How to Choose a Software Development Company

Avatar
Author

Start with what you can verify on your own, before speaking to anyone. The public IAPMEI list of PME Líder companies, the public contracts record on the Base portal, the open source the company publishes, and its filed accounts. Four sources independent of any sales conversation.

Then assess what changed in 2026. Portugal transposed NIS2 through Decreto-Lei n.º 125/2025 of 4 December, which approved the Regime Jurídico da Cibersegurança and entered into force on 3 April 2026. The obligations attach to the covered entity, which means the security posture of whoever builds and maintains your software became part of your own exposure. Very serious administrative offences reach 10 million euros.

The second date is 11 September 2026, when the reporting obligations in Article 14 of the Cyber Resilience Act started applying to anyone placing products with digital elements on the EU market, including those bundling open source components. We covered what that requires in 24-hour vulnerability reporting under the CRA and in cyber resilience with open source and secure by design. The practical effect is simple. The question of whose name goes in the contract stopped being purely commercial.

This article is written from the supplier side, which means it includes the questions we would rather not be asked.

What can you verify before the first meeting?

More than most buyers attempt. Four checks, all in public sources, all independent of what the company says about itself.

PME Líder or PME Excelência status. Published annually by IAPMEI. It tells you third parties verified the financial criteria: positive net income, EBITDA across two financial years, financial autonomy, net financial debt to EBITDA, and a risk rating assigned by a Mutual Guarantee Society.
Public contracts record. On the Base portal. It tells you whether the company has delivered to the state, at what values and over what timelines. The public sector is demanding on documentation, and that leaves a trail.
Published open source. On the company GitHub or GitLab. It is the only work sample that was not prepared in order to sell it: real code quality, maintenance cadence, and whether they respond to third-party issues.
Filed accounts. Mandatory publication. They tell you whether the company has the scale to sustain a multi-year contract, and whether it depends on a single client.

None of these checks tells you whether the company is good at writing software. They tell you whether it is a serious company, which eliminates a considerable part of the market before spending a meeting.

One note on PME Líder: it is a financial status, not a technical one. In the 2025 edition 14,133 companies across all sectors were recognised, so it is neither rare nor distinctive in itself. The value is the inverse. If a company with ten years of trading does not hold it, that is worth two questions.

What does NIS2 require you to demand from a software supplier?

The supply chain management obligation attaches to the covered entity. That is, to the client. If you are in scope and your supplier cannot demonstrate its security posture, the finding is yours. Eight clauses are worth a contract review at the next renewal.

Incident notification windows that fit inside your own reporting duties, not your supplier’s convenience.
A named security contact, with a real out-of-hours escalation path.
Component inventory or SBOM, available on request.
Vulnerability handling commitments, with response times by severity.
Access control and offboarding evidence for anyone touching your systems.
Subcontractor disclosure, including where their people physically sit.
Data location and applicable jurisdiction, stated explicitly.
A right to audit, or an accepted certification in its place.
Ask for a current component inventory. If it arrives in 48 hours, there is a process. If it takes three weeks, you have learned something more useful than any questionnaire would tell you.

And there is a consequence almost nobody anticipates. Contracts signed before April 2026 contain none of this, because no obligation existed. That is nobody’s failure. It is work outstanding.

Evaluating suppliers and want to test the checks in this article?
Talk to our team

Which questions separate suppliers who look identical?

Every proposal says the team is senior and the methodology is agile. These five produce different answers.

Who maintains the software you delivered five years ago? Separates those who deliver projects from those who sustain systems. If the answer is vague, your system will meet the same fate.
Show me code you wrote that I can read. Companies that publish open source answer in seconds. Companies that do not have to negotiate permissions. That is already the answer.
What goes wrong in your projects, and what did you change because of it? An honest answer describes a specific case. An evasive answer describes a process.
Who are the people who will work on this, and are they available? Separates the sales team from the delivery team. Ask for names and ask to speak to them before signing. It is the question that most often changes the outcome.
What do you need from us to keep this on schedule? An experienced supplier has a list ready: decisions, access, availability of your own people. A supplier without a list will blame you later.

Which contracting model matches your problem?

