply-chain confidence
Show partners and regulators that your third-party dependencies are mapped, tested and protected, evidence that satisfies both SOCI Act supply-chain obligations and enterprise vendor-risk assessments.
Who ISO 22301 is for in Australia
Not sure if ISO 22301 fits your sector? Tell us what you do, we'll tell you straight, no pressure.
Get my fixed-fee quoteWhat does ISO 22301 certification cost?
Your fee depends on one thing: the size of your organisation. Tell us your headcount and we'll send a single fixed fee covering gap analysis, documentation, consultancy and your certification audit, agreed upfront, no hourly billing, no surprises.
Five steps to certified
One dedicated Australian consultant from quote to certificate, we do the heavy lifting.
- 01
Quick quote & scope
Tell us your standard and headcount, your quote arrives within 24 hours, agreed before we start.
- 02
Gap analysis
Your dedicated consultant maps what you already have against the standard, so you only build what's missing.
- 03
System build
We write the policies, procedures and records with you, tailored to how your business actually operates.
- 04
Implementation & internal audit
We embed the system, train your team and run the internal audit to confirm you're ready.
- 05
Certification audit
We prepare and support you through the audit, independent or JAS-ANZ accredited, your choice.


EFQM 5★ Recognised for Excellence
Fewer than 400 organisations worldwide hold it, IMSM is one of them
Think of it as ISO certification for our own business, we hold ourselves to the same standard we hold you to.
It's an independent assessment of our own quality management against the European Foundation for Quality Management framework.
“IMSM provided excellent support throughout the certification. Expert guidance helped us educate people internally, and the implementation process was smooth.”
“Having our business ISO 9001 certified adds credibility to the organisation, but the processes and procedures introduced make for a far more productive and efficient workplace throughout the entire structure.”
ISO 22301, common questions
What's the difference between a BCP and ISO 22301?+
A Business Continuity Plan is a document; ISO 22301 is the management system that produces, tests, maintains and continually improves that plan, generating the evidence auditors, regulators and insurers recognise. If you already have a plan, you're part-way there, we build the system around it.
Does ISO 22301 satisfy APRA CPS 230?+
It maps strongly to CPS 230's operational-risk, business-continuity and service-provider requirements, particularly identifying critical operations, setting tolerance levels and testing, giving regulated entities a defensible, audit-ready framework, though APRA may still require additional specific evidence.
Does it cover the SOCI Act and a CIRMP?+
Yes, 22301 delivers the structured, tested continuity evidence that underpins a Critical Infrastructure Risk Management Program for operators in energy, water, transport, data storage, healthcare and food.
We already have ISO 27001, does that help?+
Yes, both share the same high-level structure, so leadership, risk and internal-audit clauses integrate, and many clients certify the two together for efficiency.
How long does certification take?+
Most organisations certify in as little as 2 months, with a clear fixed-fee timeline set upfront.
What testing is required?+
22301 requires you to exercise your plans through tabletop and live scenarios that prove critical services can be recovered, producing the evidence regulators and insurers expect.
Ready to get ISO 22301 certified?
Most clients have their quote within 24 hours. Let's see what certification looks like for your business.