Skip to main content
Category: Business Continuity

Alternate Site

Simply put

An alternate site is a location that is different from an organization's primary or original location, which can be used on a temporary basis when the primary location is unavailable. In a business continuity context, it provides a place from which operations can continue if the main facility cannot be used.

Formal definition

An alternate site is a secondary location, distinct from the primary operating site, designated to support the continuation or recovery of operations when the primary location is unavailable. Based on the available evidence, it is described generally as a location different from the original that may serve temporary purposes; specific characteristics, activation criteria, and the extent of readiness typically depend on an organization's continuity and recovery planning and are not defined in the source material provided.

Why it matters

An alternate site addresses one of the most fundamental risks in business continuity planning: the loss of access to an organization's primary operating location. Disruptions such as fire, flood, power failure, or facility damage can render a main facility unusable, and without a predetermined place from which to continue work, operations may halt entirely. Designating a location different from the original gives an organization a temporary base from which critical activities can resume while the primary site is unavailable.

For compliance-focused organizations, the concept is relevant because business continuity and recovery capabilities are frequently examined as part of a broader control environment. In a SOC 2 engagement, controls supporting availability may be assessed when that Trust Services Category is included in scope, and an alternate site can form part of how an organization demonstrates its ability to maintain or restore operations. Similarly, within an ISO 27001 ISMS, continuity considerations may be reflected in the controls an organization selects based on its risk assessment, depending on the version of the standard and the Statement of Applicability.

It is important to note that simply having an alternate site does not, by itself, guarantee continuity of operations. The evidence provided describes the alternate site only generally as a temporary location different from the original; the specific readiness, activation criteria, and effectiveness of such a site depend on an organization's own continuity and recovery planning, which is out of scope of the source material.

Who it's relevant to

Business Continuity and Disaster Recovery Managers
These professionals are responsible for planning how an organization continues to operate when its primary location is unavailable. An alternate site is a core element of that planning, providing a temporary location from which operations can continue, with readiness and activation details determined by the organization's own continuity strategy.
Compliance and GRC Professionals
Where availability-related controls are in scope, such as in a SOC 2 examination that includes the Availability category, or within an ISO 27001 ISMS where continuity-related controls are selected via the Statement of Applicability, the presence and design of an alternate site may be relevant evidence of an organization's recovery capabilities. The specific requirements depend on scope, applicable criteria, and the framework involved.
IT and Operations Teams
Teams responsible for maintaining infrastructure and delivering services rely on alternate site arrangements to move or restore operations when the primary facility cannot be used. The extent to which an alternate site can support their systems typically depends on how it has been provisioned within the organization's recovery planning.

Inside Alternate Site

Recovery Site Facility
A secondary location used to resume information processing or business operations when the primary site becomes unavailable due to disruption, disaster, or other continuity events.
Site Readiness Spectrum
Alternate sites vary in readiness, typically described along a spectrum from hot sites (fully provisioned and near-immediate) to warm sites (partially provisioned) to cold sites (facility only, requiring setup). The appropriate choice depends on recovery objectives and scope.
Recovery Objectives Alignment
The selection and configuration of an alternate site is typically driven by recovery time and recovery point expectations defined in business continuity and disaster recovery planning.
Geographic Separation
An alternate site is generally located at sufficient distance from the primary site so that a single regional event is less likely to affect both, though the specific separation depends on risk assessment and scope.
Relationship to Framework Requirements
Alternate sites commonly support controls relevant to the SOC 2 Availability category (an optional Trust Services Criteria selected based on scope) and to ISO/IEC 27001 ISMS requirements addressing continuity, where implemented Annex A reference controls are selected via the Statement of Applicability.

Common questions

Answers to the questions practitioners most commonly ask about Alternate Site.

