Cyber insurance evidence pack 2026: what to include
What an underwriting evidence pack contains, why an independent SOC-CMM assessment strengthens your underwriting and claims position, and how to maintain it year over year.
Why do underwriters ask for evidence, not answers?
The cyber insurance market has tightened underwriting. Questionnaires a few years ago accepted ticked boxes: do you have MFA, do you have backups, do you have a response plan. Today the underwriter asks the same questions and adds a second layer: prove it. They want to see the dashboard, the report, the documented exercise.
The reason is statistical. Insurers have paid losses at organizations that had ticked every box. The distance between what an organization declares and what it can demonstrate is precisely the risk the underwriter is trying to price. A well-built evidence pack reduces that uncertainty, and uncertainty is what makes a policy expensive.
The figure that best summarizes the problem comes from the SOC-CMM model itself: self-assessments score on average about 0.6 maturity points higher than assessments performed by third parties (SOC Maturity Report 2026, SOC-CMM®). On a 0-to-5 scale, that is the difference between a defined process and one that exists only in the slide deck. Underwriters do not know that exact number, but they know the phenomenon. That is why they discount unsupported claims.
What does an underwriting evidence pack contain?
A useful evidence pack has four blocks. Each answers a different underwriter question, and all four must be verifiable: dated document, identified source, named owner.
| Block | What it answers | Typical format |
|---|---|---|
| Control evidence | Do the declared controls exist and work? | Control matrix with coverage figures, dashboard exports, signed policies |
| SOC maturity | Is the defensive capability sustainable or accidental? | SOC-CMM assessment report with 0-5 scores per domain |
| Detection coverage | Which attack techniques would you actually detect? | Use-case mapping against MITRE ATT&CK with a coverage percentage |
| History and response | What has happened before, and how did you respond? | Incident register, MTTD/MTTR metrics, latest tabletop with conclusions |
The control block covers what every questionnaire asks: a security policy approved by the governing body and current, MFA on privileged and remote access with a coverage figure, EDR on corporate endpoints with its real percentage, immutable or offline backups with a documented restore test, vulnerability management with severity-based SLAs, and management of critical ICT third parties.
The detection block is what most separates a mediocre pack from a strong one. The global average of declared coverage against MITRE ATT&CK sits around 60% of techniques (SOC Maturity Report 2026, SOC-CMM®). If you present your real figure, with methodology, you communicate something most applicants cannot: that you know what you do not see. To an underwriter, that is worth more than an impossible 100%.
The history block is uncomfortable, but omitting it is worse. An honest incident register with detection and containment times demonstrates that the response process works. A blank page suggests nobody is looking.
Why does an independent SOC-CMM assessment strengthen your position?
The finding first: a maturity score issued by an external assessor is the only element of the pack that does not rest on your own word. Everything else, dashboards, policies, metrics, is produced by your team. The independent assessment is produced by someone with no stake in the result.
The SOC-CMM is the right model for this purpose for three reasons. It is the de facto standard for measuring the maturity of security operations centers, created by Rob van Os in 2016 and cited by MITRE. It assesses five domains (Business, People, Process, Technology, Services) with continuous 0-to-5 scoring, which gives the underwriter a comparable figure rather than a subjective traffic light. And a public benchmark exists: global domain averages sit between 2.2 and 2.7, so your score is read in context.
At underwriting, the effect is direct: the underwriter replaces uncertainty with a third-party measurement, and uncertainty is the component that prices worst. In a claim, the effect is defensive. If, after an incident, the insurer questions whether the statements in the application were accurate, an independent report dated before the loss documents the real state of the SOC at that moment. Your position no longer depends on reconstructing evidence under pressure.
Low maturity is no reason to hide. A 2.4 score with a dated, owned improvement plan is better evidence than a self-assessed 4 with no methodology. The underwriter prices trajectory and honesty, not perfection. What gets penalized is the claim you cannot support.
How to assemble the pack in a week
The pack is built from evidence that already exists. The work is organization, not creation. A reasonable 5-to-7-day sequence:
- 1.Day 1: inventory what you already have. Current policies, latest assessment, coverage dashboards, incident register, latest tabletop.
- 2.Days 2-3: complete the control matrix. Every control with its linked evidence, its coverage percentage and its date. No figure, no entry.
- 3.Day 4: write the one-page cover memo: SOC-CMM maturity score, detection coverage, incident history summary and the three improvements of the past year.
- 4.Day 5: add the improvement plan with owners and dates. It answers the question every underwriter asks: what will you improve this year.
- 5.Days 6-7: cross-review. Every statement in the questionnaire must point to a document in the pack. Anything unsupported gets rephrased or withdrawn.
The most expensive mistake is answering the questionnaire in free text without linking evidence. The statement 'MFA everywhere' with no coverage figure is worth less than '94% of privileged accounts, evidence attached'. Precision is the signal.
How to maintain the pack year over year
Renewal is where the pack truly pays off. The underwriter compares this year's pack with last year's, and documented improvement is the strongest argument you can present: the maturity score went up, ATT&CK coverage grew, last year's improvement plan was executed.
- Repeat the SOC maturity assessment on an annual cadence, aligned with the renewal window, so the score arrives fresh.
- Update the control matrix quarterly; coverage figures go stale fast.
- Run at least one tabletop per year and archive the conclusions; it is the cheapest and most valued evidence in the pack.
- Close out each year's improvement plan with per-initiative status before opening the next one.
- Version the full pack: the history is itself evidence of governance.
A maintained pack turns renewal from an interrogation into an update. That is the difference between defending your SOC every year and demonstrating it once, with evidence that compounds.
Frequently asked questions
Is a SOC-CMM self-assessment enough for the pack?
It is better than nothing, but its evidentiary value is limited. Self-assessments score on average about 0.6 points higher than third-party assessments (SOC Maturity Report 2026, SOC-CMM®), and underwriters discount accordingly. An independent assessment removes that discount because it is issued by someone with no stake in the result. If a self-assessment is all you can do this year, declare it as such and plan the external assessment for renewal.
Does a strong pack reduce the premium?
A solid pack reduces the underwriter's uncertainty, and uncertainty is one of the factors that makes pricing expensive. The concrete effect depends on your sector, loss history and the state of the market at the time, so promising percentages would not be serious. What is consistent: verifiable evidence improves your negotiating position relative to an equivalent application with no documentary support.
Does the same pack work for renewal?
Yes, and that is where it pays off most. At renewal the underwriter compares the current pack with last year's. Documented improvement, maturity rising, detection coverage growing, the improvement plan executed, justifies keeping conditions. A static pack, by contrast, suggests a stalled security program.
What if my SOC maturity is low?
Present it with the improvement plan next to it. A modest score measured with a methodology, accompanied by a roadmap with owners and dates, communicates governance and trajectory. Hiding or inflating it is the expensive option: if, after a loss, the evidence contradicts the application, your claims position weakens exactly when you need it most.
How often should I update the pack?
Maturity assessment and tabletop, once a year, aligned with the renewal window. Control matrix and coverage figures, quarterly. Incident register and response metrics, continuously. The cover memo is rewritten at each renewal with the year's changes.

Written by
Daute DelgadoCEO & Co-founder, Primedefence
Daute Delgado is CEO and co-founder of Primedefence. He spent more than a decade defending airlines, managed SOCs and international organizations, first as an operator and later leading security teams.
View full profileNeed an independent SOC-CMM assessment?
Book an express diagnostic with a senior assessor. No product sales, no SOC operation.



