window.dataLayer = window.dataLayer || [];function gtag(){dataLayer.push(arguments);}gtag('js', new Date());gtag('config', 'G-FQXKQJYQM1');
Schneiderman Insurance Agency
Schneiderman Insurance Agency

Technology Insurance and Tech E&O

Technology Insurance and Tech E&O2026-09-19T21:54:03-07:00
Technology Insurance and Tech E&O

What is Technology Insurance and Tech E&O?

Technology companies carry a mix of risks that standard business policies were not built for. Examples are a software bug or a missed deadline that costs a client money, a data breach, or a claim over the content on your platform.

Technology errors and omissions (tech E&O) is designed for exactly this, and for tech, software, SaaS, and IT-services firms it is usually the core policy. At its center is professional liability, which responds when a client alleges the technology product or service you delivered failed, was late, or caused them financial harm.

Modern tech E&O forms combine that with cyber, and often media liability, in a single policy, because technology companies face all three at once.

What it covers.

Technology E&O (professional liability): claims that your software, product, or service failed to perform, contained an error, or caused a client a financial loss. This includes the cost of defending those claims even when the allegation is groundless. General liability specifically excludes your professional services, so this is the coverage that fills that gap. - Cyber: first-party and third-party cyber coverage (breach response, ransomware and extortion, business interruption, funds-transfer fraud, and privacy and network-security liability). See the Cyber Liability page for the full picture. - Media and multimedia liability: content-based claims such as defamation, infringement, or invasion of privacy arising from your website, platform, or the content you host or publish. A general liability policy’s advertising-injury coverage largely leaves these out. See the Media Liability page.

Who needs it.

Software developers and SaaS companies, IT consultants and managed service providers, web and app developers, data hosting and analytics firms, hardware and device makers, and technology startups. Clients and investors increasingly require it by contract, and a certificate of tech E&O is often a condition of signing.

California context.

California is a national technology hub, and contracts here frequently require tech E&O at specified limits before work begins. Coverage is usually written on a claims-made basis, so the retroactive date and continuity of coverage matter; we help you avoid gaps when you change policies.

How we help.

We look at what your company actually builds and delivers, and help you set limits and a retroactive date that fit your contracts and exposure. We coordinate the E&O, cyber, and media pieces so they do not leave gaps between them, issue the certificates your clients ask for, and advocate for you at claim time. Coverage is governed by the policy form.

FAQ

Is tech E&O the same as cyber insurance?

Not quite. Cyber covers data and security events; tech E&O adds professional liability for the technology you deliver. Modern tech E&O policies usually combine both, plus media liability.

Do I need tech E&O if I already have general liability?

Usually yes. General liability excludes your professional services, which is the main risk a technology company faces.

My clients are asking for a certificate before we start. Can you help?

Yes. We can quote the coverage and issue the certificate once it is bound. Some placements are quick and others need underwriting review, and we tell you which applies before you commit

A coding error and a data breach are separate triggers needing separate wording, a split now relevant to many of the fields we work with.

Technology company insurance in California, explained

Does California require a software or IT company to carry insurance?

One policy, and only once the company has an employee. Labor Code section 3700 requires every employer except the state to secure workers' compensation, through an insurer authorized in California or a certificate of consent to self-insure. No state license or bond is required to write software, run a SaaS platform or provide IT consulting, so no licensing body imposes an insurance condition. Every other policy a technology firm buys is driven by client contracts, investor terms or its own balance sheet. "Technology insurance" is not a policy form; it is a set of separately underwritten policies that this section takes one at a time.

Why does a general liability policy not respond to a software failure or a data breach?

Because the form is written for bodily injury, property damage and a short list of personal and advertising injury offenses. The standard ISO general liability form states that electronic data is not tangible property and excludes damages arising out of the loss of, corruption of or inability to access it. It excludes damage to impaired property caused by a defect in your product or work or by a failure to perform a contract, and it excludes the cost of recalling or replacing your product. It also excludes infringement of copyright, patent, trademark or trade secret except in your own advertisement, and it excludes insureds whose business is designing websites for others. Each of those gaps is why a technology firm buys the two policies below alongside its general liability.

What does technology errors and omissions insurance do for a SaaS or IT firm?

It is built for the claim a general liability policy cannot reach: a client says your software, platform, code or IT service failed to perform as promised and the client lost money. The trigger is a negligent act, error or omission in the technology product or service, with no bodily injury or property damage required. Most forms are claims-made, so the retroactive date and continuous renewal matter. California public-entity contracts commonly require the retroactive date to precede the contract, with coverage or an extended reporting period running for several years after the work ends. One county's standard IT exhibit asks for $2,000,000 limits and a five-year tail. Many technology E&O forms are combined with cyber and media liability, and the client's contract usually lists which elements it expects on the certificate.

