Skip to main content
Category: Business Continuity

Continuity Exercise

Also known as: Business Continuity Exercise, BCP Test, Continuity Test, Continuity Rehearsal, Continuity Plan Exercise
Simply put

A continuity exercise is a planned test or rehearsal of an organization's business continuity or disaster recovery plans to check whether the organization could actually keep operating, or recover, during a disruptive event. Rather than assuming the plan works on paper, teams practice it, sometimes by talking through a scenario and sometimes by simulating a real outage, to find gaps before a genuine crisis occurs. In a compliance context, these exercises produce evidence that continuity controls are not just documented but tested.

Formal definition

A continuity exercise is a structured evaluation activity in which business continuity, disaster recovery, or incident response arrangements are tested against defined scenarios to validate their design, operating effectiveness, and readiness. Exercises range in rigor from discussion-based formats (such as tabletop or walkthrough reviews) to operational formats (such as simulations, failover tests, or full interruption tests), with the type and frequency typically driven by risk assessment, recovery objectives, and scoping decisions. In SOC 2 examinations, exercise results commonly serve as evidence supporting the Availability category of the Trust Services Criteria (an optional category selected based on scope) and, where in scope, the Common Criteria; in a Type II report they may demonstrate operating effectiveness over the defined review period. Under ISO/IEC 27001, related requirements are typically addressed within the ISMS clauses (for example operational planning and control) and through applicable Annex A reference controls selected via the Statement of Applicability, with the precise control designation depending on the edition cited. The specific formats, cadence, and acceptance criteria are not fixed by these frameworks and vary by organization, auditor, certification body, and scope; a documented exercise does not by itself guarantee that operations will not be disrupted, only that the tested arrangements were exercised under the conditions defined.

Why it matters

A continuity plan that has never been exercised is an untested assumption. Documentation may describe recovery steps, contact trees, and failover procedures in convincing detail, yet still fail when a real disruption exposes stale contact information, undocumented system dependencies, or recovery objectives that cannot actually be met with available resources. Continuity exercises exist to surface these gaps in a controlled setting, before a genuine crisis makes them costly. For compliance purposes, they convert a written plan into demonstrable evidence that continuity arrangements have been not only designed but tested under defined conditions.

Who it's relevant to

Compliance and GRC Managers
Compliance managers rely on continuity exercises to produce audit-ready evidence that continuity controls are tested, not just documented. They typically coordinate the scheduling, scenario selection, and documentation of exercises so that results align with the review period of a SOC 2 Type II report or the ISMS requirements assessed during an ISO 27001 certification cycle.
SOC 2 Auditors and Assessors
For CPA firms performing a SOC 2 examination, exercise records serve as evidence supporting the Availability category (where selected in scope) and, where relevant, the Common Criteria. In a Type II engagement, assessors look for evidence that exercises occurred during the defined review period and that identified gaps were addressed, keeping in mind that acceptance criteria are set by scope rather than fixed by the standard.
ISO 27001 Certification Bodies and ISMS Owners
Accredited certification bodies and internal ISMS owners assess whether continuity-related arrangements are addressed within the applicable ISMS clauses and through Annex A reference controls selected via the Statement of Applicability. The precise control designation depends on the edition cited, so ISMS owners should confirm the relevant version when documenting how exercises satisfy selected controls.
Security Engineers and IT Operations Teams
Engineers and operations staff execute the technical portions of operational exercises, such as failover and restoration tests, and are often the first to encounter undocumented dependencies or recovery-time shortfalls. Their observations turn a theoretical plan into validated capability and feed directly into the remediation actions that make future exercises more reliable.

Inside Continuity Exercise

Continuity Exercise
A planned test or rehearsal of a business continuity plan (BCP), disaster recovery plan, or incident response procedure, conducted to validate whether the organization can maintain or restore operations following a disruptive event. In SOC 2 engagements, evidence of such exercises typically supports the Availability Trust Services Criteria; in ISO 27001, business continuity is addressed through the ISMS operational planning and, in the 2022 revision, Annex A control A.5.30 (ICT readiness for business continuity).
Exercise Scenario
The hypothetical disruption (for example, data center outage, ransomware event, or loss of a key supplier) around which the exercise is structured. Scenarios are typically chosen based on the organization's risk assessment and the scope of its continuity objectives.
Exercise Type
The format of the exercise, which commonly ranges from discussion-based tabletop walkthroughs to operational or full-scale simulations that actually invoke recovery procedures. The type selected depends on scope, maturity, and the objectives set by management.
Objectives and Success Criteria
Predefined goals such as validating recovery time objectives (RTOs), recovery point objectives (RPOs), communication trees, and roles and responsibilities. These provide the measurable basis for evaluating the exercise outcome.
Documentation and Evidence
Records such as exercise plans, participation logs, results, identified gaps, and corrective action items. For a SOC 2 Type II examination, this documentation may serve as evidence that the control operated over the review period; for ISO 27001, it may support conformity during a certification or surveillance audit.
Post-Exercise Review and Remediation
The lessons-learned analysis following the exercise, in which gaps are identified and continuity documentation is updated. This feeds the continual improvement expectations found in both frameworks.

Common questions

Answers to the questions practitioners most commonly ask about Continuity Exercise.

