ISO 22301 Controversies

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Procurement signal weak

Compared to ISO 27001 / SOC 2, ISO 22301 less commonly required:

  • Many customers don't ask.
  • Implementation cost less justified for SaaS.
  • Often pursued by regulatory pressure (DORA, NIS2) rather than direct procurement.

Ceremonial testing

Exercise programmes often weak:

  • Tabletop exercises rubber-stamped.
  • Tests cover known-good scenarios.
  • Real disruption discovers unrehearsed conditions.

ICT continuity ambiguity

ISO 22301 + ISO 27031 + ISO 27001 A.5.29-A.5.30 overlap on ICT continuity:

  • Implementation responsibility unclear.
  • Different evidence formats per standard.
  • Combined implementations sometimes ambiguous.

Pandemic / supply-chain blind spots pre-2020

ISO 22301:2019 published pre-pandemic. Update process slow:

  • Pandemic scenarios largely absent from pre-2020 implementations.
  • Supply-chain scenarios light in older implementations.
  • Update expected but timeline uncertain.

Counterpoint

  • Annex SL alignment efficient.
  • BIA methodology valuable regardless of certification.
  • DORA / NIS2 driving adoption.
  • Cross-disruption-type scope broader than cyber-only frameworks.

See also