Do IT contractors need professional indemnity insurance?
Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited · Last reviewed 2026-08-06
If you contract in IT — whether you're a developer, an infrastructure engineer, a project manager, a data specialist or a one-person consultancy through your own limited company — you've probably seen "PII" or "professional indemnity" listed in a contract schedule and wondered whether it's genuinely necessary or just paperwork. It's a fair question, and the honest answer has two parts: what the law says, and what the market actually does. They're not the same thing, and for an IT contractor the second part is what usually decides it.
Is professional indemnity insurance a legal requirement for IT contractors?
No. There is no UK statute that makes professional indemnity (PI) insurance compulsory for IT contractors or technology consultancies. Unlike, say, solicitors or accountants whose professional bodies mandate cover, the IT sector has no equivalent regulator forcing you to hold a policy. So if you're asking purely "will I break the law without it?", the answer is that you won't.
But that's rarely the question that matters. The reason nearly every serious IT contractor carries PI is contractual, not legal. Agencies, umbrella arrangements and end clients write insurance requirements into their contracts, and those requirements are as binding on you as any other clause you sign. Miss them and you don't get the engagement — or you breach an agreement you've already started. So while the government doesn't require it, the people paying your invoices very often do.
Why do agencies and clients insist on it?
From the client's side, the logic is straightforward. When they hire a contractor, they're placing a piece of their business — a system migration, a codebase, a security configuration, a data pipeline — in the hands of someone outside their own payroll. If that work goes wrong and it costs them money, they want to know there's a policy standing behind you that can respond, rather than a sole trader or a small limited company that might not have the funds to settle a claim.
Professional indemnity does exactly that. It's designed to respond to claims that your professional work — your advice, your code, your configuration, a missed requirement, an error in delivery — caused a third party financial loss. It typically covers the legal costs of defending the allegation as well as any damages or settlement, up to the limit on the policy. For a client, requiring it is a simple way to make sure that if your work causes them a loss, there's a mechanism to recover it. That's why the requirement appears so consistently across agency terms and statements of work.
It's worth understanding this as a commercial gate, not a formality. Procurement and supplier-onboarding teams will often ask for evidence of cover — a certificate showing the required limit — before they'll set you up as a supplier at all. No certificate, no purchase order.
Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.
Been handed a contract with an insurance schedule you're not sure you meet? Send it to us and we'll tell you exactly what cover satisfies it.
Get a tailored quote →What does technology PI actually protect against?
Technology professional indemnity — sometimes called technology errors & omissions, or tech E&O, which is simply the American name for the same thing — is built around the specific ways IT work can go wrong. A general "professional advice" policy written for a management consultant doesn't always fit a business that both advises and builds. Tech PI is designed to sit across both.
In practice it responds to allegations such as:
- A software deliverable didn't perform as specified and the client says the failure cost them money.
- You gave technical advice or recommended an approach that the client claims led to a loss.
- A project overran or a deliverable was defective, and the client alleges negligence.
- An unintentional breach of a third party's intellectual property in the work you supplied.
The value isn't only in paying out a settlement. A large part of what you're buying is the defence — the legal and expert costs of dealing with an accusation, even one that turns out to be unfounded. IT disputes are often technical and contested, and defending yourself out of your own pocket can be ruinous long before any question of fault is settled. Because the exact scope, exclusions and limits vary between insurers, it's worth reading the wording (or having a broker read it) against the kind of work you actually do. Our overview of technology professional indemnity insurance goes deeper on how these policies are constructed.
How much cover will a contract ask for?
Agency and client contracts usually specify a minimum limit of indemnity — the maximum the policy will pay for a claim. Common figures you'll see requested are £1 million, £2 million or £5 million, and larger enterprise or public-sector engagements sometimes ask for more. There's no single "right" number; it's driven by the counterparty's own risk appetite and the scale of the work.
