How do you negotiate MSA indemnification and insurance minimums without handing the economic loss to the vendor?
Negotiate MSA indemnification and insurance so that each risk sits with the party best able to control it, rather than dumping the whole economic loss on the vendor (which the vendor will price back into your deal anyway). The mechanics: (1) keep indemnification and the liability cap as two separate clauses — indemnity says *who defends and pays a third-party claim*, the cap says *how big the vendor's total exposure gets*; (2) set a general cap at a defensible multiple of fees (commonly 1x–2x trailing 12-month fees) and then carve specific catastrophic risks out from under that cap — third-party IP infringement, breach of confidentiality, data/security breach, and gross negligence or willful misconduct — either uncapped or set to a higher "supercap" (often 2x–5x fees); (3) require insurance minimums that back the carve-outs — commercial general liability, professional liability / errors & omissions, and cyber liability — and treat those limits as a floor for recovery, not a ceiling on the vendor's obligation, so a covered loss is paid by an insurer instead of coming out of the vendor's balance sheet; (4) make key clauses mutual where it's fair — you indemnify the vendor for claims arising from *your* data and *your* misuse — which lowers the vendor's net risk without lowering your protection; and (5) scale every number to deal size, data sensitivity, and the vendor's ability to pay rather than demanding one blunt high limit that a mid-market vendor can't carry.
The reason this doesn't "hand the economic loss to the vendor" is that most of the real dollars flow through insurance, not the vendor's cash. You are not asking the vendor to self-fund a $5M breach; you are asking them to carry a $5M cyber policy, name you where appropriate, and accept an uncapped or supercapped indemnity *only for the handful of risks they alone control*. Routine performance failures stay under a modest cap the vendor can live with. That is the whole game: separate the levers, cap the routine, uncap the catastrophic, and fund the catastrophic through insurance.
Why MSA Indemnification Decides Who Eats the Loss
Indemnification is the clause that answers a brutally simple question: when a third party sues because of something that happened under this contract, who pays for the defense and the settlement? An MSA without a thought-through indemnity is not a milder version of the problem — it is a coin flip on who absorbs a six- or seven-figure event. This is why indemnity and its companion liability cap are consistently among the last clauses to close in enterprise legal review, and why deals stall there for weeks.
The failure mode buyers most fear is the broad "all claims" indemnity — language where the vendor agrees to indemnify only for its own gross negligence, or, worse, where *you* agree to indemnify the vendor for "any and all claims arising out of the agreement." Read literally, that second version can make you the backstop for the vendor's own product defects. The failure mode vendors most fear is unlimited liability — an indemnity with no cap, no carve-out discipline, and an insurance requirement they can't afford, which turns a routine SaaS subscription into a bet-the-company exposure.
The instinct on the buyer side is to solve fear with size: demand a huge cap, demand $10M of every kind of insurance, demand the vendor eat everything. That instinct is exactly what "hands the economic loss to the vendor," and it backfires three ways. First, the vendor prices the risk back to you — a vendor forced to carry catastrophic uncapped exposure raises the subscription price or walks. Second, an unrealistic insurance floor (say $10M cyber from a 30-person startup) is either a fiction the vendor can't actually meet, or it disqualifies the vendor you wanted. Third, a single blunt cap ignores that different risks have wildly different severities — a missed SLA and a leaked customer database do not belong under the same number.
The sophisticated move is to stop treating "the vendor pays" as the goal. The goal is loss sits with the party that could have prevented it, and is funded by insurance wherever possible. A vendor controls its own code, its own security posture, and whether it grossly mishandles your data — so those risks are theirs, and they buy insurance to fund them. You control your own data, your own configuration choices, and how you use the product — so those risks are yours. Everything in the negotiation below is a tool for drawing that line precisely instead of bluntly.
The Three Levers You Are Actually Negotiating
Practitioners who lose these negotiations usually do so because they conflate three distinct clauses into one argument. They are separate levers, and you pull them independently.
