What Cyber Insurance Requirements Look Like in 2026

Decorative title card illustration

Carriers now expect six baseline controls before they’ll write you a policy: multi-factor authentication on email, remote access, and admin accounts; EDR or MDR on every endpoint; immutable or offline backups with documented restore tests; a written and tested incident response plan; a patching cadence with no unsupported systems; and privileged access management with clean email security. That’s the checklist. The harder part is that carriers no longer take your word for it.

Underwriting has turned into an evidence-based process, with insurers running external scans and asking for screenshots, exports, and restore-test logs before they’ll bind or renew a policy. Missing a control can mean a declined application or a coverage exclusion carved right into your policy.

Pro Tip: Start gathering proof 60 to 90 days before your renewal or binding date. MoneyGeek’s underwriting research shows that’s the window most brokers recommend to fix gaps without scrambling.

Key Takeaways

Cyber insurance requirements in 2026 center on six controls (MFA, EDR/MDR, immutable backups, tested incident response, current patching, and locked-down privileged access) backed by verifiable evidence, not self-reported claims.

Point Details
Four controls dominate underwriting MFA, EDR/MDR, immutable backups, and a tested IR plan are the near-universal baseline carriers check first.
Evidence beats claims Carriers verify answers with external scans and request exports, screenshots, and restore-test logs.
Start 60 to 90 days early Begin gathering proof and fixing gaps well before your renewal or binding date to avoid a scramble.
Regulated industries need more Healthcare, retail, finance, and government contractors face added documentation like HIPAA safeguards or CMMC alignment.
Architechmsp speeds evidence collection Its free assessment and managed security services map controls to underwriting questions and produce proof packets faster.

Cyber Insurance Requirements Checklist: What Carriers Actually Ask For

Every underwriting questionnaire boils down to the same question asked six different ways: can you prove you’d survive an attack? Here’s what each control means in practice and what “proof” looks like when a carrier asks.

Multi-factor authentication. Insurers want MFA on email, remote access (VPN, RDP), and every privileged or admin account. Phishing-resistant methods like FIDO2 keys or passkeys are increasingly preferred over SMS codes, especially for admin access. You’ll need to export coverage reports from Azure AD, Okta, or whatever identity provider you run, showing which accounts have MFA enabled and which method they use.

Diagram of multi-factor authentication requirements and methods

EDR and MDR. The denominator matters here. Carriers don’t ask “do you have EDR?” They ask what percentage of endpoints and servers it covers.

Backups. The standard here is 3-2-1: three copies of data, on two different media types, with one copy offline or immutable so ransomware can’t touch it. But the control that actually gets checked is the restore test. Carriers want a log showing you restored from backup on a specific date, how long it took (your recovery time objective), and how much data you’d have lost (your recovery point objective). Architechmsp builds backup and disaster recovery validation into ongoing service, specifically because untested backups fail silently, often at the worst possible moment.

Technician testing backup restore in server room

Incident response. A plan sitting in a drawer doesn’t count. Carriers want a dated tabletop exercise, meaning your team actually walked through a simulated breach scenario in the last 12 months, plus a contact list of internal responders and any outside IR retainer you’ve signed. Having a retainer with a response firm on standby is increasingly treated as its own line item on applications.

Patch management. Most carriers now expect critical, internet-facing vulnerabilities patched within 30 days of disclosure. You also need an inventory showing no end-of-life operating systems or unsupported software running in production, or documented network segmentation isolating anything you can’t retire yet.

Privileged access management. This means inventorying every account with elevated permissions and confirming daily users aren’t logging in with domain admin credentials to check email. Separation between admin accounts and regular work accounts is a specific, checkable item.

Email security. SPF, DKIM, and DMARC configured and enforced, plus inbound filtering and specific controls against business email compromise, like verification steps before wiring funds based on an email request.

External attack surface. Carriers frequently run their own scans of your public-facing infrastructure before binding a policy. Open ports, expired certificates, and exposed admin panels show up here, and remediation timelines get scrutinized.

Vendor and funds-transfer controls. Dual authorization on wire transfers and documented vendor verification steps close one of the most common fraud vectors insurers see.

Building the Proof Packet Underwriters Want to See

Insurance applications have grown to 12 to 20 pages of fine-grained control questions, and carriers cross-check answers against what they find in external scans. Treat the application like an audit, not a form to fill out quickly.

Here’s the artifact list that maps directly to what underwriters ask:

  1. MFA coverage export from your identity provider, showing enrollment percentage by account type
  2. EDR/MDR coverage report listing agent deployment percentage across endpoints and servers
  3. Backup restore test log with date, duration, and data recovered
  4. Patch management report showing time to patch for critical vulnerabilities
  5. IR tabletop exercise notes with date and participants
  6. IR retainer contract or SLA, if you have one
  7. Privileged account inventory with separation-of-duties confirmation
  8. Vendor security attestations for critical third parties

Some of these are machine-verifiable, meaning a carrier’s own scanning tools can confirm them independently. Others, like tabletop notes, are manual and depend on you keeping accurate records with timestamps. COMNEXIA’s research on 2026 qualifying standards notes that evidence provenance, meaning when an artifact was created and whether it’s been altered, matters as much as the artifact itself.

