When to negotiate MSA clauses vs let them through
Not every clause in a master services agreement is worth negotiating. A framework for deciding which MSA clauses matter, which don't, and how to move fast on the rest.
An MSA from a typical enterprise SaaS vendor runs 15-25 pages. Counting the order form, SLA, DPA, and security addendum, a full deal package can easily exceed 80 pages. A team that tries to negotiate every clause in that package will still be in redlines three months later. A team that negotiates none of them will sign something that costs them real money or real flexibility.
The question that actually matters in MSA negotiation isn't how to negotiate a given clause, that's the easy part once you know what to ask for. The harder question is which clauses to negotiate at all. Most MSAs have a small number of clauses that genuinely matter and a large number that don't, and teams that don't distinguish between them waste cycles on cosmetic language while missing the handful of terms that will actually show up in a dispute.
This is a framework for deciding, clause by clause, whether to negotiate or let it through.
The first filter: does this clause ever matter?
Every MSA clause falls into one of three categories:
- Clauses that matter in normal operations. These come up month to month, year to year. Pricing, payment terms, notice windows, auto-renewal, SLA credits.
- Clauses that matter only in disputes. These never come up unless something goes badly wrong. Liability caps, indemnification, governing law, limitation of damages, termination for cause.
- Clauses that rarely matter. Warranty disclaimers, force majeure, order of precedence, notices, interpretation.
The temptation is to spend the most time on the clauses that come up most often (category 1) and the least time on the clauses that rarely come up (category 3). That's half right. The clauses in category 2 deserve disproportionate attention, they're the ones with tail-risk magnitude even if they never fire.
An MSA negotiation that gets the pricing and notice window right but accepts a $50K liability cap on a deal that touches 100,000 end-user records has optimized the wrong thing.
The cost-of-negotiation filter
Every redline has a cost. It delays close, consumes legal hours on both sides, can damage the relationship, and can cause the vendor to quietly reprice the deal to compensate for concessions. The second filter is whether the expected value of a given redline exceeds its cost.
A rough heuristic:
- If the clause is market-standard and the vendor rarely concedes (governing law to vendor's state, consequential damages mutual waiver), the expected value of redlining is low. Accept.
- If the clause is market-standard and the vendor often concedes on mid-market deals (renewal pricing cap, SLA termination rights, liability super-cap for data breach), the expected value is high. Negotiate.
- If the clause is non-standard and aggressive (perpetual license to customer data, uncapped indemnification by buyer, unilateral price adjustment mid-term), expected value is very high. Negotiate hard or walk.
The nuance is in the middle category. Experienced MSA negotiation teams know which clauses vendors have pre-approved concessions on and which require escalation. A redline that can be cleared by the AE ships in days; a redline that requires the vendor's GC ships in weeks. Picking the battles the vendor's sales team can win without escalating keeps the deal moving.
Clauses that usually justify negotiation
These are the clauses where the expected value of a redline is high enough that most mid-market and enterprise deals negotiate them as a matter of course.
Liability cap, especially the super-cap
The most important clause in most MSAs. A 12-month-fees cap looks innocuous until you think about what a data breach, IP infringement lawsuit, or willful misconduct claim would actually cost. The redline to add is a super-cap for specific scenarios (data breach, IP indemnification, confidentiality breach, willful misconduct) with either a multiple of fees or a dollar floor, whichever is higher.
A worked example: on a $120K ARR deal, the default cap is $120K. A super-cap adding "greater of 5x annual fees or $2.5M for data breach and IP indemnification" produces meaningful protection in the scenarios that actually generate large losses.
Renewal pricing
Auto-renewal at "then-current rates" is a unilateral price-adjustment right dressed up as an operational convenience. Cap it. A 5-7% annual cap is close to market-standard on mid-market deals and typically lands in the first redline cycle.
Termination rights
Two specific negotiations matter here. First, symmetric termination for convenience, either both parties have it or neither does; asymmetric language is a red flag. Second, a termination right for persistent SLA failure, credits alone are rarely meaningful as a remedy for chronic downtime.
Data processing and security
If the agreement involves personal data, the DPA and security addendum are where regulatory and operational risk actually lives. Worth detailed review on every deal. Vendor-side resistance tends to focus on subprocessor notification (consent vs. notice), audit rights (frequency and scope), and breach notification windows (24 vs. 72 hours).
Indemnification scope
The scope of vendor IP indemnification is one of the most-negotiated MSA clauses. Vendor paper typically narrows indemnification to "direct infringement by the Services as provided by Vendor," excluding combinations, customizations, and open-source components. Pushing back on at least the combination exclusion is close to universal.
Clauses where negotiation usually isn't worth it
The counterpart: clauses where the expected value of redlining is low enough that most teams let them through.
