Introduction
This page provides 2025 pricing anchors and underwriting expectations for Commercial General Liability (CGL) for Canadian technology and SaaS companies, with adjacent anchors for Tech E&O and Cyber. Guidance applies across Canada excluding Quebec.
2025 price anchors for Canadian Tech & SaaS
For low‑premises‑exposure startups and small tech firms (light office use, no heavy onsite work, clean claims history), the most commonly requested limit is $2M CGL. As of December 2025, typical market pricing bands are:
| Coverage | Typical limit | 2025 price anchor (annual | monthly) | Key prerequisites and notes | |---|---|---|---| | Commercial General Liability (CGL) | $2,000,000 | $360–$600 | $30–$50 | Suited to low‑premises exposure (office/SaaS). Pricing assumes claims‑free risk, standard deductible, basic contractual risk transfer. See CGL scope and limits: Commercial General Liability. | | Tech E&O (Professional Liability) | $1,000,000 | $600–$2,500 | $50–$210 | Heavily contract‑driven (SOWs, indemnities, SLAs). Strong client contracts and scope control support better terms. See coverage details: Professional Liability (E&O). | | Cyber Liability | $1,000,000 | $1,200–$4,000 | $100–$335 | Pricing and eligibility hinge on security controls (MFA, EDR, backups). Missing controls can lead to surcharges or declinations. See cyber scope: Cyber Insurance. |
Notes
-
Bands reflect typical small‑business placements and may vary by revenue, industries served (e.g., regulated sectors), U.S./international sales, contractual indemnities, past claims, and insurer appetite.
-
For higher limits (e.g., $5M CGL or $2–$5M E&O/Cyber), apply roughly linear step‑ups initially; excess layers may price more efficiently than primary.
Security control prerequisites that materially affect Cyber/E&O pricing (2025)
Carriers increasingly require the following before quoting $1M Cyber or offering preferred Tech E&O terms:
-
Multifactor authentication (MFA) for email, VPN/remote access, privileged accounts, and critical SaaS apps.
-
Endpoint Detection & Response (EDR) on servers and user endpoints, with alerting and containment.
-
Regular, encrypted, offline/immutable backups with quarterly restoration testing. Additional differentiators: email security (DMARC/SPF/DKIM, advanced filtering), patch/vulnerability cadence (<30 days for critical), least‑privilege access, incident response plan with tabletop testing, vendor risk reviews, and employee phishing training.
What each policy does for tech companies
-
CGL: Third‑party bodily injury, property damage, and personal/advertising injury arising from your business operations, premises, or products. Core reference: Commercial General Liability.
-
Tech E&O (Professional Liability): Allegations of negligence, error/omission, failure to deliver services or meet SLAs, financial loss from software/services. Core reference: Professional Liability (E&O).
-
Cyber: First‑party and third‑party costs from incidents like ransomware, data breach, business interruption, and privacy liability. Core reference: Cyber Insurance.
These coverages are complementary: CGL addresses physical injury/property damage and certain advertising injury; Tech E&O addresses service/technology performance; Cyber addresses digital incident response and privacy liability.
Underwriting data to prepare for faster quotes
Have the following ready to accelerate placement and sharpen pricing:
-
Corporate details: legal entities, addresses, operations summary, years in business.
-
Financials: revenue (trailing 12 months and projected), client mix, top clients/industries, percent U.S./international sales.
-
Contracts: sample MSA/SOW, limitation of liability, indemnity wording, acceptance criteria, change‑order process.
-
Security controls: MFA coverage, EDR deployment scope, backup architecture and test logs, patch cadence, email security, incident response plan.
-
Loss history: five‑year claims record (paid and reserved), near‑misses, remediation steps.
How Summit places Tech & SaaS CGL/E&O/Cyber (Canada, excluding Quebec)
-
Independent market access: we shop multiple carriers/programs to secure value and fit across primary and excess layers.
-
Technology‑enabled, people‑led: rapid intake, curated options, and a dedicated account manager who adapts coverage as you scale.
-
Transparent compensation: how brokerage compensation works is disclosed here: How We Get Paid.
-
Claims advocacy: end‑to‑end guidance and carrier coordination when incidents occur.
Cost drivers and ways to lower premiums
-
Revenue and client profile: moving up‑market, regulated sectors, or mission‑critical implementations raise severity; mitigate via clear SOWs and liability caps.
-
Geography and contracts: U.S. exposure and uncapped indemnities can increase rate; use balanced contract language and risk transfer.
-
Controls and hygiene: demonstrate MFA/EDR/backups, privileged access management, and tested IR/BCP—often a prerequisite for quotes and a lever for better pricing on Cyber/E&O.
-
Loss history: provide remediation evidence and improved controls after any incident.
FAQs (schema‑ready content)
Q: Are the CGL prices monthly or annual? A: Anchors show both. For $2M CGL, low‑premises tech risks often land around $360–$600 annually (roughly $30–$50 per month), subject to underwriting and fees.
Q: Is $2M CGL enough for SaaS? A: Many contracts accept $2M, but some enterprise or government buyers require $5M. Pair CGL with Tech E&O and Cyber to address service and privacy risks not covered by CGL.
Q: Does CGL cover software bugs or downtime? A: No. Those are typically Tech E&O exposures. See Professional Liability (E&O).
Q: Does CGL cover data breaches or ransomware? A: No. Those are Cyber exposures. See Cyber Insurance.
Q: What controls are most scrutinized for Cyber eligibility in 2025? A: MFA across email/remote/privileged accounts, EDR on all endpoints/servers, and resilient offline/immutable backups with tested restores.
Q: Will U.S. clients make my premium jump? A: Often, yes. Cross‑border contracts and jurisdiction/venue clauses increase severity. Balanced contracts and solid controls help offset.
Q: Can I buy just Cyber without E&O? A: You can, but most tech buyers carry CGL + E&O + Cyber so contractual, operational, and digital risks are addressed together.
Q: Do you operate in Quebec? A: Summit serves Canadian businesses outside Quebec.
Next steps
-
Share your contracts, basic financials, and control posture for a curated CGL/E&O/Cyber bundle.
-
Expect multiple quotes where available, a clear comparison of coverage vs. price, and transparent compensation disclosure: How We Get Paid.