Insurance Questionnaire Mapping

What Cyber Insurance Auditors Check
And How ComplianceLayer Proves It

See exactly which insurance questionnaire items our scan covers, with evidence you can attach to your application.

Question-by-question mapping

Insurance Questions Mapped to Scan Modules

Insurance QuestionWhat They Want to SeeComplianceLayer ModuleEvidence Provided
Do you enforce DMARC on your email domain?DMARC record with p=reject or p=quarantineDNS & Email AuthDMARC policy status, SPF alignment, DKIM validation
Are any remote access ports (RDP, SSH) exposed to the internet?No exposed RDP (3389), SSH (22), Telnet (23)Open PortsFull port scan results, exposed service identification
Is your SSL/TLS certificate valid and current?Valid cert, strong cipher suites, no expired certsSSL/TLSCertificate validity, expiry date, protocol versions, cipher analysis
Do you have security headers configured?HSTS, CSP, X-Frame-Options, etc.HTTP HeadersHeader-by-header analysis with pass/fail
Is your domain on any blacklists or reputation lists?Clean reputation across major blacklistsBlacklist CheckResults from 35+ blacklist databases
Do you have a Web Application Firewall?WAF detected and activeWAF DetectionWAF vendor identification, configuration status
Are there known vulnerabilities in your web stack?No known vulnerable librariesJavaScript AuditVulnerable library detection, version analysis
Is DNSSEC enabled for your domain?Signed DNS zoneDNSSECDNSSEC chain validation status
Do your cookies use secure flags?HttpOnly, Secure, SameSite attributesCookie SecurityCookie-by-cookie security flag analysis
Are you compliant with GDPR/CCPA data handling?Cookie consent, privacy controlsCompliance & Tracker AnalysisThird-party tracker identification, consent detection
How to use this

MSP Playbook for Insurance Renewals

Scan your clients before their insurance renewal. Fix what the underwriter would flag. Attach the evidence to the application.

Step 01

Scan the client domain before renewal

Enter the domain into ComplianceLayer. The scan runs all 16 modules in under 60 seconds -- no credentials, no agent install, no client involvement required.

Step 02

Review findings against the questionnaire

Use the mapping table above to match scan results to specific insurance questions. Every finding includes a pass/warn/fail status and the evidence the underwriter expects.

Step 03

Remediate flagged issues

Each failing check includes step-by-step remediation guidance. Fix DMARC, close exposed ports, add missing headers -- most fixes take minutes, not days.

Step 04

Re-scan and attach the report

Run a follow-up scan to confirm fixes. Export the PDF report and attach it to the insurance application as evidence of compliance.

Start scanning your clients

Free for your first domain. No credit card, no sales call, no agent install. See what the underwriter sees in under 60 seconds.

Related: What cyber insurers scan on your domain

Get started

Start scanning your first
domain in 60 seconds.

No credit card. No sales call. No setup. Free tier is permanent.

10 free scans per month, foreverAPI key in 30 secondsCancel anytime

All scans are passive and external — we never access your servers, install agents, or require credentials. View our security practices, live system status, or browse domain reports.