Sophie Laurent, YuSMP Group
Sophie Laurent Compliance & Delivery Lead, YuSMP Group · Specialises in vendor due diligence and GDPR-aligned software delivery for EU and US clients

TL;DR — vendor selection at a glance

Get the choice right and it really comes down to six dimensions. Score every candidate against them before price ever enters the conversation:

  • Certifications: ISO 27001 (information security) + SOC 2 Type II (US/EU enterprise) + GDPR Article 28 DPA for EU data
  • IP & NDA: mutual NDA before spec sharing; contract assigns all IP to client; code held in client-owned repo
  • Portfolio fit: at least 2 projects in your complexity tier and industry, delivered in the last 24 months
  • Engagement model: fixed price (stable small scope) / T&M (evolving product) / dedicated team (continuous velocity)
  • References: 2–3 live reference calls, not just written testimonials on a profile page
  • Communication: timezone overlap, named project manager, defined escalation path

Start with clear requirements — before you shortlist anyone

What decides whether your build succeeds? Mostly one thing, and you settle it long before you contact a single vendor: how well you have scoped the work. Study after study on IT projects points the same way. Teams that start from written, agreed requirements ship on time and on budget far more often than teams that hand over a vague brief. Here is the practical test we use. If you cannot lay out the problem, who the users are, and the outcomes you genuinely need in roughly two pages, then no vendor can quote you accurately — however senior their engineers happen to be.

So pin down four things before you draft a shortlist. First, the business outcome the software has to produce. Second, the core user journeys you need for launch — the rest can wait for later phases. Third, your hard constraints: budget ceiling, deadline, compliance obligations, and any existing systems you will have to integrate with. Fourth, how you will judge success in the first 90 days after go-live. This is also the point to decide what kind of engagement you are actually buying. A full product build, an MVP to validate demand, and a team that extends your own engineers each call for a different sort of partner. And when the scoping itself is the hard part, a structured discovery phase with a custom software development partner is what turns a fuzzy idea into a costed, buildable specification.

A clear requirements document earns its keep twice over. It lets you compare proposals like for like, and it quickly separates the vendors who wrestle with your actual problem from the ones who paste in a generic estimate. Pay attention to the questions they ask you back, too — the sharpness of those questions is one of the earliest selection signals you will get.

Good vs cheap: the real trade-off

The $25/hr offshore team and the $65/hr nearshore senior team will both promise to build your product. The gap between them tends to surface around 6 months in, once the easy work is behind you. Vendors who charge below-market rates usually have to make the numbers work somehow, and it shows up as one of these trade-offs:

  • Staffing projects with junior engineers who require intensive oversight
  • Using undisclosed subcontractors, which creates IP chain-of-title risk
  • Omitting security controls, audit logging and compliance architecture (expensive to retrofit)
  • Delivering working demos that mask architectural debt requiring rewrites at scale

Gartner research on IT outsourcing keeps landing on the same finding: rework on low-cost engagements averages 20–40% of total hours. Put numbers to it. On a $150,000 project, 30% rework is an extra $45,000 that never showed up anywhere in the proposal. Then add what it costs your own team to babysit a struggling engagement. Fairly often the “cheap” option ends up more expensive than a properly scoped one with a senior partner.

None of this is an argument for hiring the priciest vendor you can find. The target you actually want to optimise for is value for quality, and that is rarely the same thing as the lowest hourly rate. We work the full economics through in our guide to outsourcing vs in-house development.

Certifications: ISO 27001, SOC 2, GDPR

It is tempting to read certifications as box-ticking. They are not. Each one is independently audited proof that a vendor has actually put specific controls in place. Here is what the main three mean once you get past the acronym:

ISO 27001

This is the international standard for information security management systems, or ISMS. To earn it, a vendor sits through a third-party audit covering its policies, access controls, incident response, supplier management, and physical and cloud security. Accredited bodies issue the certificate, and they come back every year for surveillance audits to confirm it still holds. If your project touches personal data, financial data, or anything regulated, treat ISO 27001 as the price of entry rather than something that sets one vendor apart from another.

