Skip to main content

What if I don't have formal cybersecurity policies? Alternative evidence

Find out what alternative evidence CyberVadis accepts if your company does not yet have formal cybersecurity policies in place, and how to submit documentation that still demonstrates your engagement with security practices.

Written by Ana Nikolaeva

Not every company has a fully documented information security management system. If your organisation is still developing its formal security policies, you can still complete the CyberVadis assessment and receive a meaningful score.

CyberVadis accepts any document that demonstrates your company's engagement with cybersecurity practices across the four assessment functions: Identify, Protect, Detect, and React. Formal policies are not the only form of acceptable evidence.

Examples of alternative evidence

If you do not have standard policy documents, the following types of evidence are accepted:

  • Action plans or roadmaps for upcoming cybersecurity projects or improvements

  • Management commitment statements or signed memos confirming the organisation's commitment to cybersecurity

  • Internal emails or communications promoting security awareness or describing security decisions

  • Employee training materials such as presentation slides, training invitations, attendance logs, or completion certificates

  • Meeting minutes from security review meetings or risk discussions

  • Contracts or agreements with IT service providers that include security requirements

  • Screenshots or records of security tools in use, even without a formal policy governing them

  • Certificates of participation in external security training or awareness programmes

How to present alternative evidence effectively

When submitting non-standard documents, use the comment field within each question to explain what the document demonstrates and how it relates to the control being assessed. This context helps our analysts evaluate your submission accurately and award the appropriate credit.

How alternative evidence affects your score

Informal evidence typically earns partial credit rather than full credit for a given control. A management commitment email, for example, demonstrates intent but not implementation. This is expected and valid. The assessment is designed to identify gaps as well as strengths, and partial credit is always better than leaving a control unanswered.

Your results will include a personalized improvement plan with specific recommendations for formalizing and strengthening your security practices. The assessment is the starting point of an improvement journey, not a pass/fail test.

Not sure if a document qualifies?

If you are unsure whether a specific document is acceptable as evidence, contact your account manager at account.management@cybervadis.com before submitting. They will advise on whether the document is suitable and how best to present it.

Did this answer your question?