A pandemic shuts down data centers. A major cloud provider suffers a region-wide outage. A cyberattack takes down a third-party payment processor your platform depends on. Your SaaS agreement says you guarantee 99.9% uptime — but none of those events were remotely within your control.
Force majeure clauses exist to address exactly this situation. They allocate the risk of genuinely unforeseeable, uncontrollable events that prevent a party from performing its contractual obligations. In SaaS and technology contracts, where performance commitments are often specific and measurable, a properly drafted force majeure clause is one of the provisions that separates a contract built for the real world from one built for a world where nothing unexpected ever happens.
Understanding what force majeure covers, how to draft it for a SaaS context, and where the limits of the clause fall is essential for any technology company or business customer that relies on software to run its operations.
1. What Force Majeure Means in a Contract
Force majeure is a French legal term meaning “superior force.” In a contract, a force majeure clause excuses a party from performing — or delays the timeline for performance — when an extraordinary event outside that party’s control makes performance impossible, impractical, or illegal.
The clause does not automatically apply whenever something goes wrong. Three conditions generally must be satisfied for a force majeure defense to succeed under US contract law.
First, the event must fall within the scope of events the clause specifically covers. Courts interpret force majeure clauses narrowly — if an event is not listed or clearly falls within a listed category, courts are unlikely to extend the clause to cover it.
Second, the event must have been unforeseeable at the time the contract was signed. An event that was a known risk when the parties executed the agreement is rarely treated as force majeure. Seasonal outages, predictable regulatory changes, or market fluctuations typically do not qualify.
Third, the event must have actually caused the failure to perform. A party cannot invoke force majeure because a covered event occurred if that event had nothing to do with the failure. The causal link between the force majeure event and the performance failure must be direct.
2. Force Majeure in a SaaS Context: What It Typically Covers
Generic force majeure language borrowed from construction or manufacturing contracts often fails to account for the specific technical realities of cloud-hosted software. A well-drafted force majeure clause for a SaaS agreement should explicitly address the categories of events most likely to affect software delivery.
Covered categories typically include:
- Natural disasters: earthquakes, floods, hurricanes, wildfires, and other weather events that physically damage data center infrastructure
- Acts of war and terrorism that destroy or damage critical infrastructure
- Government actions: laws, regulations, embargoes, or government orders that prohibit or materially prevent performance
- Widespread telecommunications failures that are beyond the vendor’s reasonable control
- Major cyberattacks or state-sponsored intrusions that compromise core infrastructure, where the vendor has implemented reasonable security measures
- Pandemic-related public health orders that physically prevent personnel from operating necessary systems
Categories that are typically excluded:
Force majeure clauses in SaaS contracts should specify what does not qualify, because courts in the US have held that ambiguous force majeure clauses will be construed against the party seeking to invoke them.
Events that should not qualify include: routine cloud provider outages (the SaaS vendor’s choice of infrastructure is a business decision, not an act of God), financial distress or inability to pay suppliers, vendor personnel shortages caused by ordinary attrition, or competitive market changes that make the software less profitable to operate.
The distinction matters significantly. In Kel Kim Corp. v. Central Markets, Inc., the New York Court of Appeals held that force majeure clauses cover only events that are beyond the reasonable control of the affected party and that render performance objectively impossible — not merely more difficult or expensive.
3. The Critical Drafting Problem: “Beyond Our Reasonable Control”
Many SaaS contracts include force majeure language that reads: “Neither party shall be liable for any failure or delay in performance due to causes beyond its reasonable control.” This language is dangerously vague.
The phrase “beyond our reasonable control” invites disputes about what the affected party could have done to prevent or mitigate the event. Courts look at whether the party had business continuity measures in place, whether they diversified infrastructure across providers or regions, and whether their incident response was adequate.
A SaaS vendor with all infrastructure in a single availability zone who invokes force majeure after a regional outage may not succeed if a court determines that geographic redundancy was a reasonable precaution. The clause’s protection depends heavily on what “reasonable control” means in context — and that question is decided after the fact, in litigation.
Better drafting specifies concrete categories of covered events rather than relying on a catch-all. It also addresses the infrastructure-specific issues relevant to SaaS: third-party cloud provider failures, DNS or BGP routing failures, and internet backbone disruptions are different in kind from weather events, and the clause should address them explicitly with appropriate carve-outs and limitations.
4. Notice Requirements and Duty to Mitigate
Most force majeure clauses impose procedural requirements on the party invoking them. These requirements are not formalities — failing to meet them can forfeit the protection the clause provides.
Typical procedural requirements include:
Notice obligations: the affected party must provide written notice to the other party within a specified timeframe after the force majeure event begins. Notice periods in SaaS contracts often range from 24 to 72 hours for service-affecting events. Late notice can result in the clause being unavailable for the period before notice was given.
Description of the event: the notice must describe the nature of the force majeure event, which obligations are affected, and the anticipated duration of the impact.
Duty to mitigate: the affected party must take reasonable steps to minimize the duration and impact of the force majeure event and resume performance as quickly as reasonably possible. A SaaS vendor that invokes force majeure but makes no effort to activate backup systems or reroute traffic may not have satisfied this obligation.
For SaaS uptime obligations, force majeure provisions must be read alongside the SaaS SLA framework and the service credit structure. If force majeure excludes an outage from the SLA calculation, the credit structure must clearly reflect that exclusion or the two provisions will conflict.
5. When Force Majeure Does Not Apply: Common Disputes
The most frequent disputes over force majeure in technology contracts arise when one party characterizes a foreseeable or preventable event as a force majeure event to avoid liability.