Governing law and venue
Vendors strongly prefer their home jurisdiction. Fighting this delays the deal without producing meaningful value unless there's a specific compliance driver (e.g., a EU buyer needing EU law). A neutral compromise (Delaware, New York) sometimes lands, but most mid-market deals accept the vendor's default.
Force majeure
Almost always mutual, almost always covers the expected events (natural disaster, government action, network failure beyond the party's control). The language varies in granularity but rarely in substance. Read it to make sure pandemics and cyberattacks are handled the way you expect; otherwise let it through.
Notices
Specific mailing addresses and methods for formal notices. Worth reading to make sure non-renewal notice doesn't require certified mail to a legal department you've never heard of, but the structural language rarely matters. Confirm the delivery method for your non-renewal notice is practical (email sometimes counts, sometimes doesn't) and move on.
Severability, interpretation, entire agreement
Boilerplate. Read once to make sure there's nothing unusual, then stop negotiating.
Consequential damages waiver (mutual)
Almost every MSA has a mutual waiver of consequential, indirect, and punitive damages. Carve-outs for indemnification obligations, confidentiality breach, and data breach are worth negotiating for; the mutual waiver itself is close to universal and rarely dislodgeable.
The clauses that depend on the deal
Some clauses are worth negotiating on some deals and not others. The deciding factors are deal size, regulatory posture, and the specific business context.
Most-favored-customer language
Worth asking for on large deals where the pricing dynamics with peer customers matter. Usually struck on small deals because vendors refuse to couple pricing across their customer base. On a sub-$500K ARR deal, usually not worth the fight. On a seven-figure enterprise deal, sometimes negotiable in a narrowed form.
Audit rights
Regulated buyers (financial services, healthcare, public sector) need meaningful audit rights to satisfy their own compliance program. Unregulated buyers often don't need them and can let the vendor's standard SOC 2 attestation substitute.
Insurance requirements
Matters more for deals where the vendor operates in your environment, handles sensitive data, or integrates deeply into your stack. Matters less for arm's-length SaaS where the vendor's service is entirely remote and the data scope is limited.
Publicity and logo rights
Regulated buyers and buyers under investor confidentiality often strike these entirely. Non-regulated buyers sometimes accept in exchange for a pricing concession (vendor may use logo after six months of production use, or in exchange for a case study).
Sequencing: negotiate in the right order
Even within the clauses worth negotiating, order matters. Negotiating high-impact clauses first preserves leverage; negotiating cosmetic clauses first wastes it.
A rough sequence that works on most mid-market deals:
- Commercial terms first. Price, payment terms, renewal cap, term length. Get the deal shape right before the legal redlines start.
- Economic risk clauses second. Liability cap, indemnification, super-cap for data breach. These determine the real cost of a bad outcome.
- Operational clauses third. SLA terms, termination rights, notice windows, support commitments. These determine what the relationship looks like month to month.
- Data and security fourth. DPA, security addendum, subprocessor consent, breach notification. Often runs in parallel with the legal redlines but tends to have its own reviewers on both sides.
- Everything else last. Publicity, assignment, notices, interpretation. Should be cleared in a single pass at the end.
The common mistake is starting with the legal redlines before the commercial shape is settled. When pricing and term length are still moving, every other clause is negotiating against a target that isn't stable yet.
How many cycles should this take
A rule of thumb: a well-run mid-market MSA negotiation should close in two to three redline cycles. Cycle one is the buyer's markup against the vendor's template. Cycle two is the vendor's response plus any newly-introduced redlines. Cycle three (sometimes) is the final cleanup.
Negotiations that take five or more cycles usually indicate one of three problems: the parties disagree fundamentally on a commercial issue that nobody has surfaced cleanly, the legal teams are negotiating boilerplate that nobody empowered them to concede on, or the buyer hasn't decided what matters and keeps re-opening clauses that were closed. All three are fixable, but only if someone notices.
A useful forcing function: after the first redline cycle, both sides should know the three or four clauses that are actually still in dispute. If the list is longer than that, the negotiation hasn't converged yet.
The bottom line
MSA negotiation is a selection problem more than a drafting problem. The clauses in a given MSA that genuinely move the value of the deal are a small subset, usually liability structure, renewal economics, termination rights, indemnification scope, and the data and security terms. Everything else is either market-standard, low-impact, or both.
Teams that negotiate well are disciplined about letting the low-value clauses through quickly so they can spend their political capital and legal hours on the two or three clauses that actually matter. Teams that negotiate poorly treat every clause as equally important, exhaust themselves and the vendor, and still end up with a contract where the liability cap is wrong.
The right question at the start of an MSA negotiation isn't "what can we push on?" It's "on this specific deal, what are the three clauses that would cost us real money if they went the wrong way?" Fight those three. Ship the rest.