{"id":39168,"date":"2026-09-11T20:57:45","date_gmt":"2026-09-11T15:57:45","guid":{"rendered":"https:\/\/www.brandligo.com\/blog\/?p=39168"},"modified":"2026-09-12T09:52:57","modified_gmt":"2026-09-12T04:52:57","slug":"software-vendor-due-diligence-checklist-2026","status":"publish","type":"post","link":"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/","title":{"rendered":"Software Vendor Due Diligence Checklist (2026): 25 Checks Before You Sign"},"content":{"rendered":"<p>Software vendor due diligence should answer one question before a contract is signed: <strong>what evidence shows this supplier can deliver, protect, support and eventually hand over what you are buying?<\/strong><\/p>\n<p>A polished demo, a familiar logo or a low hourly rate is not enough. In 2026, buyers also need to test delivery risk, security practices, ownership, continuity, data handling and exit terms. NIST\u2019s finalized 2026 C-SCRM Due Diligence Assessment Quick-Start Guide reinforces this evidence-based approach to supplier research, while the NIST Secure Software Development Framework gives buyers and software producers a common language for discussing secure development practices.<\/p>\n<p>This checklist is designed for businesses evaluating a custom software development company, implementation partner, SaaS supplier or technology vendor. It complements Brandligo\u2019s <a href=\"https:\/\/www.brandligo.com\/blog\/choose-software-development-company\/\">software development company selection guide<\/a> and <a href=\"https:\/\/www.brandligo.com\/blog\/2024-top-software-development-companies\/\">software development company comparison<\/a>.<\/p>\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_87 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">In This Article<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#Software_vendor_due_diligence_checklist_at_a_glance\" >Software vendor due diligence checklist at a glance<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#1_Verify_the_company_before_evaluating_the_proposal\" >1. Verify the company before evaluating the proposal<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#1_Confirm_the_contracting_legal_entity\" >1. Confirm the contracting legal entity<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#2_Confirm_where_the_work_will_actually_be_delivered\" >2. Confirm where the work will actually be delivered<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#3_Check_ownership_and_material_business_changes\" >3. Check ownership and material business changes<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#4_Validate_references_that_match_your_project_type\" >4. Validate references that match your project type<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#2_Test_whether_the_vendor_can_deliver_your_project\" >2. Test whether the vendor can deliver your project<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#5_Ask_for_the_named_delivery_team\" >5. Ask for the named delivery team<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#6_Review_a_realistic_delivery_plan\" >6. Review a realistic delivery plan<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#7_Ask_how_scope_changes_are_controlled\" >7. Ask how scope changes are controlled<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#8_Examine_quality_assurance_practices\" >8. Examine quality assurance practices<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#9_Request_evidence_of_similar_technical_work\" >9. Request evidence of similar technical work<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#3_Review_security_and_software-supply-chain_risk\" >3. Review security and software-supply-chain risk<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#10_Ask_how_secure_development_is_built_into_the_lifecycle\" >10. Ask how secure development is built into the lifecycle<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#11_Verify_access-control_practices\" >11. Verify access-control practices<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#12_Review_dependency_and_third-party_software_management\" >12. Review dependency and third-party software management<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-17\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#13_Understand_vulnerability_reporting_and_remediation\" >13. Understand vulnerability reporting and remediation<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-18\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#14_Check_incident-notification_obligations\" >14. Check incident-notification obligations<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-19\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#4_Make_data_IP_and_infrastructure_ownership_explicit\" >4. Make data, IP and infrastructure ownership explicit<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-20\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#15_Define_who_owns_newly_created_intellectual_property\" >15. Define who owns newly created intellectual property<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-21\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#16_Keep_source_code_in_a_controlled_repository\" >16. Keep source code in a controlled repository<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-22\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#17_Keep_critical_cloud_and_platform_accounts_transferable\" >17. Keep