Back to Frameworks

ISO/TS 22318:2021

International (ISO/TC 292); adopted as PD ISO/TS 22318 (UK) and by other national bodies
v2021 (second edition)
5 domains
28 controls

The ISO technical specification that extends ISO 22301 business continuity to supplier relationships: the supply chain model, SCCM embedded in the contract lifecycle, risk and SCCM ownership, the BCMS prerequisites, the four strategy options with supplier assessment and contractual continuity requirements, and maintenance, performance and improvement. Clause 4 from the held preview text, clauses 5 to 7 on their contents-page titles, the TS's own embedding description and the held ISO 22301; guidance, not certifiable.

Verified

ISO/TS 22318:2021 is a compliance framework from International (ISO/TC 292); adopted as PD ISO/TS 22318 (UK) and by other national bodies with 5 domains and 28 controls that map to 120 other frameworks. The largest domains are Clause 6: Effective SCCM – ISO/TS 22318:2021 (8 controls), Clause 4: The value of supply chain continuity management – ISO/TS 22318:2021 (7 controls), Clause 5: BCMS prerequisites for SCCM – ISO/TS 22318:2021 (7 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykControl text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

Annexes A to C (informative) – ISO/TS 22318:2021

3 controls
Controls in the Annexes A to C (informative) – ISO/TS 22318:2021 domain of ISO/TS 22318:20213 controls
CodeTitle
iso-ts-22318-2021::AAnnex A Example of general questions to be sent to priority suppliers (informative)
iso-ts-22318-2021::BAnnex B Managing priority suppliers' disruptions (informative)
iso-ts-22318-2021::CAnnex C Examples of joint exercises with suppliers (informative)

Clause 4: The value of supply chain continuity management – ISO/TS 22318:2021

7 controls
Controls in the Clause 4: The value of supply chain continuity management – ISO/TS 22318:2021 domain of ISO/TS 22318:20217 controls
CodeTitle
iso-ts-22318-2021::4.1.14.1.1 The supply chain: general
iso-ts-22318-2021::4.1.24.1.2 Supply chain model
iso-ts-22318-2021::4.2.14.2.1 Supply chain continuity management: general
iso-ts-22318-2021::4.2.24.2.2 Embedding SCCM
iso-ts-22318-2021::4.2.34.2.3 Benefits and opportunities
iso-ts-22318-2021::4.34.3 Risk ownership
iso-ts-22318-2021::4.44.4 SCCM ownership

Clause 5: BCMS prerequisites for SCCM – ISO/TS 22318:2021

7 controls
Controls in the Clause 5: BCMS prerequisites for SCCM – ISO/TS 22318:2021 domain of ISO/TS 22318:20217 controls
CodeTitle
iso-ts-22318-2021::5.2.15.2.1 Accountability and responsibility
iso-ts-22318-2021::5.2.25.2.2 Resources for managing SCCM
iso-ts-22318-2021::5.2.35.2.3 SCCM framework
iso-ts-22318-2021::5.2.45.2.4 Performance evaluation programme
iso-ts-22318-2021::5.35.3 Promulgate business continuity principles throughout the supply chain
iso-ts-22318-2021::5.4.25.4.2 Continuity requirements
iso-ts-22318-2021::5.4.35.4.3 Risk assessment

Clause 6: Effective SCCM – ISO/TS 22318:2021

8 controls
Controls in the Clause 6: Effective SCCM – ISO/TS 22318:2021 domain of ISO/TS 22318:20218 controls
CodeTitle
iso-ts-22318-2021::6.2.26.2.2 Option 1: Reduce dependency and impact
iso-ts-22318-2021::6.2.36.2.3 Option 2: Rely on the organization's business continuity strategies and solutions
iso-ts-22318-2021::6.2.46.2.4 Option 3: Rely on the supplier's business continuity strategies and solutions
iso-ts-22318-2021::6.2.56.2.5 Option 4: Do nothing and retain the risk by informed decision
iso-ts-22318-2021::6.36.3 Assess suppliers' continuity compliance
iso-ts-22318-2021::6.4.26.4.2 Principles to establish the continuity requirements in the contract
iso-ts-22318-2021::6.4.36.4.3 Continuity requirements
iso-ts-22318-2021::6.56.5 Review and update

