Cyber Security
Cyber Essentials and Cyber Insurance: What Insurers Actually Look For
31 July 2026

Cyber Essentials is increasingly mentioned in the same breath as cyber insurance — and for good reason. The two are genuinely connected. Holding a valid Cyber Essentials certificate tells an insurer something meaningful about your baseline security posture, and many policies reflect that with reduced premiums or simplified underwriting.
But the relationship between certification and coverage is more nuanced than most businesses realise, and understanding where Cyber Essentials ends is just as important as getting it.
What Cyber Essentials actually covers
Cyber Essentials is a government-backed certification scheme that verifies five technical controls are in place at a point in time:
- Boundary firewalls and internet gateways — controlling what traffic can reach your network
- Secure configuration — systems set up securely rather than with default settings left unchanged
- User access control — accounts with only the permissions they need, and strong authentication for administrative access
- Malware protection — protection against malicious software on devices
- Patch management — software kept up to date, particularly for high-risk vulnerabilities
These are meaningful controls. They address the most common attack vectors and form the foundation of a defensible security posture. The NCSC estimates that Cyber Essentials addresses the vast majority of commodity cyber attacks.
Where Cyber Essentials ends
Cyber Essentials is a baseline, not a ceiling. There are several areas that fall outside its scope that insurers increasingly look at when assessing a claim:
Backup and recovery. Cyber Essentials does not verify that your backups work, that they are stored separately from your main network, or that you have tested a restoration. Many insurers ask specifically about backup testing and offsite copies — neither of which is addressed by the certification.
Incident response. Having a documented plan for what to do in the first hours of an incident is outside Cyber Essentials scope. Insurers expect one to exist and to be followed, including timely notification to them after an incident is discovered.
Staff awareness. Phishing and social engineering account for a significant proportion of successful attacks. Cyber Essentials does not assess whether your staff know how to recognise and report suspicious activity.
Supplier and supply chain controls. How your data is handled by the third parties you work with sits outside the certification boundary.
Cyber Essentials Plus
Cyber Essentials Plus adds independent technical verification to the self-assessed Cyber Essentials — an assessor tests your systems rather than taking your word for it. Some insurers treat Plus more favourably than the base certification because it provides external evidence rather than self-declaration. If your insurer asks specifically about Plus, it is worth understanding whether the step up affects your premium or underwriting terms.
The point-in-time problem
Cyber Essentials is an annual assessment. Your certificate is accurate on the day you are assessed. What happens between renewals is not tracked. A system added to your network three months after certification, a user account created without MFA, or a patch that slipped through — none of these invalidate your certificate, but all of them could give an insurer grounds to question whether the controls described in your policy application were actually in place at the time of an incident.
This is the gap that matters most in practice: the distance between what the certificate says and what your environment actually looks like today.
Using your assessment as ongoing evidence
The most useful thing Cyber Essentials can do for your insurance position is not the certificate itself — it is the discipline of treating your controls as something to be checked regularly rather than ticked annually.
The Technology Resilience Score™ gives you a continuous view of where your controls stand across backup and recovery, access management, staff awareness, device management, and incident preparedness — the areas that Cyber Essentials covers and the areas it does not. Your score tells you what your environment actually looks like today, not what it looked like at your last assessment.
If you hold Cyber Essentials and your TRS score is strong across the areas the certification does not cover, you are in a genuinely defensible position. If there are gaps, you know what they are and can close them before your next renewal — or your next incident.
Get your free Technology Resilience Score →
We are not insurance advisers. For guidance on your specific policy and how Cyber Essentials affects your coverage, speak to your broker or insurer directly.
Is your business's technology environment resilient?
Find out how prepared you really are to keep operating and recover quickly if disruption hits — with a free Technology Resilience Score™.