Skip to contentAbout Fig Group
Insurance

Cyber Essentials and cyber insurance: evidence, underwriting, and the IASME scheme benefit (2026)

An evidence-led guide to how customers may use Cyber Essentials records in conversations with insurers, brokers, or underwriters, plus a clear explanation of the separate IASME-arranged scheme benefit.

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

8 min read

Share

Section 01

Cyber Essentials and cyber insurance: evidence, underwriting, and the IASME scheme benefit (2026)

Cyber Essentials can provide a documented record of foundational security controls. A customer may choose to share its certificate and supporting evidence with an insurer, broker, or underwriter when those records are relevant to an external review.

Insurance providers set their own information requirements and make their own decisions about eligibility, pricing, terms, limits, exclusions, and claims. Cyber Essentials certification does not guarantee any insurance outcome.

Section 02

The separate IASME scheme benefit

Eligible Cyber Essentials certificate holders may separately receive a cyber-liability benefit arranged by IASME through its insurance partner. Eligibility criteria and policy terms apply, and the benefit is available at scheme level rather than as a Fig product.

Customers should refer to IASME and the applicable policy documentation for current eligibility, limits, duration, exclusions, and other terms. Fig does not provide, advise on, recommend, arrange, distribute, place, bind, underwrite, or administer this benefit or any other insurance.

Section 03

How Cyber Essentials affects standalone cyber insurance

For separately purchased insurance, the relevance of Cyber Essentials depends on the provider's own review criteria. Four areas may arise in an evidence request:

1. Underwriting friction

An insurer or underwriter may ask whether an organisation holds Cyber Essentials or Cyber Essentials Plus. The certificate can provide evidence of an assessed control baseline, but the recipient decides what additional information is required.

2. Pricing and terms

Insurance providers use their own underwriting models. A certificate or supporting control evidence may be considered, but Fig does not predict or promise how it will affect pricing, terms, limits, or exclusions.

3. Cover limits and sub-limits

Requirements vary by provider, policy, sector, and organisation. Customers should ask their chosen insurer, broker, or underwriter which certifications and supporting records are relevant to the review.

4. Incident-time records

Cyber Essentials is a point-in-time assessment. Separate, maintained records can show how controls were operated after certification. Customers should take advice from their chosen insurer, broker, or legal adviser about policy conditions and any information required following an incident.

Records a customer may choose to share include:

  • Documentary evidence that the five controls were assessed and found compliant at the date of issue.
  • An entry on the IASME directory that pre-dates the incident.
  • Assessor feedback on the submission (available through the certification body's portal).

What it does not give them:

  • Proof that the controls were continuously maintained between assessment and incident.
  • Evidence of ongoing monitoring, patch cadence, or MFA coverage drift.

Fig Group's compliance platform can keep this evidence current between certifications. The customer controls any export and decides whether to share it externally. Fig does not administer or support an insurance claim.

Section 04

Preparing a customer-controlled export

Before sharing evidence externally:

1. Confirm what information the recipient has requested.

2. Review the scope and date of each record.

3. Remove information that is not relevant or appropriate to disclose.

4. Confirm who is authorised to receive the export.

5. Keep a record of what was shared and when.

Where the request concerns disclosure obligations, policy interpretation, or insurance advice, customers should speak to their chosen authorised broker, insurer, underwriter, or legal adviser.

Section 05

What Fig does and does not do

Fig provides compliance software, certification services, and evidence reporting. It helps customers keep governance and security records current and export them in a structured format.

Fig does not:

  • recommend an insurance product or provider
  • advise on insurance coverage or policy terms
  • introduce customers to insurers or underwriters
  • complete or submit insurance applications
  • distribute, place, bind, or underwrite policies
  • administer policies, renewals, or claims
  • promise premium, coverage, renewal, or claim outcomes

Section 06

Bottom line

Cyber Essentials and maintained compliance records can support an evidence-led conversation with an insurer, broker, or underwriter. The customer controls what is shared, and the insurance provider makes every insurance decision independently.

Start Cyber Essentials from £299.99 + VAT | Insurer-grade evidence | All pricing | Free readiness check

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig handles this?

Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig