Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Choose a software development company by checking what it can demonstrate—not just what it promises. Compare candidates on relevant experience, the people and suppliers doing the work, delivery scope, secure development practices, verification, vulnerability handling, and the commitments written into the contract. This 15-point checklist organizes those questions for a buyer; it is not an official standard or a universal scoring system.

How to use this checklist

Use the questions below in proposals, interviews, and contract discussions. Ask candidates to support important claims with relevant examples, explanations, and documents. The right level of diligence depends on the system being built, the data it handles, the project’s risk, and your organization’s requirements.

NIST and CISA guidance cited here comes from U.S. federal cybersecurity and procurement contexts, though it can inform other buyers. It does not replace project-specific security assessment or legal advice for your jurisdiction. NIST’s supply-chain guidance also notes that it does not provide federal contract language.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

15 questions to ask before choosing a company

1. Can it show relevant work?

Ask for examples that resemble your problem, technical environment, and constraints. Find out what the company actually delivered and what its role was. Treat examples as evidence to examine, not a guarantee that your project will have the same outcome. NIST’s procurement guidance supports requesting information from suppliers, but does not prescribe a universal portfolio test. NIST: Software Cybersecurity for Producers and Purchasers.

2. Who will do and oversee the work?

Ask which people will perform and lead the work, what responsibilities they will hold, and whether any work will be delegated. Include subcontractors and service providers in the discussion: the company’s delivery and security practices may depend on suppliers beyond the firm you hire. CISA’s vendor-assessment materials include questions about supplier policies and obligations. CISA: Assisting Small and Medium-sized Businesses Assess Vendors and Suppliers.

3. Can you verify the supplier’s identity?

Confirm the legal entity you would contract with and request traceable company information. NIST’s supply-chain due-diligence guide treats foundational supplier checks as an early step, rather than assuming that a polished proposal establishes who is responsible. NIST: Cybersecurity Supply Chain Management: Due Diligence Assessment Quick-Start Guide.

4. Can it explain its supply chain and provenance?

Ask which suppliers, components, and services may be involved, and what information the company can provide about them. The depth of detail you need will vary with the project, but a supplier should be able to discuss relevant dependencies and their origins. NIST identifies supply-chain tiers and provenance as due-diligence considerations. NIST: Cybersecurity Supply Chain Management: Due Diligence Assessment Quick-Start Guide.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Are scope and deliverables specific?

Make the proposed work concrete in writing. Clarify deliverables, assumptions, exclusions, dependencies, and how you will judge whether work is complete. The sources cited here do not prescribe a software statement-of-work template; the purpose is to make project-specific expectations clear enough that both sides can identify what is and is not included.

6. Does it follow secure practices throughout the software life cycle?

Ask how security is incorporated from planning and development through release and maintenance, and what evidence can be shared. NIST recommends attestation covering practices performed throughout the software life cycle. It also explains that, given software’s dynamic nature, attesting to ongoing processes and procedures is typically more valuable than attesting to how one particular release was produced. NIST: Attesting to Conformity with Secure Software Development Practices.

7. What verification techniques does it use?

Ask which verification techniques are appropriate to your project, when they are used, and what results or other evidence can be shared. NIST recommends that purchasers incorporate applicable minimum verification techniques into supplier requirements; which techniques apply depends on the software and its risks. NIST: Software Cybersecurity for Producers and Purchasers; NIST: Software Verification.

8. Who owns security decisions and remediation?

Establish who defines security requirements, performs or coordinates reviews, decides how findings are addressed, and tracks remediation during the engagement. Use the answers to clarify accountability between your organization and the supplier. Do not treat an unsupported certification claim as proof that a company can meet your project’s needs. NIST: Software Cybersecurity for Producers and Purchasers; NIST: Software Verification.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

9. How are vulnerabilities reported and handled?

Ask how people report vulnerabilities, how the company assesses and prioritizes them, how fixes are delivered, and how affected customers are informed. Also discuss incident-response responsibilities and coordination with relevant suppliers. CISA’s acquisition materials include questions about vulnerability-disclosure and incident-response processes in the supplier ecosystem. CISA: Assisting Small and Medium-sized Businesses Assess Vendors and Suppliers.

