Client & Vendor Contract Insurance Review

Contractual Insurance Requirements Make sure your coverage matches what you signed.

Client agreements and MSAs increasingly spell out exactly what cyber and Technology E&O insurance you must carry. We compare those requirements against your actual policies, identify the gaps, and help you meet requirements the insurance market can support.

The Basics

What are contractual insurance requirements?

Contractual insurance requirements are clauses in a contract that require one party, usually the vendor or service provider, to carry specific types and amounts of insurance. For technology and data services, that typically means cyber liability and Technology E&O, often with minimum limits and specific policy wording.

The challenge is that these clauses are often written with general liability in mind. Cyber and E&O policies work differently, so some requests can’t be met exactly as written.

Where to find them in a contract

  • An “Insurance” section or exhibit in the MSA
  • The indemnification section, which often references insurance
  • Data protection or security addenda
  • Vendor onboarding or procurement questionnaires
  • Statements of work that add project-specific requirements
Clause Decoder

Common insurance clauses, and how cyber and E&O policies handle them

A general guide to the requirements we see most often. Whether a specific request can be met depends on your policies and insurers.

ClauseWhat it asks forHow cyber and Tech E&O typically handle it
Minimum limitsA stated amount per claim and in the aggregateUsually achievable
Met through the policy limit, or with excess layers when higher limits are needed
Specific coverage typesCyber, Tech E&O, or both, sometimes named preciselyUsually achievable
Often met with a combined cyber and Tech E&O policy
Additional insuredThe client added as an insured on your policyReview needed
Handled differently than general liability. Some insurers allow it by endorsement, often with limited scope
Waiver of subrogationYour insurer gives up the right to recover from the clientReview needed
Often available by endorsement or under the policy’s existing terms
Primary and non-contributoryYour policy pays before the client’s own insuranceReview needed
Depends on the policy’s “other insurance” wording and available endorsements
Coverage after the contract endsCoverage maintained for a period, such as several years, after work endsReview needed
Claims-made policies need continuous renewal or an extended reporting period
Insurer financial ratingInsurers with a minimum financial strength ratingUsually achievable
Confirmed by your broker when the program is placed
Notice of cancellationAdvance notice to the client if coverage is cancelledReview needed
Insurers vary; some offer notice endorsements, others rely on the insured to notify
Where Mismatches Happen

The gaps we find most often

Limits below the requirement

The contract requires more than your current limit, or requires it per claim when your policy’s aggregate is shared across all claims.

Wrong or missing coverage type

The contract calls for Tech E&O or cyber, and the business carries only general liability or a narrow professional policy.

Sublimits below the requirement

The headline limit meets the contract, but the coverage the client cares about, such as privacy liability, is sublimited.

Indemnity beyond insurance

You’ve agreed to indemnify a client for losses your policy excludes, such as liability assumed by contract.

Endorsements never added

Additional insured, waiver of subrogation, or primary wording was promised in the contract but never added to the policy.

Certificates that overstate coverage

A certificate of insurance doesn’t change the policy. If the policy doesn’t match, the certificate won’t fix it.

How We Help

Meeting requirements the market can support

We read your contract’s insurance requirements alongside your policy wording, identify what is already met, what needs an endorsement or higher limit, and what may not be available as written.

Where a requirement can’t be met exactly, we can suggest insurance terms that are commonly accepted, so you and your attorney can respond to the client with confidence.

What to send us for a review

  • The insurance section or exhibit of the contract
  • The indemnification section
  • Your current policies and endorsements
  • Any certificate of insurance the client rejected
  • Your deadline, if signature is pending
Our Approach

How a contract insurance review works

  1. Step 01

    Gather

    Collect the contract’s insurance and indemnity terms and your current policies.

  2. Step 02

    Compare

    Check each requirement against your policy wording, limits, and endorsements.

  3. Step 03

    Close Gaps

    Pursue endorsements, higher limits, or coverage changes with insurers where needed.

  4. Step 04

    Document

    Provide accurate certificates and a clear summary of what is and isn’t met.

Not sure your program matches your contracts?

Our free, private two-minute self-assessment includes contract requirements. Nothing is sent or saved.

Frequently Asked Questions

Contract insurance questions, answered.

Have a question that isn’t here? Ask our team.

Can a client be added as an additional insured on a cyber or Tech E&O policy?

Sometimes. Additional insured status is standard on general liability policies but is handled differently on cyber and Technology E&O policies. Some insurers allow it by endorsement, usually limited to claims arising from your work, while others do not offer it. A broker can confirm what your insurer will provide and suggest commonly accepted alternatives.

What is a waiver of subrogation?

A waiver of subrogation means your insurer gives up its right to recover a paid loss from the other party to the contract. Clients often require it so that a claim paid by your insurer does not lead to a lawsuit against them. Many cyber and Tech E&O policies can accommodate it by endorsement or under existing terms.

Does a certificate of insurance prove I meet a contract’s requirements?

No. A certificate of insurance summarizes coverage but does not change the policy or add coverage. If the policy does not include a required limit or endorsement, the certificate cannot create it. Requirements should be confirmed against the actual policy wording.

What should I do if I can’t meet a contract’s insurance requirement?

Review the requirement with your broker before signing. Some gaps can be closed with an endorsement or higher limit. Others may not be available in the insurance market as written, in which case your attorney may be able to negotiate alternative wording that the client accepts. Signing a requirement you cannot meet can create a breach of contract.

Why do contracts require coverage after the work ends?

Cyber and Technology E&O policies are usually claims-made, meaning they respond to claims made while the policy is active. Because a problem with your work may not surface until later, clients often require you to maintain coverage, or purchase an extended reporting period, for several years after the contract ends.

Contract Pending?

Don’t let insurance hold up the deal.

Send us the insurance requirements and your current coverage. We’ll help you understand what’s met, what’s missing, and your options.

Information on this page is general and educational. It is not legal advice; consult your attorney about contract terms. Actual coverage depends on policy language, endorsements, exclusions, limits, and conditions. ComplexCyber.com is operated by Cyber Data Risk Managers LLC, an independent insurance brokerage. Insurance availability, eligibility, terms, limits, and pricing are subject to insurer underwriting and approval. No coverage is bound through this website. Privacy Policy