§ Cybersecurity proof & diagnostic assets·print-friendly · evidence register

The control evidence a cyber-insurance application asks for.

Underwriting questionnaires increasingly ask you to prove controls, not just claim them. This register lists the artifacts applications commonly request, with a column to record the evidence you will attach and its as-of date — so your answers are supportable representations.

About this asset

Audience
Owners and IT/security leads assembling evidence for a cyber-insurance application or renewal — and for enterprise-customer security questionnaires.
Owner service
Cyber Insurance Evidence Readiness Assessment
Classification
Classification: Public · Version 1.0 · July 2026
Methodology
The control areas reflect the essential-hygiene controls carriers commonly ask about, organized around outcomes in NIST Cybersecurity Framework 2.0 (NIST CSWP 29) and the CISA Cross-Sector CPGs. Specific questions and thresholds vary by carrier; this is an evidence-gathering aid, not a policy.
Limitations
Point-in-time, self-diagnostic checklist you complete yourself. It is not a DSE assessment, an audit, insurance advice, a broker service, or legal advice, and it produces no eligibility, premium, or claim determination.
Verification
The framework references were checked against the csrc.nist.gov and cisa.gov landing pages linked below. Control areas are stated generically; no carrier, form, or coverage outcome is named or implied.
The evidence register

Attach the artifact, date it.

For each control, note the evidence you will attach and the date it reflects. A dated, evidence-backed answer is easier to support later than a bare “yes”. How you answer any application question is a decision for you, your broker, and your counsel.

Cyber-insurance evidence register — complete the evidence and as-of-date columns yourself
Ready Control area Evidence artifact to attach As-of date
MFA coverageReport or export showing MFA is enforced on email, remote access, and privileged accounts, and where any exceptions remain.__________
Endpoint detection & response (EDR) coverageDeployment report showing EDR coverage across servers and workstations, and the count of unmanaged endpoints.__________
Backup & restore testingEvidence of recent, tested backups — a timed restore log and an offline/immutable-copy confirmation.__________
Incident response planThe written IR plan and the date of its most recent test or tabletop.__________
Patching cadenceEvidence of a documented patch/update cadence and current status for internet-facing and critical systems.__________
Privileged-access controlsAdmin-account inventory, separation of privileged accounts, and how elevated access is protected and reviewed.__________
Security-awareness trainingRecords of staff security-awareness and phishing training, with completion rates and the last training date.__________

Want the eight artifact bundles broken down further, including why a qualified yes beats an unsupported yes? Read the deep dive.

Make the evidence pack real before you apply.

A free 30-minute Cyber Risk Check scopes a readiness engagement that assembles and dates this evidence — the same pack that answers enterprise-customer questionnaires — so your representations are supportable.

What this is and is not. A point-in-time, self-diagnostic evidence checklist. DSE is not an insurance broker, agent, or carrier and guarantees no eligibility, premium, or claim outcome. Carrier requirements vary — your application answers are your representations. It is not a DSE assessment, an audit, insurance advice, or legal advice. See the deep dive for the full artifact breakdown.

Primary sources, verified.