Back to Articles

Cyber Essentials and Insurance: A UK Business Guide to How Certification Affects Cyber Insurance Premiums in 2026

Cyber Essentials and Insurance: A UK Business Guide to How Certification Affects Cyber Insurance Premiums in 2026

The idea that a Cyber Essentials certificate earns a cyber insurance discount is repeated so often that most UK businesses assume the relationship is a simple one: certify, present the certificate, pay less. The reality underwriters describe is different and more useful to understand. Certification mostly affects whether you are quoted at all, which questions on the proposal form you can answer favourably, and how much the insurer trusts your answers — and in 2026 there is one control that matters more to most underwriters than the certificate itself.

This guide covers the mechanics rather than the sales pitch. It explains how certification enters a premium calculation and what it does not do, the controls underwriters verify independently of any certificate and why multi-factor authentication has become the gate rather than a bonus, the duty of fair presentation that makes accuracy on a proposal form a legal matter rather than an administrative one, why the scope of your certification is the detail that most often causes trouble, where certification stops being sufficient as indemnity limits rise, and how to assemble an evidence pack that gets a broker the best terms available. The broader picture of what cover involves sits in our guides to cyber insurance for UK businesses and Cyber Essentials Plus and cyber insurance.

One framing note before starting. What follows is general information about how certification interacts with underwriting, written from the perspective of getting your security and evidence in order. It is not insurance advice, and decisions about cover, limits and policy wording belong with an FCA-authorised broker who can assess your circumstances.

How certification actually enters the premium calculation

A cyber premium starts from a base rate driven by things you largely cannot change: sector, turnover, the volume and sensitivity of data you hold, your claims history, and the indemnity limit and excess you want. Controls then modify that base, and this is where certification enters — but it enters in three distinct ways that are worth separating, because only one of them is a discount.

As a gate. Most insurers now operate minimum control requirements below which they will not quote at any price. If you cannot evidence multi-factor authentication on remote access and email, or you have no tested backup capability, a substantial share of the market simply declines. Certification helps here because achieving it forces several of those controls into place, so the practical benefit is access to the market rather than a reduction within it.

As corroboration. Underwriters are reading self-declared answers on a proposal form and have limited means to verify them. A certificate from an independent body raises confidence that the answers reflect reality. This is why Cyber Essentials Plus, which involves a hands-on technical audit, carries more weight than the self-assessed basic level — it is not that the controls differ substantially, it is that somebody independently tested them.

As a rating factor. Some insurers do apply an explicit reduction for certification, and some brokers have facilities where it is a stated condition of a preferential rate. The effect where it exists is real but usually modest relative to the base drivers, and it varies enough between insurers that a specific percentage should not be assumed. Anybody quoting you a fixed discount figure for certification in the abstract is describing one insurer’s appetite rather than a market rule.

The practical consequence of those three is that the value of certification is concentrated in the first two. Being quotable by more of the market, with answers the underwriter believes, produces better outcomes than chasing a headline percentage — and it is also the part that survives a change of insurer.

Pro Tip

Before renewal, get a blank copy of the proposal form from your broker and complete it as a dry run, in writing, with evidence attached to each answer. Every question you cannot answer confidently is a specific piece of work with a deadline attached, and you will usually find two or three. Doing this eight to twelve weeks out converts renewal from an exercise in describing your security to an exercise in evidencing it — and it surfaces the gaps while there is still time to close them rather than during the week the quote is needed.

Certification and cyber cover in UK businesses — the numbers

The figures below reflect what we observe across UK organisations of 20 to 400 staff going through certification and cyber insurance renewal. They describe the SME band, where the interaction between the two is most consequential.

MFA
The single control most likely to determine whether an insurer quotes at all
£25k
Indicative indemnity limit of the cyber liability cover included with basic certification
3 in 10
Certified organisations whose certification scope is narrower than they describe to insurers
8–12
Weeks before renewal that evidence gathering should realistically begin

The first card is not a number because the answer is not a number. Multi-factor authentication on remote access, email and administrative accounts has become the control that decides quotability across much of the market. Organisations that have it are in a conversation about price; organisations that do not are frequently in a conversation about whether cover is available. Certification pushes you toward it, which is much of why certification helps.

The second card is the one most often misunderstood. Basic Cyber Essentials certification includes cyber liability cover for UK-domiciled organisations below a turnover threshold, on an opt-in basis, and the indemnity limit is modest. It is a genuine benefit and it is not a substitute for a policy sized to your actual exposure — a single ransomware incident with business interruption and recovery costs will exceed that limit comfortably. Treat it as a floor that comes free rather than as your cyber cover.

The third card is the one that carries the most risk and attracts the least attention, and the rest of this guide returns to it. Certification has a defined scope, that scope can legitimately be narrower than the whole organisation, and describing a partial certification as though it covered everything is a misrepresentation with consequences at claim time rather than a presentational nicety.

What underwriters check independently of the certificate

The chart below shows how often each control is specifically asked about or verified during UK SME cyber underwriting, based on proposal forms and broker questionnaires we work through with clients. Several of these go beyond what any certification level examines, which is why a certificate alone does not complete the picture.

