- Vendors with senior capacity can start engineers within 10 business days and replace them within 2 weeks if needed, while those requiring 4+ weeks lack bench availability.
- Mature vendors report 10-20% median project delay rates and explain root causes, whereas vendors claiming 100% on-time delivery have no delivery metrics or accountability.
- ISO 27001 or SOC 2 certified vendors pass security questionnaires during procurement reviews, while uncertified vendors block deals when customers audit your vendor list.
Why This List Matters
European SMBs hiring custom software vendors face a decision that can determine whether a project delivers on time or becomes a multi-year budget drain. The CHAOS Report 2025 found that only 29% of software projects deliver on time and budget, while 19% fail outright. For SMBs with 50 to 500 employees, a failed software project does not just delay revenue; it consumes senior leadership time, burns engineering capacity, and creates technical debt that blocks future growth.
This decision is especially high-stakes in regulated industries. Financial services, healthcare, and insurance companies selling into enterprise customers face procurement reviews that audit vendor security, continuity planning, and compliance certifications. A vendor without ISO/IEC 27001:2022 Information Security Management or documented GDPR Article 32 compliance can block deals at the final stage, even if the software works perfectly.
These 9 questions separate vendors who can deliver from those who cannot.
1. Do You Have Senior Engineers Available Within 10 Business Days?
Best for: European SMBs who cannot afford 6-month hiring cycles and need senior engineering capacity immediately.
What it is: The ability to start experienced engineers (8+ years in production systems) within 10 business days, fully onboarded to your Git workflow, CI/CD pipeline, and sprint cadence within 2 weeks. This is not a recruitment promise. This is proven bench capacity.
Why it ranks here: Time to value separates vendors with real capacity from those who start recruiting after you sign. According to The Forrester Wave: Modern Application Development Services, Q1 2025, vendors in this space must demonstrate global service delivery capability across multiple regions. Vendors without bench capacity cannot start projects quickly, forcing you into long delays while they hire.
Senior engineers cost €5,000 to €6,000 per month in European markets. Vendors offering €3,000 to €4,000 rates are substituting junior engineers who require mentorship and create technical debt.
Implementation Reality
Timeline: Engineers start within 10 business days, onboard to your tooling in 1 to 2 weeks
Team effort: 4 to 6 hours from your side for onboarding (Git access, Slack invites, sprint intro)
Ongoing maintenance: Zero additional overhead beyond normal code review and sprint ceremonies
Clear Limitations
- Vendors with true bench capacity charge premium rates (€5,000+ per month)
- Starting in under 10 days requires vendor to maintain idle capacity between projects
- Niche technology stacks (legacy COBOL, obscure frameworks) may require longer sourcing
2. How Do Your Engineers Integrate With Our Existing Team and Tooling?
Best for: SMBs with established development workflows who need external engineers to work inside their processes, not alongside them.
What it is: Vendors offering embedded engineers place senior developers directly inside your sprint cadence, tooling, and delivery infrastructure. These engineers commit to your GitHub repos, attend your standups, use your Jira boards, and deploy through your CI/CD pipelines. Contrast this with external team models, where vendors maintain separate project management tooling, communication channels, and deployment infrastructure, creating handoff friction at every integration point.
Why it ranks here: Integration overhead directly impacts delivery velocity. Research from the British Computer Society documents that context switching between tooling environments costs 20 to 30 percent of developer productivity. When external vendors maintain parallel infrastructure (separate Slack workspaces, duplicate Jira instances, isolated Git repos), your internal team loses hours per week translating requirements, reconciling statuses, and coordinating deployments. Embedded engineers eliminate this tax by appearing as teammates in your commit history, pull requests, and code reviews.
Implementation Reality
Timeline: Embedded engineers onboard to your tooling and processes within 5 to 10 business days. External teams require 3 to 4 weeks to establish parallel infrastructure and integration points.
Team effort: Your internal team invests 10 to 15 hours during onboarding (access provisioning, workflow walkthroughs, coding standards review). External teams require ongoing coordination effort (2 to 4 hours per week for status syncs, handoff meetings, and deployment coordination).
Ongoing maintenance: Embedded engineers require no additional tooling overhead. External teams add 15 to 20 SaaS tools to your environment (Gartner estimates median software teams already use 15 to 20 tools, doubling this burden increases license costs and security surface area).
Clear Limitations
3. What Security Certifications Do You Hold (Not Just Support)?
Best for: European SMBs selling into regulated customers (financial services, healthcare, government) where vendor security questionnaires block deals without formal certifications.
