Skip to content
ResourcesContact
Sign inTalk to a lawyer
  1. Home/
  2. Resources/
  3. Enterprise SaaS
Enterprise SaaS

7 Legal Issues That Stall Enterprise Deals

Ben SuLawyer; closed $280M+ in enterprise deals over 3 months, representing startups selling into enterprise and reviewing vendor MSAs buy-side·Updated Aug 12, 2026·9 min read

Enterprise deals stall on the legal side over a predictable short list: limitation of liability, indemnification, security and data-protection terms, data and AI usage rights, termination and auto-renewal, whose contract paper the deal runs on, and the procurement mechanics that kill momentum after the terms are agreed. Almost none of it is about price - it is about who carries the risk if something goes wrong.

I'm a lawyer. Over the last three months I closed north of $280M in enterprise deals - sitting on the sell-side for startups selling into large enterprises whose legal was run by in-house counsel and tier-1 firms, and on the buy-side reviewing vendor master services agreements (MSAs) for clients. The same seven issues stalled deals over and over, on both sides of the table. Here is the list, what each one actually is, why it stops a deal, and the move that gets a sell-side startup through it.

This is general information from my experience, not legal advice for your specific deal.

1. Limitation of liability: the cap almost every enterprise deal fights over

A limitation of liability clause is the term that caps the maximum dollar amount a vendor can be forced to pay if something goes wrong. It is the single most contested term in commercial contracting - limitation of liability has ranked at or near the top of World Commerce & Contracting's Most Negotiated Terms survey for over a decade, alongside indemnification and price.

Here is why it stalls a deal. The enterprise buyer wants a high cap or no cap at all, because they are protecting themselves against a vendor failure. The startup cannot survive an uncapped liability tied to a $150K contract - one bad clause can be an existential event.

The sell-side move: anchor the cap at 1x the fees paid in the prior 12 months, a common startup position Andreessen Horowitz documents for SaaS deals. Offer a higher "super-cap" (for example 2x fees) for narrow, high-consequence risks like a data breach, and accept a short list of uncapped carve-outs where it's genuinely market - usually the IP infringement indemnity. When the buyer's number is too big to accept, buying an insurance policy to cover the exposure (and sometimes splitting the cost) is a real option that keeps the deal alive.

2. Indemnification: the uncapped carve-out that hides the real exposure

An indemnification clause is a promise to cover the other side's losses if a specified bad thing happens - most often a claim that your product infringes someone's intellectual property, or that you mishandled their data. Indemnities are consistently a top-three most-negotiated term because they can quietly reintroduce the unlimited exposure your liability cap was supposed to remove.

Indemnification stalls deals because the two sides argue about two things at once: how broad the promise is, and whether it sits inside or outside the liability cap. An enterprise buyer will ask for broad indemnities - sometimes covering indirect losses like reputational harm - and want the IP indemnity uncapped.

The sell-side move: limit what you indemnify to direct losses (legal fees, court costs, settlement of the covered claim), not indirect or consequential losses. Keep IP infringement as the one indemnity you'll take uncapped if you have to, because for real infringement the customer's position is reasonable - but resist adding data-incident or "any breach" indemnities on top of an already-negotiated liability structure. Every indemnity you give should map to a risk you can actually control.

3. The security review and your DPA: where deals go quiet for a month

A security review is the enterprise's process of vetting whether a vendor is safe to plug into their systems and data - security questionnaires, a SOC 2 report, penetration-test summaries, and a negotiated data processing agreement (DPA). It is the classic "it looked done, then it went silent" stall, and it lands after the commercial terms are already agreed.

This stalls deals because it involves teams the salesperson doesn't control and paperwork the startup often hasn't prepared. Industry estimates put enterprise security reviews at roughly four to six weeks per deal (Cyberbase), and that is before any DPA redlines. A DPA is a contract required under privacy laws like the GDPR and CCPA whenever the vendor processes personal data on the customer's behalf; a healthcare buyer may also require a HIPAA business associate agreement, and an Ontario health customer a PHIPA service-provider agreement.

The sell-side move: get ahead of it. Have a current SOC 2 report, a completed standard security questionnaire, and a vendor-friendly DPA template ready before the review starts, so the buyer is redlining your paper instead of waiting on your engineers. The vendors who close fastest treat security artifacts as sales collateral, not a fire drill.

4. Data and AI usage rights: the modern sticking point

Data usage rights govern what the vendor is allowed to do with the customer's data - in particular, whether you can use it to train or improve machine-learning models and reuse those models across other customers. This term barely existed as a fight a few years ago; today it is one of the first questions a sophisticated enterprise buyer's counsel asks.

It stalls deals because the incentives are directly opposed. The startup often wants to use aggregated customer data to improve the product; the enterprise wants its data locked down, especially anything sensitive or competitively meaningful. Contracts that grant the vendor overly broad rights to "use, analyze, or resell" customer data reliably draw a redline from enterprise legal.

The sell-side move: pick a clear tier and put it in writing. A workable middle position is that the customer owns its data, and the vendor may use it only to provide and improve the service - with any model training either excluded for that customer or limited to de-identified, aggregated data that can't be traced back to them. Name the boundary explicitly. Ambiguity here is what turns a two-day review into a two-week one.

5. Termination for convenience and auto-renewal: the revenue-predictability fight

Termination for convenience lets a customer walk away from the contract at any time without cause; auto-renewal automatically extends the term unless someone opts out. Together they decide how predictable your revenue is, which is why both your CFO and your investors care about them.