Fixed-scope project
Delivery belongs to the supplier
Makes sense when the problem is well defined and the outcome is describable before starting.
Team augmentation
Delivery remains yours
Makes sense when you have process and technical leadership and lack capacity. The engineers join your team and your rituals.
The most frequent confusion is contracting team augmentation while expecting outsourcing. People join the team, nobody on the client side leads technically, and six months later the conversation is about why the supplier did not take decisions that were never assigned to it. We cover the difference between the two models separately, along with the practical benefits of augmentation and the regulatory alignment argument for nearshoring to Portugal.

How do you compare proposals without comparing only price?

Two proposals for the same request rarely cover the same scope, which makes direct value comparison misleading. Normalise first.

What is included after delivery. Warranty, defect correction, evolutionary maintenance, tracking dependency versions. If one proposal includes it and the other does not, they are not comparable.
Who runs the tests, and with what evidence. Automated tests delivered to you are an asset. Manual testing performed by the supplier leaves nothing behind when the contract ends.
Who keeps what. Ownership of the code, the data model, the infrastructure as code. And what happens if you want to change supplier.
Which assumptions support the timeline. Availability of your people, decision turnaround, access to systems. Timelines rest on these assumptions, and that is where they slip.

On figures, an honest position. We do not publish price ranges in this article because the answer depends on scope, the number of platforms, audit requirements and what already exists. Any published range would be too wide to decide with or too narrow to be true. Describe the scope and ask for a number, not a range.

Related reading

Nearshore Portugal: the compliance case Why regulatory alignment now appears in RFPs from regulated sectors, and what it replaces.
Team augmentation vs outsourcing The distinction that costs the most when it is confused at contract stage.
CRA September 2026: 24-hour vulnerability reporting What your suppliers now owe you inside a day, and why contracts signed earlier do not say so.
Software quality evidence: the gap that costs Why a supplier with a green dashboard may still fail a supervisory review.
Software development What we build, for whom, and the delivery models we work in.

Frequently asked questions

Verifying a supplier

How do you check whether a software development company is solid?
Four public checks before any meeting: the IAPMEI list of PME Líder and PME Excelência companies, which rests on verified financial criteria; the public contracts record on the Base portal; the open source the company publishes; and its filed accounts. None of these assesses technical quality. All of them assess solidity.
What is the PME Líder status and what does it guarantee?
It is a status awarded by IAPMEI, the Portuguese agency for competitiveness and innovation, since 2008, based on financial criteria including positive net income, EBITDA across two financial years, financial autonomy and a risk rating assigned by a Mutual Guarantee Society. In the 2025 edition 14,133 companies were recognised. It does not assess technical capability.

NIS2 and contracting models

Does NIS2 require changing contracts with software suppliers?
The obligations attach to the covered entity, not to every supplier. But the covered entity has to manage the security of its supply chain, which in practice requires contractual commitments on incident notification, vulnerability handling, subcontracting and data location. In Portugal the Regime Jurídico da Cibersegurança has been in force since 3 April 2026.
What is the difference between team augmentation and outsourcing?
In team augmentation the engineers join your team and your processes, and delivery remains yours. In outsourcing you transfer responsibility for delivery to the supplier, including the decisions. Contracting one while expecting the other is the most common mistake, and it costs more than picking the wrong supplier within the right model.

Questions and pricing

What questions should you ask a software company before contracting?
Five that produce measurably different answers between suppliers: who maintains the software you delivered five years ago, what code written by your team can I read, what goes wrong in your projects, who are the people who will work on this and are they available, and what do you need from us to keep this on schedule.
Why are there no indicative prices in this article?
Because a useful range does not exist. The figure depends on scope, the number of platforms, audit requirements and what is already built. A range wide enough to be true is not usable for a decision. Describe the scope and ask each supplier for a specific number instead.
Caixa Mágica Software
Caixa Mágica Team
Caixa Mágica Software is a Portuguese software company with 20+ years of experience delivering custom software, AI solutions and nearshore development teams for European businesses.
Software Development · Caixa Mágica Software
Ask us the five questions in this article
We publish open source, we maintain software we delivered more than a decade ago, and our public contracts record is verifiable without asking us for anything. Describe the scope and we will return a number, not a range.