An exercise without objectives agreed in advance always concludes that it went well. This programme gives you the scenario, the injects on a clock, five stopwatch measures against your own targets, and the evidence file a supervisor will accept without a covering conversation.
Read it carefully. Financial entities shall:
A technical recovery test does not discharge the second. For entities other than microenterprises the testing plans must also include scenarios of cyber-attacks and of switchovers between the primary infrastructure and the redundant capacity. The multi-year tab of the workbook checks all of that per year and shows a gap when a limb is uncovered.
Objectives and measurable pass criteria are set at design time, in the workbook. Deciding afterwards whether it went well is not evaluation, it is recollection.
Detection to declaration. Declaration to a quorate team. To the first situation report. To an approved holding statement. To the management body. Each against your own target, each PASS or FAIL, no adjectives.
Every scenario carries an inject that invalidates the plan the team has settled into: the backups are encrypted too, the provider doubles its estimate, the corruption predates the last backup. Without it a rehearsed team performs the rehearsal.
| What is in the programme | |
|---|---|
| 01 | Exercise programme policy and multi-year plan |
| 02 | Scenario library — twelve severe but plausible |
| 03 | Exercise Director and facilitator guide, including safety rules |
| 04 | Player, observer and control cell briefing packs |
| 05 | Evaluation criteria and observer sheets |
| 06 | After-action report and supervisor evidence file |
| 07 | Exercise designer and after-action review workbook (Excel) |
| Inside the workbook | |
| • | Scenario library — 12 scenarios with the limb each one evidences |
| • | Exercise designer — pick a scenario and the detail derives |
| • | Inject schedule — 60 injects on a wall clock, response time captured |
| • | Timing — five measures, target vs actual, PASS or FAIL |
| • | Findings register — the same schema as real-incident findings |
| • | Multi-year programme — 12 quarters with Article 11(6) coverage checks |
| • | AAR builder — generated sentences for the report |
Need the plan as well? Both packs together for €249 instead of €298.
For the first limb, possibly. For the second, no. Article 11(6) separately requires the crisis communication plans to be tested, and a technical failover test does not exercise a holding statement, an approval route or a spokesperson. Schedule it separately and the obligation becomes trivially easy to evidence.
No, and nothing can be. ISO 22361:2022 and ISO 22320:2018 are guidelines documents, not requirements standards, so there is no conformity clause and nothing for a certification body to audit against. The programme is structured on their process, and we mean that literally.
A walkthrough or a communication drill, yes. A tabletop, better not: the value comes from injects delivered on the clock by someone who is not playing, and from an observer who is not allowed to help. The facilitator guide is written so that someone internal can take the role.
Not if you follow the safety rules in document 03: everything prefixed, no live client contact, no live regulatory submission, no production change without an approved rollback, and a stop phrase everyone is briefed on. Exercises have delayed real incident responses because nobody could tell the two apart; that is what the rules prevent.
A folder that answers the question without a conversation: the approved exercise plan, the scenario, the participants, the observer records, the timings, the after-action report, the findings and the evidence they were closed. Document 06 gives you that structure and the one-page cover note that states which limb of Article 11(6) the exercise evidences.
Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.