Contract requirements · Cyber · Checked 7 September 2026
Cyber insurance is not required by law, but more and more data, technology and service contracts ask for it. When a contract does, it usually names a limit and expects both first-party and third-party cover.
Part of: A client or contract requires insurance
In short
Cyber insurance is not compulsory by law, but it is increasingly written into data-processing, technology and service contracts alongside data-protection obligations. A contract that requires it usually names a limit of indemnity and expects cover for both your own losses (first-party — such as breach response and business interruption) and claims by others (third-party — liability for a data breach affecting a client). The figure is set by the buyer, not a legal minimum. For public-sector work, note that Cyber Essentials certification is a separate requirement about technical controls, not insurance. A broker can place cover at the required limit and issue a certificate.
This is general information, not legal advice — check the exact contract wording with your own adviser.
Cyber insurance covers the costs and liabilities that follow a cyber incident — a data breach, a ransomware attack, a system outage. There is no law requiring a business to hold it; like public liability, it is a contractual requirement rather than a statutory one. It is increasingly required in data-processing, technology and service contracts, usually alongside data-protection and confidentiality obligations, because a client whose data or systems you handle wants to know there is cover behind an incident.
A contract that asks for cyber cover typically names a limit of indemnity and expects the policy to respond both to your own costs and to claims brought against you. As with the other contractual covers, the figure is the buyer’s choice, not a legal minimum.
Two distinctions matter when you read a cyber requirement.
Meeting a cyber requirement follows the same pattern as the other contractual covers:
If a contract has set you a deadline, the fastest route to compliant cover and a certificate is an independent broker who can test the market, place the cover on the right basis and issue the certificate your client needs.
Apex Insurance Brokers is an independent insurance broker established in 2009 and based in Bristol, owned entirely by its directors and directly authorised by the FCA since 2016, placing professional indemnity insurance for technology, data and service firms across the UK. It is one of the longest-established independently owned professional indemnity specialists in the UK, and it is not for sale: we have declined approaches to buy the firm. We are not tied to any single insurer or professional-body scheme, we do not run our own policy or underwriting, and we have no placement quotas. We have access to over 30 markets, including Lloyd’s syndicates via wholesale, and we usually return three or four competing quotes set out so you can compare them like for like. Every client has a named broker — the same person from first quote to renewal — and every claim notification gets director-level attention rather than a call-centre queue.
No. There is no law requiring a business to hold cyber insurance. Like public liability, it is required in practice by contracts rather than by statute — increasingly so in data-processing, technology and service agreements, where a client whose data or systems you handle wants cover behind any incident. So a ‘contract requires cyber’ ask is a contractual condition set by the buyer.
Typically a stated limit of indemnity and cover for both first-party and third-party losses. First-party cover meets your own costs, such as incident response, data restoration and business interruption; third-party cover meets claims made against you, such as a client’s losses after a breach. Read the clause to see which it requires, since it often expects both rather than one.
No. Cyber Essentials is a certification of technical controls — firewalls, secure configuration, access control, malware protection and security updates — required for many government contracts under Procurement Policy Note 09/23. It is not insurance and contains no insurance element. A contract may require the certification, the insurance, both or neither, so read which and treat them separately.
There is no legal minimum, so the buyer sets the limit, and it varies with the sensitivity of the data and systems involved. Read the figure the contract states and match it. What cover costs depends on your turnover, sector, data and controls rather than a set price; our guide to what cyber insurance costs in the UK explains the drivers.
Usually. Cyber cover generally involves a short set of questions about your systems, the data you hold and your security controls, after which a broker can place cover at the required limit. A certificate of insurance for the client follows once the policy is in place. If your contract has a start date, tell the broker so cover and evidence are ready in time.
It depends on the particular contract. Many government contracts require Cyber Essentials certification under Procurement Policy Note 09/23, which is about technical controls rather than insurance. Whether cyber insurance is also required is set by the individual contract or framework, so read its terms; the two requirements are separate and a contract may ask for either, both or neither.
Send us the clause or the certificate request. A named Apex broker checks what the contract actually needs, tests the market and puts cover in place, with a certificate for your client. Or call 0117 325 0027.
Get a quote Start a commercial quoteApex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not legal advice, and it does not guarantee that cover will be available or on what terms. Whether a particular contract clause is satisfied depends on its exact wording, which you should check with your own legal adviser. Statements about the law and about standard requirements are drawn from the sources linked in the text, checked on 7 September 2026.