The idea that a Cyber Essentials certificate earns a cyber insurance discount is repeated so often that most UK businesses assume the relationship is a simple one: certify, present the certificate, pay less. The reality underwriters describe is different and more useful to understand. Certification mostly affects whether you are quoted at all, which questions on the proposal form you can answer favourably, and how much the insurer trusts your answers — and in 2026 there is one control that matters more to most underwriters than the certificate itself.
This guide covers the mechanics rather than the sales pitch. It explains how certification enters a premium calculation and what it does not do, the controls underwriters verify independently of any certificate and why multi-factor authentication has become the gate rather than a bonus, the duty of fair presentation that makes accuracy on a proposal form a legal matter rather than an administrative one, why the scope of your certification is the detail that most often causes trouble, where certification stops being sufficient as indemnity limits rise, and how to assemble an evidence pack that gets a broker the best terms available. The broader picture of what cover involves sits in our guides to cyber insurance for UK businesses and Cyber Essentials Plus and cyber insurance.
One framing note before starting. What follows is general information about how certification interacts with underwriting, written from the perspective of getting your security and evidence in order. It is not insurance advice, and decisions about cover, limits and policy wording belong with an FCA-authorised broker who can assess your circumstances.
How certification actually enters the premium calculation
A cyber premium starts from a base rate driven by things you largely cannot change: sector, turnover, the volume and sensitivity of data you hold, your claims history, and the indemnity limit and excess you want. Controls then modify that base, and this is where certification enters — but it enters in three distinct ways that are worth separating, because only one of them is a discount.
As a gate. Most insurers now operate minimum control requirements below which they will not quote at any price. If you cannot evidence multi-factor authentication on remote access and email, or you have no tested backup capability, a substantial share of the market simply declines. Certification helps here because achieving it forces several of those controls into place, so the practical benefit is access to the market rather than a reduction within it.
As corroboration. Underwriters are reading self-declared answers on a proposal form and have limited means to verify them. A certificate from an independent body raises confidence that the answers reflect reality. This is why Cyber Essentials Plus, which involves a hands-on technical audit, carries more weight than the self-assessed basic level — it is not that the controls differ substantially, it is that somebody independently tested them.
As a rating factor. Some insurers do apply an explicit reduction for certification, and some brokers have facilities where it is a stated condition of a preferential rate. The effect where it exists is real but usually modest relative to the base drivers, and it varies enough between insurers that a specific percentage should not be assumed. Anybody quoting you a fixed discount figure for certification in the abstract is describing one insurer’s appetite rather than a market rule.
The practical consequence of those three is that the value of certification is concentrated in the first two. Being quotable by more of the market, with answers the underwriter believes, produces better outcomes than chasing a headline percentage — and it is also the part that survives a change of insurer.
Before renewal, get a blank copy of the proposal form from your broker and complete it as a dry run, in writing, with evidence attached to each answer. Every question you cannot answer confidently is a specific piece of work with a deadline attached, and you will usually find two or three. Doing this eight to twelve weeks out converts renewal from an exercise in describing your security to an exercise in evidencing it — and it surfaces the gaps while there is still time to close them rather than during the week the quote is needed.
Certification and cyber cover in UK businesses — the numbers
The figures below reflect what we observe across UK organisations of 20 to 400 staff going through certification and cyber insurance renewal. They describe the SME band, where the interaction between the two is most consequential.
The first card is not a number because the answer is not a number. Multi-factor authentication on remote access, email and administrative accounts has become the control that decides quotability across much of the market. Organisations that have it are in a conversation about price; organisations that do not are frequently in a conversation about whether cover is available. Certification pushes you toward it, which is much of why certification helps.
The second card is the one most often misunderstood. Basic Cyber Essentials certification includes cyber liability cover for UK-domiciled organisations below a turnover threshold, on an opt-in basis, and the indemnity limit is modest. It is a genuine benefit and it is not a substitute for a policy sized to your actual exposure — a single ransomware incident with business interruption and recovery costs will exceed that limit comfortably. Treat it as a floor that comes free rather than as your cyber cover.
The third card is the one that carries the most risk and attracts the least attention, and the rest of this guide returns to it. Certification has a defined scope, that scope can legitimately be narrower than the whole organisation, and describing a partial certification as though it covered everything is a misrepresentation with consequences at claim time rather than a presentational nicety.
What underwriters check independently of the certificate
The chart below shows how often each control is specifically asked about or verified during UK SME cyber underwriting, based on proposal forms and broker questionnaires we work through with clients. Several of these go beyond what any certification level examines, which is why a certificate alone does not complete the picture.