Carriers distinguish between having a control and being able to prove it. As artifacts age, insurers may run mid-term scans that trigger remediation demands or, in worse cases, coverage exclusions.

If a control is only partially in place, don’t fudge the application. State the honest current status and attach a remediation timeline.

Your 60 to 90 Day Path to Insurance-Ready

Waiting until the week before renewal to gather proof is how businesses end up with declined applications or gutted coverage. Work backward from your binding date instead.

  1. Days 1 to 7: Enforce MFA on email, admin accounts, and your backup console immediately. Confirm EDR is actually installed on every endpoint, not just the ones IT remembers. Run a backup restore test and write down what happened.
  2. Days 7 to 30: Close obvious external exposure (open ports, expired certificates). Inventory any end-of-life systems and either retire or isolate them. Schedule your IR tabletop exercise and pull together training completion records.
  3. Days 30 to 60: Finish your privileged account inventory and separate admin credentials from daily-use accounts. Collect EDR/MDR monitoring logs covering at least 30 days. Run a second restore test if the first one surfaced problems.
  4. Days 60 to 90: Assemble every artifact into a single packet, mapped question-by-question to your carrier’s application. Loop in your broker early. Where a control still isn’t complete, write the remediation date down and be upfront about it.

Pro Tip: Keep this packet updated year-round instead of rebuilding it from scratch each renewal. Carriers increasingly run mid-term checks, and a stale proof packet is nearly as bad as no proof at all.

Industry Notes: HIPAA, PCI, and Government Contracts

Regulated sectors carry extra weight in underwriting. Healthcare practices need documented HIPAA safeguards and breach notification procedures, and suggested limits for small practices often run $2 million to $5 million given the cost of a patient data breach. Architechmsp’s HIPAA IT requirements guide covers what Massachusetts practices specifically need on file.

Ransomware coverage adds another layer. Sub-limits and co-insurance clauses are common, and some policies require pre-approval before you pay a ransom, so read that section of your policy carefully before you need it.

Data Protection and Encryption Requirements

Encryption shows up on nearly every cyber insurance questionnaire, and carriers ask about it in two separate places: data at rest and data in transit. Data at rest means anything sitting on a server, laptop, or backup drive. Insurers want full-disk encryption on laptops (BitLocker for Windows, FileVault for Mac) and encrypted storage for databases holding customer records, health information, or payment data.

Data in transit means information moving between systems, like an employee accessing files remotely or a payment processor communicating with your point-of-sale system. TLS 1.2 or higher is the baseline most carriers expect for any web-facing application handling sensitive data.

Beyond encryption itself, underwriters increasingly ask about data classification, meaning whether you actually know where your sensitive data lives. A business that can say “customer records live in these three systems, all encrypted, with access limited to these five people” answers the questionnaire faster and more credibly than one that says “we encrypt everything” without specifics.

Mobile devices deserve a specific mention. Laptops and phones that access company email or files need the same encryption standards as servers, plus remote wipe capability in case a device is lost or stolen. This is one of the more commonly overlooked items on applications, since businesses tend to think about encryption in terms of servers and forget the laptop an employee took home last Tuesday.

Hands initiating remote wipe on mobile device

Reporting Obligations and Timelines After a Breach

Your policy’s notification clause is not a suggestion. Most cyber insurance policies require you to notify the carrier within a specific window after discovering an incident, commonly 24 to 72 hours, though the exact number varies by policy and should be confirmed with your broker rather than assumed.

Miss that window and you risk a denied claim, even if the incident itself was covered. This trips up more businesses than any control gap, because the panic of an active breach makes “call the insurance company” feel less urgent than stopping the bleeding technically. Both have to happen at once.

Beyond the carrier, you likely have separate legal obligations. All 50 states have breach notification laws requiring you to inform affected individuals within a defined timeframe, and healthcare organizations face additional HIPAA breach notification rules with their own clock. These obligations run in parallel with your insurance notification requirement, not instead of it.

Many policies also require you to use a pre-approved incident response vendor from the carrier’s panel rather than a firm of your choosing, at least for the initial response. Bringing in your own forensics team before checking your policy’s panel requirements is a common and expensive mistake. Read this section of your policy before you need it, not during the incident.

Minimum Cybersecurity Standards Mandated by Insurers

There’s no single universal standard every carrier enforces, but the practical floor has become remarkably consistent across the market. Multiple carrier toolkits and underwriting guides converge on the same four controls as the near-universal baseline: MFA, EDR, immutable backups, and a tested incident response plan.

Below that floor, a business often can’t get quoted at all, or gets quoted with exclusions that gut the coverage’s usefulness. Above it, the specifics vary by carrier, industry, and revenue size. A $2 million manufacturing company faces different questions than a $50 million healthcare system, but both get asked about the same four fundamentals first.

