← All posts

How to Evaluate a New SaaS Vendor: A Due Diligence Checklist

July 17, 2026

A mid-market team evaluating a new vendor usually has one person pushing hard for the tool and no one assigned to slow the process down. That imbalance is where bad contracts get signed: a security gap goes unchecked, an auto-renewal clause gets missed, and the total cost turns out to be 40% higher than the number in the sales deck. A structured due diligence checklist, run the same way for every purchase, closes that gap without adding weeks to the timeline.

The scale of the problem

Third-party risk has grown faster than most procurement processes have kept up with. According to Verizon's 2025 Data Breach Investigations Report, breaches involving a third party jumped to 30% of all breaches in 2025, up from roughly 15% the year before, the largest single-year shift the report has recorded. SecurityScorecard's 2025 Global Third-Party Breach Report puts the number even higher: 35.5% of breaches now trace back to third-party access, and the average third-party breach costs $4.91 million to remediate, about 40% more than a comparable internal breach. A single vendor breach now produces an average of 5.28 downstream victims, meaning the fallout rarely stays contained to the vendor and the buyer alone.

The buying process itself has also gotten more crowded without getting more rigorous. Gartner research shows the average buying committee for a SaaS purchase above $100,000 in annual contract value now runs 11 stakeholders, up from 8.2 in 2024 and 5.4 in 2014. More people in the room does not translate to more scrutiny. In practice, it usually means the diligence work gets spread across enough people that no single person owns it, and pieces fall through.

Meanwhile, a large share of new vendor relationships start with no formal review at all. Research from SaaS management platform Zylo finds that unsanctioned software purchases make up only about 4% of total SaaS spend at the average company, but account for roughly 34% of the SaaS portfolio by number of applications, and that shadow spend has roughly doubled year over year. For a finance or operations lead, the practical read is blunt: the vendor that feels safest, the tool a department head has already fallen in love with, is often exactly the one most likely to skip a review, because the review looks like friction on a decision everyone has already made emotionally.

Why most mid-market vendor evaluations fail

Vendor evaluations rarely fail because nobody cares about risk. They fail because of a handful of structural gaps that show up the same way at almost every mid-market company.

No single owner. Evaluation gets split across whoever happens to be in the deal's Slack thread: the requesting department, someone in IT, occasionally finance. Nobody has the authority, or the mandate, to say no.

No tiering. A $2,000-a-year scheduling tool and a $150,000 platform that will hold customer financial records go through the same ad hoc process, or more often, neither goes through any process at all.

Compressed timelines. Budget cycles or a looming contract deadline get fixed before diligence starts, so when time runs short, the diligence step is what gets cut, not the deal.

Security review as formality. A security questionnaire gets sent and then ignored while contract negotiation moves ahead in parallel, so by the time an answer comes back, the deal has already been agreed to in principle.

Nothing gets written down. Without a saved record of what was checked and what was waived, the next evaluation starts from zero, and the same mistakes repeat with a different vendor.

The due diligence checklist: what to check before you sign

Start by tiering the vendor. The depth of the review should match what the vendor actually touches, not how loud the internal advocate is.

Tier What it touches Review depth
Tier 1 Customer PII, financial records, or production systems Full security review, SOC 2 Type II required, legal review of the data processing agreement
Tier 2 Internal business data only, no customer PII, limited system access Standard security questionnaire, contract review by procurement or finance
Tier 3 No sensitive data, isolated tool, easily replaced Lightweight checklist, single-owner sign-off

Once you know the tier, work through seven areas. Tier 1 vendors need all seven in depth; Tier 3 vendors can move through most of this in an afternoon.

Security and data handling. Confirm what data the vendor will store, process, or transmit, and check that it matches what the tool actually needs to do its job, not what it could theoretically collect. Ask where data is hosted and whether that location satisfies any regulatory obligations you carry, such as GDPR for European customer data. Request the vendor's SOC 2 Type II report, not Type I: Type II demonstrates the controls worked over a period of months, not just that they existed on a single day. Check the audit period is current (within the last 12 months) and read the auditor's opinion for exceptions, not just the cover page.

Compliance and certifications. Beyond SOC 2, check whether the vendor holds certifications relevant to your industry: ISO 27001 for general information security, HIPAA attestations for healthcare data, PCI DSS if payment data is involved. Ask for the vendor's subprocessor list, the other companies that touch your data indirectly through the vendor's own stack, and confirm they are notified of subprocessor changes rather than finding out after the fact.

Financial stability. For any vendor that will become operationally load-bearing, check basic signs of financial health: funding history, last known valuation or revenue disclosures, headcount trends on LinkedIn, and how long they have operated at their current scale. A vendor that shuts down or gets acquired mid-contract is a switching-cost problem, not just an inconvenience.

Contract and commercial terms. Read the auto-renewal clause and note the exact cancellation notice window, commonly 30 to 90 days before renewal. Check for a price escalation clause and what percentage increase it permits at renewal. Confirm whether the contract includes a true-up mechanism if usage exceeds the licensed amount, and what the true-up pricing is versus the original per-seat rate. None of this is negotiable after signature, so it has to be reviewed before.

Integration and technical fit. Confirm the vendor's API or native integrations actually connect to the systems you already run, not just systems in the same product category. Ask about data export: what format you get your data back in if you leave, and whether export is free or a paid service.