Lever 1 — Indemnification (scope). This is the *promise to defend and hold harmless* against third-party claims. The scope question is: *which* claims? A well-drafted indemnity enumerates trigger events — IP infringement by the vendor's product, the vendor's breach of confidentiality, the vendor's violation of law, personal injury or property damage caused by the vendor. Note the word "third-party." True indemnity is about claims *someone outside the contract* brings; direct losses between you and the vendor are handled by the breach/damages clauses, not indemnity. Confusing the two is the single most common drafting error, and it inflates the fight unnecessarily.
Lever 2 — Limitation of liability (the cap and exclusions). This clause does two things: it excludes categories of damages (almost always consequential, incidental, and punitive damages, plus lost profits and lost revenue), and it caps total liability at a number. The cap is usually expressed as a multiple of fees — trailing 12 months (TTM) is the most common reference, sometimes total fees paid over the term. Critically, the cap and the indemnity interact: if your negotiated indemnity is technically *subject to* the cap, then a huge IP judgment gets squeezed down to 1x fees and your indemnity is nearly worthless. The whole art of the carve-out (next section) is deciding which indemnities live *above* the cap.
Lever 3 — Insurance requirements (the funding). This clause requires the vendor to carry specified policies at specified limits, name you as an additional insured where appropriate, provide certificates of insurance (COIs), and give notice of cancellation. Insurance is what makes the other two levers affordable: a vendor can accept a supercapped data-breach indemnity precisely because a cyber policy — not its checking account — funds the first several million dollars.
Here is the mental model that keeps these straight: **indemnity decides *whether* the vendor owes you, the cap decides *how much*, and insurance decides *where the money comes from*.** When you argue all three at once — "I want a broad indemnity, uncapped, with $10M of insurance" — you sound greedy and the vendor digs in. When you argue them separately — "narrow, well-defined triggers; a modest general cap with a few specific carve-outs; and insurance sized to fund exactly those carve-outs" — you sound reasonable, and reasonable closes.
Building a Liability Cap With Supercap Carve-Outs
The cap is where the economic-loss question is really decided, so structure it deliberately.
Start with the general cap. For most B2B SaaS and services MSAs, the negotiable range for the *general* cap runs from a floor of the trailing 12-month fees up to roughly 2x–3x TTM fees. Vendors open at "fees paid in the 12 months preceding the claim" (their favorite, because it's small early in the relationship). Buyers open higher. A defensible landing spot for routine, non-catastrophic breaches is 1x–2x TTM fees. Do not fight to the death here — routine breaches are rarely where the catastrophic dollars live, and spending leverage to move a general cap from 1x to 2x is usually a poor trade.
Then carve out the catastrophic risks. The carve-outs are the clauses that either sit *entirely outside* the cap (uncapped) or get a higher separate cap — a "supercap." The standard carve-out list, in rough order of how often each is granted:
- Third-party IP infringement indemnity. Frequently uncapped or supercapped, because the vendor alone controls whether its product infringes. If the vendor resists uncapped, a common compromise is a supercap (e.g., the greater of $1M–$5M or a multiple of fees) with a duty to *procure a license, modify the product, or refund* as the remedy.
- Breach of confidentiality. Often carved out because the harm (leaked trade secrets) dwarfs the contract value.
- Data / security breach. Increasingly its own carve-out with its own supercap, explicitly backed by a required cyber policy. A supercap of 2x–5x fees, or a stated dollar figure, tied to whether the breach resulted from the vendor's failure to maintain agreed security controls, is a common structure.
- Gross negligence and willful misconduct. Almost universally uncapped — no vendor can credibly argue it should be shielded from liability for intentional wrongdoing, and courts in many jurisdictions won't enforce a cap on it anyway.
- Indemnification obligations generally, and sometimes breach of the payment obligation (your obligation to actually pay).
Discipline the carve-outs so the vendor can say yes. An uncapped carve-out with no boundaries is what scares vendors into unlimited-liability panic. Give them predictability without giving up protection:
- Materiality / basket thresholds: small claims (e.g., under $50K) stay under the general cap; only larger claims reach the carve-out. This mirrors the "basket" mechanics common in M&A and construction contracts.
- Time limits / sunset: a carve-out that applies only for the term plus a defined tail (often 1–2 years) rather than forever.