Notice how the top three concern ransomware specifically. That reflects where claims cost sits: underwriters are pricing the probability and severity of an incident that encrypts your estate, and the questions that predict severity are about whether you can recover without paying. A tested restore is a different question from a backup existing, and the distinction is exactly the one insurers have learned to ask about — which is also the distinction covered in our guide to backup retention policy.
Endpoint detection and response at seventy-four per cent is the requirement that has moved fastest. Traditional signature-based antivirus, which satisfies the malware protection control in a certification context, is increasingly treated as insufficient by underwriters who want behavioural detection and the ability to respond on the endpoint. An organisation can therefore hold a valid certificate and still fall short of an insurer’s malware expectations, which surprises people who assume the certificate is the benchmark.
The incident response plan at sixty-three per cent is worth preparing for because it is cheap and frequently missing. Underwriters are not asking for a thick document; they want evidence that someone has decided in advance who does what, who is called, how the insurer is notified and within what period. Notification timeframes in particular matter, because late notification can prejudice a claim regardless of how good your controls were.
What certification and cover cost in the UK
The figures below are indicative UK costs for 2026, excluding VAT. Certification fees are set on turnover bands by the scheme and are published; audit and premium figures vary considerably with size, sector and the state of your controls, so treat them as sizing rather than quotations. Fuller certification pricing sits in our guide to Cyber Essentials cost in the UK.
| Item | Indicative UK cost | Frequency | Note |
|---|---|---|---|
| Cyber Essentials certification fee | £320–600 | Annual | Banded by turnover; self-assessed and independently reviewed |
| Cyber Essentials Plus audit | £1,400–3,500+ | Annual | Hands-on technical testing; scales with device and user count |
| Remediation to reach certification | £0–8,000 | Largely one-off | Depends entirely on current state; MFA and EDR are common gaps |
| Cyber insurance, £250k–£1m limit | £500–3,000 | Annual premium | SME band; varies widely by sector, data volume and controls |
| Cyber insurance, £2m–£5m limit | £3,000–15,000 | Annual premium | Fuller questionnaire, sometimes external scanning or interview |
The comparison that matters here is the third row against the fourth. Remediation to reach certification is frequently a larger number than the annual premium, which means framing certification as a way to save money on insurance gets the proportions wrong. The honest framing is that certification and the remediation behind it reduce the probability and severity of an incident, and that improved insurance terms are a secondary consequence of having genuinely better controls rather than the point of the exercise.
The step from the fourth row to the fifth is where the character of underwriting changes. At modest limits, a proposal form and a certificate frequently complete the process. At higher limits, insurers apply more scrutiny: longer questionnaires, external attack-surface scanning conducted without your involvement, sometimes a call with whoever is technically accountable. Certification remains useful at that level and stops being the main event.
On the remediation range, the zero at the bottom end is genuine. Organisations already running MFA, managed patching, EDR and tested backups may find certification is largely documentation and evidence gathering. Organisations without those will find the cost sits in the controls rather than the certificate, which is the correct place for it to sit.
Basic certification against Cyber Essentials Plus, from an underwriting view
The comparison below highlights Cyber Essentials Plus, specifically for its effect on underwriting rather than as a general recommendation. Both levels cover the same five control areas; what differs is how the claim to have implemented them is verified, and verification is precisely what an underwriter is buying. For organisations whose only driver is a contractual requirement to hold a certificate, basic remains a perfectly rational choice.
Cyber Essentials
Self-assessment, independently reviewed
Cyber Essentials Plus
Hands-on technical audit
The verification row is the whole distinction. An underwriter reading a basic certificate knows that an organisation answered a set of questions and that a certification body found the answers coherent. An underwriter reading a Plus certificate knows that somebody independent connected to sampled machines and checked. Where an insurer differentiates between the two — and not all do — that is the reason.
The evidence-at-claim row deserves care, because it is easily overstated. Neither certificate pays a claim, and neither prevents an insurer from investigating whether the controls you described were actually in place at the time of the incident. What a Plus audit provides is contemporaneous independent evidence that specific controls were tested on a specific date, which is a materially stronger position than an assertion. The detail of what that audit involves is covered in our guide to the Cyber Essentials Plus technical audit, and the broader choice between levels in our guide to Cyber Essentials against Cyber Essentials Plus.
One practical note on timing: both certifications are annual, and an expired certificate is worth very little at renewal. Aligning the certification cycle so the certificate is current and comfortably in date when the insurance renewal questionnaire is completed is a small piece of administration that occasionally makes a real difference.