critical cloud and platform accounts transferable<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-23\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#18_Document_data_location_retention_and_deletion\" >18. Document data location, retention and deletion<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-24\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#5_Stress-test_the_commercial_model\" >5. Stress-test the commercial model<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-25\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#19_Compare_total_cost_not_only_hourly_rate\" >19. Compare total cost, not only hourly rate<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-26\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#20_Define_milestone_acceptance_before_work_starts\" >20. Define milestone acceptance before work starts<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-27\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#21_Understand_change-order_pricing\" >21. Understand change-order pricing<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-28\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#22_Review_service_and_support_commitments\" >22. Review service and support commitments<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-29\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#6_Evaluate_exit_risk_before_signing\" >6. Evaluate exit risk before signing<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-30\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#23_Require_a_practical_handover_path\" >23. Require a practical handover path<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-31\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#24_Confirm_usable_data-export_rights\" >24. Confirm usable data-export rights<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-32\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#25_Define_termination_and_transition_assistance\" >25. Define termination and transition assistance<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-33\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#A_simple_evidence-based_scoring_method\" >A simple evidence-based scoring method<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-34\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#Red_flags_that_deserve_a_closer_look\" >Red flags that deserve a closer look<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-35\" href=\"https:\/\/www.brandligo.com\/blog\/software-vendor-due-diligence-checklist-2026\/#What_to_do_after_due_diligence\" >What to do after due diligence<\/a><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"Software_vendor_due_diligence_checklist_at_a_glance\"><\/span>Software vendor due diligence checklist at a glance<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<table><thead><tr><th>Area<\/th><th>What to verify<\/th><th>Evidence to request<\/th><\/tr><\/thead><tbody>\n<tr><td>Company legitimacy<\/td><td>Legal entity, ownership, operating history, delivery locations<\/td><td>Registration details, contractual entity, office and team information<\/td><\/tr>\n<tr><td>Delivery capability<\/td><td>Relevant work, assigned team, engineering process, QA<\/td><td>Named team, sample artifacts, references, delivery plan<\/td><\/tr>\n<tr><td>Security<\/td><td>Secure development, access controls, vulnerability handling<\/td><td>Policies, certifications where relevant, testing evidence, incident process<\/td><\/tr>\n<tr><td>Commercial terms<\/td><td>Pricing, change control, payment triggers, hidden dependencies<\/td><td>Rate card, statement of work, assumptions, change-order rules<\/td><\/tr>\n<tr><td>Ownership<\/td><td>Source code, data, IP, repositories, cloud accounts<\/td><td>Contract clauses and client-controlled access<\/td><\/tr>\n<tr><td>Exit readiness<\/td><td>Transition support, exports, documentation, lock-in<\/td><td>Termination clause, handover plan, export format, transition obligations<\/td><\/tr>\n<\/tbody><\/table>\n<h2><span class=\"ez-toc-section\" id=\"1_Verify_the_company_before_evaluating_the_proposal\"><\/span>1. Verify the company before evaluating the proposal<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"1_Confirm_the_contracting_legal_entity\"><\/span>1. Confirm the contracting legal entity<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Make sure the company name on the proposal matches the legal entity that will sign the agreement and receive payment. If the sales brand, development company and billing entity are different, ask why and document the relationship.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"2_Confirm_where_the_work_will_actually_be_delivered\"><\/span>2. Confirm where the work will actually be delivered<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>A local sales office does not necessarily mean a local engineering team. Ask where developers, project managers, QA staff and support teams are located, which time zones they work in and whether subcontractors will participate.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"3_Check_ownership_and_material_business_changes\"><\/span>3. Check ownership and material business changes<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Recent acquisitions, major restructures or dependence on a parent company can affect delivery continuity. The goal is not to reject change; it is to understand who controls the supplier and which entity is responsible if something goes wrong.