Nobody wants a self-assessment that says you're secure. An auditor, a broker or a large client's security team wants proof: a third-party attestation, not your word for it. We hold the setting itself, the policy that enforces it, and the log that shows exceptions being handled. We collect and maintain that evidence while we run the environment, not in a scramble every twelve months.
It's not just managed service providers who tick yes to get the form off their desk. Plenty of businesses do the same, because "no" invites more questions than "yes" does. But a false yes costs more than an accurate no, because the gap doesn't disappear. It waits for the audit, or the incident, whichever comes first. We're the ones on the phone either way, so we'd rather the answer be one that holds up.