An insurance requirements clause is a contract term that sets out which types of insurance a party must carry, at what minimum limits, for how long, and how it proves the coverage. In IT, telecom and managed services contracts the clause is usually aimed at the provider, so the customer has some assurance that the provider could pay claims arising from injury, property damage, professional errors or a security incident. Some contracts also place insurance requirements on the customer.
At a glance
- It lists required coverage types and minimum limits, and sometimes deductibles and insurer quality.
- Technology deals commonly add cyber or privacy liability and professional liability to general liability.
- Proof usually comes as a certificate of insurance, with renewal certificates and notice of cancellation.
- Insurance funds what a party owes; the contract’s liability terms decide what it owes.
- Appropriate types and limits vary by service, risk, industry and jurisdiction.
What problem it solves
A contract promise is worth less if the other side can’t pay. If a managed service provider’s mistake causes an outage or a breach, the damages and response costs may exceed what a small or mid-sized provider could pay from its own funds. Insurance requirements help make sure there is money behind the provider’s indemnities and liability commitments.
The clause also helps buyers meet their own obligations. Customers’ contracts, lenders and cyber insurance carriers may ask whether critical vendors carry appropriate coverage, and third-party risk management (TPRM) programs often check certificates as part of onboarding.
How it works
Coverage types. Common requirements include commercial general liability, professional liability or technology errors and omissions, cyber or network security and privacy liability, workers’ compensation and employer’s liability where the law requires it, auto liability for field service, and sometimes crime or fidelity coverage for providers with access to funds or systems. Not every contract needs every type.
Limits. The clause sets minimum per-claim and aggregate limits for each policy. Appropriate figures depend on the size of the deal, the data involved and the potential impact of a failure, and are worth discussing with your broker rather than copying from another contract.
Additional insured and waivers. Customers commonly ask to be named as an additional insured on some policies, typically general liability, and for a waiver of subrogation. Not every policy type allows this, and insurers decide what they will endorse.
Evidence. The provider delivers a certificate of insurance at signing and on renewal. Many clauses also require notice before cancellation or material reduction, and some allow the customer to request policy endorsements.
Claims-made coverage. Cyber and professional liability policies are often written on a claims-made basis, so contracts may require coverage to continue, or a tail to be bought, for a period after the contract ends.
Subcontractors. The clause may require the provider to make its subcontractors carry similar coverage, which links to the subcontracting clause.
Interpretation. What a policy actually covers depends on its wording and exclusions, and the contract clause is interpreted under the governing law. This is general information; it isn’t legal advice, so have counsel and your insurance broker review both the contract and the certificates.
Collecting and tracking certificates across many providers is a routine vendor management task, alongside contract and billing tracking in telecom expense management. For outsourced operations, managed network services providers with administrative access are a common focus for cyber coverage requirements.
When it matters for buyers
- Providers with privileged access. MSPs, MSSPs and network managers that can reach your systems or data.
- Handling sensitive data. Personal, payment or health data raise the stakes of a breach; align with your data processing agreement (DPA).
- On-site work. Installers and field technicians bring injury and property risks.
- When your insurer asks. Your own cyber insurance application may ask about vendor coverage.
- When a provider asks you for coverage. Check that the required types and limits match what you carry before signing.
Questions to ask vendors
- Which insurance policies do you carry, at what limits, and with which insurers?
- Does your cyber policy cover incidents affecting customer data and systems, and what are the main exclusions?
- Will you name us as an additional insured where the policy allows, and provide a certificate?
- Will you notify us before coverage is cancelled or materially reduced?
- Are your cyber and professional policies claims-made, and will coverage continue after the contract ends?
- Do your subcontractors carry comparable coverage?
How it differs from cyber insurance
Cyber insurance is a type of policy that covers some costs and liability after a security incident. An insurance requirements clause is a contract term that may require a party to buy cyber insurance, among other policies, and to prove it. Your own cyber policy protects your organization; the clause is about making sure the provider has its own coverage, so claims arising from the provider’s failures have funding behind them.
