One of the challenges I have seen in large organizations is when different stakeholder sponsor implementation of ISO22301 and ISO27001 and come up with different versions of policies for the same concept. Also the entire process becomes extremely cumbersome for employees that need to provide feedback multiple times for essentially the same concepts.
Can there be a single choice between ISO22301 and 27001 for technology companies? Or which one takes the priority and should be implemented first?
Answer: The choice between ISO 22301 or ISO 27001, or which one to implement first will depend on organization's context and its objectives, so there is no definitive answer for this question.
If your scope is just supporting your business processes, you might get more by focusing on implementing ISO 22301.
If your scope handles just digital products, and information technology processes are the core of your organization, the implementing of ISO 27001 would be a better choice.
Regarding the concepts conflicts, the first thing would be for the spons ors to try to reach an agreement about a common version that would satisfy both sets of requirements. If this is not possible, then the situation should be taken to top management for evaluation what should be the best decision (e.g., to decide for a single concept to be used or accept the additional administrative effort that such difference will bring). But considering the current versions of ISO management standards releases after 2012, the integration of concepts shouldn't be hard to achieve.