What it is: Vendors who hold ISO/IEC 27001:2022 Information Security Management or SOC 2 Trust Services Criteria certifications operate certified secure infrastructure and pass procurement reviews. Vendors who only "support implementation" lack certified processes and may block deals when your customers audit your vendor list.
Why it ranks here: Security certifications are mandatory gates in regulated procurement. Without certifications, your vendor becomes a deal blocker.
Implementation Reality
Timeline: ISO 27001 certification takes 6 to 9 months for vendors to obtain. SOC 2 Type II attestation takes 9 to 12 months.
Cost signal: ISO 27001 certification costs €15,000 to €30,000 for SMBs. Vendors without it have not invested in security infrastructure.
Ongoing maintenance: Annual surveillance audits and continuous control monitoring.
Clear Limitations
- Certification proves documented processes exist, not that engineers follow them perfectly
- Some certifications (SOC 2) are self-selected scope, vendors can exclude inconvenient controls
- Certifications expire or lapse if vendors do not maintain compliance
Choose this option if:
- You sell into financial services, healthcare, or government sectors requiring vendor audits
- Your customers send security questionnaires during procurement (ISO 27001 answers 80% of questions)
- You handle EU customer data and need vendors with signed GDPR Article 32 on security of processing compliant Data Processing Agreements
4. What’s Your Median Project Delay Rate and Why?
Best for: Risk-averse SMBs evaluating vendor track record and delivery discipline.
What it is: Honest vendors track and disclose median project delays. A vendor claiming "100% on-time delivery" either has no metrics or is lying. The PMI Pulse of the Profession 2025 found that only 58% of projects meet original goals and business intent. Mature vendors report 10-20% timeline variance and explain root causes (scope creep, dependency delays, discovery unknowns). Vendors who won't share delay data have no delivery accountability.
Why it ranks here: Delivery predictability separates vendors who can execute from those who cannot. This question forces vendors to reveal whether they track velocity, burndown, and cycle time metrics or rely on gut feel and optimism. Timeline variance is a proxy for process maturity.
Implementation Reality
Timeline: Request delay metrics during initial vendor calls (week 1)
Team effort: 2-3 hours analyzing vendor responses and reference calls
Ongoing maintenance: Track actual delivery variance quarterly to validate vendor claims
Clear Limitations
- Vendors with fewer than 10 recent projects may lack statistical significance
- Delay metrics don't reveal quality issues or technical debt accumulation
- Some variance is unavoidable due to scope changes or external dependencies
Choose this option if:
- Your project timeline is fixed due to funding rounds, regulatory deadlines, or market windows
- Previous vendor engagements failed due to missed deadlines
- You need predictable delivery to coordinate internal resources (product, marketing, sales)
5. How Do You Handle Intellectual Property and Code Ownership?
All custom code, designs, and deliverables should belong to you upon payment. Vendors who retain IP rights or claim 'shared ownership' can block future development, demand ongoing licensing fees, or prevent you from switching vendors. Insist on full IP assignment in the contract.
Best for: Companies building proprietary software assets where code ownership directly affects company valuation and exit readiness.
What it is: A contractual provision specifying that all work product (source code, documentation, designs, configurations, and related intellectual property) transfers to you as the client upon final payment. This is distinct from licensing arrangements where you gain usage rights but the vendor retains ownership.
Why it ranks here: IP ownership disputes surface late in vendor relationships, typically when you attempt to switch vendors, bring development in-house, or undergo due diligence for investment or acquisition. By that point, renegotiation is expensive or impossible. According to WIPO guidance on IP transfer in software contracts, explicit written assignment is the only reliable protection. Verbal assurances and implied ownership do not hold up in European contract law.
Implementation Reality
- Timeline: IP assignment clauses should appear in the initial contract, not negotiated later
- Team effort: Legal review adds 4-8 hours to contract negotiation
- Ongoing maintenance: No ongoing burden once documented correctly
Clear Limitations
- Vendor reusable components: Some vendors use proprietary frameworks or libraries they've built across multiple clients. These typically remain vendor property, but the custom code built on top should be yours.
- Open source dependencies: Code built using MIT, Apache, or similar licenses remains under those licenses. You gain ownership of the custom application code, not the underlying libraries.
- Third-party integrations: APIs and services you integrate with (Stripe, Twilio, AWS) remain owned by those providers. You own the integration code.
When it stops being the right choice: If you're building a proof-of-concept or temporary system with a planned 6-12 month lifespan, shared IP or vendor-retained ownership may reduce upfront costs.
