Updated July 2026

There is no universal legal duty to hold cyber insurance. Read the ITT now and follow the tender wording; if the ITT names cover, hold the policy by the required date.
Buyer motives: law, reputation and risk
Public bodies ask for cyber controls to protect public data and services. The Procurement Act 2023 sets key procurement duties for covered procurements, while some legacy procurements may still follow earlier rules. Buyers also follow guidance from the National Cyber Security Centre and the Cabinet Office when checking suppliers.
Procurement obligations
The buyer checks suppliers against applicable procurement law and internal policy. The Procurement Act 2023, relevant transitional rules and Procurement Policy Notes guide that check. Buyers balance legal compliance with service continuity and data protection.
Typical buyer asks
Common requests include Cyber Essentials, evidence of policies and minimum insurance limits. Central government often asks for Cyber Essentials as baseline evidence. Local authorities and health bodies frequently want both controls and insurance cover.
A clear insurance statement in the bid improves credibility quickly.
When tenders demand insurance or limits
Some tenders name required cover and minimum limits. Treat those tenders as mandatory for that procurement. Framework agreements and grant contracts may list precise policy wording or minimum indemnity figures.
If an ITT or contract schedule requires active insurance wording or a retroactive date, the bidder must hold compliant cover by the stated date. If the ITT allows post-award compliance, a verifiable insurer commitment with a firm start date may satisfy the buyer. Failure to meet explicit wording risks exclusion.
Explicit insurance clauses
An explicit clause will name required cover, insurer or limit and sometimes a retroactive date. If the ITT lists these items, the bidder must provide compliant evidence. The procurement officer will expect a policy schedule and insurer contact details.
Frameworks and sectors
Certain sectors impose stricter insurance or resilience rules, especially health and finance. The NIS Regulations 2018 and the Data Protection Act 2018 raise expectations for critical suppliers. Where frameworks cover sensitive services, bespoke cyber conditions are more likely.
Public bodies vary by sector in how strictly they treat cyber risk. This variance affects the indemnity limits they expect in tenders.
In health and social care, buyers often seek multi-million pound limits. Typical ranges run from £5m to £10m or more on high-risk NHS frameworks. Financial services tend to expect mid-to-high millions and combined cyber and professional indemnity wording. Education and local authorities often require lower but still material limits, commonly £1m to £5m.
For low-risk facilities or supply-only contracts, buyers may accept a £1m limit or Cyber Essentials plus a modest policy. These ranges are indicative, not fixed rules. Exact limits and wording depend on service sensitivity and ITT wording.
How to prove cover in a tender
A short evidence pack often decides outcomes when cover sits on the margin. Buyers want verifiable facts: a certificate, policy schedule or a director's declaration with dates. A plan with set purchase dates can satisfy many procurement officers before award.
One-page evidence
The one-page evidence must state insurer name, policy number, limits and effective dates. Include a Cyber Essentials certificate reference if held and an insurer contact for verification. Add a short mitigation paragraph on backups and incident response.
Sample bid wording
Use the one‑page evidence and procurement wording below as sample bid wording.
Cyber Essentials vs cyber insurance
Cyber Essentials proves baseline technical controls. Cyber insurance pays certain financial losses after an incident. Buyers use Cyber Essentials to check controls and insurance to check financial resilience.
What each proves
Cyber Essentials shows simple technical controls are in place. Cyber insurance shows the bidder can meet some financial consequences after an incident. Together they cut both the chance of an incident and the financial shock if one happens.
Procurement impact
The most frequent error at this point is assuming a policy alone replaces certification. That mistake costs bids when buyers list Cyber Essentials or technical checks. A bidder who presents both a certificate and a policy schedule scores better on control and resilience grounds.
| Item |
Cyber Essentials |
Cyber insurance |
| Purpose |
Proves baseline technical controls |
Pays certain financial losses after incident |
| Evidence for buyer |
Certificate or Plus assessment report |
Policy schedule and insurer contact |
| Common exclusions |
Does not cover losses directly |
Regulatory fines and state attacks often excluded |
| Typical procurement use |
Baseline requirement by many central buyers |
Used where buyers ask for financial assurance |
The mistake often missed: a policy limit number alone does not prove cover for regulatory fines or specific contractual liabilities.
Certify
Get Cyber Essentials in 1–4 weeks.
Insure
Bind a small SME policy in 3–14 days.
Prove
One page: policy, limits, dates and contact.
Costs, timelines and practical path
A realistic plan helps a bidder choose to buy, declare or challenge. Typical costs and times guide the decision and let the bidder prove intent. The procurement officer values verifiable dates and named contacts.
Estimated costs and times
Typical certification costs range from £300 to £1,200 for Cyber Essentials, while a Cyber Essentials Plus assessment can cost £1,200 to £3,500. An SME cyber insurance premium usually starts around £200 to £2,000 per year depending on turnover and sector.
Last-minute options
If the tender closes in under two weeks, present existing cover and a binding date for purchase. Getting quotes and binding cover usually takes 3 to 14 days with accurate details. Cyber Essentials can be done faster when an organisation is ready and an assessor is available.
NCSC Cyber Essentials scheme
The data show that procurement teams commonly accept Cyber Essentials as baseline evidence. This works well in theory, but buyers still ask for insurer confirmation when contracts involve sensitive data. An anonymised case: a small supplier showed a policy limit but the insurer excluded fines, and the bid lost.