Where businesses fall short of insurer expectations
The grid below groups the gaps we find when preparing UK organisations for a cyber renewal. The badges reflect how much each gap affects quotability or terms, rather than how serious a security weakness it represents in isolation.
The second card is where the consequences are most severe and least visible, and it is the subject of the next section. Every row in it describes a way of presenting your security position more favourably than the evidence supports — usually without any intention to mislead, because the person completing the form genuinely believes MFA is everywhere or that the certification covered the whole business.
The notification timeframe row in the third card is rated high deliberately. Policies specify a period within which an incident must be reported, and that period is frequently short. An organisation that suffers an incident on a Friday, spends a week containing it and notifies the insurer afterwards may have prejudiced its own claim while doing entirely sensible technical work. Knowing the number, and having it written where the incident responders will see it, costs nothing.
The supplier risk row reflects a direction of travel. Underwriters increasingly ask about dependency on third parties, because a material share of incidents arrive through a supplier rather than directly. Certification does not examine your suppliers, so this is another area where the certificate does not answer the question being asked.
The duty of fair presentation, and why accuracy is a legal matter
This is the part of the certification-and-insurance relationship that gets least attention and carries the most consequence. When a UK business buys commercial insurance, it does not simply answer questions; it owes the insurer a duty of fair presentation of the risk under the Insurance Act 2015. That duty is broader than not lying.
In practice it requires disclosure of every material circumstance you know or ought to know, or enough information to put a prudent insurer on notice that it should ask further questions, presented in a reasonably clear and accessible way. “Ought to know” is the phrase that matters, because it extends to what would have been revealed by a reasonable search of information available within the organisation. Not having asked your IT provider whether MFA is genuinely deployed everywhere is not obviously a defence.
The remedies if the duty is breached depend on the nature of the breach. Where it was deliberate or reckless, an insurer may treat the policy as though it never existed and keep the premium. Where it was neither, the remedy is proportionate to what the insurer would have done with full information: it may avoid the policy if it would not have written the risk at all, or apply the terms it would have imposed, or reduce a claim payment proportionately if it would have charged a higher premium. That middle outcome is the common one and it means a claim can be paid at a fraction of its value because of an answer nobody thought about carefully.
Why certification raises the stakes rather than lowering them
A certificate is a specific, documented, dated assertion about your controls. Presenting it supports your presentation of the risk — and it also creates a record that can be compared with reality after an incident. If the certificate scope covered your head office and the incident began on an uncertified subsidiary’s network, the mismatch is discoverable. Certification therefore makes an accurate presentation easier and an inaccurate one more exposed, which is the correct incentive but not the one people expect.
What good practice looks like
Answer the proposal form from evidence rather than belief, and keep the evidence. Record who answered each question, on what date, and what they relied on. Where a control is partially deployed, say so precisely — “MFA is enforced on all remote access and email, and on eleven of fourteen administrative accounts, with the remaining three scheduled for completion in October” is a far better answer than a yes or a no, and it is the kind of answer that protects a claim. Underwriters deal in partial deployments constantly; what damages you is not the gap but the misdescription.
And disclose material change during the policy period if the wording requires it. An acquisition, a new remote access route, a migration, the loss of a key control — these can be material, and the duty does not necessarily end at inception.
Scope is the detail that catches people
Cyber Essentials certification has a defined scope, and that scope can legitimately cover less than the whole organisation. A business may certify one office, one operating company, one network segment, or exclude a subsidiary. The scheme permits this and the certificate states what was covered.
The problem is what happens next. The certificate gets filed, the marketing team mentions it on the website, and eighteen months later somebody completing an insurance proposal form ticks the box saying the organisation holds Cyber Essentials without rereading the scope statement. Roughly three in ten certified organisations we work with describe their certification more broadly than the scope supports, almost always without any intention to mislead.
Three scope traps worth checking
The first is organisational. Group structures, subsidiaries, recently acquired businesses and trading names each raise the question of which legal entity was certified and which entity is being insured. If they are not the same, that is a material fact.
The second is technical. A scope that excluded a segment, a site, a set of legacy servers or a category of device means the controls were not assessed there. Home workers and bring-your-own-device arrangements are common exclusions, and they are also common incident routes, which is an unfortunate combination.
The third is temporal. Certification is a point-in-time assessment renewed annually. Substantial change since the assessment — a migration, a new remote access method, a merger — means the certificate describes an estate that has moved on.