MFA on remote access, email and admin accounts
96%
Backup architecture, offline or immutable copy
91%
Tested restore within a stated timeframe
78%
Endpoint detection and response, not just antivirus
74%
Patching cadence with a stated timescale
69%
Documented incident response plan
63%
Privileged access separation and review
52%

Notice how the top three concern ransomware specifically. That reflects where claims cost sits: underwriters are pricing the probability and severity of an incident that encrypts your estate, and the questions that predict severity are about whether you can recover without paying. A tested restore is a different question from a backup existing, and the distinction is exactly the one insurers have learned to ask about — which is also the distinction covered in our guide to backup retention policy.

Endpoint detection and response at seventy-four per cent is the requirement that has moved fastest. Traditional signature-based antivirus, which satisfies the malware protection control in a certification context, is increasingly treated as insufficient by underwriters who want behavioural detection and the ability to respond on the endpoint. An organisation can therefore hold a valid certificate and still fall short of an insurer’s malware expectations, which surprises people who assume the certificate is the benchmark.

The incident response plan at sixty-three per cent is worth preparing for because it is cheap and frequently missing. Underwriters are not asking for a thick document; they want evidence that someone has decided in advance who does what, who is called, how the insurer is notified and within what period. Notification timeframes in particular matter, because late notification can prejudice a claim regardless of how good your controls were.

What certification and cover cost in the UK

The figures below are indicative UK costs for 2026, excluding VAT. Certification fees are set on turnover bands by the scheme and are published; audit and premium figures vary considerably with size, sector and the state of your controls, so treat them as sizing rather than quotations. Fuller certification pricing sits in our guide to Cyber Essentials cost in the UK.

Item Indicative UK cost Frequency Note
Cyber Essentials certification fee £320–600 Annual Banded by turnover; self-assessed and independently reviewed
Cyber Essentials Plus audit £1,400–3,500+ Annual Hands-on technical testing; scales with device and user count
Remediation to reach certification £0–8,000 Largely one-off Depends entirely on current state; MFA and EDR are common gaps
Cyber insurance, £250k–£1m limit £500–3,000 Annual premium SME band; varies widely by sector, data volume and controls
Cyber insurance, £2m–£5m limit £3,000–15,000 Annual premium Fuller questionnaire, sometimes external scanning or interview

The comparison that matters here is the third row against the fourth. Remediation to reach certification is frequently a larger number than the annual premium, which means framing certification as a way to save money on insurance gets the proportions wrong. The honest framing is that certification and the remediation behind it reduce the probability and severity of an incident, and that improved insurance terms are a secondary consequence of having genuinely better controls rather than the point of the exercise.

The step from the fourth row to the fifth is where the character of underwriting changes. At modest limits, a proposal form and a certificate frequently complete the process. At higher limits, insurers apply more scrutiny: longer questionnaires, external attack-surface scanning conducted without your involvement, sometimes a call with whoever is technically accountable. Certification remains useful at that level and stops being the main event.

On the remediation range, the zero at the bottom end is genuine. Organisations already running MFA, managed patching, EDR and tested backups may find certification is largely documentation and evidence gathering. Organisations without those will find the cost sits in the controls rather than the certificate, which is the correct place for it to sit.

Basic certification against Cyber Essentials Plus, from an underwriting view

The comparison below highlights Cyber Essentials Plus, specifically for its effect on underwriting rather than as a general recommendation. Both levels cover the same five control areas; what differs is how the claim to have implemented them is verified, and verification is precisely what an underwriter is buying. For organisations whose only driver is a contractual requirement to hold a certificate, basic remains a perfectly rational choice.

Cyber Essentials

Self-assessment, independently reviewed

Verification Your answers, reviewed by a body
Technical testing None
Annual cost £320–600
Underwriter confidence Moderate
Included cover Yes, modest limit, opt-in
Satisfies contract requirements Usually
Evidence value at claim Shows intent and baseline
Best where Contractual need, budget constrained

Cyber Essentials Plus

Hands-on technical audit

Verification Independently tested, not declared
Technical testing Sampled devices and configurations
Annual cost £1,400–3,500+ plus the fee
Underwriter confidence Materially higher
Included cover Via the underlying certification
Satisfies contract requirements Yes, including stricter ones
Evidence value at claim Demonstrates tested controls
Best where Insurance terms, supply chain scrutiny

The verification row is the whole distinction. An underwriter reading a basic certificate knows that an organisation answered a set of questions and that a certification body found the answers coherent. An underwriter reading a Plus certificate knows that somebody independent connected to sampled machines and checked. Where an insurer differentiates between the two — and not all do — that is the reason.

The evidence-at-claim row deserves care, because it is easily overstated. Neither certificate pays a claim, and neither prevents an insurer from investigating whether the controls you described were actually in place at the time of the incident. What a Plus audit provides is contemporaneous independent evidence that specific controls were tested on a specific date, which is a materially stronger position than an assertion. The detail of what that audit involves is covered in our guide to the Cyber Essentials Plus technical audit, and the broader choice between levels in our guide to Cyber Essentials against Cyber Essentials Plus.

One practical note on timing: both certifications are annual, and an expired certificate is worth very little at renewal. Aligning the certification cycle so the certificate is current and comfortably in date when the insurance renewal questionnaire is completed is a small piece of administration that occasionally makes a real difference.

