Vendor contract checklist: five clauses to read before you sign
Most small teams sign vendor contracts the way they accept cookie banners — scroll to the bottom, click, done. The contract then sits in someone's email until the day it matters: the renewal that auto-charged a card for another year, the vendor breach where nobody can find the notification clause, the exit where nobody knows what happens to the data. The vendor security review decides whether a vendor is safe enough; this page is the signing gate that decides on what terms. Five clauses, twenty minutes, before the signature — not after the invoice.
1. Termination and auto-renewal: the clause that decides whether you can leave
- Read the exit before the entrance. Before feature lists and price, find how you get out: notice period (30/60/90 days?), renewal term (month-to-month or auto-annual?), and penalties for early exit. A twelve-month auto-renewal with a sixty-day notice window means your real decision date is four months before the renewal date — not the week the invoice lands.
- Put the notice deadline on the calendar at signature time. The moment the contract is signed, the renewal date and the notice-by date go into the software license register — the register's renewal column already runs the sixty-day decision; the contract's notice clause is what makes that decision legally possible. A register row without the notice deadline is a countdown you cannot act on.
- Auto-renewal is a default, not a law of nature. Ask for month-to-month during negotiation, especially in year one. Vendors say yes more often than teams think to ask. If the answer is no, the ask itself tells you how the vendor treats leverage — useful information for the escalation ladder you may climb later.
- Write the exit trigger while goodwill is high. One line in your own ops notes: "we leave if X happens twice" (two missed SLA months, one unanswered P1 in 48 hours, a price increase above Y%). The escalation ladder ends in a written exit trigger; the contract is where you confirm an exit is actually available when the trigger fires.
2. Data ownership, export, and deletion: what happens to your data when you go
- Ownership in one sentence. The contract should say your data is yours, full stop. If the vendor's data clause grants itself licenses to "improve services" over your customer records, decide now — in writing, in the negotiation — not during the breach postmortem.
- Export is a deliverable, not a favor. The clause that matters is format and cost: CSV/database dump? API? Included in the plan or billed as a "professional service"? A vendor that owns your only copy in a proprietary format has a hostage, and the offboarding checklist starts with getting the data out. Test the export on day one, not departure day — the same discipline as the backup restore test, applied to a vendor.
- Deletion on exit, with a deadline. Look for: data deleted within 30–90 days of termination, written confirmation on request, and the same promise flowing down to subprocessors. If the contract is silent, your data lives in their backups forever — which becomes your problem in the next breach and the next customer questionnaire.
- Subprocessor list and change notice. You need to know which other companies touch your data and get a heads-up when that list grows. Small teams cannot run enterprise subprocessor governance — but "email me before you add one" costs the vendor nothing and is a fair ask at signature.
3. Breach notification: who tells you, how fast, and saying what
- The number that matters is hours, not adjectives. "Prompt notification" means whatever the vendor wants it to mean. Ask for a number: 24–72 hours to notify you of a security incident affecting your data. For comparison, the GDPR clock for you starts at 72 hours — if your processor notifies you on day six, your own obligation is already broken.
- Notification needs a channel that works during the incident. An email to a support alias is not notification. The clause should name how (email to your security contact, phone for confirmed incidents) — and your security contact should be a shared mailbox, not one person's address, for the same reason the break-glass accounts page gives: incidents do not check who is on holiday.
- What the vendor commits to after the breach. Notification content (what data, how many, what they did), cooperation with your own customer communications, and who pays for what. You will write your customers' notification based on their facts; a vendor that refuses to share facts quietly makes you lie.
- If they will not put a number in writing, that is the answer. A vendor's refusal to commit to a notification window is a finding — exactly the kind the vendor security review records. You can still sign; you just sign knowing, and you write the risk down where the annual review will find it.
4. Liability, uptime promises, and support tiers: the parts that only matter at 2 a.m.
- Read the liability cap and its exclusions. Nearly every SaaS contract caps liability at twelve months of fees — that is normal and usually fine. What matters is the exclusions: if "loss of data" is carved out, a vendor bug that wipes your data costs them nothing. One sentence of negotiating capital ("carve customer data loss out of the exclusion") is worth more than an hour arguing the cap.
- Uptime promises need a remedy, not a percentage. 99.9% with a service-credit ceiling of one month's fee is theater for a small team. What you actually need mirrors the SLA/SLO page's honesty rule: a number you can measure, a status page you can check, and support tiers with named response times. The credits are decoration; the response times are the product.
- Support tier is a contract line, not a hope. Rung zero of the escalation ladder is "read the tier you already paid for." At signature, confirm which tier you bought, its response times, and what "urgent" means in their ticketing system — because at 2am that sentence is the difference between a sixty-minute wait and a Monday-morning one.
- The payment-process clause beats fraud after the fact. Verify how banking details change are handled (portal-only, callback verification) and connect it to the invoice-fraud checklist: most BEC attacks arrive as a vendor "update" to payment details. A contract line that pins changes to a verified channel is cheaper than the incident.
5. The signature discipline: who signs, and where the contract lives
- One signer, and it is not whoever clicked fastest. Pick one person (or role) who signs vendor contracts. Click-through "I agree" checkboxes on self-serve tools are the exception everyone abuses — the rule is that anything with a renewal invoice above the team's threshold (say $50/month) gets the five-clause read. The shadow IT audit exists precisely because the click-through path bypassed every gate.
- The signed contract lives in one place, linked from the register. Same discipline as the license register's "where the key lives" column: the PDF goes to one folder with one naming pattern, and the register row links to it. When the auditor, the insurer, or the new admin asks "what are the terms with this vendor?", the answer is one hop — the new admin's first week depends on that hop existing.
- Amendments are contracts too. The renewal quote, the seat increase, the plan downgrade — each one is a new agreement. File them with the original. The register's annual prune (keep / watch / kill) only works if the paper trail is where the verdict is being made.
- When to actually pay a lawyer. A five-person team cannot run legal review on every vendor — and does not need to. The five-clause read covers the $0–$500/month tier. Pay a lawyer when: annual spend crosses roughly $10k, customer PII is flowing at scale, or the vendor refuses changes to the data and breach clauses. That is a threshold rule, written down, not a vibe.
Small-team honesty note: this page will not make a bad contract good. Vendors send their paper on their terms, and most small teams sign most of it — that is the realistic baseline. What the checklist buys you is knowing which five clauses you are accepting and having the two that matter most (notice deadline, notification window) written into your own register and calendar before the invoice arrives. The trap this page exists to prevent is the signature as amnesia: nobody read it, nobody filed it, and three years later the exit conversation starts with "wait, we renewed in March?" Twenty minutes per contract, one owner, one folder. That is the whole program.
Related: vendor security review · software license register · vendor escalation ladder · vendor offboarding and data deletion · SLA and SLO definitions · cyber insurance requirements · invoice fraud / BEC prevention · SaaS sprawl audit · shadow IT audit · annual security review · API key rotation · break-glass accounts · customer security questionnaire · contractor onboarding · backup restore test · new admin's first week