KuCoin earns ISO 22301 certification for operational resilience

by · crypto.news

KuCoin has secured ISO 22301:2019 certification for its business continuity management system, adding an international continuity standard to the exchange’s existing security and operational controls.

Summary

  • KuCoin has secured ISO 22301:2019 certification for its business continuity management system.
  • The standard covers preparations for operational disruptions and recovery of critical services.
  • KuCoin now lists ISO 22301 alongside ISO 27001 and SOC 2 Type II in its Trust Framework.
  • The certification comes as regulators place more focus on operational resilience for crypto and financial firms.

According to KuCoin’s Aug. 11 announcement, the certification covers its framework for preparing for operational disruptions, maintaining critical services and restoring affected systems when incidents occur.

KuCoin ISO 22301 certification covers service continuity

ISO 22301 sets requirements for a Business Continuity Management System, or BCMS, under which companies identify possible operational disruptions, establish response procedures and prepare recovery plans for critical services.

For KuCoin, the certification adds business continuity management to a compliance framework that already includes ISO/IEC 27001:2022 for information security and SOC 2 Type II for operational controls.

The exchange said ISO 22301 is designed to cover disruptions that can come from cyber incidents, infrastructure failures, problems involving outside service providers and other unexpected events. Its focus extends beyond preventing an incident by requiring procedures for keeping important operations running and restoring services when interruptions occur.

Such requirements have particular relevance for cryptocurrency exchanges because trading takes place around the clock rather than within fixed market hours. Platforms must maintain access to trading, asset transfers, payments and other services across different regions and time zones.

KuCoin identified cloud outages, blockchain node failures, payment infrastructure problems and reliance on third-party providers among the operational risks that exchanges may need to manage alongside cybersecurity threats.

The certification follows previous additions to the exchange’s security controls. As crypto.news reported in December, KuCoin already held SOC 2 Type II, ISO 27001:2022, ISO 27701 and Cryptocurrency Security Standard certifications at the time it received its European regulatory authorization. The exchange also used third-party proof-of-reserves audits.

KuCoin now lists ISO/IEC 27001:2022 for information security management, SOC 2 Type II for operational reliability and ISO 22301:2019 for business continuity as three parts of its Trust Framework.

Operational resilience requirements have entered crypto regulation

Business continuity controls have also become part of regulatory requirements for financial and crypto companies in several markets.

In the European Union, the Markets in Crypto-Assets Regulation establishes rules for crypto-asset service providers, while the Digital Operational Resilience Act sets requirements covering information and communications technology risks for regulated financial entities.

DORA includes requirements around ICT risk management, incident handling, resilience testing and third-party technology risks. KuCoin also cited regulatory guidance from the Monetary Authority of Singapore and the Hong Kong Monetary Authority when discussing the role of continuity planning in financial services.

KuCoin already operates under MiCA through its European subsidiary. The exchange secured its MiCA license in Austria in late 2025, allowing KuCoin EU Exchange GmbH to provide regulated crypto services across 29 European Economic Area countries through the framework’s passporting system.

The Austrian authorization covers trading, custody and other digital asset services. MiCA also places requirements on licensed crypto service providers involving capital, governance, customer asset segregation and disclosures.

KuCoin CEO BC Wong said at the time that regulatory compliance formed part of the company’s long-term strategy. The authorization followed KuCoin’s registration as a Digital Currency Exchange with Australian financial intelligence agency AUSTRAC in November 2025.

According to Wong, MiCA had made regulatory compliance a basic requirement for companies seeking to operate in Europe. He said the exchange was investing in custody systems, compliance workflows and market-making infrastructure while operating under the European framework.

KuCoin adds continuity controls to its trust framework

With the latest certification, KuCoin is putting additional controls around how its services respond when normal operations are disrupted.

The company said the BCMS framework requires organizations to identify risks before an incident, establish continuity plans and improve their ability to recover important services. The process also requires ongoing review rather than treating continuity planning as a one-time exercise.

BC Wong said maintaining user trust depended on a platform’s ability to remain consistent and reliable as well as secure.

“Trust is built not only through security, but also through consistency and reliability,” Wong said.

“As the digital asset industry continues to mature, operational resilience is becoming just as important as security,” he added, saying the ISO 22301 certification strengthens KuCoin’s preparations for unexpected events and its ability to restore operations.

The certification comes as KuCoin has also been building its regulatory presence outside Europe.

In April, the Central Bank of Nigeria selected KuCoin as the only global cryptocurrency exchange among six companies participating in a supervisory pilot for virtual asset service providers. The Nigerian regulatory pilot focuses on anti-money laundering, counter-terrorist financing and counter-proliferation financing controls aligned with Financial Action Task Force standards.

Participants were required to provide detailed reports and work on governance, transaction monitoring and Travel Rule controls under the program. KuCoin joined five Nigerian fintech and crypto companies in the first group selected by the central bank.

Its regulatory record has also included enforcement actions in the United States. In March, KuCoin parent Peken Global Limited agreed to a $500,000 civil penalty to resolve Commodity Futures Trading Commission claims related to operating an unregistered offshore commodities exchange.

Under the CFTC settlement reached in March, Peken Global resolved the regulator’s remaining claims without admitting or denying the allegations and avoided a disgorgement order after cooperating with investigators.

The CFTC case followed KuCoin’s January 2025 guilty plea in a separate U.S. criminal case involving the operation of an unlicensed money transmitting business. The company agreed to pay more than $297 million in penalties in that case, while U.S. prosecutors had alleged deficiencies in its anti-money laundering and know-your-customer controls.

Against that regulatory history, KuCoin has continued adding formal security, compliance and operational standards to its systems. The ISO 22301 certification specifically addresses whether an organization has established processes to maintain or recover critical functions when disruptions occur.

Under its current Trust Framework, ISO/IEC 27001:2022 covers the management of information-security risks, while SOC 2 Type II assesses controls related to areas such as security and operational processes over a defined period. ISO 22301 adds a separate framework governing business continuity planning and recovery.

KuCoin said the three standards are intended to support information protection, service reliability and operational resilience across the exchange.

Wong said the company would continue investing in infrastructure under its “Trust First. Trade Next.” approach, with the latest certification focused on its ability to prepare for unexpected events and recover critical digital asset services efficiently.