- Tie the trigger to fault: a data-breach supercap that applies "to the extent the breach resulted from Vendor's failure to maintain the security controls in Exhibit X" — not to every breach including ones your own misconfiguration caused.
Make it mutual where it's fair. You are not only a claimant; you are also a source of risk. If your data includes content that infringes someone's IP, and the vendor gets sued because they processed it, *you* should indemnify *them*. A well-balanced MSA has the vendor indemnify for IP-in-the-product and security failures, and the buyer indemnify for the buyer's-data and buyer's-misuse claims — often at a lower cap because the buyer-side risk is more contained. Mutuality is the single most persuasive concession you can offer: it costs you little on deals where your data is clean, and it dramatically lowers the vendor's *net* exposure, which is what unsticks the negotiation. This is the concrete answer to "without handing the economic loss to the vendor" — you are visibly taking back the slice of loss that was always yours.
Insurance Minimums: Make Them a Floor, Not a Ceiling
Insurance is where buyers most often either overreach (killing the deal) or underprotect (leaving carve-outs unfunded). The discipline is to size each policy to the risk it funds, and to draft the supporting mechanics that make a certificate actually worth something.
The policies that matter, and why:
- Commercial General Liability (CGL). Covers bodily injury and property damage. Standard limits are $1M per occurrence / $2M aggregate. For a pure-software vendor this is almost boilerplate; don't over-negotiate it.
- Professional Liability / Errors & Omissions (E&O). Covers claims that the vendor's *service or advice* caused financial harm — the workhorse policy for a services or SaaS vendor. Typical $1M–$5M per claim, scaled to deal size.
- Cyber Liability / Tech E&O. The policy that funds your data-breach carve-out — covers breach response, notification, forensics, regulatory defense, and third-party liability. This is the one to focus energy on. Typical $1M–$10M depending on the sensitivity and volume of data.
- Workers' compensation and employer's liability, and umbrella/excess to layer over the primaries when you need higher effective limits without forcing the vendor to buy up every primary.
Floor, not ceiling — the critical distinction. Vendors love to argue "our policy limit is the most we can ever owe you." Reject that framing in drafting. Include language that the required insurance is a minimum requirement and does not limit the vendor's liability or indemnification obligations under the agreement. The insurance is the *funding mechanism* for the carve-outs, not a *cap* on them. A vendor with a $5M cyber policy and an uncapped confidentiality carve-out owes you the full loss; the first $5M just happens to come from the insurer.
The mechanics that make a COI meaningful (a certificate alone proves almost nothing):
- Additional insured status on the CGL where appropriate, so you can claim directly under the vendor's policy for covered events — this extends coverage to you *without raising the vendor's premium*, one of the cleanest wins available.
- Primary and non-contributory wording, so the vendor's policy pays first before your own coverage is touched.
- Waiver of subrogation, so the vendor's insurer can't turn around and sue you to recover what it paid — mutual waivers keep both sides' premiums stable and are standard in construction and technology contracts.
- Notice of cancellation or material change (commonly 30 days) so a lapse doesn't surprise you.
- A.M. Best rating floor (e.g., insurer rated A- VII or better) so the coverage is actually collectible.
When the vendor can't meet the number, trade instead of walking. A mid-market or startup vendor may have a strong balance sheet but a thin policy. Options that keep the deal alive without leaving you exposed:
- Accept a self-insured retention (SIR) or higher deductible — the vendor self-funds the first tranche (e.g., $250K–$500K), lowering their premium, while insurance funds the tail.
- Accept a lower limit now with a contractual step-up — e.g., $1M today, increasing to $3M within 12 months as the vendor scales.
- Take a parent-company or corporate guarantee in lieu of a policy the subsidiary can't carry.
- Layer an umbrella policy over modest primaries to reach the effective limit cheaply.
Each of these is a way to keep the economic loss funded and off the vendor's operating cash without pretending a small vendor is a large one.
Tiering Both Indemnity and Insurance to Real Risk
The blunt-instrument mistake is one cap and one insurance schedule for every engagement regardless of what's actually at stake. The fix is to tier — to make the numbers a function of the risk profile of the specific service.