None of these are reasons not to certify a subset; partial certification is often the sensible commercial choice. They are reasons to read your own scope statement before describing the certification to anybody, and to describe it in the terms the certificate actually uses. If the scope is narrow and the insurance covers the whole group, say that plainly — an underwriter can price a known gap and cannot price one they discover at claim stage.
Getting insurance-ready — twelve weeks before renewal
The sequence below assumes an existing policy approaching renewal and a business that wants better terms than last year. Working backwards from the renewal date is deliberate, because the binding constraint is how long control changes take to become evidenceable.
The item most often left too late is the restore test, because it requires coordination and somebody to be available. It is also among the most valuable things in the pack, since it converts the answer to the most heavily weighted severity question from an assertion into a documented fact with a date on it.
Twelve weeks is comfortable rather than generous. Deploying MFA across administrative accounts in an estate that has never had it involves discovering accounts nobody remembered, service accounts that break when challenged, and at least one application that does not support it. That discovery process is the reason this work does not compress well.
Benchmarks — control readiness against insurer expectations
The figures below show how often each control or artefact is genuinely in place across UK organisations of 20 to 400 staff at the point we begin renewal preparation. Readings are generous: a control counts as present if it exists anywhere in the estate, which is itself part of the problem.
Presence of insurer-expected controls in UK SMEs
The first two rows together describe the most common underwriting problem in the UK SME market. Eighty-one per cent have MFA on email, which is what most people mean when they say they have MFA. Forty-four per cent have it on every administrative account — and administrative accounts are what an attacker needs. The gap between those two numbers is where a confident yes on a proposal form turns into an inaccurate statement, because the person answering is thinking about the email rollout they remember.
Rows four and five are the same pattern in a different control. Forty-one per cent have tested a restore; seventeen per cent can produce a document showing what was restored, how long it took and when. Underwriters increasingly want the second, and the difference between them is an hour of writing at the time of the test rather than any additional technical work.
The bottom two rows are the process failures that make everything above harder to present well. Nineteen per cent reread the scope statement, so four in five describe a certification whose boundaries they have not checked. Twelve per cent evidence and record their proposal answers, which means the working that would support a claim two years later does not exist in most organisations. Both are free, and both are the difference between a defensible presentation and a hopeful one.
The number that decides quotability
If one control determines whether a UK SME can obtain cyber cover on reasonable terms in 2026, it is comprehensive multi-factor authentication — and the operative word is comprehensive, because partial deployment is where most organisations sit and it is not what underwriters are asking about.
Forty-four per cent means that a slight majority of organisations would, if the question were answered precisely, have to disclose an exception — a service account, a legacy application, a break-glass credential, an administrator on a system that does not support it. Those exceptions are frequently defensible and manageable. What is not manageable is answering yes and having the exception surface during a claim investigation into an incident that began with a compromised administrative credential.
The practical importance of this figure is that it is both the most weighted underwriting question and one of the cheapest gaps to close. MFA on administrative accounts is a configuration exercise rather than a purchase for most organisations already running Microsoft 365 or equivalent, and the work is mostly discovery — finding the accounts nobody remembered, and dealing with the one application that will not cooperate.
Where an exception genuinely cannot be removed, the answer is to document it, compensate for it — network restriction, monitoring, a long unique credential in a managed vault — and disclose it in those terms. An underwriter presented with “one legacy administrative account cannot support MFA; it is restricted to a single management network, credentials are vaulted and rotated, and access is logged and reviewed monthly” is being given something they can price. The same situation described as a yes is a problem stored up for later.
Where certification stops being sufficient
Cyber Essentials is a baseline, and it is deliberately designed as one. Understanding where it runs out prevents the disappointment of presenting a certificate to an underwriter who wants considerably more.
As indemnity limits rise
At modest limits a certificate and a proposal form frequently complete the underwriting process. As limits rise into the millions, insurers apply their own assessment: longer questionnaires, external attack-surface scanning performed without your involvement, sometimes a technical call. Certification remains a positive input and stops being the deciding one, and the gap between what the scheme examines and what the underwriter examines widens.
Where the estate is larger or more complex
The five control areas were designed for organisations that can reasonably describe their estate. A business with multiple sites, several operating companies, cloud platforms, bespoke applications and a substantial supplier chain has risks the scheme does not reach into: application security, privileged access management, logging and detection maturity, third-party dependency. Insurers pricing that risk will ask about those areas directly.
In regulated sectors and demanding supply chains
Financial services, healthcare and defence supply chains frequently expect more than a baseline — ISO 27001 certification, SOC 2 reporting, penetration testing on a defined cycle, or scheme-specific requirements. In these contexts Cyber Essentials functions as a prerequisite rather than an achievement, and its absence is disqualifying while its presence is unremarkable.
