FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
Technology & IT insurance

Software development company insurance

Reviewed by Apex Insurance Brokers · Last reviewed 2026-08-06

In short: A UK software house typically needs technology professional indemnity (tech PI/E&O) for mistakes in the software or advice you deliver, cyber cover for the data and systems you handle, public liability for client-site and premises risks, and employers' liability the moment you take on staff. Most firms buy tech PI and cyber together in one combined technology policy.

Whether you build bespoke platforms for enterprise clients, ship your own SaaS product, or take on fixed-scope development contracts, your exposure is unusual: the thing you sell is code, and code can fail in ways that cost a client real money long after you've been paid. This guide walks through the covers that actually matter for a software development company, why each one applies to the way you work, and what your clients will almost certainly insist on before they sign.

What insurance does a software development company actually need?

There's no single "software house policy" you tick a box for. Instead you're assembling a small stack of covers around one central risk: that your work causes a client a financial loss. For most development firms the core is technology professional indemnity, usually paired with cyber insurance, then public liability and — once you employ anyone — employers' liability. Depending on what you build and how you market it, media and intellectual property liability may also belong in the mix.

The right shape depends on your contracts, your client base, and how much of your revenue comes from your own product versus client project work. A firm building compliance software for banks carries very different exposure from a two-person studio making marketing microsites. That's the honest answer to "how much cover do I need" — it's set by the risk you actually run, which is exactly what a broker is for.

Why is technology professional indemnity the cover that matters most?

Technology professional indemnity — often written as tech PI, and called technology errors & omissions (tech E&O) in the US and in some policy wordings — is the same core protection under two names. It responds when a client alleges that a mistake, oversight or negligent piece of advice in your work caused them financial harm, and it funds both the legal defence and any damages or settlement.

For a software company that risk is everywhere. A bug in a payment flow that lets transactions slip through. A missed edge case that corrupts a client's data. An integration that behaves differently in production than in staging. A late delivery that blows a launch date written into the contract. Advice you gave on architecture that turned out to be wrong. In each case the client's loss can dwarf your project fee, and a claim can arrive months after go-live. Tech PI is what stands between that allegation and your balance sheet. Related reading: startup and scale-up cover.

A crucial point: professional indemnity is not a legal requirement for IT firms. There's no statute forcing you to hold it. What drives almost every purchase is contract — clients, agencies and procurement teams routinely require a stated level of PI cover (often £1m, £2m or £5m as illustrative limits) before they'll engage you, and they'll ask to see the certificate. In practice, then, it's a commercial necessity even though it isn't a statutory one. Our technology professional indemnity guide goes deeper on how limits and wordings are set.

Larger or more complex risk? Speak directly to a director — call 0117 325 0027 or email info@apexinsurancebrokers.co.uk.

Tell us what you build and who your clients are, and we'll size tech PI and cyber to the contracts you're actually signing.

Get a tailored quote →

Do we need cyber insurance if we're already careful about security?

Good engineering hygiene lowers your risk; it doesn't remove it. As a development firm you routinely touch client data, hold source code and credentials, connect to production systems, and run your own infrastructure — every one of which is a target. Cyber insurance exists for the day something gets through despite your best practices: a ransomware hit, a compromised dependency, a phishing attack that reaches your admin accounts, or a breach of personal data you were processing on a client's behalf.

What cyber cover does well is fund the response. That typically means specialist incident-response and forensics to work out what happened, legal support, the cost of notifying affected people and the Information Commissioner's Office (ICO) where required under UK GDPR and the Data Protection Act 2018, business interruption while you're down, and third-party liability if a client or individual claims against you over the breach.

One thing to be precise about: whether a UK regulatory or data-protection fine can be insured at all is legally uncertain, and policies often exclude or restrict it. So don't buy cyber cover on the assumption it will pay an ICO fine — treat that as unreliable. The dependable value is in breach response, business interruption and the liability you may owe others. Our cyber insurance explainer sets this out in plain terms.

Tech PI or cyber — where's the line, and should we buy both?

