Evidence library
Proof, not checkboxes.
Collect the evidence once and reuse it everywhere. Every framework, questionnaire and renewal asks for versions of the same twenty things — Sentinel keeps them in one library, each item with an owner, a status and an expiry date, so a lapsed penetration test is flagged there before an auditor finds it.
Self-service signup opens shortly — we will set you up in the meantime
Evidence status
26 controls- Accepted41
- Needs Review2
- Pending1
- Expired1
- Missing1
Register
Expiring first| Evidence | Control | Owner | Status | Validity |
|---|---|---|---|---|
| Backup restore test report — Q3 2026 | A.8.13 | Jordan Blake | Missing | Due 30 Sep 2026 |
| Penetration test report — external (2025) | A.8.8 | Priya Raman | Expired | Expired 20 Jul 2026 |
| Privileged account inventory | A.8.2 | Priya Raman | Needs Review | Uploaded 4 Sep 2026 |
| Statement of Applicability — draft v3 | C.6 | Elena Kowalski | Pending | Due 31 Aug 2026 |
| MFA enforcement — Microsoft 365 Conditional Access | A.8.5 | Priya Raman | Accepted | Valid to 14 Aug 2027 |
| EDR coverage report — 98% of endpoints | A.8.7 | Jordan Blake | Accepted | Valid to 28 Nov 2026 |
- Backup restore test report — Q3 2026
- Control
- A.8.13
- Owner
- Jordan Blake
- Status
- Missing
- Validity
- Due 30 Sep 2026
- Penetration test report — external (2025)
- Control
- A.8.8
- Owner
- Priya Raman
- Status
- Expired
- Validity
- Expired 20 Jul 2026
- Privileged account inventory
- Control
- A.8.2
- Owner
- Priya Raman
- Status
- Needs Review
- Validity
- Uploaded 4 Sep 2026
- + 3 more in the workspace
The evidence register, expiring first. Figures are from the example workspace used across this site — Northstar Manufacturing Ltd. is fictional.
A control without evidence is only a claim.
An auditor, an underwriter and a customer's security team are all asking the same thing in different words: show me that this operated, and show me when. A folder of documents cannot answer that on demand, however complete it is.
The problem
Nobody loses their evidence. They lose track of whether it is still true.
The proof almost always exists somewhere. What has gone is the record of what it was for, who owned it, and when it stopped counting. That is not a filing problem — it is what makes a security review take three weeks instead of three days.
Four things every reader has personally seen
- 01
A folder called “Audit 2024”
Three levels into somebody else’s drive. They left in March, and the drive went with their licence. The contents were fine. Nobody can reach them.
- 02
The same PDF, five times
Attached to an ISO request, a SOC 2 request and three customer questionnaires. The policy has since been revised, and four of the five copies are the old one.
- 03
A penetration test from 2023
Still being sent to prospects. Nobody looked at the date on the cover page, including the people sending it.
- 04
A screenshot you cannot reproduce
MFA was enforced the day the screenshot was taken. The exception list has grown since. The screenshot has not.
Status
Seven words, used the same way every time.
A status is only useful if everybody in the building reads it identically. These seven are the ones Sentinel uses — on the item, on the control register, in the gap list and in the reporting. Not a maturity ladder, and not a score. Seven words.
| Status | What it means | What it is worth when somebody asks |
|---|---|---|
| Accepted | A named reviewer agreed this item evidences this control, and the date they agreed is on the record. | Full. This is the only state that means somebody with authority looked. |
| Approved | The same decision recorded on the document itself — a policy signed off by whoever is allowed to sign it. | Full, for the document. The control still needs proof that it operated. |
| Under Review | The item exists and is with a reviewer. Nobody has agreed yet that it does the job. | Nothing yet. It is work in progress, and it is visible as work in progress. |
| Pending | Requested and expected, not yet supplied. The control already knows what it is waiting for. | Nothing yet. But the gap has a name and an owner rather than being an empty cell. |
| Draft | Written and not approved. The annual review was started and never signed. | Nothing. A draft policy is a draft policy however good the drafting is. |
| Expired | Past its expiry date. Somebody had this, and it lapsed. | Nothing — and it is the more embarrassing kind of nothing, because it used to be there. |
| Missing | The control needs proof and there is none on file. | Nothing. It sits on the register as a named item with an owner, not as a blank. |
The mix, in the example workspace
26 controls, 26 expected items.
- Accepted41
- Needs Review2
- Pending1
- Expired1
- Missing1
1 expired and 1 missing — 2 of 26. A quarter of the library would fail on the day somebody asked, and the point of the bar is that you can see which quarter.
Missing and Expired are not shaded politely
An expired policy and a missing policy are worth the same to the person asking: nothing. A tool that renders Expired in a gentler colour is being kind about the one that is more embarrassing, because somebody had it and let it go.
