Skip to main content

The insurance and Cyber Essentials evidence pack

What the six pages of the evidence pack measure, what "attested" and "cannot measure" mean, and how the verify link lets a broker or auditor confirm it without seeing your data.

Written for the business owner7 min readUpdated

Cyber insurers and Cyber Essentials assessors ask the same handful of questions in almost every form: is MFA on for email, remote access and privileged accounts; is every device protected; are backups in place; is there an incident-response plan; is staff trained. The evidence pack answers each one from this platform's own records — a count, the moment it was checked, and a hash — so you have a real answer ready instead of guessing on the day the form arrives.

Where to find it

Compliance > Evidence pack in the console. It is on every plan — generating the pack manually costs nothing and needs no add-on. Choose Download to open a print-ready page you can save as a PDF, or Copy verify link to hand a broker or auditor a link that confirms the pack's hash without giving them access to your console.

The six pages

What each page of the evidence pack measures.
PageWhat it answersBuilt from
Multi-factor authenticationPrivileged accounts and email/cloud accounts with a second factor of any kind. Remote access (VPN/RDP) is answered cannot measure — this platform does not monitor on-premises remote access.Your users, their MFA/passkey enrolment, and who holds access-changing permissions.
Endpoint detection and responseDevices with an active sensor checked in within the last 24 hours, against every device this platform knows about.Sensor check-ins and the endpoint inventory.
BackupsAttested, never measured: whoever runs your backups records who attested it and when it expires.The attestation you record on this page.
Incident-response planAttested, from the plan drafted and attested on the incident response plan page.The IR plan's own attestation, read here, not duplicated.
Security-awareness trainingWhether at least one active account completed a course in the last 12 months, and how many.Academy course completions.
Cyber Essentials: MFA everywhereEvery connected cloud service (SSO/federated identity provider), and whether a tenant-wide rule requiring a second factor covers all of them.Connected identity providers and your sign-on policy rules.

A page whose module is not on your plan reads cannot measure with that reason stated — never a fabricated gap, and never silently hidden.

What the labels mean

Yes
Full coverage, measured just now. A partial result is never rounded up to yes — 2 of 3 accounts covered reads as no, with the real count shown.
No
Measured, and the answer is no (or partial, or nothing is currently attested).
Cannot measure
This platform does not have the data to answer — either the module is not on your plan, or there is nothing to measure against. Always comes with a stated reason.
Attested
A named person vouched for it with an expiry. Backups and the incident-response plan are always attested, never "measured", because this platform cannot directly observe either one.

Attesting backups

  1. Open the Backups panel

    On the evidence pack page, choose Attest backups.

  2. Enter who is attesting, and an expiry

    The expiry cannot be more than about 13 months out — an attestation with no practical end date is not a real check-in.

  3. Add a note if it helps

    For example, which vendor and whether a restore has been tested. Optional, but it is what a reader sees alongside "attested by".

An expired attestation reads no again until someone attests again — it is never shown as valid past the date its own attester gave it.

The verify link

Every time the pack is downloaded — as JSON or as the printable document — it gets a fresh pack ID and hash, printed in the document's footer. Anyone with that pack ID and hash can visit the verify link and get back exactly one thing: whether they match, and if so, when the pack was generated. Nothing else — no organisation name, no counts, no way to guess a valid pack ID from a wrong one.

What to read next

  1. Your incident response plan — the plan this pack's IR page reads its attestation from.
  2. Evidence-bound drafts — the insurer notice and NIS2 early warning drafted from the same kind of records.
  3. Plans and what each includes — which modules unlock which pages of this pack.

Was this article wrong?

If a procedure here does not match what you see, or a limit we described has changed, tell us and we will fix the page. Email us about this article, or see how to get help if you need an answer rather than a correction.

Everything in compliance evidence