Vendor Contracts & Procurement
Overview
Contracts are the skeleton of enterprise sales. A clean MSA + Order Form +
DPA + SLA package closes deals in weeks. A messy, non-standard contract gets
stuck in legal review for months. The mistake: letting every enterprise
customer dictate terms from scratch. You need standard templates that cover
80% of deals, with red-line boundaries for the remaining 20%. This skill
covers the complete contract stack: MSA, Order Form, SLA, DPA — for both
selling to customers (inbound) and buying from vendors (outbound).
Authoritative Foundations
- YC — Standard commercial terms for B2B SaaS — Startup operating cadence — default alive, talk to users, launch fast.
- SaaS Capital — B2B SaaS contract benchmarks — B2B SaaS contract benchmarks
- Jason Lemkin (SaaStr) — Enterprise contract negotiation — Enterprise contract negotiation
- David Skok (Matrix Partners) — B2B contract structure — SaaS metrics — CAC payback, LTV/CAC, unit economics by stage.
When to Use
Trigger phrases: "MSA template", "master service agreement", "order form",
"SLA agreement", "data processing agreement template", "enterprise contract",
"vendor contract", "procurement process", "contract negotiation",
"commercial terms for SaaS", "standard contract"
Step-by-Step Process
Phase 1: Inbound Contracts (Selling to Customers)
The standard contract stack:
CONTRACT STACK (4 documents):
1. MSA (Master Services Agreement)
- The "umbrella" contract. Signed once. Governs the entire relationship.
- Covers: service description, payment terms, term/termination, IP,
confidentiality, limitation of liability, warranties, indemnification,
governing law, dispute resolution
2. Order Form
- Each purchase gets its own Order Form.
- Covers: products purchased, quantity (seats/volume), price, term length,
billing frequency, renewal terms, special terms
- References the MSA
3. SLA (Service Level Agreement)
- Can be part of MSA or separate.
- Covers: uptime commitment, response times, credits for downtime,
support hours, escalation paths
4. DPA (Data Processing Agreement)
- Required for GDPR compliance and enterprise deals.
- Covers: data processed, purpose, sub-processors, security measures,
breach notification, data subject rights, SCCs
MSA — Key clauses and negotiation positions:
| Clause |
Standard Position |
Fallback |
Non-Negotiable |
| Limitation of Liability |
12 months of fees paid |
24 months |
Never unlimited |
| Indemnification |
Mutual for IP claims. Customer indemnifies for their data. |
Customer indemnifies for their use only |
Never indemnify for customer's data misuse |
| Warranty Disclaimer |
"AS IS" — no warranties beyond what's explicitly stated |
Accept limited warranties (performance, security) |
Never warranty "error-free" or "uninterrupted" |
| Termination for Convenience |
30 days written notice |
60 days |
Must include — don't lock into perpetual |
| Governing Law |
Your state (or Delaware) |
Their state |
Not international (costly to litigate) |
| Payment Terms |
Net 30, annual upfront |
Net 45, quarterly |
Never Net 90+ (cash flow killer) |
Order Form — standard fields:
- Company name, address, billing contact
- Products/services purchased
- Quantity (seats, volume, API calls)
- Term (monthly / annual / multi-year) — push for annual
- Price per unit, total contract value
- Billing frequency
- Start date, end date, auto-renewal terms
- Special terms (discounts, pilot terms, custom features)
- Signed by both parties
SLA — standard commitments:
- Uptime: 99.5% (standard) to 99.9% (enterprise). 99.99% is unreasonable
for a startup.
- Credits: 5-10% of monthly fee per X% downtime. Cap at 100% of monthly fee.
- Exclusions: planned maintenance (48 hours notice), force majeure,
customer-caused issues, third-party services
- Response times: P1 (15-60 min), P2 (1-4 hours), P3 (4-24 hours)
DPA — key elements:
- See:
data-privacy-compliance skill for full DPA details
- Must include: data types, processing purpose, sub-processor list,
security measures, breach notification (72 hours), data subject rights,
SCCs for international transfers
- Have a standard DPA ready. Enterprise customers WILL ask for one.
Phase 2: Contract Negotiation Playbook
The enterprise legal review gauntlet:
- Week 1: Customer's procurement team receives your MSA.
- Week 2-3: Their legal team red-lines the MSA (30-50 changes).
- Week 4: Back-and-forth negotiation. Compromise on minor. Hold on major.
- Week 5-6: Final review. Signatures.
