
Icertis typical implementation process:
Discovery and Needs Assessment: Stakeholders collaborate to gather business requirements and define project scope, including compliance objectives, integration needs, and contract volume.
Solution Design: The implementation team configures workflows, contract templates, approval hierarchies, and security settings tailored to the organization’s specific needs.
Data Migration and Integration: Existing contracts and relevant metadata are migrated, and integrations with enterprise systems (e.g., SAP, Microsoft, Salesforce) are established.
Platform Configuration: Customization of modules, user roles, permission structures, and automation rules to align with business policies.
User Training and Change Management: End users and administrators receive training on platform features, best practices, and new processes to drive adoption.
Testing and Validation: End-to-end platform testing, including user acceptance testing and validation of integrations, contract analytics, and compliance workflows.
Icertis is highly configurable and can be tailored across data models, workflows, integrations, and industry-specific solutions to fit complex enterprise requirements end to end. Customization spans contract structure, automation rules, AI-enabled operations, and deep connectors to core systems to align with unique processes by department and region.
Icertis offers a suite of training and support resources for new users, designed to facilitate smooth onboarding and ongoing success with the platform. The main offerings include:
Icertis Academy: Provides structured learning paths tailored for different user roles, including practitioners, administrators, functional professionals, and technical professionals. These programs use blended learning formats (online and in-person) and cover topics such as contract creation, workflow management, compliance, integration, and customization. The Academy also offers certification to validate skills and knowledge.
Customizable Training: Training content can be tailored for individuals or corporate clients, with options for online or classroom delivery. The curriculum covers basic to advanced concepts, including contract lifecycle management, collaboration tools, approval workflows, reporting, and integration.
Role-Based Onboarding: Onboarding experiences are personalized based on user roles (e.g., contract managers, legal, procurement), ensuring that each user receives relevant guidance and resources.
24/7 Global Frontline Support: Icertis provides complimentary, direct end-user support around the clock, ensuring help is available whenever needed, regardless of time zone or location.
In-App Guidance and Self-Help: Through partnerships with digital adoption platforms like Whatfix, Icertis embeds contextual help, step-by-step guides, FAQs, explainer videos, and product tours directly within the platform. This enables users to access support and learn at their own pace, without leaving the application.
Knowledge Base and Community: Icertis Connect is an exclusive customer community where users can access support, search the knowledge base, request help, and engage with other users and experts.
Icertis employs security measures to protect data on its platform. Key security features include:
Encryption at Rest: Icertis Contract Intelligence encrypts contract data stored on disk or backup systems using Advanced Encryption Standard (AES) 256-bit encryption, provided by Microsoft Azure's underlying services, ensuring strong data protection from unauthorized access.
Data Privacy and Compliance: Icertis follows commercially reasonable efforts and industry-accepted standards to secure personal information from unauthorized access, use, or disclosure, complying with data privacy regulations, including GDPR. The company processes personal data strictly under subscriber instructions and applicable legal frameworks.
Administrative, Physical, and Technical Controls: Icertis implements reasonable security measures to prevent loss, misuse, unauthorized access, alteration, or disclosure of subscriber data. These measures are part of a defined security framework addressing data security, malware protection, and incident response.
Endpoint Privilege Management: Using solutions like CyberArk Endpoint Privilege Manager, Icertis enforces strict control over administrative rights on endpoints, reducing the risk of compromised devices affecting data integrity and security.
Icertis typically delivers two major ICI releases per year—around June and December—with maintenance packs issued roughly every 4–6 weeks in between. Updates are managed as SaaS rollouts with documented release notes, patch versions, and a version support policy that covers up to two prior releases to guide upgrade planning.
Major releases are typically scheduled for June and December, with maintenance packs delivered every 4–6 weeks to address incremental improvements and fixes.
Historical examples include ICI 8.1 as a major release and subsequent updates like “8.1 Patch 6” in February 2023, evidencing ongoing maintenance between major drops.
Major releases introduce new capabilities across modules; for example, 8.1 added enhancements in Obligations, Rebates, Sourcing, and Supplier Relationship Management.
Patch releases provide targeted fixes and incremental enhancements, with ICI publishing explicit patch lines such as the 8.2 series (Patch 2 through Patch 6).
