FCA authorised · FRN 724952 0117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →

Software quality

Professional indemnity insurance for software testers

Yes, if clients rely on your testing to decide whether software is ready, you need professional indemnity insurance. A tester’s product is assurance: a test report, an accessibility audit, a penetration test finding or a recommendation to release. When a defect you should have caught reaches customers, or a test itself causes an outage, the loss is financial and public liability will not pay it. PI defends the claim that your testing fell short, subject to the policy terms.

In short

Testing cannot prove software is free of defects, but clients act on your findings, and claims follow when a defect inside the agreed scope is missed. Functional, performance, accessibility and security testing each fail in different ways. Penetration testers carry an extra risk: under the Computer Misuse Act 1990, a tester’s access is unauthorised without consent from someone entitled to control it, so written scope and authorisation are essential. Accessibility auditors support public bodies that must make websites and apps perceivable, operable, understandable and robust, which GOV.UK guidance ties to WCAG 2.2 AA. PI answers negligence claims; cyber covers your own systems and the findings you store.

Start your PI proposal →or call 0117 325 0027 to speak to a broker

Why testing is a professional risk

Last reviewed 5 October 2026 by the Apex professional indemnity team.

Testers rarely write the code that fails, so it is tempting to assume the risk belongs to the developer. Not all of it does. Clients pay you for assurance: that functions in scope behave as specified, that a system will carry the expected load, that a site meets an accessibility standard, or that an application has no exploitable weakness you could find. They then release, launch or publish on the strength of your report.

If a defect you should have found reaches customers, the client’s loss is financial: refunds, remediation, lost sales, questions from a regulator. Public liability (PL) insurance only answers injury and property damage, so it has nothing to offer. The allegation is that your testing lacked the skill and care of a competent tester, and professional indemnity (PI), usually written for technology firms as errors and omissions cover, is the policy that responds.

How claims arise for software testers

The examples below are illustrative and do not describe real claims. Each sets out the failure, who lost money and what they would allege.

  1. A billing rule outside the test cases. You test a subscription platform’s new billing engine. Your cases cover monthly and annual plans but not mid-term upgrades, which the specification describes. After release thousands of customers are overcharged, and the client claims its refund and remediation costs, alleging your test design missed a documented requirement.
  2. A load profile with no spike. Your performance test models steady traffic for a ticketing launch, and you report the platform ready. On launch morning demand arrives in one surge, the site fails and sales are lost. The client alleges your workload model ignored the launch pattern it had described.
  3. A load test aimed at the wrong place. A script meant for the test environment runs against a production interface shared with a payment provider. The provider throttles the client’s account during trading hours, and the client claims its lost orders.
  4. A finding that never made the report. Your web application test misses an access control flaw that was in scope. Months later an attacker uses it to extract customer records. The client’s cyber insurer pays the response costs, then pursues you, alleging a competent tester would have found the flaw.
  5. An accessibility audit a complaint overturned. You audit a council’s online forms and report conformance with WCAG 2.2 AA. A resident who uses a screen reader complains that a key form cannot be completed by keyboard. The council must correct its accessibility statement, fix the forms and commission a new audit, and it claims those costs.

Each dispute is about the standard of your testing against the scope you agreed, which is why the paperwork around a test matters as much as the test.

The rules and standards testing is judged against

Rule or standardWhat it saysWhy it matters to you
Computer Misuse Act 1990, ss.1, 3 and 17It is an offence to cause a computer to perform a function to secure access you know is unauthorised, or to do an act you know is unauthorised intending to impair a computer’s operation or data, or reckless as to that. Access is unauthorised if you are not entitled to control that kind of access and lack consent from someone who is.Written authority from the right person is what separates a security test from an offence.
NCSC penetration testing guidanceA penetration test can only validate that systems are not vulnerable to known issues on the day of the test. Scoping should record the technical boundaries of the test and any compliance or legislative requirements the plan must meet.Your report is not a guarantee, and your scoping record is evidence of what you were asked to do.
NCSC CHECK schemeThe scheme under which NCSC-assured companies carry out authorised penetration tests of public sector and critical national infrastructure systems.Public sector clients may ask for it, and insurers will ask what accreditation you hold.
Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018Public sector bodies must make websites and apps perceivable, operable, understandable and robust, unless a disproportionate burden assessment justifies otherwise, and publish an accessibility statement explaining what is not accessible and why.Your audit findings often become the basis of that statement.
GOV.UK guidance on accessibility requirementsPublic sector sites and apps should meet WCAG 2.2 AA. GDS monitors compliance; the Equality and Human Rights Commission and the Equality Commission for Northern Ireland enforce. A body stays legally responsible even if it has outsourced its website.The body keeps the legal duty, so a missed failure turns into a contract claim against its suppliers.
WCAG 2.2 (W3C Recommendation)Three conformance levels, A, AA and AAA, built on content being perceivable, operable, understandable and robust.State the version and level you tested. An audit against WCAG 2.1 does not cover the criteria added in 2.2.
ISO/IEC/IEEE 29119-2:2021 and 29119-3:2021Generic test processes for any organisation, project or life cycle model, and templates for the test documentation those processes produce.If you say you follow the series, your plans and reports will be compared with it.

Penetration testing: why written scope and authorisation matter

The Computer Misuse Act 1990 makes consent precise. Under section 17(5), access is unauthorised if the person is not entitled to control access of the kind in question and does not have consent to that kind of access from someone who is. Two practical points follow.

Agree rules of engagement, emergency contacts, stop conditions and how you will handle personal data you come across, and keep the signed authorisation with the report.

