Related guide · Procurement Without Getting Locked In

Address integration, data ownership, cybersecurity, service levels, pricing changes, support, contract renewal, and how you will retrieve your data and leave the platform if necessary.

GUIDE · 17 min read

The short version

Lock-in is rarely a single clause. It builds up out of ordinary decisions: data held in a format only the vendor reads, integrations the vendor built and only the vendor maintains, an annual price that escalates faster than the budget, and no written answer to what happens on the day you leave. The time to fix all of that is while they still want your signature. Ask what it costs to get your data out before you ask what it costs to get in.

Bring purchasing into the conversation early

Do not finish the technical evaluation and then ask purchasing how the department is allowed to buy it. Procurement strategy should be discussed while requirements are still being developed.

Purchasing staff are not an obstacle at the end of the process. They are the people who know which methods are available to your jurisdiction, what documentation each one requires, how long each takes, and what the funding source adds on top. Any of those answers can change the requirements — and changing requirements is cheap while they are still a draft and expensive once they are a published solicitation.

The question is not only which product the department wants. It is how this department is allowed to buy it, and how long that takes.

Know the procurement path

These are the common routes a public agency uses to buy technology. Which of them is available to you depends on your jurisdiction, the funding source and the amount involved, so treat this as vocabulary for the conversation with purchasing rather than as a decision the project team can make on its own.

COMPETITIVE SOLICITATION / RFP
Useful when the department needs vendors to respond to defined requirements and explain how their solution meets them.
RFQ / QUOTE PROCESS
May be appropriate for more standardized purchases, depending on local rules and the dollar amount.
COOPERATIVE PURCHASING
May allow an eligible agency to purchase through an existing competitively awarded contract when permitted by state or local law and agency policy.
SOLE SOURCE
An exception that generally requires a documented basis and must satisfy applicable law and policy. It is a justification to be written and defended, not a shortcut around competition.

Procurement requirements vary by jurisdiction, funding source and purchase amount. Engage your purchasing and legal staff early.

Nothing on this page tells you that a particular method is legal or appropriate for your purchase. That determination belongs to your purchasing office and your legal counsel, working from your own law and policy. What this page can do is make sure you ask the question at the point where the answer is still useful.

A cooperative contract does not switch off the grant's rules

If any part of the purchase is paid for with federal grant funding, the fact that you are buying through an existing cooperative or schedule contract does not by itself satisfy the federal procurement requirements attached to that award.

FEMA's guidance for recipients and subrecipients sets out the shape of it: local governments and nonprofits follow the federal procurement standards, and where federal, state, tribal and local rules differ, the most restrictive rule applies. Required contract provisions still have to appear in the contract, competition requirements still apply according to your entity type and dollar amount, and the file still has to document how the method was chosen.

GSA's Cooperative Purchasing program can be a legitimate route for eligible state and local governments buying information technology, security and law enforcement products. Being eligible to use it is a separate question from whether using it satisfies your grant's requirements and your own policy. Confirm both, in writing, before the purchase order goes out.

Do not let the product write the specification

If the requirements are so specific that only the product already selected can meet them, go back and confirm that those specifications are genuinely operational requirements rather than product features reverse-engineered into the solicitation.

This usually happens without anyone intending it. A department sees a demo, likes it, and writes the requirements from memory of what the demo did. The result is a solicitation that is technically competitive and practically closed, which is both a poor purchase and a real protest risk.

The test is straightforward. For each requirement, can you state the operational reason it exists in terms of what the department has to accomplish? A requirement you can only justify by naming a product is a product feature, not a requirement.

Questions for purchasing

Take these to your purchasing office while the requirements are still being written.

  • What procurement methods are legally available?
  • Does the funding source add requirements?
  • Is an existing cooperative contract available?
  • Does using it satisfy our local requirements?
  • Is competition required?
  • What documentation is required?
  • What is the justification if sole source is being considered?
  • Who owns the final contract?
  • What terms must be included for cybersecurity, data, termination and records?

Start here

If you read one thing on this subject, read this.

Official resourceFEMA

Purchasing Under a FEMA Award: Complying with the Federal Procurement Standards

FEMA's Procurement Under Grants guidance: which federal procurement standards apply to states, local governments, tribal nations and nonprofits, what has to be documented, and the contract provisions a federally funded contract must contain.

Why it matters

The authoritative answer to what a grant adds on top of your own procurement policy. It is explicit that where federal, state, tribal and local rules differ, you follow the most restrictive rule.

Go deeper

Official resourceU.S. General Services Administration

Cooperative Purchasing Program

How eligible state and local governments can buy information technology, security and law enforcement products and services through GSA's Multiple Award Schedule contracts.

Why it matters

Explains what the program covers and who is eligible. Eligibility to use it is a separate question from whether using it satisfies your grant requirements and your own policy — confirm both.

Official resourceU.S. General Services Administration

Purchasing Programs for State and Local Governments

The full set of GSA programs open to state and local agencies, including Cooperative Purchasing, Disaster Purchasing and the 1122 Program, with the eligibility determination process for each.

Why it matters

Worth reading with your purchasing office before assuming a federal route is or is not available to your department.

Hub guidePublic Safety Technology Hub

Related guide · Evaluate Total Cost of Ownership

The five-year cost of the thing you are about to write into a contract, including what a grant does and does not pay for.

Why it matters

Escalation caps, exit costs and data migration charges are contract terms as much as they are cost lines. Settle them here, before signature.

Questions to ask your vendor

  1. What exactly do we own, and what are we licensing?
  2. In what format can we export our data, and how often?
  3. Who owns the integrations built for us?
  4. What is the annual price escalation, and is it capped in writing?
  5. What service levels apply, and what happens when they are missed?
  6. What are the renewal terms, and what notice do we have to give?
  7. What does it cost to migrate away, and how long do we retain access?