Home/Resources/Renewal checklist

Renewal readiness checklist

The 90-day cyber insurance renewal checklist

A phase-by-phase pre-renewal plan: baseline last year's answers against your live environment, remediate the gaps that carry the largest coverage consequence, and hand your broker an evidence-backed application.

Not insurance advice. This is a technical readiness checklist. Coverage decisions belong with your licensed broker.

Why 90 days

Ninety days is the shortest runway that reliably works, for two reasons. First, remediation lead time: the gaps that matter most to underwriters, such as MFA coverage on remaining accounts, backup immutability, and privileged access review, each take weeks to close properly, and your broker typically wants the completed submission two to four weeks before the renewal date. Second, drift: your environment has changed since last year's application. New SaaS tools, new admin accounts, a migrated backup platform, staff turnover. An answer that was true when it was signed may be false today, and application answers are representations the carrier relies on. What follows is the plan in three phases, plus a triage order if your renewal is closer than 90 days.

If you are renewing for the first time or facing a new carrier's form, read the cyber insurance questionnaire guide for what applications ask, and the requirements guide for what carriers expect control by control.

Days 90 to 60

Baseline: find out what is actually true

The goal of this phase is a truthful map of where you stand: every prior answer classified as verified, attested, or gap. Do not fix anything yet. Fixing before you have the full picture wastes the remediation window on the wrong controls.

  • Retrieve last year's application and policy. Get the full signed application, any ransomware supplemental, the policy itself, and any subjectivities or conditions the carrier attached at binding. Your broker has copies if you do not.
  • Inventory what changed since submission. New cloud services, new admin or service accounts, backup platform changes, EDR migrations, staff and vendor changes, mergers or new entities. Each change is a place an old answer may no longer hold.
  • Verify every prior answer against the live environment. Not against memory, and not against last year's evidence. Pull current MFA enforcement, current privileged account counts, current backup configuration, current EDR coverage, current SPF, DKIM, and DMARC records.
  • Classify each answer: verified, attested, or gap. Verified means live evidence confirms it. Attested means someone credible states it but no system evidence exists yet, common for restore tests and tabletop exercises. Gap means the environment contradicts the answer or nobody can support it.
  • Rank the gaps by coverage consequence. A gap on a control the carrier treats as a condition or heavy rating factor, MFA in particular, outranks a gap on a minor rating question. This ranking becomes the phase-two work list.
Days 60 to 30

Remediate: close the highest-impact gaps first

Work the ranked gap list from phase one, highest coverage consequence first. In most environments that means MFA, then backups, then privileged access, because those are the controls carriers most often treat as gating rather than merely rating.

  • Close MFA coverage gaps. Email, remote access, and every privileged account, including the service and break-glass accounts that surveys miss. "MFA everywhere" answers fail on the accounts nobody thought to check.
  • Make backups immutable and run a restore test. Enable immutability or equivalent segregation on the backup platform, then perform and date-stamp an actual restore test. Carriers increasingly ask for a test within the last 12 months; a dated record is the evidence.
  • Complete a privileged access review. Count global and privileged admins, remove stale assignments, and record the review with a date and reviewer. The record is what turns "we review access" from a claim into evidence.
  • Assign a named owner and date to every remaining gap. A gap without an owner does not close. Track owner, action, and target date; anything targeted after the submission date moves to the exception list.
  • Document exceptions honestly. For each gap that will still be open at submission, write down what it is, why, the compensating controls, and the remediation date. This feeds the drift brief and keeps the application accurate.
Days 30 to 0

Package: assemble the submission

The final phase turns verified answers into a submission the broker can present with confidence: evidence mapped per answer, a short drift brief, and a signer who has actually reviewed what they are signing.

  • Assemble evidence per answer. One artifact per application answer, using the table below as the collection list. Evidence that maps to a specific question is worth more than a large unmapped export.
  • Write the drift brief. One or two pages: what changed since last year's application, which answers changed and why, what was remediated, and which exceptions remain open with owners and dates. Underwriters read change; give it to them directly.
  • Review with the signer. The person who signs the application should walk every answer, see its evidence or exception, and understand that the answers are representations the carrier relies on. No answer goes out that the signer has not seen supported.
  • Deliver to the broker with the application. Send the completed application, the evidence package, and the drift brief together, brokers commonly ask for the completed submission two to four weeks before the renewal date. How and when to present it to markets is your broker's call.
Reference

Evidence to collect per control area

The artifacts that support the answers most US carrier applications ask about. Collect these during the package phase, one mapped to each answer.