Expiry
A date on every item is the whole difference between a folder and a system.
A shared drive holds the same files. What it cannot do is know that the restore test is due on 30 September, which control rests on it, and that it is flagged in the library once it lapses, not found during fieldwork.
- Every item carries an expiry — a validity date, not a filename with a year in it
- Sorted by what fails first — the register opens on the items closest to their date
- Renewal is dated work — an action with an owner, not a reminder in one person’s calendar
- The superseded item is kept — so the period it covered is still on the record
Register — expiring first
Example data| Evidence | Control | Owner | Status | Validity |
|---|---|---|---|---|
| Backup restore test report — Q3 2026 | A.8.13 | Jordan Blake | Missing | Due 30 Sep 2026 |
| Penetration test report — external (2025) | A.8.8 | Priya Raman | Expired | Expired 20 Jul 2026 |
| Privileged account inventory | A.8.2 | Priya Raman | Needs Review | Uploaded 4 Sep 2026 |
| Statement of Applicability — draft v3 | C.6 | Elena Kowalski | Pending | Due 31 Aug 2026 |
| MFA enforcement — Microsoft 365 Conditional Access | A.8.5 | Priya Raman | Accepted | Valid to 14 Aug 2027 |
| EDR coverage report — 98% of endpoints | A.8.7 | Jordan Blake | Accepted | Valid to 28 Nov 2026 |
- Backup restore test report — Q3 2026
- Control
- A.8.13
- Owner
- Jordan Blake
- Status
- Missing
- Validity
- Due 30 Sep 2026
- Penetration test report — external (2025)
- Control
- A.8.8
- Owner
- Priya Raman
- Status
- Expired
- Validity
- Expired 20 Jul 2026
- Privileged account inventory
- Control
- A.8.2
- Owner
- Priya Raman
- Status
- Needs Review
- Validity
- Uploaded 4 Sep 2026
- + 3 more in the workspace
One requirement, traced
Follow one line all the way through.
A spreadsheet can hold every one of these rows. What it cannot do is know that the A.8.13 backup evidence expired in February, that the evidence library flags it, and that somebody needs to run a restore test before the renewal.
Six records, one link each. Break any link and you are back to a claim.
CyberWave diagram · one requirement, traced
- RequirementISO/IEC 27001:2022 · A.8.13Information backup
- ControlBackups immutable and offlineOperating
- OwnerM. DelacroixAccountable
- EvidenceBackup restore test — Q4Expired 18 Feb 2026
- GapRestore test out of dateOpen, awaiting retest
- ActionRun and document restore testDue 15 Apr 2026
Reuse
One item, every framework that asks for it.
Frameworks overlap far more than their numbering suggests. The library is organised around the proof, not around whichever audit asked for it first — so the fourth questionnaire of the year is an afternoon rather than a fortnight.
| ISO/IEC 27001:2022 | SOC 2 | NIST CSF 2.0 | CIS Controls v8.1 | Insurer questionnaire | |
|---|---|---|---|---|---|
| MFA enforcement export | A.5.16 Identity management | Logical access (CC6) | PR.AA — Identity management, authentication and access control | Control 6 — Access control management | Question 1 — MFA on email, remote access and admin |
| Backup restore test | A.8.13 Information backup | Availability (A1) | PR.DS — Data security | Control 11 — Data recovery | Question 3 — backups immutable, offline and restore-tested |
| Awareness training completion | A.6.3 Awareness, education and training | Control environment (CC1) | PR.AT — Awareness and training | Control 14 — Security awareness and skills training | Question 7 — training and phishing simulations |
| Supplier security reviews | A.5.19 Supplier relationships | Risk mitigation (CC9) | GV.SC — Cybersecurity supply chain risk management | Control 15 — Service provider management | Question 8 — critical vendor and third-party reviews |
- MFA enforcement export
- A.5.16 Identity management
- Backup restore test
- A.8.13 Information backup
- Awareness training completion
- A.6.3 Awareness, education and training
- Supplier security reviews
- A.5.19 Supplier relationships
- MFA enforcement export
- Logical access (CC6)
- Backup restore test
- Availability (A1)
- Awareness training completion
- Control environment (CC1)
- Supplier security reviews
- Risk mitigation (CC9)
- MFA enforcement export
- PR.AA — Identity management, authentication and access control
- Backup restore test
- PR.DS — Data security
- Awareness training completion
- PR.AT — Awareness and training
- Supplier security reviews
- GV.SC — Cybersecurity supply chain risk management
- MFA enforcement export
- Control 6 — Access control management
- Backup restore test
- Control 11 — Data recovery
- Awareness training completion
- Control 14 — Security awareness and skills training
- Supplier security reviews
- Control 15 — Service provider management
- MFA enforcement export
- Question 1 — MFA on email, remote access and admin
- Backup restore test
- Question 3 — backups immutable, offline and restore-tested
- Awareness training completion
- Question 7 — training and phishing simulations
- Supplier security reviews
- Question 8 — critical vendor and third-party reviews
Because the item exists once, the expiry date exists once. Renewing the restore test updates the ISO control, the SOC 2 criterion, the CIS safeguard and the insurer answer together — rather than four copies of one document drifting apart over a year.
