1. Planned
The control is intended or budgeted but has not yet been deployed. A planned control should not be represented as implemented.
Cyber Insurance Readiness
Cyber insurance applications and renewals increasingly depend on whether your organization can substantiate the security controls it says are in place. The exact questions vary by insurer and policy, so the practical goal is to maintain current, verifiable evidence across identity, endpoint security, backups, patching, email, incidents, vendors, and governance.
There is no single evidence checklist used by every cyber insurer. A business should be prepared to substantiate the controls it represents on an application with current configuration records, reports, policies, test results, logs, ownership records, and remediation evidence. Do not answer yes because a control is planned, partially deployed, or assumed to exist.
The control is intended or budgeted but has not yet been deployed. A planned control should not be represented as implemented.
The control exists only for part of the environment, user population, device fleet, or workflow. Document coverage, exceptions, and the remediation plan before making broad representations.
The control is configured and in use, but the organization still needs reliable evidence showing its scope, configuration, ownership, and operating status.
The control is operating across the stated scope and current evidence supports that conclusion. This is the strongest position from which to answer underwriting questions.
Prepare evidence showing MFA coverage, administrator-account protections, identity-provider settings, access-review practices, terminated-user handling, and documented exceptions.
Maintain device inventories, endpoint protection or monitoring coverage, vulnerability and patch records, security-alert evidence, and documentation for systems that fall outside normal maintenance.
Prepare backup configuration records, retention and separation details, restore-test results, recovery objectives, business-continuity procedures, and ownership for failed backup or restore events.
Retain email-security settings, awareness and phishing records, incident-response plans and exercises, vendor due diligence, policies, responsible owners, prior-incident documentation, and evidence of recurring management review.
Underwriting forms are not a universal security standard and the exact questions vary by carrier and policy. Use the application to validate the underlying control state, coordinate coverage interpretations with the broker or insurer, and avoid unsupported yes/no answers when deployment or evidence is incomplete.
Last reviewed August 10, 2026. Because underwriting questions differ by carrier and policy, this checklist uses broad current security guidance to help organizations substantiate control statements rather than predict insurer-specific requirements.
Use these resources to validate the underlying controls, identify material gaps, and prepare for insurer questions without overstating what has actually been implemented.
Smart Biz iT's Cyber Insurance Readiness service helps validate technical controls, identify evidence gaps, and organize remediation before application or renewal. For a broader security baseline, start with the Smart Security Snapshot.