Direct answer
Retain the vendor and service identity, business owner, criticality rationale, systems/data/access dependencies, questionnaire responses, supporting evidence, evidence dates and scope, material findings, exceptions, treatment owners and the final approval or acceptance decision. Keep representations distinguishable from independently verifiable evidence.
Evidence to retain
Dependency evidence
EvidenceVendor/service identity
EvidenceBusiness owner
EvidenceSystems/data/access affected
EvidenceCriticality rationale and review date
Assessment evidence
EvidenceQuestionnaire version and responses
EvidenceSupporting artefacts
EvidenceEvidence scope and freshness
EvidenceAssessor/reviewer notes
Risk evidence
EvidenceMaterial findings
EvidenceExceptions or unknowns
EvidenceTreatment decision
EvidenceOwner and due date
Decision evidence
EvidenceApproval/conditional approval
EvidenceResidual-risk acceptance where applicable
EvidenceReview trigger
EvidenceRenewal or reassessment date
Relevant Cybatar sources
Cybatar sourcehttps://crgexplore.com/platform/resilience-vendor-assuranceCybatar sourcehttps://crgexplore.com/platform/risk-compliance-assuranceCybatar sourcehttps://crgexplore.com/evidenceCybatar sourcehttps://crgexplore.com/recommendation-guide
External references
NIST SP 1326https://csrc.nist.gov/pubs/sp/1326/finalNIST SP 800-161 Rev. 1https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final
Claim boundary
Evidence quality varies. A supplier-provided document, questionnaire answer or certification can support a decision but should not automatically be treated as proof of every control, service or environment in scope.