Countdown until the UK analogue phone switch-off on 31 January 2027.Is your business affected?
Guide

Cyber Insurance Requirements: What UK Insurers Actually Ask For

UK cyber insurers rarely demand a certificate by name — they demand the controls behind one. This guide maps what proposal forms actually ask for, where Cyber Essentials answers the questions, where it doesn't, and how to become insurable in about 30 days.

The short answer

Most UK cyber insurers don't formally mandate Cyber Essentials — but their proposal forms ask for almost exactly its five controls: MFA, patching within 14 days, firewalls, secure configuration and malware protection. Get those wrong and cover is refused, loaded or voided at claim time. Cyber Essentials certification evidences the controls in one recognised document, includes £25,000 of cyber liability cover for eligible smaller organisations, and — per the NCSC — certified-control organisations are 92% less likely to make a claim. Insurers usually want two things on top: EDR and tested backups.

How AMVIA gets you certified in 30–45 days

Do UK insurers require Cyber Essentials?

Almost never as a formal, named mandate — and any page telling you otherwise is overselling. What's verifiably true is subtler and more important: UK cyber insurers underwrite on controls, and the controls on their proposal forms map closely onto the five that Cyber Essentials certifies. Hiscox, for example, publishes eligibility criteria for its UK cyber policies built on specific technical controls rather than any certificate; US-and-UK insurtech Coalition publishes a near-identical control list. Answer those questions badly and you don't get a worse premium — you often don't get cover, or you get cover that fails at claim time because the declared controls weren't real.

The direction of travel has been set for a decade. In November 2014, the Cabinet Office and the CEOs of major UK insurers signed a joint statement agreeing insurers should promote adoption of good practice, 'including Cyber Essentials'; the 2015 HM Government and Marsh report UK Cyber Security: The Role of Insurance — steering group including the ABI, Lloyd's, AIG, Allianz, Beazley and Hiscox — agreed CE would feature in SME risk assessment. A decade on, the government's own evaluation of the scheme (DSIT Cyber Essentials Impact Evaluation, July 2024) found certification affects insurance in two concrete ways: bundled cover included with certification, and some insurers offering better terms to certified organisations.

The 92% number, and what it actually means

The NCSC's 10 Years of Cyber Essentials report states that organisations with Cyber Essentials controls are 92% less likely to make a cyber insurance claim than organisations without them. It's the strongest published statistic connecting the scheme to insurance outcomes — and it's worth reading precisely: the data comes from claims on the insurance policy bundled with certification, not the whole UK market, and it measures the controls doing their job (fewer incidents), not premiums falling. It's an argument that the five controls work, which is exactly why underwriters ask about them.

What's on the proposal form — mapped to Cyber Essentials

What insurers askCyber Essentials control?Notes
MFA on email, remote access and admin accounts✔ User access controlThe single most scrutinised answer on the form; inadequate MFA is widely cited by brokers as a leading cause of declined cover and disputed claims
Critical patches applied within 14 days✔ Security update managementThe 14-day window on insurer forms is literally the CE requirement
Firewalls at the boundary and on devices✔ FirewallsDirect match
Hardened configurations, default passwords removed✔ Secure configurationDirect match
Anti-malware on all endpoints✔ Malware protectionCE requires malware protection; many insurers now expect EDR specifically, which goes beyond CE
Tested, offline or immutable backups✘ Not a CE controlThe biggest gap — NCSC deliberately excludes backups from CE, but ransomware underwriting all but requires them

The honest conclusion: Cyber Essentials answers most of the proposal form; MFA-everywhere, EDR and tested backups are the usual extras insurers want on top. That's also, not coincidentally, the shape of a sensible SME security programme.

The insurance included with certification

Basic Cyber Essentials certification through IASME includes cyber liability insurance with a £25,000 indemnity limit at no extra cost, for eligible organisations: UK or Crown Dependencies domiciled, under £20 million annual turnover, certifying the whole organisation, and opting in during assessment. The policy is underwritten by AIG UK and administered by Sutcliffe & Co, and includes a 24/7 incident-response helpline; Sutcliffe publicly offers paid uplifts of the bundled cover to higher limits. Treat £25,000 as a floor, not a policy — a serious incident costs more (the government's 2024 Cyber Security Breaches Survey put the average cost of the most disruptive breach at £8,260, and that average hides a long expensive tail) — but it's a genuinely free layer that arrives with the certificate.

What cover costs, and what certification does to it

UK SME cyber premiums start from roughly £90–£200 a year for micro-business policies (NimbleFins, 2026) and run into the low thousands for mid-sized SMEs with meaningful cover limits; broker-published ranges of £300–£6,000 a year are typical of the segment. Market conditions are currently favourable — Howden's 2025 cyber report recorded premium rates falling through 2025 as competition increased. On discounts: brokers and certification bodies report certified organisations obtaining better pricing, but no major UK insurer publishes a fixed Cyber Essentials discount — the certificate's real, verifiable value is that it evidences the controls underwriters already require, speeds the proposal process, and reduces the risk of a declined application or a voided claim. Anyone quoting you a guaranteed '10–30% off for CE' is repeating marketing, not policy wording.

Becoming insurable in about 30 days

If you can't answer the proposal form honestly today, the path is the same one certification takes — which is why we deliver them together. AMVIA's Cyber Essentials service (£250 + VAT/month, all-in) implements the five controls hands-on — MFA rolled out, patching brought inside 14 days, firewalls and configurations baselined, malware protection verified — and typically reaches certification in 30–45 days, official fees and the bundled £25k insurance eligibility included. Where your insurer wants the extras, the same team runs EDR and backup work as part of our wider managed security services, and Cyber Essentials Plus (£400 + VAT/month) adds the independent technical audit — the strongest evidence you can hand an underwriter that the declared controls are real. Start by seeing where you stand: the free cyber insurance readiness check takes ten minutes and maps your answers to the questions insurers actually ask, and our guide to getting cyber insurance in the UK covers the buying process itself.

What underwriters weigh

MFA coverage

On email, remote access and every admin account — the first question on the form and the most common reason cover is refused or claims are disputed.

14-day patching

Critical and high-severity patches applied within 14 days — the insurer expectation and the Cyber Essentials requirement are the same number.

EDR, not just antivirus

Endpoint detection and response is increasingly the expected standard — a step beyond what Cyber Essentials requires.

Tested backups

Offline or immutable, and actually restore-tested. Not a CE control — and the gap ransomware underwriters care about most.

Recognised certification

Cyber Essentials evidences five of the six control areas in one register-verifiable document — and brings £25k of bundled cover for eligible organisations.

Honest declarations

A proposal form is a legal document. Declaring controls you don't have doesn't get you cover — it gets you a voided claim when it matters.

Before you fill in the proposal form

Run this list first — every 'no' is either a premium loading, a refusal, or a future claim dispute.

Cyber insurance and Cyber Essentials — your questions

Free tool

Would your proposal form survive scrutiny?

Take the free cyber insurance readiness check — your answers mapped to the controls UK insurers actually ask about, with an instant gap report.

Insurance-ready in about 30 days

The controls insurers require and the controls Cyber Essentials certifies are nearly the same list. We implement them hands-on, certify you, and keep you there — £250 + VAT/month, all-in.