Cyber insurance carriers ask around sixty questions on a standard 2026 renewal application, and they take most of the answers on faith. They verify roughly a third — MFA depth, backup restore-test evidence, EDR coverage percentage, and a handful of others where the technical evidence is either already available via API or easy to require at bind. Which questions land in which bucket, and how, is the actual gating logic for the renewal — not what is printed on the questionnaire, not what the broker says at bind, not what the declarations page looks like when the coverage certificate lands in the buyer's inbox.
Every year the verified bucket gets bigger. Ten years ago, cyber underwriting was a self-attestation exercise. Post-Change-Healthcare, post-MOVEit, and post the 2024-2025 supply-chain incident cycle, carriers have moved every question they can from “take on faith” to “verify via evidence.” The 2026 market makes this shift explicit — Marsh reported cyber rates down 5% in Q1 2026, and Aon described conditions as buyer-friendly, but underwriting depth kept increasing. Applications dig deeper into MFA enforcement, endpoint detection, patching cadence, incident response, and backup testing, even as headline pricing softens.
Here is a line-by-line look at what carriers verify vs. what they take on faith on the 2026 questionnaire, the specific evidence they accept as verification, and the four unverified questions where the buyer's answer is the actual leverage point on the renewal premium.
What carriers actually verify — the 2026 list
The verification bucket splits into three technical categories: identity + access controls, backup + recovery capability, and evidence that the security program is running rather than being described. Each category has specific artifacts carriers accept and specific artifacts they do not.
The questionnaire asks “do you have MFA.” The verification is different. Carriers now want MFA enforcement on every privileged account (admin, root, service accounts) proven via IdP configuration export; MFA enforcement on every remote-access path (VPN, SSH bastion, cloud console) proven via CloudTrail or equivalent audit-log excerpts; MFA enforcement on email (M365, Google Workspace) proven via conditional-access-policy screenshot or JSON export. “We have MFA” without those three artifacts scores as partial-credit and stays in the higher-premium band.
The specific evidence acceptable: Okta admin-panel screenshot showing app-level MFA policy plus a 30-day audit-log slice showing zero MFA bypasses; Azure Conditional Access policy JSON export; or the equivalent from any modern identity provider. What is not acceptable: a written attestation from IT that MFA is enabled.
Post-Change-Healthcare, carriers expanded this category dramatically. The questionnaire asks “do you have backups.” The verification: date of last restore test; scope of what was restored (production database vs. a test file); time-to-restore evidence; and independence of backup storage from production authentication (air-gap or object-lock proof). Air-gap is the specific evidence buyers should position around — carriers accept immutable-object-lock configuration exports from S3, Azure Blob, or Wasabi as evidence. They do not accept “we have snapshots” as evidence.
The buyer who ships a restore-test log with a time-to-restore figure and an air-gap configuration export lands in a preferred pricing band. The buyer who ships an attestation lands in the standard band. Same policy, different premium — with the delta driven by the immutability evidence, not the backup fact.
The 2020 version of this question was “do you have endpoint protection.” The 2026 version is “show us coverage.” Coverage means: the percentage of production endpoints running the EDR agent (target: 100%; below 95% penalized), the percentage running current signature or policy versions (target: 100%; below 90% penalized), and the mean time to remediation on flagged events over the last 90 days (target: under 4 hours; over 24 hours penalized).
Carriers now pull this from carrier-integration APIs where the buyer's provider supports it — CrowdStrike, SentinelOne, and Microsoft Defender all have carrier-integration paths where the buyer authorizes a read-only coverage export. Coalition in particular has built continuous underwriting around this pattern; not authorizing the integration when the carrier asks is itself a signal to the underwriter. Buyers who decline typically move to a higher-premium band unless they have a specific reason to withhold.
What carriers still take on faith — and why the “faith” column is the buyer's leverage
Roughly forty questions on the 2026 questionnaire are still self-attested. Employee security training completion. Vendor risk management program maturity. Incident response plan existence. Data classification schema. Encryption at rest. Encryption in transit. Password policy specifics. Written information security policy version. Vulnerability management program cadence. The list runs long.
The buyer's temptation is to blur the line — write “yes” on every question and move on. That is the wrong play. The right play is to notice that the “take on faith” answers are where carriers give the biggest premium concessions when a buyer ships evidence anyway. If you write “yes, we have a written IR plan” and attach the plan, that is a concession. If you write “yes, we have tested our IR plan” and attach the tabletop report with dates, participants, and lessons-learned, that is a bigger concession.
Tested IR plan. Carriers ask “do you have one.” They accept “yes.” Shipping a tabletop report typically moves premium 3–7% at renewal.
Vendor risk program with named risk owner. Carriers ask “do you have one.” They accept “yes.” A subprocessor register with per-vendor risk tier and named owner typically moves premium 2–5%.
AI-usage governance. New in 2026 questionnaires. Carriers ask “how do you govern AI system usage.” They accept vague answers. Shipping an AI acceptable-use policy, an AI vendor register, and evidence of AI Act Article 12 logging alignment (if applicable) typically moves premium 3–8% — the biggest concession available on any new-in-2026 question.
Data classification with retention. Carriers ask “do you classify data.” They accept “yes.” A classification schema with retention timelines and evidence of active enforcement (data-lifecycle deletion logs) typically moves premium 2–4%.
Total impact if you ship all four: 10–24% on renewal, stacked on top of the 18–22% MFA-depth impact and the compound 50–60% five-controls band. That is the leverage the questionnaire itself does not tell you exists.
What is moving to verified in 2027
Three questions that are still faith-based in 2026 are already tracking toward verification in 2027, and buyers who structure their renewal packet to ship evidence in these categories now land in a favored pricing bracket next year. This is the compounding play — every renewal cycle rewards buyers who anticipate the next verification move.