Does having an alternate site count as a specific mandatory control under SOC 2 or ISO 27001?
Neither framework prescribes an alternate site as a universal, named requirement. Under SOC 2, business continuity and availability considerations typically arise only if the Availability category of the Trust Services Criteria is included in scope, and the specific controls are shaped by scoping decisions and the service organization's own commitments. Under ISO 27001, the ISMS requirements in clauses 4 through 10 drive a risk-based approach, and any recovery-site-related reference controls in Annex A are selected through the Statement of Applicability rather than imposed automatically. Whether an alternate site is appropriate depends on the organization's risk assessment, scope, and the auditor or certification body's evaluation.
Does maintaining an alternate site guarantee that an organization will pass its SOC 2 examination or ISO 27001 certification?
No. A SOC 2 report attests only to the controls and period covered and does not guarantee any particular outcome or freedom from disruption, and an ISO 27001 certificate covers only the defined scope of the ISMS. An alternate site may support availability or continuity objectives where those are in scope, but its presence alone does not determine an examination result or certification decision. The suitability of design and, for a SOC 2 Type II, the operating effectiveness of related controls over the review period would still be evaluated.
How does the treatment of an alternate site differ between a SOC 2 Type I and a SOC 2 Type II?
A SOC 2 Type I assesses the suitability of the design of controls at a point in time, so it would typically consider whether alternate-site arrangements are designed appropriately as of that date. A SOC 2 Type II assesses both design and operating effectiveness over a defined review period, whose length is set by scoping decisions rather than a fixed duration. In a Type II, evidence that alternate-site-related controls operated as intended across the period would generally be relevant, depending on scope and the included criteria.
Where would alternate-site arrangements typically be documented for an ISO 27001 ISMS?
In most ISMS implementations, decisions about alternate sites flow from the risk assessment and are reflected in the Statement of Applicability, which records which Annex A reference controls are selected or excluded and why. The specific controls applied and their justification depend on the version of the standard referenced and the organization's scope, so the version should be specified when discussing particular control references. Supporting continuity documentation and evidence of operation would typically be maintained as part of the ISMS.
How should an organization scope an alternate site so it aligns with the boundaries of its SOC 2 report or ISO 27001 certificate?
Because a SOC 2 report attests only to the controls and period covered, and an ISO 27001 certificate covers only the defined scope of the ISMS, an alternate site is generally relevant only insofar as it falls within those boundaries. Organizations typically confirm whether the systems, services, and locations supported by the alternate site are part of the described system or the ISMS scope, since arrangements outside the stated scope would not be covered. Scoping decisions should be documented and consistent with the commitments and criteria included.
If an organization satisfies alternate-site expectations for one framework, does that carry over to the other?
Not automatically. Mapping between SOC 2 and ISO 27001 is possible but partial, and satisfying one framework does not inherently satisfy the other. The Trust Services Criteria used in a SOC 2 examination are distinct from the ISO 27001 clause requirements and Annex A reference controls, and each is evaluated by a different party under a different standard. An organization pursuing both would typically assess how its alternate-site arrangements meet each framework's requirements separately, depending on scope, criteria, and the applicable standard version.

Common misconceptions

Maintaining an alternate site is universally mandatory for SOC 2 or ISO 27001.
Neither framework mandates an alternate site in absolute terms. In SOC 2, availability-related controls apply only when the optional Availability category is in scope. In ISO 27001, continuity-related Annex A controls are selected via the Statement of Applicability informed by risk assessment, so the need depends on scope and risk decisions.
A hot site guarantees uninterrupted operations and freedom from disruption.
An alternate site reduces recovery time but does not guarantee continuity or freedom from incidents. Its effectiveness depends on configuration, testing, and the scope of what it covers. A SOC 2 report attests only to the controls and period covered and does not guarantee freedom from breaches or outages.
Having an alternate site listed in a plan is sufficient evidence of an effective control.
Design alone is not operating effectiveness. A SOC 2 Type I assesses suitability of design at a point in time, while a Type II assesses operating effectiveness over a defined review period; demonstrating an alternate site works typically requires evidence of testing and actual recoverability rather than documentation alone.

Best practices

Select the alternate site readiness level (hot, warm, or cold) based on documented recovery time and recovery point objectives rather than defaulting to the most costly option.
Confirm that the alternate site is included in the scope of any SOC 2 Availability controls or ISO 27001 ISMS continuity controls when those are within scope, and reflect applicable Annex A selections in the Statement of Applicability.
Locate the alternate site with sufficient geographic separation from the primary site, based on your risk assessment, to reduce the likelihood that a single event affects both.
Test failover and recovery to the alternate site periodically and retain evidence, since a Type II examination assesses operating effectiveness over the review period, not just design.
Document the alternate site within business continuity and disaster recovery plans, including roles, activation triggers, and dependencies, and keep it current as scope changes.
Avoid representing an alternate site as a guarantee of uninterrupted service; describe its coverage and limitations clearly to auditors and stakeholders.