Cyber Insurance Renewal Checklist: A 90-Day Countdown

For owners, CFOs, and office managers whose policy renews soon. Sequenced by week, not by topic.

By , CTO · Published · Last updated

TL;DR

  • Day 90: pull last year's questionnaire, inventory the security stack, list known gaps, and book the prep session with your IT vendor or MSP.
  • Day 60: close the gaps that can be closed in two months. Run a phishing simulation, schedule a tabletop, gather training records.
  • Day 30: assemble the evidence packet (Conditional Access exports, sign-in logs, IR plan PDF, backup test results, MSP attestation).
  • Day 14: mock-fill last year's questionnaire as if you were submitting today. Every "I'm not sure" goes on a verify list.
  • Day 7 to renewal day: verify the high-risk answers in the actual systems, then submit with the evidence packet attached.

Most renewals go sideways for one reason: the questionnaire arrives, somebody panics, and the answers get pieced together from memory in the last 72 hours. Premiums go up. A control gets misrepresented. A claim later gets disputed because the carrier's underwriting file says one thing and your environment says another.

It doesn't have to work that way. Renewal questionnaires are mostly predictable. Carriers reuse 80 percent or more of last year's questions, and the new ones tend to follow industry trend lines you can read in advance from your broker. The whole exercise is a 90-day project. Treat it that way and the answers are ready before the questionnaire arrives.

This is the countdown. Five checkpoints, each with a specific deliverable. By renewal day, you submit a clean packet, defend a lower premium with evidence, and keep your in-flight remediation honest. If you also need the verification list of which controls insurers are checking for, that's the cyber insurance compliance checklist. Read it once before you start the timeline below.

Day 90: Inventory and gap analysis

Three months out is when the prep session happens. Block 90 minutes on the calendar with whoever runs IT for you, internal or MSP. Bring last year's binder. The agenda has four items.

Pull last year's questionnaire. Most carriers send a similar form year over year. The 2026 version will have a few new questions about phishing-resistant MFA on admin accounts, log retention windows, and tabletop exercise frequency, but the bulk is unchanged. Read every answer you submitted last year. Two columns next to each: still true, or no longer true. The "no longer true" column is your remediation list.

Map the new questions. Ask your broker what trends they're seeing in 2026 questionnaires. Common additions this year: phishing-resistant authentication on privileged users, written evidence of a recent tabletop, sign-in log retention of 12 months or longer, and documentation of email-security thresholds beyond Microsoft defaults. If your broker can share a blank questionnaire from a sister carrier, even better.

List the security stack. Every product, every license tier, every version. Microsoft 365 Business Premium versus Business Standard matters; so does whether Defender for Office 365 is Plan 1 or Plan 2. EDR vendor, endpoint count, console URL. Backup product, what it covers, and the last verified restore date. If you can't list it, the carrier won't believe you have it.

Identify the gaps. What did you tell the carrier last year that you'd close, and what's the status? Be honest in this room. The questionnaire will ask the same question, and a documented "in progress with completion target of X" answer beats a fudged "yes" that falls apart in a claim review.

Day 60: Remediation

Two months out, you start fixing. The list from day 90 turns into work tickets with owners and deadlines. Most controls that take 60 days or less to deploy: enabling Conditional Access policies, turning on phishing-resistant MFA for admins, configuring backup retention, raising Defender thresholds, deploying email authentication records (SPF, DKIM, DMARC). Anything bigger (a full SIEM rollout, a zero-trust segmentation project) won't make it before renewal, and the answer becomes "in progress with target date."

Three things specifically belong in this 30-day window because they need lead time and they always show up on the questionnaire:

  • Phishing simulation. If the last campaign was more than six months ago, run a fresh one. Carriers ask for the click rate and the remediation training rate. Pick a tool, run a campaign, capture the results.
  • Tabletop exercise. If a tabletop hasn't happened in 12 months, schedule one for the next four weeks. A two-hour walkthrough of a ransomware scenario with the leadership team and the MSP counts. Document the date, attendees, and findings.
  • Training completion records. Pull the security-awareness training reports for the last 12 months. Aim for 95 percent or higher completion. Anyone below that gets a follow-up campaign before day 30.

