Disclosure · 701 filers

Business Continuity

701 companies wrote this into a filing in the last 14 days, up from 572. Below: which of them, and what the corpus says they now owe.

Data measured , page built 22 September 2026 at 16:18 UTC.

Critical

701 companies against 572, a rise of 23%, 701 companies is among the largest counts we hold, and 224 open roles name it, so it is being funded and not only disclosed.

701filers, current period
572the period before
0controls it touches
0frameworks
2008 2026 1071 filings in the busiest month
Business Continuity in 10-K and 10-Q filings, by month. The phrase was already in use in the first month we hold, so this shows how it has moved since rather than when it began.
Companies disclosing it 701 wrote this into a filing with the SEC
What it obligates 0 controls across 0 frameworks whose text speaks to it
Employers hiring for it 12,351 open US roles name it, and the ones below are hiring now

The long view, in annual and quarterly filings

A 10-K or 10-Q is a periodic report, so this counts how often the phrase appears in routine annual and quarterly reporting. It moves far more slowly and the numbers are larger. Every month since 2008. The last point is the current month and is still filling, so it always looks lower than it will be.

 
05361,071
2008 peak 1,071 in May 2020 2026

Who disclosed it

From SEC full-text search over 8-K filings. Every row links to the filing itself.

CompanyFormFiled
BROADRIDGE FINANCIAL SOLUTIONS, INC. BR10-K2026-08-04filing
Cycurion, Inc.8-K2026-09-08filing
ESSENTIAL PROPERTIES REALTY TRUST, INC. EPRT8-K2026-09-16filing
Regional Management Corp. RM10-Q2026-07-31filing
Oportun Financial Corp OPRT10-Q2026-08-06filing
Fidelity Ethereum Fund FETH8-K2026-08-10filing
Aerkomm Inc.10-Q2026-09-18filing
CSMC 2016-NXSR Commercial Mortgage Trust8-K2026-07-09filing
Palisades Venture Inc. PVIT10-Q2026-08-04filing
AXT INC AXTI10-Q2026-08-13filing
EchoStar CORP ECHO8-K2026-08-03filing
Hughes Satellite Systems Corp8-K2026-08-03filing
CAVA GROUP, INC. CAVA8-K2026-08-03filing
UPAY UPYY8-K2026-07-02filing
BROWN FORMAN CORP8-K2026-07-23filing
MCDONALDS CORP MCD8-K2026-08-04filing

The full search on EDGAR

Who is hiring for it

A sample of the open roles naming this phrase. An employer paying a salary against something is the least ambiguous demand signal there is, and every row links to the posting so the claim can be checked rather than believed. The total above is the whole US market; these are the ones we hold the posting for.

RolePosted
Manager, People Technology
NeueHealth, Inc. · St. Louis Park, Minnesota, United States
2026-09-22
Manager, Operational Technology & Manufacturing Systems
Axogen, Inc. · Vandalia, Ohio, United States
2026-09-21
Principal Site Reliability Engineer
Gen Digital Inc. · USA - Tempe, AZ
2026-09-21
Maintenance Field Manager
OCULAR THERAPEUTIX, INC · Bedford, MA
2026-09-21
Senior Site Reliability Engineer
Gen Digital Inc. · MYS - Kuala Lumpur
2026-09-18
Director, Resilience
COMMVAULT SYSTEMS INC · United States
2026-09-17
Senior Manager, Payroll
COMMVAULT SYSTEMS INC · Bangalore, India
2026-09-16
Senior Compliance Risk Manager - Securities Compliance
MERCURY SYSTEMS INC · San Francisco, CA, New York, NY, Portland, OR, or Remote within United States
2026-09-15
Risk Manager
Ping Identity Holding Corp. · UK - Remote
2026-09-15
Associate Director, Logistics
Syndax Pharmaceuticals Inc · New York, NY
2026-09-15
Director, Global Strategic Sourcing
ALNYLAM PHARMACEUTICALS, INC. · Cambridge, MA
2026-09-14
Analyst Compliance
HASBRO, INC. · Bogotá
2026-09-11
Associate Manager, Supply Chain
HASBRO, INC. · Japan
2026-09-11
Senior Director, External Manufacturing
Syndax Pharmaceuticals Inc · New York, NY
2026-09-11

Which industries file it

Companies grouped by the industry classification on their own filing. A count, not a survey.

IndustryCompanies
Chemicals and pharmaceuticals550
Banking506
Software and IT services298
Holding and investment offices263
Instruments and medical devices182
Securities and investment178
Electronics and electrical equipment160
Insurance140
Services and entertainment138
Retail134

What it obligates

No control in the corpus names this term directly. Recorded rather than filled with a guess.

ISO 22301 Evidence & Implementation Kit

49 controls sit behind ISO 22301:2019, and this is the documentation set for them: an adopt-ready artifact per control, and the evidence an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

ISO 22301:2019 NIST SP 800-53 Rev 5273 shared controlsNIST Cybersecurity Framework 2.0191 shared controlsPCI DSS 4.0175 shared controlsISO 27002:2022148 shared controlsISO 27001:2022143 shared controlsSOC 2139 shared controlsCIS Controls v890 shared controlsNIST SP 800-53 Revision 5.1 HIGH83 shared controlsCloud Security Alliance Cloud Co…78 shared controlsNIST SP 800-161 Rev 166 shared controls
ISO 22301:2019 holds 49 controls. They appear again inside 122 other frameworks in our corpus; the 10 strongest are shown. Thickness and size both carry the number of controls shared, so work done once counts in every framework on this diagram.
49If you already run ISO 22301:2019, that is the 49 controls behind this disclosure, already evidenced.
148And ISO 27002:2022 is not a separate programme. 148 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
143And ISO 27001:2022 is not a separate programme. 143 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
44And ISO/IEC 42001:2023 is not a separate programme. 44 of its controls are the same controls. If it is on next year's plan, that part of it is already done.

