Cyber Insurance Requirements: What UK Insurers Actually Ask For
UK cyber insurers rarely demand a certificate by name — they demand the controls behind one. This guide maps what proposal forms actually ask for, where Cyber Essentials answers the questions, where it doesn't, and how to become insurable in about 30 days.
The short answer
Most UK cyber insurers don't formally mandate Cyber Essentials — but their proposal forms ask for almost exactly its five controls: MFA, patching within 14 days, firewalls, secure configuration and malware protection. Get those wrong and cover is refused, loaded or voided at claim time. Cyber Essentials certification evidences the controls in one recognised document, includes £25,000 of cyber liability cover for eligible smaller organisations, and — per the NCSC — certified-control organisations are 92% less likely to make a claim. Insurers usually want two things on top: EDR and tested backups.
How AMVIA gets you certified in 30–45 daysDo UK insurers require Cyber Essentials?
Almost never as a formal, named mandate — and any page telling you otherwise is overselling. What's verifiably true is subtler and more important: UK cyber insurers underwrite on controls, and the controls on their proposal forms map closely onto the five that Cyber Essentials certifies. Hiscox, for example, publishes eligibility criteria for its UK cyber policies built on specific technical controls rather than any certificate; US-and-UK insurtech Coalition publishes a near-identical control list. Answer those questions badly and you don't get a worse premium — you often don't get cover, or you get cover that fails at claim time because the declared controls weren't real.
The direction of travel has been set for a decade. In November 2014, the Cabinet Office and the CEOs of major UK insurers signed a joint statement agreeing insurers should promote adoption of good practice, 'including Cyber Essentials'; the 2015 HM Government and Marsh report UK Cyber Security: The Role of Insurance — steering group including the ABI, Lloyd's, AIG, Allianz, Beazley and Hiscox — agreed CE would feature in SME risk assessment. A decade on, the government's own evaluation of the scheme (DSIT Cyber Essentials Impact Evaluation, July 2024) found certification affects insurance in two concrete ways: bundled cover included with certification, and some insurers offering better terms to certified organisations.
The 92% number, and what it actually means
The NCSC's 10 Years of Cyber Essentials report states that organisations with Cyber Essentials controls are 92% less likely to make a cyber insurance claim than organisations without them. It's the strongest published statistic connecting the scheme to insurance outcomes — and it's worth reading precisely: the data comes from claims on the insurance policy bundled with certification, not the whole UK market, and it measures the controls doing their job (fewer incidents), not premiums falling. It's an argument that the five controls work, which is exactly why underwriters ask about them.
What's on the proposal form — mapped to Cyber Essentials
| What insurers ask | Cyber Essentials control? | Notes |
|---|---|---|
| MFA on email, remote access and admin accounts | ✔ User access control | The single most scrutinised answer on the form; inadequate MFA is widely cited by brokers as a leading cause of declined cover and disputed claims |
| Critical patches applied within 14 days | ✔ Security update management | The 14-day window on insurer forms is literally the CE requirement |
| Firewalls at the boundary and on devices | ✔ Firewalls | Direct match |
| Hardened configurations, default passwords removed | ✔ Secure configuration | Direct match |
| Anti-malware on all endpoints | ✔ Malware protection | CE requires malware protection; many insurers now expect EDR specifically, which goes beyond CE |
| Tested, offline or immutable backups | ✘ Not a CE control | The biggest gap — NCSC deliberately excludes backups from CE, but ransomware underwriting all but requires them |
The honest conclusion: Cyber Essentials answers most of the proposal form; MFA-everywhere, EDR and tested backups are the usual extras insurers want on top. That's also, not coincidentally, the shape of a sensible SME security programme.
The insurance included with certification
Basic Cyber Essentials certification through IASME includes cyber liability insurance with a £25,000 indemnity limit at no extra cost, for eligible organisations: UK or Crown Dependencies domiciled, under £20 million annual turnover, certifying the whole organisation, and opting in during assessment. The policy is underwritten by AIG UK and administered by Sutcliffe & Co, and includes a 24/7 incident-response helpline; Sutcliffe publicly offers paid uplifts of the bundled cover to higher limits. Treat £25,000 as a floor, not a policy — a serious incident costs more (the government's 2024 Cyber Security Breaches Survey put the average cost of the most disruptive breach at £8,260, and that average hides a long expensive tail) — but it's a genuinely free layer that arrives with the certificate.
What cover costs, and what certification does to it
UK SME cyber premiums start from roughly £90–£200 a year for micro-business policies (NimbleFins, 2026) and run into the low thousands for mid-sized SMEs with meaningful cover limits; broker-published ranges of £300–£6,000 a year are typical of the segment. Market conditions are currently favourable — Howden's 2025 cyber report recorded premium rates falling through 2025 as competition increased. On discounts: brokers and certification bodies report certified organisations obtaining better pricing, but no major UK insurer publishes a fixed Cyber Essentials discount — the certificate's real, verifiable value is that it evidences the controls underwriters already require, speeds the proposal process, and reduces the risk of a declined application or a voided claim. Anyone quoting you a guaranteed '10–30% off for CE' is repeating marketing, not policy wording.
