Frameworks / SOC 2 / SOC2-A1.3 SOC 2 SOC2-A1.3: A1.3 Testing recovery plan procedures Procedures in the recovery plan that support system recovery are tested to confirm objectives can be met. Points of focus: business continuity plan testing is performed periodically, with scenarios weighted by how likely and how severe threats are, components across the organisation and its vendors that can impair availability, and unavailability of key people or vendors (vendors added in 2022), and plans are revised from the results; and backup data is tested periodically for integrity and completeness.
Maintained by Gerard Blokdyk · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 278 controls across 74 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CP-10 System Recovery and Reconstitution CP-10(2) System Recovery and Reconstitution | Transaction Recovery (CP-10(2)) CP-2 Contingency Plan CP-2(1) Coordinate with Related Plans CP-2(3) Resume Mission and Business Functions CP-4 Contingency Plan Testing CP-4(1) Coordinate with Related Plans CP-6 Alternate Storage Site CP-6(3) Alternate Storage Site | Accessibility (CP-6(3)) CP-7 Alternate Processing Site CP-7(2) Alternate Processing Site | Accessibility (CP-7(2)) CP-7(3) Alternate Processing Site | Priority of Service (CP-7(3)) CP-8 Telecommunications Services CP-9 System Backup CP-9(1) Testing for Reliability and Integrity IR-2 Incident Response Training IR-3 Incident Response Testing IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1)) IR-9(3) Information Spillage Response | Post-spill Operations (IR-9(3)) MA-6 Timely Maintenance (MA-6) PE-17 Alternate Work Site CP-10 System Recovery and Reconstitution CP-10(2) System Recovery and Reconstitution | Transaction Recovery (CP-10(2)) CP-2 Contingency Plan CP-2(1) Coordinate with Related Plans CP-2(3) Resume Mission and Business Functions CP-4 Contingency Plan Testing CP-4(1) Coordinate with Related Plans CP-6 Alternate Storage Site CP-6(3) Alternate Storage Site | Accessibility (CP-6(3)) CP-7 Alternate Processing Site CP-7(2) Alternate Processing Site | Accessibility (CP-7(2)) CP-7(3) Alternate Processing Site | Priority of Service (CP-7(3)) CP-8 Telecommunications Services CP-9 System Backup CP-9(1) Testing for Reliability and Integrity IR-2 Incident Response Training IR-3 Incident Response Testing IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1)) IR-9(3) Information Spillage Response | Post-spill Operations (IR-9(3)) MA-6 Timely Maintenance (MA-6) PE-17 Alternate Work Site NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated NIST-CSF-ID.IM-01 Improvements are identified from evaluations NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process NIST-CSF-RC.RP-02 Recovery actions are selected, scoped, prioritized, and performed NIST-CSF-RC.RP-03 The integrity of backups and other restoration assets is verified before using them for restoration NIST-CSF-RC.RP-04 Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms NIST-CSF-RC.RP-05 The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied 7.5.1 General 8.2.1 General 8.2.2 Business impact analysis 8.3 Business continuity strategies and solutions 8.3.2 Identification of strategies and solutions 8.3.5 Implementation of solutions 8.4 Business continuity plans and procedures 8.4.1 General 8.4.4 Business continuity plans 8.4.5 Recovery 8.5 Exercise programme 5.6.1 Operational planning and control 6.14 Information security aspects of business continuity management 6.14.1 Information security continuity 6.14.2 Redundancies 6.9.3 Backup ASD37-20 Multi-factor authentication (Essential) ASD37-34 Regular backups (Essential) ASD37-35 Business continuity and disaster recovery plans (Very Good) ASD37-36 System recovery capabilities (Very Good) 4.3.2 Legal and Other Requirements 4.4.1 Resources, Roles, Responsibility, and Authority 4.4.2 Competence, Training, and Awareness 4.4.8 Business Continuity and Recovery CIS-11.1 Establish and Maintain a Data Recovery Process CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data CIS-11.5 Test Data Recovery CIS-17.7 Conduct Routine Incident Response Exercises 5.24 Information security incident management planning and preparation 5.29 Information security during disruption 5.30 ICT readiness for business continuity 8.13 Information backup 5.29 Information security during disruption 5.30 ICT readiness for business continuity 8.13 Information backup 8.34 Protection of information systems during audit testing 27031-8.1 Exercising and Testing 27031-8.2 Maintaining IRBC 27031-9.3 Management Review 27031-B High availability