The short version
- Read the insurance clause before you sign, not when the client asks for a certificate. Some terms take time to add, and a few cannot be added at all.
- Five things to find: the limit, the required coverage parts, how long coverage must last after the work ends, who must be named on the policy, and how proof is delivered.
- Insurance and indemnity are different promises. The indemnity clause can make you liable for more than your policy covers, and most policies exclude liability you take on by contract alone.
- Cyber is claims-made. A clause requiring "occurrence" coverage, or coverage for years after the contract, needs a retroactive date and an extended reporting period, not a different policy.
- Negotiate what does not fit. Clients usually accept reasonable changes when you explain what the market offers.
What a typical clause looks like
An illustrative composite of common contract language, not a quote from any specific contract.
Vendor shall maintain, at its own expense, Cyber Liability insurance, including network security and privacy liability, with limits of not less than $1,000,000 per claim and $2,000,000 in the aggregate, covering claims arising from unauthorized access to or disclosure of Client data. Such coverage shall be primary and noncontributory, shall name Client as an additional insured, and shall be maintained for the term of this Agreement and for three years thereafter. Vendor shall provide a certificate of insurance before commencing work and thirty days' notice of cancellation.
Each phrase maps to something specific on your policy.
Reading the clause, term by term
| Clause language | What it means | How to satisfy it |
|---|---|---|
| "Not less than $1,000,000 per claim and $2,000,000 aggregate" | The minimum per claim and per policy year | Check the declarations page; per-claim and aggregate limits must both meet it |
| "Network security and privacy liability" | Third-party coverage for claims that your security failure exposed data or harmed the client | Standard in most cyber policies; confirm it is not sublimited below the requirement |
| "Technology errors and omissions" or "professional liability" | Coverage for failures of the service you provide | A separate coverage part or policy, often combined with cyber for tech firms; see cyber vs tech E&O |
| "Breach response costs" or "notification costs" | First-party costs of responding to a breach of the client's data | Confirm breach response applies to data you hold for others |
| "Additional insured" | The client gets rights under your policy | Often not available on cyber policies; some insurers offer an endorsement, usually limited to the client's liability for your acts |
| "Primary and noncontributory" | Your policy pays before the client's own insurance | Usually available by endorsement where the client is an additional insured |
| "Waiver of subrogation" | Your insurer will not sue the client to recover what it paid | Available by endorsement on some policies |
| "For three years after the Agreement ends" | Coverage must continue after the work is done | Keep renewing with the same retroactive date, or buy an extended reporting period if coverage ends |
| "Certificate of insurance before work begins" | Proof of coverage | Your broker issues a certificate; cyber is usually listed under "other" coverages |
| "Thirty days' notice of cancellation" | The client wants warning if coverage stops | Many policies only promise notice to the named insured; a notice endorsement or broker commitment may be needed |
The red-flag clauses worth negotiating
| Requirement | Why it is a problem | What to propose |
|---|---|---|
| "Occurrence-based" cyber coverage | Cyber policies are written on a claims-made basis | Claims-made with a retroactive date before the work began, plus an extended reporting period |
| Additional insured on cyber, with no qualifications | Many insurers do not offer it, or only for vicarious liability | Additional insured "where available," or limited to liability arising from your acts |
| Uncapped indemnity for any data incident | You could owe more than your policy pays, and contractual liability beyond what the law imposes is often excluded | Cap indemnity at the insurance limit or a multiple of fees |
| Notice of any incident within hours | May be stricter than law or practical; Washington requires vendors to notify the data owner "immediately" after discovery | A defined window, such as 48 or 72 hours after confirming an incident affecting the client's data |
| Limits "exclusive of defense costs" | Most cyber policies include defense within the limit | Accept defense within limits at a higher limit, or confirm the market can do it |
| Coverage for the client's own business interruption | Your policy covers your losses, not the client's | Address it under your liability coverage, through indemnity, not first-party coverage |
| Limits far above your size | Some clients use one template for every vendor | Ask whether a lower limit is acceptable for your scope of work |
Washington's breach law already requires a business that maintains data it does not own to notify the owner immediately after discovering a breach. A contract can add detail, but it cannot make the legal duty go away. See Washington data breach notification law.
Insurance clause vs indemnity clause
| Insurance clause | Indemnity clause | |
|---|---|---|
| What it does | Requires you to carry specific coverage | Makes you responsible for the client's losses |
| Limit | The policy limit | Whatever the contract says, possibly unlimited |
| Who pays | Your insurer, within the policy's terms | You, with insurance responding only if the policy covers it |
| Common gap | A coverage part or limit is missing | Your policy excludes liability you assumed by contract beyond what the law would impose |
Have the two clauses reviewed together. A business that meets the insurance requirement can still be badly exposed by an indemnity it cannot insure.
Step by step before you sign
- Send the full contract to your broker, not just the insurance exhibit. The indemnity, limitation of liability, and data security sections matter too.
- Compare each requirement with your current policy using the table above.
- Price the gaps: a higher limit, a technology errors and omissions part, an additional insured or notice endorsement.
- Negotiate what the market cannot provide, with language your broker suggests.
- Get the certificate once coverage is in place, and diary the dates that require renewal proof.
Who sees these clauses most
- IT and managed service providers, software and SaaS companies: almost always cyber plus technology errors and omissions. See the managed IT provider story.
- Marketing agencies, consultants, accountants, and staffing firms handling client data.
- Health care vendors and billing services, often alongside HIPAA business associate agreements.
- Contractors working for hospitals, schools, and governments, whose vendor requirements increasingly include cyber.
- Tenants in some commercial leases, particularly where they connect to the landlord's building systems.