CP-6: Alternate Storage Site

CP-06 requires organizations to establish and maintain an alternate storage site for backup data that can be retrieved when the primary

Quick-reference card

FieldValue
Control IDCP-06
Control NameAlternate Storage Site
FrameworkNIST SP 800-53 Revision 5
Control FamilyContingency Planning
BaselinesModerate, High
Implementation LevelOrganization
RelevanceFirst Party and Third Party
Risk SeverityMedium

What this control requires

CP-06 requires organizations to establish and maintain an alternate storage site for backup data that can be retrieved when the primary site is unavailable. This means establishing formal agreements that define storage terms, retrieval procedures, and the security protections the alternate site must uphold.

The requirement goes beyond selecting a remote location. Your alternate storage site must enforce controls equivalent to those at your primary site, covering physical access, environmental protections, and coordination of backup media delivery and retrieval. Without that equivalence, your backup data may be accessible but insufficiently protected, which undermines the entire purpose of maintaining a separate site.

In practice, organizations operating under NIST SP 800-53 Moderate and High baselines must treat this control as a foundational element of their contingency planning program. The Contingency Planning family includes several related controls that work together to protect mission-critical operations. Geographically distributed architectures, including cloud-based storage regions, can satisfy CP-06 requirements when they meet the equivalence standard. The control connects directly to your contingency plan, ensuring that essential mission and business functions survive disruption at the primary site.

Why it matters

Most organizations treat alternate storage as a checkbox in their contingency plan, choosing a second location and assuming the work is done. The real risk emerges when that alternate site lacks equivalent protections or when retrieval agreements haven’t been tested under realistic conditions.

Failure to maintain CP-06 introduces direct audit risk. Federal agencies and contractors undergoing Federal Information Security Management Act (FISMA) assessments or Authorization to Operate (ATO) reviews will face findings if assessors cannot verify that an alternate storage site exists with documented agreements and equivalent controls. For organizations pursuing Federal Risk and Authorization Management Program (FedRAMP) authorization, a gap here can delay or block certification.

Beyond audit consequences, weak alternate storage arrangements create operational fragility. If your primary site experiences a natural disaster, infrastructure failure, or targeted attack, your ability to recover depends entirely on whether backup data is retrievable from a protected alternate location within your defined recovery time objectives (RTO) and recovery point objectives (RPO).

Vendor supply chain risk compounds this problem. When your third-party service providers lack verified alternate storage capabilities, a single disruption can cascade across your operations and theirs simultaneously.

What attackers exploit

  • Single points of failure in storage architecture, where primary and backup data share the same physical facility, network segment, or cloud availability zone
  • Weak or untested retrieval agreements that prevent timely data recovery when an incident forces failover
  • Insufficient environmental controls at the alternate site, leaving backup media vulnerable to physical theft, water damage, or temperature degradation
  • Lack of geographic separation between primary and alternate sites, so a regional event affects both simultaneously
  • Absent encryption or access controls on backup media during transport or at the alternate facility

How to implement

Establishing a reliable alternate storage site requires more than selecting a secondary location. The challenge is maintaining equivalent protections across two environments while ensuring retrieval actually works when you need it.

For your organization

Start by documenting your alternate storage requirements in your contingency plan. Define the geographic separation you need based on a risk assessment of regional threats, including natural disasters, power grid dependencies, and network infrastructure overlap. The alternate site should be far enough away that a single event cannot affect both locations.

Documentation alone isn’t enough — you must also formalize agreements with the alternate storage provider. These agreements must specify access rules, physical security requirements, environmental protections (temperature, humidity, fire suppression), and coordination procedures for delivering and retrieving backup media. If you use cloud storage regions as your alternate site, verify that the provider’s controls meet your equivalence standard through independent audit reports such as SOC 2 Type II.

Once agreements are in place, implement the following controls at the alternate site to achieve equivalence with your primary facility:

  • Physical access controls restricting entry to authorized personnel
  • Environmental monitoring and protections matching your primary site
  • Encryption of data at rest and in transit between sites
  • Logging and monitoring of access to backup media
  • Regular testing of retrieval procedures, including timed recovery drills aligned with your RTO and RPO

Where programs most often fall short is in maintenance, not initial setup. Teams fail to update alternate site agreements when primary site controls change, neglect to test retrieval under realistic failure conditions, and assume cloud replication alone satisfies CP-06 without verifying the provider’s physical and environmental controls. Document every test result as evidence for assessors.

For your vendors

When evaluating whether a third-party provider maintains adequate alternate storage, go beyond self-attestation. Request and verify the following:

Questionnaire questions to include:

  • Does the vendor maintain an alternate storage site geographically separate from the primary site?
  • What formal agreements govern storage and retrieval at the alternate site?
  • Are controls at the alternate site equivalent to those at the primary site, and how is equivalence verified?
  • What is the vendor’s documented RTO and RPO for data stored at the alternate site?
  • When was the last retrieval test performed, and what were the results?

