Software support
Yes. If you maintain, fix, patch or support software that clients run their business on, you need professional indemnity insurance. Support claims are rarely about accidents. They follow a fault triaged too slowly, a fix that broke something else, or an old system kept running after it could no longer be secured. Those losses are financial, so public liability will not respond. PI usually covers the client’s claim that your support fell below a competent standard; cyber insurance covers attacks on your own systems.
Part of: Professional indemnity for IT professionals
In short
Support providers are judged on how quickly they respond to faults and whether their fixes, updates and advice are sound. Claims come from priority calls that underestimated a fault, regressions after a patch, old platforms left exposed and diagnostic data mishandled. PI pays defence costs and compensation where negligence is alleged, subject to the policy terms, but usually not service credits. The government’s voluntary Software Security Code of Practice expects software vendors to give at least a year’s notice before support ends. If clients contract on your standard terms, the Unfair Contract Terms Act 1977 limits how far you can reserve a right to cut back the service.
Last reviewed 5 October 2026 by the Apex professional indemnity team.
A maintenance and support contract is a promise to keep software working: take calls within agreed times, diagnose faults, ship fixes and updates, apply patches and advise on upgrades. Some providers support products they wrote; others take over bespoke or legacy systems whose original developers have long gone. Either way, the client keeps trading on the strength of your work.
The losses that follow a support failure are financial. Orders cannot ship, payroll runs late, a month-end close stalls or records are corrupted. Public liability (PL) insurance, which covers accidental injury and property damage, does not answer those claims. The allegation is that you did not support the system with the care and skill expected, or that you broke the service schedule, and professional indemnity (PI) is designed for it. Software firms usually buy it as technology errors and omissions cover.
These five examples are illustrative only. They show the kind of allegation support providers face, not real cases or outcomes.
Each is a complaint about how you delivered a professional service. A policy written for accidents would answer none of them.
When a client says your support fell short, the comparison starts with your own service schedule and moves on to what a competent support provider would have done.
| Reference point | What it says | Why it matters to you |
|---|---|---|
| Your service schedule | Priority definitions, response and resolution targets, hours of cover, supported versions and exclusions. | Vague definitions leave room for argument about what you promised. |
| Unfair Contract Terms Act 1977, s.3 | Where a client deals on your written standard terms, you cannot rely on a term to restrict liability for your own breach, or to justify performing substantially differently from what was reasonably expected, or not at all, unless the term is reasonable. | Clauses that let you withdraw support for a version or scale back a service must pass the reasonableness test. |
| Software Security Code of Practice (UK government, May 2025) | A voluntary code for organisations that develop and sell software or software services. Vendors should have a clear process for testing software and updates before distribution, provide timely security updates and notifications, tell customers the level of support provided and give at least a year’s notice before support ends. | A ready benchmark for what clients may expect from a vendor that supports its own product. |
| Cyber Essentials v3.3 (NCSC, April 2026) | In-scope software must be licensed and supported, meaning a vendor has committed to regular vulnerability fixes. Unsupported software must be removed or placed in a sub-set that blocks all internet traffic. | A legacy system you maintain can affect your client’s certification. |
| NCSC guidance on obsolete products | The only fully effective mitigation is to stop using the obsolete product. Until then, isolate it, limit its exposure and monitor it. | The yardstick your advice about legacy platforms will be held against. |
| ISO/IEC/IEEE 14764:2022 | Guidance on software maintenance, built on the maintenance process in ISO/IEC/IEEE 12207:2017, with definitions of the types of maintenance. | A shared reference for scoping what “maintenance” includes in your contract. |
A support dispute often begins with a misunderstanding about what the service schedule promised. Three distinctions do most of the work.
Service credits for missed targets work as a price adjustment, and PI usually excludes them. PI is designed for the client’s claim for its actual loss when your handling of a fault was negligent.
Keeping old systems alive is legitimate, valuable work. The risk changes once the platform underneath stops receiving security fixes from its publisher.
