A backup you have never restored is a hope, not a plan. Rehearse into an isolated environment, and climb the verification ladder in order — each rung proves something the previous cannot: CAs listed → a test issuance succeeds (the KEK actually unwraps a key) → audit/verify?limit=0 is intact (the chain came back self-consistent) → the latest checkpoint head equals the one you recorded externally (self-consistent and yours are different claims) → a status-board count matches a filtered inventory search (the statistics rollup survived).
Three ways a restore goes wrong, each with its symptom. Wrong master secret: the management process refuses to start naming a decision-key mismatch; nothing is corrupted, and nothing but the original secret will help — this is the failure escrow exists for. The restored copy runs while the original still signs: every accountability guarantee is enforced inside one database, so two live environments break the signature series silently — rehearsals run isolated and are discarded; a real failover requires the old primary dead and staying dead. A partial restore: restore whole databases, never a table subset — a bypass of the statistics triggers leaves every health check green over a board counting zero.
Now I can prove a restore works before the day it has to.