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"4_Validate_references_that_match_your_project_type\"><\/span>4. Validate references that match your project type<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Do not ask only for famous client logos. Request references for projects similar in complexity, technology, regulatory exposure or operating model. Ask those references what happened after launch, not just whether the initial project was completed.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"2_Test_whether_the_vendor_can_deliver_your_project\"><\/span>2. Test whether the vendor can deliver your project<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.brandligo.com\/blog\/wp-content\/uploads\/2026\/09\/software-vendor-delivery-team-review.jpg\" alt=\"Software team reviewing an app development project during a vendor evaluation meeting\" loading=\"lazy\"\/><figcaption class=\"wp-element-caption\">Vendor delivery-team review. Photo: Mapbox\/Unsplash.<\/figcaption><\/figure>\n<h3><span class=\"ez-toc-section\" id=\"5_Ask_for_the_named_delivery_team\"><\/span>5. Ask for the named delivery team<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Evaluate the people expected to do the work, not only senior staff presented during sales calls. Confirm roles, seniority, availability and how substitutions are handled.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"6_Review_a_realistic_delivery_plan\"><\/span>6. Review a realistic delivery plan<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The plan should identify discovery, architecture, implementation, testing, deployment and support rather than presenting one unexplained deadline. Look for assumptions and dependencies that could move the schedule.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"7_Ask_how_scope_changes_are_controlled\"><\/span>7. Ask how scope changes are controlled<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Most software projects change. A mature vendor should explain who approves changes, how schedule and budget impacts are estimated, and how decisions are recorded.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"8_Examine_quality_assurance_practices\"><\/span>8. Examine quality assurance practices<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Ask what is tested automatically, what requires manual QA, how defects are triaged, and what acceptance criteria determine whether a milestone is complete.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"9_Request_evidence_of_similar_technical_work\"><\/span>9. Request evidence of similar technical work<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>A portfolio screenshot is weak evidence. Better evidence includes architecture explanations, deployment patterns, integration experience, migration approaches or anonymized delivery artifacts that demonstrate the vendor has solved comparable problems.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"3_Review_security_and_software-supply-chain_risk\"><\/span>3. Review security and software-supply-chain risk<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.brandligo.com\/blog\/wp-content\/uploads\/2026\/09\/software-vendor-security-review-scaled.jpg\" alt=\"Developer reviewing code on a computer during a software security assessment\" loading=\"lazy\"\/><figcaption class=\"wp-element-caption\">Software security review. Photo: Julio Lopez\/Unsplash.<\/figcaption><\/figure>\n<p>NIST\u2019s <a href=\"https:\/\/www.nist.gov\/news-events\/news\/2026\/07\/nist-releases-finalized-c-scrm-due-diligence-assessment-quick-start-guide\" target=\"_blank\" rel=\"noopener\">July 8, 2026 supplier due-diligence guidance<\/a> describes due diligence as reasonable research and investigative rigor before procurement decisions. For software, security evidence should scale with the risk of the system being purchased.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"10_Ask_how_secure_development_is_built_into_the_lifecycle\"><\/span>10. Ask how secure development is built into the lifecycle<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Use the <a href=\"https:\/\/csrc.nist.gov\/projects\/ssdf\" target=\"_blank\" rel=\"noopener\">NIST Secure Software Development Framework<\/a> as a reference point. You do not need a vendor to use NIST terminology, but they should be able to explain how they prevent, detect and respond to software vulnerabilities.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"11_Verify_access-control_practices\"><\/span>11. Verify access-control practices<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Ask how developers receive access to source code, production systems, secrets, customer data and cloud environments. Confirm whether multi-factor authentication, least-privilege access and offboarding controls are used.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"12_Review_dependency_and_third-party_software_management\"><\/span>12. Review dependency and third-party software management<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Modern applications rely heavily on open-source packages and external services. Ask how dependencies are selected, updated and monitored and who is responsible when a critical vulnerability affects one of them.