Contractual Insurance Requirements Make sure your coverage matches what you signed.
Client agreements and MSAs increasingly spell out exactly what cyber and Technology E&O insurance you must carry. We compare those requirements against your actual policies, identify the gaps, and help you meet requirements the insurance market can support.
What are contractual insurance requirements?
Contractual insurance requirements are clauses in a contract that require one party, usually the vendor or service provider, to carry specific types and amounts of insurance. For technology and data services, that typically means cyber liability and Technology E&O, often with minimum limits and specific policy wording.
The challenge is that these clauses are often written with general liability in mind. Cyber and E&O policies work differently, so some requests can’t be met exactly as written.
Where to find them in a contract
- An “Insurance” section or exhibit in the MSA
- The indemnification section, which often references insurance
- Data protection or security addenda
- Vendor onboarding or procurement questionnaires
- Statements of work that add project-specific requirements
Common insurance clauses, and how cyber and E&O policies handle them
A general guide to the requirements we see most often. Whether a specific request can be met depends on your policies and insurers.
| Clause | What it asks for | How cyber and Tech E&O typically handle it |
|---|---|---|
| Minimum limits | A stated amount per claim and in the aggregate | Usually achievable Met through the policy limit, or with excess layers when higher limits are needed |
| Specific coverage types | Cyber, Tech E&O, or both, sometimes named precisely | Usually achievable Often met with a combined cyber and Tech E&O policy |
| Additional insured | The client added as an insured on your policy | Review needed Handled differently than general liability. Some insurers allow it by endorsement, often with limited scope |
| Waiver of subrogation | Your insurer gives up the right to recover from the client | Review needed Often available by endorsement or under the policy’s existing terms |
| Primary and non-contributory | Your policy pays before the client’s own insurance | Review needed Depends on the policy’s “other insurance” wording and available endorsements |
| Coverage after the contract ends | Coverage maintained for a period, such as several years, after work ends | Review needed Claims-made policies need continuous renewal or an extended reporting period |
| Insurer financial rating | Insurers with a minimum financial strength rating | Usually achievable Confirmed by your broker when the program is placed |
| Notice of cancellation | Advance notice to the client if coverage is cancelled | Review needed Insurers vary; some offer notice endorsements, others rely on the insured to notify |
The gaps we find most often
Limits below the requirement
The contract requires more than your current limit, or requires it per claim when your policy’s aggregate is shared across all claims.
Wrong or missing coverage type
The contract calls for Tech E&O or cyber, and the business carries only general liability or a narrow professional policy.
Sublimits below the requirement
The headline limit meets the contract, but the coverage the client cares about, such as privacy liability, is sublimited.
Indemnity beyond insurance
You’ve agreed to indemnify a client for losses your policy excludes, such as liability assumed by contract.
Endorsements never added
Additional insured, waiver of subrogation, or primary wording was promised in the contract but never added to the policy.
Certificates that overstate coverage
A certificate of insurance doesn’t change the policy. If the policy doesn’t match, the certificate won’t fix it.
Meeting requirements the market can support
We read your contract’s insurance requirements alongside your policy wording, identify what is already met, what needs an endorsement or higher limit, and what may not be available as written.
Where a requirement can’t be met exactly, we can suggest insurance terms that are commonly accepted, so you and your attorney can respond to the client with confidence.
Related: Technology E&O insurance · High-limit and excess cyber
What to send us for a review
- The insurance section or exhibit of the contract
- The indemnification section
- Your current policies and endorsements
- Any certificate of insurance the client rejected
- Your deadline, if signature is pending
How a contract insurance review works
- Step 01
Gather
Collect the contract’s insurance and indemnity terms and your current policies.
- Step 02
Compare
Check each requirement against your policy wording, limits, and endorsements.
- Step 03
Close Gaps
Pursue endorsements, higher limits, or coverage changes with insurers where needed.
- Step 04
Document
Provide accurate certificates and a clear summary of what is and isn’t met.
Not sure your program matches your contracts?
Our free, private two-minute self-assessment includes contract requirements. Nothing is sent or saved.
Contract insurance questions, answered.
Have a question that isn’t here? Ask our team.
Can a client be added as an additional insured on a cyber or Tech E&O policy?
Sometimes. Additional insured status is standard on general liability policies but is handled differently on cyber and Technology E&O policies. Some insurers allow it by endorsement, usually limited to claims arising from your work, while others do not offer it. A broker can confirm what your insurer will provide and suggest commonly accepted alternatives.
What is a waiver of subrogation?
A waiver of subrogation means your insurer gives up its right to recover a paid loss from the other party to the contract. Clients often require it so that a claim paid by your insurer does not lead to a lawsuit against them. Many cyber and Tech E&O policies can accommodate it by endorsement or under existing terms.
Does a certificate of insurance prove I meet a contract’s requirements?
No. A certificate of insurance summarizes coverage but does not change the policy or add coverage. If the policy does not include a required limit or endorsement, the certificate cannot create it. Requirements should be confirmed against the actual policy wording.
What should I do if I can’t meet a contract’s insurance requirement?
Review the requirement with your broker before signing. Some gaps can be closed with an endorsement or higher limit. Others may not be available in the insurance market as written, in which case your attorney may be able to negotiate alternative wording that the client accepts. Signing a requirement you cannot meet can create a breach of contract.
Why do contracts require coverage after the work ends?
Cyber and Technology E&O policies are usually claims-made, meaning they respond to claims made while the policy is active. Because a problem with your work may not surface until later, clients often require you to maintain coverage, or purchase an extended reporting period, for several years after the contract ends.
Don’t let insurance hold up the deal.
Send us the insurance requirements and your current coverage. We’ll help you understand what’s met, what’s missing, and your options.
Information on this page is general and educational. It is not legal advice; consult your attorney about contract terms. Actual coverage depends on policy language, endorsements, exclusions, limits, and conditions. ComplexCyber.com is operated by Cyber Data Risk Managers LLC, an independent insurance brokerage. Insurance availability, eligibility, terms, limits, and pricing are subject to insurer underwriting and approval. No coverage is bound through this website. Privacy Policy