Skip to content
Compliance requirements / Cyber insurance

Cyber insurance penetration testing requirements

No standard — the underwriter decidesIndividual carriers and their application forms

There is no standard to comply with, which makes this the most misunderstood item on the list. Whether a penetration test is required depends entirely on the carrier, the limit you are asking for, and your sector. What is consistent is that testing questions now appear on most applications, that answers form part of the representations the policy is written on, and that inaccurate answers give an insurer grounds to contest a claim.

How often

Whatever you stated on the application. Annual is the most common answer given, and therefore the most common commitment made.

What is in scope

Usually the internet-facing estate at minimum. Higher limits often bring expectations of internal and application testing too.

The actual text

Clause by clause.

What the standard says, rather than what a vendor says it says. Quote these references directly when you are asked to justify a testing programme internally.

ReferenceRequirement
Application
The proposal form
Most carriers now ask directly whether penetration testing is performed, how often, by whom, and whether findings are remediated. These answers are representations relied upon in underwriting.
Warranties
Policy conditions
Some policies include conditions or warranties requiring stated controls to be maintained during the policy period. Where testing is named, letting it lapse can affect cover.
Limits
Higher limits, harder questions
Testing evidence is more often required as requested limits increase, and for sectors carriers regard as higher hazard — healthcare, financial services, managed service providers and anyone holding large volumes of personal data.
Claims
Post-incident scrutiny
After an incident, carriers examine whether the control posture described at underwriting was accurate. A test that was promised annually and last performed three years ago is exactly the discrepancy that gets found.
Evidence

What the assessor wants to see.

Work through it here. Progress is kept in your browser, and copy or print drops it straight into an audit folder.

evidence checklist
4 items to evidence

Tick what you already hold. Progress is saved in this browser only — nothing is sent anywhere — and copy or print puts it into your audit folder.

Failure modes

Where people lose the point

  • Answering the application optimistically. The form is a representation, not a marketing document.
  • Declaring annual testing and then letting it slide, while the policy renews on the original answer.
  • Assuming a vulnerability scan satisfies a question that asks about penetration testing.
  • Not telling the broker when the estate changes materially mid-term.
  • Treating the certificate as the goal rather than the reduction in the loss the policy exists to cover.
Questions

Cyber insurance and penetration testing

Does cyber insurance require a penetration test?
Not universally. There is no standard, so it varies by carrier, limit and sector. What is close to universal is that the application asks about testing, and that the answer becomes part of the basis on which the policy is priced and written. The practical question is less "is it required" and more "what did we say we do, and do we do it".
Will penetration testing reduce our cyber insurance premium?
Sometimes, but it is rarely a simple discount. Testing tends to matter as one of a set of controls — alongside multi-factor authentication, endpoint detection, backup and recovery, and privileged access management — that together determine whether a carrier will offer cover at all, at what limit, and with what retention. Improving the answer to several questions moves terms more than perfecting one.
Can an insurer deny a claim because we did not penetration test?
An insurer can contest a claim where the representations made at underwriting turn out to be inaccurate, or where a policy condition requiring specific controls was not met. That is a materially different thing from denying a claim simply because a test was not performed. The risk sits in the mismatch between what you declared and what was true — which is a documentation problem as much as a security one.

For the longer narrative treatment — worked examples, cost and timing — read Cyber insurance and pentesting: how it affects premiums.

Testing that produces evidence, not just findings.

Reports mapped to the control they satisfy, with a replayable record behind every finding — which is what an assessor asks for when they push back.