Cyber Insurance Requirements in 2026: The Controls Underwriters Actually Check

The direct answer: there is no published standard for cyber insurance requirements, but in 2026 underwriters converge on a short list of controls they check and expect you to evidence. Phishing-resistant multi-factor authentication covering privileged accounts, email, and remote access, with legacy authentication paths closed. Endpoint detection and response across endpoints including servers, backed by 24/7 monitoring or a managed detection service. An incident response plan that has actually been tested, with the record to prove it. Immutable or offline backups. Mailbox-level detection for business email compromise. And documented third-party risk oversight. These are market expectations reported by brokers and security vendors, not rules issued by a standards body, so treat the specifics as directional. What is not directional is the evidence: what you can prove now drives both whether you are insurable and what you pay.
Market conditions verified August 27, 2026. This page is updated when underwriting expectations shift.
The application stopped being a questionnaire
The structural change in 2026 is that the cyber insurance application functions as a technical audit. Broker and vendor commentary through the year describes applications that ask for coverage percentages rather than yes or no answers, ask who monitors detections outside business hours, and ask when the incident response plan was last exercised. One 2026 summary of underwriter expectations frames the whole exercise around proof rather than assertion, and others tracking how requirements are changing describe the same shift.
The practical consequence for a mid-market company is that the person filling out the application is no longer the right person to own it alone. An office manager or a generalist IT lead can answer a questionnaire. Producing a coverage report from your identity provider, a deployment report from your endpoint agent, and a dated tabletop record is a different job. That gap is where renewals go badly, and it usually shows up three weeks before the policy period ends.
The control list, and what counts as evidence
The table below is the working checklist. The left column is what underwriters ask about. The right column is what you should have ready before anyone asks, because an answer you cannot substantiate is underwritten as if the control is absent.
| Control | What the 2026 application asks | Evidence to have ready |
|---|---|---|
| Multi-factor authentication | Phishing-resistant factors preferred, full coverage of privileged accounts, email, and remote access, legacy authentication disabled | Identity provider coverage report, enrolled accounts against total, conditional access policy export |
| Endpoint detection and response | Effectively full endpoint coverage including servers, with 24/7 monitoring or a managed detection service behind it | Agent deployment report against the asset inventory, service contract or roster showing after-hours coverage |
| Incident response | Plan exists, plan has been tested, and someone can say when | Dated tabletop report with participants, scenario, findings, and what changed afterward |
| Backups | Immutable or offline copies, isolated from production credentials, and restores that have been proven | Configuration showing immutability or air gap, plus a restore test record with dates and outcome |
| Business email compromise | Mailbox-level detection, not just a gateway filter, and controls on payment change requests | Tooling configuration, authentication records for your sending domain, the written funds-transfer verification procedure |
| Third-party risk | A vendor inventory, tiering by access and criticality, and evidence that reviews actually happen | Vendor register with review dates, collected attestations, contract security terms |
One caution on numbers. Broker and vendor sources in 2026 quote figures such as full coverage on privileged accounts and endpoint coverage in the mid-nineties as percentages. Those are directional descriptions of what carriers look for, not thresholds published anywhere you can appeal to. Individual carriers set their own bar, and it moves with their loss experience.
Renewal inside the next two quarters?
A Z Cyber advisor can walk your environment against this list, show you which answers you can evidence today, and recommend what to close first.
Where mid-market applications actually fail
Three failure patterns account for most of the trouble, and none of them is a missing product.
Partial MFA coverage. The rollout reached the workforce and stopped short of service accounts, break-glass administrators, a legacy VPN concentrator, or a mail protocol that still accepts basic authentication. From the underwriter's side, a control with a documented bypass is not a control. The 2026 emphasis on phishing-resistant factors, meaning FIDO2 and hardware keys rather than push notifications an employee can approve by reflex, matters less than closing those paths first.
Servers left off the endpoint agent. This is the most common gap in this list when a company is otherwise well run. Laptops are covered because they are managed centrally. The file server, the domain controller, the hypervisor, and the twelve-year-old application host that nobody wants to touch are not, and those are precisely the assets ransomware operators go for. Paired with the 24/7 question, this is where a mid-market answer often turns from yes into a qualified maybe.
A plan with no test behind it. A written incident response plan is table stakes. What underwriters increasingly want is the artifact from exercising it: date, scenario, who participated, what broke, what changed. If a control review is coming, an untested plan is a document, not a capability, and time-to-respond is exactly what carriers are trying to price.
