Control cross-reference
PCI DSS v4.x and your incident response exercise.
PCI DSS v4 requirement 12.10 is explicit that the incident response plan is tested, and that the testing is documented. The requirements below are the ones an exercise speaks to.
This is a cross-reference, not an assessment. Running an exercise does not by itself satisfy any control here. It produces a dated, attributed record, and your auditor decides what that record is worth against these criteria.
The controls
What an exercise speaks to.
-
12.10.1
Incident response plan elements
-
12.10.2
Annual test of the incident response plan
-
12.10.4
Incident response training and readiness
The evidence
What a reviewer is actually asking for.
Not the plan. Almost everyone has a plan. They are asking whether it was exercised, when, by whom, and what that surfaced. That is a record with a date and people in it, and it only exists if the exercise actually happened.
Run one.
A live tabletop on your own systems and plan, with the record written by the time you finish, for $199.