Source code escrow protects clients from the opposite problem: losing you. Source code and build instructions are deposited with an independent escrow agent and released to the client if agreed events occur, typically the supplier’s insolvency or a failure to provide support. As the depositor, keep deposits current and complete, and consider independent verification that the deposit can actually be built. PI responds to negligence, such as an honest omission from a deposit, subject to the wording; it is not there for deposits you chose not to make.
| Usually covered by PI | Often excluded or limited | Needs a different policy |
|---|---|---|
| Negligent diagnosis, triage and handling of faults | Service credits and fee reductions under the service schedule | A cyber attack on your own network or support tools (cyber) |
| Fixes, patches and updates that cause loss through negligence | The cost of rewriting your own defective fix | Injury or property damage during a site visit (public liability) |
| Negligent advice about upgrades, end of support and security | Obligations you chose not to perform, such as skipped escrow deposits | Your own servers and laptops (property or equipment cover) |
| Loss of client data you hold, sometimes sub-limited | Fines and penalties, which wordings commonly exclude | Injury to your own employees (employers’ liability) |
| Defence costs, including independent technical experts | Problems you knew about before the policy began | Theft of client funds by your own staff (crime cover) |
Cover is subject to the insurer’s acceptance and the policy terms, including how your professional business is described. If you also host the software you support, declare the hosting too.
Two parts of a support operation sit exactly where PI and cyber insurance meet.
Test both policies against the same event: one compromised release reaching many clients. Check that PI does not exclude everything with a cyber cause and that the cyber policy does not exclude your professional services. We can review the two wordings side by side.
Your limit is usually driven by your largest support contract and the client’s procurement terms. Because one release can reach every client on a product, think about aggregation as well as size: many policies treat claims with a common cause as one claim, and every claim in the policy year draws on the same aggregate limit. Our guide to aggregate and each and every claim limits explains the difference.
Support contracts roll on for years, and so does the exposure. In England and Wales, a claim on a simple contract cannot be brought more than six years after the cause of action accrued. PI is claims-made, so the policy in force when the client claims is the one that pays. Keep cover continuous and arrange run-off if you sell the business or hand a product line to another provider. If you take over support from someone else, tell your insurer and record the state of the system at handover, so inherited faults are not treated as yours.
A complete proposal gets better terms than a bare one, and a broker can only present what you tell us. Have these ready:
Speak to a broker
PI for software maintenance and support providers, placed by a named broker
Start the online proposal and save it as you go, or leave your number and a named broker will call you back, usually the same working day.
Apex Insurance Brokers is an independent insurance broker based in Bristol, established in 2009 and authorised and regulated by the Financial Conduct Authority. We are not tied to one insurer: we work with over 30 markets, including Lloyd’s syndicates through wholesale brokers, and every client has a named broker who handles the placement, mid-term changes, certificates for clients and the renewal.
Yes. Clients run their businesses on the software you support, so a slow response, a faulty fix or poor advice about an ageing platform can cause serious financial loss. Public liability won’t cover that. PI pays defence costs and compensation when your support is alleged to have been negligent, subject to the policy terms.
No law requires it. In practice support contracts, public sector frameworks and larger clients’ supplier checks make PI a condition, usually with a minimum limit, and some ask you to keep it for a period after the contract ends. Read the insurance clause before you sign or renew.
Usually, where the client alleges the fix was negligently designed or tested and claims its resulting loss, subject to the policy terms. PI won’t normally pay to rewrite your own faulty code, or refund fees and service credits. Regression testing and a rollback plan for each release are your strongest evidence.
They can, but if clients contract on your written standard terms, the Unfair Contract Terms Act 1977 says a term letting you perform substantially differently from what was reasonably expected, or not at all, must be reasonable. A published version policy and generous notice help show that it is.
Not automatically. The decision is usually the client’s, but if you advise on or run the platform you may be expected to warn clearly and set out options. The NCSC says the only fully effective mitigation is to stop using obsolete products. Put your advice and the client’s decision in writing.
Not directly, but tell your insurer about escrow agreements you sign. PI is built for negligence, so an honest error in a deposit may be covered, subject to the wording. Failing to make deposits you promised is a contract breach PI is unlikely to pay for, so keep deposits current.
Apex arranges professional indemnity insurance for software maintenance and support providers across the UK. Tell us about your work and we’ll find cover that fits. Or call 0117 325 0027.
Start your PI proposal Call 0117 325 0027Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not advice on your individual circumstances. Cover is always subject to the insurer’s acceptance and the policy terms, and this page does not guarantee that cover will be available or on what terms.