A CA is just some bytes, not a service. And it has been established that there's a backup login path: use (a copy of) the CA outside of the automated certificate signing service to manually sign the needed certificates.
They'd be screwed if they lost the CA's private key, but it is much easer to keep some data around than to keep a service functioning properly.