Cyber insurance used to be a straightforward risk-transfer transaction: fill out a questionnaire, attest to your controls, pay the premium. That market has hardened. Carriers now routinely ask a direct question most applicants weren’t prepared for a few years ago — do you conduct third-party penetration testing, and how often — because a self-attested checkbox questionnaire tells an underwriter almost nothing about whether the controls it describes actually hold up under a real attack. A penetration test report is one of the few pieces of evidence that does.
This guide covers exactly what underwriters look for in that report — scope, frequency, and format — the gaps that most commonly delay a renewal, and how to prepare evidence proactively instead of scrambling when the application arrives.
Contents
1. Introduction & Context
No law requires a penetration test to purchase cyber insurance, and coverage can still be bound without one. In practice, though, penetration testing has moved from a discretionary technical exercise to a standard underwriting question, and real carrier applications show exactly how directly it now feeds pricing and eligibility. Corvus, for example, asks applicants a single yes-or-no question about whether they conduct annual penetration testing of their network. Beazley asks a more granular frequency question — never, annually, two to three times a year, or quarterly or more often — meaning the cadence itself, not just the presence of testing, carries underwriting weight.
The market shift behind this is straightforward: rising claim volumes and more expensive incidents pushed carriers to stop taking self-attested control questionnaires at face value. A third-party penetration test report is one of the few pieces of evidence in a typical application that demonstrates, rather than describes, whether an organization’s defenses actually work. This guide covers what that evidence needs to look like to satisfy underwriting review, and the specific gaps that most commonly delay a renewal or an initial application.
2. Business Impact
The financial exposure here runs in two directions at once: the cost of an incident without adequate coverage, and the cost of coverage that gets delayed, denied, or priced higher because the application evidence was incomplete. IBM’s Cost of a Data Breach Report 2026 places the average breach cost at $4.99M USD — the highest figure on record — which is precisely the exposure cyber insurance exists to transfer, and precisely what an underwriter is trying to price accurately when they ask for pentest evidence.
| Evidence Gap | Business Consequence | Underwriting Impact | Severity |
| No pentest within the carrier’s required window (commonly 12 months) | Application flagged incomplete | Binding delayed or coverage denied | HIGH |
| Vulnerability scan submitted instead of a true third-party pentest | Doesn’t satisfy the carrier’s definition of adversarial testing | Application treated as non-responsive | CRITICAL |
| Report scope doesn’t match what the application describes as tested | Self-attestation contradicted by the evidence provided | May trigger supplemental testing requirement before binding | MEDIUM |
| Findings identified with no documented remediation | Raises the question of whether findings get acted on at all | Can trigger coverage exclusions or a higher premium | HIGH |
| No retained evidence from the prior renewal cycle | Can’t demonstrate consistent testing practice over time | Increased underwriting scrutiny | MEDIUM |
None of these gaps require a failed test to become a problem — an organization can have genuinely strong security and still see an application delayed purely because the evidence submitted doesn’t answer the specific questions the underwriting process asks.
3. What Underwriters Look For
3.1 Scope Requirements
At minimum, underwriters expect testing to cover internet-facing applications and external network perimeter — the surface most directly reachable by an outside attacker. Given how consistently ransomware claims originate from compromised internal access spreading laterally, a growing number of applications and higher coverage tiers also ask about internal network and Active Directory testing, not just the external perimeter. Confirm which the specific application is asking about before assuming an external-only engagement satisfies the question.
3.2 Frequency Requirements
Annual testing is the common baseline question, but it isn’t the ceiling. Applications increasingly ask for the exact cadence — annually, two to three times a year, or quarterly or more — and higher-risk applicants or higher coverage tiers are more likely to see quarterly-or-more treated favorably in pricing. Treat frequency as a variable that affects the quote, not a single pass/fail threshold.
3.3 Report Format and Evidence
Raw tool output rarely satisfies an underwriting review on its own. What tends to hold up is a report with an executive summary an underwriter without deep technical background can act on, a defined and stated scope, categorized findings by severity, and — critically — documented remediation status and retest evidence for anything previously identified as critical or high. A single point-in-time report with no evidence of what happened after delivery reads, to an underwriter, as untested follow-through.
3.4 Common Gaps That Delay Renewals
- Stale evidence: A pentest from 18 months ago, submitted against a question asking for testing within the last 12.
- Scope mismatch: An application describes broad testing while the attached report covers only a single subdomain.
- Wrong artifact type: A vulnerability scan report submitted where the question specifically asked about third-party penetration testing.
- No remediation trail: Findings listed with no indication of what happened to them afterward, leaving the underwriter to assume the worst.
4. Proactive Detection with the Teisoft Exposure Platform
The Teisoft Exposure Platform supports insurance readiness as an ongoing state rather than a scramble before each renewal. Continuous External Asset Discovery keeps the scope statement in an application accurate as the environment changes between formal engagements, and Automated Exposure Validation (AEV) provides continuously updated evidence of which findings are genuinely exploitable — supporting documentation an underwriter can see was maintained year-round, not assembled the week the renewal notice arrived.
4.1 What Continuous Monitoring Adds to Insurance Readiness
- An accurate, current scope statement: The external footprint an application describes matches what discovery has actually confirmed, rather than what was true at last year’s renewal.
- A documented remediation trail: Findings, their validation status, and remediation history are tracked continuously rather than reconstructed from memory when an application asks for it.