Clause 7: Maintenance, performance and continual improvement – ISO/TS 22318:2021

3 controls
Controls in the Clause 7: Maintenance, performance and continual improvement – ISO/TS 22318:2021 domain of ISO/TS 22318:20213 controls
CodeTitle
iso-ts-22318-2021::7.27.2 Maintenance
iso-ts-22318-2021::7.37.3 Performance evaluation
iso-ts-22318-2021::7.47.4 Continual improvement

Your Compliance Coverage

If you comply with ISO/TS 22318:2021, you already cover:

Maps to 120 other frameworks

64 total controls
PSD2 SCA
5 source controls mapped|1 target controls covered
8%
OSFI B-13
5 source controls mapped|1 target controls covered
8%
Open Banking Security
5 source controls mapped|1 target controls covered
8%
Oman National Cybersecurity Framework
5 source controls mapped|1 target controls covered
8%
NIS2 Directive Implementing Acts
5 source controls mapped|1 target controls covered
8%
Nevada Gaming Control Board Cybersecurity Requirements
5 source controls mapped|1 target controls covered
8%
Monetary Authority of Singapore Technology Risk Management Guidelines
5 source controls mapped|1 target controls covered
8%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
5 source controls mapped|4 target controls covered
8%
ASD Strategies to Mitigate Cyber Security Incidents
5 source controls mapped|3 target controls covered
8%
ISO/TS 22317:2021
5 source controls mapped|5 target controls covered
8%
ASIS SPC.1-2009 - Organizational Resilience Standard
5 source controls mapped|1 target controls covered
8%
ISO/IEC 27031:2011
5 source controls mapped|6 target controls covered
8%
FFIEC IT Examination Handbook
5 source controls mapped|2 target controls covered
8%
ISO 22316
5 source controls mapped|5 target controls covered
8%
South Korea ISMS-P
5 source controls mapped|3 target controls covered
8%
PCI PIN Security
5 source controls mapped|2 target controls covered
8%
NFPA 1600 - Standard on Continuity, Emergency, and Crisis Management
5 source controls mapped|4 target controls covered
8%
PCI SSF
5 source controls mapped|2 target controls covered
8%
PCI P2PE
5 source controls mapped|2 target controls covered
8%
SOC for Cybersecurity - Cybersecurity Risk Management Examination
5 source controls mapped|1 target controls covered
8%
ISO 22301:2019
4 source controls mapped|3 target controls covered
6%
ISO/IEC 27010:2015
3 source controls mapped|2 target controls covered
5%
ISO 50001:2018 - Energy Management Systems
3 source controls mapped|2 target controls covered
5%
ISO 13485:2016
3 source controls mapped|2 target controls covered
5%
ISO 22313:2020 - Guidance on Business Continuity Management Systems
3 source controls mapped|3 target controls covered
5%
Annex 11 to EU GMP - Computerised Systems
3 source controls mapped|2 target controls covered
5%
BS 65000:2014 - Guidance on Organizational Resilience
3 source controls mapped|1 target controls covered
5%
5%
APRA CPS 230 Operational Risk Management
3 source controls mapped|3 target controls covered
5%
ISO 28001:2007 Supply Chain Security Management
3 source controls mapped|2 target controls covered
5%
TISAX - Trusted Information Security Assessment Exchange
3 source controls mapped|4 target controls covered
5%
5%
NIST Privacy Framework
3 source controls mapped|2 target controls covered
5%
NERC CIP
3 source controls mapped|2 target controls covered
5%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
3 source controls mapped|3 target controls covered
5%
IEC 62443
3 source controls mapped|6 target controls covered
5%
API 1164
3 source controls mapped|6 target controls covered
5%
ISO/IEC 27011:2024
3 source controls mapped|2 target controls covered
5%
NIST SP 800-53 Rev 5
3 source controls mapped|5 target controls covered
5%
NIST SP 1800-32
3 source controls mapped|6 target controls covered
5%
ISO/IEC 27019:2024
3 source controls mapped|6 target controls covered
5%
UK Security and Emergency Measures Direction (SEMD) - Water Industry
3 source controls mapped|2 target controls covered
5%
NIST Cybersecurity Framework 2.0
3 source controls mapped|6 target controls covered
5%
ISO 37301:2021
2 source controls mapped|1 target controls covered
3%
ISO 55001:2014
2 source controls mapped|1 target controls covered
3%
ISO 37001:2016
2 source controls mapped|1 target controls covered
3%
ISO 27701:2019
2 source controls mapped|1 target controls covered
3%
ISO 9001:2015
2 source controls mapped|1 target controls covered
3%
TSA Pipeline Cybersecurity Directives
2 source controls mapped|1 target controls covered
3%
SLSA
2 source controls mapped|1 target controls covered
3%
SIG (Shared Assessments)
2 source controls mapped|1 target controls covered
3%
PTES
2 source controls mapped|1 target controls covered
3%
OWASP SAMM
2 source controls mapped|1 target controls covered
3%
OWASP MASVS
2 source controls mapped|1 target controls covered
3%
OpenSSF Scorecard
2 source controls mapped|1 target controls covered
3%
NIST SP 800-92
2 source controls mapped|1 target controls covered
3%
NIST SP 800-88
2 source controls mapped|1 target controls covered
3%
NIST SP 800-63-4
