Insurance Questionnaire Mapping

What Cyber Insurance Auditors Check
And How ComplianceLayer Helps You Prepare

See which insurance questionnaire items our scan covers, with supporting documentation you can bring to your application.

Question-by-question mapping

Insurance Questions Mapped to Scan Modules

Insurance QuestionWhat They Want to SeeComplianceLayer ModuleWhat the Scan Shows
Do you enforce DMARC on your email domain?DMARC record with p=reject or p=quarantineDNS & Email AuthDMARC policy status, SPF alignment, DKIM validation
Are any remote access ports (RDP, SSH) exposed to the internet?No exposed RDP (3389), SSH (22), Telnet (23)Open PortsFull port scan results, exposed service identification
Is your SSL/TLS certificate valid and current?Valid cert, strong cipher suites, no expired certsSSL/TLSCertificate validity, expiry date, protocol versions, cipher analysis
Do you have security headers configured?HSTS, CSP, X-Frame-Options, etc.HTTP HeadersHeader-by-header analysis with pass/fail
Is your domain on any blacklists or reputation lists?Clean reputation across major blacklistsBlacklist CheckResults from 14 blacklist databases
Do you have a Web Application Firewall?WAF detected and activeWAF DetectionWAF vendor identification, configuration status
Are there known vulnerabilities in your web stack?No known vulnerable librariesJavaScript AuditVulnerable library detection, version analysis
Is DNSSEC enabled for your domain?Signed DNS zoneDNSSECDNSSEC chain validation status
Do your cookies use secure flags?HttpOnly, Secure, SameSite attributesCookie SecurityCookie-by-cookie security flag analysis
Are you compliant with GDPR/CCPA data handling?Cookie consent, privacy controlsCompliance & Tracker AnalysisThird-party tracker identification and consent banner detection — a partial external signal only; GDPR/CCPA compliance cannot be determined by an external scan

Disclaimer: ComplianceLayer assesses externally observable technical controls. Scan results are informational and do not constitute a compliance certification, audit opinion, or guarantee of insurability or insurance outcomes. Full compliance requires organizational controls, policies, and formal audits, and acceptance of any report is at the discretion of your auditor, assessor, or insurer.

How to use this

MSP Playbook for Insurance Renewals

Scan your clients before their insurance renewal. Fix the kinds of issues underwriters commonly flag. Bring the documentation to the application.

Step 01

Scan the client domain before renewal

Enter the domain into ComplianceLayer. The scan runs all 15 scan modules typically in under a minute -- no credentials, no agent install, no client involvement required.

Step 02

Review findings against the questionnaire

Use the mapping table above to match scan results to specific insurance questions. Every finding includes a pass/warn/fail status and the technical details underwriters commonly ask about.

Step 03

Remediate flagged issues

Each failing check includes step-by-step remediation guidance. Fix DMARC, close exposed ports, add missing headers -- most fixes take minutes, not days.

Step 04

Re-scan and attach the report

Run a follow-up scan to confirm fixes. Export the PDF report and attach it to the insurance application as supporting documentation of the domain's external security posture.

Start scanning your clients

Free for your first domain. No credit card, no sales call, no agent install. See your external posture the way an outside reviewer would, typically in under a minute.

Related: What cyber insurers scan on your domain

Get started

Start scanning your first
domain in 60 seconds.

No credit card. No sales call. No setup. The free tier is here to stay.

10 free scans per monthAPI key in 30 secondsCancel anytime

All scans are external and non-exploitative — we never access your servers, install agents, or require credentials. View our security practices, or live system status.