SOC 2 Type II

SOC 2 started life as a US audit standard, and today US and EU enterprise procurement teams ask for it routinely. The distinction that matters is Type I versus Type II. Type I is a snapshot taken on a single day. Type II watches the controls run over a stretch of time, usually 6–12 months, which tells you a great deal more. That is the version your security team wants, because it shows the controls were genuinely operating rather than merely written down in a policy binder. For a product that will hold US customer data, SaaS clients, or health records, a SOC 2 Type II vendor is normally a hard procurement requirement. Our article on SOC 2 Type II for SaaS startups walks through what the audit actually covers.

GDPR compliance (Article 28 DPA)

Under the GDPR, any vendor processing the personal data of EU residents on your behalf counts as a “data processor,” and Article 28 says you need a written Data Processing Agreement (DPA) between you. There is no opting out of this, and it cannot be waived. A proper DPA spells out the processing purposes and how long it runs, the categories of data, which sub-processors are involved, how data subject rights get supported, what happens to the data when the contract ends, and your audit rights. Check that it exists before you onboard anyone. Discovering the gap after a breach is the expensive way to learn the lesson.

security certification document review during software vendor due diligence
Reviewing certification documents — ISO 27001 certificate, SOC 2 Type II report, Article 28 DPA — should happen before shortlisting, not after contract signing. Ask for current certificates, not marketing claims.

Security, NDA and IP protection

When you outsource, contract law is what protects your IP and your data. Not goodwill, and not a handshake. A few clauses should stay non-negotiable:

Mutual NDA before spec sharing

If a vendor will not sign an NDA before you hand over technical specifications, walk away — that alone tells you enough. Make the NDA mutual so it protects both sides, have it cover trade secrets and technical know-how, and pin down jurisdiction and remedies. US clients tend to default to Delaware or New York law. EU clients should match the governing law to their primary operating country.

IP assignment clause

Your contract needs a work-for-hire clause that hands every piece of IP created during the engagement to your company, in plain language. Check that it reaches all of it — source code, design assets, documentation, test suites, CI/CD scripts, custom libraries. One more line is worth adding explicitly: make sure the vendor is not quietly folding GPL-licensed open-source components into your deliverables. GPL “virality” can undercut your ability to keep the product proprietary, and you want to know about it before it ships, not after.

Code repository ownership

From day one, code should land in a repository your organisation owns and controls. A setup where the vendor holds the primary repo is one to refuse outright. And write the exit into the contract while you are at it: when the engagement ends, you get every credential, access token, piece of infrastructure config, and deployment script handed back.

Sub-contractor disclosure

Ask, in so many words, whether subcontractors or freelancers will touch the work — and insist on knowing who they are. Every one of them has to be bound by the same NDA and IP-assignment terms you agreed with the vendor. Undisclosed subcontracting is a recurring source of two headaches in particular: fights over who actually owns the code, and security incidents nobody saw coming.

Social proof: case studies and references

Of all the signals you can gather, a vendor’s portfolio and their references predict delivery quality most reliably. So dig into them properly rather than skimming the surface.

Portfolio evaluation

Look for at least two projects that sit in your complexity tier — simple, medium, or enterprise — and your industry vertical, all delivered inside the last 24 months. Recency is doing real work here. A 2018 fintech case study says almost nothing about the team, toolchain, or compliance posture the vendor has today. It is also worth asking a blunt question: are the lead engineers from that showcase project still on the payroll?

software development agency portfolio review meeting with case study documents
Evaluating a vendor’s portfolio in depth — asking about architectural decisions, team composition and post-launch outcomes — reveals far more than reading the case study landing page.

Reference calls

Treat the written testimonials on Clutch or a vendor’s own website for what they are: curated marketing material. A live reference call is a different animal. Ask for 2–3 references from projects of similar complexity, get them on the phone, and work through:

  • Did the project deliver on time and within 15% of initial budget?
  • How did the vendor handle scope changes and unexpected technical challenges?
  • How was communication during the engagement — proactive or reactive?
  • What would you do differently if you engaged them again?
  • Would you hire them again for your next project?

And if a vendor simply cannot put you in touch with a live reference client? That usually means there is something they would rather you did not hear.

Engagement models compared

The engagement model you pick settles who carries the scope risk. It also shapes how the costs are structured and how far the work can bend when requirements move on you.

