1) monitor the complete certificate chain
2) indeed have a backup certificate ready (might be non EV), this is especially a must if you use HSTS [1] (which you should use BTW) it is actually a (low priority) government recommendation (B5-6) in The Netherlands [2], but that might have something to do with the government heavily using DigiNotar which got compromised and had it root certificates revoked by Microsoft which caused some communication issues..
[1] https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security
[2] https://www.ncsc.nl/binaries/nl/dienstverlening/expertise-ad... (in Dutch)