Becoming insurable in about 30 days
If you can't answer the proposal form honestly today, the path is the same one certification takes — which is why we deliver them together. AMVIA's Cyber Essentials service (£250 + VAT/month, all-in) implements the five controls hands-on — MFA rolled out, patching brought inside 14 days, firewalls and configurations baselined, malware protection verified — and typically reaches certification in 30–45 days, official fees and the bundled £25k insurance eligibility included. Where your insurer wants the extras, the same team runs EDR and backup work as part of our wider managed security services, and Cyber Essentials Plus (£400 + VAT/month) adds the independent technical audit — the strongest evidence you can hand an underwriter that the declared controls are real. Start by seeing where you stand: the free cyber insurance readiness check takes ten minutes and maps your answers to the questions insurers actually ask, and our guide to getting cyber insurance in the UK covers the buying process itself.
What underwriters weigh
MFA coverage
On email, remote access and every admin account — the first question on the form and the most common reason cover is refused or claims are disputed.
14-day patching
Critical and high-severity patches applied within 14 days — the insurer expectation and the Cyber Essentials requirement are the same number.
EDR, not just antivirus
Endpoint detection and response is increasingly the expected standard — a step beyond what Cyber Essentials requires.
Tested backups
Offline or immutable, and actually restore-tested. Not a CE control — and the gap ransomware underwriters care about most.
Recognised certification
Cyber Essentials evidences five of the six control areas in one register-verifiable document — and brings £25k of bundled cover for eligible organisations.
Honest declarations
A proposal form is a legal document. Declaring controls you don't have doesn't get you cover — it gets you a voided claim when it matters.
Before you fill in the proposal form
Run this list first — every 'no' is either a premium loading, a refusal, or a future claim dispute.
Cyber insurance and Cyber Essentials — your questions
Generally no — no major UK insurer publishes a blanket rule refusing cover without the certificate. But insurers underwrite on the same controls Cyber Essentials certifies: MFA, 14-day patching, firewalls, secure configuration and malware protection. In practice the certificate is the fastest recognised way to evidence those controls, and organisations that can't demonstrate them face refusal, loaded premiums or restricted cover.
Yes, for eligible organisations: basic Cyber Essentials certification through IASME includes cyber liability insurance with a £25,000 indemnity limit at no extra cost — for UK or Crown Dependencies organisations under £20 million turnover that certify the whole organisation and opt in during assessment. It's underwritten by AIG UK, administered by Sutcliffe & Co, and includes a 24/7 incident-response helpline. It's a useful floor, not a substitute for a properly sized standalone policy.
It can help, but be wary of specific promises: no major UK insurer publishes a fixed CE discount, and claims of '10–30% off' trace to marketing rather than policy wording. The government's July 2024 evaluation of the scheme found some insurers do offer better terms to certified organisations, and the certificate reliably speeds underwriting and reduces refusal risk — which for many SMEs is worth more than a discount.
The NCSC's '10 Years of Cyber Essentials' report states organisations with Cyber Essentials controls are 92% less likely to make a cyber insurance claim than those without. The underlying data comes from the insurance policy bundled with certification rather than the whole UK market — so read it as strong evidence the five controls prevent incidents, not as a market-wide premium promise.
Two main ones. Tested, offline or immutable backups — the NCSC deliberately excludes backups from CE, but ransomware underwriting all but requires them. And EDR (endpoint detection and response) — CE requires malware protection, but many insurers now expect the more capable EDR standard specifically. Both are common additions we implement alongside certification.
Because credential-based attacks are the dominant entry route, and MFA is the control that blunts them. It's typically the first question on the proposal form, brokers repeatedly cite missing or partial MFA as a leading cause of refused cover and disputed claims, and 'MFA on email, remote access and admin accounts' has become the de facto minimum. It's also squarely inside Cyber Essentials' user access control requirements.
Entry-level policies for micro businesses start around £90–£200 a year; SMEs buying meaningful cover limits typically pay from a few hundred pounds to a few thousand, with broker-published ranges of roughly £300–£6,000 a year. Rates fell through 2025 as market competition increased (Howden, 2025), making it a comparatively good time to buy — provided your controls survive the proposal form.
Yes — the proposal form is the basis of the contract, and misrepresenting controls (MFA 'enforced' with exceptions, patching 'within 14 days' in theory) is grounds for a dispute or voided claim precisely when you need the policy. This is the strongest argument for independently verified certification: Cyber Essentials Plus has an assessor test the controls, so what you declare is what an independent party found.
Implement the five CE controls plus backups and EDR — which is a 30–45 day exercise for a typical SME estate when done hands-on. AMVIA's Cyber Essentials service (£250+VAT/month) does the implementation and certification together, and the free cyber insurance readiness check will show you in ten minutes which questions you'd currently fail.
Would your proposal form survive scrutiny?
Take the free cyber insurance readiness check — your answers mapped to the controls UK insurers actually ask about, with an instant gap report.
Insurance-ready in about 30 days
The controls insurers require and the controls Cyber Essentials certifies are nearly the same list. We implement them hands-on, certify you, and keep you there — £250 + VAT/month, all-in.
Keep reading
Cyber insurance readiness check
Ten minutes against the questions insurers actually ask — instant results and a gap report.
Cyber Essentials — £250/month
The five controls implemented for you, certified in 30–45 days, kept certified all year.
Cyber Essentials Plus — £400/month
Independently audited controls — the strongest evidence you can hand an underwriter.
How to get cyber insurance in the UK
The buying process itself: brokers vs direct, cover levels, and what to have ready.
Protect your business → Get Cybersecurity Assessment