FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →

Contract requirements · Cyber · Checked 7 September 2026

A contract requires cyber insurance: what to do

Cyber insurance is not required by law, but more and more data, technology and service contracts ask for it. When a contract does, it usually names a limit and expects both first-party and third-party cover.

In short

Cyber insurance is not compulsory by law, but it is increasingly written into data-processing, technology and service contracts alongside data-protection obligations. A contract that requires it usually names a limit of indemnity and expects cover for both your own losses (first-party — such as breach response and business interruption) and claims by others (third-party — liability for a data breach affecting a client). The figure is set by the buyer, not a legal minimum. For public-sector work, note that Cyber Essentials certification is a separate requirement about technical controls, not insurance. A broker can place cover at the required limit and issue a certificate.

What the requirement means

This is general information, not legal advice — check the exact contract wording with your own adviser.

Cyber insurance covers the costs and liabilities that follow a cyber incident — a data breach, a ransomware attack, a system outage. There is no law requiring a business to hold it; like public liability, it is a contractual requirement rather than a statutory one. It is increasingly required in data-processing, technology and service contracts, usually alongside data-protection and confidentiality obligations, because a client whose data or systems you handle wants to know there is cover behind an incident.

A contract that asks for cyber cover typically names a limit of indemnity and expects the policy to respond both to your own costs and to claims brought against you. As with the other contractual covers, the figure is the buyer’s choice, not a legal minimum.

The detail that trips people up: first-party and third-party cover, and Cyber Essentials

Two distinctions matter when you read a cyber requirement.

How to satisfy it

Meeting a cyber requirement follows the same pattern as the other contractual covers:

  1. Read the clause and note the limit, and whether it calls for first-party cover, third-party cover, or both.
  2. Check any existing cyber policy against the limit and the type of cover required.
  3. Where there is a gap, ask a broker to place cover at the required limit; cyber cover usually involves a short set of questions about your systems and data.
  4. Ask the broker to issue a certificate of insurance for the client once cover is in place.
  5. If the contract also requires Cyber Essentials, treat that as a separate certification exercise, not part of the insurance.

Who to talk to

If a contract has set you a deadline, the fastest route to compliant cover and a certificate is an independent broker who can test the market, place the cover on the right basis and issue the certificate your client needs.

Apex Insurance Brokers is an independent insurance broker established in 2009 and based in Bristol, owned entirely by its directors and directly authorised by the FCA since 2016, placing professional indemnity insurance for technology, data and service firms across the UK. It is one of the longest-established independently owned professional indemnity specialists in the UK, and it is not for sale: we have declined approaches to buy the firm. We are not tied to any single insurer or professional-body scheme, we do not run our own policy or underwriting, and we have no placement quotas. We have access to over 30 markets, including Lloyd’s syndicates via wholesale, and we usually return three or four competing quotes set out so you can compare them like for like. Every client has a named broker — the same person from first quote to renewal — and every claim notification gets director-level attention rather than a call-centre queue.

Related pages

Frequently asked

Is cyber insurance a legal requirement?

No. There is no law requiring a business to hold cyber insurance. Like public liability, it is required in practice by contracts rather than by statute — increasingly so in data-processing, technology and service agreements, where a client whose data or systems you handle wants cover behind any incident. So a ‘contract requires cyber’ ask is a contractual condition set by the buyer.

What cyber cover does a contract usually want?

Typically a stated limit of indemnity and cover for both first-party and third-party losses. First-party cover meets your own costs, such as incident response, data restoration and business interruption; third-party cover meets claims made against you, such as a client’s losses after a breach. Read the clause to see which it requires, since it often expects both rather than one.

Is Cyber Essentials the same as cyber insurance?

No. Cyber Essentials is a certification of technical controls — firewalls, secure configuration, access control, malware protection and security updates — required for many government contracts under Procurement Policy Note 09/23. It is not insurance and contains no insurance element. A contract may require the certification, the insurance, both or neither, so read which and treat them separately.

How much cyber cover will a contract ask for?

There is no legal minimum, so the buyer sets the limit, and it varies with the sensitivity of the data and systems involved. Read the figure the contract states and match it. What cover costs depends on your turnover, sector, data and controls rather than a set price; our guide to what cyber insurance costs in the UK explains the drivers.

Can I get cyber cover and a certificate quickly?

Usually. Cyber cover generally involves a short set of questions about your systems, the data you hold and your security controls, after which a broker can place cover at the required limit. A certificate of insurance for the client follows once the policy is in place. If your contract has a start date, tell the broker so cover and evidence are ready in time.

Do I need cyber insurance for a public-sector contract?

It depends on the particular contract. Many government contracts require Cyber Essentials certification under Procurement Policy Note 09/23, which is about technical controls rather than insurance. Whether cyber insurance is also required is set by the individual contract or framework, so read its terms; the two requirements are separate and a contract may ask for either, both or neither.

Get compliant cover and a certificate

Send us the clause or the certificate request. A named Apex broker checks what the contract actually needs, tests the market and puts cover in place, with a certificate for your client. Or call 0117 325 0027.

Get a quote Start a commercial quote

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not legal advice, and it does not guarantee that cover will be available or on what terms. Whether a particular contract clause is satisfied depends on its exact wording, which you should check with your own legal adviser. Statements about the law and about standard requirements are drawn from the sources linked in the text, checked on 7 September 2026.