2 source controls mapped|1 target controls covered
3%
NIST SP 800-61
2 source controls mapped|1 target controls covered
3%
NIST SP 800-146
2 source controls mapped|1 target controls covered
3%
NIST SP 800-145
2 source controls mapped|1 target controls covered
3%
NIST SP 800-144
2 source controls mapped|1 target controls covered
3%
NIST SP 800-137
2 source controls mapped|1 target controls covered
3%
NIST SP 800-123
2 source controls mapped|1 target controls covered
3%
NAIC Insurance Data Security Model Law (MDL-668)
2 source controls mapped|1 target controls covered
3%
NABERS - National Australian Built Environment Rating System
2 source controls mapped|1 target controls covered
3%
MTCS (Singapore)
2 source controls mapped|1 target controls covered
3%
MITRE ATT&CK
2 source controls mapped|1 target controls covered
3%
Japan FSA Cybersecurity Guidelines for Financial Institutions
2 source controls mapped|1 target controls covered
3%
ISO 22320:2018
2 source controls mapped|1 target controls covered
3%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
2 source controls mapped|1 target controls covered
3%
ISO/SAE 21434
2 source controls mapped|1 target controls covered
3%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
2 source controls mapped|1 target controls covered
3%
SSAE 18 - Attestation Standards (SOC Reporting)
2 source controls mapped|3 target controls covered
3%
SANS Incident Handler's Handbook and PICERL Methodology
2 source controls mapped|3 target controls covered
3%
SOC 2
2 source controls mapped|2 target controls covered
3%
NIST SP 800-190
2 source controls mapped|1 target controls covered
3%
ISO/IEC 27043:2015
2 source controls mapped|1 target controls covered
3%
ISO 27017
2 source controls mapped|1 target controls covered
3%
ISO 27018
2 source controls mapped|1 target controls covered
3%
NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity
2 source controls mapped|1 target controls covered
3%
ICH Q10 - Pharmaceutical Quality System
1 source controls mapped|1 target controls covered
2%
UK Gambling Commission - Cyber Resilience Requirements
1 source controls mapped|1 target controls covered
2%
UK FCA/PRA Operational Resilience Framework
1 source controls mapped|1 target controls covered
2%
SA8000:2014 - Social Accountability Standard
1 source controls mapped|1 target controls covered
2%
SASB Standards
1 source controls mapped|2 target controls covered
2%
PIC/S Guide to Good Manufacturing Practice for Medicinal Products
1 source controls mapped|1 target controls covered
2%
OWASP Top 10 for LLM Applications 2025
1 source controls mapped|1 target controls covered
2%
Modern Slavery Act 2018 (Australia)
1 source controls mapped|2 target controls covered
2%
ICAO Annex 17 - Aviation Security (AVSEC)
1 source controls mapped|1 target controls covered
2%
German Supply Chain Due Diligence Act (LkSG)
1 source controls mapped|2 target controls covered
2%
French Sapin II Law (Law No. 2016-1691)
1 source controls mapped|1 target controls covered
2%
Authorised Economic Operator (AEO) Programmes - Global Standards
1 source controls mapped|3 target controls covered
2%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
1 source controls mapped|2 target controls covered
2%
Automotive SPICE (ASPICE) v4.1 - Process Assessment Model
1 source controls mapped|1 target controls covered
2%
ISO 20400:2017 - Sustainable Procurement
1 source controls mapped|3 target controls covered
2%
SQF Code Edition 9 - Safe Quality Food
1 source controls mapped|1 target controls covered
2%
ISO 26000:2010
1 source controls mapped|1 target controls covered
2%
FBI CJIS Security Policy
1 source controls mapped|1 target controls covered
2%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
1 source controls mapped|1 target controls covered
2%
AS9100D - Aerospace Quality Management System
1 source controls mapped|1 target controls covered
2%
ISO 41001:2018 - Facility Management Systems
1 source controls mapped|1 target controls covered
2%
Space ISAC (Information Sharing and Analysis Center) - Threat Framework
1 source controls mapped|1 target controls covered
2%
21 CFR Part 211 - Current Good Manufacturing Practice
1 source controls mapped|1 target controls covered
2%
Sigstore - Software Artifact Signing and Verification
1 source controls mapped|1 target controls covered
2%
UK Telecommunications (Security) Act 2021
1 source controls mapped|1 target controls covered
2%
Security of Critical Infrastructure Act 2018 (SOCI)
1 source controls mapped|1 target controls covered
2%
2%
Solvency II
1 source controls mapped|3 target controls covered
2%
ISO/IEC 23894:2023
1 source controls mapped|1 target controls covered
2%
ISO/IEC 27003:2017
1 source controls mapped|2 target controls covered
2%
Protective Security Policy Framework (PSPF) Release 2024
1 source controls mapped|1 target controls covered
2%
BREEAM - Building Research Establishment Environmental Assessment Method
1 source controls mapped|1 target controls covered
2%
ISO 10006:2003
1 source controls mapped|1 target controls covered
2%

