FCA authorised · FRN 724952 0117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →

Software support

Professional indemnity insurance for software maintenance and support providers

Yes. If you maintain, fix, patch or support software that clients run their business on, you need professional indemnity insurance. Support claims are rarely about accidents. They follow a fault triaged too slowly, a fix that broke something else, or an old system kept running after it could no longer be secured. Those losses are financial, so public liability will not respond. PI usually covers the client’s claim that your support fell below a competent standard; cyber insurance covers attacks on your own systems.

In short

Support providers are judged on how quickly they respond to faults and whether their fixes, updates and advice are sound. Claims come from priority calls that underestimated a fault, regressions after a patch, old platforms left exposed and diagnostic data mishandled. PI pays defence costs and compensation where negligence is alleged, subject to the policy terms, but usually not service credits. The government’s voluntary Software Security Code of Practice expects software vendors to give at least a year’s notice before support ends. If clients contract on your standard terms, the Unfair Contract Terms Act 1977 limits how far you can reserve a right to cut back the service.

Start your PI proposal →or call 0117 325 0027 to speak to a broker

Why support contracts carry professional risk

Last reviewed 5 October 2026 by the Apex professional indemnity team.

A maintenance and support contract is a promise to keep software working: take calls within agreed times, diagnose faults, ship fixes and updates, apply patches and advise on upgrades. Some providers support products they wrote; others take over bespoke or legacy systems whose original developers have long gone. Either way, the client keeps trading on the strength of your work.

The losses that follow a support failure are financial. Orders cannot ship, payroll runs late, a month-end close stalls or records are corrupted. Public liability (PL) insurance, which covers accidental injury and property damage, does not answer those claims. The allegation is that you did not support the system with the care and skill expected, or that you broke the service schedule, and professional indemnity (PI) is designed for it. Software firms usually buy it as technology errors and omissions cover.

Where support claims come from

These five examples are illustrative only. They show the kind of allegation support providers face, not real cases or outcomes.

  1. A priority set too low. A logistics client reports at 6am that label printing has stopped. Your service desk logs it as medium priority because the application is still running. Dispatch halts for most of the day, and the client claims lost revenue and the penalties its own customers charged, alleging your triage ignored the impact definitions in the service schedule.
  2. A fix that broke the payment file. You release a hotfix for a rounding error in a finance module without regression testing the export to the bank. The next supplier payment run fails, payments go out days late, and the client claims late payment charges and the cost of processing by hand.
  3. A patch in the middle of year-end. Your engineer applies a database update during a change freeze the client had notified for its financial year-end. Tables lock, the close slips, and the client claims extra audit fees and the cost of explaining late figures to its lender.
  4. An old platform with a known flaw. You support a housing provider’s bespoke application on a database version its publisher no longer patches, a risk you mentioned once in a quarterly report. An attacker exploits a published vulnerability, and the client alleges you should have warned clearly, costed an upgrade and isolated the server.
  5. A diagnostic copy kept too long. To reproduce a fault, a client sends a full backup of its customer database. It stays on your support file share for a year, until a compromised account is used to copy it. The client notifies thousands of customers and claims its costs from you.

Each is a complaint about how you delivered a professional service. A policy written for accidents would answer none of them.

What your support is measured against

When a client says your support fell short, the comparison starts with your own service schedule and moves on to what a competent support provider would have done.

Reference pointWhat it saysWhy it matters to you
Your service schedulePriority definitions, response and resolution targets, hours of cover, supported versions and exclusions.Vague definitions leave room for argument about what you promised.
Unfair Contract Terms Act 1977, s.3Where a client deals on your written standard terms, you cannot rely on a term to restrict liability for your own breach, or to justify performing substantially differently from what was reasonably expected, or not at all, unless the term is reasonable.Clauses that let you withdraw support for a version or scale back a service must pass the reasonableness test.
Software Security Code of Practice (UK government, May 2025)A voluntary code for organisations that develop and sell software or software services. Vendors should have a clear process for testing software and updates before distribution, provide timely security updates and notifications, tell customers the level of support provided and give at least a year’s notice before support ends.A ready benchmark for what clients may expect from a vendor that supports its own product.
Cyber Essentials v3.3 (NCSC, April 2026)In-scope software must be licensed and supported, meaning a vendor has committed to regular vulnerability fixes. Unsupported software must be removed or placed in a sub-set that blocks all internet traffic.A legacy system you maintain can affect your client’s certification.
NCSC guidance on obsolete productsThe only fully effective mitigation is to stop using the obsolete product. Until then, isolate it, limit its exposure and monitor it.The yardstick your advice about legacy platforms will be held against.
ISO/IEC/IEEE 14764:2022Guidance on software maintenance, built on the maintenance process in ISO/IEC/IEEE 12207:2017, with definitions of the types of maintenance.A shared reference for scoping what “maintenance” includes in your contract.

Response times are not fix times

A support dispute often begins with a misunderstanding about what the service schedule promised. Three distinctions do most of the work.

Service credits for missed targets work as a price adjustment, and PI usually excludes them. PI is designed for the client’s claim for its actual loss when your handling of a fault was negligent.