Where the controls exist but detection does not
The scheme is largely preventative. It says relatively little about whether you would notice an intrusion, how quickly, and what you would do. Underwriters increasingly care about detection and response because those determine severity rather than probability, and an organisation with excellent preventative controls and no monitoring has a certificate and an unanswered question. Independent testing is the usual way to evidence the gap between intended and actual security posture, and we cover that in our guide to what happens during a penetration test.
None of this diminishes the certificate. A baseline that is genuinely in place across a defined scope, independently tested at the Plus level, and accurately described is worth having and does improve your position. It simply is not a complete answer to the question an underwriter is asking, and treating it as one is how organisations arrive at renewal expecting a discount and receiving a questionnaire.
The 12-point evidence pack for your broker
Items one to four are the certification evidence. Items five to nine are the controls underwriters weight most heavily. Items ten to twelve are what turns a collection of documents into a presentation.
- The certificate itself, current and in date. Confirm it will remain valid through the policy period, and note the renewal date alongside the insurance renewal date so the two do not drift apart.
- The scope statement, read rather than filed. Which legal entity, which sites, which network segments, which device categories, and as at what date. This is the document that most often contradicts what people believe.
- The Cyber Essentials Plus audit report, if you hold it. Independent contemporaneous evidence that specific controls were tested on a specific date, which is a materially stronger position than an assertion.
- A written note of every difference between certified scope and insured entity. Subsidiaries, acquisitions, excluded segments, home working arrangements. Disclose these deliberately; an underwriter can price a known gap.
- Evidence of MFA coverage, stated precisely. Remote access, email and administrative accounts, with exact numbers where deployment is partial and a date for completion. Precision here protects a claim.
- Documentation of any MFA exception and its compensating controls. Network restriction, vaulted credentials, logging and review. Described this way it is priceable; described as a yes it is a stored-up problem.
- Backup architecture description including the offline or immutable copy. What is backed up, where the copies live, and which copy could not be deleted by a compromised administrator.
- A documented restore test with a timing. What was restored, how long it took, when, and who witnessed it. Only about 17 per cent of organisations can produce this, and it answers the most heavily weighted severity question.
- Endpoint protection detail. Which product, what coverage across the device estate, and whether it provides behavioural detection and response rather than signature matching alone.
- The incident response plan, including the insurer notification timeframe. Short and usable. The notification requirement written where responders will actually see it, because late notification can prejudice a claim regardless of controls.
- Patching policy with stated timescales, and training records. The cadence you actually operate rather than an aspiration, plus evidence that staff have had security awareness training within a reasonable period.
- A one-page covering summary written for an underwriter. Business language, the controls in place, the known gaps and what is being done about them. This is the document that distinguishes a well-presented risk from a folder of attachments.
If only three items are prepared, make them two, five and eight. The scope statement prevents the most common misrepresentation. Precise MFA coverage answers the question that decides quotability, and stating it precisely rather than as a yes is what protects a claim. And the documented restore test converts the most heavily weighted severity question from an assertion into a dated fact. Together they are perhaps a day of work and they address the three areas where presentations most often fail.
Insurance readiness — where most certified organisations sit
Combining the assessment areas gives an indication of how well an organisation would present at a cyber renewal today, including those that already hold certification. The gauge reflects a first review of a certified UK business of 20 to 400 staff approaching renewal without preparation.
A score around forty is higher than several of the benchmarks in this series, and the reason is the certification itself: an organisation that has certified has necessarily addressed the five control areas to some degree, which puts a floor under the score. What drags it down is the difference between having controls and being able to evidence them precisely, plus the scope and representation issues that certification does nothing to prevent.
The composition is consistent. Preventative controls score reasonably. MFA scores well on email and poorly on administrative accounts. Backup existence scores moderately and tested documented recovery scores badly. Detection and response scores poorly because the scheme does not require it. Process and evidence — the scope statement, the recorded proposal answers, the known notification timeframe — score worst, and they are the cheapest to fix.
Worth stating plainly: a low score here is not an argument that certification was a waste. It is an argument that certification and insurance readiness are overlapping rather than identical exercises, and that the gap between them is mostly evidence and precision rather than additional security spending. An organisation at forty can usually reach the seventies in a few weeks without buying anything beyond possibly EDR.
Common mistakes at the certification and insurance intersection
The errors below recur across UK renewals. Almost none are security failures; they are presentation and process failures, which is what makes them both cheap to avoid and easy to miss.