Sentinel supports readiness, governance, assessment, evidence organisation and control management. CyberWave does not certify compliance, issue audit opinions, guarantee compliance, or replace independent auditors, certification bodies or legal counsel. Framework references are informational readiness mappings.
Gaps
A gap list is a work list, not a percentage.
“73% evidence coverage” is a number people argue about in a meeting. “The restore test expired in February and the supplier reviews have no owner” is a number of afternoons.
Items past their date. Somebody had these, and they lapsed.
Controls that need proof and have none on file.
Controls with nobody’s name against them, of 26.
The same figures, as rows to work
Example data · anything not Accepted| Evidence | Control | Owner | Status | Validity |
|---|---|---|---|---|
| Backup restore test report — Q3 2026 | A.8.13 | Jordan Blake | Missing | Due 30 Sep 2026 |
| Penetration test report — external (2025) | A.8.8 | Priya Raman | Expired | Expired 20 Jul 2026 |
| Privileged account inventory | A.8.2 | Priya Raman | Needs Review | Uploaded 4 Sep 2026 |
| Statement of Applicability — draft v3 | C.6 | Elena Kowalski | Pending | Due 31 Aug 2026 |
- Backup restore test report — Q3 2026
- Control
- A.8.13
- Owner
- Jordan Blake
- Status
- Missing
- Validity
- Due 30 Sep 2026
- Penetration test report — external (2025)
- Control
- A.8.8
- Owner
- Priya Raman
- Status
- Expired
- Validity
- Expired 20 Jul 2026
- Privileged account inventory
- Control
- A.8.2
- Owner
- Priya Raman
- Status
- Needs Review
- Validity
- Uploaded 4 Sep 2026
- + 1 more in the workspace
It works in the other direction too. When a document turns up that nobody requested, it can be filed against the controls it happens to cover — which is how the useful half of an old audit folder gets rescued instead of re-created.
Underwriting
A package a broker can forward without editing it.
An insurer’s security questionnaire is an evidence request with a deadline attached. The answers are already in the library. The work is assembling them into something an underwriter can read in order.
Answered from the register
Each answer carries the item it came from and the date that item was accepted — rather than an assertion typed into a form by whoever had the tab open.
An index the underwriter can follow
What is attached, what it evidences, when it was accepted and when it expires. A reviewer sees the shape of the programme without opening every file.
The gaps, before they are found
Anything Missing or Expired is visible to you first. Knowing about a gap and having a dated plan for it is a different conversation from being asked about it cold.
The same pack, next renewal
The library persists and the items carry dates, so next year is an update rather than a rebuild.
Cyber Insurance Submission Pack
A reviewed, broker-ready evidence and questionnaire package assembled from your workspace.
$499one-time
Assembled and reviewed by CyberWave from your own workspace. Arranged with us rather than bought at a checkout, because the scope depends on what your renewal asks for.
CyberWave helps you prepare for underwriting and security questions, organise evidence, identify possible gaps and plan remediation. CyberWave is not an insurer or an insurance broker, does not bind coverage, does not interpret policy coverage as legal advice, and does not guarantee coverage, premium reduction, claim payment or insurer acceptance. You remain responsible for complete and truthful representations to your insurer or broker.
Questions
What buyers ask about the evidence library.
Including the three nobody volunteers: who accepts an item, where the files sit, and whether we grade proof by how strong it is.
The evidence library is included from Essentials upwards, at $99 per month. Broker and underwriter evidence packages are part of Full Platform.
Compare plansCan one evidence item count towards more than one framework?
Do you rate evidence by how strong the proof is — self-declared, attested, independently tested?
Does Sentinel collect evidence from our systems on its own?
Who decides an item is Accepted?
Where is our evidence stored, and who can reach it?
We already have hundreds of documents. Is this a migration project?
Start with the twenty documents somebody is about to ask for.
Not a full index of the drive. One framework or one renewal, the controls it touches, and the proof attached to them with a date on it. The rest builds itself from there.
Self-service signup opens shortly — we will set you up in the meantime
- Published pricing — no quote-on-request tier
- No credit card required for the trial
- No automatic charge when a trial ends
- Tenant-isolated architecture, data stored in Canada
- Clear data-processing terms
- No compliance guarantee — human judgement still required