Vendor Management

cyber essentials for suppliers contract clauses a shield with keyhole plinth

Cyber Essentials for Suppliers: Proven Safe Contract Terms

Most organisations ask for Cyber Essentials during the tender and never mention it again, which leaves the requirement sitting in a questionnaire with no expiry date, no evidence obligation and no consequence attached. This guide shows how to write it into the contract instead: which suppliers belong in scope and at what level, model clause wording for the certification obligation, how to define scope so a certificate for somewhere else cannot satisfy it, what evidence to demand and how to verify it against the register, how the obligation flows down to subcontractors, what happens when certification lapses mid-term, and a proportionate remedy ladder that runs from a rectification plan to termination without ending a workable relationship.

Read more
software handover checklist changing development partners a vault door ajar plinth

Software Handover Checklist: Essential Guide to Avoid Risk

Changing development partners is the moment your leverage is highest and your knowledge is thinnest. This software handover checklist covers everything that has to transfer before the outgoing supplier’s last billable day: repositories and full commit history, build and deployment pipelines, infrastructure accounts, domains and certificates, secrets and credentials, third-party licences, architecture and runbook documentation, test suites, and the data your users depend on. It sets out realistic timelines and costs for a structured transition, the acceptance tests that prove the handover actually worked, the contract clauses that make all of it enforceable, and the mistakes that turn a routine supplier change into a rewrite.

Read more
source code ownership outsourced software project a padlock on cube stack

Source Code Ownership: Essential Guide to Avoid IP Risk

Paying a supplier to build software does not make you the owner of it. In the UK, and in most of the jurisdictions British companies outsource to, copyright in code vests in the author by default — which means the agency, the freelancer or the offshore studio that wrote it, unless a contract says otherwise in exactly the right words. This guide works through source code ownership the way it actually goes wrong: the legal default nobody checks, the three ownership models suppliers offer, the background IP and open-source carve-outs that hollow out an assignment clause, why escrow is a fallback rather than a substitute, and how to prove at handover that you can genuinely rebuild the product without the people who wrote it.

Read more
software development contract checklist a sealed scroll on hexagonal plinth

Software Development Contract Checklist: Proven Risk Guide

Most disputes in bespoke software development are not about quality — they are about ownership, access and exit, the three things nobody negotiates while everyone is still optimistic. This software development contract checklist works through the clauses in the order they cause trouble: intellectual property and assignment, source code, repositories and escrow, third-party and open-source licence risk, exit rights and termination, data protection and security obligations, warranties, liability caps and indemnities, and payment, acceptance and change control. Each section gives the wording to look for, the red flag that means you are about to sign something expensive, and the practical fallback when a supplier will not move.

Read more
fixed-price vs time-and-materials - fixed price vs time and materials software contracts a two sealed scrolls on balance plinth

Fixed-Price vs Time-and-Materials: Proven Risk Guide

The same 3,200-hour build can be quoted at £180,000 under one commercial model and £240,000 under the other, and the cheaper quote is very often not the cheaper project. This guide treats fixed-price vs time-and-materials as a risk-allocation decision rather than a pricing one: a full head-to-head comparison table, how each model actually behaves once delivery starts, what the cost-overrun research really shows, the hidden costs neither side advertises, a project-type decision matrix, a risk register showing who carries what, the capped and hybrid structures most experienced buyers end up using, a five-question framework for choosing, the contract clauses that protect you in either model, and straight answers to the questions buyers ask most.

Read more
software development rfp how to write one a central prism with five orbiting spheres

Software Development RFP: Proven Guide to Avoid Mistakes

Ask five agencies to quote from a thin brief and you get five proposals that cannot be compared — different assumptions, different scope, and prices ranging from £40,000 to £250,000. This guide explains how to write a software development RFP that produces comparable, honest bids: why the document filters who bothers to respond, when an RFP beats an RFI or a direct conversation, the sections that belong in it and in what order, how to write requirements a developer can actually estimate, why publishing a budget range and your evaluation weightings improves what arrives, how to score responses and read the assumptions page before the price, the mistakes that drive the best suppliers away, a section-by-section outline with a realistic eight to ten week timetable, and straight answers to the questions buyers ask most.

Read more
switch it support providers without disruption a two hubs linked by cable

Switch IT Support Providers: Proven Guide to Avoid Downtime

How to move to a new managed IT partner without breaking the business — auditing your exit position, choosing the incoming provider, running an overlap so cover never lapses, handing over credentials and licences, sequencing cutover week, telling staff and suppliers, and the day-thirty review that proves the transition actually finished.

Read more
it provider onboarding checklist first 30 days a two interlocking chain links

IT Provider Onboarding Checklist: Proven Safe 30-Day Plan

What to demand from a new MSP in your first thirty days — kick-off and credentials, full estate discovery, monitoring and patch baselines, verified restores, MFA and security standards, contract carve-outs, exit rights, and the day-30 review that proves the transition actually finished.

Read more
managed it services contract a sealed scroll on plinth

What Should Be Included in a Managed IT Services Contract?

Scope, service levels, security, data protection, onboarding, reporting, renewal and exit — a complete managed IT support agreement covers all of them, and the schedules matter far more than the main agreement. This guide walks through every section the document should contain, what good looks like in each one, and the specific clauses worth arguing over before signature.

Read more
CHAT