For the M365-specific controls that should be in place by now (MFA enforcement, legacy authentication blocking, mailbox forwarding rule restrictions, audit logging), work the technical fixes into the day 60 sprint. The deployment-side reference is on SecureYourTenant: the M365 security checklist for 2026. That's the IT vendor's task list. Your job is to confirm each line item is closed.

Document everything you fix during this month with a date stamp. A screenshot of a Conditional Access policy in "On" state, dated, with your tenant name visible, is worth more in underwriting than any verbal assurance. If your MSP did the work, ask for a one-page attestation letter naming what they configured and when.

Day 30: The documentation pass

One month out, the packet starts taking shape. This is where most renewals fall behind, because nobody owns the assembly. Pick one person to own it. The packet is one PDF (or a folder if your broker prefers) containing the evidence for every control the questionnaire will ask about.

At minimum it includes:

  • Conditional Access policy export. A list of every CA policy with state (on, off, report-only), users, conditions, and grant. Native export from Entra works fine.
  • Sign-in log summary. Last 30 days. MFA coverage rate by user. Any sign-ins that bypassed MFA, with explanation.
  • Training completion report. 12-month rollup, percentage complete by department, phishing simulation results.
  • Incident response plan PDF. Current version. Cover page with revision date and approver. Contact list updated.
  • Backup test results. Most recent restore date, what was restored, RTO and RPO measured.
  • MSP attestation, if applicable. Letter from your MSP listing managed services, in-scope systems, and last security review date.
  • Email authentication record screenshots. SPF, DKIM, and DMARC records for every active domain.

Then reconcile every claim from last year's questionnaire. For each "yes" answer you submitted, find the artifact in the packet that proves it. Two outcomes. Either the artifact exists and goes in, or you discover a control you reported as "yes" can't actually be evidenced. That second case is the one to catch now, not at day 7.

Update the IR plan if anything has changed since last year: new SaaS apps, new locations, leadership turnover, MSP changes. The plan should name a primary incident commander, a deputy, the legal contact, the cyber insurance carrier's claim hotline, the forensics firm on retainer (if any), and the PR contact. If your IR plan was last reviewed 14 months ago and the answer to "reviewed in last 12 months" is supposed to be yes, the review meeting happens this week.

Day 14: Mock-fill the questionnaire

Two weeks out, sit down with last year's questionnaire and answer it as if it's today. Don't submit it. The point is to flush out every "I'm not sure" before the real one arrives. Anything that gets a question mark or a maybe goes on a verify list for the next seven days.

Common gotchas the mock-fill catches:

  • "We have MFA" versus "MFA is enforced for all users." Two different questions. The first is true if MFA is configured. The second is only true if Conditional Access blocks sign-in without it. Most owners say yes to the second when they should say yes to the first only.
  • "We back up our data" versus "We have tested restoration." A backup that has never been restored is unverified. The carrier wants the test date and the RTO measured during it.
  • "We have an incident response plan" versus "Our IR plan has been reviewed in the last 12 months." Pull the document. Check the revision date. If it's older than a year, the review is overdue and the answer is no until you fix it.
  • "We do security awareness training" versus "We have evidence of 95% completion in the last 12 months." The completion rate is the question. Make sure the report supports the number you're about to write down.

Have your IT lead or MSP review the mock answers. They'll catch the questions where the answer in your head doesn't match the configuration in the tenant. Better to discover that disagreement now, with a week to fix it, than during a claim review.

The renewal questionnaire is also where insurers check whether MFA is real. The full breakdown of what they look for, and what counts: how to answer the MFA section of a 2026 questionnaire.

Save the mock-fill. You'll reuse most of it word-for-word when the real form arrives, and the verify list becomes the day 7 checklist.