Zero Trust is entering the conversation as vocabulary
Carriers including Marsh and Chubb are cited in 2026 commentary as pulling Zero Trust principles into underwriting conversations. This is worth understanding correctly. No carrier is handing you a Zero Trust certification to pass. What is happening is that the questions are getting architectural: how are administrative privileges scoped, is remote access still a flat VPN into a flat network, is identity evaluated conditionally at each access, and what stops lateral movement once one workstation is compromised. Sources tracking 2026 requirements for businesses and the email-side priorities for the year describe the same drift toward architecture and evidence over product inventories.
Build the evidence pack before the renewal window
The work that changes a renewal outcome is done four to six months out, not in the two weeks a broker gives you. Start with the asset inventory, because every coverage percentage on the application is a fraction whose denominator you need to defend. Then produce the six evidence artifacts in the table above and date them. Then close the gaps you found, in the order the carrier weights them, which in practice means identity and endpoint coverage first.
This is ordinary program work, not an insurance project. The controls on the application are a subset of the domains any running program already operates, which we lay out in the fourteen domains of a well-run security program. If those domains have a standing owner and produce dated records as a side effect of running, the application is a reporting exercise. If they do not, the application becomes an emergency.
Two companion pieces cover the adjacent questions. For why carriers moved to evidence-based underwriting in the first place, read why carriers are demanding more and how to prove readiness. For the calendar and negotiation mechanics of the renewal itself, read how to walk into a renewal prepared.
Two Z Cyber entry points map directly to this. Insurance readiness scores your environment against what carriers underwrite on and shows which answers you can evidence today. A risk assessment is the broader version: your advisor applies the published methodology, tests the controls, and presents findings you can hand to a broker. In both cases the advisor reviews and recommends, and your team decides what to remediate and accepts the residual risk.
What to watch next
Two dated items intersect with underwriting over the next several months. First, the CIRCIA final rule is currently targeted for September 2026 publication, per CISA's July 2026 Unified Agenda preview, though the date has slipped repeatedly since the original October 2025 statutory deadline. Once final, covered entities across the sixteen critical infrastructure sectors would face 72-hour incident reporting and 24-hour ransomware payment reporting to CISA, which raises the stakes on the same tested incident response capability underwriters are already asking about. Coverage from July 2026 tracks the current timeline.
Second, the liability protections in the Cybersecurity Information Sharing Act of 2015 expire again on September 30, 2026, after a lapse in late 2025 and two short extensions. That does not change any control on your application, but it affects the threat intelligence feeds many mid-market programs consume through an ISAC or a managed detection provider, and it is worth a question to your provider before the date.
Watch your own renewal calendar first. If it opens in the next two quarters, the evidence pack is the project, and it starts with the asset inventory. Talk to a Z Cyber advisor and we will walk the list with you.
Frequently Asked Questions
What do I need for cyber insurance in 2026?
Brokers and carriers converge on a short control list: phishing-resistant multi-factor authentication covering privileged accounts, email, and remote access with legacy authentication disabled; endpoint detection and response across endpoints including servers, with 24/7 monitoring or a managed detection service; a tested incident response plan with the test record; immutable or offline backups; mailbox-level business email compromise detection; and documented third-party risk oversight. None of this is a published standard. It is the shape the application now takes.
Do cyber insurers require phishing-resistant MFA, or is app-based MFA enough?
App-based multi-factor authentication still gets answered on most applications, but the direction of travel in 2026 is toward phishing-resistant factors, with FIDO2 and hardware keys the preferred form. The sharper question underwriters ask is coverage, not factor type: whether privileged accounts, email, and remote access are covered without exception, and whether legacy authentication protocols that bypass the control are disabled. A partial rollout with legacy paths open reads as no control at all.
Do cyber insurance carriers require EDR on servers?
Servers are the coverage gap that most often surprises mid-market applicants. Endpoint detection and response is commonly deployed to laptops and desktops and left off file servers, domain controllers, hypervisors, and legacy application hosts, which is exactly where ransomware does its damage. Underwriters increasingly ask for effectively full endpoint coverage including servers, and pair the question with one about who watches the alerts at 3am.
What evidence do cyber insurance underwriters ask for?
Assume every yes on the application has to be provable. Useful evidence includes a coverage report from your identity provider showing enrolled accounts against total accounts, a deployment report from your endpoint agent showing covered assets including servers, the dated report from your last incident response tabletop, a restore test record showing a recovery actually succeeded, and current vendor assessments. Undocumented controls are underwritten as absent.
Are cyber insurers asking about Zero Trust?
Zero Trust language has started entering underwriting conversations, with Marsh and Chubb among the names cited in 2026 broker and vendor commentary. Treat it as vocabulary rather than a checkbox. In practice it surfaces as questions about segmentation, least privilege on administrative accounts, conditional access on identity, and whether remote access still depends on a flat VPN. Answering well means describing your architecture, not naming a product.
Subscribe for Updates
Get cybersecurity insights delivered to your inbox.