References and support. Ask for two references from companies of a similar size and industry, not the vendor's biggest logos. Ask specifically about support response times and what happens when something breaks outside business hours, since SLA language in a contract and lived experience from existing customers often diverge.

Total cost of ownership. Price out the full cost, not just the list price per seat: implementation or onboarding fees, required add-on modules, overage charges, and the internal time cost of managing the tool. Mid-market teams that evaluate only the sticker price routinely find the fully loaded cost running 20 to 40% above the number in the initial quote once these are added in.

A six-step evaluation framework

  1. Define the requirement and assign a tier. Before any vendor conversation, write down what problem the tool solves, what data it will touch, and which tier that puts it in.
  2. Request documentation up front. Send the security questionnaire and request the SOC 2 report at the same time you request pricing, not after commercial terms are agreed. Vendors that stall on documentation are telling you something.
  3. Score vendors against the same weighted criteria. Use the same checklist and the same weighting for every vendor in the same tier, so the decision is comparable and defensible later.
  4. Run reference calls before the final round. References take a week or two to schedule. Start early enough that a bad reference can still change the outcome.
  5. Route the contract through a real review, not a rubber stamp. Legal or a trained procurement lead should read the actual contract language on auto-renewal, escalation, and liability caps, not just the redlines the vendor's AE flags.
  6. Record the decision. Save the completed checklist, the SOC 2 report, and the final contract terms in one place tied to the vendor. The next renewal, or the next similar purchase, starts from that record instead of from zero.

Example: evaluating a new HR platform at a 220-person company

A 220-person mid-market company was replacing its HR system, moving payroll and employee records to a new platform quoted at $38,000 a year. Because the tool would hold Social Security numbers and bank details for every employee, it was tiered as Tier 1 on intake, before pricing conversations went anywhere.

The security questionnaire surfaced that the vendor's SOC 2 report was Type I, issued 14 months earlier, meaning it confirmed controls existed on one day but not that they held up over time. The company asked for the vendor's next Type II report and made the contract contingent on delivery within 90 days, a condition the vendor accepted without pushback, which by itself was informative.

Contract review found a 12% annual price escalation clause on renewal, well above the 3 to 7% range more typical for HR platforms at this size, and a 90-day cancellation notice window buried in an exhibit rather than the main terms. Both became negotiation points before signature rather than surprises at renewal. The finance lead running the review estimated the total first-year cost, once implementation fees and a required payroll add-on were included, at $51,000, about 34% above the initial quote. That number, not the sticker price, is what went into the budget.

What a mature vendor evaluation process looks like

Companies that get this right share a few habits. Every new vendor is tiered within the first conversation, before pricing is discussed, so the review depth is set by risk rather than by how far along the deal already is. Security documentation is requested in parallel with pricing, not after a verbal agreement, which keeps a stalled security review from becoming the reason a deal that is otherwise done falls through at the last minute. One person, not a committee, owns the final sign-off for each tier, so accountability is clear when something is missed. And every completed evaluation is saved in a format the next reviewer can reuse, so the checklist gets faster and more consistent with each purchase rather than starting over every time.

For a Tier 1 vendor, a properly run process from first questionnaire to signed contract typically takes three to five weeks, most of it waiting on the vendor for documentation and reference availability rather than internal review time. Teams that compress this below two weeks are almost always skipping the SOC 2 review, the reference calls, or both.

Frequently asked questions

How long should a SaaS vendor due diligence review take?

For a Tier 1 vendor handling sensitive data, budget three to five weeks from first questionnaire to signed contract, most of it spent waiting on the vendor to produce documentation and schedule reference calls. A Tier 3 vendor with no sensitive data access can often clear a lightweight checklist in a day or two.

What is the difference between a SOC 2 Type I and Type II report, and which should I require?

A Type I report confirms a vendor's security controls existed and were designed correctly on a single date. A Type II report confirms those controls actually operated effectively over a period, typically six to twelve months. For any vendor touching customer or financial data, require Type II; a Type I report only proves the controls existed on paper.

How much does skipping vendor due diligence actually cost?

Third-party breaches now account for 35.5% of all breaches and cost an average of $4.91 million to remediate, according to SecurityScorecard's 2025 research, roughly 40% more than an internal breach. Beyond breach risk, skipped commercial review routinely misses auto-renewal and escalation clauses that add 20 to 40% to the real first-year cost versus the quoted price.

Who should own vendor due diligence at a mid-market company without a dedicated procurement team?

Assign one person per risk tier rather than spreading ownership across a committee. A finance or operations lead can reasonably own Tier 2 and Tier 3 reviews, while Tier 1 vendors touching sensitive data should have a named owner with authority to say no, working alongside whoever handles legal review of the contract.

What should be in a vendor security questionnaire for a mid-market SaaS purchase?

At minimum, ask what data the vendor stores or processes, where it is hosted, whether they hold a current SOC 2 Type II report, their subprocessor list and notification policy for changes to it, their data breach notification timeline, and what happens to your data on contract termination, including export format and any associated fees.

How do I negotiate better terms once due diligence surfaces a problem?

Use specific findings, not general leverage. A price escalation clause above the 3 to 7% range typical for the category, a cancellation window buried outside the main contract terms, or an outdated SOC 2 report are all concrete, defensible reasons to request a change, and vendors are more likely to move on a specific, documented ask than a general request for a better deal.

Related Articles

No items found.

Procr

Stop renewing blind.

See what Procr does with your real vendor portfolio.

Book a demo →