When software outlives its support: legacy systems and escrow

Keeping old systems alive is legitimate, valuable work. The risk changes once the platform underneath stops receiving security fixes from its publisher.

Source code escrow protects clients from the opposite problem: losing you. Source code and build instructions are deposited with an independent escrow agent and released to the client if agreed events occur, typically the supplier’s insolvency or a failure to provide support. As the depositor, keep deposits current and complete, and consider independent verification that the deposit can actually be built. PI responds to negligence, such as an honest omission from a deposit, subject to the wording; it is not there for deposits you chose not to make.

What PI covers for support providers, and what it doesn’t

Usually covered by PIOften excluded or limitedNeeds a different policy
Negligent diagnosis, triage and handling of faultsService credits and fee reductions under the service scheduleA cyber attack on your own network or support tools (cyber)
Fixes, patches and updates that cause loss through negligenceThe cost of rewriting your own defective fixInjury or property damage during a site visit (public liability)
Negligent advice about upgrades, end of support and securityObligations you chose not to perform, such as skipped escrow depositsYour own servers and laptops (property or equipment cover)
Loss of client data you hold, sometimes sub-limitedFines and penalties, which wordings commonly excludeInjury to your own employees (employers’ liability)
Defence costs, including independent technical expertsProblems you knew about before the policy beganTheft of client funds by your own staff (crime cover)

Cover is subject to the insurer’s acceptance and the policy terms, including how your professional business is described. If you also host the software you support, declare the hosting too.

Updates you ship and data you hold: PI and cyber together

Two parts of a support operation sit exactly where PI and cyber insurance meet.

Test both policies against the same event: one compromised release reaching many clients. Check that PI does not exclude everything with a cyber cause and that the cyber policy does not exclude your professional services. We can review the two wordings side by side.

How much cover, and for how long

Your limit is usually driven by your largest support contract and the client’s procurement terms. Because one release can reach every client on a product, think about aggregation as well as size: many policies treat claims with a common cause as one claim, and every claim in the policy year draws on the same aggregate limit. Our guide to aggregate and each and every claim limits explains the difference.

Support contracts roll on for years, and so does the exposure. In England and Wales, a claim on a simple contract cannot be brought more than six years after the cause of action accrued. PI is claims-made, so the policy in force when the client claims is the one that pays. Keep cover continuous and arrange run-off if you sell the business or hand a product line to another provider. If you take over support from someone else, tell your insurer and record the state of the system at handover, so inherited faults are not treated as yours.

What insurers will ask you

A complete proposal gets better terms than a bare one, and a broker can only present what you tell us. Have these ready:

Speak to a broker

PI for software maintenance and support providers, placed by a named broker

Start the online proposal and save it as you go, or leave your number and a named broker will call you back, usually the same working day.

Start your PI proposal →or call 0117 325 0027

How Apex places this cover

Apex Insurance Brokers is an independent insurance broker based in Bristol, established in 2009 and authorised and regulated by the Financial Conduct Authority. We are not tied to one insurer: we work with over 30 markets, including Lloyd’s syndicates through wholesale brokers, and every client has a named broker who handles the placement, mid-term changes, certificates for clients and the renewal.

Related guides

Sources

Frequently asked

Do software maintenance and support providers need professional indemnity insurance?

Yes. Clients run their businesses on the software you support, so a slow response, a faulty fix or poor advice about an ageing platform can cause serious financial loss. Public liability won’t cover that. PI pays defence costs and compensation when your support is alleged to have been negligent, subject to the policy terms.

Is PI a legal requirement for software maintenance and support providers?

No law requires it. In practice support contracts, public sector frameworks and larger clients’ supplier checks make PI a condition, usually with a minimum limit, and some ask you to keep it for a period after the contract ends. Read the insurance clause before you sign or renew.

Does PI cover a fix that breaks something else?

Usually, where the client alleges the fix was negligently designed or tested and claims its resulting loss, subject to the policy terms. PI won’t normally pay to rewrite your own faulty code, or refund fees and service credits. Regression testing and a rollback plan for each release are your strongest evidence.

Can our standard terms let us stop supporting an old version?

They can, but if clients contract on your written standard terms, the Unfair Contract Terms Act 1977 says a term letting you perform substantially differently from what was reasonably expected, or not at all, must be reasonable. A published version policy and generous notice help show that it is.

Are we liable if a client keeps running software past its end of support?

Not automatically. The decision is usually the client’s, but if you advise on or run the platform you may be expected to warn clearly and set out options. The NCSC says the only fully effective mitigation is to stop using obsolete products. Put your advice and the client’s decision in writing.

Does source code escrow affect our insurance?

Not directly, but tell your insurer about escrow agreements you sign. PI is built for negligence, so an honest error in a deposit may be covered, subject to the wording. Failing to make deposits you promised is a contract breach PI is unlikely to pay for, so keep deposits current.

Ready to compare cover?

Apex arranges professional indemnity insurance for software maintenance and support providers across the UK. Tell us about your work and we’ll find cover that fits. Or call 0117 325 0027.

Start your PI proposal Call 0117 325 0027

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not advice on your individual circumstances. Cover is always subject to the insurer’s acceptance and the policy terms, and this page does not guarantee that cover will be available or on what terms.