Skip to content
Buy an exerciseBuy

Free, no signup

Index your evidence once.

Questionnaires take weeks because nobody knows where the answers live, who owns them, or how old they are. Build the register once and each one becomes a lookup. The last section, the questions you cannot answer yes to yet, is the one that changes deals.

This is a register of what you hold, not a claim about what it proves. Listing a document here says it exists and when it was last touched; whether it satisfies anything is between you and the person asking.

The record

What you hold.

How to fill this in

Today. Then put a reminder in the calendar to redo it, because this document decays faster than anything else you will write.

Strong
2026-08-19, next review 2026-11-19
Weak
(left blank)

Why the weak one costs you. An undated index is worse than none: someone will answer a questionnaire from it in eight months and confidently cite a pen test that expired, an access review that never happened, and an owner who left. The date is what tells the next reader how much of this to trust, and a review date is what stops it quietly rotting.

How to fill this in

Name the product or environment this covers. If you run more than one, this index covers one of them.

Strong
Security evidence index, Northwind SaaS platform (production)
Weak
Security evidence

Why the weak one costs you. Companies with a second product, a legacy environment, or an acquired platform routinely answer questionnaires from the index of the wrong one. The scope belongs in the title because that is the only part everyone reads, and a row about production controls is simply false about the legacy stack.

How to fill this in

One named person with a contact, plus a deputy. Not a team, and not an alias that forwards to four people who each assume one of the others has it.

Strong
Dana K., Security. Deputy: Marcus T.
Weak
The security team

Why the weak one costs you. An index owned by a team is updated by nobody, which is exactly how it comes to be eight months stale. Naming a deputy matters more here than elsewhere, because the request that needs this document usually arrives with a deadline attached to a deal, and often while the owner is away.

How to fill this in

Name the environments and products in scope, then the ones that are not, including anything acquired or legacy.

Strong
Covers the Northwind SaaS platform in production (AWS us-east-1). Does not cover the legacy Contoso platform acquired in 2025, which runs separate identity and backup arrangements.
Weak
Covers Northwind.

Why the weak one costs you. The acquired platform is the classic trap: it has its own identity provider, its own backup regime, and none of the controls described here, yet it is inside the same legal entity a customer is contracting with. An index that does not name it invites someone under deadline pressure to answer for it, and that answer is in writing.

How to fill this in

One row per artifact. Say what it evidences in your own words rather than restating its title, give the real last-updated date, name one owner, and say where the file actually is.

Strong
Access review Q2 2026 | Quarterly review of production access, with removals actioned | 2026-07-01 | Marcus T. | Drive, Security/Reviews
Pen test report | External network and application test, 3 highs remediated | 2026-03-14 | Dana K. | Vanta, Documents
Weak
Access review | Access review | Current | Security | Drive

Why the weak one costs you. The three columns people skip are the three that matter. "Last updated" is what tells you an artifact is usable, and an expired pen test is worse than none because it dates your last serious look for anyone reading carefully. "Where it lives" is what lets someone other than the owner answer a questionnaire at all. And describing what a document evidences in your own words is the check that catches the common case where the policy says something narrower than the question being asked.

How to fill this in

Cite the questionnaire and the item reference, name the artifact, and put any qualification in the caveat column so the person answering sees it before they type yes.

Strong
HECVAT HFIH-01 | IR plan v4 | Revision date is 2025-11, review due
Weak
Copying the full question text into this document

Why the weak one costs you. Two reasons, and the second is the one nobody expects. Practically, question wording changes between questionnaire versions while item references stay stable, so a reference survives and a quotation dates. Legally, several widely used questionnaires are licensed and their terms restrict reproducing the text, one of them explicitly extending to internal use and to training or testing AI systems. Referencing by number gives you the same lookup with none of that exposure.

How to fill this in

List them plainly, with the reason and a real target date and a named owner. Keep it in the index rather than in someone's head.

Strong
Annual IR plan test | Last exercise was 2024, none since | Dana K. | 2026-10-31
Weak
Leaving the gaps out, or writing 'in progress'

Why the weak one costs you. Buyers do not expect a young company to have everything, and a dated commitment with an owner is something a security reviewer can accept and write into a conditional approval. What ends deals is discovering the gap in month three of the relationship, because at that point it reads as concealment rather than immaturity. Keeping this list inside the index is also the only reliable way it gets worked on, since anything tracked separately from the questionnaire process is the first thing to be forgotten.

Generated in your browser. Nothing is sent anywhere and there is nothing to sign up for.

Preview

What downloads.

Common mistakes

What to leave out.

These get added by people trying to be thorough, and each one makes the record weaker.

Questionnaire text copied verbatim
Several of the common questionnaires are licensed, and at least one restricts reproducing its text even internally, as well as using it with AI systems. Reference items by number and you get the same lookup with none of that risk.
The artifacts themselves
This is an index. Pasting policy text, config, or anything with a credential in it turns a document you want widely shared into one you cannot share at all.
Rows for things you intend to do
An artifact that does not exist yet belongs in the not-yet list with a date. Listed as an artifact, it will be cited by someone under deadline pressure who does not check.
Customer names as references
Naming who asked, or who accepted an answer, is a disclosure you probably do not have permission to make, and it circulates further than you think.
A verdict on your own compliance
Holding the artifact and satisfying the control are different claims. Record the first and let the person assessing you reach the second.

The limits of a write-up

Two things an index cannot show.

These are left visibly empty in the download rather than quietly dropped, because a record that hides what it is missing is worse than one that admits it.

That a control is operating, not just documented
A policy evidences intent. Operation is evidenced by records of the thing actually happening: dated reviews, tickets, logs, exercise records. An index of documents can look complete while the activity behind it has quietly lapsed.
That the rows are still true
Every line here is accurate on the index date and decays from there. Access reviews, penetration tests and exercises all expire, and nothing in this document knows that it has aged.

Where this stops

The row most indexes cannot fill.

Work through this honestly and the gap is nearly always the same one: the annual test of the incident response plan, because it needs a dated record with people in it and a plan nobody has exercised cannot produce one. That is the row ControlDrill fills. The exercise runs on your systems and your plan, and the record is written by the time you finish.