Cyber insurance applications have changed substantially since 2021. What was once a relatively brief questionnaire has become a detailed technical assessment of your security controls, and penetration testing has moved from an optional differentiator to a mandatory requirement at most carriers and coverage tiers above $1 million.
The challenge for organisations renewing coverage or applying for the first time is that the requirement is rarely specific. The questionnaire asks: "Do you conduct penetration testing?" An organisation that runs an automated scanner annually answers yes. An organisation that conducts thorough third-party penetration testing with full exploitation confirmation also answers yes. Underwriters are increasingly aware of this ambiguity and increasingly asking follow-up questions that distinguish the two.
This guide maps what cyber insurance underwriters actually examine about penetration testing, what distinguishes a pentest that satisfies underwriting requirements from one that does not, and how the testing programme you maintain affects both your ability to obtain coverage and the premiums you pay.
Why cyber insurers require penetration testing
The shift toward mandatory penetration testing requirements reflects a fundamental change in how cyber insurers price and manage risk. The surge in ransomware claims between 2019 and 2022 showed that organisations with weak security controls produced dramatically higher claim rates and claim sizes than those with mature controls. Insurers responded by using the underwriting application as a security assessment tool.
Penetration testing satisfies a specific underwriting need: it provides evidence that security controls have been tested under adversarial conditions, not just implemented and attested. A SOC 2 report tells the underwriter that a control existed and operated during the audit period. A penetration test report tells the underwriter whether that control would hold against an attacker who actively tried to bypass it.
The distinction matters for insurance underwriting in the same way it matters for actual security: a control that exists on paper but fails under testing creates real risk. Insurers who absorbed large claims from organisations with apparently complete control inventories learned to ask for testing evidence.
What counts as penetration testing for underwriting purposes
Underwriters do not all use the same definition of penetration testing, and carriers vary significantly in their requirements. The spectrum of what organisations submit under the "penetration testing" label runs from automated vulnerability scanners through DAST tools through genuine third-party penetration testing with active exploitation.
The clearest dividing line that the most rigorous underwriters draw: does the testing include active exploitation with proof of what is actually exploitable, or does it identify potential vulnerabilities without confirming them?
Automated vulnerability scanning fires signatures at known inputs and matches responses against vulnerability patterns. It finds potential CVEs in known software versions and known vulnerability signatures. It does not confirm exploitability. Underwriters who ask for evidence of penetration testing and receive a scanner report are increasingly noting the distinction.
DAST tools test running web applications through their external interface using signature matching. More thorough than network scanners, still not exploitation-confirmed.
Third-party penetration testing with active exploitation is what underwriters mean when they explicitly require penetration testing: independent testers attempting to exploit vulnerabilities and documenting what is actually exploitable with proof. The report contains confirmed findings rather than potential findings.
If your cyber insurance application asks "do you conduct annual penetration testing?" and your programme consists of automated scanning, the honest answer depends on how the insurer defines the term. The safer path (and the path that produces better security outcomes) is commissioning genuine third-party penetration testing with active exploitation for renewal cycles.
What the penetration test report should contain
Underwriters reviewing penetration testing evidence look for specific content in the report that distinguishes a credible assessment from a checkbox exercise. What is inside a VAPT report and what's in a penetration testing report: a buyer's breakdown cover the full report anatomy. For underwriting specifically, the following elements carry the most weight.
Testing firm independence. Reports from internal teams or from the same vendor providing other security services receive less weight than reports from independent third-party firms. Some carriers specifically require testing by firms they have approved or that hold specific accreditations (CREST, OSCP-certified testers).
Scope statement. The scope section should cover systems that the underwriter would consider material to the risk: internet-facing applications, remote access infrastructure, email systems, systems containing customer data. A scope limited to a development environment or a single non-critical system raises questions about coverage completeness.
Testing date. Most underwriters require penetration testing within the last twelve months for the evidence to be current. Some carriers are moving to six months for higher coverage tiers, particularly for organisations that experienced a claim or that are in higher-risk industries.
Finding distribution and severity. The finding severity distribution tells the underwriter something about both the security posture and the quality of the testing. A complex application environment with zero findings raises questions about testing depth. A report with only low-severity findings may indicate incomplete scope. High or critical findings that have been remediated with retest confirmation are generally acceptable: they demonstrate that the process works.
Remediation status. Unmediated critical findings at renewal are a coverage concern. Most carriers expect critical findings to be remediated before binding coverage or will note them as exclusions. Documented remediation with retest confirmation is the appropriate response.