What does a cyber policy do, and what does California law require after a breach?

Civil Code section 1798.82 requires a business that owns or licenses computerized personal information to notify affected Californians within 30 calendar days of discovering a breach. That deadline has been in force since 1 January 2026 under SB 446. If more than 500 residents are notified, a sample notice goes to the Attorney General within 15 calendar days and the breach is published on the Attorney General's list. If Social Security, driver's license or state ID numbers were exposed, the business must offer identity theft services at no cost for at least 12 months. A business that maintains data it does not own must notify the owner immediately. A cyber liability policy is built to fund that response, including forensics, legal drafting, the notification mailing and the services offer, and its third-party side responds to privacy claims and regulatory proceedings.

Does the CCPA apply to my start-up, and what changes if I am a service provider?

The California Consumer Privacy Act applies to a for-profit business that meets one of three tests. The first is annual gross revenue above the adjusted threshold, currently $26,625,000. The second is buying, selling or sharing the personal information of 100,000 or more consumers or households a year. The third is deriving half or more of revenue from selling or sharing personal information. Most early-stage firms fall below those tests but process customer data for a business that does not. In that role the firm is a service provider or contractor under Civil Code section 1798.140 and must sign a written contract. That contract bars selling or sharing the data and restricts its use to the specified purpose. Separately, section 1798.81.5 requires reasonable security for personal information regardless of size. Section 1798.150 gives consumers a private action after a breach caused by a failure of that duty, with statutory damages that adjust every two years. The threshold and damages figures next adjust in January 2027.

My cloud host or payment processor went down. Is my lost revenue insured?

Not by the provider's insurance, and not by a standard property or general liability policy. The provider's remedy is written into its service agreement and is usually a service credit. Your own cyber policy may include dependent business interruption, which is built to pay your income loss when a defined third-party provider's network is interrupted. Three prerequisites decide whether it responds. The provider must fall inside the policy's definition of a dependent system, the cause must be a covered event, and the outage must exceed the waiting period on the declarations page. Read the definition, the cause list and the waiting period before assuming the platform you depend on is inside them.

I pay 1099 developers. Does that change my workers' compensation picture?

Usually. Under Labor Code section 2775 a worker is presumed an employee unless the hiring entity proves freedom from control, work outside its usual course of business, and an independently established trade. A software firm hiring a developer to write software will usually fail the second test. The business-to-business exemption in section 2776 can return the analysis to the older multi-factor test. It applies only to a sole proprietor or entity working under a written contract that meets the section's listed criteria, including a separate business location and the ability to work for others. If the developer is an employee for compensation purposes, section 3700 makes the firm responsible for the policy. Software developers are usually rated under WCIRB class 8859, which includes the firm's clerical and outside sales staff; IT staff who install or repair hardware at client sites carry a separate class.

What employment and management exposures does a small start-up carry?

California's harassment law reaches any employer with one or more employees, and its discrimination provisions reach five or more, under Government Code section 12940 and section 12926. At five employees the firm must also provide harassment training under section 12950.1. Employment practices liability is the policy built for the wrongful termination, harassment and discrimination claims those sections create. A workplace violence prevention plan under Labor Code section 6401.9 has been required since 1 July 2024. A workplace with fewer than 10 employees that is not open to the public is exempt, and so are teleworkers at locations the employer does not control. Once outside investors sit on the board, directors and officers liability is built for claims against the people running the company, and a hardware start-up adds products liability and property coverage for inventory.

How do you get a technology company quote from us?

Start a business insurance quote and tell us what you build or manage, your revenue, and your headcount and contractor count. Add the personal data you hold or process, the providers you depend on, and the insurance exhibit from any client or investor agreement. Some technology firms we can write directly and quickly. Others go to underwriting for approval, or need a wholesale market, and those take longer. Either way you know before you decide.

Statutory figures current as of September 2026 and specific to California; the CCPA revenue threshold and statutory damages adjust in January 2027. Form descriptions refer to standard ISO wording; no form text is reproduced.

Do I need tech E&O if I already have general liability?2026-08-10T13:42:49-07:00

Usually yes. General liability excludes your professional services, which is the main risk a technology company faces.

My clients are asking for a certificate before we start. Can you help?2026-09-07T16:12:48-07:00

Yes. We can quote the coverage and issue the certificate once it is bound. Some placements are quick and others need underwriting review, and we tell you which applies before you commit.

Is tech E&O the same as cyber insurance?2026-08-10T13:42:51-07:00

Not quite. Cyber covers data and security events; tech E&O adds professional liability for the technology you deliver. Modern tech E&O policies usually combine both, plus media liability.