In case anyone else has been thinking about how to monitor OCSP stapling to avoid being caught off-guard again, I’ve created a Nagios/Icinga plugin for this purpose. You can find it on GitHub or on Icinga’s (Plugin) Exchange.
Rather than querying the CA’s OCSP server directly, this actually monitors the (cached) OCSP response a TLS server sends, so this should catch issues where your server is unable to update the OCSP response as well. More details if you follow one of the links above.
Hope this is useful to some. Happy about any feedback on things I might have missed or that could be improved (perhaps on GitHub or the plugin page, as to not further hijack this thread ).