Run as two programmes

197 controls

ISO 22301:2019 and ISO 27002:2022 scoped separately, each with its own evidence, its own owner and its own budget line. This is how almost everybody does it.

Run once, counted twice

148 already done

148 of ISO 27002:2022's controls are controls you evidenced for ISO 22301:2019. Same artefacts, same owner, no second effort. The mapping is the only reason anybody knows.

2008 2026 1071 filings in the busiest month
Business Continuity in 10-K and 10-Q filings, by month. The phrase was already in use in the first month we hold, so this shows how it has moved since rather than when it began.

What this actually means

Why now
701 public companies wrote this into an 8-K in the last seven days, 23% more than the seven before. That is not sentiment or a survey. It is a count of companies choosing to put a phrase into a document they are legally accountable for.
Who already cares
12,351 open US roles name this work today, which suggests increased attention to it beyond what any filing says. A job advertisement clears a budget holder and a filing clears legal, so the two answer to different people. We have not measured which moves first, only that both are moving.
What comes into scope
Once the phrase is on the record it maps to obligations within ISO 22301:2019. 49 controls behind those, and the difference between asserting them and evidencing them is the whole of the work.
Who is quietly ahead
Anyone already running ISO 22301:2019 has done 148 of the controls that carry ISO 27002:2022 too. Same evidence, second standard. Most organisations run those as two programmes with two budgets because nobody told them the mapping existed.
Who is exposed
43 companies disclosed this for the first time in the last ninety days, out of 3630 in total. A first mention is a company deciding it can no longer not say it. Whoever has not yet is either genuinely unaffected or has not looked, and nothing here distinguishes the two.

What this obligates

The instruments in our corpus that govern this disclosure, and how many controls sit behind each. This is not a filing count. It is what applies once a company has written the phrase down.

1 frameworks, 49 controls between them.

ISO 22301:2019 NIST SP 800-53 Rev 5273 shared controlsNIST Cybersecurity Framework 2.0191 shared controlsPCI DSS 4.0175 shared controlsISO 27002:2022148 shared controlsISO 27001:2022143 shared controlsSOC 2139 shared controlsCIS Controls v890 shared controlsNIST SP 800-53 Revision 5.1 HIGH83 shared controlsCloud Security Alliance Cloud Co…78 shared controlsNIST SP 800-161 Rev 166 shared controls
ISO 22301:2019 holds 49 controls. They appear again inside 122 other frameworks in our corpus; the 10 strongest are shown. Thickness and size both carry the number of controls shared, so work done once counts in every framework on this diagram.

What closing it also moves

The same controls appear in other frameworks through mappings held in our corpus. Work done here is already progress there. This is the part that is not in EDGAR and not in any public dataset: it comes from mappings built and verified by hand, control by control.

ISO 27002:2022148
ISO 27001:2022143
ISO/IEC 42001:202344
ISO 9001:201538
ISO 27701:201935
ISO 22000:201832
ISO 37001:201628
ISO 37301:202128

Counted as controls reached through cross-framework mappings. It measures overlap of work, not compliance with the named framework.

Run as two programmes

197 controls

ISO 22301:2019 and ISO 27002:2022 scoped separately, each with its own evidence, its own owner and its own budget line. This is how almost everybody does it.

Run once, counted twice

148 already done

148 of ISO 27002:2022's controls are controls you evidenced for ISO 22301:2019. Same artefacts, same owner, no second effort. The mapping is the only reason anybody knows.

49If you already run ISO 22301:2019, that is the 49 controls behind this disclosure, already evidenced.
148And ISO 27002:2022 is not a separate programme. 148 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
143And ISO 27001:2022 is not a separate programme. 143 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
44And ISO/IEC 42001:2023 is not a separate programme. 44 of its controls are the same controls. If it is on next year's plan, that part of it is already done.

If that number surprised you, the same measurement across every topic we track:
What changed this week →

This is what it looks like when the same failure is named by standards bodies who never spoke to each other:
How compliance programmes fail →

And the companies that have already written this into a filing:
Business Continuity filers →

Tell me when Business Continuity files something new

One email when a public company newly discloses this, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

Where this comes from

The left half is public record: SEC full-text search over 8-K filings, counted across a 14 day window against the equivalent window before it. You can check every row.

The right half is ours: 723 frameworks and 20,473 controls, 531 of those frameworks verified against their source documents, with the auditor evidence and common failure modes recorded control by control. Controls appear here because their own text names this term.

Cite this

The Art of Service Signals. Business Continuity corporate disclosure activity: 701 filers against 572 in the prior period, in 10-K and 10-Q filings, this quarter against the same quarter last year. Accessed 23 September 2026. https://signals.theartofservice.com/t/business-continuity/

Free to use with attribution, no permission needed. The chart downloads as an SVG with the source printed on it. If you cite it we would like to know, but you do not need to ask.

Today's edition · How programmes fail · The obligation index