Choosing
Do you need ISO 22301 if you already have ISO 27001?
ISO/IEC 27001 already requires you to address continuity for information security. Whether you need a separate management system depends on what you are actually protecting.
Facts checked — 2026-09-11
When is ISO 22301 worth certifying?
For many organisations, the continuity requirements inside ISO/IEC 27001 are enough: availability is an information security property, and Annex A expects it to be addressed. Adding a second certified management system for its own sake is cost without a buyer.
Pursue ISO 22301 when a customer or regulator names it, or when the risk that matters is disruption of your operations rather than of your data — a logistics dependency, a single site, a supplier whose failure stops you delivering. It shares the harmonised clause structure with ISO/IEC 27001, so it is an addition to an existing system rather than a second one.
The bottom line
If nobody is asking for it and your real risk is data rather than downtime, the continuity clauses in ISO 27001 are probably sufficient.
Related services
ISO 22301 — Business Continuity Management
Know which activities cannot stop, how long they can be down, and what you will actually do — tested before you need it.
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
Related insights
Choosing
SOC 2 Type 1 or Type 2: which one to get, and what each can evidence
A blocked contract argues for a Type 1. Very little else does — and the minimum period you have been told about is not a rule.
Choosing
SOC 2 or ISO 27001 first? A commercial question wearing a technical costume
Your pipeline decides this, not the frameworks — and the two produce very different things to hand a customer.
Choosing
Accredited and unaccredited certification are not the same product
Both produce a certificate. Only one carries independent oversight of the auditor — and it is checkable.