Evidence to request:

  • Alternate storage site agreements or contracts
  • Most recent contingency plan with alternate storage provisions
  • Results from the last retrieval or failover test
  • SOC 2 Type II or equivalent audit report covering the alternate site
  • Physical security and environmental control documentation for the alternate facility

Red flags to watch for:

  • The vendor cannot produce a current alternate storage site agreement
  • Primary and alternate sites are in the same geographic region or share infrastructure dependencies
  • No documented retrieval tests within the past 12 months
  • The vendor relies solely on cloud replication without independent verification of the provider’s controls
  • Alternate site access controls are less restrictive than primary site controls

Red flags in any of these areas warrant deeper scrutiny. Verify claims by cross-referencing the vendor’s contingency plan with their alternate site agreements. If the vendor uses a cloud provider, request the cloud provider’s SOC 2 report and confirm that the specific storage region serves as the designated alternate site.

Evidence examples

Evidence TypeExample Artifact
Contingency planning policyOrganizational policy defining requirements for alternate storage sites, including geographic separation and control equivalence standards
Alternate storage site agreementSigned contract with the alternate site provider specifying access rules, environmental protections, retrieval procedures, and security requirements
Contingency planCurrent contingency plan identifying the designated alternate storage site, RTO/RPO targets, and failover procedures
Retrieval test resultsDocumentation of the most recent backup retrieval drill, including time-to-recovery measurements and identified gaps
Physical security documentationAccess control logs, visitor records, and environmental monitoring reports from the alternate storage facility
System security planSystem security plan sections describing how alternate storage site controls meet equivalence requirements relative to the primary site

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20225.29 Information security during disruptionPartial
ISO 27001:20227.5 Protecting against physical and environmental threatsPartial
ISO 27001:20228.14 Redundancy of information processing facilitiesPartial
  • CP-02 — Contingency Plan: defines the overarching plan that CP-06 supports by designating where backup data resides during a disruption
  • CP-07 — Alternate Processing Site: addresses the processing counterpart to alternate storage, ensuring compute capacity survives a primary site failure
  • CP-08 — Telecommunications Services: covers the communication links needed to access and retrieve data from the alternate storage site
  • CP-09 — System Backup: governs the creation of the backup data that CP-06 protects at the alternate location
  • CP-10 — System Recovery and Reconstitution: defines how systems are restored using data retrieved from the alternate storage site
  • MP-04 — Media Storage: specifies protections for storage media at both primary and alternate locations
  • MP-05 — Media Transport: addresses security of backup media during transit between primary and alternate sites
  • PE-03 — Physical Access Control: establishes the physical access requirements that the alternate site must match for control equivalence
  • SC-36 — Distributed Processing and Storage: covers architectures that distribute data across multiple sites, which may satisfy CP-06 when properly configured
  • SI-13 — Predictable Failure Prevention: supports proactive measures that reduce the likelihood of needing to failover to the alternate site

Frequently asked questions

What is NIST SP 800-53 CP-06

CP-06 requires organizations to establish an alternate storage site with formal agreements that permit the storage and retrieval of system backup information, while maintaining controls equivalent to the primary site. The control falls within the Contingency Planning family and applies to Moderate and High baselines. Your alternate storage site agreements must address physical access, environmental protections, and coordination of backup media delivery to satisfy assessor requirements.

What happens if CP-06 is not implemented

Without an established alternate storage site, your organization cannot recover critical data if the primary storage location becomes unavailable due to a disaster, infrastructure failure, or attack. Assessors evaluating your system under FISMA or FedRAMP will issue findings for the absence of documented alternate storage site agreements and equivalent controls. The resulting audit risk can delay authorization decisions and weaken your overall contingency planning posture.

How do you audit CP-06

Auditing CP-06 starts with verifying that an alternate storage site exists and that formal agreements are in place governing storage, retrieval, and security protections. Assessors review the contingency plan to confirm it references the alternate site and defines retrieval procedures. They then compare the controls at the alternate site against those at the primary site to verify equivalence, examining physical access control documentation, environmental monitoring records, and the results of the most recent retrieval test.

What is the difference between an alternate storage site and an alternate processing site

An alternate storage site holds duplicate copies of backup data and system information, while an alternate processing site provides the compute capacity to run systems when the primary processing location is unavailable. CP-06 governs the storage side, and CP-07 governs the processing side. In practice, your contingency plan needs both, because retrievable backup data is only useful if you also have a functioning environment to restore and run those systems.

Experience superior visibility and a simpler approach to cyber risk management