Where businesses fall short of insurer expectations

The grid below groups the gaps we find when preparing UK organisations for a cyber renewal. The badges reflect how much each gap affects quotability or terms, rather than how serious a security weakness it represents in isolation.

Controls underwriters gate on
MFA missing on remote access or email High risk
MFA absent on administrative accounts specifically High risk
No offline or immutable backup copy High risk
Restore never tested, or not within a stated time High risk
Signature antivirus only, no behavioural detection Medium risk
End-of-support operating systems still in use Medium risk
Scope and representation
Certification scope narrower than described to insurer High risk
Proposal form answered from assumption, not evidence High risk
Controls described as universal when partially deployed High risk
Subsidiaries or acquisitions outside the certified scope Medium risk
No record of who answered what, or on what basis Medium risk
Material change since certification not disclosed Medium risk
Process and readiness
No documented incident response plan Medium risk
Insurer notification timeframe unknown internally High risk
Evidence gathering started days before renewal Medium risk
Certificate expired or expiring inside the policy period Medium risk
No staff security training records Lower risk
Supplier and third-party risk never assessed Medium risk

The second card is where the consequences are most severe and least visible, and it is the subject of the next section. Every row in it describes a way of presenting your security position more favourably than the evidence supports — usually without any intention to mislead, because the person completing the form genuinely believes MFA is everywhere or that the certification covered the whole business.

The notification timeframe row in the third card is rated high deliberately. Policies specify a period within which an incident must be reported, and that period is frequently short. An organisation that suffers an incident on a Friday, spends a week containing it and notifies the insurer afterwards may have prejudiced its own claim while doing entirely sensible technical work. Knowing the number, and having it written where the incident responders will see it, costs nothing.

The supplier risk row reflects a direction of travel. Underwriters increasingly ask about dependency on third parties, because a material share of incidents arrive through a supplier rather than directly. Certification does not examine your suppliers, so this is another area where the certificate does not answer the question being asked.

The duty of fair presentation, and why accuracy is a legal matter

This is the part of the certification-and-insurance relationship that gets least attention and carries the most consequence. When a UK business buys commercial insurance, it does not simply answer questions; it owes the insurer a duty of fair presentation of the risk under the Insurance Act 2015. That duty is broader than not lying.

In practice it requires disclosure of every material circumstance you know or ought to know, or enough information to put a prudent insurer on notice that it should ask further questions, presented in a reasonably clear and accessible way. “Ought to know” is the phrase that matters, because it extends to what would have been revealed by a reasonable search of information available within the organisation. Not having asked your IT provider whether MFA is genuinely deployed everywhere is not obviously a defence.

The remedies if the duty is breached depend on the nature of the breach. Where it was deliberate or reckless, an insurer may treat the policy as though it never existed and keep the premium. Where it was neither, the remedy is proportionate to what the insurer would have done with full information: it may avoid the policy if it would not have written the risk at all, or apply the terms it would have imposed, or reduce a claim payment proportionately if it would have charged a higher premium. That middle outcome is the common one and it means a claim can be paid at a fraction of its value because of an answer nobody thought about carefully.

Why certification raises the stakes rather than lowering them

A certificate is a specific, documented, dated assertion about your controls. Presenting it supports your presentation of the risk — and it also creates a record that can be compared with reality after an incident. If the certificate scope covered your head office and the incident began on an uncertified subsidiary’s network, the mismatch is discoverable. Certification therefore makes an accurate presentation easier and an inaccurate one more exposed, which is the correct incentive but not the one people expect.

What good practice looks like

Answer the proposal form from evidence rather than belief, and keep the evidence. Record who answered each question, on what date, and what they relied on. Where a control is partially deployed, say so precisely — “MFA is enforced on all remote access and email, and on eleven of fourteen administrative accounts, with the remaining three scheduled for completion in October” is a far better answer than a yes or a no, and it is the kind of answer that protects a claim. Underwriters deal in partial deployments constantly; what damages you is not the gap but the misdescription.

And disclose material change during the policy period if the wording requires it. An acquisition, a new remote access route, a migration, the loss of a key control — these can be material, and the duty does not necessarily end at inception.

Scope is the detail that catches people

Cyber Essentials certification has a defined scope, and that scope can legitimately cover less than the whole organisation. A business may certify one office, one operating company, one network segment, or exclude a subsidiary. The scheme permits this and the certificate states what was covered.

The problem is what happens next. The certificate gets filed, the marketing team mentions it on the website, and eighteen months later somebody completing an insurance proposal form ticks the box saying the organisation holds Cyber Essentials without rereading the scope statement. Roughly three in ten certified organisations we work with describe their certification more broadly than the scope supports, almost always without any intention to mislead.

Three scope traps worth checking

The first is organisational. Group structures, subsidiaries, recently acquired businesses and trading names each raise the question of which legal entity was certified and which entity is being insured. If they are not the same, that is a material fact.

The second is technical. A scope that excluded a segment, a site, a set of legacy servers or a category of device means the controls were not assessed there. Home workers and bring-your-own-device arrangements are common exclusions, and they are also common incident routes, which is an unfortunate combination.

The third is temporal. Certification is a point-in-time assessment renewed annually. Substantial change since the assessment — a migration, a new remote access method, a merger — means the certificate describes an estate that has moved on.