Model How it works Best for Risk
Fixed price Agreed scope, timeline and price. Changes via formal change requests. Well-defined MVP, short build (<$75k), stable requirements Vendor inflates price to absorb scope risk; spec ambiguity causes disputes
Time & Materials Billed on actual hours and materials. Scope can evolve sprint-to-sprint. Iterative product development, SaaS, discovery-to-build continuity Budget overrun without strong PM oversight; requires active client involvement
Dedicated team Named senior engineers embedded in your delivery team. Monthly retainer. Continuous development, scaling an existing product, long-term engagement Knowledge concentration risk; requires strong in-house product ownership

For most mid-market builds, a hybrid approach works best in practice. Run a fixed-price discovery and architecture phase first (4–6 weeks), then move into T&M delivery sprints capped by a monthly budget. You take the scope risk off the table up front without losing flexibility later. For products that run for years rather than months, a dedicated team working to quarterly objectives strikes the best balance between velocity and accountability.

AI and modern engineering capability (2026)

By 2026, a credible partner has to show you real, shipped work with AI-assisted engineering. A line about it in the sales deck does not count. GitHub’s 2025 Octoverse report put AI-assisted coding in the hands of the overwhelming majority of active developers, and the distance between teams that wield those tools well and teams that do not now lands squarely on delivery speed and cost. Put two questions to every shortlisted vendor. How is AI tooling built into their own workflow — code generation, review, testing? And have they actually shipped production features that use AI, whether that is retrieval, classification, agents, or LLM integration, for a paying client?

Real capability and marketing hype are easy to confuse here, so listen for candour. A strong partner will tell you plainly where AI speeds delivery up and where it does not, will keep code review and IP/licence checks on anything AI generates, and will not let generated code slip past the security practices we covered above. If AI-powered features sit on your roadmap specifically, weight this dimension heavily and vet the partner’s AI, ML & data track record exactly as you would vet any other portfolio claim: references and shipped examples, not slideware.

Red flags to watch for

Any of these patterns should raise your guard, and two or three of them together should raise it a lot:

  • Fixed price quoted without discovery — any vendor who quotes a firm fixed price on a medium or complex system without a 4–6 week discovery phase is either underestimating or hiding scope assumptions that will surface as change requests mid-project.
  • No current ISO 27001 or SOC 2 certificate on request — claiming compliance without being able to produce the certificate is not compliance.
  • References who cannot be contacted directly — written testimonials only, no live contact details.
  • Vendor-controlled code repository — if the vendor owns the repo, you are dependent on them to access your own product at any point, including in a dispute.
  • Vague sub-contractor policy — “we may use partners” without specific disclosure is a data processing and IP risk.
  • Unrealistic timelines relative to scope — a senior team delivering a 4-month build in 6 weeks should raise questions about what is being omitted (testing, security review, documentation).
  • No named project manager — “the team will be your point of contact” is a communication structure that breaks down under pressure.
  • Excessive non-disclosure requests for basic company information — legitimate vendors provide company registration, insurance certificates and financial references; excessive opacity about the business is a due-diligence red flag.

15 questions to ask every software development vendor

Work these into your first pass over the RFP responses and into the follow-up calls. Often the weak, evasive answers tell you more than the polished ones do.

  1. Can you provide your current ISO 27001 certificate and, if applicable, your most recent SOC 2 Type II report?
  2. Do you have a standard Article 28 GDPR Data Processing Agreement, and can we review it before signing?
  3. Who will own the intellectual property of all work delivered — specifically source code, design assets and documentation?
  4. Will any work be performed by subcontractors or freelancers? If so, who are they and what NDA/IP terms are they bound by?
  5. In which repository will our code be held, and will we have full admin access from day one?
  6. Can you provide 2–3 reference clients from projects in our complexity tier we can contact directly?
  7. What is your proposed engagement model for our project, and why?
  8. Who will be the named project manager, and what is your escalation process when issues arise?
  9. What is your engineering team’s average seniority, and what is your current team turnover rate?
  10. How do you handle scope changes under a fixed-price contract?
  11. What security practices are built into your development process (code review, SAST, dependency scanning, penetration testing)?
  12. How do you manage data localisation and processing for EU personal data under GDPR?
  13. What are your standard handover deliverables at end of contract (code, credentials, documentation, knowledge transfer)?
  14. What SLA do you offer on post-launch support and bug fixes?
  15. Can you provide a fully itemised cost breakdown by phase, with explicit assumptions for each line item?