What’s changed since 2023 is verification. A few years ago, checking a box on an application was often enough. Now carriers cross-reference your answers against external scans of your network, and some run these scans again mid-policy.

Think of these standards less as a compliance hurdle and more as the security posture that keeps you operating after an attack, regardless of whether you’re filing a claim. The businesses that treat underwriting requirements as a genuine security upgrade, rather than paperwork to get past, tend to need their policy less often.

Employee Training as an Underwriting Requirement

Human error remains the entry point for most breaches, and carriers have caught up to that reality. Security awareness training now shows up as its own line item on many applications, separate from the technical controls.

What insurers typically want to see is a defined training cadence, meaning employees complete security awareness modules on a set schedule (often quarterly or annually) rather than once at hiring and never again. Phishing simulation programs, where employees receive test phishing emails and their click rates get tracked, are increasingly requested as supporting evidence.

The documentation matters as much as the training itself. A completion log showing who took training, when, and what score they got turns a vague “we train our staff” answer into something a carrier can actually verify. Businesses that can’t produce this record often get treated the same as businesses with no training program at all, regardless of what they’ve actually done internally.

Training content should cover recognizing phishing attempts, verifying wire transfer requests before acting on them, and reporting suspicious activity quickly rather than trying to handle it quietly. That last point matters more than it sounds. Employees who delay reporting a suspected compromise because they’re embarrassed or unsure often turn a contained incident into a much larger one by the time IT finds out.

Cyber insurance requirements don’t exist in isolation from the legal obligations your business already carries, and carriers increasingly ask about both together. If your business handles protected health information, payment card data, or personal information covered by state privacy laws, your insurance application will likely ask you to demonstrate compliance with the relevant framework, not just describe your technical controls.

This overlap runs in both directions. A HIPAA compliance gap can affect your insurability and premium, while your cyber policy’s own reporting requirements sit alongside, not instead of, your state breach notification obligations. Massachusetts businesses in particular fall under 201 CMR 17.00, the state’s own data security regulation, which requires a written information security program for any business holding residents’ personal information.

Carriers also increasingly ask whether your contracts with vendors and clients include data protection clauses, since a breach originating from a vendor can still expose your business to liability. If you handle government contracts, alignment with NIST 800-171 or CMMC isn’t optional in the way it might be for a private-sector business; it’s often a contractual precondition that your insurer will also want documented.

The practical takeaway: don’t treat your insurance application and your regulatory compliance work as two separate projects. The evidence you gather for one almost always satisfies part of the other, and keeping them aligned saves real time when both come due at once.

Why Treating Underwriting as a Security Program Actually Works

The businesses that struggle most with cyber insurance requirements are the ones treating the application as a hoop to jump through rather than a security checkup with a deadline attached. Architechmsp built its six-step security framework around exactly this overlap: the controls that satisfy underwriters happen to be the same controls that keep small businesses operating after a real attack. An MSP that already monitors your endpoints, tests your backups, and logs your patch cadence can hand over evidence in days, not weeks, because the artifacts already exist as a byproduct of daily operations rather than a scramble before renewal.

— Tyson

How Architechmsp Gets You Insurance-Ready Faster

Chasing down MFA exports, EDR coverage reports, and restore-test logs on your own, on top of running a business, is exactly why so many SMBs miss their renewal window or get hit with exclusions they didn’t see coming. Architechmsp built its process around closing that gap.

Architechmsp

A free cybersecurity assessment maps your current controls directly against what underwriters ask, and hands you back a proof checklist showing exactly what’s covered and what’s missing. From there, Architechmsp’s managed cybersecurity services cover the pieces that carriers weight most heavily: EDR/MDR deployment and monitoring, backup validation with documented restore tests, IR tabletop exercises, patch management with SLA tracking, and privileged access cleanup. New Bedford and southeastern Massachusetts businesses get this delivered locally, with a zero-major-incident track record backing the work. Book the free assessment and find out exactly where your current setup stands before your renewal date arrives.

Sources

FAQ

What Are the Typical Requirements for Cyber Insurance?

Most carriers require MFA on email, remote access, and admin accounts, EDR or MDR on all endpoints, immutable or offline backups with tested restores, a documented incident response plan, current patching, and evidence you can produce on request for each.

Is Cyber Insurance Mandatory?

No federal or Massachusetts law requires cyber insurance outright, though some client contracts, vendor agreements, or industry regulations effectively require it as a condition of doing business.

Is Cyber Liability Insurance Mandatory?

Cyber liability insurance isn’t legally mandated in most states, but businesses handling payment card data, health records, or government contracts often find it required contractually even without a statutory mandate.

Do Small Businesses Need Cyber Insurance?

Small businesses are frequent ransomware targets precisely because attackers assume weaker defenses, and a single incident without coverage can mean six figures in recovery costs, legal fees, and lost business. Working with a managed provider like Architechmsp to build insurable controls reduces both your breach risk and your premium over time.