A cyber insurance application is an evidence exercise wearing a questionnaire’s clothing. The questions look like a survey — do you enforce MFA, do you have offline backups, do you have a written incident response plan — but each answer is an attestation, and the gap between “yes, mostly” and “yes, and here is the artifact” is what a renewal conversation, and later a claim review, tends to turn on.
This checklist is the artifact set we assemble in a readiness engagement, organized by the control areas that recur across underwriting questionnaires. Two constraints up front, because they shape everything below. We cannot tell you what any specific carrier will ask, accept, or cover — that is between you, your broker, and the underwriter. And nothing here makes any claim payable. What it does is put you in a position to answer accurately, quickly, and with something behind the answer.
Want to put this into practice? Use our free Cyber Risk Self-Assessment.
Why accuracy matters more than a good score
The temptation on a questionnaire is to answer to the aspiration. Resist it. An application answer is a representation you are making to an insurer, and the safest posture is a precise “yes, for this population, with these exclusions” rather than an unqualified yes that a later review can contradict. In our experience, underwriters respond better to a qualified yes with a documented remediation date than to an unqualified yes with an obvious hole behind it — and a qualified yes cannot be characterized later as a misrepresentation.
If a question cannot be answered accurately in the affirmative, the useful move is to answer it accurately in the negative, attach the compensating control, and attach the remediation date. That is a fundable position. An unsupported yes is not.
The eight evidence bundles
A print-ready version of the eight bundles below — one line per artifact, with space to record who owns it and whether you can evidence it yet — is in our cyber insurance evidence checklist.
1. Identity and access
- MFA coverage by population, expressed as a number, with the excluded populations named: service accounts, shared mailboxes, break-glass accounts, contractors, and any legacy application that cannot support it.
- Privileged role membership with last-use dates, and whether privilege is standing or activated just in time.
- Remote access method and whether it is behind MFA.
- Joiner-mover-leaver evidence: a sample of deprovisioning records with timestamps.
Identity questions carry the most weight on most questionnaires, and they are the ones where “we’re rolling it out” is most often recorded as a yes. Pull the actual numbers. The method is in the Microsoft 365 security assessment checklist.
2. Backup and recovery
- Backup scope, retention, and where copies live.
- Evidence that backups are protected from the production identity estate — immutability or offline separation — not just that they exist.
- The last restore-test record, with date, scope, measured recovery time, and outcome.
- Documented RTO and RPO per critical business process.
The restore-test record is the highest-value single artifact in the whole pack, because it converts a claim about resilience into a measurement. If you have none, run one before renewal; the method is in how to prove your backups will actually restore.
3. Endpoint and email controls
- Endpoint protection coverage as a percentage of known assets, plus the count of assets not covered and why.
- Patch compliance for internet-facing systems, with the cadence and the exception list.
- Email authentication posture — SPF, DKIM, DMARC — per sending domain.
- Whether external-sender indicators are enabled and whether auto-forwarding to external addresses is restricted.
4. Payment and social-engineering controls
- The written out-of-band verification procedure for payment and payee changes, and evidence it is enforced rather than aspirational.
- Dual-authorization thresholds for outbound payments.
- Help-desk identity verification procedure for password and MFA resets.
These are process controls, not technology, and they are increasingly asked about because they are what actually interrupts a funds-transfer loss.
5. Governance and program
- The written information security policy set with an approval date and an owner.
- The named individual accountable for the program.
- The most recent risk assessment, with the roadmap and evidence of progress against it.
- Security awareness training completion rates and phishing simulation results if you run them.
- Board or executive reporting cadence and a sample report.
Where a regulatory regime applies, this bundle may already be mandatory rather than optional. The FTC Safeguards Rule at 16 CFR 314.4 requires a designated Qualified Individual, a written risk assessment, encryption of customer information in transit and at rest, multi-factor authentication, a written incident response plan, service-provider oversight, and a written report to the board or a senior officer at least annually. If you are covered by it, the pack you owe your regulator overlaps almost entirely with the pack the underwriter wants.
6. Testing and vulnerability management
- Vulnerability scan cadence and evidence, with remediation SLAs by severity and actual performance against them.
- Penetration test reports, if any, with the retest evidence.
- The exception register for anything knowingly unremediated.
The Safeguards Rule sets a useful benchmark even for organizations it does not cover: 16 CFR 314.4(d)(2) requires continuous monitoring or, absent it, annual penetration testing plus vulnerability assessments at least every six months, and additionally whenever there are material changes to operations or business arrangements. That is a defensible cadence to be measured against whether or not the rule applies to you.
7. Incident response
- The written plan, with the seven content areas the Safeguards Rule enumerates as a reasonable structure: goals, internal response processes, roles and decision authority, internal and external communications, remediation requirements, documentation and reporting, and post-event revision.
- The date and scope of the last tabletop exercise, with the findings and what was closed.
- The offline contact sheet, including the carrier’s breach hotline.
If none of this exists yet, incident response planning without a security team covers building it with the staff you have.
8. Third parties
- Vendor inventory with data access, criticality, and contractual security terms.
