How the 90-day schedule works
Day 0 is the date the underwriter or broker sets (the quote, the bind, or any date they choose). Each gap gets one checkpoint: day 30, day 60 or day 90. The checkpoints are a default the underwriter or broker sets and can move line by line; they are not a deadline in any standard.
The default rule
| Checkpoint | Lines due at it |
|---|---|
| day 30 | Multi-factor authentication items, backup items, and any line whose held requirement sets a timeframe of two weeks or less. |
| day 60 | The rest of the core lines for the jurisdiction: the target maturity level in Australia, CIS Controls and NIST CSF 2.0 in the United States, Cyber Essentials in the United Kingdom. |
| day 90 | Sector add-on lines, Privacy Act lines, items beyond the core list, your own conditions, and anything marked not sure. |
The requirement's own timeframe
Some requirements carry their own time: the Essential Eight's patching within two weeks or within 48 hours of release, Cyber Essentials' 14 days for high and critical updates, the FTC Safeguards Rule's notice no later than 30 days after discovery, 23 NYCRR 500.17's 72 hours, the Notifiable Data Breaches scheme's 30-day assessment. The line shows those words, in the requirement's own words, beside the checkpoint, never in place of it.
What each line says
| When | The line reads |
|---|---|
| reported closed on or before its checkpoint | reported closed on 19 Aug by the applicant |
| reported closed after its checkpoint | reported closed on 12 Sep by the applicant, after the day 30 checkpoint (Mon 31 Aug) |
| its checkpoint date has gone by with no closure reported | open at the day 30 checkpoint (Mon 31 Aug) |
| its checkpoint is still ahead | due at day 60 (Wed 30 Sep) |
The checkpoint day itself counts as by it. The clock reads "day 66 of 90" from day 0 to the as-at date. The counts per checkpoint are: lines due at it, reported closed by it, reported closed after it, and still open. No exposure figure, no dollar estimate and no risk rating appear anywhere.
Closures are what the applicant reports
The applicant reports a line closed through its private link, with a date and an optional note; the report is kept with the time it was made, and a later report never removes an earlier one. The underwriter or broker can record a closure the applicant reported another way, under their own name. Nothing here checks a closure.