This matters for insurance as well. PI is built for civil claims of negligence, such as a test that unexpectedly takes a service down or a report that misses a flaw. It is not designed for criminal proceedings, and wordings commonly exclude deliberate acts, fines and penalties. A clean authorisation trail keeps a dispute in civil, insurable territory.

Accessibility audits and the public sector regulations

Public bodies carry the legal duty, but they rely on testers to tell them where they stand. Under the 2018 regulations they must meet the accessibility requirement unless a disproportionate burden assessment justifies otherwise, and their accessibility statement must explain what is not accessible and why, offer a way to report problems and link to the enforcement procedure. The statement has to be kept under regular review.

Your report usually feeds that statement, so a missed failure becomes a public statement that is wrong. Keep your exposure to what you actually did:

Private sector clients may ask for the same standard in their contracts, and the same discipline protects you there.

Signing off a release: what your report certifies

Testing shows the presence of defects, not their absence, and your sign-off should say so. Clients, and later their lawyers, will read a test completion report as a statement of fact, so write it as one.

A report that says “no defects found” without stating its scope is the hardest document to defend.

What PI covers for testers, and where cyber takes over

Usually covered by PIOften excluded or limitedNeeds a different policy
Defects missed through negligent test design or executionPromises that software is free of defectsA breach of your own systems and stored findings (cyber)
Outages or data damage caused by your tests, such as a load test in the wrong environmentWork outside the agreed scope or authorisationInjury or damage at a client site (public liability)
Negligent accessibility audits and conformance reportsFines, penalties and criminal proceedingsInjury to your own staff (employers’ liability)
Security tests that miss in-scope vulnerabilitiesThe cost of re-running your own testsLoss or theft of your own laptops and test devices (equipment cover)
Defence costs, including independent testing expertsClaims you knew about before the policy startedDirectors’ liability for running your firm (D&O)

Your systems hold some of the most sensitive material a client has: vulnerability findings, test credentials, network diagrams and sometimes live data. If attackers reach that store, cyber insurance usually pays for your investigation, recovery and notification costs. Claims from clients whose weaknesses were exposed through you are liability claims, which may fall to PI or to the cyber policy depending on the wordings, so check that the two fit. Avoid testing with live personal data unless the client has agreed how it will be protected and deleted.

How much cover, and for how long

Limits are usually set by the client or, when you test as a subcontractor, by the development or integration firm that engages you, which may pass down the insurance terms it agreed with the end client. Check whether a limit is each and every claim or aggregate, and whether your liability cap matches it.

Security and accessibility work can carry more risk than the fee suggests, because one missed finding can sit behind a large breach or a public complaint. PI is claims-made: the policy in force when a claim is made responds, and defects can surface long after release. Keep cover continuous, keep your retroactive date when you change insurer, and arrange run-off if you stop trading. For more on choosing a figure, see how much PI cover you need.

What insurers will ask you

A complete proposal gets better terms than a bare one, and a broker can only present what you tell us. Have these ready:

Speak to a broker

PI for software testers, placed by a named broker

Start the online proposal and save it as you go, or leave your number and a named broker will call you back, usually the same working day.

Start your PI proposal →or call 0117 325 0027

How Apex places this cover

Apex Insurance Brokers is an independent insurance broker based in Bristol, established in 2009 and authorised and regulated by the Financial Conduct Authority. We are not tied to one insurer: we work with over 30 markets, including Lloyd’s syndicates through wholesale brokers, and every client has a named broker who handles the placement, mid-term changes, certificates for clients and the renewal.

Related guides

Sources

Frequently asked

Do software testers need professional indemnity insurance?

Yes, if clients rely on your testing to release software, publish an accessibility statement or judge their security. A missed defect, a misleading report or a test that causes an outage can cost a client a great deal, and public liability won’t pay. PI covers defence costs and compensation for negligence claims, subject to the policy terms.

Is PI a legal requirement for software testers?

No law requires software testers to hold PI. In practice clients and the development or integration firms that subcontract testing make it a contract condition, usually with a minimum limit. Public sector and security work can come with stricter insurance and accreditation requirements set in the tender or contract.

Can a client sue us for a bug we didn’t find?

It can try. Testing cannot prove software is defect-free, so the question is whether your testing met a competent standard for the scope agreed. A clear test plan, agreed exit criteria and a completion report listing what was and wasn’t tested are your strongest defence, and PI pays to defend the claim, subject to the policy terms.

Do we need written authorisation for a penetration test?

In practice, yes. Under the Computer Misuse Act 1990, access is unauthorised if you are not entitled to control it and lack consent from someone who is. Get written authority from the system owner setting out targets, techniques and timings, and check whether cloud or hosting providers must also agree.

Does PI cover an accessibility audit that missed failures?

It can, if the audit was negligent and the client lost money as a result, such as re-auditing, fixing content or correcting its accessibility statement, subject to the policy terms. Declare accessibility work to your insurer, and state the standard, version, sample and method in every report.

Does PI cover a load test that takes down a live system?

Usually, if the outage resulted from a negligent mistake, such as running a script against the wrong environment, and the client claims its financial loss, subject to the wording. Public liability covers physical damage, not downtime. Agree test windows, target environments and third-party approvals in writing beforehand.

Ready to compare cover?

Apex arranges professional indemnity insurance for software testers across the UK. Tell us about your work and we’ll find cover that fits. Or call 0117 325 0027.

Start your PI proposal Call 0117 325 0027

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not advice on your individual circumstances. Cover is always subject to the insurer’s acceptance and the policy terms, and this page does not guarantee that cover will be available or on what terms.