embedded systems PCI-PIN-12 Disaster recovery procedures PCI-PIN-13 Third-party dependency management PCI-PIN-14 Critical service identification PCI-PIN-15 Communication and escalation procedures SSAE18-A1.1 A1.1 - Availability Commitments and Requirements SSAE18-A1.2 A1.2 - Environmental Protections and Recovery SSAE18-A1.3 A1.3 - Recovery Plan Testing SSAE18-CC7.5 CC7.5 - Incident Recovery IM8-DAT.2 Data Protection IM8-DSS.2 Service Reliability Standards IM8-RES.2 Disaster Recovery IM8-RES.4 Resilience Testing API1164-17 Wireless and Field Communications API1164-18 Field Device Security API1164-19 Safety Instrumented Systems Interface CPS234-14 Definition of Information Security Roles and Responsibilities CPS234-15 Information Security Capability CPS234-32 Annual Review and Testing of Response Plans CFTC-SS-11 Testing and Review of Business Continuity and Disaster Recovery Capabilities CFTC-SS-22 Business Continuity and Disaster Recovery Planning Category CFTC-SS-9 Next Business Day Recovery Time Objective DORA-Art.11 Response and recovery DORA-Art.12 Backup policies and procedures, restoration and recovery DORA-Art.24 General requirements for the performance of digital operational resilience testing FFIEC-11 Business continuity planning and testing FFIEC-12 Disaster recovery procedures FFIEC-14 Critical service identification IEC62443-16 Incident response plan for operational disruptions IEC62443-17 Recovery plan for critical systems IEC62443-20 Exercises and drills for OT incidents ISO27019-16 Incident response plan for operational disruptions ISO27019-18 Reporting obligations to authorities ISO27019-20 Exercises and drills for OT incidents 10.7.3 10.7.3 Respond promptly to critical security control failures 12.10.2 12.10.2 Annual review and testing of the incident response plan 12.3.1 12.3.1 Targeted risk analysis for flexible-frequency requirements PCI-P2PE-11 Business continuity planning and testing PCI-P2PE-12 Disaster recovery procedures PCI-P2PE-14 Critical service identification PCI-SSF-12 Disaster recovery procedures PCI-SSF-14 Critical service identification PCI-SSF-15 Communication and escalation procedures PICERL-C2 System Backup PICERL-R1 System Restoration PICERL-R2 Security Verification C5-BCM-04 Verification, updating and testing of the business continuity C5-OPS-08 Data Backup and Recovery - Regular Testing DIQ-1 Data Integration and Interoperability RMD-1 Reference Data Management 62351-12 Resilience and security recommendations for DER 62351-13 Cyber-physical generation and storage resilience ISO22316-08 Recovery time and point objectives ISO22316-12 Recovery strategy for critical activities ISO22317-08 Recovery time and point objectives ISO22317-12 Recovery strategy for critical activities ISO22318-08 Recovery time and point objectives ISO22318-12 Recovery strategy for critical activities NFPA1600-5.3 Resource Needs Assessment NFPA1600-6.4 Continuity and Recovery SOC-CY-A1 Availability Commitments SOC-CY-A2 Disaster Recovery SOCI-S30BC Notification of critical cyber security incidents (12 hours) SOCI-S30BD Notification of other cyber security incidents (72 hours) ISMSP-PI-06 Personal Information Destruction ISMSP-SYS-06 Business Continuity and Disaster Recovery OB-API.4 MI Reporting Specification OB-OPS.1 API Availability Requirements SEMD-CS-3 Cyber Resilience SEMD-ER-1 Emergency Exercise and Testing E8-BACKUP-ML1 Regular Backups (ML1) ANSSI-HYG-37 Define and Apply a Backup Policy for Critical Components AEO-12 Crisis Management and Incident Recovery BS65000-RM-03 Leadership and Culture COBIT-BAI04 Managed availability and capacity CAT-D5-4 Resilience planning and testing FEDRAMP-CP-9 System Backup ISO-22320-5.2 Incident management process ISO20000-03 Capacity and availability management ISO-25012-4.13 Availability 27007-5.4 Establishing the Programme Resources 27011-8.6 Data protection and backup ISO27043-23 Backup and recovery procedures ISO21434-23 Backup and recovery procedures ITIL4-03 Capacity and availability management Art.21.2.c Business continuity, backup management, disaster recovery and crisis management SASB-BMI-2 Business Model Resilience UKAI-3 Bias Detection, Fairness, Validation UKOPRES-5 Third-Party Risk, Concentration Risk CERT-1 RRA Certification to EPA CYB-5 Cyber Incident Response Plan Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in A - Availability You are reading one control. How much of SOC 2 have you already done? SOC 2 SOC2-A1.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 278 it maps to, and the evidence behind each claim, over MCP and REST.