Your goal: Get from MSA sent → signed in under 4 weeks. Every week of
delay is a week your revenue isn't starting.
Negotiation rules:
- Protect liability cap at all costs. "We can be flexible on [X], but
our liability cap of 12 months' fees is standard for SaaS companies at
our stage."
- Push back on IP indemnity expansion. "We'll indemnify for our IP
infringement. We can't indemnify for your use of our product with your
data — that's your domain."
- Accept minor redlines gracefully. "Sure, we can accept Net 45 instead
of Net 30." Small concessions build goodwill for the big ones.
- Have a line you won't cross. Unlimited liability. Non-standard IP
assignment (they want YOUR IP). Perpetual, irrevocable licenses. Walk
away if they insist on these.
When to bring in your lawyer:
- Contract value > $50K and heavily red-lined
- Customer wants custom indemnity beyond IP
- International jurisdiction (their country's law)
- Data processing terms outside standard DPA
- Any clause that seems like it creates material risk
Phase 3: Outbound Procurement (Buying from Vendors)
Vendor evaluation framework:
- Security Review: DPA signed? SOC2 report obtained? Sub-processors
documented?
- Commercial Terms: Annual vs monthly? Auto-renewal? Price lock?
Termination for convenience?
- Data Processing: What data do they access? Where is it stored? Who
are their sub-processors?
- Integration Risk: How critical is this vendor to your product? What
happens if they go down or sunset the feature?
Vendor contract red flags (when YOU are the buyer):
- Auto-renewal with no notice period ("you're locked in for another year")
- Unilateral price increases ("we can raise your price by 20% at any time")
- No termination for convenience (you're stuck even if the product degrades)
- "We can use your data to improve our models" — for any vendor with access
to customer data, this is a hard NO
- No SLA or uptime commitment (they go down, you have no recourse)
Vendor procurement process:
- Business case: why do we need this? alternatives considered?
- Security review: DPA + SOC2 + sub-processors
- Commercial review: pricing, terms, auto-renewal
- Legal review: MSA, DPA, any red flags
- Approval: based on spend threshold — see
gtm-spend-management → spend-approval-matrix ($2K / $10K / $50K tiers)
- Payment: Ramp bill pay or virtual card per vendor roster
Phase 4: Contract Management
Store contracts somewhere you can find them:
- Contract repository: DocuSign, PandaDoc, Ironclad, or at minimum — a
shared Google Drive folder with naming convention
- Key metadata per contract: counterparty, start date, end date, renewal
terms, contract value, auto-renewal (Y/N), termination notice deadline
- Calendar reminders: 90 days before auto-renewal or expiration
Contract tools:
- DocuSign ($10-40/mo): e-signatures, templates, basic management
- PandaDoc ($19-49/mo): proposals, contracts, e-signatures
- Ironclad ($$$): enterprise contract lifecycle management
- Common Paper: open-source standard contracts for B2B SaaS
Output Format
CONTRACT STACK — [Company]
STANDARD DOCUMENTS:
- [ ] MSA — [template ready / needs lawyer review / pending]
- [ ] Order Form — [template ready]
- [ ] SLA — [template ready. Uptime: X%]
- [ ] DPA — [template ready. SCCs: Yes/No]
CONTRACT PROCESS:
- Sales → Legal handoff: [when does legal get involved? $X threshold?]
- Average cycle time: [weeks from MSA sent → signed]
- Non-standard terms log: [what we've accepted and why]
VENDOR PROCUREMENT:
- [ ] Vendor security review checklist
- [ ] Procurement approval thresholds: $X / $Y / $Z
- Contract repository: [tool / folder]
Implementation Checklist
Quality Check
Before delivering, verify:
Common Pitfalls
No standard MSA. Every enterprise customer sends you THEIR contract.
You're negotiating from their paper. Every time. Every deal takes months.
Fix: Have your own MSA template. "We use our standard MSA. Our customers
find it fair."
Unlimited liability. You signed a contract with no liability cap. A
customer sues for $5M in damages from your $10K/year SaaS product. Your
company is dead. Fix: Liability cap = 12 months of fees. Non-negotiable
for early-stage companies.
Custom contracts for every deal. "This customer wants their own MSA."
Now you're managing 50 unique contracts with different terms. Legal risk
per contract. Fix: 80/20 rule. 80% of deals use standard contract. 20%
negotiate minor terms. 0% get fully custom.
No auto-renewal tracking. Contract auto-renews at 3x the price.
