Do UK Businesses Need Penetration Testing for Cyber Insurance? Policy Conditions Explained

Do UK Businesses Need Penetration Testing for Cyber Insurance? Policy Conditions Explained

By EJN Labs · 11 Sep 2026 · 7 min read

No single law requires penetration testing before you can buy cyber insurance. Insurers set their own underwriting requirements, so whether a test is mandatory depends on the policy: some ask about it on the proposal form, others make it a condition for higher cover limits, and none of that removes your Insurance Act 2015 duty to present the risk accurately.

Why penetration testing comes up when you buy or renew cyber insurance

Penetration testing comes up because insurers price cyber cover on your actual exposure, and a report is one of the clearest ways to show what that exposure looks like. Underwriters ask broad questions about controls on proposal forms, and a recent test answers several at once with evidence rather than a tick-box.

Renewal is when this typically becomes concrete. Cyber policies are reassessed annually, and if your last submission described controls that have since changed, or a broker flags a gap during that review, testing evidence is the quickest way to close it before terms move against you. None of this is a regulatory trigger; the driver is commercial risk pricing, which is a separate question from whether a law obliges you to test at all.

Does UK law require a penetration test for cyber insurance cover?

No UK law requires a penetration test as a condition of buying or keeping cyber insurance. What the law does require is accuracy: the Insurance Act 2015 duty of fair presentation obliges a business to disclose material facts about its risk honestly, and that duty covers whatever you say about your security controls.

The two get conflated because they arrive in the same conversation. Nobody is legally obliged to commission a test, but the National Cyber Security Centre’s cyber insurance guidance notes that purchasing a policy may require providing information about your existing security controls, and warns that most policies are reassessed every 12 months with the onus on the insured to keep that information current. Get that wrong, and it is section 3 of the Insurance Act 2015, the duty of fair presentation, an insurer points to when declining a claim, not a testing rule you failed to follow.

What insurers actually ask for in the proposal form

Proposal forms typically ask about controls rather than naming a penetration test outright, covering authentication, patching, backups and any certification you hold. A test becomes explicit mainly at higher cover limits, in regulated sectors, or when a broker wants firmer evidence than a self-reported answer.

Cyber Essentials is one of the certifications insurers reference most often, since it gives underwriters a recognised baseline without asking their team to interpret a bespoke technical report. Some insurers offer a premium discount for holding it. Where a business handles significant customer data, takes payments, or sits in a supply chain a larger buyer audits, a broker will commonly push for a recent penetration test on top of certification, because certification alone does not show how a specific application or network behaves under attack.

How a penetration test for insurance evidence is typically scoped

A penetration test for insurance evidence is scoped around whichever systems the policy or questionnaire asks about, usually your external network and any customer-facing web application. Insurers want a report they can file against the proposal form, not a generic certificate.

A typical engagement starts with the questionnaire or renewal letter itself: which systems the insurer or broker wants covered, and by when. Scoping then follows the same pattern as any other engagement, an external infrastructure penetration test covering internet-facing systems, extended to a web application penetration test where customer data flows through a website or portal. Testing is carried out by a CREST-accredited firm, and the report is written so a broker or underwriter can read the executive summary without a technical background, with the detail available behind it for anyone who wants to check the work.

What does penetration testing for cyber insurance cost in the UK?

Penetration testing for cyber insurance evidence typically costs £3,300 to £7,000 in the UK market, covering an external infrastructure test of 3 to 5 days at £1,100 to £1,400 per day. Adding a customer-facing web application extends that to £5,500 to £11,200 across 5 to 8 days.

These are typical UK market ranges rather than a quote; the actual figure comes from scoping against your specific systems and whatever the insurer or broker has asked to see.

ScopeTypical effortTypical UK cost
External infrastructure test (insurance evidence)3 to 5 days£3,300 to £7,000
External infrastructure + web application5 to 8 days£5,500 to £11,200
Retest after remediation1 to 2 days£1,100 to £2,800

For a broader view of how UK penetration testing prices are put together, see our guide to penetration testing costs in the UK. Renewal timing matters here too: insurers and brokers commonly want a report dated within the last 12 months, so starting the engagement four to six weeks before your renewal date leaves room for remediation if the test turns up something significant.

How EJN Labs approaches penetration testing for cyber insurance

EJN Labs is a UK CREST-accredited penetration testing firm, certified to ISO 27001 and ISO 9001, and a licensed IASME Certification Body for Cyber Essentials. Testing is delivered by UK-based testers, working from your renewal letter so the report answers the points your insurer or broker has raised.

We scope engagements around the evidence gap you actually have: a broker asking for a recent third-party test, an underwriting question set referencing controls you have not yet evidenced, or simply wanting a current report on file before your renewal date arrives. The output is a report written for two audiences at once, technical enough for your IT team to action, and clear enough for a broker or underwriter to file against the questionnaire without translation. If you already hold Cyber Essentials or Cyber Essentials Plus, we build on it rather than duplicating ground it already covers.

Frequently Asked Questions

Does UK law require penetration testing to buy cyber insurance?

No. No UK statute or regulator requires a penetration test before a business can buy cyber insurance. Insurers set their underwriting questions, and the only legal requirement is the Insurance Act 2015 duty of fair presentation (section 3), requiring accurate disclosure of your security information, tested or not.

Will my cyber insurance claim be rejected without a penetration test?

Not simply for lacking a test. A claim is more commonly disputed when what you told the insurer about your controls does not match reality, a fair-presentation issue, not a missing-test issue. If your proposal form asked whether testing had been done and you answered inaccurately, that answer puts the claim at risk.

What evidence do cyber insurers actually accept?

Insurers and brokers commonly accept a penetration test report from a CREST-accredited firm, a summary for the proposal form, and evidence of an active certification such as Cyber Essentials. What satisfies an insurer varies, so check your renewal letter rather than assume one format fits every policy.

How much does penetration testing for cyber insurance cost in the UK?

An external infrastructure test for insurance evidence typically costs £3,300 to £7,000 in the UK market, based on 3 to 5 days at £1,100 to £1,400 per day. Adding a web application extends the scope to £5,500 to £11,200 across 5 to 8 days. Get a scoped quote for an exact figure.

How often do insurers expect penetration testing to be repeated?

Most cyber insurance policies are reassessed every 12 months, so a test dated within the last year is the useful benchmark rather than a one-off exercise. If your systems change materially between renewals, updating the evidence before the next renewal date is worth doing rather than waiting for the insurer to ask.

Get your evidence ready before your renewal date

If a broker or underwriter has asked for penetration testing evidence, or you would rather have it on file before the question arrives, we can scope an engagement around your renewal timeline. Get a CREST pentesting quote and we will give you a fixed price for the defined scope.

For related reading, see our guide: does GDPR require penetration testing? We also cover penetration testing for small business and what underwriters accept when a cyber insurance renewal asks for penetration testing.

Leave a Reply

Your email address will not be published. Required fields are marked *