These stall deals because they sit at the intersection of legal and deal economics. A big buyer wants the freedom to exit; the startup needs committed term to recognize revenue and forecast. Aggressive auto-renewal terms - especially one-sided price increases on renewal - also draw procurement pushback in the other direction when you're the vendor pricing it that way.

The sell-side move: resist a pure termination-for-convenience right on a committed-term deal. If you must give one, a16z's guidance is to trade it for a shorter term or no refund of prepaid fees, so you're not exposed to a mid-term walkaway. On renewals, keep any price-increase mechanism reasonable and capped - the version that quietly raises price "at vendor's discretion" is the one that gets flagged and slows the close.

6. "Whose paper?" - redlining the enterprise's MSA

"Whose paper" is the question of which side's contract template the deal runs on: your order form and MSA, or the buyer's. It sounds procedural, but it silently sets every default position in the negotiation, and it is one of the biggest hidden drivers of how long a deal takes.

It stalls deals because starting on the enterprise's MSA means starting from terms written entirely for their protection - and a large buyer's paper can run well over 100 pages once the DPA and security exhibits are attached. Redlining all of it, clause by clause, is where weeks disappear.

The sell-side move: lead with your own paper whenever your leverage allows - it anchors the deal on your positions and closes faster. When a large enterprise insists on theirs (and they often will), don't rewrite the whole document. Negotiate the handful of terms that carry real risk - liability, indemnity, data, termination - and let the rest go. Keep a redline playbook with your pre-approved position, fallback, and hard line on each key clause, so every deal starts from the same known place instead of a blank-page argument.

7. The unglamorous mechanics that die in procurement

The last stall isn't a clause - it's the operational layer: signature authority, correct legal entity names, insurance requirements, and the stack of documents (MSA + DPA + order form + SOW) that all have to line up before anyone can sign. This is where a deal that's legally "done" sits for another two weeks.

It stalls deals because enterprise procurement is a gauntlet the founder rarely sees coming. The wrong entity name on the signature block, a missing certificate of insurance for a coverage level buried in the MSA, or a signer who turns out not to have authority can each bounce the contract back into a queue.

The sell-side move: run a pre-signature checklist. Confirm the exact legal entities on both sides, verify the signatory actually has authority, check the insurance and any flow-down requirements early (not at signature), and make sure the MSA, DPA, order form, and any SOW reference each other cleanly. None of it is hard. All of it is a delay when you find out at the finish line.

How to keep these seven from stalling your next deal

The pattern across all seven is that the delay is rarely the disagreement itself - it's not having a decided position ready when the issue comes up. Deals stall while a founder figures out, in real time, what they're willing to accept on a liability cap or a data clause. The teams that close fast have already decided: a known cap, a known indemnity position, a ready DPA, a redline playbook, and a procurement checklist. The negotiation still happens; it just doesn't start from zero every time.

Frequently asked questions

What are the most negotiated terms in enterprise contracts?

Limitation of liability, indemnification, and price/charge have ranked among the most negotiated commercial contract terms in World Commerce & Contracting's annual Most Negotiated Terms survey for years. In enterprise software deals specifically, data protection and security terms and termination rights are close behind.

Why do enterprise deals stall in legal review?

Enterprise deals stall in legal review when the parties disagree on risk-allocation terms (liability caps, indemnities, data protection), when the vendor's security posture can't survive a security questionnaire, or when the deal gets stuck in procurement over the vendor's own paper, missing entity details, or insurance requirements. Most delays are about who carries the risk if something goes wrong, not about price.

What is a typical limitation of liability cap for a SaaS startup?

A common sell-side position is to cap liability at 1x the fees paid in the prior 12 months, with a higher "super-cap" (for example 2x fees) for specific risks like a data breach, and a short list of uncapped carve-outs such as the IP infringement indemnity. Enterprise buyers often push for higher multiples or uncapped liability; where the numbers matter, some vendors buy insurance to cover the gap.

How long does a security review add to an enterprise sales cycle?

Security review is frequently one of the slowest steps after commercial terms are agreed - industry estimates put it at roughly four to six weeks per enterprise deal, driven by security questionnaires, SOC 2 evidence, and DPA negotiation. Having current SOC 2 reports and a ready DPA before the review starts is the main way to compress it.

Should a startup sign on the customer's paper or its own?

Start from your own paper whenever you have the leverage - it anchors the negotiation on your positions and usually closes faster. Large enterprise buyers will often insist on their own MSA; when that happens, negotiate the handful of terms that carry real risk (liability, indemnity, data, termination) rather than rewriting the whole document, and keep a redline playbook so every deal starts from the same known positions.

This article is general information from my experience closing enterprise deals, not legal advice. The right position on any of these terms depends on your specific deal, leverage, and risk tolerance - consult a qualified attorney for your situation.

Every issue above comes down to having a decided position ready before the redline lands. LegalLayer, the premium tier of LegalBooks, gives growth-stage companies a lawyer-designed contract template plus a system of agents that draft, negotiate, and review enterprise deals fast - inside the exact limits a licensed lawyer set (green to flex, yellow to escalate, red as a hard line), with every concession logged. It's how sell-side teams answer redlines in real time instead of losing weeks to legal turnaround.

Make the next legal step with confidence.

Talk to a lawyer

LegalBooks combines practical startup workflows with lawyer review when the decision calls for it.

Ben SuLawyer; closed $280M+ in enterprise deals over 3 months, representing startups selling into enterprise and reviewing vendor MSAs buy-side·Updated Aug 12, 2026·9 min read

Ben Su is Co-founder and Head of Legal Service Delivery at LegalLayer, and a lawyer.

TermsPrivacyContact

© 2026 LegalBooks