You didn't notice. Customer is furious. Fix: Calendar reminders 90 days
before every renewal. Review terms before auto-renewal triggers.
Ignoring vendor security review. You bought a tool without checking
its security. It gets breached. Your customer data is exposed. Your
customer sues YOU — not the vendor. Fix: Security review every vendor
that touches customer data. DPA + SOC2 minimum.
⚠️ Disclaimer
This skill provides general informational guidance based on publicly available frameworks and operator experience. It is NOT legal advice, accounting advice, tax advice, financial advice, insurance advice, or professional services advice.
Consult qualified professionals for your specific situation — attorneys for legal/equity matters, CPAs for tax and accounting, licensed brokers for insurance, and certified security assessors for compliance. This skill does not create a professional-client relationship. Use it as a starting point for research and preparation.
Execution Artifacts
references/framework-notes.md — Named frameworks and reference tables
templates/output-template.md — Deliverable shell for agent output
scripts/check-output.py — Lightweight deliverable validator
Related Skills
legal-for-founders — Foundational contracts, ToS, Privacy Policy
data-privacy-compliance — DPA details, SCCs, GDPR requirements
security-assessments — Vendor security questionnaires, pen testing
soc2-compliance — SOC2 that every enterprise vendor review asks for
deal-desk — Deal structuring, pricing, proposals
1---2name: vendor-contracts3description: Vendor contracts, MSAs, DPAs, and procurement for B2B SaaS — master service agreements, service level agreements, data processing agreements, order forms, vendor security assessments, and contract negotiation playbooks. Use when selling to enterprise (inbound contracts), buying from vendors (outbound procurement), negotiating terms, or building standard agreement templates. Triggers on: "MSA", "SLA agreement", "data processing agreement", "order form", "vendor security review", "enterprise contract", "procurement".4license: MIT5---67# Vendor Contracts & Procurement89## Overview1011Contracts are the skeleton of enterprise sales. A clean MSA + Order Form +12DPA + SLA package closes deals in weeks. A messy, non-standard contract gets13stuck in legal review for months. The mistake: letting every enterprise14customer dictate terms from scratch. You need standard templates that cover1580% of deals, with red-line boundaries for the remaining 20%. This skill16covers the complete contract stack: MSA, Order Form, SLA, DPA — for both17selling to customers (inbound) and buying from vendors (outbound).1819## Authoritative Foundations2021- **YC — Standard commercial terms for B2B SaaS** — Startup operating cadence — default alive, talk to users, launch fast.22- **SaaS Capital — B2B SaaS contract benchmarks** — B2B SaaS contract benchmarks23- **Jason Lemkin (SaaStr) — Enterprise contract negotiation** — Enterprise contract negotiation24- **David Skok (Matrix Partners) — B2B contract structure** — SaaS metrics — CAC payback, LTV/CAC, unit economics by stage.2526## When to Use2728Trigger phrases: "MSA template", "master service agreement", "order form",29"SLA agreement", "data processing agreement template", "enterprise contract",30"vendor contract", "procurement process", "contract negotiation",31"commercial terms for SaaS", "standard contract"3233## Step-by-Step Process3435### Phase 1: Inbound Contracts (Selling to Customers)3637**The standard contract stack:**3839```40CONTRACT STACK (4 documents):41421. MSA (Master Services Agreement)43 - The "umbrella" contract. Signed once. Governs the entire relationship.44 - Covers: service description, payment terms, term/termination, IP,45 confidentiality, limitation of liability, warranties, indemnification,46 governing law, dispute resolution47482. Order Form49 - Each purchase gets its own Order Form.50 - Covers: products purchased, quantity (seats/volume), price, term length,51 billing frequency, renewal terms, special terms52 - References the MSA53543. SLA (Service Level Agreement)55 - Can be part of MSA or separate.56 - Covers: uptime commitment, response times, credits for downtime,57 support hours, escalation paths58594. DPA (Data Processing Agreement)60 - Required for GDPR compliance and enterprise deals.61 - Covers: data processed, purpose, sub-processors, security measures,62 breach notification, data subject rights, SCCs63```6465**MSA — Key clauses and negotiation positions:**6667| Clause | Standard Position | Fallback | Non-Negotiable |68|---|---|---|---|69| **Limitation of Liability** | 12 months of fees paid | 24 months | Never unlimited |70| **Indemnification** | Mutual for IP