Skip to main content
Promotional banner for the pentest readiness checklist
A Vendor Cyber Contract Review TemplateUnderwriting & Risk Selection
5 min readFor Cyber Insurance Buyers & Brokers

A Vendor Cyber Contract Review Template

Think your vendor agreements protect you when a breach happens? Many organizations only discover the gaps after an incident forces them to scrutinize the fine print.

Vendor contracts lay the groundwork for cyber risk transfer, but they don't eliminate your exposure. When a marketing agency loses your customer database or a cloud provider goes offline, the contract determines financial responsibility, but your operations still suffer. Review these agreements before an incident occurs, not during one.

This template provides a structured framework for evaluating vendor cyber contracts. Use it during renewals, before onboarding new vendors, or when your organization's risk profile changes.

Purpose of the Template

This review template helps identify coverage gaps between what your vendor contract promises and what your Stand-Alone Cyber Policy actually covers. Use it to:

  • Verify that vendor insurance requirements match your actual exposure.
  • Confirm indemnification language covers the incidents you care about.
  • Spot conflicts between vendor obligations and your own policy terms.
  • Document which party controls incident response decisions.

The template focuses on cyber-specific provisions. You'll still need legal review for broader contractual issues, but this provides the operational lens your risk and insurance teams need.

Prerequisites

Before using this template, gather:

  • Current vendor contract (including all amendments and exhibits).
  • Your organization's Stand-Alone Cyber Policy declarations and coverage forms.
  • List of what data or systems the vendor accesses.
  • Documentation of the vendor's current insurance certificates.

Understand which business functions this vendor supports. A payroll provider holding employee tax records creates different exposure than a marketing agency managing your social media accounts.

The Vendor Cyber Contract Review Template

Vendor Name: _______________
Contract Renewal Date: _______________
Reviewer: _______________
Review Date: _______________

Section 1: Insurance Requirements

Does the contract require the vendor to maintain Cyber Liability Insurance?
☐ Yes ☐ No

Required policy limit: $_______________

Is this limit adequate for the data/systems at risk?
☐ Yes ☐ No ☐ Uncertain

Does the contract specify coverage for:
☐ Data breach response costs
☐ Regulatory defense and penalties
☐ Business Interruption Coverage
☐ Data Restoration Coverage
☐ Cyber Extortion Coverage

Are you named as an additional insured?
☐ Yes ☐ No

If yes, does the contract specify:
☐ Whether coverage is primary or excess to your own policy
☐ What events trigger additional insured protection
☐ Whether you receive notice of policy changes or cancellations

Section 2: Indemnification Provisions

Does the vendor agree to indemnify you for cyber incidents?
☐ Yes ☐ No ☐ Partial

Indemnification covers:
☐ Third-party claims (lawsuits, regulatory actions)
☐ First-party losses (your own response costs, business interruption)
☐ Both

Are there carve-outs or limitations?
☐ Caps on indemnity amounts
☐ Exclusions for certain incident types
☐ Requirement that you prove vendor negligence

Notes on limitations:


Section 3: Incident Response Obligations

Who controls the incident response if a breach occurs?
☐ Your organization
☐ The vendor
☐ Joint decision-making
☐ Not specified

Does the contract require the vendor to:
☐ Notify you within a specific timeframe (specify: ___ hours/days)
☐ Preserve forensic evidence
☐ Cooperate with your Breach Coach and forensic team
☐ Cover costs of your independent investigation

Does the contract address Breach Notification Requirements?
☐ Vendor handles all notifications
☐ You retain control of customer/employee notifications
☐ Joint approach required
☐ Not addressed

Section 4: Security Standards and Audit Rights

Does the contract require the vendor to maintain specific security controls?
☐ Yes (specify framework: _______________)
☐ No
☐ Vague language only

Do you have the right to:
☐ Audit vendor security practices
☐ Review vendor SOC 2 reports or similar certifications
☐ Require remediation of identified vulnerabilities
☐ Terminate for security failures

Audit frequency allowed: _______________

Section 5: Limits of Liability

Does the contract cap the vendor's total liability?
☐ Yes (amount: $_______________) ☐ No

Does the cap apply to cyber incidents specifically?
☐ Yes ☐ No ☐ Unclear

If capped, does the amount exceed:
☐ The vendor's insurance policy limits
☐ Your potential losses from a vendor-caused incident
☐ Neither

Section 6: Gaps and Conflicts

Compare vendor contract to your Stand-Alone Cyber Policy:

Your policy's Contingent Business Interruption coverage:
☐ Covers vendor outages ☐ Excludes vendor events ☐ Requires specific trigger

If your policy excludes certain vendor-related losses, does the vendor contract fill that gap?
☐ Yes ☐ No ☐ Partial

Conflicts identified:


How to Customize It

Adjust Section 1 based on the vendor's role. A cloud infrastructure provider needs higher limits than a vendor with read-only access to non-sensitive data. If the vendor processes payment card data, add a line for PCI DSS compliance requirements.

In Section 3, specify notification timeframes that align with your own Breach Notification Requirements. If you operate in California, you may need vendor notification within specific windows to meet regulatory deadlines.

For Section 5, calculate realistic loss scenarios. If this vendor's failure could halt operations for three days, estimate your daily revenue loss and compare it to the liability cap. A vendor who agrees to a $100,000 liability cap but could cause $500,000 in business interruption creates a gap your Stand-Alone Cyber Policy needs to fill.

Add vendor-specific questions. If the vendor uses subcontractors, ask whether insurance and indemnification obligations flow down to those parties.

Validation Steps

After completing the template:

  1. Cross-reference with your Cyber Insurance policy. Confirm that gaps in vendor coverage don't create uncovered exposure. If the vendor's indemnification excludes regulatory penalties, verify your policy covers those costs.

  2. Request current certificates of insurance. Verify the vendor actually maintains the coverage the contract requires. Check policy effective dates and limits.

  3. Escalate conflicts to legal and risk leadership. When vendor liability caps fall short or indemnification language contains broad carve-outs, document the exposure and decide whether to renegotiate, accept the risk, or increase your own coverage limits.

  4. Schedule the next review. Vendor risk changes when contracts renew, when vendors add new services, or when your own operations evolve. Set a calendar reminder for 90 days before contract renewal.

This template doesn't replace legal counsel, but it gives you the operational framework to spot issues before they become claims. Contracts establish who pays. Your Stand-Alone Cyber Policy determines whether you can actually collect. Review both together, and you'll know what protection you actually have when a vendor causes the next incident.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like