Buyer Requirements · 5 min read

Insurance for Vendor Onboarding & Reviews

Before a large customer lets you touch their systems or data, you usually pass through vendor onboarding: a security questionnaire, a controls review, and a request for a current certificate of insurance. The insurance ask is rarely optional. Vendor risk teams frequently require proof of cyber coverage — and often tech E&O — before go-live, because you are about to become part of their attack surface. No compliant certificate, no access, no launch. This page explains what vendor onboarding and security reviews typically require on the insurance side, why those requirements exist, and how to clear them without holding up your own launch date. For the broader set of contractual asks that surround onboarding, our enterprise contract requirements guide is the companion; here we focus on the security review and the certificate of insurance.

What Onboarding and Security Reviews Ask For

A vendor security review usually pairs a controls assessment with an insurance check. On the insurance side, the recurring requests as of 2026 are:

  • A current cyber certificate of insurance. Proof of active cyber liability coverage, frequently $1M–$5M depending on the data you will handle.
  • Tech E&O evidence. Many reviews also want professional liability of $1M–$2M, since a vendor's product failure can cause the customer a loss.
  • Additional-insured status. The customer may ask to be added to your policy for claims arising from your work.
  • Controls attestation. Questionnaires probe MFA, EDR, tested backups, and a written incident response plan — frequently the same evidence behind a SOC 2 report.
  • COI before go-live. The certificate is typically a gate: access and launch wait until it is on file.

These requests are checked by a risk team that is comparing your answers and your certificate against a fixed standard. Anything missing comes back as a finding that blocks onboarding.

Why Vendors Get Reviewed

Customers run these reviews because third-party vendors are a leading source of breaches. When you connect to a customer's environment or process its records, your weaknesses become theirs. The security questionnaire tests whether your controls are real, and the insurance requirement ensures that if an incident traces back to you, there is funded coverage to respond rather than a startup that cannot absorb the loss.

Note that a SOC 2 report and insurance answer different parts of the review. SOC 2 is an attestation that your controls operate; it transfers no risk and pays nothing toward an incident. The cyber certificate proves you can fund a response. Many reviews want both, and the good news is that the controls behind a SOC 2 — MFA, EDR, tested backups, an IR plan — are the same ones that earn better cyber pricing. Our cyber insurance for technology companies overview explains how those controls translate into coverage.

Illustrative scenario: A startup clears a customer's security questionnaire on controls but stalls at go-live because the onboarding portal requires a $2M cyber COI naming the customer as additional insured. Having the policy and endorsement ready in advance turns a blocker into a same-day upload. For how the underlying coverage works, see our cyber insurance for small businesses guide.

Clearing the Review Quickly

Speed comes from preparation. Keep your cyber and tech E&O policies active with the endorsements customers commonly request, and keep your controls documentation current so the questionnaire goes fast. Anchor limits to your customers' typical asks — $1M–$5M cyber and $1M–$2M tech E&O as of 2026 — rather than guessing. Premiums vary with revenue, data volume, sector, and controls, but early-stage tech programs often fall in the low-to-mid four figures annually for $1M of coverage as of 2026 — typical market ranges, not a quote. When your broker can issue a matching COI on demand, onboarding stops being a bottleneck.

Clear Onboarding Without Delays

OnePark Risk places cyber and tech E&O for startups selling into the enterprise, and we keep your certificates and endorsements ready so vendor onboarding never stalls your launch. Request a coverage review and we will return options matched to your customers' security and insurance requirements.

Frequently asked questions

Why does vendor onboarding require insurance?

Because vendors are a common source of breaches. When you connect to a customer's systems or handle its data, your risk becomes theirs, so they require proof of cyber coverage — and often tech E&O — to ensure a funded response if an incident traces back to you. The certificate is usually a condition of go-live.

Does a SOC 2 report satisfy the insurance requirement?

No. SOC 2 is an attestation that your controls operate effectively; it transfers no risk and pays nothing toward an incident. Insurance is what funds the response. Many security reviews want both — the report for diligence and a certificate for financial backing.

How quickly can I provide a certificate of insurance?

If your policies are active with the right endorsements, a broker can usually issue a COI fast. Delays come from missing coverages, limits, or additional-insured endorsements that must be added first. Preparing before onboarding starts keeps your launch on schedule.

What limits do security reviews typically require?

As of 2026, common requests are $1M–$5M cyber and $1M–$2M tech E&O, with the higher end for vendors handling sensitive or large volumes of data. Additional-insured status is frequently requested. The exact ask depends on the customer and the data involved.

This material is general educational information, not legal, tax, or insurance advice. Coverage availability, policy terms, and regulatory requirements vary by state, carrier, and applicant.