5
11 Comments

How should I approach the requirements of a big customer?

Just came back to a sales meeting with a prospective enterprise customers. It's a big one, one of the top ten privately owned business in the US. For a little company like mine, still searching for PMF, it's also a long shot.

Though my software solves a pain most acutely felt by big companies, I really don't want to be one of those companies that always seemed to be on the verge of closing some Big Deal. And then, when all the right pieces seemed to be in place, they discover whole new set of requirements that are impossible to meet.

But the meeting went better than expected! From the last time we've talked and yesterday, my contact had experienced the problem I solved first-hand. He was excited and wanted to introduce me to several other people in the company. It looked like I got myself a champion inside.

So why do I feel so anxious?

He told me their company usually made the following demands.

  1. They need white label version they can put their logo. That's not hard.
  2. They need SSO. It was further ahead on my roadmap, but totally doable.
  3. They want to host the application on their servers.

Now this 3rd demand spooked me. My product is a SaaS, not a software license. The alternative, he told me, would be to get a bunch of certifications they would otherwise require - which would more expensive and take way longer.

I could do an one-off, sure. I know that Rappi, now a behemoth in last mile delivery in Latin America actually started out by licensing their application to El Corte Inglès. Even with a one-off software license deal, I could to get some recurring revenue by including a maintenance contract so that, every time I update my product, I send them a new Docker image they can run in their infrastructure...

In this scenario, however, I get no usage data that I could otherwise use to improve the product and/or create benchmarks and algorithms on.

Since this company also sells technology consulting services, they could simply steal my software and distribute it themselves if they wanted. Sure I could try to protect myself with a contract, but I feel this would be innocuous. It would be very hard, if not impossible, to detect them reselling my software without permission. Even if I did detect them, the legal costs would be nothing to them - and prohibitive to me.

Obviously, I'm getting ahead of myself. We haven't even started a POC yet.

But still, I don't know whether those are valid fears or simply fear of success. How should I approach this? Do I have any negotiation leverage?

on November 20, 2021
  1. 2

    You need to really uncover what's going on and who is requiring this. Here are a few scenarios:

    1. Your business contact THINKS that is what is required but doesn't realize that the Security/IT team is fine with AWS/Azure/GCP. Try to get a dialogue with the Security/IT team.
    2. The business contact doesn't care at all but the Security/IT team requires on-prem. Say that you would build this for them but that you'd like to talk to the Security team about specifications. Use this opportunity to see if the Security team will budge and somehow be ok with AWS/Saas.

    In both cases, you want your business contact to connect you with the Security/IT team to really understand requirements.

    1. 1

      He is the infrastructure IT director though...

      1. 1

        Is on-prem his requirement that he sets for the organization? Do they have a separate security team that dictates that? You need to get to untangle that.

  2. 2

    I wouldn't be too concerned with #3, depending on their business. For example, casinos are famous for their secrecy and will only use products they can run in-house.

    However, I'm wondering if your best move would be to get the certifications. It could be worth the time and effort because it could open new doors and build an extra moat for your product.

    The next 30-45 days might be the perfect window of opportunity that. With the holidays season upon us, their company could be too busy/distracted to get a serious deal done anytime soon. If that's true, then an early-Spring deal with a more robust offering might be easier and better for you in the future.

    What do you risk by trying to get the certifications?

    1. 1

      The biggest risk would be...well, the money. I believe a SOC2 would cost me 25k, while a penetration test would cost 20k. I think annual examinations are required, so I might get certified, the deal might get delayed or fall through and I'm left with a whole in my wallet.

      For reference, 10k allows me to live about 6 months without income in Portugal and I currently have less than than in my company's bank account

      1. 2

        Oh wow, that is pretty expensive.

        Well, everything is a risk vs. reward tradeoff. If there's a way to offset risk with a co-founder or by pre-selling some deals (i.e. pay X in advance for a lifetime rate) it might help.

        Good luck and keep us all updated with your decision and how you progress.

  3. 1

    I worked in a bank enterprise for many years. The last eight on the product / delivery side. I had to oversee some of our contracts with smaller vendors.

    The 3rd requirement seems pretty standard for enterprise. They want to deal with all companies the same way. Each department owns a little bit of what they expected without a single decision owner. For example, how contracts and what’s expected normally is with the Vendor Management.

    From experience, it depends on how big and regulated the enterprise company is. The larger/more regulated, the more sliced up is each function to individual teams and they’ll follow a very standard process.

    I’m not sure about the leverage. For the approach, I think they’ll expect what they’re used to. Would it help if wrote out the high-level process we followed?

    1. 1

      Do you mean asking for certifications or hosting the application themselves?

      I expected the former, but the latter changes my business model from SaaS to software licensing.

      I've never ran a software in this manner. Just to start: imagine I fix some bug. For a SaaS, all my customers will get the fix as soon as I deploy the new version. But if this company is on a 6 month update cycle, everyone who works there will have to live with an annoying bug for 6 months.

      I think sharing your process would be a great help on what to expect, btw!

      1. 1

        Yes. Depending on how big they are and what industry they serve, they’ll want to host the application. Usually, if they’re asking to host, it’s from a data privacy concern.

        Your 6-month update cycle is what we had to do with one small vendor within our enterprise.

        Do you know what industry they fall into? Who are their users?
        Have they hold you their high level requirements, use case? Anything more?

        1. 1

          They are in professional services. From auditing to consulting. My tool focuses on internal users, so that's who I expect they will be serving.

          I haven't got back on the internal requirements for a SaaS, but I expect soc2 and pentest certifications. Those might be expensive in the short term, but more beneficial in the long one.

          How was your experience with that vendor? Did your users loved their product? Were the vendor's Customer Service and Product Manager able to get in touch with your users?

          1. 1

            I wore multiple hats. I was the Senior Product Manager, Senior Business Architect, owned and executed product delivery along with our Senior Technology Manager. In addition, I had to oversee the contracts and quarterly checks of the vendor meeting the contract (SLAs, responsiveness to issues, issue severity) with our Senior Technology Manager and Vendor Manager.

            I'm assuming this, pluckd.co, is your product. Our enterprise treats employee data as private. It might be worth looking into Personally Identifiable Information (PII) if you haven't yet.

            We have many vendors, but in this particular one, I dealt with 3 people. The total size of the company was 9. They were good but were often surprised about our processes. For example, our vendor manager told us many times that the vendor can't start work without going through our internal process. No matter how small it is. A single request requires us to draft a document, get a dollar estimate, find a funding source. After that, no further work could be done. We were in bank, so it'll vary what kind of enterprise it is.

            One of the things you hear with enterprises is the sale cycle is also 6+ months. So you just need to prepare yourself for that.

            Feel free to set up a video chat if it would be helpful. I can tell you my experience within.