Pipeline Velocity, Stage Progression & Enterprise Deal ClosingPlaybook3 min readUpdated September 2026

Negotiating Indemnification Caps Without Losing the Deal

An indemnification clause decides who pays if something goes wrong, a data breach, an IP infringement claim, a third-party lawsuit tied to your product. Enterprise buyers routinely ask for that liability to be uncapped, and agreeing without limits means a single bad incident on one contract could theoretically cost you more than the entire relationship is worth.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

What indemnification actually covers, and why enterprise buyers push on it

Indemnification obligates one party to cover the other's losses, including legal defense costs, arising from specific triggering events, most commonly IP infringement claims, breaches of confidentiality or data protection obligations, and gross negligence or willful misconduct. Enterprise legal teams push hard on this because they're managing risk across dozens or hundreds of vendor relationships, and an uncapped clause is simply the safest position for them to start from, regardless of how likely any actual claim is against your specific product.

The standard structure: a cap tied to fees paid, with named carve-outs

Most vendor-favorable, still-reasonable contracts cap general indemnification liability at a multiple of fees paid under the agreement, commonly somewhere between one and three times the annual contract value. That cap then gets carved out, meaning removed or raised, for specific categories the buyer considers non-negotiable: IP infringement claims, breaches of confidentiality, and sometimes data security incidents get their own, typically higher, cap or no cap at all.

This layered structure, a general cap with named exceptions, is the version most enterprise legal teams will actually accept, because it acknowledges their real risk categories without exposing you to unlimited liability across every possible claim.

Which carve-outs are reasonable, and which are exposure you can't afford

IP infringement is a standard, defensible carve-out, since a buyer reasonably doesn't want to be dragged into a lawsuit over your product's underlying technology. A confidentiality or data breach carve-out is increasingly standard too, particularly if you handle sensitive customer data, and it's worth pricing that risk into your insurance rather than fighting it outright.

What's not reasonable is an uncapped carve-out for ordinary breach of contract or general negligence, categories broad enough that almost any dispute could get characterized to fall under them, effectively making your entire liability uncapped through the back door. Read every carve-out for how broadly it's defined, not just what category it's labeled.

Checking your insurance before you agree to anything

Never agree to a liability cap, or the removal of one, without confirming what your actual insurance coverage looks like against it. A data breach carve-out that exceeds your cyber liability coverage limit means you're personally exposed to the gap, not your insurer, regardless of what looked reasonable on paper during the negotiation. Loop in whoever manages your insurance policies before finalizing any indemnification language on a deal large enough to matter, not after the contract is already signed.

Before you agree to any cap or carve-out, confirm each of these:

  • Your cyber liability and other insurance limits, so a data breach carve-out never exceeds what your policy would actually pay.
  • Whoever manages your insurance policy has reviewed the proposed cap and carve-outs and agrees the gap is acceptable.
  • Deal desk or finance has set the cap threshold in advance, so legal is not making a business risk decision during a redline.
  • The general cap is expressed as a multiple of fees paid, with each carve-out named and limited to a specific category.
  • The signed language matches what was agreed, checked by legal against a pre-signature checklist before anyone signs.

How to counter an uncapped request without killing the deal

Most procurement teams asking for uncapped liability will accept a well-reasoned layered structure once you explain it, rather than actually needing an unlimited number for its own sake. Come back with the standard cap-plus-carve-outs structure and a clear explanation of why it addresses their real concerns: a full remedy for the categories that matter most, IP and confidentiality, with a sensible ceiling everywhere else. Framing the counter as risk-appropriate rather than as a negotiating tactic tends to land better with a legal team that's mostly following a template anyway.

Getting the final language locked down

Once the cap and carve-outs are agreed, make sure the signed document actually reflects them precisely, since indemnification language is dense and easy to misread during a fast final redline. Run the contract through a pre-signature checklist, something like Process Street, with legal confirming the cap and carve-out language specifically, and route the final version through an e-signature platform like Foxit eSign so there's a clean record of exactly what both sides agreed to.

Keep a running internal reference of every deviation from your standard indemnification template, and why it was approved, so the next negotiation on a similar deal starts from precedent instead of re-litigating the same tradeoffs from scratch. Legal teams turn over, and an unwritten rationale for a past exception tends to disappear along with whoever originally approved it.

Executive Capability Standard

What Good Looks Like

Every enterprise contract's indemnification clause uses a general liability cap tied to fees paid, with named carve-outs limited to specific, well-defined risk categories, checked against actual insurance coverage before anyone signs.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Pull your current contract template's indemnification language and confirm whether it has a cap, and if so, what it's tied to.
2. Do Manually:Have legal manually review any indemnification redline against your standard cap-plus-carve-outs position before it goes back to the customer.
3. Delegate:Give deal desk ownership of setting indemnification risk tolerance and cap thresholds that legal negotiates against.
4. Automate:Build a standard indemnification clause with the layered cap structure into your contract template, so reps and legal start from the defensible version by default.
5. Buy:Bring in outside counsel with enterprise SaaS experience to review your indemnification position against current insurance coverage if you haven't done that review recently.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

What's a typical indemnification cap multiple for a mid-market SaaS deal?

Somewhere between one and three times the annual contract value is common for general liability, though the right number depends on your risk exposure and deal size. There's no universal figure; treat it as a starting position for negotiation rather than a fixed rule, and be ready to explain the reasoning behind whatever number you propose.

Should we ever accept a fully uncapped indemnification clause?

Rarely, and only after confirming your insurance coverage can genuinely absorb the risk category involved. An uncapped clause with no insurance backing it is a real, open-ended financial exposure, not just an aggressive negotiating position, and it deserves a direct conversation with whoever manages your risk before agreeing.

Who should own this negotiation, sales or legal?

Legal should draft and negotiate the actual language, but deal desk or finance should set the risk tolerance and cap thresholds beforehand, so legal isn't making a business risk decision on the fly during a redline. Sales should stay informed enough to know when a request has moved outside standard limits.

Does the indemnification cap need to match our insurance policy limits exactly?

Not exactly, but it shouldn't wildly exceed what your policy actually covers, since the gap between the two is money you'd pay out of pocket if a claim actually happened. Review the alignment periodically, since either your contract terms or your insurance coverage can change independently over time.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides