Vendor shortlist, evaluation matrix, TCO model, contract red-flag review. Fixed-scope, 2–3 weeks. Retainer or one-off engagement.
- Audit
- Architect
- Scale
monthly retainer
Who this is for
You're a non-technical executive deciding on a CMS, analytics platform, payment provider, or AI tool. The vendor's sales team is polished and the demos all look roughly equivalent. You have no one internally who can poke holes in the technical claims, stress-test the contract terms, or model what this actually costs over three years. That's the gap I fill: a software vendor selection consultant with no referral ties to any vendor, whose only job is to give you an honest technical read before the contract goes out.
The pain today
- Vendor sales demos making every option look equivalent
- No internal technical expertise to challenge vendor claims
- A previous vendor choice that turned out wrong — not repeating that
- Contract terms that sound standard but carry hidden data rights and exit traps
- TCO that's hard to pin down when the quoted price and the real bill diverge fast
The outcome you get
- A vendor shortlist built on a scoring rubric, not on sales rapport
- Build vs buy vs partner analysis when the choice isn't obvious
- Contract red-flag review: data rights, SLAs, auto-renewal, exit, liability caps
- 3-year TCO model per vendor including implementation, overage, and migration costs
- Negotiation leverage mapped before the second sales call
Build, buy, or partner — the question before the question
Most vendor-selection requests arrive framed as "which vendor should we pick." Before answering that, I challenge the frame: should you be buying a vendor at all?
Build means custom development owned fully in-house — maximum control, maximum maintenance burden. Right when the capability is a genuine competitive differentiator. Buy means a vendor product replacing an internal capability entirely — minimum control, minimum maintenance. Right when the capability is a commodity (payments, email, transactional analytics). Partner means a joint build or deep integration with a vendor — shared control, shared maintenance. Right when the capability is adjacent to your core but needs specific tuning.
Many vendor-selection engagements are really build/buy questions in disguise. I surface that early. Sometimes the right answer is "don't hire a vendor; this function shouldn't exist as a product yet." That saves more money than a good vendor choice does.
A vendor shortlist built on a scoring rubric, not on sales rapport
How I structure a vendor evaluation
A structured software vendor evaluation has four layers. First, requirements: what does the system actually need to do, ranked by priority — not a wish list, a weighted set of must-haves and nice-to-haves. Second, vendor qualification: a scored criteria matrix covering functional fit, technical integration requirements, security and compliance posture (SOC 2, ISO 27001, data residency), vendor financial health, support model, and roadmap alignment. Third, TCO modeling: 3-year total cost per vendor, built from implementation fees, per-seat or usage-based pricing, projected overages, integration work, and eventual migration cost. Fourth, contract review: a 15-20 item red-flag checklist applied to every shortlisted vendor's contract before any negotiation begins.
I join vendor demos when useful — the dynamic changes when a technical person is in the room asking questions the sales team hasn't heard before. I've seen vendors quietly revise their SLA terms after a 20-minute demo debrief.
40+: Payment providers integrated.
Contract terms I push back on every time
Vendor contracts run through a consistent set of traps. Here are the ones I flag on nearly every engagement.
Data rights: default contracts frequently grant vendors broad rights to use your data for "service improvement" and model training. The fix is limiting those rights to pure service delivery only. SLAs: a 99% uptime guarantee equals roughly 7 hours of downtime per month. For production systems, I target 99.9% or higher, with defined financial penalties, not just credits. Auto-renewal: contracts with 90-day notice windows are common. I push for 30-day notice, and I flag the renewal date on the first day of the engagement. Exit clauses: "you get 60 days of data export on termination" is the standard; I negotiate 90 days plus documented migration assistance. Liability caps: most vendors cap liability at one month of fees. For mission-critical systems, I target 12 months' fees as the cap. Termination for convenience: some vendors forbid it outright. It belongs in every contract.
TCO modeling: where the headline price falls apart
The sticker price is usually the least important number in a vendor comparison. The costs that determine true TCO are mostly invisible until you're 18 months in.
Implementation: vendor onboarding fees ($2k–$20k per week depending on the platform), internal team time allocated to the project, and any second-vendor integration work. Ongoing: per-seat fees that escalate faster than your headcount, overage charges on API calls, transactions, or active users that only appear after you hit scale, and add-on modules that turn out to be essential but weren't in the demo. Migration: exit costs when you eventually leave, which every vendor makes as painful as possible by design.
I build a 3-year TCO model per finalist. In most engagements the cheapest headline-price vendor is not the cheapest at 36 months. I've seen cases where the vendor with 2x the monthly cost works out 40–50% cheaper when onboarding, integration engineering, and likely exit costs are priced in honestly.
