Gold Pika

Your customer wants proof of cyber insurance. Now what?

The contract is almost signed.

Then procurement sends over an insurance schedule asking for things like Cyber Liability, Tech E&O and a certificate of insurance.

If you've never dealt with this before, it can look more alarming than it is.

Here's what they're asking for, what usually happens next, and where companies tend to get stuck.

Why they're asking

Your customer takes on risk by letting your software touch their data or their operations. The schedule is their standard way of making sure that if something goes wrong, there's coverage to recover against — not a five-person company with no balance sheet.

Two things follow. The requirement is usually boilerplate: the same schedule goes to every vendor, which is why it can look heavy for what you do. And the people enforcing it are checking boxes against a policy, not judging you. So resolving a mismatch is mostly about producing a documented match to a checklist.

What the schedule is actually asking for

The document names coverage types and attaches conditions to them. The terms that show up most often:

Cyber liability
Covers data breaches and security incidents — commonly breach response, notification, and liability to third parties whose data was involved.
Technology errors & omissions (Tech E&O)
Professional liability for tech companies: broadly, claims that your product failed to perform and caused financial loss. Cyber and Tech E&O are often written together in one policy for software companies — so a schedule asking for both may be satisfiable by a single policy.
Commercial general liability (CGL)
Traditional business liability, mostly bodily injury and property damage. Often required even where it has little to do with software, because the schedule is standard.
Per-occurrence and aggregate limits
Two different numbers. Per-occurrence applies to a single claim; aggregate is the most the policy pays across the whole period.
Additional insured
A request to add your customer to your policy so they have rights under it. Routine on general liability, and frequently not available on professional liability or Tech E&O — one of the most common sources of friction.
Waiver of subrogation
Your insurer gives up its right to pursue your customer to recover a payout. Usually added by endorsement, not automatic.
Primary and non-contributory
A request that your policy pays first, before any of your customer's own insurance, without asking theirs to share.
Claims-made, and the retroactive date
Cyber and Tech E&O are usually claims-made: the policy responds to claims made during the period, not to incidents that occurred during it. The retroactive date sets how far back covered work can reach — worth understanding before you promise anything about historical work.
Certificate of insurance (COI)
The one-page document — commonly an ACORD form — that evidences your coverage. Your broker or insurer issues it. It's what procurement actually wants in the folder.

What usually happens next

  1. Pull the requirements into a list: coverage types, per-occurrence and aggregate limits, and every endorsement requested (additional insured, waiver of subrogation, primary and non-contributory).
  2. Check what you already have. If you've raised funding you may already hold D&O, and sometimes general liability from an office lease.
  3. Take the schedule itself — not a summary — to a licensed broker or insurer. The document is what they quote against, and it decides which endorsements are available.
  4. Get quotes, and ask specifically whether every requested endorsement can actually be issued.
  5. Bind the coverage. Nothing can be certified before it exists.
  6. Request the COI with the exact wording asked for, including the precise legal entity name and address of the certificate holder.
  7. Send it to procurement and expect a review against their checklist.

How long it takes

The part founders underestimate isn't buying the policy — it's the round trips. An underwriter question, an endorsement that turns out to be unavailable, a certificate issued with the wrong entity name, a reviewer who's out for two days.

If the deal has a signature date, work backwards from it and start early. The schedule is usually in the draft contract, so this can run alongside legal review rather than after it.

Where it tends to get stuck

What to ask a broker

You don't need the answers in advance. You need the schedule and these questions:

The short version

An insurance schedule is a checklist held by someone who isn't evaluating you personally. The work is translating it accurately, getting it to a licensed professional early, and being precise about names and wording on the certificate. It's procedural — but it runs on other people's timelines, which is why it blocks deals when it's left until the contract is otherwise ready to sign.

Sources and further reading

Where this guide describes coverage types and process, it draws on industry and regulator sources. They explain the concepts in more depth:


Gold Pika provides general information, not legal, financial or insurance advice, and we are not licensed to advise or to arrange coverage. For your specific situation, work with a licensed broker or insurer. This page contains no affiliate links. Found an error? Tell us.