All vendor management guides

Vendor management Guide

How to Negotiate Liability Caps and Indemnities with Software Vendors

Decide your positions on liability caps, carve-outs and indemnities before the RFP goes out, and make vendors respond to them in writing. Then negotiate the cap amount, the list of exclusions and the indemnity process as one package, trading on the points that matter least to your risk profile. This guide walks through the terms, typical market positions, example wording and a fallback playbook.

Know the four levers you are negotiating

Liability discussions get muddled because people treat "the cap" as a single number. It is really four connected terms:

  1. The general cap. The maximum either party pays for most claims, usually expressed as a multiple of fees.
  2. Carve-outs and super caps. Claims that sit outside the general cap, either uncapped or subject to a separate, higher cap.
  3. The consequential damages exclusion. A waiver of indirect losses such as lost profits, lost data or business interruption. This often removes more real protection than the cap itself.
  4. Indemnities. Promises to defend and pay for specific third-party claims, such as IP infringement.

A generous cap with a broad consequential damages exclusion can leave you with almost nothing recoverable after a data breach. Read all four together before you react to any one of them.

Set your positions in the RFP, not after selection

Your leverage is highest when several vendors are still competing. Once you name a preferred vendor, their legal team knows the business wants to sign.

Include a short contract terms section in the RFP and ask each vendor to accept, reject or propose alternatives line by line. For example:

Please confirm acceptance of the following, or state your proposed alternative: a) General liability cap of the greater of 2x fees paid or payable in the prior 12 months, or [$ amount]. b) Uncapped liability for IP infringement indemnity, gross negligence, willful misconduct and breach of confidentiality. c) Separate cap of [3x] annual fees for data protection and security breaches.

Score the responses. A vendor that rejects everything and offers only its standard paper is telling you how the rest of the relationship will go. Deviations should cost points in the evaluation, the same as a missing feature.

Get the cap level and structure right

Vendor standard terms commonly cap liability at fees paid in the prior 12 months. That is a common starting point, not a rule, and it has problems:

  • Early in the term, fees paid may be close to zero. Use "fees paid or payable" for the relevant period, not just "paid."
  • Low-cost tools can hold high-risk data. A $20,000 a year HR tool with employee records can cause a breach far larger than its fees. Add a fixed dollar floor: "the greater of 12 months' fees or $X."
  • Per-claim vs. aggregate. Vendors prefer an aggregate cap across the whole contract. Push for the cap to reset annually, or at least measure it against the full contract value.

Multiples of 1x to 2x annual fees for the general cap are widely seen in mid-market SaaS deals. Enterprise buyers with real negotiating weight often get more. For the super cap on data and security breaches, 2x to 5x annual fees or a fixed amount tied to the vendor's cyber insurance is a common range.

Ask for the vendor's certificate of insurance. If their cyber policy limit is well below your proposed super cap, you will likely need to meet near the insured amount, and you should know that early.

Negotiate the carve-outs and the consequential damages waiver

Most real protection lives in what sits outside the cap. A reasonable buyer-side list of uncapped items:

  • Indemnification obligations, especially IP infringement
  • Gross negligence, fraud and willful misconduct
  • Breach of confidentiality obligations
  • Your obligation to pay fees (vendors will insist on this one, and it is fair)

Data protection breaches are usually where you land on a super cap rather than unlimited liability. Few vendors accept unlimited data liability, and asking for it can stall the deal.

For the consequential damages exclusion, focus on what losses count as "direct." Specify them so they cannot be argued away as consequential:

The following shall be deemed direct damages recoverable under this Agreement: costs of breach notification, credit monitoring, forensic investigation, regulatory fines to the extent permitted by law, reasonable costs of procuring replacement services, and costs of restoring or recreating lost data.

This clause often does more for you than raising the cap by another multiple.

Make indemnities usable, not decorative

An indemnity only helps if the process works when a claim arrives. Check these points:

IP infringement indemnity

  • Covers the software as delivered and as used according to the documentation.
  • Vendor defends and pays settlements and awarded damages, not just "losses finally awarded."
  • Remedies if the product is enjoined: modify, license or replace, and a pro-rata refund of prepaid fees as a last resort.
  • Exclusions should be narrow: your modifications, combinations the vendor did not specify, or use against the documentation. Reject vague exclusions like "combination with any third-party product" for software that is designed to integrate.

Data breach and third-party claims

  • Vendor indemnifies for third-party and regulatory claims arising from its breach of security or data obligations.
  • Tie this to the super cap so the two sections do not contradict each other.

Process terms

  • Prompt notice, but failure to notify only reduces the obligation to the extent it actually caused prejudice.
  • Vendor controls the defense, but cannot settle in a way that admits fault for you or imposes obligations on you without consent.
  • You can join with your own counsel at your own cost.

Vendors will ask for mutual indemnities, usually for your content or data infringing third-party rights. That is reasonable. Keep your side narrow and matched in scope.

Use a trade playbook with fallback positions

Go in with three positions for each lever: ideal, target and walk-away. Get sign-off on the walk-away from legal and the business owner before talks start, so you are not escalating mid-call.

Example playbook for a SaaS tool processing customer personal data:

TermIdealTargetWalk-away
General cap2x annual fees1.5x with $ floor1x fees paid or payable
Data super cap5x annual fees3x annual feesCyber policy limit
IP indemnityUncappedUncappedUncapped
Direct damages listFull listNotification, forensics, restorationNotification costs

Useful trades when a vendor pushes back:

  • Accept mutual caps in exchange for a higher super cap.
  • Give up the annual reset if they add the direct damages definition.
  • Offer a longer term or a prepayment for better liability terms, if the business wanted that anyway.

Avoid trading away the IP indemnity. It costs a reputable vendor little and protects you from risks you cannot assess yourself.

Pre-signature checklist

  • Cap uses "paid or payable" and includes a dollar floor
  • Carve-outs listed explicitly, with super cap amounts stated
  • Direct damages defined to include breach response costs
  • Consequential damages exclusion does not override carve-outs or indemnities
  • IP indemnity includes defense, settlement, and replace-or-refund remedies
  • Indemnity exclusions are narrow and specific
  • Settlement consent requirement in place
  • Vendor insurance certificate reviewed against the super cap
  • Order form and any DPA do not contain conflicting liability terms
  • Order of precedence clause says which document wins

The last two catch many buyers. A DPA with its own separate cap can quietly override what you negotiated in the main agreement. Have counsel review final terms, especially in regulated industries.

Let pingpong run it for you

pingpong drafts the RFP, finds and invites vendors, collects proposals through a private portal, scores them with five AI models and flags the gotchas above. It drafts every negotiation message for your approval, then keeps watching the market so you renegotiate before renewal. $100 for the first month, then $799 a month.

Common questions

What is a typical liability cap for a SaaS contract?

Vendor standard terms often cap liability at the fees paid in the prior 12 months, and 1x to 2x annual fees is a commonly seen range in negotiated mid-market deals. Data breaches are often handled with a separate, higher super cap. The right number depends on the data involved and the damage an outage or breach could cause, not only the contract value.

Should I insist on unlimited liability for data breaches?

Usually not. Most vendors will refuse, and the request can stall negotiations. You will generally get further by agreeing a super cap sized to the realistic cost of a breach and defining breach response costs as direct damages, so they are actually recoverable.

Is a mutual liability cap fair to the buyer?

Often yes, as long as your obligation to pay fees and the vendor's key obligations sit outside it. Your realistic exposure to the vendor is usually small, so mutuality costs you little and can be a useful concession to trade for a higher super cap or a better direct damages definition.