Software quality
Yes, if clients rely on your testing to decide whether software is ready, you need professional indemnity insurance. A tester’s product is assurance: a test report, an accessibility audit, a penetration test finding or a recommendation to release. When a defect you should have caught reaches customers, or a test itself causes an outage, the loss is financial and public liability will not pay it. PI defends the claim that your testing fell short, subject to the policy terms.
Part of: Professional indemnity for IT professionals
In short
Testing cannot prove software is free of defects, but clients act on your findings, and claims follow when a defect inside the agreed scope is missed. Functional, performance, accessibility and security testing each fail in different ways. Penetration testers carry an extra risk: under the Computer Misuse Act 1990, a tester’s access is unauthorised without consent from someone entitled to control it, so written scope and authorisation are essential. Accessibility auditors support public bodies that must make websites and apps perceivable, operable, understandable and robust, which GOV.UK guidance ties to WCAG 2.2 AA. PI answers negligence claims; cyber covers your own systems and the findings you store.
Last reviewed 5 October 2026 by the Apex professional indemnity team.
Testers rarely write the code that fails, so it is tempting to assume the risk belongs to the developer. Not all of it does. Clients pay you for assurance: that functions in scope behave as specified, that a system will carry the expected load, that a site meets an accessibility standard, or that an application has no exploitable weakness you could find. They then release, launch or publish on the strength of your report.
If a defect you should have found reaches customers, the client’s loss is financial: refunds, remediation, lost sales, questions from a regulator. Public liability (PL) insurance only answers injury and property damage, so it has nothing to offer. The allegation is that your testing lacked the skill and care of a competent tester, and professional indemnity (PI), usually written for technology firms as errors and omissions cover, is the policy that responds.
The examples below are illustrative and do not describe real claims. Each sets out the failure, who lost money and what they would allege.
Each dispute is about the standard of your testing against the scope you agreed, which is why the paperwork around a test matters as much as the test.
| Rule or standard | What it says | Why it matters to you |
|---|---|---|
| Computer Misuse Act 1990, ss.1, 3 and 17 | It is an offence to cause a computer to perform a function to secure access you know is unauthorised, or to do an act you know is unauthorised intending to impair a computer’s operation or data, or reckless as to that. Access is unauthorised if you are not entitled to control that kind of access and lack consent from someone who is. | Written authority from the right person is what separates a security test from an offence. |
| NCSC penetration testing guidance | A penetration test can only validate that systems are not vulnerable to known issues on the day of the test. Scoping should record the technical boundaries of the test and any compliance or legislative requirements the plan must meet. | Your report is not a guarantee, and your scoping record is evidence of what you were asked to do. |
| NCSC CHECK scheme | The scheme under which NCSC-assured companies carry out authorised penetration tests of public sector and critical national infrastructure systems. | Public sector clients may ask for it, and insurers will ask what accreditation you hold. |
| Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018 | Public sector bodies must make websites and apps perceivable, operable, understandable and robust, unless a disproportionate burden assessment justifies otherwise, and publish an accessibility statement explaining what is not accessible and why. | Your audit findings often become the basis of that statement. |
| GOV.UK guidance on accessibility requirements | Public sector sites and apps should meet WCAG 2.2 AA. GDS monitors compliance; the Equality and Human Rights Commission and the Equality Commission for Northern Ireland enforce. A body stays legally responsible even if it has outsourced its website. | The body keeps the legal duty, so a missed failure turns into a contract claim against its suppliers. |
| WCAG 2.2 (W3C Recommendation) | Three conformance levels, A, AA and AAA, built on content being perceivable, operable, understandable and robust. | State the version and level you tested. An audit against WCAG 2.1 does not cover the criteria added in 2.2. |
| ISO/IEC/IEEE 29119-2:2021 and 29119-3:2021 | Generic test processes for any organisation, project or life cycle model, and templates for the test documentation those processes produce. | If you say you follow the series, your plans and reports will be compared with it. |
The Computer Misuse Act 1990 makes consent precise. Under section 17(5), access is unauthorised if the person is not entitled to control access of the kind in question and does not have consent to that kind of access from someone who is. Two practical points follow.
Agree rules of engagement, emergency contacts, stop conditions and how you will handle personal data you come across, and keep the signed authorisation with the report.
This matters for insurance as well. PI is built for civil claims of negligence, such as a test that unexpectedly takes a service down or a report that misses a flaw. It is not designed for criminal proceedings, and wordings commonly exclude deliberate acts, fines and penalties. A clean authorisation trail keeps a dispute in civil, insurable territory.