- Assuming certification produces a headline discount. Its main value is quotability and corroboration, not a percentage. Some insurers apply an explicit reduction, it varies, and building a business case on an assumed figure is unwise.
- Describing certification more broadly than the scope supports. Roughly three in ten certified organisations do this, almost always innocently, because nobody rereads the scope statement before completing a form.
- Answering the MFA question yes when deployment is partial. Eighty-one per cent have MFA on email; forty-four per cent have it on every administrative account. The question is about the second and the answer is usually based on the first.
- Treating the included cover as your cyber insurance. The cover bundled with basic certification has a modest limit and is opt-in. It is a free floor, not a policy sized to your exposure.
- Answering the proposal form from belief rather than evidence. Only about 12 per cent record their answers and the basis for them, which means the working that would support a claim does not exist.
- Confusing backups existing with recovery being proven. Underwriters ask about tested restores within a stated timeframe. Forty-one per cent have tested; seventeen per cent documented it.
- Not knowing the notification timeframe. Only around 14 per cent do. An organisation that contains an incident competently for a week and notifies afterwards may have prejudiced its own claim.
- Expecting the certificate to answer detection questions. The scheme is largely preventative and says little about whether you would notice an intrusion. Underwriters care about that because it drives severity.
- Starting evidence gathering days before renewal. Closing a gating control gap takes weeks, and MFA discovery across administrative accounts always surfaces surprises.
- Letting the certificate lapse before the questionnaire. An expired certificate carries very little weight. Align the certification and insurance cycles once and the problem disappears.
The most consequential version of these mistakes is a well-intentioned yes. Under the Insurance Act 2015 duty of fair presentation, a misrepresentation that was neither deliberate nor reckless still has proportionate remedies: an insurer may apply the terms it would have imposed with full information, or reduce a claim payment proportionately if it would have charged more. That means a claim can be paid at a fraction of its value because somebody ticked a box about MFA while thinking about the email rollout. The protection is precision rather than optimism — state partial deployments as partial, with numbers and dates. Underwriters handle partial deployments constantly; what damages you is the misdescription rather than the gap.
What this looks like in practice
A UK engineering consultancy with 75 staff across two offices held Cyber Essentials and had done for three years. Its cyber policy carried a £1m limit at a premium of about £2,400, and the finance director had been told at the previous renewal that certification was already reflected in the pricing. The business wanted better terms and assumed the route was Cyber Essentials Plus.
The dry run on a blank proposal form found three things before any money was spent. The certification scope covered the head office network only; the second office, added after an acquisition eighteen months earlier, had never been included, and nobody had noticed because the certificate was renewed by answering the same questions as the previous year. MFA was enforced on email and remote access but three of eleven administrative accounts were exempt, including a domain administrator used by an outsourced application supplier. And backups ran to a cloud repository reachable with the same administrative credentials as the production environment, with no immutable copy and no restore test on record since 2024.
On the existing policy, the proposal form from the previous renewal had recorded a yes against both the MFA question and a question about backup segregation. Neither answer had been deliberate misrepresentation — the person completing it had asked the outsourced IT provider, received a broadly positive answer, and recorded it. But had a ransomware incident occurred through the exempt administrator account, the insurer would have had grounds to examine both answers.
The remediation took nine weeks and cost approximately £5,100, almost all of it on controls rather than certification: MFA extended to all administrative accounts including a negotiated change with the application supplier, object lock enabled on the backup repository with separated administrative credentials, and a documented restore test. The certification scope was widened to include the second office at the next renewal, which raised the fee band slightly.
At renewal the premium came in at about £2,050 on the same £1m limit — a reduction, though a smaller one than the £5,100 spend, and the broker was explicit that part of it reflected a softer market rather than the controls alone. What the finance director judged more valuable was different: the answers on the form were now evidenced, the scope matched the insured entity, and the £1m of cover was considerably more likely to actually pay out. Cyber Essentials Plus was deferred as unnecessary for the current requirement.
We went in wanting a cheaper premium and came out with a policy that would probably have worked. The uncomfortable realisation was that for two years we had been paying for cover while having told the insurer things that were not quite right, entirely by accident, because nobody had ever checked the answers against what was actually configured. The saving was nice. Not having that exposure any more was the point.
Two points generalise. The first is that the dry run found everything, cost nothing, and would have been just as effective at any point in the previous three years. The second is that the premium reduction was real, modest, and not the main benefit — which is the honest shape of this relationship and the reason to be sceptical of any proposition that leads with a discount figure.
