ISO 22301 position

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

What it does well

  • Annex SL alignment with ISO 27001 + ISO 9001 + ISO 42001 enables integrated management systems.
  • BIA methodology is operationally usable.
  • Certifiable with mature audit ecosystem.
  • Sector applicability broad.
  • Disruption-scenario coverage beyond cyber (pandemic, geopolitical, supply chain, natural disaster).

What it does poorly

  • Lower procurement signal than ISO 27001 — many customers don't ask.
  • Implementation cost non-trivial for smaller orgs.
  • Tabletop-exercise discipline often weak; ceremonial testing common.
  • Cross-disruption-type integration patchy in many implementations.
  • Cyber-resilience overlap with ISO 27001 can produce ambiguity.

Evidence

  • Adopted widely in regulated industries (financial services, healthcare, critical infrastructure).
  • DORA and NIS2 use ISO 22301 as practical implementation reference.
  • ISO 22301 + ISO 27001 combined audits common.

Personal calibration

  • For client engagements: ISO 22301 typically secondary to ISO 27001 priority.
  • For SRE work: BC discipline embedded in DR / runbook / failover practice; ISO 22301 vocabulary in stakeholder communication.

See also