Cyber Insurance Application Scannermap an application to controls
For the cyber insurance broker or the risk manager answering a carrier's application

Paste a carrier application. See the controls each question tests.

A carrier's cyber application is a set of control requirements in disguise. Cyber Insurance Application Scanner reads the questions and shows, for each one, the ISO 27001:2022 controls, the SOC 2 criterion and the NIST CSF 2.0 outcome it points at, with the evidence an applicant would hand the carrier. Paste the questions one per line, or pick a held carrier. Every mapped row carries the source question beside it, so nothing is asserted that the application does not ask. The questions are read in this browser: nothing is uploaded while you map, and nothing leaves until you save.

Paste your ownNo account to map an application.
  1. Paste the application questions, or pick a carrier. A carrier's questionnaire, one question per line, or the held Coalition application from the picker. The questions are read in this browser.
  2. You get the controls each question tests. The ISO 27001:2022 control, the SOC 2 criterion and the NIST CSF 2.0 outcome a question reaches, and the framework each belongs to.
  3. You get the evidence list per control. The artefacts an applicant would hand the carrier for that control, so the submission is not held up.
  4. It never rules on you or your client. It maps questions to controls and quotes the source question. Whether cover is offered, and on what terms, is the carrier's underwriting decision, never this tool's.
Specimen, already runa held Coalition application question
Does Named Insured enable disk encryption on laptops, desktops, and other portable media devices?
Coalition held application question
ISO 27001:2022 A.8.24 mappeduse of cryptography
ISO 27001:2022 A.7.10 mappedstorage media
SOC 2 CC6.7 mappedrestricting and protecting information
NIST CSF 2.0 PR.DS-01 mappeddata at rest is protected
Evidence to gather: the cryptography standard and the disk-encryption configuration record, a sample of enrolled devices, and the exception report.
A broker and a risk manager working through an insurance application together at a desk
Answer a carrier's application line from the controls an applicant already holds, with the evidence to gather and the source question beside every row. It works from the application you were sent, in your browser, before submission rather than after a declined quote.
01

Paste the questions, or pick a carrier

A carrier's cyber application, one question per line, or the held Coalition application from the picker. A whole questionnaire at once, or a single line.

02

See the controls each question tests

Each question is read against the standards' text we hold for ISO 27001:2022, SOC 2 and NIST CSF 2.0, and the controls it reaches are shown with the source question beside every row.

03

Carry it to the submission

The evidence list per control, the held carriers ranked by the controls they ask, a two-carrier comparison, and a CSV of control, evidence and source question you drop into the submission file.

Paste a carrier's application questions, one per line, or pick a held carrier. A question the held carriers do not ask is shown as not held, never asserted. Knockout questions (a "no" is a common decline point) and warranty questions (a "yes" binds, where the carrier says so) are flagged in the result.
Nothing is sent anywhere until you save.

Why map the application, and not read three PDFs

The question a broker answers every week is which controls a carrier's application is really asking for, in the terms the applicant's own security team can evidence. The application is a public document; the controls sit in the frameworks the applicant already reports against. Cyber Insurance Application Scanner reads the questions, shows the controls each one reaches, and gives the evidence to gather, so a submission is not held up by a question nobody translated.

The frameworks and the held carriers are published in full: the controls the held carriers ask, the held Coalition application, a two-carrier comparison, the application template and where the text comes from. It maps questions to controls only; it never says whether an applicant will be bound.