FOR BUSINESSES WITH $10M+ IN ANNUAL REVENUE
Senior business insurance brokers for Virginia companies
A Virginia technology, service, or government-contracting company should begin with an operating map that identifies every entity, contract, incorporated clause, location, employee state, vehicle, and subcontractor. The broker should then compare those facts with FAR and DFARS clauses, CMMC scope, cyber and E&O wording, property and auto schedules, and limits. Insurance requirements in a government contract are contractual requirements: a policy is not proof of regulatory compliance, and this page does not describe a specialist government-contract placement capability.
Who this page is for
This service is for businesses with $10M+ in annual revenue and operations in Virginia that need a senior broker to connect contract clauses, cyber and E&O wording, regional premises, people, vehicles, and subcontractors as one program. Northern Virginia, Richmond, Hampton Roads, and statewide operations are areas to discuss based on the company's actual footprint; those names describe operating regions, not OnePark Risk office locations.
OnePark Risk is licensed in Virginia. The engagement is delivered through video and phone conversations, with in-person meetings arranged where practical. This page does not claim a Virginia office; licensing, service area, and office location are different facts.
Discuss your Virginia program with a senior broker
Start with a conversation. No application or documents required.
Share five contact details and, if you like, a little context about revenue band, main operating state, and what you want to discuss. A member of the OnePark Risk team contacts you to arrange the next conversation. There is no application, no document upload, and no obligation.
No insurance application or document upload required.
Build the Virginia operating map before approaching insurers
The review begins with the legal and operating footprint in Northern Virginia, Richmond, Hampton Roads, and every other disclosed location, including operations outside Virginia. The map identifies which entity signs commercial and government contracts, employs personnel, holds facility clearances where applicable, leases premises, owns equipment, manages subcontractors, and operates vehicles. Regional labels are a starting point for discovery; they cannot replace specific addresses, activities, and insured entities, and they are not OnePark Risk office locations.
Technology and service companies should define each deliverable in plain language: software, integration, consulting, managed service, staffing, engineering, or another activity. Customer contracts and policy definitions may classify the same work differently. More limit does not broaden an insured-services definition that omits the work, and an additional insured certificate does not modify an E&O or cyber form.
Physical operations require separate premises, property, auto, and workers' compensation information. Offices, warehouses, field locations, ports, customer sites, and remote employees create different schedules. Whether a particular market, form, or higher limit is available for a specific company is confirmed during the review from actual underwriting information; this page does not state that a specialist government-contract market or capability is available.
What does FAR 52.228-5 require the review to identify?
FAR 52.228-5 is a contractual clause concerning insurance under cost-reimbursement contracts. When included in a contract, it requires the contractor to maintain specified insurance and generally to provide evidence as directed by the contracting officer. The contract, incorporated clauses, agency supplements, and contracting officer direction control; this page does not state a universal dollar minimum.
The insurance review should extract each required coverage, amount, evidence provision, subcontractor obligation, notice term, and any approval requirement. It should then compare the clause with workers' compensation, employers liability, general liability, auto, property, professional liability, cyber, and other policies actually relevant to the contract. Some obligations may not fit standard policy wording and should be identified for counsel and the contracting team.
Government-contract insurance requirements are contractual requirements, not proof that the contractor meets procurement, security, accounting, labor, or performance duties. A compliant certificate cannot repair a missing endorsement or excluded service, and an insurance policy cannot amend the government contract.
How should DFARS 252.204-7012 and CMMC enter the discussion?
DFARS 252.204-7012 is a contractual and regulatory requirement addressing safeguarding covered defense information and cyber-incident reporting in covered Department of Defense contracting. The review should identify whether the clause appears, what systems and information are in scope, applicable flow-down duties, and the incident-reporting process. Qualified legal, contracting, and cybersecurity advisers should determine applicability and compliance.
The Cybersecurity Maturity Model Certification, or CMMC, is a Department of Defense program for assessing implementation of specified cybersecurity requirements at the level applicable to a contract. It is a contractual and regulatory requirement framework, not an insurance limit and not a promise that a cyber policy satisfies procurement eligibility. This page states no universal dollar minimum for either requirement.
Insurance does not establish compliance with government cybersecurity requirements; a cyber policy may respond to certain costs after an incident, but the contractual and regulatory obligations remain the contractor's. Underwriting questions about controls may overlap with compliance work, yet an insurer's acceptance or questionnaire does not certify compliance.
Coordinate cyber and E&O without treating them as compliance tools
Technology E&O generally addresses covered allegations that defined technology services failed to perform, while cyber can address defined security, privacy, response, restoration, and interruption events. A government contractor may face both customer allegations and its own response costs after one incident. The review should compare allocation, other-insurance wording, notice, consent, defense, exclusions, and whether the policies share an annual aggregate.
Claims-made terms require attention to retroactive dates, reporting provisions, insured entities, acquisitions, and policy periods. If defense is inside the limit, legal expense can reduce what remains for covered settlement or judgment. A deductible and self-insured retention may also impose different payment and handling duties. These terms matter independently of any contractual minimum.
Subcontractors and cloud, identity, managed-service, and data-hosting providers create dependency and flow-down questions. Contracts should identify security duties, indemnity, incident notice, insurance, and access to covered information. A cyber dependency sublimit may be smaller than the policy's annual aggregate, and an E&O form may not define every subcontracted service as insured.
What physical exposures should a regional review separate?
A company's own office and data-related operations in Northern Virginia, professional or administrative operations in Richmond, and field, logistics, marine-adjacent, or customer-site work in Hampton Roads can present materially different facts. These are examples for discovery, not assumptions about any particular company and not office locations. The review needs addresses, occupancy, equipment, values, public access, travel, vehicles, and contract-site responsibilities for each location.