Public bodies carry the legal duty, but they rely on testers to tell them where they stand. Under the 2018 regulations they must meet the accessibility requirement unless a disproportionate burden assessment justifies otherwise, and their accessibility statement must explain what is not accessible and why, offer a way to report problems and link to the enforcement procedure. The statement has to be kept under regular review.
Your report usually feeds that statement, so a missed failure becomes a public statement that is wrong. Keep your exposure to what you actually did:
Private sector clients may ask for the same standard in their contracts, and the same discipline protects you there.
Testing shows the presence of defects, not their absence, and your sign-off should say so. Clients, and later their lawyers, will read a test completion report as a statement of fact, so write it as one.
A report that says “no defects found” without stating its scope is the hardest document to defend.
| Usually covered by PI | Often excluded or limited | Needs a different policy |
|---|---|---|
| Defects missed through negligent test design or execution | Promises that software is free of defects | A breach of your own systems and stored findings (cyber) |
| Outages or data damage caused by your tests, such as a load test in the wrong environment | Work outside the agreed scope or authorisation | Injury or damage at a client site (public liability) |
| Negligent accessibility audits and conformance reports | Fines, penalties and criminal proceedings | Injury to your own staff (employers’ liability) |
| Security tests that miss in-scope vulnerabilities | The cost of re-running your own tests | Loss or theft of your own laptops and test devices (equipment cover) |
| Defence costs, including independent testing experts | Claims you knew about before the policy started | Directors’ liability for running your firm (D&O) |
Your systems hold some of the most sensitive material a client has: vulnerability findings, test credentials, network diagrams and sometimes live data. If attackers reach that store, cyber insurance usually pays for your investigation, recovery and notification costs. Claims from clients whose weaknesses were exposed through you are liability claims, which may fall to PI or to the cyber policy depending on the wordings, so check that the two fit. Avoid testing with live personal data unless the client has agreed how it will be protected and deleted.
Limits are usually set by the client or, when you test as a subcontractor, by the development or integration firm that engages you, which may pass down the insurance terms it agreed with the end client. Check whether a limit is each and every claim or aggregate, and whether your liability cap matches it.
Security and accessibility work can carry more risk than the fee suggests, because one missed finding can sit behind a large breach or a public complaint. PI is claims-made: the policy in force when a claim is made responds, and defects can surface long after release. Keep cover continuous, keep your retroactive date when you change insurer, and arrange run-off if you stop trading. For more on choosing a figure, see how much PI cover you need.
A complete proposal gets better terms than a bare one, and a broker can only present what you tell us. Have these ready:
Speak to a broker
PI for software testers, placed by a named broker
Start the online proposal and save it as you go, or leave your number and a named broker will call you back, usually the same working day.
Apex Insurance Brokers is an independent insurance broker based in Bristol, established in 2009 and authorised and regulated by the Financial Conduct Authority. We are not tied to one insurer: we work with over 30 markets, including Lloyd’s syndicates through wholesale brokers, and every client has a named broker who handles the placement, mid-term changes, certificates for clients and the renewal.
Yes, if clients rely on your testing to release software, publish an accessibility statement or judge their security. A missed defect, a misleading report or a test that causes an outage can cost a client a great deal, and public liability won’t pay. PI covers defence costs and compensation for negligence claims, subject to the policy terms.
No law requires software testers to hold PI. In practice clients and the development or integration firms that subcontract testing make it a contract condition, usually with a minimum limit. Public sector and security work can come with stricter insurance and accreditation requirements set in the tender or contract.
It can try. Testing cannot prove software is defect-free, so the question is whether your testing met a competent standard for the scope agreed. A clear test plan, agreed exit criteria and a completion report listing what was and wasn’t tested are your strongest defence, and PI pays to defend the claim, subject to the policy terms.
In practice, yes. Under the Computer Misuse Act 1990, access is unauthorised if you are not entitled to control it and lack consent from someone who is. Get written authority from the system owner setting out targets, techniques and timings, and check whether cloud or hosting providers must also agree.
It can, if the audit was negligent and the client lost money as a result, such as re-auditing, fixing content or correcting its accessibility statement, subject to the policy terms. Declare accessibility work to your insurer, and state the standard, version, sample and method in every report.
Usually, if the outage resulted from a negligent mistake, such as running a script against the wrong environment, and the client claims its financial loss, subject to the wording. Public liability covers physical damage, not downtime. Agree test windows, target environments and third-party approvals in writing beforehand.
Apex arranges professional indemnity insurance for software testers across the UK. Tell us about your work and we’ll find cover that fits. Or call 0117 325 0027.
Start your PI proposal Call 0117 325 0027Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not advice on your individual circumstances. Cover is always subject to the insurer’s acceptance and the policy terms, and this page does not guarantee that cover will be available or on what terms.