None of these are reasons not to certify a subset; partial certification is often the sensible commercial choice. They are reasons to read your own scope statement before describing the certification to anybody, and to describe it in the terms the certificate actually uses. If the scope is narrow and the insurance covers the whole group, say that plainly — an underwriter can price a known gap and cannot price one they discover at claim stage.

Getting insurance-ready — twelve weeks before renewal

The sequence below assumes an existing policy approaching renewal and a business that wants better terms than last year. Working backwards from the renewal date is deliberate, because the binding constraint is how long control changes take to become evidenceable.

Week 12 — Dry-run the proposal form
Get a blank form from the broker and complete it in writing with evidence against each answer. Every question you cannot evidence becomes a work item with a deadline. This single step generates the whole plan and usually finds two or three gaps.
Week 12 — Reread your certification scope statement
What entity, what sites, what segments, what device categories, and what date. Compare that against what is being insured. Note every difference now, so it can be disclosed deliberately rather than discovered later.
Weeks 11–8 — Close the gating control gaps
MFA on remote access, email and every administrative account. An offline or immutable backup copy. EDR rather than signature antivirus alone. These are the controls that decide quotability, and they take weeks rather than days to deploy and verify properly.
Week 8 — Test a restore and document it
An actual restore of an actual system, timed, with a written record of what was restored, how long it took and who witnessed it. “Backups run successfully” is not the question underwriters are asking; recovery within a stated timeframe is.
Weeks 7–5 — Write or refresh the incident response plan
Who does what, who is called, and critically the insurer notification requirement and timeframe written where responders will see it. A short usable document beats a long unread one, and this is also a certification-adjacent artefact worth having regardless.
Weeks 5–4 — Confirm certification currency
Ensure the certificate is in date and will remain so through the policy period, and consider whether Cyber Essentials Plus is worth pursuing before renewal if insurance terms are a primary driver. An expired certificate is worth very little at this point.
Weeks 4–3 — Assemble the evidence pack
Certificate and scope statement, audit report if Plus, MFA coverage evidence, backup test record, incident response plan, patching policy, training records, and a short covering summary written for an underwriter rather than an engineer.
Weeks 3–0 — Broker submission and questions
Submit early enough that underwriter questions can be answered properly rather than guessed at under time pressure. Keep a record of every answer given and its basis, because that record is what supports a claim two years from now.

The item most often left too late is the restore test, because it requires coordination and somebody to be available. It is also among the most valuable things in the pack, since it converts the answer to the most heavily weighted severity question from an assertion into a documented fact with a date on it.

Twelve weeks is comfortable rather than generous. Deploying MFA across administrative accounts in an estate that has never had it involves discovering accounts nobody remembered, service accounts that break when challenged, and at least one application that does not support it. That discovery process is the reason this work does not compress well.

Benchmarks — control readiness against insurer expectations

The figures below show how often each control or artefact is genuinely in place across UK organisations of 20 to 400 staff at the point we begin renewal preparation. Readings are generous: a control counts as present if it exists anywhere in the estate, which is itself part of the problem.

Presence of insurer-expected controls in UK SMEs

MFA on email
81%
MFA on every administrative account without exception
44%
Offline or immutable backup copy
38%
Restore tested in the last 12 months
41%
Restore test documented with a timing
17%
Endpoint detection and response deployed
49%
Documented incident response plan
33%
Insurer notification timeframe known internally
14%
Certification scope statement reread before renewal
19%
Proposal form answers evidenced and recorded
12%

The first two rows together describe the most common underwriting problem in the UK SME market. Eighty-one per cent have MFA on email, which is what most people mean when they say they have MFA. Forty-four per cent have it on every administrative account — and administrative accounts are what an attacker needs. The gap between those two numbers is where a confident yes on a proposal form turns into an inaccurate statement, because the person answering is thinking about the email rollout they remember.

Rows four and five are the same pattern in a different control. Forty-one per cent have tested a restore; seventeen per cent can produce a document showing what was restored, how long it took and when. Underwriters increasingly want the second, and the difference between them is an hour of writing at the time of the test rather than any additional technical work.

The bottom two rows are the process failures that make everything above harder to present well. Nineteen per cent reread the scope statement, so four in five describe a certification whose boundaries they have not checked. Twelve per cent evidence and record their proposal answers, which means the working that would support a claim two years later does not exist in most organisations. Both are free, and both are the difference between a defensible presentation and a hopeful one.

The number that decides quotability

If one control determines whether a UK SME can obtain cyber cover on reasonable terms in 2026, it is comprehensive multi-factor authentication — and the operative word is comprehensive, because partial deployment is where most organisations sit and it is not what underwriters are asking about.

44%
Share of UK SMEs with multi-factor authentication enforced on every administrative account without exception

Forty-four per cent means that a slight majority of organisations would, if the question were answered precisely, have to disclose an exception — a service account, a legacy application, a break-glass credential, an administrator on a system that does not support it. Those exceptions are frequently defensible and manageable. What is not manageable is answering yes and having the exception surface during a claim investigation into an incident that began with a compromised administrative credential.

