KuCoin has obtained the ISO 22301:2019 certification for its business continuity management system, adding a formal layer of operational resilience to its existing security and compliance framework. The standard specifically addresses how the exchange prepares for, responds to, and recovers from disruptions to critical services.
The certification establishes a Business Continuity Management System (BCMS) that requires risk assessments, continuity plans, recovery procedures, testing, and ongoing reviews. KuCoin states that ISO 22301 is designed to cover disruptions from cyber incidents, infrastructure failures, third-party provider issues, and other unexpected events, ensuring that trading, asset transfers, and payments remain available around the clock across global time zones.
The exchange now integrates ISO 22301 alongside its existing ISO/IEC 27001:2022 (information security) and SOC 2 Type II (operational controls) certifications as part of its Trust Framework. KuCoin CEO BC Wong emphasized that “trust is built not only through security, but also through consistency and reliability,” and that operational resilience is becoming as important as security in the maturing digital asset industry.
The move comes as regulators worldwide increase their focus on operational resilience for crypto firms. KuCoin already operates under MiCA through its Austrian-licensed subsidiary, allowing passporting across 29 EEA countries, and is subject to EU DORA requirements for ICT risk management. The certification also aligns with guidance from the Monetary Authority of Singapore and the Hong Kong Monetary Authority. Additionally, KuCoin’s participation in a Nigerian supervisory pilot for virtual asset service providers highlights its expanding regulatory footprint, while past U.S. enforcement actions have driven the exchange to strengthen its governance and compliance systems.