Does completing a continuity exercise count as passing a SOC 2 or ISO 27001 requirement?
Not on its own. A continuity exercise is a test or rehearsal of business continuity or disaster recovery plans; it produces evidence that plans have been exercised, but it does not by itself constitute compliance. In a SOC 2 examination, the results may serve as evidence supporting controls relevant to the Availability category (which is optional and selected based on scope) rather than the required Security/Common Criteria. In ISO 27001, continuity-related activities are typically evaluated against the ISMS requirements and any applicable Annex A reference controls selected via the Statement of Applicability. Whether the exercise satisfies a given criterion depends on scope, the auditor or certification body, and how the control was designed and operated.
Is a continuity exercise the same thing as having a written business continuity plan?
No. A written plan documents intended response and recovery activities, whereas a continuity exercise is the act of testing, rehearsing, or validating that plan. Auditors and certification bodies generally look for evidence that plans are not only documented but also exercised, because a plan that has never been tested may not perform as designed. In most engagements, both the existence of the plan and evidence that it has been exercised are considered, though the specific expectations vary by scope, framework, and reviewer.
How does a continuity exercise typically provide evidence in a SOC 2 Type II examination?
In a SOC 2 Type II examination, which assesses both the design and operating effectiveness of controls over a defined review period, evidence that a continuity exercise was performed during that period can support controls associated with the Availability category when that category is in scope. Typical artifacts include exercise plans, participation records, results, identified gaps, and remediation follow-up. A Type I examination, by contrast, assesses suitability of design at a point in time and would focus on whether the control is designed to include such exercises rather than whether they operated over a period. Because Availability is optional, its inclusion depends on the scoping decisions made for the engagement.
Where would continuity exercises fit within an ISO 27001 ISMS?
Continuity exercises generally support the operational and evaluation activities within the ISMS requirements (clauses 4 through 10) and may map to information security continuity-related reference controls in Annex A that are selected through the Statement of Applicability and informed by the risk assessment. Note that Annex A was restructured in the 2022 revision, so the exact control reference and its placement depend on the edition in use; you should confirm the current control identifier against the version applicable to your certification. Some organizations also align continuity activities with a dedicated business continuity management standard, though ISO 27001 itself addresses continuity from an information security perspective rather than providing a full continuity management framework.
How often should continuity exercises be conducted for audit purposes?
There is no universal frequency mandated across both frameworks. In most engagements, organizations conduct exercises on a periodic basis and after significant changes to systems or the environment, with the interval driven by risk assessment, the criticality of the affected services, and internal policy. For a SOC 2 Type II examination, evidence of at least one exercise within the defined review period is commonly expected when Availability is in scope, but the exact cadence is a scoping and control-design decision rather than a fixed rule. Confirm expectations with your auditor or certification body, since these depend on scope and the reviewer's judgment.
What documentation should be retained after a continuity exercise?
Typically, organizations retain the exercise scope or scenario, the date performed, participants and their roles, the objectives, observed results, any gaps or failures identified, and the resulting remediation or follow-up actions. This documentation allows an auditor or certification body to verify not only that the exercise occurred but that findings were tracked to resolution. The specific artifacts requested can vary by reviewer and by the controls in scope, so it is advisable to align retained evidence with the control descriptions being tested.

Common misconceptions

Successfully completing a continuity exercise is mandatory for a SOC 2 report and proves the organization is resilient to any disruption.
SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard. Whether continuity testing is in scope depends on the criteria selected, continuity most commonly relates to the optional Availability category rather than the required Security (Common Criteria). A report attests only to the controls and period covered and does not guarantee freedom from future disruption or breach.
ISO 27001 requires a specific, fixed continuity exercise mandated in a numbered Annex A control identical across all editions.
ISO 27001 certification is issued by an accredited certification body against the ISMS requirements in clauses 4 through 10. Annex A lists reference controls selected via the Statement of Applicability and informed by risk assessment. Business continuity for ICT is addressed in Annex A control A.5.30 in the 2022 revision; the control numbering and structure differ from the 2013 version, so the applicable edition should be specified. The nature and frequency of any exercise depends on scope and risk rather than a single universal rule.
A continuity exercise passed under one framework automatically satisfies the other.
Mapping between SOC 2 and ISO 27001 is possible but partial. Continuity evidence prepared for a SOC 2 Availability assessment may inform ISO 27001 conformity and vice versa, but satisfying one framework does not automatically satisfy the other, since the auditor, certification body, scope, and applicable criteria differ.

Best practices

Define clear objectives and success criteria before each exercise, tying them to recovery time and recovery point objectives derived from your risk assessment and business impact analysis.
Match the exercise type to your scope and maturity, start with tabletop walkthroughs and progress toward operational or full-scale simulations as capability grows.
Retain thorough documentation (exercise plans, participant logs, results, gaps, and corrective actions), since in a SOC 2 Type II examination this typically serves as operating-effectiveness evidence over the review period.
Conduct a formal post-exercise review, log identified gaps, and update continuity and recovery documentation to demonstrate the continual improvement expected under both frameworks.
Align exercise scope with the boundaries of your attestation or certification, recognize that a SOC 2 report covers only the controls and period examined, and an ISO 27001 certificate covers only the defined ISMS scope.
When citing ISO control references internally, specify the standard edition (for example, Annex A A.5.30 in the 2022 revision), since control numbering and structure vary between editions.