Evidence artifacts per control area for a cyber insurance renewal submission
Control areaEvidence to collect
Multifactor authenticationConditional access or MFA policy export, enforcement coverage counts, list of excluded accounts with justification
Backup and recoveryImmutability or segregation configuration, backup scope, dated restore test record with outcome
Endpoint detection and responseEDR deployment coverage across endpoints and servers, monitoring arrangement
Privileged accessPrivileged and global admin counts, dated access review record, PIM or just-in-time configuration if used
Email securityCurrent SPF, DKIM, and DMARC records with policy mode, phishing training completion records
Incident responseWritten plan with revision date, dated tabletop or exercise record, log retention settings

If renewal is closer than 90 days

Compress the plan rather than skipping phases, and let coverage consequence set the order. Accuracy outranks completeness: a smaller set of verified answers with honestly documented exceptions is a stronger submission than a fully answered application nobody checked.

  1. Verify the heavyweight answers first. MFA, backups, and EDR carry the largest coverage consequence on most forms. Check those against the live environment before anything else.
  2. Fix only what can land before submission. MFA policy gaps and backup immutability settings can often close in days; a full privileged access review may not. Do not start work that will be half-done at signing.
  3. Move everything else to the exception list. Owner, compensating controls, target date. Give it to your broker so they have the full picture.
  4. Never guess to fill a deadline. An accurate answer with a documented plan is a negotiation; an inaccurate answer is a misstatement risk. Material misstatements have been grounds for rescission attempts, as in Columbia Casualty v. Cottage Health (2015) and Travelers v. International Control Services (2022).

How Insurance Posture Analyzer compresses the 90 days

Most of the 90-day plan is spent building a baseline by hand: pulling last year's answers, checking each one against the environment, and classifying the result. With continuous, read-only scans of Microsoft 365, Entra ID, and Azure, that baseline already exists on day 90. Insurance Posture Analyzer keeps each mapped application answer cross-checked against the live environment and flags drift as it happens, so phase one becomes reading a report instead of running a manual audit.

The package phase compresses the same way: answers carry their evidence as they are attested and verified, gaps are graded by coverage consequence to set the remediation order, and the broker-ready drift brief collects what changed with the evidence files in one place. Scheduled rescans between renewals mean the next cycle starts from what is true today rather than from memory. Connections are read-only throughout; see the security page for the access model.

FAQ

Renewal preparation, answered

When should I start preparing for renewal?

Ninety days before the renewal date. Remediation is the constraint: closing MFA coverage gaps, adding backup immutability, or completing a privileged access review each takes weeks, and brokers typically want the submission package two to four weeks before renewal. Ninety days leaves roughly a month each to baseline, remediate, and package.

What evidence do brokers actually want?

Evidence mapped to specific answers: MFA policy exports and coverage counts, backup immutability settings plus a dated restore test, EDR coverage, privileged account counts with access review records, SPF, DKIM, and DMARC records, and a tested incident response plan. A short drift brief explaining what changed since last year is more useful to underwriting than an undifferentiated document dump.

What if a gap cannot be closed before renewal?

Answer accurately and document the gap as an exception with a named owner, compensating controls, and a target date, then let the broker present it with that context. An accurate answer with a credible plan is a negotiation; an inaccurate one is a representation risk, as the rescission attempts in Columbia Casualty v. Cottage Health (2015) and Travelers v. International Control Services (2022) illustrate. Whether such an attempt succeeds depends on materiality and state law.

What if renewal is less than 90 days away?

Compress, do not skip. Verify the answers with the largest coverage consequence first (MFA, backups, EDR), fix only what can realistically land before submission, and move everything else to a documented exception list. A smaller set of verified answers beats a fully answered application no one checked.

Start your renewal baseline today

Connect a read-only account or upload last year's application. Insurance Posture Analyzer cross-checks every mapped answer against your live environment, so day 90 starts with the baseline already built.

Assess your posture