Procurement and compliance
Large customers do not buy software; they onboard suppliers. Do this work before they ask and you cut weeks off every deal.
- Company basics: Companies House, business bank account, VAT decision, insurances.
- Cyber Essentials (the certificate every UK construction buyer asks for).
- A data processing agreement (DPA) and privacy notice you can send the same day.
- A one-page security summary and a supplier-questionnaire answer bank.
- Cyber Essentials Plus once the first housebuilder asks. ISO 27001 only when a contract depends on it.
The checklist, with lead times and costs
Lead times are estimatesS16 until you have measured your own.
| Item | Why they ask | Lead time | Cost | Status |
|---|---|---|---|---|
| Limited company, registered office, business bank | Supplier forms need a company number and bank details | 1–5 days | £50 + bank fees | Do first |
| Public liability + professional indemnity insurance | Most supplier forms set minimums (typically £1m–£5m PL, £1m PI for software) | 1–3 days | £300–£900 / year | S10Do first |
| ICO data protection fee | Legally required for a controller; buyers check the register | Same day | £52 / year (tier 1) | S9Do first |
| Cyber Essentials | Standard ask in UK construction and public-sector supply chains | 1–3 weeks (self-assessment) | £320–£600 | S8Month 1 |
| Cyber Essentials Plus | Housebuilder and FM groups increasingly require it | 4–8 weeks after CE | £1,400–£2,500 | S8When asked |
| DPA + privacy notice + sub-processor list | UK GDPR Article 28; you process workers' names and phone numbers | 1 week to draft | Free (ICO templates) or £500–£1,500 with a solicitor | S11Month 1 |
| Security summary (1 page) | Answers 80% of a questionnaire before it is sent | 1 day | Free | Month 1 |
| Supplier questionnaire answer bank | Every large buyer sends a 60–200 question form; reuse answers | Builds over time | Free | Month 1 |
| Terms of service + SLA | Order forms reference them | 1 week | Template-based; solicitor review £500–£1,000 | S11Month 1 |
| ISO 27001 | Enterprise deals and some FM/catering groups | 4–9 months | £8k–£20k first year | S11Only if a contract needs it |
| Constructionline / SafeContractor | Relevant for contractors, rarely for a software supplier; ask before paying | 2–6 weeks | £100s–£1,000+/yr | Ask first |
Costs are as at August 2026: certification and ICO fees from the published price lists, insurance and legal from typical quotes (see Sources for each). Confirm before budgeting. The numbers that matter are the lead times: Cyber Essentials and the DPA are on the critical path of your first housebuilder deal.
Answering "where is our data?"
| Question | Answer |
|---|---|
| What personal data do you hold? | Name, phone number, optional email, language, group membership, and the content people post. Photos in hazard reports may show people. |
| Where is it hosted? | AWS, [London/Ireland] region, on servers managed via Laravel Forge. Backups daily, retained [30] days. |
| Who are your sub-processors? | AWS (hosting, storage), Twilio (SMS verification), OpenAI (translation of post text only), Mux (video), Pusher (real-time, if used), Mailgun (email). List published and updated with notice. |
| Is data sent outside the UK? | Translation and SMS providers process in the US under standard contractual clauses / UK IDTA. Post text only is sent for translation. |
| How do you delete data? | Leavers are locked out on their leaving date; tenant deletion on request within 30 days; backups age out. |
| Access control? | Tenant isolation at the database layer; roles (admin, moderator, worker); admin impersonation is logged. |
| Encryption? | TLS in transit; encryption at rest on AWS volumes and S3. |
| Incidents? | Named contact, notification within 72 hours, written procedure. |
Fill in the bracketed values from the actual deployment before sending this to anyone. A wrong answer here is worse than a slow one.