Retest evidence. For findings remediated since the last test, retest confirmation that the vulnerability is closed carries more weight than a developer's statement that it was fixed.
The broader control environment: what else insurers review
Penetration testing is one element of the underwriting assessment. The security controls that underwriters consistently evaluate alongside testing requirements include the following.
Multi-factor authentication (MFA). The single control most consistently linked to ransomware claim prevention. Carriers who experienced large claims from ransomware attacks originating through credential compromise moved MFA from optional to mandatory for most coverage tiers. MFA enforcement on email, remote access (VPN, RDP), and privileged account access is typically required. Phishing-resistant MFA (hardware keys, passkeys) is increasingly preferred for privileged access.
Endpoint detection and response (EDR). Traditional antivirus is no longer sufficient for most carriers. EDR with active monitoring (not just installed but monitored, with alerting, and with response capability) is a standard requirement. Some carriers specify managed EDR with 24/7 monitoring as a requirement for coverage above certain limits.
Privileged access management (PAM). Separation of privileged from standard user accounts, controlled access to administrative interfaces, and session recording for privileged access are increasingly reviewed. Shared administrator passwords with no individual accountability are a significant underwriting concern.
Backup and recovery. Offline or immutable backups (backups that cannot be encrypted by ransomware affecting the primary environment) are a standard requirement. Backup testing (periodic recovery tests that confirm backups are restorable) is increasingly required rather than just assumed. Coverage for ransomware extortion events is often conditioned on documented backup capability.
Email security. Email filtering with anti-phishing controls, DMARC enforcement, and user security awareness training are standard requirements. The combination of email as the primary ransomware delivery vector and the measurable reduction in successful phishing from technical controls makes email security a high-weight factor.
Incident response plan. A documented incident response plan with named roles, defined procedures, and evidence of testing (tabletop exercise within the last year) is increasingly required rather than optional. Carriers who paid large claims to organisations that had no incident response plan and made avoidable decisions under pressure have priced this control into their requirements.
How penetration testing frequency affects coverage and premiums
Penetration testing frequency is evaluated as part of the overall security programme maturity signal the underwriter is building. The standard minimum (annual penetration testing) satisfies most carriers' basic requirements. Organisations that test more frequently communicate a more mature security programme, which underwriters price favorably.
Annual testing is sufficient for basic coverage tiers. Some carriers ask whether post-change testing occurs following significant infrastructure changes. For organisations shipping software continuously, the question of whether penetration testing occurs between annual cycles (or whether each deployment cycle is validated) is becoming relevant to underwriting assessments at higher coverage limits.
Continuous penetration testing and how it differs from annual pentests covers the model in detail. For organisations at the largest coverage tiers or in high-risk industries (healthcare, financial services, critical infrastructure), demonstrating that security testing runs at the pace of software deployment rather than once annually is an increasingly meaningful differentiator in underwriting conversations.
The premium implications are real. Cyber insurance pricing since 2021 has incorporated security control assessments directly into rate calculations. Organisations with documented annual penetration testing, remediated findings, and a complete control environment pay materially lower premiums than those with gaps: not as a discount, but as a base rate that reflects lower expected claim probability.
Industry-specific considerations
Cyber insurance requirements vary by industry, driven by the regulatory frameworks that define baseline security requirements and by the claim history that shapes actuarial risk models.
Healthcare. HIPAA creates baseline security requirements for covered entities and business associates. Underwriters assessing healthcare organisations look for HIPAA Security Rule compliance alongside penetration testing. The combination of high-value patient data, often underfunded security programmes, and active targeting by ransomware groups makes healthcare a high-risk category with correspondingly stringent underwriting requirements.
Financial services. PCI DSS Requirement 11.4 mandates annual penetration testing for organisations handling card data. SOC 2 penetration testing: what auditors actually require covers SOC 2 testing evidence that financial services SaaS organisations commonly need to provide alongside insurance documentation.
Critical infrastructure and manufacturing. OT/ICS environments create specific testing requirements: active exploitation against operational technology requires more caution than IT testing. Some carriers ask specifically whether OT systems have been assessed, with specialized methodology rather than standard IT penetration testing.
Technology companies. SaaS and software companies face both direct insurance requirements and customer-driven requirements: enterprise customers increasingly require penetration testing evidence in vendor security assessments. The testing programme that satisfies insurance underwriting often also satisfies enterprise customer requirements. 8 questions to ask before buying vulnerability scanning services covers evaluation criteria relevant for both insurance and enterprise customer requirements.