Day 7: Final verification in the actual systems

One week out, walk every high-risk answer back to the source. Don't trust the documentation alone. The packet was built from policy exports and screenshots, but configurations drift between the export and the submission, and a control somebody disabled "for one ticket" two weeks ago is exactly the kind of thing that surfaces in a claim review.

The high-risk verifications, in order:

  • MFA coverage. Pull a sign-in log report for the last 30 days. Filter to interactive sign-ins. Confirm 100 percent of those used MFA, with no exceptions other than approved break-glass accounts.
  • Conditional Access state. Every policy that's supposed to be on should be on, not in report-only mode. Check the state column for each. Anything in "report-only" that should be enforced becomes a same-day fix.
  • Backup verification. When was the last successful test restore? If the answer is older than 90 days, run one this week. Document the RTO measured.
  • IR plan currency. Open the PDF. Are the contact numbers still good? Has the carrier hotline changed? Is the cyber liability policy number on the cover sheet correct? Update before submission.
  • Phishing-resistant MFA on admins. Carriers in 2026 are specifically asking whether privileged accounts use FIDO2, certificate-based auth, or Windows Hello, not SMS. Check the Entra authentication methods report for global admin accounts.
  • Email authentication records. SPF, DKIM, and DMARC for every active sending domain. Run a quick lookup on each. A misconfigured DMARC record is a common questionnaire gotcha.

If a verification fails, the answer changes from "yes" to "in progress, target date X." Don't fudge it. Carriers sometimes spot-check, and even when they don't, a misrepresentation discovered during a claim is the fastest way to a coverage dispute.

Renewal day: Submission

Submit early in the day. Attach the evidence packet from day 30 (refreshed with anything updated during day 7 verification). Answer only the questions asked. Owners often volunteer information that isn't requested, thinking it shows transparency; in practice it gives the underwriter more surface area to scope concerns about.

Three submission rules that pay off:

  • Be honest about in-flight work. A "yes, target completion June 30" answer is fine and often expected. A "yes" that turns out to be a "not yet" damages the relationship and can void coverage on a claim tied to that control.
  • Cite the artifact. Where the questionnaire allows commentary, point to the exhibit number or the file name. "Conditional Access export, Exhibit B, page 3" beats a freehand description every time.
  • Save everything. Save your final answers, the evidence packet, and the carrier's confirmation email in one folder named with the renewal year. Next year, half of next year's prep work is already done.

After submission, expect one or two clarifying questions from the underwriter. They usually arrive within 5 business days. Answer them with the same packet-and-cite discipline. Most renewals close cleanly when the questionnaire prep is this thorough.

The seven things that move premiums in 2026 renewals

If the goal is a flat or lower renewal (and after three years of double-digit hikes, most owners want exactly that), these are the levers that actually move the needle this year. Brokers we've talked to confirm the same shortlist:

  1. Phishing-resistant MFA on administrative accounts. SMS MFA on a global admin is a 2024-era control. FIDO2 keys, certificate-based auth, or Windows Hello on every privileged account is the 2026 baseline.
  2. Documented incident response plan with named roles. Not a template. A plan that names individuals, has a revision date inside the last 12 months, and lists external contacts (carrier, forensics, legal).
  3. Tested backup with measured RTO and RPO. A backup that has been restored, with the recovery time written down. The number on paper is what the carrier underwrites.
  4. Email security beyond default. Defender for Office 365 active, custom anti-phishing thresholds, and email authentication records (SPF, DKIM, DMARC) configured on every sending domain. The full task list is on EmailShield: Microsoft 365 email security checklist.
  5. Twelve-month log retention. Sign-in logs and audit logs retained for at least 12 months. The default M365 retention varies by license; many small tenants need a Purview add-on or a SIEM ingestion path to hit this number.
  6. Conditional Access posture exported and reviewed. Not just "we have CA." A documented review of every policy, what it does, and a confirmation that nothing critical is in report-only mode by accident.
  7. Tabletop exercise within the last 12 months. A documented one. Two hours of leadership walking through a ransomware or BEC scenario with the MSP and the IR plan open. Notes captured. Findings turned into work tickets.

