Your customer wants proof of cyber insurance. Now what?
The contract is almost signed.
Then procurement sends over an insurance schedule asking for things like Cyber Liability, Tech E&O and a certificate of insurance.
If you've never dealt with this before, it can look more alarming than it is.
Here's what they're asking for, what usually happens next, and where companies tend to get stuck.
Why they're asking
Your customer takes on risk by letting your software touch their data or their operations. The schedule is their standard way of making sure that if something goes wrong, there's coverage to recover against — not a five-person company with no balance sheet.
Two things follow. The requirement is usually boilerplate: the same schedule goes to every vendor, which is why it can look heavy for what you do. And the people enforcing it are checking boxes against a policy, not judging you. So resolving a mismatch is mostly about producing a documented match to a checklist.
What the schedule is actually asking for
The document names coverage types and attaches conditions to them. The terms that show up most often:
- Cyber liability
- Covers data breaches and security incidents — commonly breach response, notification, and liability to third parties whose data was involved.
- Technology errors & omissions (Tech E&O)
- Professional liability for tech companies: broadly, claims that your product failed to perform and caused financial loss. Cyber and Tech E&O are often written together in one policy for software companies — so a schedule asking for both may be satisfiable by a single policy.
- Commercial general liability (CGL)
- Traditional business liability, mostly bodily injury and property damage. Often required even where it has little to do with software, because the schedule is standard.
- Per-occurrence and aggregate limits
- Two different numbers. Per-occurrence applies to a single claim; aggregate is the most the policy pays across the whole period.
- Additional insured
- A request to add your customer to your policy so they have rights under it. Routine on general liability, and frequently not available on professional liability or Tech E&O — one of the most common sources of friction.
- Waiver of subrogation
- Your insurer gives up its right to pursue your customer to recover a payout. Usually added by endorsement, not automatic.
- Primary and non-contributory
- A request that your policy pays first, before any of your customer's own insurance, without asking theirs to share.
- Claims-made, and the retroactive date
- Cyber and Tech E&O are usually claims-made: the policy responds to claims made during the period, not to incidents that occurred during it. The retroactive date sets how far back covered work can reach — worth understanding before you promise anything about historical work.
- Certificate of insurance (COI)
- The one-page document — commonly an ACORD form — that evidences your coverage. Your broker or insurer issues it. It's what procurement actually wants in the folder.
What usually happens next
- Pull the requirements into a list: coverage types, per-occurrence and aggregate limits, and every endorsement requested (additional insured, waiver of subrogation, primary and non-contributory).
- Check what you already have. If you've raised funding you may already hold D&O, and sometimes general liability from an office lease.
- Take the schedule itself — not a summary — to a licensed broker or insurer. The document is what they quote against, and it decides which endorsements are available.
- Get quotes, and ask specifically whether every requested endorsement can actually be issued.
- Bind the coverage. Nothing can be certified before it exists.
- Request the COI with the exact wording asked for, including the precise legal entity name and address of the certificate holder.
- Send it to procurement and expect a review against their checklist.
How long it takes
The part founders underestimate isn't buying the policy — it's the round trips. An underwriter question, an endorsement that turns out to be unavailable, a certificate issued with the wrong entity name, a reviewer who's out for two days.
If the deal has a signature date, work backwards from it and start early. The schedule is usually in the draft contract, so this can run alongside legal review rather than after it.
Where it tends to get stuck
- Additional insured on professional liability. Frequently requested, frequently unavailable. The fix is usually a conversation between your broker and their risk team.
- Limits above what a company your size is normally written for. There are established ways to handle this — raise it early rather than discover it late.
- The retroactive date versus work already delivered, if you've been shipping during a pilot.
- Entity name mismatches. The certificate holder must match the contracting entity exactly. Trivial, and a very common cause of a rejected certificate.
- Assuming the schedule is fixed — or that it's fully negotiable. Some requirements are set by the customer's own policy; others are boilerplate a risk team will amend once your broker explains what's actually available.
What to ask a broker
You don't need the answers in advance. You need the schedule and these questions:
- Can one policy satisfy every coverage type here, or does it need more than one?
- Which requested endorsements can actually be issued, and which can't?
- What will the retroactive date be, and what does that mean for work already delivered?
- What do you need from me to quote, and how fast can a certificate be issued once bound?
- If the next enterprise customer asks for more, how does this policy adapt?
The short version
An insurance schedule is a checklist held by someone who isn't evaluating you personally. The work is translating it accurately, getting it to a licensed professional early, and being precise about names and wording on the certificate. It's procedural — but it runs on other people's timelines, which is why it blocks deals when it's left until the contract is otherwise ready to sign.
Sources and further reading
Where this guide describes coverage types and process, it draws on industry and regulator sources. They explain the concepts in more depth:
- U.S. Small Business Administration — Get business insurance
- Insurance Information Institute — Cyber insurance
- Insurance Information Institute — Professional liability (errors & omissions)
- Texas Department of Insurance — Professional liability FAQ (including claims-made vs. occurrence)