The practical importance of this figure is that it is both the most weighted underwriting question and one of the cheapest gaps to close. MFA on administrative accounts is a configuration exercise rather than a purchase for most organisations already running Microsoft 365 or equivalent, and the work is mostly discovery — finding the accounts nobody remembered, and dealing with the one application that will not cooperate.

Where an exception genuinely cannot be removed, the answer is to document it, compensate for it — network restriction, monitoring, a long unique credential in a managed vault — and disclose it in those terms. An underwriter presented with “one legacy administrative account cannot support MFA; it is restricted to a single management network, credentials are vaulted and rotated, and access is logged and reviewed monthly” is being given something they can price. The same situation described as a yes is a problem stored up for later.

Where certification stops being sufficient

Cyber Essentials is a baseline, and it is deliberately designed as one. Understanding where it runs out prevents the disappointment of presenting a certificate to an underwriter who wants considerably more.

As indemnity limits rise

At modest limits a certificate and a proposal form frequently complete the underwriting process. As limits rise into the millions, insurers apply their own assessment: longer questionnaires, external attack-surface scanning performed without your involvement, sometimes a technical call. Certification remains a positive input and stops being the deciding one, and the gap between what the scheme examines and what the underwriter examines widens.

Where the estate is larger or more complex

The five control areas were designed for organisations that can reasonably describe their estate. A business with multiple sites, several operating companies, cloud platforms, bespoke applications and a substantial supplier chain has risks the scheme does not reach into: application security, privileged access management, logging and detection maturity, third-party dependency. Insurers pricing that risk will ask about those areas directly.

In regulated sectors and demanding supply chains

Financial services, healthcare and defence supply chains frequently expect more than a baseline — ISO 27001 certification, SOC 2 reporting, penetration testing on a defined cycle, or scheme-specific requirements. In these contexts Cyber Essentials functions as a prerequisite rather than an achievement, and its absence is disqualifying while its presence is unremarkable.

Where the controls exist but detection does not

The scheme is largely preventative. It says relatively little about whether you would notice an intrusion, how quickly, and what you would do. Underwriters increasingly care about detection and response because those determine severity rather than probability, and an organisation with excellent preventative controls and no monitoring has a certificate and an unanswered question. Independent testing is the usual way to evidence the gap between intended and actual security posture, and we cover that in our guide to what happens during a penetration test.

None of this diminishes the certificate. A baseline that is genuinely in place across a defined scope, independently tested at the Plus level, and accurately described is worth having and does improve your position. It simply is not a complete answer to the question an underwriter is asking, and treating it as one is how organisations arrive at renewal expecting a discount and receiving a questionnaire.

The 12-point evidence pack for your broker

Items one to four are the certification evidence. Items five to nine are the controls underwriters weight most heavily. Items ten to twelve are what turns a collection of documents into a presentation.

  1. The certificate itself, current and in date. Confirm it will remain valid through the policy period, and note the renewal date alongside the insurance renewal date so the two do not drift apart.
  2. The scope statement, read rather than filed. Which legal entity, which sites, which network segments, which device categories, and as at what date. This is the document that most often contradicts what people believe.
  3. The Cyber Essentials Plus audit report, if you hold it. Independent contemporaneous evidence that specific controls were tested on a specific date, which is a materially stronger position than an assertion.
  4. A written note of every difference between certified scope and insured entity. Subsidiaries, acquisitions, excluded segments, home working arrangements. Disclose these deliberately; an underwriter can price a known gap.
  5. Evidence of MFA coverage, stated precisely. Remote access, email and administrative accounts, with exact numbers where deployment is partial and a date for completion. Precision here protects a claim.
  6. Documentation of any MFA exception and its compensating controls. Network restriction, vaulted credentials, logging and review. Described this way it is priceable; described as a yes it is a stored-up problem.
  7. Backup architecture description including the offline or immutable copy. What is backed up, where the copies live, and which copy could not be deleted by a compromised administrator.
  8. A documented restore test with a timing. What was restored, how long it took, when, and who witnessed it. Only about 17 per cent of organisations can produce this, and it answers the most heavily weighted severity question.
  9. Endpoint protection detail. Which product, what coverage across the device estate, and whether it provides behavioural detection and response rather than signature matching alone.
  10. The incident response plan, including the insurer notification timeframe. Short and usable. The notification requirement written where responders will actually see it, because late notification can prejudice a claim regardless of controls.
  11. Patching policy with stated timescales, and training records. The cadence you actually operate rather than an aspiration, plus evidence that staff have had security awareness training within a reasonable period.
  12. A one-page covering summary written for an underwriter. Business language, the controls in place, the known gaps and what is being done about them. This is the document that distinguishes a well-presented risk from a folder of attachments.
Note

If only three items are prepared, make them two, five and eight. The scope statement prevents the most common misrepresentation. Precise MFA coverage answers the question that decides quotability, and stating it precisely rather than as a yes is what protects a claim. And the documented restore test converts the most heavily weighted severity question from an assertion into a dated fact. Together they are perhaps a day of work and they address the three areas where presentations most often fail.

Insurance readiness — where most certified organisations sit

Combining the assessment areas gives an indication of how well an organisation would present at a cyber renewal today, including those that already hold certification. The gauge reflects a first review of a certified UK business of 20 to 400 staff approaching renewal without preparation.