These seven aren't a wish list. They're what underwriters score most heavily this cycle. A clean answer on all seven is the difference between a flat renewal and a 15 to 30 percent hike. If you've already had a breach in the policy term, the playbook for hardening before renewal is on BreachShield: data breach response checklist (25 steps). The post-incident hardening sections are the ones to bring into your renewal packet.

If you're 30 days out and haven't started

It happens. The renewal calendar slipped, a key person left, the questionnaire arrived three weeks earlier than expected. Compressed timeline, three weeks to submission. Here's what's still possible.

Week 1 (days 30 to 23): triage and packet. Skip the gap analysis as a separate step. Open last year's questionnaire and your tenant simultaneously, and walk through every question once. For each, pick one of three labels: still true, no longer true and fixable in a week, or no longer true and won't be fixed in time. Build the evidence packet for the still-true items. The fixable items become the next week's work list.

Week 2 (days 22 to 15): emergency remediation. Fix the fixable. Conditional Access policies, MFA enforcement, mailbox forwarding rules, audit logging defaults are configuration changes, not projects. A focused week with the MSP can close 5 to 8 line items. Document each fix with a screenshot the same day you complete it.

Week 3 (days 14 to 7): mock-fill and verify. Same as the standard timeline, compressed. Mock-fill on day 14, verify in the systems on day 10, fix any last-minute discoveries by day 8.

Submission (day 7 to 0): ship it. Submit honestly. The "in progress" items get explicit target dates. The packet covers what's actually in place. A 30-day compressed renewal is harder than a 90-day one, but a clean honest answer on a tight timeline still beats a fudged answer on any timeline.

One thing not to do under time pressure: don't pick a different carrier in the last two weeks just because the renewal got tight. Carrier shopping is a day 60 activity, not a day 14 one. New carriers re-underwrite from scratch, and a rushed application to an unfamiliar carrier is how coverage gaps creep in.

Common questions

How early should I start if my policy is bigger than $5M in coverage?

120 days, not 90. Larger limits mean a longer underwriting cycle, sometimes a separate technical questionnaire from a third-party assessor, and occasionally a phone interview with a security engineer at the carrier. Build in a month of buffer at the front. The deliverables at each checkpoint are the same; you just shift the calendar left.

My broker says they'll handle the questionnaire — do I still need this prep?

Yes. The broker submits, but the answers come from you. A broker can format and route the document, recommend phrasings, and push back when a carrier asks for something unreasonable. They can't tell you whether your tenant has Conditional Access enforced or whether your last backup test was 30 or 300 days ago. Treat the broker as a routing layer, not as the source of truth.

What if a control on the questionnaire isn't deployed and won't be by renewal day?

Mark it as "in progress" with a target completion date. Most carriers accept this for 1 to 3 line items, especially when paired with a deployment plan attached as an exhibit. What they won't accept is a "yes" that turns out to be a "not yet" during a claim review. The premium impact of a documented in-progress item is usually small. The impact of misrepresentation is denied coverage. The math is one-sided.

Should I share the evidence packet with the broker before they submit?

Yes. Brokers will often spot inconsistencies between the answer text and the exhibits, or know that a particular carrier wants a specific exhibit format. A 20-minute review before submission catches the kind of mistake nobody wants to discover after the fact.

My MSP runs all this — how much of the prep do they do versus me?

The MSP produces the technical evidence (CA exports, sign-in reports, backup test results, configuration screenshots) and writes the attestation letter. You own the business-side answers (claims history, business changes, training completion, IR plan ownership), the questionnaire submission, and the broker relationship. The split usually breaks 60/40 by hours (MSP handles 60, you handle 40), but the accountability stays on your side. For the trade-off picture, the comparison post is on InsurableIT: cyber insurance implementation case study.

Get the free Insurance Readiness Checklist

No spam. Unsubscribe anytime.

Start With a Free Tenant Assessment

A clean renewal packet starts with knowing what's actually deployed in your tenant. The free risk check documents your current M365 controls and produces a report you can drop straight into the day 30 evidence packet. No guesswork, no fudged answers.