The two overlap enough to confuse and differ enough to matter. Roughly: tech PI answers for the quality of your work — the code, the advice, the deliverable that let a client down. Cyber answers for a security event — the breach, the attack, the data loss, whether it hits your systems or a client's. A single incident can trigger both. Say a flaw you introduced is exploited and client data is exposed: the defective-work angle is PI territory, the breach-response and notification costs are cyber territory.

Because those edges blur, most software firms are best served buying the two together in a combined technology policy, where tech PI and cyber sit under one wording from one insurer. That closes the gaps that appear when separate policies point at each other, and it's usually cleaner to manage and to evidence to clients. We compare the standalone-versus-bundled question in detail on our combined technology insurance page.

What about public liability and employers' liability?

Public liability covers injury to a third party or damage to their property arising from your business activities — someone tripping over a cable at your office, or your consultant knocking over kit while working on a client's premises. If your developers ever attend client sites, or clients and couriers come to you, most agencies and landlords will expect it, and it's inexpensive relative to the protection it gives.

Employers' liability is different in kind: it's a legal requirement. Under the Employers' Liability (Compulsory Insurance) Act 1969, once you employ staff you must hold employers' liability cover, subject to narrow exceptions. It protects you against claims from employees who are injured or made ill through their work. If you're a sole director with no employees you may fall within an exception — but the moment you hire your first developer, this stops being optional, so it's worth confirming your position rather than assuming.

When does media and intellectual property liability come into play?

Software rarely ships in isolation. You embed third-party libraries, integrate open-source components, produce UI, copy and sometimes content, and occasionally reuse patterns across clients. Media and IP liability responds to allegations that your work infringed someone's intellectual property — a copyright, trademark or design right — or that content you produced was defamatory. It's often built into technology and tech PI wordings rather than bought separately, but the level of cover varies, so it's worth checking what your policy actually grants rather than assuming it's fully handled. If you build products with a strong content or media element, or you white-label work, this is a section to read carefully with your broker.

What do our clients typically demand in the contract?

Procurement teams and framework agreements tend to standardise around a few requirements, and they'll usually want evidence before onboarding you. Expect to be asked for a specified level of professional indemnity (a limit written into the contract), increasingly a stated level of cyber cover given data-protection expectations, public liability, and employers' liability if you have staff. Larger clients may name a minimum limit, require you to hold cover for a period after the contract ends, or ask to be noted on the policy.

The practical trap is buying a limit that looked fine last year and finding a new client's contract needs more. It's far easier to size cover to the contracts you're chasing than to scramble mid-tender — which is a good moment to speak to an Apex technology specialist before you sign anything binding you to a limit you don't yet hold.

Does insurance affect our IR35 position?

No — and this is worth being clear about because it comes up constantly, especially for firms that use contractors or operate through personal service companies. IR35 (the off-payroll working rules) is a tax matter about employment status for tax purposes. Holding professional indemnity, cyber or any other insurance does not change or determine your IR35 status, and no policy can make an inside-IR35 engagement outside, or vice versa. Insurance manages the risk of claims; it doesn't touch how HMRC views your working arrangements. For anything to do with IR35 status itself, take advice from a qualified accountant or tax adviser — that's the right professional for the question, and it's genuinely separate from the cover we arrange.

What drives the cost of a software company's cover?

We won't quote a figure here because a meaningful one only comes from your specifics, but the factors are consistent. Insurers look at your annual revenue and headcount, the type of software you build and how business-critical it is, your client sectors (regulated industries like finance and health carry more scrutiny), the limits of indemnity your contracts require, the volume and sensitivity of personal data you process, your security controls and development practices, and your claims history. A firm handling payment or health data for enterprise clients sits differently from one building brochure sites, even at the same turnover. Present those details well and you get cover priced to your real risk rather than a worst-case assumption — which is a large part of what a specialist broker does for you.

If you're weighing where these covers overlap, our comparison of professional indemnity versus cyber insurance for tech companies is a useful next read.

Apex arranges technology cover for UK software houses every week — bespoke shops, SaaS products and contract developers alike. Let's build a policy around what you actually ship.

Get a tailored quote →

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This article is general information, not advice on a specific policy or a recommendation to buy any product.

Get a quote →