Tier the indemnity/cap by service risk. Segment services by how much damage a failure could cause and attach proportionate treatment:
- Low-risk (e.g., basic hosting, a read-only dashboard, marketing content): general cap around 1x fees, standard exclusions, no supercap needed.
- Medium-risk (e.g., systems that touch payments, workflow automation with financial impact): higher general cap and a data-breach carve-out.
- High-risk (e.g., processing PHI/PII, security-critical infrastructure, anything regulated): supercapped or uncapped data and confidentiality carve-outs, and the strongest insurance schedule.
Document the tiers in an indemnification/insurance schedule attached to the MSA, with clear definitions of each category, so a later SOW simply references the applicable tier rather than reopening the whole negotiation.
Tier the insurance to volume or sensitivity. Rather than a single flat cyber limit, scale it to a real exposure metric — for example, coverage that steps up with the volume of records processed or the sensitivity of the data category (public → confidential → regulated). The principle is that a vendor touching a few thousand low-sensitivity records shouldn't be forced to buy the same policy as one processing hundreds of thousands of health records — and conversely, the high-volume vendor shouldn't get away with a token limit. Scaling coverage to actual exposure is what keeps the requirement *defensible* in negotiation: the vendor can see the logic, so they stop treating your number as arbitrary and start treating it as a risk calculation they can meet.
Tiering is also your best rebuttal when a vendor cries "unrealistic." You are not demanding a blanket $10M; you are demanding coverage *proportional to the specific risk this engagement creates*. That reframing moves the conversation from a power struggle to an underwriting exercise, which is exactly where you want it.
The Negotiation Playbook: Anchors, Counters, and Escalation
Structure is nothing without the moves that get it signed. Here is the practical sequence.
Anchor with a rationale, not a demand. Open every ask with the risk it addresses. "We need the data-breach indemnity carved out above the cap because a breach of our customer records could cost multiples of this contract's value, and you're the party controlling the security controls." A rationale is much harder to reject than a number.
Trade concessions across levers. Because the three levers are separate, you can give on one to win another. Concede a slightly lower general cap in exchange for a clean, uncapped IP-infringement carve-out. Accept the vendor's existing insurance limits in exchange for additional-insured status and primary/non-contributory wording. Offer mutuality (you indemnify for your data) to win a supercap on their security failures. Each trade lowers the vendor's *net* exposure while preserving your protection — which is the literal mechanism for not "handing the loss to the vendor."
Know your walk-away red flags. Reject on sight: an indemnity that makes *you* the backstop for the vendor's product ("Customer indemnifies Vendor for any and all claims arising from the agreement"); a general cap set at a small fixed dollar amount unrelated to the deal ("liability capped at $10,000"); an indemnity that is silent on IP infringement entirely; or an insurance requirement so low it can't fund the carve-outs it's supposed to back.
Use a graduated escalation ladder. When the vendor won't move, escalate in defined steps rather than issuing ultimatums:
- Re-anchor on the risk. Restate what event the clause protects against and quantify it if you can.
- Offer a bounded version. Propose the carve-out *with* a materiality threshold, a sunset, and a fault trigger — this often converts a "no" to unlimited into a "yes" to a disciplined supercap.
- Substitute insurance for balance-sheet risk. "You don't have to self-fund this — carry the cyber policy and we take exposure above the limit." Vendors relax dramatically once they realize the ask is a premium, not a liability.
- Bring in the numbers. Reference benchmark ranges (1x–2x general caps; supercaps at 2x–5x for data/IP) so the vendor sees your position as market, not extortionate.
- Escalate to counsel-to-counsel, and only as a last resort raise the deal's fate. Most indemnity fights are resolved at step 2 or 3.
Get the boilerplate right so the structure survives. Confirm the survival clause keeps indemnity and confidentiality obligations alive after termination; confirm the notice-of-claim and duty-to-defend mechanics (who controls the defense, who approves settlement); and confirm the insurance and indemnity clauses cross-reference correctly so a carve-out isn't accidentally swallowed by the cap. A perfectly negotiated cap is worthless if a stray "notwithstanding anything to the contrary" clause pulls the carve-outs back under it. Have someone read the limitation-of-liability, indemnification, and insurance clauses *together*, out loud, as a system — that final read is where most six-figure drafting errors are caught.
