Force majeure after pandemics: drafting clauses that actually work
Pandemics, cyber attacks, supply-chain collapse, sanctions — what the post-2020 wave of force-majeure litigation taught us about clauses that hold up in court.
Force majeure is having a moment
Before 2020, force-majeure clauses were boilerplate everyone skipped. After three years of pandemic litigation, a Russia/Ukraine sanctions wave, semiconductor shortages, and several high-profile cyber attacks, courts on three continents have rewritten the rulebook. The clause in your template from 2019 almost certainly does not say what you think it says.
What "force majeure" actually means
Force majeure is a contractual defence to non-performance — it suspends or excuses an obligation when an unforeseeable, uncontrollable event makes performance impossible or impractical. It is not a general escape hatch. Courts read these clauses narrowly, and they require the party invoking force majeure to prove (1) the event, (2) causation, and (3) mitigation.
The pandemic litigation lessons
The wave of COVID-era force-majeure cases — In re Hitz Restaurant Group (US Bankruptcy 2020), Polonsky v. Polonsky (NY 2021), and the UK Supreme Court's FCA business interruption test case — established three principles: (1) generic catch-alls like "acts of God" don't cover pandemics unless specifically listed, (2) government orders are not the same as the underlying event, (3) financial hardship alone is never force majeure.
Drafting a 2026-grade force-majeure clause
Modern best practice has four elements: (1) enumerated events, including pandemics, government orders, cyber attacks, sanctions, and supply-chain disruption; (2) a catch-all for events of similar magnitude not within the reasonable control of the affected party; (3) carve-outs for payment obligations (you can't claim force majeure to avoid paying); (4) a procedure including notice within X days, an obligation to mitigate, and a termination right if force majeure persists beyond Y days.
Cyber attacks as force majeure
After the 2024 CrowdStrike outage and the Change Healthcare ransomware incident, courts have started recognising cyber events as potential force majeure — but only when (a) the event is genuinely unforeseeable, (b) the affected party had reasonable security controls in place, and (c) the obligation could not be performed manually or via workaround. If you're a SaaS vendor, a ransomware attack on your own systems is rarely going to qualify.
Sanctions and export controls
Force majeure for sanctions is a special case. Most modern clauses treat the imposition of new sanctions on a counterparty as a triggering event, while existing sanctions are not (they were foreseeable). The U.S. Treasury's OFAC and the EU's DG TRADE guidance is essential reading if your contract has any cross-border element.
The supply-chain clause
After the 2021–2023 supply-chain shocks, sophisticated parties now negotiate a separate supply-chain disruption clause distinct from force majeure. It allows price adjustments (not just suspension) when input costs rise above defined thresholds, and it specifies which party bears the cost of seeking alternative suppliers.
How AI surfaces force-majeure issues
ContractScan AI flags force-majeure clauses on every contract review, scores them against post-2020 best practice, and highlights missing carve-outs (especially around payment obligations) and missing termination rights. On a multi-vendor procurement review, this can save weeks of manual work.
Stop reading contracts. Start understanding them.
Upload any PDF or DOCX and get a plain-English summary, risk score, and negotiation suggestions in under 60 seconds.
Try ContractScan AI free