A Client Contract Requires Cyber Insurance: What the Clause Means and What to Buy

When a contract requires cyber insurance, it usually specifies a minimum limit, the coverage parts (network security and privacy liability, sometimes technology errors and omissions), how long coverage must last, and proof by certificate. Read each term against your policy before you sign. Some requirements, such as additional insured status or occurrence-based coverage, may not be available on a cyber policy and are worth negotiating.

By Trella Commercial · Updated October 4, 2026

The short version

  • Read the insurance clause before you sign, not when the client asks for a certificate. Some terms take time to add, and a few cannot be added at all.
  • Five things to find: the limit, the required coverage parts, how long coverage must last after the work ends, who must be named on the policy, and how proof is delivered.
  • Insurance and indemnity are different promises. The indemnity clause can make you liable for more than your policy covers, and most policies exclude liability you take on by contract alone.
  • Cyber is claims-made. A clause requiring "occurrence" coverage, or coverage for years after the contract, needs a retroactive date and an extended reporting period, not a different policy.
  • Negotiate what does not fit. Clients usually accept reasonable changes when you explain what the market offers.

What a typical clause looks like

An illustrative composite of common contract language, not a quote from any specific contract.

Vendor shall maintain, at its own expense, Cyber Liability insurance, including network security and privacy liability, with limits of not less than $1,000,000 per claim and $2,000,000 in the aggregate, covering claims arising from unauthorized access to or disclosure of Client data. Such coverage shall be primary and noncontributory, shall name Client as an additional insured, and shall be maintained for the term of this Agreement and for three years thereafter. Vendor shall provide a certificate of insurance before commencing work and thirty days' notice of cancellation.

Each phrase maps to something specific on your policy.

Reading the clause, term by term

Clause languageWhat it meansHow to satisfy it
"Not less than $1,000,000 per claim and $2,000,000 aggregate"The minimum per claim and per policy yearCheck the declarations page; per-claim and aggregate limits must both meet it
"Network security and privacy liability"Third-party coverage for claims that your security failure exposed data or harmed the clientStandard in most cyber policies; confirm it is not sublimited below the requirement
"Technology errors and omissions" or "professional liability"Coverage for failures of the service you provideA separate coverage part or policy, often combined with cyber for tech firms; see cyber vs tech E&O
"Breach response costs" or "notification costs"First-party costs of responding to a breach of the client's dataConfirm breach response applies to data you hold for others
"Additional insured"The client gets rights under your policyOften not available on cyber policies; some insurers offer an endorsement, usually limited to the client's liability for your acts
"Primary and noncontributory"Your policy pays before the client's own insuranceUsually available by endorsement where the client is an additional insured
"Waiver of subrogation"Your insurer will not sue the client to recover what it paidAvailable by endorsement on some policies
"For three years after the Agreement ends"Coverage must continue after the work is doneKeep renewing with the same retroactive date, or buy an extended reporting period if coverage ends
"Certificate of insurance before work begins"Proof of coverageYour broker issues a certificate; cyber is usually listed under "other" coverages
"Thirty days' notice of cancellation"The client wants warning if coverage stopsMany policies only promise notice to the named insured; a notice endorsement or broker commitment may be needed

The red-flag clauses worth negotiating

RequirementWhy it is a problemWhat to propose
"Occurrence-based" cyber coverageCyber policies are written on a claims-made basisClaims-made with a retroactive date before the work began, plus an extended reporting period
Additional insured on cyber, with no qualificationsMany insurers do not offer it, or only for vicarious liabilityAdditional insured "where available," or limited to liability arising from your acts
Uncapped indemnity for any data incidentYou could owe more than your policy pays, and contractual liability beyond what the law imposes is often excludedCap indemnity at the insurance limit or a multiple of fees
Notice of any incident within hoursMay be stricter than law or practical; Washington requires vendors to notify the data owner "immediately" after discoveryA defined window, such as 48 or 72 hours after confirming an incident affecting the client's data
Limits "exclusive of defense costs"Most cyber policies include defense within the limitAccept defense within limits at a higher limit, or confirm the market can do it
Coverage for the client's own business interruptionYour policy covers your losses, not the client'sAddress it under your liability coverage, through indemnity, not first-party coverage
Limits far above your sizeSome clients use one template for every vendorAsk whether a lower limit is acceptable for your scope of work

Washington's breach law already requires a business that maintains data it does not own to notify the owner immediately after discovering a breach. A contract can add detail, but it cannot make the legal duty go away. See Washington data breach notification law.

Insurance clause vs indemnity clause

Insurance clauseIndemnity clause
What it doesRequires you to carry specific coverageMakes you responsible for the client's losses
LimitThe policy limitWhatever the contract says, possibly unlimited
Who paysYour insurer, within the policy's termsYou, with insurance responding only if the policy covers it
Common gapA coverage part or limit is missingYour policy excludes liability you assumed by contract beyond what the law would impose

Have the two clauses reviewed together. A business that meets the insurance requirement can still be badly exposed by an indemnity it cannot insure.

Step by step before you sign

  1. Send the full contract to your broker, not just the insurance exhibit. The indemnity, limitation of liability, and data security sections matter too.
  2. Compare each requirement with your current policy using the table above.
  3. Price the gaps: a higher limit, a technology errors and omissions part, an additional insured or notice endorsement.
  4. Negotiate what the market cannot provide, with language your broker suggests.
  5. Get the certificate once coverage is in place, and diary the dates that require renewal proof.

Who sees these clauses most

  • IT and managed service providers, software and SaaS companies: almost always cyber plus technology errors and omissions. See the managed IT provider story.
  • Marketing agencies, consultants, accountants, and staffing firms handling client data.
  • Health care vendors and billing services, often alongside HIPAA business associate agreements.
  • Contractors working for hospitals, schools, and governments, whose vendor requirements increasingly include cyber.
  • Tenants in some commercial leases, particularly where they connect to the landlord's building systems.

Common questions

What does "network security and privacy liability" mean in a contract?

It refers to third-party cyber coverage for claims that your security failure allowed unauthorized access to data or systems, or that you failed to protect personal or confidential information. Most cyber policies include it, but confirm it is not sublimited below the contract's required limit.

Can I add a client as an additional insured on my cyber policy?

Sometimes. Many cyber insurers do not offer additional insured status, and others offer it only for the client's liability arising from your acts. If a contract requires it, ask your broker before signing, and negotiate "where available" language if needed.

What is a certificate of insurance for cyber coverage?

A standard form your broker issues showing your policies, limits, and dates. Cyber coverage is usually listed in the "other" section. A certificate is proof of coverage, but it does not change the policy; any required endorsements must actually be added.

The contract requires coverage for three years after the work ends. How does that work?

Cyber policies are claims-made, so a claim must be made while a policy is in force. Keep renewing with the same retroactive date for the required period, or, if you stop buying coverage, purchase an extended reporting period.

Do I need technology errors and omissions if the contract only says cyber?

If you provide technology products or services, a client's claim that your service failed is usually a technology errors and omissions claim, not a cyber claim. Many contracts require both, and many insurers combine them on one policy.

Sources

This page is general information, not legal advice. Have contract language reviewed by your attorney and your broker before you sign. Reviewed October 2026.

More in this guide

Find out what your current policies actually cover.

Send us what you have. We review it line by line against your leases and contracts, and tell you plainly what is missing. Free, and no obligation.