The practical trap for contractors is buying a limit that's comfortably fine for one client and then discovering the next contract demands double it. It's cheaper and far less stressful to size your cover against the engagements you're realistically chasing, rather than scrambling to increase a limit mid-tender. If you're moving between clients regularly, talk to a broker about a limit that carries you across the market you work in rather than the one contract in front of you. An Apex specialist can look at the limits typically demanded in your niche and help you set cover that won't keep tripping you up.
Does holding PI insurance affect my IR35 status?
No — and this is an important one to be clear about, because it's a common misconception. IR35 (the off-payroll working rules) is a tax matter. It's about whether HMRC considers you genuinely in business on your own account or effectively an employee for tax purposes. That status is determined by the reality of your working arrangements — how you're engaged, controlled and substituted — not by what insurance you carry.
Buying professional indemnity does not change, improve or determine your IR35 position. It can be one of several things that are consistent with running a genuine business, but no policy makes you "outside IR35", and anyone telling you otherwise is oversimplifying. For your actual IR35 status and how to handle it, speak to a qualified accountant or tax adviser — that's a tax question, not an insurance one. Carry insurance because your contracts require it and because it protects you, not because you think it settles your tax status.
What other cover do IT contractors usually need alongside PI?
Professional indemnity is the piece contracts most often demand, but it isn't the whole picture, and clients increasingly ask for more than one type of cover.
Public liability deals with injury to people or damage to property — relevant if you work on client sites. Cyber insurance is a growing contractual requirement in its own right: it's designed to fund your response to a security breach or data incident — things like specialist breach response, notifying affected people, restoring systems, business interruption, and third-party liability if others suffer loss. One caution worth stating plainly: whether a UK data-protection fine (under UK GDPR and the Data Protection Act 2018, enforced by the Information Commissioner's Office) can lawfully be insured at all is legally uncertain, and such fines are often excluded or restricted. So don't buy cyber cover expecting it to simply pay a regulator's fine — buy it for the response and liability costs, which are where the real financial damage usually lands. Our guide to cyber insurance and our comparison of PI versus cyber cover unpack how these two sit together.
One legal requirement worth flagging: if your limited company employs anyone — even a single part-time member of staff — employers' liability insurance is compulsory under the Employers' Liability (Compulsory Insurance) Act 1969, with only narrow exceptions. Most one-person contractors won't trigger it, but the moment you take someone on, it stops being optional.
What happens if I skip it?
Two things, and both are worse than the premium. First, the commercial cost: you lose contracts. If a client or agency requires PI and you can't evidence it, they move to a contractor who can. In a competitive market, being uninsurable at the point of tender simply takes you out of the running — often before anyone even reads your CV.
Second, the exposure. Without cover, a single disputed piece of work can leave you personally exposed to legal costs and a potential settlement, even where you've done nothing wrong, because defending the allegation still costs money. For a contractor working through a small limited company, one contested claim can outweigh a year's earnings. PI exists precisely so that a bad day doesn't become a business-ending one.
Put bluntly: for most IT contractors the question isn't really "do I have to", it's "can I win and keep good work without it" — and the answer to that is usually no.
Apex arranges professional indemnity and wider cover built specifically for IT and technology contractors — sized to the contracts you're chasing, not a generic template.
Get a tailored quote →The practical takeaway
Legally, no one is going to fine you for contracting in IT without professional indemnity insurance. Commercially, it's close to essential: the agencies and clients you want to work with will require it, they'll ask to see proof of it, and they'll pick someone else if you can't provide it. On top of that, it protects you personally and through your company against exactly the kind of claim — "your work cost us money" — that IT contractors are most exposed to.
Because the limits demanded and the wordings on offer vary so much, it pays to get cover set up around the reality of your contracting work rather than a box-ticking minimum. If you'd like a hand matching a policy to the contracts in front of you, Apex works with IT contractors day in, day out — talk to one of our specialists and we'll make sure you're covered for the work you actually do.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.
