Procurement signal weak
Compared to ISO 27001 / SOC 2, ISO 22301 less commonly required:
- Many customers don't ask.
- Implementation cost less justified for SaaS.
- Often pursued by regulatory pressure (DORA, NIS2) rather than direct procurement.
Ceremonial testing
Exercise programmes often weak:
- Tabletop exercises rubber-stamped.
- Tests cover known-good scenarios.
- Real disruption discovers unrehearsed conditions.
ICT continuity ambiguity
ISO 22301 + ISO 27031 + ISO 27001 A.5.29-A.5.30 overlap on ICT continuity:
- Implementation responsibility unclear.
- Different evidence formats per standard.
- Combined implementations sometimes ambiguous.
Pandemic / supply-chain blind spots pre-2020
ISO 22301:2019 published pre-pandemic. Update process slow:
- Pandemic scenarios largely absent from pre-2020 implementations.
- Supply-chain scenarios light in older implementations.
- Update expected but timeline uncertain.
Counterpoint
- Annex SL alignment efficient.
- BIA methodology valuable regardless of certification.
- DORA / NIS2 driving adoption.
- Cross-disruption-type scope broader than cyber-only frameworks.