FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
Technology & IT insurance

IR35 and insurance for IT contractors

Reviewed by Matthew Bartlett, Director, Apex Insurance Brokers Limited · Last reviewed 2026-08-06

In short: IR35 is a tax rule about your employment status for tax — holding insurance does not change or determine it, and no policy will make you “outside IR35”. That’s a question for a qualified accountant. What insurance does affect is your ability to win work: agencies and clients almost always require professional indemnity, public liability and, if you employ anyone, employers’ liability before you sign.

Does having insurance change my IR35 status?

No. This is the single most important thing to be clear about, so let’s state it plainly: buying professional indemnity, public liability or any other cover has no bearing on whether HMRC considers you inside or outside IR35. IR35 — the off-payroll working rules — is a tax matter. It asks a simple question with complicated answers: if we stripped away your limited company, would the working relationship between you and your end client look like employment? If it would, you’re “inside” and taxed broadly like an employee. If it genuinely wouldn’t, you’re “outside” and taxed as a business.

The factors that drive that assessment are things like control (who decides how, when and where the work is done), personal service and the right of substitution, and mutuality of obligation. Insurance isn’t on that list. You could hold £5m of professional indemnity and still be caught inside IR35; you could hold none and be firmly outside. So if anyone tells you a particular policy will “keep you outside IR35”, treat that as a red flag — it’s not how the rules work.

For the status question itself — reviewing your contracts, your working practices and your risk position — you want a qualified accountant or tax adviser who specialises in contractors. That’s their domain, not ours, and it’s worth getting right. Our job starts once the commercial side kicks in.

So why does everyone say contractors need insurance?

Because although insurance doesn’t touch your tax status, it’s almost always a condition of getting paid. When you operate through your own limited company and win work through an agency or directly with an end client, the contract you sign will typically list insurance as a requirement. That’s the connection people muddle: it isn’t that being outside IR35 legally forces you to buy cover — it’s that the kind of arm’s-length, business-to-business engagements that tend to sit outside IR35 come with commercial contracts, and those contracts want you insured.

A typical IT contract schedule asks for three things: professional indemnity, public liability and, once you take on any staff, employers’ liability. The specified limits are usually non-negotiable — the agency has agreed them upstream with the end client and simply passes the requirement down to you. Turn up to sign-on day without the right certificates and your start date slips, or the role goes to someone who has them ready. So the practical reality is that insurance is a gateway to the contract, not a lever on your tax position.

Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.

Landed a contract that lists insurance requirements you don’t yet hold? We’ll match the cover to the schedule so you can sign on time.

Get a tailored quote →

What insurance does an IT contractor actually need?

For most independent IT contractors and consultancies, three covers do the heavy lifting, and a fourth is increasingly expected.

If you want to see how these fit together for a technology business specifically, our overview of what insurance an IT company needs walks through each in turn, and our dedicated IT contractor insurance page is built around the contractor set-up.

My contract lists specific insurance limits — what do they mean?

Agency and client contracts don’t just ask you to “have insurance” — they specify limits of indemnity, and those numbers matter. You’ll commonly see professional indemnity at £1m, £2m or £5m, and sometimes higher for enterprise or public-sector work; public liability often at £1m, £2m or £5m; and, where relevant, employers’ liability at the level the contract states. These are illustrative of the kinds of figures that appear — your contract will tell you exactly what’s expected.

Two things trip contractors up. First, the limit has to be in place for the duration of the engagement and, for PI, ideally kept running afterwards — claims can surface months or years after a project ends, and most PI works on a “claims-made” basis, meaning the policy that responds is the one live when the claim is made, not when you did the work. Let cover lapse after a contract and a later claim may find you exposed. Second, an under-specified limit can stall your onboarding just as surely as no cover at all. It’s worth reading the insurance clause before you agree a rate, not after — and if the wording is ambiguous, a quick conversation with a broker beats guessing.

Where does cyber insurance fit for an IT contractor?

Cyber cover deserves its own note because IT contractors sit close to the risk. You may hold client credentials, touch production systems, process personal data, or be the route through which an incident reaches a client. If something goes wrong, cyber insurance is designed to fund the response: incident response specialists, forensic investigation, legal support, notifying affected people, and business interruption if your own operations are knocked offline. It can also respond to certain third-party liabilities arising from a breach.

One point to be careful about, because it’s widely misunderstood: cyber insurance is not a way to pay off a regulatory fine. Under UK GDPR and the Data Protection Act 2018, the Information Commissioner’s Office (ICO) can impose penalties — but whether such fines are insurable at all is legally uncertain in the UK, and policies often exclude or restrict them. So don’t buy cyber cover expecting it to settle an ICO fine. Buy it for what it reliably does: getting you through a breach and covering the response costs and liabilities that follow. Our guide to cyber insurance explained goes deeper, and if you want to understand how it differs from PI, the comparison of professional indemnity vs cyber insurance is a good next read.

Does being inside IR35 mean I don't need insurance?

Not necessarily — and this is where the tax question and the insurance question stay firmly separate. If you’re assessed inside IR35 you’re taxed differently, but you may still be trading through your limited company, still signing a contract with an agency or client, and that contract can still require PI, PL and EL regardless of your tax status. The insurance obligation flows from the contract terms, not from the IR35 determination.

Equally, if your working arrangement genuinely changed — say you moved to an umbrella company or became an employee — your own liability position changes too, and it’s worth checking whether policies you hold in your own company name are still doing anything useful for you. The honest answer is that “inside or outside” tells you about tax; “what does my contract say” and “what work am I actually doing” tell you about insurance. Keep the two questions in separate boxes and you’ll avoid the confusion that catches a lot of contractors out.

How should I approach getting this right?

Start by treating the two decisions independently. Get your IR35 status reviewed by an accountant or tax adviser who knows contractor work — that protects you on the tax side. Separately, when a contract comes in, read the insurance schedule early and line up cover that matches the named limits before your start date, so onboarding is never held up by a missing certificate.

Where it helps to have one set of cover that scales with your work, a combined technology package bringing tech PI and cyber together can be simpler than buying pieces separately, and it keeps your certificates consistent across multiple client contracts. If you’d rather talk it through than self-serve — particularly if a contract clause is worded oddly or the required limits look unusual — speak to an Apex specialist and we’ll read the requirement with you.

We arrange PI, PL, EL and cyber for IT contractors day in, day out — and we’ll size it to your contracts, not sell you cover you don’t need.

Get a tailored quote →

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.

Get a quote →