CP-7: Alternate Processing Site

CP-07 requires organizations to maintain an alternate processing site ready to resume essential operations when the primary site fails.

Compliance Hub / NIST SP 800-53 / Contingency Planning / CP-07

Quick-reference card

FieldValue
Control IDCP-07
Control NameAlternate Processing Site
FrameworkNIST SP 800-53, Revision 5
Control FamilyContingency Planning
BaselinesMODERATE HIGH
RelevanceOrganization (First Party and Third Party)
Risk SeverityMedium

What this control requires

CP-07 requires organizations to maintain an alternate processing site ready to resume essential operations when the primary site fails. The control doesn’t ask for a backup location on paper. It demands operational readiness, contractual agreements, and equivalent security controls at the alternate site.

In practice, this means three things must be in place before a disruption occurs. First, you need formal agreements, whether with a colocation provider, a cloud service provider, or an internal facility, that define how and when system operations transfer. Second, the equipment, supplies, and connectivity required to resume operations must either be pre-staged at the alternate site or covered by contracts that guarantee delivery within your defined recovery window.

But the requirement that most organizations overlook is control equivalence. The alternate site must maintain security controls matching the primary site, including physical access controls, environmental protections, and personnel coordination. A business continuity plan that routes processing to a site with weaker security controls doesn’t satisfy CP-07. It creates a new attack surface.

Why it matters

Most organizations don’t test their alternate processing capability until they need it. By then, it’s too late to discover that the failover site lacks current configurations, the network path hasn’t been validated, or the agreements expired six months ago.

The result is direct audit exposure. Failure to maintain CP-07 can lead to certification withdrawal or regulatory findings. For organizations subject to FedRAMP, FISMA, or similar frameworks, a missing or untested alternate processing site is a significant gap that assessors flag consistently. The control sits in both the Moderate and High baselines, meaning any system categorized at those impact levels must address it.

Where this breaks down in practice is the equivalence requirement. Organizations frequently maintain a “warm” or “cold” alternate site that lacks the same monitoring, logging, or access control posture as the primary environment. During an actual failover, that gap means operating in a degraded security state at precisely the moment you can least afford it.

Specifically, cloud-based failover architectures have reduced the infrastructure burden but introduce their own equivalence challenges around data residency, encryption key management, and identity federation.

What attackers exploit

When CP-07 controls are absent or untested, attackers and auditors alike find predictable gaps.

  • Unmonitored failover environments. Alternate sites with reduced logging or detection coverage become blind spots during active incidents.
  • Stale configurations. Alternate sites running outdated software or firewall rules that diverge from the primary site.
  • Weak physical security at backup locations. Colocation or secondary office spaces with less stringent access controls.
  • Untested recovery procedures. Organizations that can’t execute a failover within their stated recovery time objective.
  • Single-region cloud deployments. Systems with no geographic redundancy that are vulnerable to regional outages.

How to implement

The most common failure mode for CP-07 isn’t the absence of an alternate site. It’s the absence of tested, documented, and contractually backed readiness at that site.

For your organization

Step 1. Define your recovery requirements. Start with your contingency plan (CP-02) and identify which system operations qualify as essential mission and business functions. Assign each a recovery time objective (RTO) that determines how quickly processing must resume at the alternate site.

Step 2. Select and establish the alternate site. Options include dedicated secondary data centers, colocation facilities, cloud-based failover regions, or hybrid arrangements. The site must be geographically distinct from the primary location to reduce susceptibility to the same threats, including natural disasters, power grid failures, and regional network outages. Document the rationale for your geographic separation.

Step 3. Formalize agreements. Whether you’re using an internal facility or a third-party provider, put agreements in place that cover transfer timelines, priority-of-service provisions, environmental conditions, physical and logical access rules, and personnel coordination. For cloud providers, review your disaster recovery plan and map service-level agreement (SLA) commitments against your RTOs.

Step 4. Pre-stage or contract for equipment and supplies. Maintain an inventory of what’s needed to resume operations. Either pre-position equipment at the alternate site or hold contracts with suppliers that guarantee delivery within your recovery window. Update this inventory at least annually.

Step 5. Ensure control equivalence. Replicate the security posture of your primary site at the alternate location. This includes access control mechanisms, environmental protections (emergency power, fire suppression, climate control), monitoring and logging capabilities, and encryption standards. ISO 27001 control 8.14 on redundancy of information processing facilities addresses a parallel requirement.

Common mistakes:

  • Treating the alternate site as a “set and forget” investment, where configurations drift, agreements lapse, and equipment ages out
  • Failing to test failover procedures under realistic conditions
  • Assuming cloud provider SLAs automatically satisfy CP-07 without mapping them to organizational RTOs
  • Neglecting physical security equivalence at colocation or branch office sites

For your vendors

What to ask in security questionnaires:

  • Does your organization maintain an alternate processing site for systems that handle our data?
  • What is the defined recovery time objective for failover to the alternate site?
  • Are security controls at the alternate site equivalent to the primary site? How is equivalence validated?
  • When was the most recent failover test conducted, and what were the results?
  • Do your alternate processing site agreements include priority-of-service provisions?