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"13_Understand_vulnerability_reporting_and_remediation\"><\/span>13. Understand vulnerability reporting and remediation<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Confirm how security issues are reported, prioritized and fixed. For higher-risk systems, ask whether the vendor can provide relevant security testing evidence, vulnerability disclosure information or software supply-chain artifacts.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"14_Check_incident-notification_obligations\"><\/span>14. Check incident-notification obligations<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The contract should define when the supplier must notify you about a security incident affecting your systems or data, what information they must provide and who coordinates remediation.<\/p>\n<p>CISA\u2019s guidance on <a href=\"https:\/\/www.cisa.gov\/resources-tools\/resources\/choosing-secure-and-verifiable-technologies\" target=\"_blank\" rel=\"noopener\">choosing secure and verifiable technologies<\/a> is also useful for buyers that need a more security-focused procurement review.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"4_Make_data_IP_and_infrastructure_ownership_explicit\"><\/span>4. Make data, IP and infrastructure ownership explicit<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"15_Define_who_owns_newly_created_intellectual_property\"><\/span>15. Define who owns newly created intellectual property<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Do not assume payment automatically gives you every right you expect. The agreement should distinguish client-owned work, vendor pre-existing IP, third-party components and reusable frameworks.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"16_Keep_source_code_in_a_controlled_repository\"><\/span>16. Keep source code in a controlled repository<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>For custom software, decide who owns the GitHub, GitLab or other repository and when the buyer receives administrative access. Waiting until the final invoice to discover that the vendor controls the only current copy creates avoidable risk.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"17_Keep_critical_cloud_and_platform_accounts_transferable\"><\/span>17. Keep critical cloud and platform accounts transferable<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Domains, cloud subscriptions, app-store accounts, analytics, payment services, certificates and production credentials should not become hostage to a vendor-owned account.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"18_Document_data_location_retention_and_deletion\"><\/span>18. Document data location, retention and deletion<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Ask where project and production data is stored, who can access it, how long backups remain available and what deletion evidence can be provided at termination.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"5_Stress-test_the_commercial_model\"><\/span>5. Stress-test the commercial model<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"19_Compare_total_cost_not_only_hourly_rate\"><\/span>19. Compare total cost, not only hourly rate<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Include discovery, project management, QA, infrastructure, licenses, third-party tools, support, change requests and transition costs. A low development rate can still produce a higher total cost if important activities are excluded.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"20_Define_milestone_acceptance_before_work_starts\"><\/span>20. Define milestone acceptance before work starts<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Payment triggers should map to understandable deliverables and acceptance criteria. Avoid milestones that depend only on calendar dates or vague percentages of completion.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"21_Understand_change-order_pricing\"><\/span>21. Understand change-order pricing<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Ask how new work is estimated, who approves it and whether the vendor can begin chargeable changes without written authorization.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"22_Review_service_and_support_commitments\"><\/span>22. Review service and support commitments<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>If the vendor will support production software, define response targets, coverage hours, severity levels, maintenance responsibilities and what is excluded from support.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"6_Evaluate_exit_risk_before_signing\"><\/span>6. Evaluate exit risk before signing<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"23_Require_a_practical_handover_path\"><\/span>23. Require a practical handover path<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The contract should cover source code, architecture documentation, credentials, deployment instructions, runbooks, unresolved defects and knowledge transfer. A relationship is safer when transition is possible even if nobody expects to use it.