Quick practical guidance is often the best next step.
Practical checklist: choosing cover for tenders
A short checklist avoids last-minute surprises and shows procurement intent. Use the checklist to gather documents, contact a broker and brief legal counsel. Keep a named contact for verification in the submission.
Quick procurement checklist
- Locate cyber clauses and insurance limits in the ITT.
- Gather policy schedule or Cyber Essentials certificate.
- Get written insurer confirmation or broker letter with scope and retroactive date.
Who to involve and when
Contact a broker as soon as the ITT is read and clarify ambiguous clauses with the procurement officer. Legal counsel should review policy exclusions if limits or fines are material. The bidder should assign a single point of contact to manage evidence and correspondence.
Exceptions apply when the procurement documentation explicitly makes cyber insurance mandatory or specifies minimum policy wording and limits. Also this guidance does not apply to tenders outside England or to highly regulated contracts in health, finance or defence where bespoke cover is required.
Before the FAQ, a quick action helps the bidder move forward quickly. If the bidder is unsure, instruct a broker or legal adviser to review the ITT within 48 hours and give a short written statement for the bid.
A simple decision flow helps you decide whether to bind cover before bidding. First, read the ITT and any referenced framework agreement for explicit cyber wording. If it requires named indemnity, retroactive dates or insurer wording at submission, hold compliant cover by the stated date.
Second, assess the contract’s sensitivity. Does the work involve personal data, critical infrastructure or likely large business interruption costs? High sensitivity pushes toward immediate cover.
Third, compare your potential exposure against turnover and buyer limits. If exposure exceeds retained risk, buy cover that meets indemnity limits and provides an insurer contact and policy schedule for the tender.
If the ITT asks only for intent or post-award compliance, obtain written verifiable insurer or broker confirmation of a binding start date. Include that confirmation in the one-page evidence.
Throughout, keep the policy schedule, insurer contact and indemnity limits ready for procurement checks and clarification questions.
Questions frequently asked by bidders
Is cyber insurance mandatory for government?
No blanket legal rule forces SMEs to hold cyber insurance to bid. Some tenders or frameworks explicitly require insurance or minimum limits. Always check the ITT and raise a clarification question right away.
Do I need Cyber Essentials for government?
Many central government contracts and frameworks prefer or require Cyber Essentials. This certification proves baseline technical controls for buyers. Where required, lack of certification can lower the score or cause disqualification.
Can an SME win without insurance if it has Cyber Essentials?
Yes, winning without insurance is possible when the ITT requires only Cyber Essentials. Buyers value demonstrated controls and resilience. For contracts asking for financial assurance, insurance will improve the bidder's position.
How fast can a small company obtain evidence of cover?
Binding a standard SME cyber policy can take 3 to 14 days with accurate information. Cyber Essentials typically takes 1 to 4 weeks depending on readiness. If time is tight, declare current cover and set binding dates in the bid.
What proof do procurement officers accept as evidence?
Procurement officers commonly accept a policy schedule, insurer contact and Cyber Essentials certificate. Some may request policy wording or a broker letter for high-risk contracts. Provide verifiable contacts and dates for quick checks.
There is no single statute that forces every SME to hold cyber insurance before a bid. Procurement law and contractual terms do determine whether cover is required for a given tender. The Public Contracts Regulations 2015 set the framework for how buyers may evaluate suppliers.
The ITT, framework agreement or contract schedule can make insurance mandatory for that specific procurement. If that explicit wording appears, a bidder who lacks the stated cover at the point required risks exclusion. If documents only ask for intent or timescales, a verifiable purchase plan or binding insurer confirmation may be acceptable.
In short: the legal baseline is no universal statutory duty. Contract terms in the ITT can create a mandatory insurance obligation for that procurement, so read the insurance clause wording carefully and treat explicit policy requirements as binding.
Your next step
Start by reading the ITT insurance section and any referenced PPNs or supplier security notes. Note the exact wording, required limits and any retroactive dates requested by the buyer. If an insurer is required by name, contact that insurer or a broker immediately.
Copy and paste this one‑page evidence template into the tender submission or an appendix:
One‑page cyber evidence
Company: [Company name]
SME size: [Employees]
Director statement: I confirm the details below are true and accurate.
Insurer: [Insurer name]
Policy number: [Policy number]
Limit of indemnity: £[limit]
Excess: £[excess]
Policy period: [Start date] to [End date]
Retroactive date (if any): [date]
Cyber Essentials: [Yes/No], Certificate ref: [ref]
Mitigations: Backups, endpoint protection, incident response provider [name]
Insurer contact for verification: [Name, role, email, phone]
Signed: [Director name] Date: [dd/mm/yyyy]
Use this procurement wording in the technical or risk section of the bid:
The supplier holds a cyber insurance policy with [Insurer]. The policy provides cover up to £[limit] and is effective from [date]. The supplier holds Cyber Essentials (certificate ref [ref]). Interim mitigations include 24/7 backups and an incident response partner. Insurer verification contact: [name]. This evidence can be provided on request.
A final warning: buying the cheapest policy at the last minute can leave key exclusions in place. Check the wording, confirm retroactive dates and be ready to show insurer contact details.
Will cyber insurance cover ICO fines?
Some policies exclude regulatory fines and criminal penalties, so the answer is often no. Insurers vary by wording and market. Check the policy exclusions and get insurer confirmation when fines are a material risk.