40/100
Typical UK certified SME cyber insurance readiness at first review

A score around forty is higher than several of the benchmarks in this series, and the reason is the certification itself: an organisation that has certified has necessarily addressed the five control areas to some degree, which puts a floor under the score. What drags it down is the difference between having controls and being able to evidence them precisely, plus the scope and representation issues that certification does nothing to prevent.

The composition is consistent. Preventative controls score reasonably. MFA scores well on email and poorly on administrative accounts. Backup existence scores moderately and tested documented recovery scores badly. Detection and response scores poorly because the scheme does not require it. Process and evidence — the scope statement, the recorded proposal answers, the known notification timeframe — score worst, and they are the cheapest to fix.

Worth stating plainly: a low score here is not an argument that certification was a waste. It is an argument that certification and insurance readiness are overlapping rather than identical exercises, and that the gap between them is mostly evidence and precision rather than additional security spending. An organisation at forty can usually reach the seventies in a few weeks without buying anything beyond possibly EDR.

Common mistakes at the certification and insurance intersection

The errors below recur across UK renewals. Almost none are security failures; they are presentation and process failures, which is what makes them both cheap to avoid and easy to miss.

  • Assuming certification produces a headline discount. Its main value is quotability and corroboration, not a percentage. Some insurers apply an explicit reduction, it varies, and building a business case on an assumed figure is unwise.
  • Describing certification more broadly than the scope supports. Roughly three in ten certified organisations do this, almost always innocently, because nobody rereads the scope statement before completing a form.
  • Answering the MFA question yes when deployment is partial. Eighty-one per cent have MFA on email; forty-four per cent have it on every administrative account. The question is about the second and the answer is usually based on the first.
  • Treating the included cover as your cyber insurance. The cover bundled with basic certification has a modest limit and is opt-in. It is a free floor, not a policy sized to your exposure.
  • Answering the proposal form from belief rather than evidence. Only about 12 per cent record their answers and the basis for them, which means the working that would support a claim does not exist.
  • Confusing backups existing with recovery being proven. Underwriters ask about tested restores within a stated timeframe. Forty-one per cent have tested; seventeen per cent documented it.
  • Not knowing the notification timeframe. Only around 14 per cent do. An organisation that contains an incident competently for a week and notifies afterwards may have prejudiced its own claim.
  • Expecting the certificate to answer detection questions. The scheme is largely preventative and says little about whether you would notice an intrusion. Underwriters care about that because it drives severity.
  • Starting evidence gathering days before renewal. Closing a gating control gap takes weeks, and MFA discovery across administrative accounts always surfaces surprises.
  • Letting the certificate lapse before the questionnaire. An expired certificate carries very little weight. Align the certification and insurance cycles once and the problem disappears.
Watch out

The most consequential version of these mistakes is a well-intentioned yes. Under the Insurance Act 2015 duty of fair presentation, a misrepresentation that was neither deliberate nor reckless still has proportionate remedies: an insurer may apply the terms it would have imposed with full information, or reduce a claim payment proportionately if it would have charged more. That means a claim can be paid at a fraction of its value because somebody ticked a box about MFA while thinking about the email rollout. The protection is precision rather than optimism — state partial deployments as partial, with numbers and dates. Underwriters handle partial deployments constantly; what damages you is the misdescription rather than the gap.

What this looks like in practice

A UK engineering consultancy with 75 staff across two offices held Cyber Essentials and had done for three years. Its cyber policy carried a £1m limit at a premium of about £2,400, and the finance director had been told at the previous renewal that certification was already reflected in the pricing. The business wanted better terms and assumed the route was Cyber Essentials Plus.

The dry run on a blank proposal form found three things before any money was spent. The certification scope covered the head office network only; the second office, added after an acquisition eighteen months earlier, had never been included, and nobody had noticed because the certificate was renewed by answering the same questions as the previous year. MFA was enforced on email and remote access but three of eleven administrative accounts were exempt, including a domain administrator used by an outsourced application supplier. And backups ran to a cloud repository reachable with the same administrative credentials as the production environment, with no immutable copy and no restore test on record since 2024.

On the existing policy, the proposal form from the previous renewal had recorded a yes against both the MFA question and a question about backup segregation. Neither answer had been deliberate misrepresentation — the person completing it had asked the outsourced IT provider, received a broadly positive answer, and recorded it. But had a ransomware incident occurred through the exempt administrator account, the insurer would have had grounds to examine both answers.

The remediation took nine weeks and cost approximately £5,100, almost all of it on controls rather than certification: MFA extended to all administrative accounts including a negotiated change with the application supplier, object lock enabled on the backup repository with separated administrative credentials, and a documented restore test. The certification scope was widened to include the second office at the next renewal, which raised the fee band slightly.

At renewal the premium came in at about £2,050 on the same £1m limit — a reduction, though a smaller one than the £5,100 spend, and the broker was explicit that part of it reflected a softer market rather than the controls alone. What the finance director judged more valuable was different: the answers on the form were now evidenced, the scope matched the insured entity, and the £1m of cover was considerably more likely to actually pay out. Cyber Essentials Plus was deferred as unnecessary for the current requirement.