FAQ
What is a typical range for an MSA liability cap?
For general, non-catastrophic breaches, caps commonly land between 1x and 2x the trailing 12 months of fees, with vendors opening at "fees paid in the prior 12 months" and buyers pushing toward 2x–3x. The more important number is the supercap for carve-outs like data breach or IP infringement, which is frequently set higher (often 2x–5x fees) or left uncapped. Never accept a single flat-dollar cap unrelated to deal size — it collapses your protection as the relationship grows.
What should be carved out from the liability cap?
The standard carve-outs are third-party IP infringement, breach of confidentiality, data/security breaches, gross negligence and willful misconduct, and each party's indemnification obligations. These sit either fully uncapped or under a higher supercap because their potential harm dwarfs the contract value and because the vendor controls whether they occur. Discipline them with materiality thresholds, sunsets, and fault-based triggers so the vendor can accept them without fearing unlimited exposure.
How do I set insurance minimums without killing the deal for a smaller vendor?
Size each policy to the risk it funds — CGL at $1M/$2M, E&O and cyber scaled to data sensitivity and deal size — and treat the limits as a floor for recovery, not a cap on liability. If the vendor can't meet a number, trade for a self-insured retention, a contractual step-up over 12 months, a parent-company guarantee, or an umbrella policy rather than walking. Additional-insured status and waiver of subrogation extend coverage to you at little or no premium cost to the vendor.
What's the difference between the indemnification clause and the limitation-of-liability clause?
Indemnification governs *third-party* claims — the vendor's promise to defend and pay when someone outside the contract sues because of the vendor's product or conduct. Limitation of liability governs the relationship *between you and the vendor* — it excludes certain damage types (consequential, lost profits) and caps the total. They interact: whether an indemnity is subject to the cap or carved out above it determines whether your indemnity is actually worth anything in a large claim.
Why is mutual indemnification the key to a fair deal?
Because you are also a source of risk. If a claim arises from *your* data (e.g., it infringes a third party's IP) or *your* misuse of the product, that loss is fairly yours, and indemnifying the vendor for it costs you little on clean deals. Offering mutuality lowers the vendor's net exposure — which is the concrete way you avoid "handing the economic loss to the vendor" — while your protection against the vendor's own IP and security failures stays intact.
How should insurance and indemnification be drafted so one doesn't undercut the other?
Draft them as complementary, not redundant. State explicitly that required insurance is a minimum and does not limit the vendor's indemnity or liability, so a policy limit can't be read as a cap. Then check that the limitation-of-liability clause's carve-outs and the insurance schedule line up — the policies should be sized to fund exactly the carved-out risks. Read the three clauses together to catch any "notwithstanding" language that accidentally pulls a carve-out back under the general cap.
Sources
- American Bar Association — Business Law Section, articles and model provisions on indemnification and limitation of liability in commercial agreements: https://www.americanbar.org/groups/business_law/
- International Risk Management Institute (IRMI) — reference material on additional insured status, waiver of subrogation, and contractual risk transfer: https://www.irmi.com/
- Insurance Information Institute (III) — explanations of general liability, professional liability, and cyber insurance coverage: https://www.iii.org/
- National Association of Insurance Commissioners (NAIC) — regulatory standards and consumer guidance on commercial insurance: https://content.naic.org/
- World Commerce & Contracting (formerly IACCM) — benchmarks and best practices on contract risk allocation and negotiation: https://www.worldcc.com/
- Harvard Business Review — negotiation strategy and risk-transfer frameworks for vendor agreements: https://hbr.org/
Related on PULSE
- [How do you track non-standard MSA clauses that impact renewals?](/knowledge/q9916)
- [How do you map stakeholder power vs. interest in an enterprise MSA negotiation before legal even touches it?](/knowledge/q279)
- [How should a 2027 pricing team design minimum order quantity and platform minimums?](/knowledge/q12506)
- [How do you weight forecast categories when consumption deals have not hit usage minimums yet?](/knowledge/q10465)
- [Should I Hire a Fractional CRO If My Family Business Is Handing Sales to the Next Generation?](/knowledge/q15906)










