Cyber Insurance Subjectivity Tracker
United Kingdom

Cyber insurance conditions in the United Kingdom, on a 90-day clock

In the United Kingdom the core list is UK Cyber Essentials, cited by its CE codes; our copy states no version, so the edition reads "as held". The test steps of Cyber Essentials Plus are not used. A control Cyber Essentials does not cover (backups, for example) is on the schedule as a condition beyond the core list. PCI DSS is an add-on when the business takes card payments.

Your insurer or broker sets day 0; each gap gets a checkpoint at day 30, 60 or 90 by the default rule, and the applicant reports each fix closed through a private link. Start from the United Kingdom template, or mark the controls in the control list.

The controls with a rule in the core list here (17)

Rule sets