Vendor scorecard template

This weighted scoring matrix gives you a way to compare shortlisted vendors on something firmer than gut feel. Move the weights around to match your own priorities — a regulated business should lean harder on security, while an early-stage startup might value communication and agility more.

Dimension Weight Score 1–5 Weighted score
Technical certifications (ISO 27001, SOC 2, DPA)20%  
Portfolio fit (complexity tier & industry)20%  
Reference quality (live calls, recency)15%  
IP & contract terms15%  
Engagement model & pricing transparency15%  
Communication & timezone fit10%  
Team seniority & retention5%  
Total100%  

Score a vendor below 3.0 on certifications or IP terms and they are out, whatever their total says. These are threshold criteria: you do not trade them off against a strong score somewhere else. Once you have actually picked a partner, our guide to the custom software development process lays out what the rest of the engagement looks like.

FAQ

How do I choose a software development company?

Start with certifications and compliance fit (ISO 27001, SOC 2, GDPR DPA). Review the portfolio for projects in your complexity tier and industry from the last 24 months. Verify IP ownership and NDA terms contractually. Compare engagement models against your scope stability. Run live reference calls — not just written testimonials. Score candidates on a weighted matrix and eliminate any vendor that falls below threshold on certifications or IP terms, regardless of price.

What certifications should a software development vendor have?

ISO 27001 is the baseline for any engagement involving sensitive data. SOC 2 Type II is standard for US enterprise procurement. GDPR Article 28 DPA is mandatory for EU personal data processing. Industry-specific additions: HIPAA for US health data, PCI-DSS for payment processing, ISO 13485 for medical devices. Ask for the actual certificate or audit report, not a marketing claim of “compliance.”

How do I protect my IP and data when outsourcing?

Four contractual protections are non-negotiable: mutual NDA before spec sharing; IP assignment clause transferring all created IP to your company; code held in your own repository from day one; and a GDPR Article 28 DPA if EU personal data is involved. Also require explicit disclosure of any subcontractors and confirm they are bound by equivalent terms. Have legal counsel review all clauses — not just the SOW — before signing.

Fixed price or time and materials for software development?

Fixed price is appropriate for well-defined, stable small builds (typically under $75,000). Time & materials is better for iterative, evolving products where requirements will change during delivery. A dedicated team retainer suits long-running continuous development. The most pragmatic approach for mid-market builds is a fixed-price discovery phase (4–6 weeks) followed by T&M delivery, which combines scope clarity with delivery flexibility.

What are red flags in a software development agency?

Key red flags: fixed price quoted without a discovery phase; no current ISO 27001 or SOC 2 certificate; references who cannot be contacted directly; vendor-controlled code repository; vague subcontractor disclosure; unrealistic timelines relative to scope; no named project manager; and excessive opacity about the company’s legal and financial status.

How do I check references for a software development company?

Ask for 2–3 live reference contacts from projects in your complexity tier delivered in the last 18 months. Call them directly. Ask whether the project delivered on time and budget, how scope changes and problems were handled, whether they would hire the vendor again, and what they would do differently. Cross-reference with Clutch or G2 reviews, but treat live calls as the primary signal — curated written testimonials are not a substitute.

Should a software development company have AI experience?

In 2026, yes. AI-assisted development is now mainstream — GitHub’s 2025 Octoverse reported adoption across the large majority of active developers — and it materially affects delivery speed and cost. Ask a vendor how AI tooling is embedded in their workflow and whether they have shipped production AI features (retrieval, classification, agents, LLM integration) for real clients. Treat AI capability as a portfolio claim to verify with references, and confirm they apply the same security and code-review discipline to AI-generated code as to any other code.

Last updated 8 June 2026. Certification requirements reflect ISO/IEC 27001:2022, AICPA SOC 2 and GDPR Regulation (EU) 2016/679 as of the publication date. Legal requirements vary by jurisdiction; consult qualified legal counsel for contract review.