6. What Happens If an Engineer Leaves Mid-Project?
Vendors should guarantee engineer replacement within 2 weeks at no additional cost. Vendors who cannot replace engineers quickly either lack bench capacity or use freelancers who are not accountable to the vendor. Insist on a swap guarantee in the contract.
Best for: SMBs running critical projects where delivery timeline matters more than individual engineer continuity.
What it is: A contractual commitment that if any assigned engineer leaves, becomes unavailable, or proves to be a poor fit, the vendor provides a replacement engineer within 14 days at no additional cost. The replacement engineer receives knowledge transfer from documentation and code reviews, not from the departing engineer.
Why it ranks here: This question separates vendors with true bench capacity (engineers on staff, ready to deploy) from marketplaces that connect you to freelancers. Freelancers answer to themselves, not the vendor. If a freelancer walks away, the marketplace has no obligation or mechanism to replace them quickly. Staffing agencies with bench capacity can swap engineers because they employ them directly.
Implementation Reality
Timeline: Replacement should occur within 10-14 business days from notification
Team effort: 5-10 hours for knowledge transfer (code walkthrough, documentation review, tooling access)
Ongoing maintenance: None if vendor maintains documentation standards throughout the engagement
Clear Limitations
- Knowledge loss is inevitable: Even with documentation, the replacement engineer will not have the same context as the original engineer for 2-4 weeks
- Not a free pass: Frequent engineer swaps (more than 1 per quarter) indicate either poor vendor screening or unrealistic client expectations
- Documentation dependency: If the original engineer did not document decisions and architecture, replacement cost increases significantly
When it stops being the right choice: For engagements under 3 months, engineer replacement guarantees matter less because the relationship is too short to justify swap overhead.
7. How Do You Prevent Scope Creep and Budget Overruns?
Vendors with formal change control processes document every scope addition, assess impact on timeline and budget, and require written approval before work begins. Vendors without change control let scope drift silently, then demand budget increases or extend deadlines without warning. According to the PMI Pulse of the Profession 2025, scope creep accounts for 43% of project failures when change control is absent.
Best for: Fixed-price contracts, regulated environments requiring audit trails, and SMBs with limited contingency budgets.
What it is: A documented process where any deviation from the original scope triggers a formal change request. The vendor provides impact analysis (cost, timeline, dependencies), you approve or reject in writing, and the project plan updates accordingly. This creates a paper trail showing what was agreed, when it changed, and why.
Why it ranks here: Change control separates vendors who manage projects from vendors who let projects manage them. Without this discipline, a €50,000 project becomes €75,000 with no clear explanation of what changed or why you are paying more.
Implementation Reality
Timeline: Change control is active from contract signature. First change request typically appears within 2-3 weeks as requirements clarify.
Team effort: Reviewing change requests takes 1-2 hours per request. Expect 3-5 change requests on a 6-month project.
Ongoing maintenance: Change log becomes project documentation. Review monthly to track scope evolution.
Clear Limitations
- Change control adds 2-3 days to approve scope changes (slows agile iteration)
- Requires disciplined requirements documentation upfront
- Does not prevent scope creep, only makes it visible and controllable
- Vendors may resist formal change control if their sales process was loose
8. What’s Your Incident Response and Business Continuity Plan?
Vendors should have documented incident response procedures and business continuity plans verified through ISO/IEC 22301 certification or equivalent frameworks. If a vendor's infrastructure fails, your project should continue with minimal disruption. Vendors without continuity plans will leave you stranded during outages, staff shortages, or regional disruptions.
Best for: Critical projects where downtime directly impacts revenue, regulated data systems requiring continuous availability, or multi-region operations needing geographic redundancy.
What it is: A business continuity plan documents how a vendor maintains operations during infrastructure failures, personnel emergencies, or regional disruptions (power outages, natural disasters, pandemics). ISO/IEC 22301 certification proves these plans exist and are tested annually.
Why it ranks here: COVID-19 proved that unpredictable disruptions occur. Vendors without continuity plans disappeared for weeks during lockdowns, leaving projects frozen.
Implementation Reality
Timeline: Request and review continuity documentation during vendor evaluation (1-2 weeks)
Team effort: Verify vendor holds ISO/IEC 22301 certification or can provide documented continuity procedures (2-4 hours)
Ongoing maintenance: Annual continuity plan reviews with vendor (4 hours per year)
Clear Limitations
- Vendors claim "we've never had an outage" without documented backup procedures
- No backup communication channels defined (if Slack fails, how do you reach engineers?)