Icertis publishes detailed release notes and technical requirements for each version to help teams assess impact, prerequisites, and adoption activities.
Support is provided for up to two releases preceding the target ICI version, which sets expectations for upgrade timelines and supported versions.
Subscriber-specific change requests, data changes, or configuration updates may require additional Professional Services under the SaaS Subscription and Services Agreement.
Administrators can display in‑app maintenance banners to notify users ahead of scheduled activities, helping minimize disruption and set expectations.
Release information is organized by version with accessible notes for 8.1 and 8.2, enabling transparent tracking of what changed and when.
Icertis’s data ownership and portability policy centers on ensuring customers retain full control over their contract data while providing mechanisms to export and migrate data as needed. According to the Icertis SaaS Subscription and Services Agreement, Icertis acknowledges that all intellectual property and proprietary rights in contract data (“Subscriber Data”) belong to the subscriber, not to Icertis. This means users own and control their contract records, documents, and associated metadata within the platform.
On data portability, Icertis supports clients’ rights to access and export contract data. The platform allows contract records and metadata to be exported in structured, machine-readable formats, aligning with common industry standards and GDPR requirements on data portability. Individuals and organizations can request the transfer of their personal or contract data, which Icertis will provide in a format suitable for migration to another platform or controller.
Key highlights:
Subscriber retains ownership of all contract data stored in Icertis.
Icertis only gains limited rights to process data as needed to deliver services, with no claim over customer information.
Customers may request access or export of their data at any time, with technical data export and reporting tools available within the platform.
Data migration to alternative platforms is supported, ensuring continuity if clients change vendors or systems.
Icertis applies transparent subscription-based terms for contract renewal and cancellation. Key data points from agreements and relevant documentation include:
The default contract subscription term is three years, with options to renew for up to two additional one-year periods or other combinations mutually agreed upon by both parties, but total renewal cannot exceed two years beyond the original term unless specifically allowed.
Maintenance and service agreements may be offered for up to five years, depending on client requirements.
Renewal tracking and automated alerts within the Icertis Contract Intelligence platform help customers manage upcoming renewals and obligation dates.
Contracts may not be terminated for convenience unless legally required or mutually agreed; Icertis’s model is based primarily on multi-year commitments and does not include broad termination-for-convenience rights except in government contracts or as required by law.
Either party may terminate the contract for uncured material breaches, with a written cure period of thirty (30) days after notification.
Failure to pay undisputed amounts within ten (10) days after notification may lead to suspension of services, and continued non-payment triggers termination rights.
Upon termination, the subscriber can request the return of their data at no additional cost within five (5) days; otherwise, Icertis may permanently delete the data.
If contracts are terminated for an uncured material breach by Icertis, customers are entitled to a refund of prepaid amounts for services and SaaS not provided.
Any payment liabilities accrued up to the termination date survive termination, and certain indemnities, confidentiality, and ownership clauses remain effective.
Written notice is required for termination and any renewal or expiry, with timelines specified in each order form or statement of work.
Icertis supports workflow-driven notification and automated expiration/reset tracking, so renewal and termination actions are managed systematically in the platform.
Termination or renewal executed in the Icertis platform automatically updates linked systems (such as purchase agreements in ERP integrations) to prevent downstream discrepancies.
Icertis software meets several major global compliance standards, making it suitable for highly regulated industries and multinational organizations. The platform is certified against and built to support key requirements, including:
ISO 27001 (information security management system)
ISO 27017 (cloud security controls)
ISO 27018 (protection of personal data in cloud environments)
GDPR (European Union General Data Protection Regulation for privacy and data protection)
HIPAA (U.S. Health Insurance Portability and Accountability Act for healthcare data security)
SOC 2 (System and Organization Controls, focusing on confidentiality, security, availability, processing integrity, privacy)
Icertis was among the first contract management vendors to achieve certifications in GDPR, HIPAA, and ISO frameworks, reflecting its commitment to enterprise-wide compliance and robust security. The company enforces strong access controls, encryption, and regulatory monitoring and provides continuous workflows to ensure contracts adhere to current rules and standards. Configurations can also address regional legal requirements and standards for e-signature, data residency, and commercial contracting.