We went in wanting a cheaper premium and came out with a policy that would probably have worked. The uncomfortable realisation was that for two years we had been paying for cover while having told the insurer things that were not quite right, entirely by accident, because nobody had ever checked the answers against what was actually configured. The saving was nice. Not having that exposure any more was the point.

Two points generalise. The first is that the dry run found everything, cost nothing, and would have been just as effective at any point in the previous three years. The second is that the premium reduction was real, modest, and not the main benefit — which is the honest shape of this relationship and the reason to be sceptical of any proposition that leads with a discount figure.

At a glance — certification and cyber insurance

Question Short answer
Does Cyber Essentials reduce cyber insurance premiums? Sometimes explicitly, but its main value is quotability and corroboration rather than a headline percentage
The three ways certification enters underwriting As a gate below which insurers decline, as corroboration of your self-declared answers, and occasionally as a stated rating factor
The control that most decides quotability Comprehensive MFA — on remote access, email and every administrative account
Why basic and Plus differ to an underwriter Same controls; Plus is independently tested rather than self-declared, which is what raises confidence
The free insurance with basic certification Real, opt-in, UK-domiciled under a turnover threshold, modest limit. A floor, not a policy.
Biggest hidden risk Certification scope narrower than described to the insurer — around three in ten certified organisations
Why accuracy is a legal matter The Insurance Act 2015 duty of fair presentation, with proportionate remedies even for innocent misrepresentation
How to answer a partially deployed control Precisely, with numbers and a completion date. Underwriters can price a known gap; they cannot price one found at claim stage.
What underwriters check beyond the certificate MFA specifics, backup architecture and tested restores, EDR, patching cadence, incident response, privileged access, supplier risk
Indicative costs Certification £320–600; Plus audit £1,400–3,500+; SME premium £500–3,000 at £250k–£1m limits
When to start preparing 8–12 weeks before renewal, beginning with a dry run of the proposal form
Where certification stops being sufficient Rising indemnity limits, complex estates, regulated sectors, and anything concerning detection rather than prevention
The cheapest high-value preparation Reread the scope statement, state MFA coverage precisely, document a timed restore test
Who should advise on the policy itself An FCA-authorised broker. This guide covers security and evidence, not cover selection.

How Cloudswitched approaches this

Cloudswitched takes UK organisations through Cyber Essentials and Cyber Essentials Plus, and where insurance terms are part of the motivation we work backwards from the proposal form rather than forwards from the certificate. In practice that means the dry run first, rereading the certification scope against the insured entity, closing the gating controls that decide quotability — comprehensive MFA, an immutable backup copy, endpoint detection and response — and producing the documented restore test and evidence pack a broker can actually use. We are not insurance advisers and do not arrange cover; what we do is make sure that when your broker asks a question, the answer is evidenced, precise and defensible two years later.

Make your certification worth something at renewal

We check your scope against what is being insured, close the controls underwriters gate on, and assemble evidence your broker can present — including saying where a certificate will not be enough.

Talk to a Cyber Essentials Specialist

Frequently Asked Questions

Does Cyber Essentials reduce cyber insurance premiums?

Sometimes, and not usually in the way it is marketed. Certification enters underwriting in three distinct ways: as a gate, because most insurers now have minimum control requirements below which they will not quote at all; as corroboration, because a certificate from an independent body raises confidence that your self-declared answers reflect reality; and occasionally as an explicit rating factor where a particular insurer or broker facility applies a stated reduction. The first two are where most of the value sits. Treat any specific discount percentage quoted in the abstract as one insurer’s appetite rather than a market rule.

What is the single most important control for getting cyber cover?

Comprehensive multi-factor authentication — on remote access, on email, and on every administrative account. It is asked about in virtually every proposal form and it frequently determines whether an insurer quotes at all rather than what they charge. The word that matters is comprehensive: around 81 per cent of UK SMEs have MFA on email, but only about 44 per cent have it enforced on every administrative account without exception, and administrative accounts are what an attacker needs. That gap is where most inaccurate proposal answers originate.

Is the free insurance included with Cyber Essentials enough?

No, and it is not intended to be. Basic certification includes cyber liability cover for UK-domiciled organisations below a turnover threshold, on an opt-in basis, with a modest indemnity limit. A single ransomware incident involving business interruption, forensic investigation and recovery will exceed that limit comfortably. Treat it as a free floor that comes with the certificate rather than as your cyber insurance, and size a proper policy against your actual exposure with a broker.

Does Cyber Essentials Plus get better insurance terms than basic?

Frequently, though not universally, and the reason is verification rather than the controls themselves. Both levels cover the same five control areas. Basic is self-assessed with the answers reviewed by a certification body; Plus involves a hands-on technical audit where somebody independent connects to sampled devices and tests. An underwriter reading a Plus certificate knows the controls were tested on a specific date, which is materially stronger than an assertion. If insurance terms are a primary driver, Plus is worth costing; if the driver is a contractual requirement to hold a certificate, basic is often sufficient.

What is the duty of fair presentation and why does it matter here?

Under the Insurance Act 2015, a business buying commercial insurance must fairly present the risk — disclosing every material circumstance it knows or ought to know, or enough to put a prudent insurer on notice to ask more. “Ought to know” extends to what a reasonable internal search would have revealed, so not having checked with your IT provider is not obviously a defence. If the duty is breached deliberately or recklessly an insurer may treat the policy as though it never existed. If it was neither, remedies are proportionate: the insurer may apply the terms it would have imposed, or reduce a claim payment proportionately. That middle outcome is the common one.

