Facing a contract or tender that demands proof of insurance?
Many owners and directors of micro and small UK businesses worry about cost and delays.
They also wonder whether a policy will meet the clause while trading continues.
Process summary
This section lists the steps to meet a contractual insurance requirement and the typical timing for each.
Read the clause carefully and note limits, retroactive dates and named parties.
Gather existing policy documents and any Cyber Essentials certificate for quick proof.
Engage a broker, get an insurer letter or binder, or propose a redraft if cover is unavailable.
Act now to avoid losing the contract opportunity.
Key actions
- Check contract for limits, perils and special wording.
- Ask your broker for a written confirmation referencing the clause.
- If needed, obtain Cyber Essentials and request quotes for cover.
If time is tight, ask for an interim binder while full wording follows.
Quick evidence list
A current policy schedule, an insurer or broker letter on headed paper, and a Cyber Essentials or Cyber Essentials Plus certificate usually convince procurement teams.
A simple certificate of insurance alone rarely suffices because it omits exclusions and retroactive wording.
If time is tight, a binder or insurer confirmation can act as interim proof while the full policy issues.
A practical, costed timetable helps SMEs plan and budget rather than merely estimating ranges.
Act now to avoid losing the contract opportunity.
-
A typical 6‑week programme might look like:
-
Week 1: clause review and broker briefing (broker fee £100–£400, internal time 4–8 hours).
-
Week 2: Cyber Essentials self‑assessment and assessor booking (assessor fee £150–£600, 1–3 days for documentation).
-
Weeks 3–4: remedial controls, MFA and patching evidence (IT contractor £200–£1,200 depending on scope, staff time variable).
-
Week 4–5: broker market submission and insurer queries (placement fee or broker commission, plus any admin fees; expect 3–10 working days for SME markets).
-
Week 6: binder or insurer confirmation and policy issue (if bespoke wording required allow extra 1–3 weeks).
Typical out‑of‑pocket costs for a microbusiness preparing to meet a standard procurement clause are often between £400 and £2,000 before the first year’s premium.
First‑year premiums for small business insurance commonly range from £150 to £3,000 depending on limits and sector.
This breakdown shows where time and money are spent and where an SME can choose lower‑cost mitigations like a higher excess or an interim binder.
Step 1: read the clause
On first read, identify the contract elements that affect insurance procurement.
Look for minimum limits, required perils such as ransomware or third‑party liability, retroactive dates, and any insurer standards.
Note any additional insureds, waiver of subrogation, or indemnity wording which can change underwriting decisions.
Act now to avoid losing the contract opportunity.
What to check
Check whether the policy must be claims‑made or occurrence and the retroactive date asked by the buyer.
Check whether the buyer demands a specific insurer rating or that the insurer be UK‑regulated.
Check for operational requirements in the contract, such as mandatory MFA or patching schedules.
Practical examples
If the clause asks for a £1m limit but the contract value is £30k, propose a proportionate limit tied to the contract value.
If the buyer names the client as an additional insured, ensure the insurer accepts that wording before signing.
If the clause demands Cyber Essentials Plus plan timing: certification can add 1–3 weeks to the schedule.
Step 2: evidence and proof
The clearest proof is a policy schedule plus a written insurer or broker confirmation that references the contract clause.
Cyber Essentials or Cyber Essentials Plus supports the case but usually does not replace a policy for limits above small thresholds.
Certificates of insurance without wording are risky and procurement teams often ask for policy wording or explicit insurer confirmation.
Act now to avoid losing the contract opportunity.
Documents clients accept
A current policy schedule showing insured perils, limits and period is the primary document buyers accept.
An insurer letter on headed paper that states the policy covers the clause wording is second best and widely accepted.
A Cyber Essentials certificate may allow faster placement with some underwriters but normally acts as supporting evidence only.
Broker and insurer letters
A broker can supply a short insurer confirmation or a binder that commits cover for a short period.
A common binder term from insurers is 30 days and that gives time to issue a full policy and satisfy many procurement teams.
Use a written letter that explicitly references the contract clause, the policy number, and the limits being relied upon.
Sample insurer confirmation (editable):
[Insurer Letterhead]
Date: [DD/MM/YYYY]
To whom it may concern,
Insurer confirms policy number [XXXXX] issued to [Supplier Name] provides insurance including first and third party cover, subject to standard policy terms, with a limit of £[LIMIT] in the period [DD/MM/YYYY] to [DD/MM/YYYY].
This confirmation is issued to assist [Supplier Name] in meeting the contract dated [DD/MM/YYYY] with [Buyer].
Signed,
[Authorised signatory]

Insurer appetite for Cyber Essentials differs by market and requested limit, so a short market map clarifies expectations.
Many mainstream UK insurers and some Lloyd's syndicates will accept Cyber Essentials as underwriting mitigation for low to modest limits, commonly up to £250k–£1m.
Cyber Essentials Plus is more persuasive for higher SME limits because of on‑site or evidence‑based verification.
Specialist MGAs and cyber carriers are more likely to accept CE for placements where standard market carriers insist on higher controls.
