Quick Answer
A complete cyber insurance application takes 4 to 8 weeks from kickoff to bind in 2026 (Source: CISA cyber insurance resources, 2026). Carriers now require MFA on email/remote access, EDR on all endpoints, immutable backups with tested recovery, security awareness training, and documented incident response plan. The security questionnaire runs 100-300 questions across identity, data, network, endpoint, cloud, and IR domains. Clean applications with strong controls bind in 1-2 weeks.
Last verified: Sep 14, 2026.
At a glance
- Application timeline: 4-8 weeks (broker-experienced: 3-5)
- Required controls: MFA, EDR, immutable backups, training, IR plan
- Security questionnaire: 100-300 questions
- Clean applications bind in 1-2 weeks
- Brokers deliver 10-25% better premiums than generalist agents
The cyber insurance application workflow
Five phases take an application from kickoff to bound policy. Most delays happen in the security questionnaire and evidence collection phases.
| Phase | Activities | Duration |
|---|---|---|
| 1. Scoping | Define coverage scope, limits, deductibles, jurisdiction; engage broker | 1 week |
| 2. Questionnaire completion | Complete security questionnaire (100-300 questions) with evidence | 1-3 weeks |
| 3. Evidence collection | Gather MFA, EDR, backup, training, IR plan evidence | 1-2 weeks |
| 4. Underwriting review | Carrier review, follow-up questions, premium quote | 1-2 weeks |
| 5. Bind & issue | Quote acceptance, payment, policy issuance | 1-3 days |
Source: Coalition cyber insurance broker workflow, 2026.
Required controls checklist
Carriers now require this minimum control set. Any missing control triggers follow-up questions or premium surcharge.
| Control | Why Required | Evidence |
|---|---|---|
| MFA on email | Most breached vector | Entra ID / Okta MFA enforcement report |
| MFA on remote access | Common ransomware entry point | VPN / ZTNA MFA enforcement report |
| MFA on privileged accounts | Credential abuse risk | PAM tool report |
| EDR on all endpoints | Ransomware detection | CrowdStrike / Defender for Endpoint coverage report |
| Immutable backups | Ransomware recovery | Backup tool report with retention policy |
| Tested backup recovery | Recovery assurance | DR test report within 12 months |
| Security awareness training | Phishing defense | Training platform completion reports |
| Incident response plan | Coordinated response | Documented plan with roles and contacts |
| Vendor risk management | Supply chain exposure | Vendor assessment records |
| Vulnerability management | Patch hygiene | Vulnerability scan reports |
Source: Coalition, Chubb, AIG cyber insurance underwriting requirements, 2026.
The security questionnaire breakdown
Modern security questionnaires organize controls by domain. Most carriers map to the CIS Controls v8 or NIST CSF 2.0 framework, making evidence reuse straightforward if your security program is already structured.
| Domain | Question Count | Example Questions |
|---|---|---|
| Identity & Access | 15-25 | Do you enforce MFA on email? Do you review privileged access quarterly? |
| Endpoint & Network | 15-25 | Do you deploy EDR on all endpoints? Are network segments separated? |
| Data Protection | 10-20 | How is data encrypted at rest and in transit? Do you classify data? |
| Cloud Security | 10-20 | How do you monitor cloud workloads? Do you use CSPM? |
| Application Security | 10-15 | Do you run SAST/DAST? Do you have a secure SDLC? |
| Third-Party Risk | 5-15 | Do you assess vendor security posture? Do you require SOC 2? |
| Governance | 10-15 | Do you have an information security policy? Who is the CISO? |
| Incident Response | 10-20 | Do you have an IR plan? Have you run a tabletop exercise? |
| Business Continuity | 5-10 | Do you have a DR plan? What is your RTO/RPO? |
| Training | 5-10 | Do you run annual security awareness training? |
Source: Coalition, Chubb, AIG security questionnaire analysis, 2026.
How to maximize approval odds
Pre-application work dramatically improves approval and premium terms. Implement MFA first (the single biggest lever), then EDR, then immutable backups with tested recovery, then security awareness training, then SIEM or MDR coverage. Document everything in a security program overview that you can attach to every application. Choose higher retentions ($10K-$25K) to reduce premium without sacrificing meaningful coverage.
Internal links
See related cyber insurance and security operations guides: Cyber insurance cost, Ransomware negotiation cost, and MDR service cost.
FAQs
See FAQ section above for cyber insurance application timeline, required controls, security questionnaire structure, exclusions, and approval best practices.
Underwriting controls depth by tier
Underwriters tier controls and require deeper evidence at higher coverage levels. Small policies can be approved with minimal evidence; $5M+ policies require full documentation.
| Coverage Tier | Required Evidence | Typical Approval Time |
|---|---|---|
| Up to $1M | MFA, EDR, backups, basic IR plan | 1-2 weeks |
| $1M-$5M | MFA + EDR + backups + IR + training + vendor risk | 2-4 weeks |
| $5M-$25M | + PAM, MFA on service accounts, table-top exercise | 4-6 weeks |
| $25M+ | + SOC reports, full SOC 2 Type II, third-party assessments | 6-8 weeks |
Source: Coalition, Chubb, AIG underwriting requirements, 2026.
FAQ expansion
Q: Does cyber insurance cover ransomware payment to sanctioned threat actors? No. OFAC sanctions make it illegal to pay or facilitate payment to certain threat actors. Reputable carriers and negotiation firms screen threat actors against OFAC lists and refuse payment to sanctioned groups. The screening process is documented for legal defense.
Q: How often should I renew my cyber insurance? Most cyber policies have a 12-month term. Renewal cycles typically begin 60-90 days before expiration. Engage broker 90 days before renewal to allow time for application updates, evidence collection, and underwriting review.
Q: Can I bundle cyber insurance with other policies? Many carriers offer packaged insurance with cyber, crime, employment practices liability (EPLI), and other management liability coverages. Bundled policies often have lower premium than standalone but less customization. Most cyber-specialty carriers (Coalition, At-Bay, Corvus) prefer standalone cyber policies.
Photo: Solomon203, PUBLIC DOMAIN, via Wikimedia Commons (https://upload.wikimedia.org/wikipedia/commons/f/f8/ANFRA_group_personal_accident_insurance_application_20200414.jpg?utm_source=commons.wikimedia.org&utm_campaign=imageinfo&utm_content=original)
Written by
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practi… Read moreShow less
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practical side of building an ed-tech startup.



