Not every company has a fully documented information security management system. If your organisation is still developing its formal security policies, you can still complete the CyberVadis assessment and receive a meaningful score.
CyberVadis accepts any document that demonstrates your company's engagement with cybersecurity practices across the four assessment functions: Identify, Protect, Detect, and React. Formal policies are not the only form of acceptable evidence.
Examples of alternative evidence
If you do not have standard policy documents, the following types of evidence are accepted:
Action plans or roadmaps for upcoming cybersecurity projects or improvements
Management commitment statements or signed memos confirming the organisation's commitment to cybersecurity
Internal emails or communications promoting security awareness or describing security decisions
Employee training materials such as presentation slides, training invitations, attendance logs, or completion certificates
Meeting minutes from security review meetings or risk discussions
Contracts or agreements with IT service providers that include security requirements
Screenshots or records of security tools in use, even without a formal policy governing them
Certificates of participation in external security training or awareness programmes
How to present alternative evidence effectively
When submitting non-standard documents, use the comment field within each question to explain what the document demonstrates and how it relates to the control being assessed. This context helps our analysts evaluate your submission accurately and award the appropriate credit.
How alternative evidence affects your score
Informal evidence typically earns partial credit rather than full credit for a given control. A management commitment email, for example, demonstrates intent but not implementation. This is expected and valid. The assessment is designed to identify gaps as well as strengths, and partial credit is always better than leaving a control unanswered.
Your results will include a personalized improvement plan with specific recommendations for formalizing and strengthening your security practices. The assessment is the starting point of an improvement journey, not a pass/fail test.
Not sure if a document qualifies?
If you are unsure whether a specific document is acceptable as evidence, contact your account manager at account.management@cybervadis.com before submitting. They will advise on whether the document is suitable and how best to present it.
