Vendor Selection Criteria and Process: What to Check Before You Sign

Vendor Selection Criteria and Process: What to Check Before You Sign

Vendor selection is the work of deciding which supplier to trust with a purchase, and checking that what it tells you is true. This guide covers vendor selection criteria for software and IT services, the evidence that proves each one, due diligence, red flags and a short version of the process. To turn the criteria into scores, use it alongside the RFP evaluation criteria guide.

The vendor selection process in brief

Vendor selection is one part of the wider procurement process, which runs from a need to a paid invoice.

  1. Define your needs, must-haves and budget range with every team the purchase affects.
  2. Build a long list from peers, industry groups, review sites and current suppliers.
  3. Narrow it with an RFI, or ask for quotes if the requirement is fully specified.
  4. Run an RFP when the purchase is complex, costly or hard to reverse, or your policy requires one.
  5. Evaluate responses against criteria set in advance, then test finalists with scripted demos and, if needed, a proof of concept.
  6. Run due diligence on your preferred vendor.
  7. Negotiate price, terms, service levels and the statement of work.
  8. Select the vendor, notify every bidder and offer debriefs.
  9. Onboard the vendor. After the contract is signed, track its performance with the vendor scorecard template.

The RFP process guide covers each step in detail, with an example timeline.

Vendor selection criteria: what to look for

Answer these questions about any vendor, whichever document you use to buy. The evaluation criteria guide covers weighting and scoring; this section covers what a good answer looks like.

Fit to your requirements

Can the product do your work, the way your teams do it, in the edition you’re paying for? Test it on your hardest scenarios.

Total cost of ownership

This is everything the purchase will cost over its life, including costs missing from the vendor’s pricing sheet: your staff’s time, a separate implementation partner, integration work and the cost of leaving. Compare the full term, renewal increases included.

Implementation capacity and the actual team

Who will do the work: the vendor, a partner or subcontractors? Have they delivered projects like yours, and are they free on your dates? For ERP, the ERP selection guide covers choosing the implementation partner.

Support and service levels

Look at support hours, response and resolution targets by severity, the uptime commitment, and what the vendor owes you when it misses one. Read the service level agreement (SLA) itself, exclusions included.

Security and compliance

Know where your data will be stored, who can access it, how you’d hear of a breach, and which laws and industry rules apply. Your security team sets the bar.

Financial stability

Will the vendor still be operating, and investing in the product, when your contract ends? Watch for ownership changes too. An acquisition can change the roadmap, the support team or the renewal price.

References and track record

Has the vendor done this for organizations of your size, industry and scope? Past customers can tell you how it behaves when something goes wrong, which no proposal will.

Contract terms and exit

Look for caps on renewal increases, termination rights, ownership and return of your data in a usable format, exit help and liability limits. Read the terms before you choose, including any online terms the vendor can change on its own.

Subcontractors and dependence on one supplier

Find out who else handles your data or does part of the work, such as subcontractors and hosting providers. You take on their risk, usually without a contract with them. If you can’t operate without this vendor, you need its tested continuity plan and an exit plan of your own.

Vendor selection checklist: what to ask for and how to verify it

The last column is how you test each claim instead of taking it on trust.

Criterion What to ask for How to verify it
Fit to requirements A response code on every requirement; your demo script, run with your data Check the demo covers every scripted step; run a proof of concept for what a demo can’t prove
Total cost of ownership One-time, recurring and renewal costs for the term; pricing assumptions; exit costs Add your internal and third-party costs; confirm every vendor priced the same scope
Implementation team Names, roles and availability of the key people, and which work for a partner or subcontractor Interview the proposed lead; name key staff, and your right to approve replacements, in the statement of work
Support and service levels The SLA, the support terms and the escalation path Read the definitions and exclusions; ask references about escalations
Security and compliance Your security questionnaire, completed; an independent audit report on the vendor’s controls, or a certificate against a recognized security standard Have your security team check the scope, the period covered and any exceptions found
Financial stability Audited financial statements, or financial information under a nondisclosure agreement Have finance review them; consider a business credit report; look for news of a sale or restructuring
References Customers of similar size, industry and scope Call customers you found yourself as well as the vendor’s choices
Contract terms and exit The full contract set, including any linked terms, and the vendor’s exceptions to yours Legal review before you select; exit terms written into the contract
Subcontractors and dependence Subcontractors and other companies handling your data, with roles and locations; the continuity plan Ask when the plan was last tested; require notice before a subcontractor changes

Due diligence before you sign

Due diligence confirms what the vendor has told you and looks for risks it hasn’t mentioned. Run it before you finish negotiating, so what you find can still go into the contract.

