Direct answer
Retain the affected scope, approved treatment, implementation/change evidence, failed or deferred assets, post-change validation, remaining exposure, exception or residual-risk decision, reviewer and closure date. The closure record should be reproducible enough to explain what changed and how that was verified.
Evidence to retain
Treatment evidence
EvidenceApproved remediation or mitigation
EvidenceChange/patch reference
EvidenceOwner
EvidenceTarget and completion dates
Implementation evidence
EvidenceTarget assets
EvidenceDeployment/change result
EvidenceFailures/deferred systems
EvidenceCompensating controls
Validation evidence
EvidenceRe-scan or re-query result
EvidenceConfiguration/version verification
EvidenceValidation timestamp
EvidenceReviewer
Closure evidence
EvidenceResidual exposure
EvidenceException/acceptance
EvidenceReopen trigger
EvidenceClosure decision
Relevant Cybatar sources
Cybatar sourcehttps://crgexplore.com/platform/exposure-vulnerability-managementCybatar sourcehttps://crgexplore.com/control-evidence/vulnerability-managementCybatar sourcehttps://crgexplore.com/platform/reporting-governanceCybatar sourcehttps://crgexplore.com/evidence
External references
NIST SP 800-40 Rev. 4https://csrc.nist.gov/pubs/sp/800/40/r4/finalCISA KEVhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog
Claim boundary
Verification proves only the checked scope and method. A successful patch or scan result does not guarantee removal of attacker persistence, complete remediation across every asset or prevention of future exploitation.