- Evidence of periodic reassessment for the vendors that matter.
- Notification clauses and the windows they impose.
Use a control baseline, not a wish list
If you need a defensible baseline to organize the pack against — and to answer “what should we be doing” without inventing a standard — two public references do the job.
CIS Critical Security Controls v8.1 defines Implementation Group 1 as a foundational set of 56 Safeguards that CIS calls essential cyber hygiene and describes as an emerging minimum standard of information security for all enterprises, selected to be implementable with limited cybersecurity expertise and aimed at thwarting general, non-targeted attacks. For a mid-market firm, IG1 is a realistic target set and maps readably onto most questionnaire sections.
CISA’s Cross-Sector Cybersecurity Performance Goals 2.0 are a voluntary, prioritized set aligned to the NIST CSF 2.0 Functions, published with cost, impact, and ease-of-implementation ratings for each goal — which makes them unusually useful for arguing a budget case rather than only for measuring posture.
Both are free, both are citable, and using either lets you describe your position in language an underwriter, a customer, and a board can all read.
Assembling it once, using it three times
The pack above is the same pack that answers an enterprise customer’s security questionnaire and a diligence request in a funding or acquisition process. Build it once, keep it current on a defined cadence, and store it somewhere that is not the file share it is supposed to protect. A cybersecurity risk assessment produces most of it as a by-product — the evidence register, the assessed profile, the severity-ranked findings, and the remediation roadmap are exactly the artifacts these three audiences ask for — which is generally a better sequence than assembling the pack in the four weeks before a renewal date.
FAQ
What evidence do cyber insurance applications typically ask for?
Underwriting questionnaires recur across eight areas: identity and access (MFA coverage and privileged access), backup and recovery (protection of backups and restore-test evidence), endpoint and email controls, payment and social-engineering process controls, governance (policy set, named owner, risk assessment, training, board reporting), testing and vulnerability management, incident response (written plan, tabletop evidence, contact sheet), and third-party oversight. Specific questions vary by carrier and are a matter for your broker and underwriter.
What should we do if we cannot answer yes to a control question?
Answer accurately in the negative, describe the compensating control, and attach a remediation date. An application answer is a representation to an insurer, and a qualified yes or a documented no with a plan is a stronger position than an unqualified yes that a later review can contradict.
Does having this evidence guarantee coverage or a paid claim?
No. Coverage terms, underwriting decisions, and claim outcomes are determined by the carrier under the policy and applicable law. Assembling evidence lets you answer accurately and quickly; it is not a coverage guarantee, an insurance recommendation, or legal advice.
What baseline should we measure ourselves against?
CIS Critical Security Controls v8.1 Implementation Group 1 is a foundational set of 56 Safeguards that CIS defines as essential cyber hygiene and an emerging minimum standard for all enterprises, designed to be implementable with limited security expertise. CISA’s Cross-Sector Cybersecurity Performance Goals 2.0 are a voluntary prioritized set aligned to NIST CSF 2.0 and published with cost, impact, and ease-of-implementation ratings. Both are free and citable.
How often should the evidence pack be refreshed?
Quarterly for the metrics that move — MFA coverage, patch compliance, training completion, privileged role membership — and on an event basis for the artifacts: after each restore test, each tabletop exercise, each penetration test, and each material change to the environment. Refreshing only before renewal produces a pack that is accurate for one week a year.
What this guide is / What it is not
What it is: A practitioner evidence checklist organized around control areas that recur in cyber insurance underwriting, anchored to CIS Critical Security Controls v8.1 Implementation Group 1, CISA’s Cross-Sector Cybersecurity Performance Goals 2.0, and the FTC Safeguards Rule at 16 CFR Part 314. What it is not: Legal advice, insurance advice, a broker service, an audit, a certification, or an attestation. DSE does not speak for any carrier, does not determine coverage, and does not guarantee that any policy will be issued, that any premium will change, or that any claim will be paid. Nothing here reduces your duty to answer an application accurately; representations to an insurer are your own and should be reviewed with your broker and counsel. Readiness work is point-in-time and does not prevent incidents.
The Bottom Line
Answer accurately, and hold an artifact behind each answer. The eight bundles above — identity, backup and restore evidence, endpoint and email, payment process controls, governance, testing, incident response, and third parties — are the same pack an enterprise customer’s questionnaire and an acquirer’s diligence request will ask for, so assemble it once and keep it current on a cadence rather than in the four weeks before renewal. Where you cannot answer yes, say so, attach the compensating control, and attach the date. That is a position you can defend later.
Key facts
- CIS Critical Security Controls v8.1 Implementation Group 1 consists of 56 Safeguards that the Center for Internet Security defines as essential cyber hygiene and describes as an emerging minimum standard of information security for all enterprises (CIS, 2026).
- The FTC Safeguards Rule at 16 CFR 314.4(d)(2) requires continuous monitoring or, absent effective continuous monitoring, annual penetration testing of information systems plus vulnerability assessments at least every six months and whenever there are material changes to operations or business arrangements (eCFR, current 2026).