10. How does it manage software components?

Ask how the company tracks third-party and open-source components and handles related risks. Where appropriate for the project, ask whether it can provide useful software bill of materials (SBOM) information. NIST identifies SBOMs, open-source controls, vendor risk, and vulnerability management as relevant supply-chain topics; the appropriate evidence depends on the software and engagement. NIST: Software Security in Supply Chains: Guidance, Purpose, Scope, and Audience.

11. What data will it handle, and how is that protected?

Identify the information the company and its suppliers will access, store, or otherwise handle. Ask what contractual obligations apply to protecting it and how those obligations extend to relevant suppliers. CISA’s vendor-assessment materials include supplier information-protection obligations among their assessment questions. CISA: Assisting Small and Medium-sized Businesses Assess Vendors and Suppliers.

12. What happens if a key supplier or component is unavailable?

Ask how the company would respond if a critical supplier, team, or component became unavailable, and whether it can explain relevant dependencies and alternatives. NIST includes supplier resilience in its due-diligence considerations. NIST: Cybersecurity Supply Chain Management: Due Diligence Assessment Quick-Start Guide.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

13. How will changes, review, and acceptance work?

Agree how either side can propose a scope change, how its impact will be reviewed, and who can approve it. Define how you will review deliverables and communicate acceptance or requested corrections. The official sources cited here do not establish universal change-control terms; set terms that fit the project.

14. Do the procurement documents and contract match the expectations?

Check that relevant requirements for security practices, suppliers, verification, data protection, vulnerability handling, and responsibilities appear in the documents you will rely on—not only in sales conversations. CISA’s software acquisition guidance raises questions about supplier agreements and security practices. The precise terms should reflect your project and applicable legal requirements. CISA and partner agencies: Choosing Secure and Verifiable Technologies.

15. Can it substantiate its claims?

For each material promise, ask what applicable practice, document, or artifact supports it and who is responsible for producing that evidence. Give greater weight to explanations of repeatable processes across the life cycle than to a claim about a single release. NIST’s attestation guidance specifically recommends: “Require attestation to cover secure software development practices performed as part of processes and procedures throughout the software life cycle.” NIST: Attesting to Conformity with Secure Software Development Practices.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Compare candidates on evidence, not a universal score

When you have multiple candidates, compare the same evidence for each. The following dimensions synthesize NIST and CISA procurement guidance; they are not a validated scoring model, and the sources do not establish universal weights.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Comparison area Evidence to look for
Relevant delivery experience Examples connected to your problem and constraints, with the company’s role made clear.
Scope and acceptance Clear deliverables, assumptions, exclusions, dependencies, review, and acceptance expectations.
People and suppliers Clarity about who will perform and oversee the work and which suppliers or components are involved.
Secure development and verification Lifecycle practices, applicable verification techniques, and evidence the company can share.
Vulnerability and incident handling Defined reporting, assessment, remediation, communication, and coordination processes.
Components and provenance Relevant information about software components, supply-chain dependencies, and provenance.
Resilience An account of how critical supplier, team, or component disruption would be handled.
Contract commitments Project-relevant security, supplier, verification, data, and responsibility expectations in procurement documents and agreements.

Do not let a single label or polished presentation substitute for the underlying evidence. If a candidate cannot answer a question, record what remains unclear and decide whether that uncertainty is acceptable for the system and engagement.

Sources and limits

The security and procurement recommendations above draw on NIST and CISA guidance. CISA’s Secure Software Development Attestation Form was released March 11, 2024; its resource page was revised March 18, 2024. CISA and partner agencies published Choosing Secure and Verifiable Technologies on December 5, 2024. NIST’s supply-chain guidance page was updated November 1, 2024. These materials support diligence questions, not a guarantee of supplier performance or a one-size-fits-all selection formula.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.