Large corporate markets usually require more than CE and will ask for documented controls, penetration tests or ISO 27001 evidence.
Given this variation, always secure written insurer confirmation or an insurance binder that states whether CE or CE Plus satisfies the condition and for what limit.
Do not rely on a verbal assurance from a broker.
An insurer confirmation or binder that names the policy number, limit and the clause being satisfied is the procurement evidence most buyers will accept.
Step 3: get cover or negotiate
If the required cover exists and is affordable, obtain quotes and secure a binder or insurer letter before signing the contract.
If the cover is unavailable or unaffordable, propose an amendment tying cover to contract value and allowing interim evidence.
If the buyer refuses to amend, weigh the commercial value of the contract against the premium and excess increases.
Act now to avoid losing the contract opportunity.
Timelines and costs
Cyber Essentials certification typically takes days to a few weeks and costs about £150–£1,200 depending on scope and assessor.
A basic SME cyber policy may cost £150–£800 per year for low limits and standard cover.
Small SMEs with larger limits should budget £500–£3,000 or more.
Underwriting and placement for bespoke wording commonly take 2–6 weeks from broker submission to policy issue.
Model clause redrafts
Below are practical redrafts that balance buyer needs and SME affordability.
Buyer request (example):
"Supplier shall maintain insurance with limits of £1,000,000 for the duration of the contract."
Suggested SME redraft:
"Supplier shall maintain insurance proportionate to the contract value, not exceeding £[X]. Supplier may provide a policy schedule or an insurer confirmation letter within 10 business days. If full cover is not available the parties will negotiate a reasonable alternative in good faith."
| Clause element |
Typical buyer ask |
SME proposal |
| Limit |
£1,000,000 |
Limit tied to contract value or capped at £[X] |
| Evidence |
Certificate of insurance |
Policy schedule or insurer letter within 10 days |
| Control proof |
Cyber Essentials Plus mandatory |
Cyber Essentials accepted as mitigation, CE Plus for higher limits |
Which insurers accept cyber essentials
Many UK insurers and Lloyd's syndicates accept Cyber Essentials as part of underwriting for SME placements, but acceptance depends on limit and insurer appetite.
A market list often includes Hiscox, Aviva, Zurich, and several Lloyd's syndicates, and specialist MGAs that focus on SME cyber.
Always get written confirmation from the underwriter that Cyber Essentials or Cyber Essentials Plus meets their condition for the requested limit.
Estimated time to produce acceptable evidence: obtain Cyber Essentials in 3–14 days. Secure a broker quote in 3–10 days. Receive a binder or insurer letter in 2–6 weeks depending on wording and underwriting checks.
When a buyer imposes insurance the legal and risk transfer consequences need clear attention.
Clauses that ask to name the buyer as an "additional insured" can create third‑party rights and may require an endorsement.
Insurers routinely check and sometimes refuse this wording unless negotiated.
Waiver of subrogation provisions prevent the insurer from pursuing the buyer after they pay a claim and many policies exclude or charge extra for such waivers.
An SME should secure written insurer confirmation that any requested waiver is effective.
Contractual indemnities that seek to make the supplier liable for the buyer’s negligence or regulatory fines can be uninsurable or subject to policy exclusions.
Primary fines or certain statutory penalties are often expressly excluded, though defence and response costs may be covered.
Claims‑made policies require careful attention to retroactive dates because a retroactive date later than the incident date can nullify cover for historic acts.
In these situations obtain an insurer confirmation referencing the precise clause text and negotiate caps, carve‑outs or staged liability where needed.
Act now to avoid losing the contract opportunity.
Common errors that ruin compliance
The most frequent mistake is assuming a Cyber Essentials certificate alone satisfies an insurance clause.
Another common error is presenting a certificate of insurance without accompanying policy wording or a signed insurer letter.
Late engagement with a broker often forces rushed placement at higher premiums or failed tenders.
Mistakes to avoid
Do not assume a standard policy covers contractual indemnities or a waiver of subrogation because these often need specific cover or endorsements.
Do not sign the contract before confirming the insurer accepts named parties and the clause wording.
Do not delay evidence submission; many tenders fail because procurement requires proof within 10–14 days and the SME had not started placement.
Real-life consequences
A case example: a small IT firm accepted a £300k contract and presented a certificate of insurance only.
The firm later discovered the policy excluded ransomware losses related to third‑party claims.
The client withheld payment until a claim was resolved, causing cashflow stress that lasted 6 weeks.
The error above shows why the policy schedule and insurer endorsement matter more than a simple certificate.
Correction: The Insurance Act 2015 updated the duty of fair presentation and replaced automatic 'basis of contract' avoidance with proportionate remedies.
Material non‑disclosure or misrepresentation can lead to insurer remedies like avoidance, proportionate reduction or different terms depending on the facts.
SMEs should make a fair presentation, disclose material facts to their broker and obtain written underwriting confirmations rather than assume avoidance is the only outcome.
The following paragraph summarises the recommended position and its limit: the firm should get an insurer confirmation before signature or negotiate a short evidence window to avoid exposure.
The evidence points to a clear rule: do not rely on certificates alone when the contract value or client demands are material.
