When you sign your first enterprise client, three things trigger obligations at once: a Master Services Agreement (MSA) with new liability and indemnification terms, insurance requirements (usually $1M general liability plus $1M–$5M cyber and professional liability named on a certificate of insurance), and data-security commitments you must actually meet. The enterprise's procurement team will send you a compliance checklist before the deal closes. This guide maps each clause you sign to the specific legal, insurance, and security obligation it creates, with dated sources you can verify yourself.
Last updated: August 2026. Insurance premiums and coverage limits vary by state, revenue, and exposure — verify current rates with a licensed broker before committing.
Methodology: Every obligation below is mapped to a public authority source (contract-management, small-business, or insurance-industry guidance) with a last-verified date. We do not recommend buying any coverage until your MSA specifies the exact limits required.
Disclosure: "Erni" is our own contract-scanning product. Where we reference it below, treat that as a first-party recommendation, not independent third-party endorsement. The scan and decode features described are free at the time of writing; verify current pricing at erni.ai.
TL;DR
- Enterprise buyers require a certificate of insurance (COI) before signing, typically $1M per-occurrence general liability and $1M–$5M cyber/professional liability.
- Your first MSA transfers risk to you through indemnification, limitation-of-liability caps, and data-processing terms most first-timers sign blind.
- Do not sign an MSA — or buy any insurance — until you have read the indemnification clause, the liability cap, and the data-security exhibit, and confirmed the exact coverage limits the contract requires.
- Total monthly cost of this workflow: $0 for the scan and decode (verify current pricing), then insurance premiums that vary by revenue and exposure.
What is an MSA and what does it obligate you to do?
A Master Services Agreement (MSA) is the master contract that governs an ongoing enterprise relationship, and it obligates you to meet specific insurance, liability, data-security, and compliance terms for the life of the engagement. Individual projects then run under short Statements of Work (SOWs) that inherit the MSA's terms.
Definition — First MSA obligations: the set of legal, insurance, and operational duties triggered the moment you sign your first Master Services Agreement with an enterprise buyer. These commonly include naming the client as an additional insured, maintaining minimum coverage limits, indemnifying the client against your errors, meeting a data-breach notification window, and passing a security review.
Here is what most 2–20 person shops miss: the MSA is not a formality you sign to start billing. It is a risk-transfer document. According to World Commerce & Contracting (formerly IACCM, guidance current as of 2024), poor contract management costs companies an average of roughly 9% of annual revenue, and small vendors carry the most one-sided terms because they have the least leverage. The U.S. Small Business Administration (reviewed 2024) notes that many client contracts contractually require specific liability coverage before work begins — meaning your ability to close the deal depends on your policy, not just your pitch.
What do I need to do when I get my first enterprise client?
Run your signed or draft MSA through a five-step workflow: scan the contract for obligations, decode your current coverage against those obligations, close the insurance gap, meet the security requirements, and produce the certificate of insurance the procurement team requires.
Before you touch any tool, complete this checkpoint:
Do not sign an MSA until you have:
- Read the indemnification clause and identified who pays for what if a claim arises.
- Located the limitation-of-liability cap and confirmed it is mutual (or negotiated it toward mutual).
- Found the data-processing or security exhibit and listed every requirement it names.
- Confirmed the exact insurance limits and endorsements required (e.g., "additional insured," "waiver of subrogation").
- Priced those limits with a licensed broker so you know the cost before you commit.
Only after that checkpoint should you evaluate tooling. The National Federation of Independent Business (small-business guidance, 2024) and state insurance regulators such as those listed by the National Association of Insurance Commissioners (consumer resources, updated 2024) can help you confirm whether a policy actually satisfies the contract's language before you certify it.
The five-step workflow
- Scan the contract. Identify every insurance, liability, and data-security clause. A free first pass can flag these obligations so nothing is missed.
- Decode your current coverage. Compare your existing general liability, cyber, and professional liability policies against the limits and endorsements the MSA demands.
- Close the insurance gap. Work with a licensed broker to add limits or endorsements only where the contract requires them. Do not over-buy.
- Meet the security requirements. Implement the breach-notification window, access controls, and any review the exhibit specifies.
- Produce the certificate of insurance (COI). Have your broker issue a COI naming the client as required, and deliver it to procurement before signing.
Free tools can handle the first two steps: our Erni Contract Requirement Scanner flags insurance and security clauses, and our Policy Decoder checks whether your current coverage satisfies them. (First-party product; see disclosure above. Verify current pricing before relying on it.)
Prices and coverage figures cited in this article were verified in August 2024 and change frequently. Confirm current rates with a licensed insurance broker and current tool pricing at the vendor's site before committing.
{
"@context": "https://schema.org",
"@graph": [
{
"@type": "Article",
"headline": "First Enterprise Client: What Changes for You",
"description": "How signing your first enterprise client triggers MSA, insurance, and data-security obligations — and a five-step workflow to meet them.",
"datePublished": "2024-08-01",
"dateModified": "2024-08-01",
"author": {
"@type": "Organization",
"name": "Erni"
},
"publisher": {
"@type": "Organization",
"name": "Erni",
"url": "https://erni.ai"
},
"citation": [
"https://www.worldcc.com/",
"https://www.sba.gov/business-guide/launch-your-business/get-business-insurance",
"https://www.nfib.com/",
"https://content.naic.org/consumer.htm"
]
},
{
"@type": "BreadcrumbList",
"itemListElement": [
{
"@type": "ListItem",
"position": 1,
"name": "Home",
"item": "https://erni.ai"
},
{
"@type": "ListItem",
"position": 2,
"name": "Guides",
"item": "https://erni.ai/guides"
},
{
"@type": "ListItem",
"position": 3,
"name": "First Enterprise Client: What Changes for You",
"item": "https://erni.ai/guides/first-enterprise-client-what-changes"
}
]
}
]
}