You have ISO 27001. Here's how much of ISO 22301 you've already done.
If you already hold ISO 27001 and your customers have started asking for ISO 22301, the good news is you're not starting from zero. The two standards were designed to fit together, and a meaningful chunk of 22301 is work you've already banked.
What transfers almost for free
Clauses 4 through 10 of 22301 are the same Annex SL management-system text that sits in 27001: context, leadership, planning, support, performance evaluation and improvement. Your policy structure, roles, internal audit programme, management review cadence and corrective-action process all carry across with light editing. You're re-pointing an existing machine at a new subject, not building a new one.
On the control side, ISO 27001:2022 already includes A.5.29 (information security during disruption) and A.5.30 (ICT readiness for business continuity). If you've implemented those, you've started your continuity strategy and your recovery capability for IT — 22301 just asks you to widen the lens beyond IT to the whole business.
What you genuinely need to build
- A proper Business Impact Analysis — MTPD, RTO and RPO for every prioritized activity, plus dependencies and resources. This is the biggest net-new piece.
- Business continuity strategies and usable plans that go beyond IT recovery to people, facilities, suppliers and communications.
- An exercise programme — scheduled, run, and documented — that validates the plans over time.
The efficient way to do it
Compliance One cross-maps 22301 to your existing 27001 controls automatically, so the shared spine is pre-satisfied and the crosswalked continuity controls inherit your evidence. What's left is the genuinely new work — and the native BIA register and exercise scheduler are built for exactly that. Most teams find 22301 is an extension of a quarter's work, not a fresh quarter of it.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map Compliance One to your environment.