When to run an RFP versus direct vendor outreach
An RFP (request for proposal) is the right tool in a narrow set of situations: the buyer has well-defined, documented requirements; multiple qualified vendors exist; and the evaluation needs to be defensible to a board or procurement committee. For most early-stage and growth-stage companies I work with, a structured RFP is overkill. It takes 8–12 weeks, vendors submit polished proposals that tell you less than a 2-hour technical demo, and the process delays a decision that could have been made faster and better.
Most of my vendor work runs as direct-outreach evaluation: define requirements, build a shortlist of 3–5 vendors, run structured demos with a scoring sheet, model TCO, and review contracts. That process takes 2–3 weeks, not 10. If your situation genuinely requires an RFP — regulatory requirement, public procurement, or board-mandated process — I can structure and manage that as a longer engagement.
Real-world context: 40+ vendor integrations at bolttech
At bolttech — a $1B+ unicorn operating across 15+ markets with 40+ payment providers integrated — vendor selection was continuous work, not a one-time event. Every new market required local payment provider relationships. Every regulator required specific partner certifications. Every product line involved build/buy tradeoffs under deadline pressure.
The evaluation framework I use today comes directly from that experience. Structured scoring beats sales-team persuasion every time. TCO matters more than headline price. Contract discipline — especially exit clauses and data rights — prevents expensive problems years later. The principles are the same at a 10-person startup as at a $1B+ unicorn; the volume differs, the discipline doesn't.
Scope, pricing, and when to skip this engagement
Single-decision vendor reviews (one category, 3–5 shortlisted vendors) fit a 2–3 week fixed-scope engagement under the Fractional CTO service at $5,499/mo. Larger vendor programs — category-wide strategy, multi-vendor RFPs, enterprise procurement support — fit an ongoing retainer.
Deliverable: requirements document, scored evaluation matrix, 3-year TCO model per vendor, contract red-flag review, negotiation strategy memo. 14-day money-back if the deliverable doesn't change how you approach the decision. Work Made for Hire on all written output.
Not every vendor decision needs this. Under $5k/year SaaS tools where you have strong internal familiarity, or vendors with 5+ peer references from companies at exactly your stage — those don't warrant consulting overhead. I'll tell you that in the first call. The engagement economics only make sense above roughly $20k/year per vendor, for mission-critical categories, or where the contract terms have multi-year exit implications.
Recent proof
A comparable engagement, delivered and documented.
Unified payment orchestration across Asia and Europe
Delivered the payment orchestration platform at bolttech, a $1B+ unicorn, with 40+ integrations across multiple regions.
Read the case studyKeep reading
Frequently asked questions
The questions prospects ask before they book.
A vendor's sales engineer is paid to make that vendor win. I have no referral relationships with any vendor — no affiliate fees, no implementation partnerships. My incentive is a deliverable that's useful to you: a shortlist you can defend, a TCO model that holds up 18 months later, and a contract you didn't sign with your eyes closed. The sales engineer knows the product better than I do; I know the red flags they won't flag.
Yes, and that's often where the engagement earns its fee. Vendor sales teams behave differently when a technical person is in the room asking questions about SLA penalty structures, API rate limits, and data residency compliance. I ask things your team doesn't know to ask, catch claims that deserve scrutiny, and translate what was said into what it actually means contractually and technically.
In rough order of how often they cost customers money: broad data rights (vendor can use your data for model training), 99% SLAs (which allow 7+ hours/month downtime), 90-day auto-renewal notice windows, exit clauses that give you only 30–60 days of data export, and liability caps set at one month's fees. I work through a 15-20 item checklist on every contract before any negotiation starts.
Single-category reviews with 3–5 shortlisted vendors take 2–3 weeks: week one for requirements and scoring framework, week two for vendor demos and technical evaluation, week three for TCO modeling, contract review, and the recommendation memo. Multi-category or RFP-based engagements run 6–10 weeks. Either way, the output is a specific recommendation with documented reasoning, not a list of options with pros and cons.
A post-signature review can still surface negotiation leverage for the renewal window or identify terms worth amending. Most SaaS contracts have annual renewals; catching problems 6 months before that window gives time to improve terms or plan a switch. Post-signature work is reactive, pre-signature is preventive — but both are worth running if the contract is mission-critical.
Below roughly $5k/year per tool, or when you have genuinely strong internal familiarity with the vendor category. If five peers at similar-stage companies all use the same tool and it's working, that social proof often outweighs independent analysis at that price point. I'll say so in the first call. Consulting overhead erases ROI on small decisions — my value is in the $20k+ annual contracts where the contract terms, TCO, and switching costs actually matter.