Coverage is not the same as your position

This page shows what ISO/TS 22318:2021 overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is ISO/TS 22318:2021 and who does it apply to?

ISO/TS 22318:2021 is a compliance framework from International (ISO/TC 292); adopted as PD ISO/TS 22318 (UK) and by other national bodies with 5 domains and 28 controls. The ISO technical specification that extends ISO 22301 business continuity to supplier relationships: the supply chain model, SCCM embedded in the contract lifecycle, risk and SCCM ownership, the BCMS prerequisites, the four strategy options with supplier assessment and contractual continuity requirements, and maintenance, performance and improvement. Clause 4 from the held preview text, clauses 5 to 7 on their contents-page titles, the TS's own embedding description and the held ISO 22301; guidance, not certifiable. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ISO/TS 22318:2021 actually require?

ISO/TS 22318:2021 has 28 controls organised across 5 domains. The largest domains are Clause 6: Effective SCCM – ISO/TS 22318:2021 (8 controls), Clause 4: The value of supply chain continuity management – ISO/TS 22318:2021 (7 controls), Clause 5: BCMS prerequisites for SCCM – ISO/TS 22318:2021 (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ISO/TS 22318:2021 do I already cover?

ISO/TS 22318:2021 maps to 120 other compliance frameworks. The top mapping partners are PSD2 SCA (8% coverage), OSFI B-13 (8% coverage), Open Banking Security (8% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement ISO/TS 22318:2021?

Start your ISO/TS 22318:2021 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/TS 22318:2021 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 28 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.

Get Started Free →

Free forever — no credit card required