  • References you choose. Vendors offer customers they’re confident about, so find your own through the vendor’s customer list or your peers, and ask each how the vendor handled a problem. A former customer, if you can find one, can tell you how leaving went.
  • Financial information. Listed companies publish audited annual reports. A private company may share statements under a nondisclosure agreement; if not, a business credit report gives a partial view.
  • Security documentation. Read the vendor’s latest independent audit report or security certificate rather than filing it. Check that it covers the service you’re buying and a recent period, and read any exceptions the auditor found. Some reports list controls the customer is expected to run itself; make sure you can.
  • Insurance certificates. Ask for a certificate of insurance showing each type of coverage your contract requires, such as professional or cyber liability, with limits and policy dates. Check it against the amounts your legal or risk team sets, and note the expiration date.

If you’re buying with public or grant money

Public buyers often have to confirm that a contractor is responsible before awarding. For US federal contracts, FAR 9.104-1 lists general standards that include adequate financial resources or the ability to obtain them, a satisfactory performance record, a satisfactory record of integrity and business ethics, and the necessary organization, experience, accounting and operational controls, and technical skills, or the ability to obtain them. Under 2 CFR 200.318(h), federal award recipients and subrecipients, other than states and Indian Tribes with their own procurement policies, must award contracts only to responsible contractors, considering factors that include integrity, past performance, and financial and technical resources. State and local rules vary, so check with your procurement office or legal counsel.

FAR and CFR references are to the text on acquisition.gov and eCFR as of October 2026. The FAR is being rewritten under the Revolutionary FAR Overhaul, and agencies can apply deviations, so check the current text before relying on a section number. This isn’t legal advice.

Red flags

Any of these can have an innocent explanation. Ask about each one and record the answer.

  • Nobody will name the delivery team, or the names change after you’ve chosen.
  • Every requirement is answered “standard”, with no detail.
  • The vendor won’t run your demo script, or resists a proof of concept.
  • A discount that expires before due diligence can finish.
  • A low price resting on a long list of assumptions, or no cap on renewal increases.
  • Security documents withheld, out of date or about a different service.
  • Promises from the proposal that the vendor won’t put in the contract.

When you don’t need a full RFP

An RFP costs you and every bidder weeks of work. RFP vs RFQ vs RFI compares the alternatives.

  • The requirement is fully specified and only price differs. Ask for quotes with the RFQ template, or in public sealed bidding, issue an invitation to bid.
  • The purchase is small and low-risk. Your policy may allow a few quotes, or a direct purchase, below a threshold it sets.
  • It’s a renewal or add-on to a product you already use. Negotiate with the current vendor after reviewing its terms and performance.
  • Only one supplier can meet the need. Document why and get the approvals your rules require; see the sole source justification guide.

The checks in this guide still apply without an RFP. Scale due diligence to the risk of the purchase: an inexpensive tool that will hold customer data still needs a security review.

Frequently asked questions

What are vendor selection criteria?

They’re the factors you judge a vendor on before buying: fit to your requirements, total cost of ownership, the implementation team, support, security, financial stability, references, contract terms and risk. Decide in advance what evidence you’ll accept for each.

What are the steps in the vendor selection process?

Define your needs, build a long list, narrow it with an RFI or quotes, and run an RFP if the purchase warrants one. Then evaluate, run due diligence, negotiate, select and onboard. Small purchases can combine or skip steps.

Is supplier selection the same as vendor selection?

In practice, yes. Both mean choosing who to buy from and checking that they can deliver. The same criteria and checks apply whichever word your purchasing policy uses.

How many vendors should you evaluate?

Enough for real competition, and few enough to evaluate each one properly. For a software RFP, a shortlist of three to five is a workable size, narrowing to two or three finalists after scoring.

What is vendor due diligence?

It’s the checks you run before signing to confirm what a vendor has told you and find risks it hasn’t mentioned. Common ones are references you choose yourself, financial information, security documentation and insurance certificates, scaled to the risk of the purchase.