The regulatory angle that sells
Every provision below is primary legislation or HSE's own guidance, linkedS24. Quote the words, not your paraphrase, and let their HSEQ lead map it to their obligations. Never give legal advice.
| Instrument | The words that matter | What it means for the product |
|---|---|---|
| Health and Safety at Work Act 1974, s.2(2)(c) | Employer must provide "such information, instruction, training and supervision as is necessary" | The base duty: a duty to provide, which in a prosecution the employer must show it discharged. |
| HSWA 1974, s.2(3) | Bring the H&S policy "and any revision of it to the notice of all of his employees" | A statutory duty to communicate a document to every employee, with no evidential mechanism defined. The export is that mechanism. |
| Management of H&S at Work Regs 1999, reg 10(1) | Provide "comprehensible and relevant information" on risks, measures and emergency procedures | The word the translation feature hangs on. Information in English to a worker who does not read English is arguably not comprehensible. |
| MHSWR 1999, reg 12 | Extends the information duty to employees of outside undertakings on the premises | The direct answer to "subcontractors aren't our employees". |
| CDM 2015, reg 13(4)(a) and reg 15(8)–(9) | Principal contractor ensures "a suitable site induction"; every contractor gives workers "appropriate supervision, instructions and information", including emergency procedures and risks from other contractors | Applies to every contractor on site, not just the PC. Reg 15(9) is a checklist of post templates: induction, emergency procedure, risk briefing, contractor interface, statutory notice. |
| HSWA 1974, s.40 | "It shall be for the accused to prove … that it was not practicable or not reasonably practicable to do more than was in fact done" | The burden of proof is reversed. Say in every discovery call: "In an HSE prosecution you don't have to be proved to have failed. You have to prove you did enough. What's your evidence?" |
| HSE guidance for employers of migrant workers | Language barriers "limit their ability to communicate effectively"; HSE publishes its own safety material in 19 languages | HSE conceding that English-only communication does not discharge the duty on a multinational site. |
| Employment Rights Act 2025 (harassment duties, "all reasonable steps", third-party liability) | Commencement scheduled for October 2026 per the Government roadmap updated 25 Aug 2026S30 | A dated, external reason to buy now. Verify the commencement date before putting it in writing to a customer; dates move. |
The WhatsApp argument, stated correctly
- The ICO report on private messaging at the Department of Health is Behind the screens, 11 July 2022, Commissioner John Edwards; DHSC received a reprimand, not a fineS31. There is no 2024 report. Get this right; it is easy to be corrected on.
- The Independent Review of Non-corporate Communications Channels in Government was announced on 2 July 2026 and expressly covers disappearing messages: proof this is a live governance issue, not a vendor line.
- Framing that wins: "Keep WhatsApp for the banter. Move anything you'd have to defend onto a system that produces a record." "WhatsApp is dangerous" does not.
- Food safety: allergen and recall notices with confirmation are audit evidence for caterers.
Your own compliance when you sell
- Cold email is lawful to corporate subscribers (Ltd, PLC, LLP, Scottish partnerships) under PECR reg 22. It is not lawful without consent to sole traders, ordinary partnerships or personal addresses. Segment the list against Companies House before sending; an active company number is the discriminatorS32.
- Every marketing email needs an opt-out address and your company name, number and registered office. Since 5 February 2026, PECR fines run to £8.7m or 2% of turnoverS32.
- UK GDPR Article 14: when you gather a named person's work email from a third party, you owe them privacy information at or before first contact. A line with a link to your privacy notice does it. Keep a written legitimate-interests assessment (ICO template).
Supplier folder: write once, before the first plc conversation
Company number, VAT number, registered address, bank details (via a verified channel), insurance certificates, and one-page policies for: health and safety, modern slavery, anti-bribery, equal opportunities, quality, environment. Plus Cyber Essentials, the DPA, the security summary and two references. Every item you cannot produce on the day adds one to three weeks of elapsed time. Note: the Prompt Payment Code is now the Fair Payment CodeS33.
International transfers, stated correctly
Twilio and Mux are certified under the UK Extension to the EU–US Data Privacy Framework, so those transfers need no IDTA or transfer risk assessment. OpenAI is not: the translation transfer needs an IDTA (or Addendum) and a documented TRA, and post text only goes to itS34.
ISO 27001
£6,750–£15,000+ and 6–12 months. At your size, offer a written ISMS roadmap plus your Cyber Essentials certificate instead; divisions accept this far more often than founders expect. Treat ISO as a year-two decision triggered by two lost deals, not by anxiety.