Third-party cloud provider outages are a particularly contested area. SaaS vendors routinely argue that an AWS, Google Cloud, or Azure outage is outside their control and therefore covered by force majeure. Customers counter that the vendor’s decision to rely on a single cloud provider — and not to maintain geographically redundant infrastructure or multi-cloud failover — makes the resulting outage a preventable business risk, not a force majeure event.
Courts have generally been skeptical of force majeure claims based on vendor infrastructure decisions that the vendor controlled. If the vendor chose a single cloud provider, did not negotiate adequate SLA protection from that provider, and did not implement redundancy, invoking force majeure may not succeed.
Cyberattacks are increasingly contested as force majeure events. Whether a cyberattack qualifies depends on whether the vendor implemented reasonable security measures and whether the attack exploited a known vulnerability that should have been patched. A sophisticated state-sponsored attack on a vendor with strong security posture is a stronger force majeure candidate than a ransomware attack enabled by an unpatched server.
Regulatory changes require careful analysis. A new data privacy law or regulatory requirement that makes certain data processing activities illegal is generally a force majeure event — the government action was outside the vendor’s control. However, if the regulatory change was foreseeable (a law that had been in legislative development for two years), it may not qualify.
6. How Force Majeure Interacts With Termination Rights
A force majeure clause must specify what happens when the affected period extends beyond a threshold duration. Without a termination right tied to extended force majeure, a customer could be locked into a non-performing contract indefinitely while the vendor claims continued protection.
Standard termination provisions in technology contracts allow either party to terminate if a force majeure event prevents material performance for a defined period — typically 30 to 90 days. Upon termination for extended force majeure, the customer should be entitled to a pro-rata refund of any prepaid subscription fees for the unused period, return of all customer data in a portable, usable format, and reasonable transition assistance.
The contract should specify these termination consequences expressly. Without them, the parties may dispute what the customer is entitled to receive after invoking force majeure-related termination rights.
These termination provisions connect closely to the data portability obligations in a well-drafted SaaS agreement and, where applicable, the escrow arrangements that protect business continuity when a vendor becomes unable to perform. The indemnification clauses in the same agreement will also govern whether either party has a claim for losses that occurred before the force majeure event was invoked.
7. Drafting Force Majeure for Your SaaS Contract
Whether you are a SaaS vendor drafting your standard agreement or a business customer reviewing a vendor’s contract, force majeure provisions require specific attention.
For SaaS vendors: Define covered events with specificity rather than relying on catch-all language. Explicitly address the infrastructure events most likely to affect your platform. Include notice obligations with realistic timeframes. Tie force majeure exclusions clearly to your SLA and service credit provisions so the two sections do not conflict. Avoid language that a court could interpret to excuse ordinary infrastructure choices made during implementation.
For SaaS customers: Resist broad force majeure language that would excuse ordinary cloud provider outages. Negotiate explicit exclusions for events that result from the vendor’s infrastructure decisions, lack of redundancy, or failure to maintain reasonable security standards. Ensure the clause includes a termination right for extended force majeure events with clear data return and refund obligations.
A technology lawyer with SaaS contract experience can identify where a force majeure clause creates unintended risk and negotiate language that accurately reflects the allocation of risk both parties actually intended.
Frequently Asked Questions
Does force majeure apply to SaaS subscription fees during an outage?
Force majeure typically suspends the vendor’s obligation to perform — it does not automatically suspend the customer’s obligation to pay. Whether payment obligations are also suspended during a force majeure event depends on how the clause is drafted. Customers should negotiate express language addressing payment during extended force majeure periods, particularly for annual prepaid contracts.
Can a SaaS vendor invoke force majeure for a cloud provider outage?
It depends on the contract language and the specific circumstances. Courts generally require that the event be beyond the reasonable control of the party invoking force majeure. A SaaS vendor that relies on a single cloud provider without redundancy may have difficulty arguing that a regional outage was truly unforeseeable or unpreventable. Multi-region redundancy is increasingly treated as a reasonable standard of care for commercial SaaS products.
How is force majeure different from an act of God clause?
“Act of God” is a narrower concept, historically limited to natural disasters. Force majeure is broader and typically includes natural disasters, government actions, cyberattacks, war, and other categories of events specified in the clause. Modern technology contracts use force majeure language rather than act of God clauses because the relevant risk categories extend well beyond weather events.
Does COVID-19 qualify as a force majeure event for SaaS contracts?
For contracts signed before early 2020, the pandemic was likely unforeseeable and qualified as a force majeure event when it prevented performance. For contracts signed after the pandemic began, COVID-19 and future pandemic-related disruptions may be expressly excluded or included depending on how the clause was negotiated. Courts have reached varying conclusions depending on the specific contract language and the nature of the performance obligation affected.
What notice do I have to give to invoke force majeure?
Notice requirements are defined by the specific force majeure clause in your contract. Most SaaS contracts require written notice within 24 to 72 hours of the event beginning. Failure to provide timely notice can result in losing protection under the clause for some or all of the affected period. Review your contract’s notice requirements and ensure your legal team is aware of them before a crisis occurs.
Get Your Force Majeure Clause Right Before You Need It
Force majeure clauses look like boilerplate until a real event tests them. At that point, the specificity of the covered events, the adequacy of the notice procedures, and the presence or absence of a termination right determine whether the clause protects your business or creates a protracted dispute.
If your SaaS contract’s force majeure provision is generic, borrowed from another industry, or has never been reviewed by a technology lawyer, contact Hansen Tong at TOS Lawyer. Reviewing and updating this clause as part of a broader contract review is a straightforward step that prevents significant exposure when something genuinely unpredictable occurs.