This works well in theory. In practice, underwriters will query controls like MFA, patching and backups and may demand proof.
That process can add 1–3 weeks to placement.
A practical course of action is to get Cyber Essentials fast, use a broker to obtain an insurer letter, and accept a higher excess to keep premium affordable.
This approach secures the contract while limiting cash outlay, but needs prompt evidence and honest disclosures to avoid later denial of cover.
When this method does not work
Some contracts ask for cover types or limits beyond the reach of microbusinesses, so negotiation becomes the only practical option.
If the buyer only asks for a simple risk assessment rather than insurance, buying an expensive policy may be unnecessary and wasteful.
If the SME handles no customer personal data and the contract's insurance demand is generic, push to narrow the clause rather than buy cover that is not needed.
Act now to avoid losing the contract opportunity.
Alternatives to insurance
Propose a hosting or subcontractor warranty, an indemnity cap tied to contract value, or a staged acceptance of liability with an agreed review after 12 months.
Consider offering a remediation plan plus Cyber Essentials as a mitigation package when full cover is unaffordable.
Explore captive, parametric or bonded approaches only when traditional markets refuse cover because those options are complex and may not suit microbusinesses.
When to negotiate out
Negotiate out when the demanded limits exceed reasonableness compared to contract value or when cover requires business changes that cannot be completed within weeks.
Ask to replace a blanket £1m requirement with wording proportional to the contract and allow interim binder proof for a limited period.
If negotiations fail decline the contract rather than accept open‑ended uncapped liabilities that are uninsured.
Contracts that require limits or policies clearly disproportionate to the contract value, or that demand cover for regulatory fines not insurable under UK law, are not suitable for this method. In those cases propose proportional limits, staged remedies, or financial caps on liability. If the buyer insists on unattainable cover the SME should negotiate alternative risk transfer or walk away.
If the contract deadline is within two weeks, contact a specialist broker immediately to request a binder and insurer confirmation while undertaking any required Cyber Essentials assessment.
Frequently asked questions
Can cyber essentials alone satisfy a buyer?
Cyber Essentials alone rarely satisfies a contractual insurance requirement for significant limits.
It shows basic controls and helps with underwriting, but procurement usually asks for an insurer letter or policy schedule for insurance proof.
For low limits some buyers accept CE Plus and an insurer confirmation, but always confirm this in writing with the buyer or broker.
What is acceptable as 'proof of insurance'?
A policy schedule plus an insurer confirmation that references the clause is the accepted proof.
A certificate of insurance without wording is often insufficient because it omits exclusions and retroactive cover.
An insurer binder or broker letter on headed paper is acceptable as interim evidence while full policy documents follow.
How long does it take to get cover?
Cyber Essentials can be obtained in 3–14 days depending on assessor availability and internal controls.
A bespoke cyber policy with special wording usually needs 2–6 weeks for underwriting and issuance.
If controls or remediation are required add 1–4 weeks for evidence collection and re‑underwriting.
What are typical premiums and excesses?
Micro SMEs can expect premiums from about £150 to £800 per year for low limits and standard cover.
Small SMEs with higher limits should budget £500–£3,000 plus depending on revenue, sector and ransom exposure.
Excesses commonly start at £500–£2,500 and rise with lower premiums or higher limits.
What to do if the buyer demands impossible
Propose a redraft tying limits to contract value and allowing a 10–14 day evidence period with an interim binder.
Offer mitigation such as Cyber Essentials Plus and a higher excess to align buyer comfort with SME affordability.
If the buyer refuses consider declining the work rather than accepting uncapped uninsured exposure.
Next steps and templates
Below are copyable templates and a short checklist to use when responding to a contract demand for insurance.
Checklist to act within 72 hours:
- Read and extract clause requirements (limits, retroactive dates, wording).
- Send clause and business facts to your broker with a 48–72 hour turnaround request.
- Obtain Cyber Essentials assessment if requested by buyer or underwriter.
- Request an insurer letter or binder and deliver it to the buyer within 10 business days.
Sample email to broker or insurer:
Subject: Urgent: Insurance confirmation request for contract
Dear [Broker Name],
Supplier: [Company Name]
Contract: [Buyer], dated [DD/MM/YYYY]
Clause: [Insert clause text]
Requested: Written insurer confirmation that existing or proposed policy covers the clause, or a binder if full policy will follow.
Needed by: [DD/MM/YYYY] (10 business days)
Please confirm availability and estimated premium/excess.
Regards,
[Name]
[Contact]
Sample client response when proposing a redraft:
Dear [Buyer contact],
Thank you for the contract. The supplier proposes the following change to the insurance clause to make cover proportionate and practicable:
[Insert suggested SME redraft from earlier section].
The supplier will provide a policy schedule or insurer confirmation within 10 business days of contract signature. If this is not acceptable please advise an alternative acceptable limit.
Regards,
[Name]
If the buyer requires evidence quickly prepare a folder with: the policy schedule, the insurer confirmation letter, Cyber Essentials or Cyber Essentials Plus certificate, and a short statement of your compliance measures.