Once an evaluation is done and a product is chosen, the agreement is where the operational details get locked in: what happens during a security incident, what happens to your data when you leave, how feature changes get communicated. These are far easier to build into the agreement while it is being drafted than to add later, and the sector has already built shared instruments so you are mostly adapting standard language rather than writing it from nothing.

Five terms deserve real attention.

Breach notification measured in days

Standard language often promises notification of a security incident “promptly” or “without undue delay.” A specific window serves both sides better: notification within a set number of days, 72 hours is a common figure, of the supplier becoming aware of an incident affecting your data, in writing, with a description of what was affected and what is being done about it. Higher education has had a couple of large third-party incidents in recent years where the exact timing of notification mattered a great deal, and a clear window removes the ambiguity before anyone needs it resolved.

Data return and deletion on exit

You will move off this product eventually, and it helps enormously to have agreed in advance what happens then: your data returned in a usable, documented format within a defined period after termination, all copies including backups deleted within a further defined period, and a certificate of deletion to prove it. Without this in writing, student records can sit indefinitely on a former supplier’s systems, which is both a records problem and a security exposure that is now entirely yours to own.

An accessibility conformance commitment with real dates

The Accessibility Conformance Report you received during evaluation probably listed a few items the product “partially supports”. Known gaps, in plain terms, turning those into actual commitments is straightforward: a schedule with dates for fixing them, a commitment to maintain WCAG 2.1 AA conformance as the product evolves, an updated report at each major release, and a remedy, a credit, or an exit right, for a material failure that never gets fixed. With the Title II timeline already in view, this keeps a shared obligation genuinely shared.

Notice before a feature you depend on changes

Software as a service means the product changes on the supplier’s own schedule, which is usually fine, for the handful of features your courses genuinely depend on, though, it is worth locking in advance written notice, a full term or more, before one gets removed or materially changed, with a way out if that change breaks something you cannot work around. You are not asking for protection against all change. You are asking not to be blindsided by the one change that matters to you.

Price protection at renewal

The first-year price gets negotiated in one context; the renewal happens in a very different one, once switching costs are higher. A cap on annual increases, tied to an index or a fixed percentage, for a defined number of renewal terms, makes the multi-year cost genuinely predictable. If a cap is not available, model the three- and five-year cost against an uncapped increase before you decide anything.

The instruments already backing these up

HECVAT 4.1.5 is the standardized security and risk questionnaire from EDUCAUSE, Internet2, and REN-ISAC. Ask every finalist for a completed one, and read the specific answers rather than checking that a box exists.

Standard data-protection addenda, maintained by many university systems and consortia, already carry versions of the first two terms in language suppliers recognize on sight.

Cooperative purchasing agreements, through E&I, state master contracts, regional consortia, often include negotiated versions of all five, so your starting point is a contract many institutions already shaped together, rather than a blank order form.

None of these five terms is unusual, and procurement offices ask for versions of all of them routinely. They tend to get dropped only when they come up at the very end, once the evaluation already feels finished. Treat the contract as the second half of the same decision. The product you chose and the agreement you sign are one purchase, not two.


Jack Wrightmann is a consultant at Wrightmann Education Technologists. Part of the Technology Procurement series.

References

  • EDUCAUSE. (2025). Higher Education Community Vendor Assessment Toolkit (HECVAT). https://www.educause.edu/higher-education-community-vendor-assessment-toolkit
  • Information Technology Industry Council. Voluntary Product Accessibility Template (VPAT), version 2.5. https://www.itic.org/policy/accessibility/vpat