Buyer Requirements · 5 min read
Insurance for Enterprise SaaS Contracts
When a SaaS company moves upmarket, the contract gets longer and the insurance section gets specific. Enterprise master service agreements no longer accept "we have a policy" — they name exact coverages, minimum limits, additional-insured status, and sometimes a waiver of subrogation. For a growing software vendor, insurance stops being a back-office line item and becomes a gate on revenue: no compliant certificate of insurance, no signature, no go-live. This page explains what enterprise SaaS contracts typically require, why those clauses exist, and how to structure a program that clears procurement without overbuying. If you want the wider view of everything a large customer asks for, our enterprise contract requirements guide maps the full checklist; this page focuses on the insurance clauses specifically.
What Enterprise MSAs Actually Require
The insurance exhibit in an enterprise SaaS agreement usually asks for a defined stack of coverages with stated minimums. As of 2026, the recurring pattern looks like this:
- Cyber liability, $1M–$5M. The headline requirement for any vendor handling customer data. Larger accounts and regulated buyers push toward the top of that range.
- Tech E&O / professional liability, $1M–$2M. Covers claims that your software failed to perform — missed SLAs, errors, negligence — and caused the customer a financial loss. Often combined with cyber for tech companies.
- General liability, around $1M. Frequently required even for pure-software vendors as a baseline.
- Additional-insured status. The customer wants to be added to your policy for claims arising from your work.
- Waiver of subrogation. Stops your insurer from later pursuing the customer to recover a paid claim.
Procurement teams treat these as pass/fail. A certificate that is missing a coverage, short on a limit, or lacking the additional-insured endorsement gets bounced back, and the deal waits.
Why These Clauses Exist
Enterprise buyers are managing their own vendor risk. A SaaS vendor often sits inside the customer's data environment, processes its records, and can become the source of a breach or an outage. The insurance requirements give the customer a funded counterparty if your service causes them a loss, rather than a startup that might not survive the event.
Tech E&O and cyber map to the two failure modes a customer fears most. Cyber answers the breach: forensics, notification, regulatory defense, and liability to affected parties. Tech E&O answers the performance failure: your product broke, missed an SLA, or produced a wrong result, and the customer lost money as a result. Together they cover "you leaked our data" and "your product failed us" — the two ways a software vendor most often triggers a claim.
Illustrative scenario: A mid-market SaaS company signs a contract requiring $3M cyber, $2M tech E&O, and additional-insured status. A short outage later disrupts the customer's workflow and prompts a claim; because the limits and endorsements were already in place, the certificate matched the contract and the response moved without a coverage dispute.
Right-Sizing Without Overbuying
The most useful anchor for limits is your contracts themselves: buy to your largest current and near-term requirement, not to a hypothetical. A seed-stage vendor selling to mid-market may be fine at $1M–$2M cyber; a vendor closing $5M-requirement enterprise deals needs to carry that limit before signing. Premiums scale with limits, revenue, data volume, and controls, but early-stage tech programs commonly fall in the low-to-mid four figures annually for $1M of coverage as of 2026 — typical market ranges, not a quote.
Strong controls also keep pricing reasonable as you raise limits. MFA, EDR, tested backups, and a documented incident response plan are what underwriters reward. For how the coverages fit together, see our tech E&O insurance guide and our overview of cyber insurance for technology companies.
Match Your Coverage to Your Contracts
OnePark Risk places cyber, tech E&O, and general liability for SaaS companies selling into the enterprise, and we read the insurance exhibit so your certificate matches the contract the first time. Request a coverage review and we will return options sized to your current deals and the ones in your pipeline.
Frequently asked questions
What insurance limits do enterprise SaaS contracts require?
As of 2026, the common minimums are $1M–$5M cyber liability and $1M–$2M tech E&O, often with around $1M general liability. Larger and more regulated customers tend to require the higher end. Always read the specific insurance exhibit, since the exact stack varies by buyer.
What does additional-insured status mean?
It means the customer is added to your policy so they are covered for claims arising out of your work for them. Enterprise MSAs request it routinely. Your broker arranges an endorsement and reflects it on the certificate of insurance you provide.
Do I need both cyber and tech E&O?
For most SaaS vendors, yes. Cyber covers data breaches and ransomware; tech E&O covers claims that your product failed and caused a financial loss. Enterprise contracts frequently require both, and carriers often offer them as a combined policy for technology companies.
What is a waiver of subrogation?
It is a clause that prevents your insurer from later trying to recover a paid claim from the customer. Enterprise agreements commonly require it. Your insurer adds it by endorsement, and it appears on the certificate.
This material is general educational information, not legal, tax, or insurance advice. Coverage availability, policy terms, and regulatory requirements vary by state, carrier, and applicant.