At a glance — certification and cyber insurance
| Question | Short answer |
|---|---|
| Does Cyber Essentials reduce cyber insurance premiums? | Sometimes explicitly, but its main value is quotability and corroboration rather than a headline percentage |
| The three ways certification enters underwriting | As a gate below which insurers decline, as corroboration of your self-declared answers, and occasionally as a stated rating factor |
| The control that most decides quotability | Comprehensive MFA — on remote access, email and every administrative account |
| Why basic and Plus differ to an underwriter | Same controls; Plus is independently tested rather than self-declared, which is what raises confidence |
| The free insurance with basic certification | Real, opt-in, UK-domiciled under a turnover threshold, modest limit. A floor, not a policy. |
| Biggest hidden risk | Certification scope narrower than described to the insurer — around three in ten certified organisations |
| Why accuracy is a legal matter | The Insurance Act 2015 duty of fair presentation, with proportionate remedies even for innocent misrepresentation |
| How to answer a partially deployed control | Precisely, with numbers and a completion date. Underwriters can price a known gap; they cannot price one found at claim stage. |
| What underwriters check beyond the certificate | MFA specifics, backup architecture and tested restores, EDR, patching cadence, incident response, privileged access, supplier risk |
| Indicative costs | Certification £320–600; Plus audit £1,400–3,500+; SME premium £500–3,000 at £250k–£1m limits |
| When to start preparing | 8–12 weeks before renewal, beginning with a dry run of the proposal form |
| Where certification stops being sufficient | Rising indemnity limits, complex estates, regulated sectors, and anything concerning detection rather than prevention |
| The cheapest high-value preparation | Reread the scope statement, state MFA coverage precisely, document a timed restore test |
| Who should advise on the policy itself | An FCA-authorised broker. This guide covers security and evidence, not cover selection. |
How Cloudswitched approaches this
Cloudswitched takes UK organisations through Cyber Essentials and Cyber Essentials Plus, and where insurance terms are part of the motivation we work backwards from the proposal form rather than forwards from the certificate. In practice that means the dry run first, rereading the certification scope against the insured entity, closing the gating controls that decide quotability — comprehensive MFA, an immutable backup copy, endpoint detection and response — and producing the documented restore test and evidence pack a broker can actually use. We are not insurance advisers and do not arrange cover; what we do is make sure that when your broker asks a question, the answer is evidenced, precise and defensible two years later.
Make your certification worth something at renewal
We check your scope against what is being insured, close the controls underwriters gate on, and assemble evidence your broker can present — including saying where a certificate will not be enough.
Talk to a Cyber Essentials SpecialistFrequently Asked Questions
Does Cyber Essentials reduce cyber insurance premiums?
Sometimes, and not usually in the way it is marketed. Certification enters underwriting in three distinct ways: as a gate, because most insurers now have minimum control requirements below which they will not quote at all; as corroboration, because a certificate from an independent body raises confidence that your self-declared answers reflect reality; and occasionally as an explicit rating factor where a particular insurer or broker facility applies a stated reduction. The first two are where most of the value sits. Treat any specific discount percentage quoted in the abstract as one insurer’s appetite rather than a market rule.
What is the single most important control for getting cyber cover?
Comprehensive multi-factor authentication — on remote access, on email, and on every administrative account. It is asked about in virtually every proposal form and it frequently determines whether an insurer quotes at all rather than what they charge. The word that matters is comprehensive: around 81 per cent of UK SMEs have MFA on email, but only about 44 per cent have it enforced on every administrative account without exception, and administrative accounts are what an attacker needs. That gap is where most inaccurate proposal answers originate.
Is the free insurance included with Cyber Essentials enough?
No, and it is not intended to be. Basic certification includes cyber liability cover for UK-domiciled organisations below a turnover threshold, on an opt-in basis, with a modest indemnity limit. A single ransomware incident involving business interruption, forensic investigation and recovery will exceed that limit comfortably. Treat it as a free floor that comes with the certificate rather than as your cyber insurance, and size a proper policy against your actual exposure with a broker.
Does Cyber Essentials Plus get better insurance terms than basic?
Frequently, though not universally, and the reason is verification rather than the controls themselves. Both levels cover the same five control areas. Basic is self-assessed with the answers reviewed by a certification body; Plus involves a hands-on technical audit where somebody independent connects to sampled devices and tests. An underwriter reading a Plus certificate knows the controls were tested on a specific date, which is materially stronger than an assertion. If insurance terms are a primary driver, Plus is worth costing; if the driver is a contractual requirement to hold a certificate, basic is often sufficient.
