Blog
Cyber Insurance Requirements for Vendors in 2026: What Your Clients' Contracts Ask For
More client contracts require vendors to carry cyber insurance and prove their security controls. What those clauses usually ask for in 2026, and who on your side should handle each part.
If you provide services to larger companies, hospitals, government agencies, or financial institutions, there's a good chance your next contract or vendor onboarding form will ask about cyber insurance. Clients want to know that if a breach on your side affects them, you have coverage and the controls to back it up. Law firms, accounting firms, manufacturers supplying larger companies, and contractors working with healthcare or government see these clauses most often.
Contract language varies, and this isn't legal or insurance advice. Have your attorney and broker review the specifics. But most of these clauses ask for the same handful of things.
What the contract usually asks for
- Proof of coverage. Usually a certificate of insurance showing a cyber liability policy with minimum limits set by the client. Some clients also ask to be named as an additional insured.
- The right kind of coverage. Contracts often specify both first-party coverage (your own costs after a breach) and third-party liability (claims from clients affected by it). Technology vendors are often asked for technology errors and omissions coverage as well.
- Breach notification. A requirement to notify the client within a set window after you discover an incident, often somewhere between 24 and 72 hours.
- Security controls. A questionnaire or contract exhibit asking about MFA, encryption, backups, endpoint protection, patching, and security awareness training.
- Evidence and audit rights. The right to request documentation of those controls, or to audit them.
- Flow-down. A requirement that your own subcontractors meet the same standards if they touch the client's data.
Some newer contracts also ask how vendors use AI tools with client data.
Two problems, two owners
These clauses look like one requirement, but they are two. The insurance part belongs with your broker: limits, coverage types, additional insured status, and certificates. The security part belongs with whoever manages your IT: the controls, the documentation, and the incident response plan that has to meet the notification window.
The two are connected. When you apply for the cyber policy itself, the carrier asks about the same controls the client does. If the answers on your insurance application and your client's questionnaire don't match, or don't match what is actually in place, that becomes a problem at claim time.
What to do before you sign
- Read the insurance and security sections of the contract before signing, not after.
- Send the insurance section to your broker to confirm your current policy meets the limits and coverage types.
- Send the security section to your IT provider to confirm every control is actually in place and documented.
- Check that your written incident response plan can meet the notification window in the contract.
- Keep the evidence ready, so the next questionnaire is a matter of pulling documents, not building them.
- Ask the same questions of any subcontractors who will touch the client's data.
Where we fit
We're not your broker and we don't sell insurance. We handle the IT side: putting the controls in place, documenting them, and helping you answer client questionnaires and carrier applications with evidence. We also have working relationships with insurance professionals who specialize in cyber coverage. If you want a second set of eyes on a contract's requirements, or want to see what other coverage options look like, we can introduce you without replacing your current broker. Our guide to cyber insurance requirements covers what carriers ask about in detail, and our guide to answering a client's vendor security questionnaire covers the questionnaire side. If you're facing one of these contracts now, see how our cyber insurance readiness work handles it.
Next step
Get a clearer view of your IT environment.
Find out what is working, where the risks are, and what needs attention next.