claims. Customer indemnifies for their data. | Customer indemnifies for their use only | Never indemnify for customer's data misuse |71| **Warranty Disclaimer** | "AS IS" — no warranties beyond what's explicitly stated | Accept limited warranties (performance, security) | Never warranty "error-free" or "uninterrupted" |72| **Termination for Convenience** | 30 days written notice | 60 days | Must include — don't lock into perpetual |73| **Governing Law** | Your state (or Delaware) | Their state | Not international (costly to litigate) |74| **Payment Terms** | Net 30, annual upfront | Net 45, quarterly | Never Net 90+ (cash flow killer) |7576**Order Form — standard fields:**77- Company name, address, billing contact78- Products/services purchased79- Quantity (seats, volume, API calls)80- Term (monthly / annual / multi-year) — push for annual81- Price per unit, total contract value82- Billing frequency83- Start date, end date, auto-renewal terms84- Special terms (discounts, pilot terms, custom features)85- Signed by both parties8687**SLA — standard commitments:**88- Uptime: 99.5% (standard) to 99.9% (enterprise). 99.99% is unreasonable89 for a startup.90- Credits: 5-10% of monthly fee per X% downtime. Cap at 100% of monthly fee.91- Exclusions: planned maintenance (48 hours notice), force majeure,92 customer-caused issues, third-party services93- Response times: P1 (15-60 min), P2 (1-4 hours), P3 (4-24 hours)9495**DPA — key elements:**96- See: `data-privacy-compliance` skill for full DPA details97- Must include: data types, processing purpose, sub-processor list,98 security measures, breach notification (72 hours), data subject rights,99 SCCs for international transfers100- Have a standard DPA ready. Enterprise customers WILL ask for one.101102### Phase 2: Contract Negotiation Playbook103104**The enterprise legal review gauntlet:**1051061. **Week 1:** Customer's procurement team receives your MSA.1072. **Week 2-3:** Their legal team red-lines the MSA (30-50 changes).1083. **Week 4:** Back-and-forth negotiation. Compromise on minor. Hold on major.1094. **Week 5-6:** Final review. Signatures.110111**Your goal:** Get from MSA sent → signed in under 4 weeks. Every week of112delay is a week your revenue isn't starting.113114**Negotiation rules:**1151161. **Protect liability cap at all costs.** "We can be flexible on [X], but117 our liability cap of 12 months' fees is standard for SaaS companies at118 our stage."1192. **Push back on IP indemnity expansion.** "We'll indemnify for our IP120 infringement. We can't indemnify for your use of our product with your121 data — that's your domain."1223. **Accept minor redlines gracefully.** "Sure, we can accept Net 45 instead123 of Net 30." Small concessions build goodwill for the big ones.1244. **Have a line you won't cross.** Unlimited liability. Non-standard IP125 assignment (they want YOUR IP). Perpetual, irrevocable licenses. Walk126 away if they insist on these.127128**When to bring in your lawyer:**129- Contract value > $50K and heavily red-lined130- Customer wants custom indemnity beyond IP131- International jurisdiction (their country's law)132- Data processing terms outside standard DPA133- Any clause that seems like it creates material risk134135### Phase 3: Outbound Procurement (Buying from Vendors)136137**Vendor evaluation framework:**1381391. **Security Review:** DPA signed? SOC2 report obtained? Sub-processors140 documented?1412. **Commercial Terms:** Annual vs monthly? Auto-renewal? Price lock?142 Termination for convenience?1433. **Data Processing:** What data do they access? Where is it stored? Who144 are their sub-processors?1454. **Integration Risk:** How critical is this vendor to your product? What146 happens if they go down or sunset the feature?147148**Vendor contract red flags (when YOU are the buyer):**149- Auto-renewal with no notice period ("you're locked in for another year")150- Unilateral price increases ("we can raise your price by 20% at any time")151- No termination for convenience (you're stuck even if the product degrades)152- "We can use your data to improve our models" — for any vendor with access153 to customer data, this is a hard NO154- No SLA or uptime commitment (they go down, you have no recourse)155156**Vendor procurement process:**1571. Business case: why do we need this? alternatives considered?1582. Security review: DPA + SOC2 + sub-processors1593. Commercial review: pricing, terms, auto-renewal1604. Legal review: MSA, DPA, any red flags1615. Approval: based on spend threshold — see `gtm-spend-management` → spend-approval-matrix ($2K / $10K / $50K tiers)1626. Payment: Ramp bill pay or virtual card per vendor roster163164### Phase 4: Contract Management165166**Store