Property business interruption generally requires covered physical damage, while cyber business interruption requires a defined network event. Restoration periods, waiting periods, dependent-provider terms, deductibles, and sublimits should be modeled separately. Vehicles, employee driving, mobile equipment, and work at customer or government sites also require clear policy and contract treatment.
A multi-state contractor should list every employee work state, payroll class, vehicle, garaging location, and operating entity. Workers' compensation and auto are state-regulated, while employment exposures vary by jurisdiction. Insurance review can flag the schedule and wording questions but cannot substitute for legal or human-resources advice.
What should the Virginia engagement deliver?
The first deliverable is a verified exposure summary: organization chart, descriptions of services, contract inventory, relevant FAR and DFARS clauses, CMMC scope and assessment information, subcontractor agreements, current and expiring policies, loss runs, locations, equipment values, payroll by state, vehicle schedules, technology dependencies, and incident-response procedures. Legal and cybersecurity advisers remain responsible for their respective compliance conclusions.
The policy comparison should show insured entities and services, trigger, retention, limit and annual aggregate, defense treatment, sublimits, exclusions, retroactive date, reporting terms, and excess attachment. Any higher-limit brokerage option is individually evaluated and subject to actual placement availability, separate from the site's distinct $1M/$2M cyber and Tech E&O program.
$10M in annual revenue does not mean $10M of every coverage. Revenue describes the size of the business; each policy limit has to be evaluated against the contracts, loss scenarios, and policy wording that apply to that coverage.
OnePark Risk is licensed in Virginia and conducts the engagement by video and phone, with in-person meetings arranged where practical. The business should prepare its contract inventory with the incorporated clauses, current and expiring policies, loss runs, location and equipment schedules, payroll by state, vehicle and driver lists, subcontractor agreements, incident-response procedures, and a list of operational changes expected during the next policy period. This page does not claim a Virginia office; a license, a service area, and an office remain different facts.
Hypothetical scenario: Hypothetical Virginia government-contractor review
Consider a hypothetical Virginia technology contractor with $44M in annual revenue, a cost-reimbursement contract containing FAR 52.228-5, a defense subcontract containing DFARS 252.204-7012, CMMC obligations, cloud dependencies, and employees in several states. The review would extract each contract requirement, map covered information and subcontractors, compare cyber and E&O definitions and reporting, and schedule physical locations, payroll, and vehicles by state. This illustration does not establish compliance, insurer acceptance, policy response, or any claim outcome.
What your senior broker should examine
- Which entities, locations, services, employees, vehicles, and subcontractors support each commercial or government contract?
- Which contracts incorporate FAR 52.228-5, DFARS 252.204-7012, CMMC, flow-down, evidence, or incident-reporting requirements?
- Do cyber and E&O policies recognize the services, covered entities, prior acts, defense treatment, and shared or separate aggregates?
- Which cloud, identity, data-hosting, and managed-service dependencies carry waiting periods or sublimits?
- How are regional property, business interruption, customer-site, fleet, and multi-state workforce exposures scheduled?
- Which employee work states, payroll classes, vehicles, and garaging locations sit outside Virginia, and do the workers' compensation and auto schedules list them?
Questions businesses ask
Does OnePark Risk have a Virginia office?
This page does not claim a Virginia office. OnePark Risk is licensed in Virginia and works by video and phone, with in-person meetings arranged where practical. A license, service area, and physical office are different facts.
Does cyber insurance satisfy CMMC or DFARS requirements?
No. Those are contractual and regulatory requirements whose applicability and compliance require qualified advice and operational evidence. Insurance may address certain covered incident costs under its terms, but it does not certify compliance.
Does FAR 52.228-5 set one insurance amount for every contractor?
No universal dollar minimum is stated on this page. The incorporated clause, contract, agency requirements, and contracting officer direction should be reviewed for the particular cost-reimbursement contract.
Does this page cover Northern Virginia, Richmond, and Hampton Roads?
Those names describe operating regions to discuss based on the company's actual footprint, not OnePark Risk office locations. The review maps the actual operations, contracts, property, people, and vehicles in each region and in every other state where the company works.
Does this page describe a specialist government-contract insurance program?
No. It explains how a senior broker reads FAR, DFARS, and CMMC requirements alongside the policies a contractor already carries. Whether a particular market, form, or higher limit is available for a specific contractor is confirmed during the review, and insurance does not certify compliance.
Can one incident involve both cyber and Tech E&O?
It can create both internal response costs and customer service-failure allegations, but policy response depends on definitions and facts. Shared aggregates, notice, exclusions, defense treatment, and other-insurance wording should be compared without assuming either policy pays.
Sources
- Virginia State Corporation Commission: Bureau of Insurance — accessed 2026-09-19; supports the state regulatory context for the Virginia licensing statement.
- Acquisition.gov: FAR 52.228-5, Insurance—Work on a Government Installation — accessed 2026-09-19; supports the description of insurance requirements incorporated into applicable cost-reimbursement contracts.
- U.S. Department of Defense Chief Information Officer: Cybersecurity Maturity Model Certification — accessed 2026-09-19; supports the description of CMMC as a Department of Defense cybersecurity assessment program rather than insurance.
Educational content for businesses evaluating a senior broker engagement. It is not a quote, a coverage recommendation, or a representation that any limit, carrier, or program is available to a particular business. Coverage is subject to policy terms and placement availability. OnePark Risk is a P&C broker licensed in NY, CA, DE, MA, PA, NJ, NV, FL, and VA.