AI-vendor inventory with model provenance. The AI Act Article 12 record-keeping infrastructure currently optional will be required for buyers deploying AI in high-risk categories. Carriers exposed to AI-adjacent claims want visibility into which models handle which data. Buyers who ship a versioned AI vendor register now build the audit trail carriers will ask for at 2027 renewal.
Subprocessor incident notification within 24 hours. Carriers have started asking about this as a “do you have this in your MSAs” question in 2026. By 2027 they will want the MSA text. Buyers who write the 24-hour clause into their standard subprocessor MSAs now save themselves a re-negotiation cycle later.
Chain-of-custody evidence for compliance artifacts. Carriers exposed to Change-Healthcare-adjacent losses want to see that compliance evidence is what buyers say it is, not what someone screenshotted six months ago. Signed evidence bundles — cryptographic hash per artifact, timestamped, verifiable — are already showing up as preference criteria on 2026 policies. By 2027 they are likely to be verified.
- Ship the 20 verified answers at bind, with the specific artifacts carriers accept.: MFA depth via IdP export. Backup restore-test log with air-gap evidence. EDR coverage via carrier-API integration where supported. Do not attest without evidence when evidence exists — it changes the pricing band.
- Ship the 4 high-leverage faith answers as evidence.: Tested IR plan, vendor register with risk owner, AI governance, data classification with retention. 10–24% premium impact on the same policy without touching any of the 20 verified answers.
- Structure the packet as a signed evidence bundle.: Cryptographic hash per artifact proves nothing was modified since bind. Carriers exposed to Change-Healthcare-adjacent claims give preference to signed evidence over screenshotted evidence.
- Position 2027-verified questions now.: AI-vendor inventory with model provenance, subprocessor incident-notification clauses in MSAs, chain-of-custody for compliance artifacts. Not required in 2026. Rewarded in 2026. Verified in 2027.
How the top three MGA carriers verify differently
Coalition, Cowbell, and At-Bay each ship a different underwriting model, and buyers who understand which carrier reads which control differently get better outcomes on the same underlying evidence. This is the market intelligence a great broker delivers verbally at bind. The written version is short.
Coalition built continuous underwriting around external attack-surface data — internet-facing asset inventory, DNS posture, certificate hygiene, and public exposure of authentication endpoints. The buyer who ships a clean external attack-surface report — no exposed RDP, no expired certificates, no leaked credentials in public dumps — lands in Coalition's preferred pricing band regardless of what the internal questionnaire looks like. Coalition also gives the largest premium concessions to buyers who authorize the carrier-API integration for their EDR (CrowdStrike, SentinelOne, Defender), because their model consumes that data operationally, not just at bind.
Cowbell is purpose-built for the small-and-mid-market segment on Zurich-backed paper. Their model runs continuous underwriting throughout the policy period — not just at bind and renewal — which means posture changes during the policy year affect renewal outcome, not just what the buyer ships at renewal application. Buyers who ship a stable evidence pipeline that Cowbell can read on a rolling basis land better than buyers who scramble to assemble a packet the week before renewal. Cowbell's SMB focus also means their MFA and backup verification thresholds are less punishing than Coalition's for very small buyers who don't yet have enterprise-grade tooling.
At-Bay leans hardest into bundled managed detection and response on Munich Re-backed paper. Their underwriting effectively assumes the buyer will consume At-Bay's MDR service as part of the policy, and prices accordingly. Buyers who ship strong evidence on identity + backup but light evidence on EDR get better outcomes at At-Bay than they would at Coalition, because At-Bay's MDR fills the EDR gap. Buyers who already have mature EDR see less differential because At-Bay's MDR bundling is a smaller lift.
The broker who steers the submission across all three based on the buyer's actual evidence position produces a materially different renewal than the broker who submits to whichever carrier the buyer was with last year. That is the value add the buyer should demand.
The broker's role — and where the broker will not help
A good broker pulls last year's questionnaire alongside this year's, marks the deltas, and tells the buyer which questions moved. A great broker names which carrier verifies which control differently and steers the submission accordingly — Coalition's continuous-underwriting model reads differently than At-Bay's bundled-MDR model, which reads differently than Cowbell's SMB-adaptive model. What the broker will not do — because it is not what brokers are paid to do — is prepare the buyer's evidence packet. That work sits with the security team, or with a fractional partner who does this work every renewal cycle across a portfolio of buyers.
The buyer who prepares the packet and hands it to the broker at bind lands a better premium than the buyer who lets the broker's submission speak for itself. That is the honest read of the 2026 market. It is not going to change in 2027.
The bottom line
The buyer's leverage in the 2026 market is not on the questions carriers already verify — those you either pass or you don't, and the premium band is set. The leverage is on the questions carriers still take on faith. A tested IR plan with dated tabletop artifacts. A vendor risk program with a named risk owner per vendor. An AI-usage governance policy with a sub-processor register. A data classification schema with retention timelines and evidence of enforcement. Each of those, unprompted, moves premium 2-8% at renewal today. Together they compound. The buyer who prepares the evidence packet and hands it to the broker at bind lands a materially different renewal than the buyer who lets the submission speak for itself. That is the honest read of the market, and it is not going to change in 2027.
Put the playbook to work
vCISO Lite ships the evidence pipeline that populates the packet — continuous MFA-coverage tracking, backup restore-test logging, EDR-coverage exports, tested-IR-plan artifacts, and the cryptographic hash-per-artifact structure carriers now prefer. The five controls that most move premiums map directly onto the platform's evidence surfaces, and the underwriter scoring model maps onto what the evidence needs to look like at bind. See how the evidence packet gets assembled at vcisolite.com.