Under active development Content is continuously updated and improved · Last updated Feb 18, 2026, 2:55 AM UTC

CP-4Contingency Plan Testing

>Control Description

Enterprises should ensure that critical suppliers are included in contingency testing. The enterprise – in coordination with the service provider(s) – should test continuity/resiliency capabilities, such as failover from a primary production site to a back-up site. This testing may occur separately from a training exercise or be performed during the exercise. Enterprises should reference their C-SCRM threat assessment output to develop scenarios to test how well the enterprise is able to withstand and/or recover from a C-SCRM threat event.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.