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"24_Confirm_usable_data-export_rights\"><\/span>24. Confirm usable data-export rights<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>For SaaS and hosted platforms, ask what can be exported, in which format, how long exports remain available after termination and whether additional fees apply.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"25_Define_termination_and_transition_assistance\"><\/span>25. Define termination and transition assistance<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Know the notice period, outstanding-payment obligations, termination rights and whether the supplier must assist a replacement provider. If a mission-critical system depends on proprietary vendor technology, identify that dependency before signing rather than during an emergency migration.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"A_simple_evidence-based_scoring_method\"><\/span>A simple evidence-based scoring method<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Use a 1\u20135 score for each category, but score <strong>evidence<\/strong>, not sales confidence:<\/p>\n<ul>\n<li><strong>1:<\/strong> no evidence or a material unresolved risk;<\/li>\n<li><strong>2:<\/strong> verbal assurance only;<\/li>\n<li><strong>3:<\/strong> adequate documented evidence;<\/li>\n<li><strong>4:<\/strong> strong evidence plus relevant references or artifacts;<\/li>\n<li><strong>5:<\/strong> strong evidence, clear contractual protection and low residual risk.<\/li>\n<\/ul>\n<p>Weight categories according to the project. Security and continuity may deserve more weight for a healthcare or financial system; speed and product-discovery capability may matter more for an early-stage MVP. Do not let the scoring model hide a non-negotiable issue: a vendor can have the highest overall score and still be unsuitable if it fails a mandatory security, ownership or compliance requirement.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Red_flags_that_deserve_a_closer_look\"><\/span>Red flags that deserve a closer look<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ul>\n<li>The vendor will not identify the actual team before contract signature.<\/li>\n<li>References cannot be contacted or do not resemble your project.<\/li>\n<li>Source-code, IP or data ownership language is ambiguous.<\/li>\n<li>Production infrastructure must remain permanently in vendor-controlled accounts.<\/li>\n<li>Security answers rely only on claims such as \u201cindustry standard\u201d without supporting evidence.<\/li>\n<li>Change requests have no approval or pricing process.<\/li>\n<li>There is no documented termination, export or handover process.<\/li>\n<li>The proposal depends on proprietary components that cannot be replaced or transferred.<\/li>\n<\/ul>\n<h2><span class=\"ez-toc-section\" id=\"What_to_do_after_due_diligence\"><\/span>What to do after due diligence<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Due diligence is not the final selection step. Use what you learned to tighten the statement of work, security requirements, acceptance criteria, ownership clauses and transition obligations. Then compare finalists on the same evidence.<\/p>\n<p>If you are still building a shortlist, browse the <a href=\"https:\/\/www.brandligo.com\/\">Brandligo company directory<\/a> and use the <a href=\"https:\/\/www.brandligo.com\/blog\/choose-software-development-company\/\">software development company selection framework<\/a> to define your requirements before contacting vendors.<\/p>\n<p><em>Editorial note:<\/em> This checklist is general procurement guidance, not legal, cybersecurity or compliance advice. Requirements vary by jurisdiction, industry, data sensitivity and system criticality.<\/p>","protected":false},"excerpt":{"rendered":"<p>A practical 2026 software vendor due diligence checklist covering delivery evidence, security, IP ownership, commercial terms, data handling and exit risk before you sign.<\/p>\n","protected":false},"author":10,"featured_media":39170,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7474],"tags":[],"class_list":["post-39168","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-buyer-guides"],"_links":{"self":[{"href":"https:\/\/www.brandligo.com\/blog\/wp-json\/wp\/v2\/posts\/39168","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.brandligo.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.brandligo.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.brandligo.com\/blog\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.brandligo.com\/blog\/wp-json\/wp\/v2\/comments?post=39168"}],"version-history":[{"count":1,"href":"https:\/\/www.brandligo.com\/blog\/wp-json\/wp\/v2\/posts\/39168\/revisions"}],"predecessor-version":[{"id":39169,"href":"https:\/\/www.brandligo.com\/blog\/wp-json\/wp\/v2\/posts\/39168\/revisions\/39169"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.brandligo.com\/blog\/wp-json\/wp\/v2\/media\/39170"}],"wp:attachment":[{"href":"https:\/\/www.brandligo.com\/blog\/wp-json\/wp\/v2\/media?parent=39168"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.brandligo.com\/blog\/wp-json\/wp\/v2\/categories?post=39168"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.brandligo.com\/blog\/wp-json\/wp\/v2\/tags?post=39168"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}