Article 11(6) is two obligations, and the second one gets missed
Read it carefully. Financial entities shall:
- test the ICT business continuity plans and the ICT response and recovery plans at least yearly;
and
- test the crisis communication plans established in accordance with Article 14.
A technical recovery test does not discharge the second. Note where the words
sit: « at least yearly » governs the first limb only, the
Regulation fixes no frequency for the crisis communication plans. Testing both every year is a
defensible policy choice, and the workbook records it as your choice rather than as a legal minimum.
For entities other than microenterprises the testing plans must also include scenarios of
cyber-attacks and of switchovers between the primary infrastructure and the redundant capacity. The
multi-year tab checks all of that per year and shows a gap when a limb is uncovered.
Pass criteria agreed before
Objectives and measurable pass criteria are set at design time, in the workbook. Deciding
afterwards whether it went well is not evaluation, it is recollection.
Five measures on a stopwatch
Detection to declaration. Declaration to a quorate team. To the first situation report. To an
approved holding statement. To the management body. Each against your own target, each PASS or
FAIL, no adjectives.
The twist
Every scenario carries an inject that invalidates the plan the team has settled into: the backups
are encrypted too, the provider doubles its estimate, the corruption predates the last backup.
Without it a rehearsed team performs the rehearsal.
We already run a DR test every year. Is that enough?
For the first limb, possibly. For the second, no. Article 11(6) separately requires the crisis
communication plans to be tested, and a technical failover test does not exercise a holding
statement, an approval route or a spokesperson. Schedule it separately and the obligation becomes
trivially easy to evidence.
Is this certified against ISO 22361?
No, and nothing can be. ISO 22361:2022 and ISO 22320:2018 are guidelines documents, not
requirements standards, so there is no conformity clause and nothing for a certification body to
audit against. The programme is structured on their process, and we mean that literally.
Can we run these exercises without a facilitator?
A walkthrough or a communication drill, yes. A tabletop, better not: the value comes from injects
delivered on the clock by someone who is not playing, and from an observer who is not allowed to
help. The facilitator guide is written so that someone internal can take the role.
Will an exercise disrupt live services?
Not if you follow the safety rules in document 03: everything prefixed, no live client contact,
no live regulatory submission, no production change without an approved rollback, and a stop
phrase everyone is briefed on. Exercises have delayed real incident responses because nobody
could tell the two apart; that is what the rules prevent.
What does the supervisor actually want to see?
A folder that answers the question without a conversation: the approved exercise plan, the
scenario, the participants, the observer records, the timings, the after-action report, the
findings and the evidence they were closed. Document 06 gives you that structure and the
one-page cover note that states which limb of Article 11(6) the exercise evidences.