Cyber Essentials and insurance — the free cover, and what it means for your premiums
A pass comes with £25,000 of cyber liability insurance at no cost for the twelve months of the certificate. Here is what the cover includes, who qualifies, why underwriters care about the certificate, and where it stops.
The short answer
Every UK organisation with turnover under £20 million that passes Cyber Essentials gets cyber liability insurance included free for the twelve months of the certificate — £25,000 of cover, with no excess, arranged through the scheme rather than bought by you. It's automatic on a pass, provided you opt in on the application form and give a domain registered in the UK. It is not a substitute for a proper cyber policy, but for a small business it is real cover for nothing.
What the free cover actually includes
- Limit: £25,000 aggregate for the certificate year.
- Excess: none.
- Covers: breach response costs — forensic investigation, legal and regulatory help, notifying affected people, crisis PR — and third-party liability arising from a data breach or cyber event.
- Includes: access to a 24-hour incident helpline, which for a small business without an IT department is worth more than the limit.
- Eligibility: UK-domiciled organisation, turnover under £20 million, whole organisation certified (not a partial scope), and the opt-in box ticked on the self-assessment.
You'll receive the policy documents from the insurer shortly after your certificate — separately, and often overlooked in the inbox. File them with the certificate.
Why insurers care about the certificate
Cyber Essentials is the baseline most cyber and professional indemnity underwriters now ask about, because the five controls it tests are the ones that stop the majority of everyday attacks. Holding it can lower a cyber premium, unlock cover that would otherwise be declined for a small firm, and — increasingly — is written into policy conditions: if the wording says you'll keep supported software and MFA on cloud accounts and you don't, a claim can be reduced or refused. The certificate is your evidence that you did.
What the free cover doesn't do
It won't cover business interruption, ransomware payments, funds transfer fraud or the cost of rebuilding systems — the losses that actually close small businesses. £25,000 disappears quickly in a real incident. Treat the included policy as a floor and, if you handle customer data, hold client money or depend on your systems to trade, talk to a broker about a standalone cyber policy. Many will ask for the certificate first; a few will insist on Cyber Essentials Plus.
Certificate first, then the broker conversation
The sensible order is: certify, collect the free cover, then take the certificate to your insurance broker and ask what it does to your premiums and cover options. Brokers we work with report the conversation goes very differently when the certificate is already on the table. If you're a broker yourself, here's how we work with you.
Keep it continuous
The insurance runs with the certificate, so a gap in certification is a gap in cover. Start renewal six weeks before expiry and the badge, the register entry and the policy all stay unbroken. What the certificate itself costs is in our cost guide.
Before anything else, run our free readiness check against the current rules — it flags the MFA and 14-day traps specifically, so you know in two minutes whether this year's renewal is a formality or a project.
Certify, collect the cover, then talk to your broker.
Fixed price, current-rules review before submission, fixes included, resubmission covered. We’ll make sure the insurance opt-in is ticked so the cover actually arrives.
hello@passcyber.co.uk · Take the readiness check
PassCyber is a trading name of Edwards Bros (Spaldwick) Ltd