Business continuity and disaster recovery for SOC 2
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · SOC 2
A disaster recovery plan you have never tested is the most common BC/DR finding. The test is the control; the document is just the script.
When you need it
If your SOC 2 includes the Availability category, BC/DR is squarely in scope. Even for a Security-only report, auditors expect a basic continuity and backup capability under the Common Criteria. Either way, the bar is "you can recover," demonstrated, not just asserted.
What the plan contains
A workable plan names the scenarios (region outage, data corruption, ransomware, key-person loss), the recovery steps, who does what, and your recovery objectives: how much downtime is tolerable (RTO) and how much data loss (RPO). Keep it concrete enough that someone could follow it under pressure.
Backups you have actually restored
Backups are necessary but not sufficient: a backup nobody has ever restored is an untested assumption. Periodically restore from backup and confirm the data is intact and the timing meets your RPO. That restore test is some of the strongest evidence you can show.
Test and record
Run a recovery exercise at least annually — a real or tabletop failover — and keep the notes: what you did, what broke, what you fixed. The exercise satisfies the testing expectation and surfaces the gaps a document review never would. SentinelPanda schedules the test and stores the evidence.