What happens if we answered a proposal question wrongly by accident?

It still has consequences, which is the point worth internalising. Innocent misrepresentation attracts proportionate remedies rather than outright avoidance, meaning a claim can be paid at a fraction of its value because the insurer would have charged more or imposed different terms with accurate information. The practical protection is precision rather than optimism. Where a control is partially deployed, say so with numbers and a completion date — underwriters deal with partial deployments constantly, and what damages you is the misdescription rather than the gap itself.

Why does our certification scope matter to an insurer?

Because certification can legitimately cover less than the whole organisation, and describing it as covering everything is a material misstatement. Around three in ten certified organisations we work with describe their certification more broadly than the scope statement supports, almost always innocently. The traps are organisational (which legal entity, which subsidiaries, which acquisitions), technical (excluded segments, sites, legacy systems, home working and personal devices) and temporal (a point-in-time assessment against an estate that has since changed). Reread the scope statement before completing any form, and disclose differences deliberately.

What do underwriters ask about that Cyber Essentials does not cover?

Several things. Specific MFA coverage rather than the general presence of it. Backup architecture, including whether an offline or immutable copy exists that a compromised administrator could not delete, and whether a restore has been tested within a stated timeframe. Endpoint detection and response as distinct from signature antivirus. Patching cadence with real timescales. A documented incident response plan including the insurer notification requirement. Privileged access separation. And supplier and third-party dependency, since a material share of incidents arrive that way. The scheme is largely preventative and says little about detection, which underwriters increasingly care about because it drives severity.

How long before renewal should we start preparing?

Eight to twelve weeks, and begin by completing a blank proposal form as a dry run with evidence attached to every answer. Twelve weeks is comfortable rather than generous: deploying MFA across administrative accounts in an estate that has never had it involves discovering accounts nobody remembered, service accounts that break when challenged, and usually one application that does not support it. That discovery process does not compress. Closing a gating control gap takes weeks, and evidence of a tested restore requires coordinating people.

What should we send our broker?

The certificate with its scope statement, the Plus audit report if you hold one, a written note of every difference between certified scope and insured entity, precise MFA coverage figures with any exception and its compensating controls documented, the backup architecture including the immutable copy, a documented restore test with a timing, endpoint protection detail, the incident response plan with the notification timeframe, the patching policy and training records — and a one-page covering summary written in business language for an underwriter rather than an engineer. That last item is what distinguishes a well-presented risk from a folder of attachments.

When is Cyber Essentials no longer enough?

As indemnity limits rise into the millions, insurers apply their own assessment: longer questionnaires, external attack-surface scanning conducted without your involvement, sometimes a technical call. Where the estate is larger or more complex — multiple operating companies, cloud platforms, bespoke applications, a substantial supplier chain — there are risks the five control areas do not reach. In regulated sectors and demanding supply chains, expectations often run to ISO 27001, SOC 2 reporting or penetration testing on a cycle, and certification becomes a prerequisite rather than an achievement. And anywhere detection rather than prevention is the question, the scheme is largely silent.

Should we get certification specifically to lower our insurance costs?

Only as a secondary motivation, because the arithmetic frequently does not support it on its own. Remediation to reach certification often costs more than the annual premium, so framing certification as an insurance saving gets the proportions wrong. The honest framing is that certification and the control work behind it reduce the probability and severity of an incident, that better insurance terms are a consequence of genuinely better controls, and that the largest benefit is often a policy considerably more likely to pay out when needed. Decisions about cover, limits and wording should go to an FCA-authorised broker; this guide is about getting the security and the evidence right.

Certification that holds up under scrutiny

Cloudswitched takes UK organisations through Cyber Essentials and Cyber Essentials Plus, closes the controls underwriters gate on, and produces evidence that is precise enough to defend a claim rather than merely tick a box.

Talk to a Cyber Essentials Specialist
Tags:Cyber Security
CloudSwitched

London-based managed IT services provider offering support, cloud solutions and cybersecurity for SMEs.

CloudSwitched Service

Cyber Essentials Certification

End-to-end Cyber Essentials Plus certification and ongoing security services

Learn More
CloudSwitchedCyber Essentials Certification
Explore Service

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

28
  • Cyber Security

Cyber Essentials and Insurance: A UK Business Guide to How Certification Affects Cyber Insurance Premiums in 2026

28 Sep, 2026

The idea that a Cyber Essentials certificate earns a cyber insurance discount is repeated so often that most UK businesses assume the relationship is a simple...

Read more
27
  • Google Ads & PPC

Google Ads Bidding Strategies: A UK Business Guide to Choosing Between Manual and Automated Bidding in 2026

27 Sep, 2026

Choosing a Google Ads bidding strategy is the decision most UK advertisers make least deliberately. It is usually made twice: once at setup, by accepting...

Read more
26
  • SEO

SEO Content Strategy: A UK Business Guide to Building Topic Authority Instead of Chasing Keywords in 2026

26 Sep, 2026

An SEO content strategy built one keyword at a time eventually starts working against itself. The mechanism is unglamorous and almost universal: a business...

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.