- Engineers work from single geographic region without redundancy
- No documented Recovery Time Objective (RTO) or Recovery Point Objective (RPO)
Choose this option if:
- Your project handles revenue-generating systems where 4+ hours of downtime costs €10,000+
- You operate in regulated industries requiring continuous data availability (financial services, healthcare)
- Your customers audit your vendor list for business continuity compliance
- You need geographic redundancy because your customer base spans multiple EU regions
9. Can You Provide References From Similar Projects in Our Industry?
Best for: Verifying vendor claims with evidence from clients who faced similar technical constraints, regulatory requirements, or integration complexity.
What it is: Request 2 to 3 reachable client references who completed projects in your industry within the last 18 months. References should confirm delivery quality, budget adherence, communication effectiveness, and willingness to re-engage the vendor.
Why it ranks here: This is the final validation step after evaluating all other criteria. Vendors can claim certifications, processes, and capabilities, but references prove whether those claims translate into delivery outcomes. According to the CHAOS Report 2025 from the Standish Group, projects with vendor references from similar contexts have 30% higher on-time delivery rates than projects with generic or no references. Industry-specific references demonstrate the vendor understands regulatory constraints (GDPR for data-heavy applications, PCI-DSS for payment systems, HIPAA for healthcare platforms) and technical patterns (multi-tenancy for SaaS, high-frequency trading for fintech, real-time data pipelines for IoT).
Implementation Reality
Timeline: Contact references within 1 week of vendor providing contact details. Schedule 20 to 30 minute calls with each reference.
Questions to ask:
- Did the vendor deliver within 10% of original timeline and budget?
- How did they handle scope changes and unexpected technical discoveries?
- Would you hire them again for a similar project?
- What surprised you, positive or negative?
Ongoing validation: For multi-year engagements, request updated references every 12 months to verify sustained delivery quality.
Clear Limitations
- NDA excuse: Legitimate NDAs allow anonymized references (company size, industry, project scope without naming the client). Vendors refusing all references cite NDAs to hide dissatisfied clients. – Stale references: Projects from 3+ years ago reflect outdated practices. Insist on references from the last 18 months.
When Lower-Ranked Options Are Better
Regulated industries with strict audit requirements: If you operate in financial services, healthcare, or government sectors, prioritize vendors holding ISO/IEC 27001:2022 Information Security Management and SOC 2 Trust Services Criteria certification over vendors promising faster start times. Procurement reviews will block uncertified vendors regardless of technical capability. This typically applies to companies storing customer financial data, processing payments, or handling protected health information.
Early-stage startups prioritizing speed over governance: If you are pre-seed or seed stage with fewer than 10 employees and need to validate product-market fit within 3 months, embedded engineers with formal change control processes may slow iteration velocity. A smaller agency willing to pivot quickly without documentation overhead can deliver faster, accepting technical debt as an intentional tradeoff. This approach stops working once you reach Series A and need to pass customer security reviews.
Fixed-scope projects under €50,000 with clear requirements: If your project has fully documented requirements, no integration dependencies, and a defined 8-12 week timeline, a fixed-price contract with an external team may reduce risk compared to time-and-materials embedded engineers.
Real-World Decision Scenarios
Scenario 1: Series A Fintech with Regulatory Pressure
Profile:
- Company size: 35 employees
- Revenue: €4.2M annually
- Target market: EU financial services
- Current state: MVP live, no ISO 27001 certification
- Growth stage: Series A funded, enterprise sales pipeline stalled
Critical questions: Q3 (security certifications), Q6 (engineer replacement), Q8 (business continuity)
Rationale: Enterprise buyers require vendor security evidence before procurement approval. Without ISO 27001 certified partners, deals stall at legal review. Engineer replacement guarantees prevent single points of failure during compliance audits.
Expected outcome: Vendor passes security questionnaires within 2 weeks, unblocking €450K deal pipeline.
Scenario 2: Bootstrapped SaaS Platform Scaling to 100 Customers
Profile:
- Company size: 12 employees
- Revenue: €1.8M annually
- Target market: European SMBs
- Current state: Monolithic Rails app, manual deployments
- Growth stage: Product-market fit achieved, scaling operations
Critical questions: Q2 (tooling integration), Q4 (project delays), Q7 (scope creep prevention)
Rationale: Embedded engineers working inside existing Git workflows and Slack channels reduce onboarding overhead.