- Evidence of consistent practice: A continuous monitoring history demonstrates ongoing security operations, not a once-a-year compliance exercise timed to the renewal date.
| → Run your free External Attack Surface Scan |
| teisoftllc.com/free-vulnerability-scan/ — find out in minutes whether your current external footprint matches what your last insurance application described. |
5. Step-by-Step: Preparing Evidence for Underwriting Review
The following five-step process prepares penetration testing evidence before a renewal deadline forces a scramble.
Step 1: Confirm Exactly What the Application Asks
Read the actual question, not the general expectation. “Do you conduct testing” and “how often do you conduct testing” require different answers, and a graduated frequency question rewards a more specific, higher answer than a simple yes would.
Step 2: Match Scope to What the Carrier Is Asking About
Confirm whether the application is asking about external perimeter testing, internal network testing, or both, and make sure the engagement scoped for evidence actually covers what will be attested to on the form.
Step 3: Commission Testing Within the Carrier’s Window
Schedule the engagement to complete comfortably before the application deadline, accounting for the time a thorough test and report actually take — not the day the renewal notice arrives.
Step 4: Document Remediation for Every Critical and High Finding
For each significant finding, record what was done, when, and how it was verified. This remediation record is frequently more valuable to an underwriter than the original findings list, since it demonstrates the organization acts on what testing reveals.
Step 5: Retain Evidence Across Renewal Cycles
Keep prior years’ reports and remediation records on file. A multi-year history of consistent testing and follow-through is stronger underwriting evidence than any single year’s report considered alone.
Insurance Readiness: Before / After
| Element | State Before | State After | Improvement |
| Evidence timing | Assembled after the renewal notice arrives | Maintained continuously, ready on request | No renewal-cycle scramble |
| Scope accuracy | Based on last year’s known environment | Verified against current continuous discovery | Application matches reality |
| Remediation documentation | Reconstructed from memory if asked | Tracked as findings are resolved | Credible follow-through evidence |
| Multi-year history | Not retained systematically | Available across renewal cycles | Demonstrated consistent practice |
6. Frequently Asked Questions (FAQ)
Q: Is a penetration test legally required to buy cyber insurance?
No law mandates it, and coverage can still be issued without one. In practice, though, most carrier applications ask directly whether — and how often — you conduct third-party penetration testing, and the answer feeds pricing and, for higher coverage tiers or higher-risk profiles, can determine whether the application is accepted at all.
Q: Does a vulnerability scan satisfy a carrier’s penetration testing question?
Generally, no. Carrier applications typically define penetration testing as adversarial testing conducted by an authorized third party to find and demonstrate exploitable weaknesses — a materially different activity from an automated scan that checks a known asset list against a known-CVE database. Submitting scan output when a carrier asked about penetration testing is a common source of application delays.
Q: How recent does a penetration test need to be to count toward an application?
Most carriers work from a rolling window, commonly 12 months, and some frequency-based questions distinguish annual testing from more frequent cycles for higher-risk applicants. A test older than the carrier’s stated window typically doesn’t count as current evidence, regardless of how thorough it was at the time.
Q: What happens if our pentest found findings we haven’t fully remediated yet?
Unremediated findings aren’t automatically disqualifying — what underwriters are generally looking for is evidence that findings get acted on, not a zero-finding report, which is rare and can itself raise questions about test rigor. Documented remediation status and a retest plan for critical findings is usually more valuable to an application than a report showing no issues at all.
Q: Should the same penetration test satisfy both PCI DSS and cyber insurance requirements?
Often the technical work can overlap substantially, but the scope and report format requirements aren’t guaranteed to be identical — PCI DSS Requirement 11.4.3 has its own scope rules around the cardholder data environment that may not match what a specific carrier’s application asks for. Confirm both sets of requirements before assuming one engagement covers both.
7. Conclusion & Next Steps
- Penetration testing isn’t legally mandated for cyber insurance, but real carrier applications — including graduated frequency questions from carriers like Beazley and binary testing questions from carriers like Corvus — show it now feeds pricing and eligibility directly, because it’s one of the few pieces of application evidence that demonstrates rather than merely describes an organization’s controls.
- What underwriters look for is specific: scope that matches what the application attests to, a frequency that meets or exceeds the carrier’s stated window, and a report format that includes documented remediation — not just a findings list. Gaps in any of these three, not test quality itself, are what most commonly delay a renewal.
- The five-step process in this guide turns insurance readiness into a maintained state rather than a pre-renewal scramble — confirming exactly what’s being asked, matching scope, scheduling within the required window, documenting remediation, and retaining evidence across cycles.
| → Primary CTA: External Attack Surface Scan (Free) |
| Run your free External Attack Surface Scan at teisoftllc.com/free-vulnerability-scan/ and find out in minutes whether your current external footprint matches what your last insurance application described. |
| → Secondary CTA: Compliance Penetration Testing |
| Teisoft’s Compliance Penetration Testing service delivers the scope, frequency, and evidence format underwriters review — with documented remediation tracking built in, not assembled after the fact. Contact Teisoft |
Related Resources on teisoftllc.com
Insurance readiness overlaps significantly with other compliance evidence requirements — see our PCI DSS compliance audit guide for a related requirement-mapping approach.
- PCI DSS Compliance Audit Guide for Web Applications
- CTEM Explained: The 5 Stages of Continuous Threat Exposure Management
- What Is External Attack Surface Management (EASM)?