Evidence to request:

  • Alternate processing site agreements or cloud provider SLAs with failover commitments
  • Most recent contingency plan test results showing failover execution
  • Equipment and supplies inventory for the alternate site
  • Documentation of security control equivalence between primary and alternate sites

Red flags:

  • Vendor cannot name their alternate processing site or describe its location relative to the primary site
  • No documented failover test in the past 12 months
  • Alternate site relies on a shared facility with no priority-of-service agreement
  • Security controls at the alternate site are described as “reduced” or “limited” during failover
  • Vendor’s disaster recovery plan does not reference an alternate processing site

Evidence examples

Evidence TypeExample Artifact
Contingency planning policyPolicy document defining alternate processing site requirements, selection criteria, and review cadence
Alternate processing site agreementSigned agreement with colocation or cloud provider specifying transfer timelines, priority-of-service, and environmental conditions
Equipment and supplies inventoryItemized inventory of pre-staged hardware, network equipment, and supplies at the alternate site with last-verified date
Contingency plan with failover proceduresContingency plan sections detailing step-by-step failover and resumption procedures for essential functions
Service-level agreementCloud provider or facility SLA mapping recovery time commitments to organizational RTOs
Control equivalence assessmentSide-by-side comparison of security controls at primary and alternate sites covering access control, monitoring, and environmental protections

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20225.29 Information security during disruptionPartial
ISO 27001:20227.5 Protecting against physical and environmental threatsPartial
ISO 27001:20228.14 Redundancy of information processing facilitiesPartial
  • CP-02, Contingency Plan. Provides the overarching plan that drives alternate processing site requirements, including which functions must be recovered and in what order.
  • CP-06, Alternate Storage Site. Addresses backup data storage locations, which must coordinate with the alternate processing site to ensure data availability during failover.
  • CP-08, Telecommunications Services. Ensures network connectivity to the alternate processing site, without which failover cannot execute regardless of site readiness.
  • CP-09, System Backup. Governs the backup processes that supply the alternate site with current data and configurations needed to resume operations.
  • CP-10, System Recovery and Reconstitution. Defines how systems are restored to operational status at the alternate site and eventually reconstituted at the primary site.
  • MA-06, Timely Maintenance. Ensures equipment at the alternate site receives maintenance within defined time periods to remain operational when needed.
  • PE-03, Physical Access Control. Applies equivalence requirements for physical access at the alternate site, including badge systems, visitor logs, and escort procedures.
  • PE-11, Emergency Power. Requires uninterruptible power supply and backup generators at the alternate processing site to match primary site resilience.
  • PE-12, Emergency Lighting. Ensures the alternate site has emergency lighting for safe operations during power transitions.
  • PE-17, Alternate Work Site. Covers the personnel side, defining where employees work during a contingency and how that coordinates with alternate processing site activation.

Frequently asked questions

What is NIST SP 800-53 CP-07?

CP-07 requires organizations to establish a geographically separate alternate processing site that can resume essential system operations within a defined recovery window when the primary site becomes unavailable. The control goes beyond having a backup location. It mandates formal agreements, pre-staged or contractually guaranteed equipment, and security controls equivalent to those at the primary site. This includes physical access controls, environmental protections like emergency power and lighting, and monitoring capabilities. Cloud-based failover environments, colocation facilities, and geographically distributed architectures all qualify as alternate processing sites under CP-07, provided they meet the equivalence and readiness requirements.

What happens if CP-07 is not implemented?

Without an alternate processing site, an organization loses the ability to continue essential operations when the primary site is disrupted by a natural disaster, infrastructure failure, cyberattack, or other incident. For organizations in the Moderate or High baselines, the absence of CP-07 is a direct audit finding that can block or delay an Authority to Operate (ATO). Assessors specifically verify that alternate site agreements exist, that equipment is available or contractually backed, and that security controls match the primary site. Beyond audit consequences, the operational risk is direct. You face extended downtime for mission-critical functions, potential data loss if backup systems (CP-09) aren’t coordinated with the alternate site, and degraded security posture if a hastily activated failover environment lacks equivalent controls.

How do you audit CP-07?

Auditors assess CP-07 by examining the alternate processing site agreement for completeness, confirming it covers transfer timelines, priority-of-service provisions, environmental conditions, and access rules. They review the contingency plan to verify that failover procedures are documented and that recovery time objectives align with the organization’s mission requirements. Auditors also inspect the equipment and supplies inventory at the alternate site, verify that delivery contracts are current, and compare physical access controls, environmental protections, and monitoring capabilities between the primary and alternate sites. Interview and test evidence round out the assessment, with assessors confirming the organization can execute a transfer within its stated recovery window.

What is the difference between an alternate processing site and an alternate storage site?

An alternate processing site (CP-07) provides the computing infrastructure needed to run system operations when the primary site is unavailable, while an alternate storage site (CP-06) provides a separate location for storing backup data and system images. The two controls work together. CP-06 ensures your data is available at a geographically distinct location, and CP-07 ensures you have the processing capability to use that data. Each control addresses different requirements. CP-06 focuses on data replication, retention, and retrieval, while CP-07 covers operational readiness, equipment availability, and security control equivalence during disruption.

Experience superior visibility and a simpler approach to cyber risk management