Skip to content
SecuriFii

Choosing

Do you need ISO 22301 if you already have ISO 27001?

ISO/IEC 27001 already requires you to address continuity for information security. Whether you need a separate management system depends on what you are actually protecting.

Facts checked2026-09-11

When is ISO 22301 worth certifying?

For many organisations, the continuity requirements inside ISO/IEC 27001 are enough: availability is an information security property, and Annex A expects it to be addressed. Adding a second certified management system for its own sake is cost without a buyer.

Pursue ISO 22301 when a customer or regulator names it, or when the risk that matters is disruption of your operations rather than of your data — a logistics dependency, a single site, a supplier whose failure stops you delivering. It shares the harmonised clause structure with ISO/IEC 27001, so it is an addition to an existing system rather than a second one.

The bottom line

If nobody is asking for it and your real risk is data rather than downtime, the continuity clauses in ISO 27001 are probably sufficient.

Related insights