contracts somewhere you can find them:**167168- Contract repository: DocuSign, PandaDoc, Ironclad, or at minimum — a169 shared Google Drive folder with naming convention170- Key metadata per contract: counterparty, start date, end date, renewal171 terms, contract value, auto-renewal (Y/N), termination notice deadline172- Calendar reminders: 90 days before auto-renewal or expiration173174**Contract tools:**175- DocuSign ($10-40/mo): e-signatures, templates, basic management176- PandaDoc ($19-49/mo): proposals, contracts, e-signatures177- Ironclad ($$$): enterprise contract lifecycle management178- Common Paper: open-source standard contracts for B2B SaaS179180## Output Format181182```183CONTRACT STACK — [Company]184185STANDARD DOCUMENTS:186- [ ] MSA — [template ready / needs lawyer review / pending]187- [ ] Order Form — [template ready]188- [ ] SLA — [template ready. Uptime: X%]189- [ ] DPA — [template ready. SCCs: Yes/No]190191CONTRACT PROCESS:192- Sales → Legal handoff: [when does legal get involved? $X threshold?]193- Average cycle time: [weeks from MSA sent → signed]194- Non-standard terms log: [what we've accepted and why]195196VENDOR PROCUREMENT:197- [ ] Vendor security review checklist198- [ ] Procurement approval thresholds: $X / $Y / $Z199- Contract repository: [tool / folder]200```201202## Implementation Checklist203204- [ ] MSA template reviewed by startup lawyer205- [ ] Order Form template ready — clean, simple, one page206- [ ] SLA with realistic uptime commitment (not 99.99%)207- [ ] DPA template ready for enterprise customers208- [ ] Liability cap: 12 months of fees (standard, defensible)209- [ ] Contract repository organized (DocuSign / PandaDoc / Ironclad)210- [ ] Vendor security review process documented211- [ ] Auto-renewal dates tracked with calendar reminders212213## Quality Check214215Before delivering, verify:216217- [ ] Output matches the user's stated request218- [ ] Named frameworks or sources are reflected in the recommendation219- [ ] The deliverable is specific enough for an agent to execute220- [ ] Any assumptions, risks, or dependencies are explicit221- [ ] No unsupported claims, invented facts, or private/internal references are included222223## Common Pitfalls2242251. **No standard MSA.** Every enterprise customer sends you THEIR contract.226 You're negotiating from their paper. Every time. Every deal takes months.227 Fix: Have your own MSA template. "We use our standard MSA. Our customers228 find it fair."2292302. **Unlimited liability.** You signed a contract with no liability cap. A231 customer sues for $5M in damages from your $10K/year SaaS product. Your232 company is dead. Fix: Liability cap = 12 months of fees. Non-negotiable233 for early-stage companies.2342353. **Custom contracts for every deal.** "This customer wants their own MSA."236 Now you're managing 50 unique contracts with different terms. Legal risk237 per contract. Fix: 80/20 rule. 80% of deals use standard contract. 20%238 negotiate minor terms. 0% get fully custom.2392404. **No auto-renewal tracking.** Contract auto-renews at 3x the price.241 You didn't notice. Customer is furious. Fix: Calendar reminders 90 days242 before every renewal. Review terms before auto-renewal triggers.2432445. **Ignoring vendor security review.** You bought a tool without checking245 its security. It gets breached. Your customer data is exposed. Your246 customer sues YOU — not the vendor. Fix: Security review every vendor247 that touches customer data. DPA + SOC2 minimum.248249250251## ⚠️ Disclaimer252253This skill provides general informational guidance based on publicly available frameworks and operator experience. It is NOT legal advice, accounting advice, tax advice, financial advice, insurance advice, or professional services advice.254255Consult qualified professionals for your specific situation — attorneys for legal/equity matters, CPAs for tax and accounting, licensed brokers for insurance, and certified security assessors for compliance. This skill does not create a professional-client relationship. Use it as a starting point for research and preparation.256257## Execution Artifacts258259- `references/framework-notes.md` — Named frameworks and reference tables260- `templates/output-template.md` — Deliverable shell for agent output261- `scripts/check-output.py` — Lightweight deliverable validator262263## Related Skills264265- `legal-for-founders` — Foundational contracts, ToS, Privacy Policy266- `data-privacy-compliance` — DPA details, SCCs, GDPR requirements267- `security-assessments` — Vendor security questionnaires, pen testing268- `soc2-compliance` — SOC2 that every enterprise vendor review asks for269- `deal-desk` — Deal structuring, pricing, proposals