What is the duty of fair presentation and why does it matter here?
Under the Insurance Act 2015, a business buying commercial insurance must fairly present the risk — disclosing every material circumstance it knows or ought to know, or enough to put a prudent insurer on notice to ask more. “Ought to know” extends to what a reasonable internal search would have revealed, so not having checked with your IT provider is not obviously a defence. If the duty is breached deliberately or recklessly an insurer may treat the policy as though it never existed. If it was neither, remedies are proportionate: the insurer may apply the terms it would have imposed, or reduce a claim payment proportionately. That middle outcome is the common one.
What happens if we answered a proposal question wrongly by accident?
It still has consequences, which is the point worth internalising. Innocent misrepresentation attracts proportionate remedies rather than outright avoidance, meaning a claim can be paid at a fraction of its value because the insurer would have charged more or imposed different terms with accurate information. The practical protection is precision rather than optimism. Where a control is partially deployed, say so with numbers and a completion date — underwriters deal with partial deployments constantly, and what damages you is the misdescription rather than the gap itself.
Why does our certification scope matter to an insurer?
Because certification can legitimately cover less than the whole organisation, and describing it as covering everything is a material misstatement. Around three in ten certified organisations we work with describe their certification more broadly than the scope statement supports, almost always innocently. The traps are organisational (which legal entity, which subsidiaries, which acquisitions), technical (excluded segments, sites, legacy systems, home working and personal devices) and temporal (a point-in-time assessment against an estate that has since changed). Reread the scope statement before completing any form, and disclose differences deliberately.
What do underwriters ask about that Cyber Essentials does not cover?
Several things. Specific MFA coverage rather than the general presence of it. Backup architecture, including whether an offline or immutable copy exists that a compromised administrator could not delete, and whether a restore has been tested within a stated timeframe. Endpoint detection and response as distinct from signature antivirus. Patching cadence with real timescales. A documented incident response plan including the insurer notification requirement. Privileged access separation. And supplier and third-party dependency, since a material share of incidents arrive that way. The scheme is largely preventative and says little about detection, which underwriters increasingly care about because it drives severity.
How long before renewal should we start preparing?
Eight to twelve weeks, and begin by completing a blank proposal form as a dry run with evidence attached to every answer. Twelve weeks is comfortable rather than generous: deploying MFA across administrative accounts in an estate that has never had it involves discovering accounts nobody remembered, service accounts that break when challenged, and usually one application that does not support it. That discovery process does not compress. Closing a gating control gap takes weeks, and evidence of a tested restore requires coordinating people.
What should we send our broker?
The certificate with its scope statement, the Plus audit report if you hold one, a written note of every difference between certified scope and insured entity, precise MFA coverage figures with any exception and its compensating controls documented, the backup architecture including the immutable copy, a documented restore test with a timing, endpoint protection detail, the incident response plan with the notification timeframe, the patching policy and training records — and a one-page covering summary written in business language for an underwriter rather than an engineer. That last item is what distinguishes a well-presented risk from a folder of attachments.
When is Cyber Essentials no longer enough?
As indemnity limits rise into the millions, insurers apply their own assessment: longer questionnaires, external attack-surface scanning conducted without your involvement, sometimes a technical call. Where the estate is larger or more complex — multiple operating companies, cloud platforms, bespoke applications, a substantial supplier chain — there are risks the five control areas do not reach. In regulated sectors and demanding supply chains, expectations often run to ISO 27001, SOC 2 reporting or penetration testing on a cycle, and certification becomes a prerequisite rather than an achievement. And anywhere detection rather than prevention is the question, the scheme is largely silent.
Should we get certification specifically to lower our insurance costs?
Only as a secondary motivation, because the arithmetic frequently does not support it on its own. Remediation to reach certification often costs more than the annual premium, so framing certification as an insurance saving gets the proportions wrong. The honest framing is that certification and the control work behind it reduce the probability and severity of an incident, that better insurance terms are a consequence of genuinely better controls, and that the largest benefit is often a policy considerably more likely to pay out when needed. Decisions about cover, limits and wording should go to an FCA-authorised broker; this guide is about getting the security and the evidence right.
Related reading
More guidance on securing, testing and governing UK business IT:
Certification that holds up under scrutiny
Cloudswitched takes UK organisations through Cyber Essentials and Cyber Essentials Plus, closes the controls underwriters gate on, and produces evidence that is precise enough to defend a claim rather than merely tick a box.
Talk to a Cyber Essentials Specialist