Submitting penetration testing evidence for insurance renewal
For organisations approaching cyber insurance renewal, a practical process for preparing penetration testing evidence:
Confirm the testing window. Verify that your most recent penetration test was conducted within the period the carrier requires (typically twelve months, sometimes six months for higher-risk profiles or higher coverage tiers).
Review the scope for material coverage. Confirm that the scope covered the systems the insurer would consider material: internet-facing applications, remote access infrastructure, systems containing customer data, email infrastructure. If significant systems were excluded from scope, the carrier may ask follow-up questions or require supplementary testing.
Review the finding status. Critical and high findings should be remediated with retest confirmation. If open critical findings remain from the last assessment, document the remediation plan and timeline before submission: carriers will ask.
Confirm tester independence. If your testing was conducted by an internal team or by a vendor providing other security services, assess whether the carrier's requirements specify third-party independence. Some applications ask this explicitly.
Prepare for follow-up. Underwriters reviewing penetration testing evidence increasingly follow up with specific questions: Who conducted the test? What scope was covered? What was the highest severity finding and what is its status? Having clear answers to these questions (and documentation to support them) accelerates the underwriting process.
For penetration testing services in the US producing independent third-party penetration testing evidence that satisfies cyber insurance underwriting requirements, VAPT services for the evidence format, and PTaaS for continuous testing that demonstrates testing cadence above the annual minimum, the 10x Pentest platform covers the application security layer. See pricing or get in touch to discuss producing penetration testing evidence that satisfies your specific carrier's requirements. Network penetration testing: what it covers and how it's done covers the network layer assessment that complements application penetration testing for comprehensive insurance evidence. Penetration testing scope: how to define it before you start covers ensuring scope matches what your insurer considers material. Agentic pentesting and continuous security validation covers the continuous testing model.
Frequently asked questions
Q1. Do cyber insurance underwriters require penetration testing?
Most cyber insurance carriers require some form of penetration testing as a condition of coverage above basic limits, though requirements vary significantly by carrier, coverage tier, and industry. At coverage levels above $1 million, most carriers ask specifically whether annual penetration testing is conducted. Some carriers distinguish between automated scanning and genuine third-party penetration testing with active exploitation. At higher coverage limits and for organisations in high-risk industries, requirements for third-party independent testing conducted within the last twelve months are increasingly standard.
Q2. What does a cyber insurer mean by penetration testing?
The definition varies by carrier and is often ambiguous in the application. In the strictest interpretation, underwriters mean third-party penetration testing with active exploitation by independent testers: a process that produces confirmed exploitable findings rather than potential vulnerabilities from signature matching. In practice, many carriers accept automated scanning under the penetration testing label. Organisations that want their testing to credibly satisfy underwriting requirements (and that want to avoid coverage disputes at claim time) should commission independent third-party penetration testing with exploitation confirmation rather than automated scanning.
Q3. How does penetration testing affect cyber insurance premiums?
Penetration testing is one component of the overall security programme assessment that underwriters use to determine premium rates. Organisations with documented annual penetration testing, remediated findings, and a complete surrounding control environment (MFA, EDR, PAM, offline backups, incident response plan) pay materially lower premiums than those with gaps. The magnitude of the premium impact depends on the carrier's pricing model and the organisation's overall risk profile. Carriers who have built actuarial models from claim data consistently find that organisations with strong security controls produce lower claim frequencies and lower claim severity, which is reflected in base rate pricing.
Q4. What should a penetration test report contain for cyber insurance purposes?
For underwriting purposes, the penetration test report should contain: identification of the testing firm (independent third party with relevant qualifications); scope statement covering material systems including internet-facing applications, remote access infrastructure, and systems containing customer data; testing date within the required window (typically twelve months); finding severity distribution showing what was found; remediation status for critical and high findings, with retest confirmation where applicable; and executive summary suitable for submission to the carrier alongside the detailed technical report. Carriers increasingly ask follow-up questions about the highest severity findings: having clear documentation of finding status and remediation reduces underwriting delays.
Q5. Is annual penetration testing sufficient for cyber insurance, or do insurers require more frequent testing?
Annual penetration testing satisfies most carriers' basic requirements for standard coverage tiers. Some carriers ask whether post-change testing occurs following significant infrastructure changes. At higher coverage limits, in high-risk industries, or for organisations that experienced a claim, some carriers are moving toward more frequent requirements or asking about continuous testing capability. Continuous or deployment-triggered penetration testing demonstrates a more mature security programme that underwriters price favourably, though it is not yet a universal requirement. As underwriting requirements continue to tighten, the gap between annual and continuous testing is increasingly relevant to underwriting conversations.