Licensing or subscription costs: base price per user, per tenant, or per feature/module. Often tiered by features or usage.
Setup/implementation fees: one-time charge for discovery, project management, initial configuration, data migration, and integrations
Professional services: fees for custom development, integration work, data migration, training, and change management.
Hosting/infra: cloud hosting costs if not included in the license; data storage, bandwidth, backups.
Support and maintenance: annual or multi-year renewal for support, updates, and access to new releases; tiers vary (Standard, Premium, Enterprise). May be billed as a percentage of license or a fixed annual amount.
Run-rate support charges: 15–25% of annual license cost is a common range, but it varies widely by vendor and service level.
Optional add-ons: security/compliance modules, analytics/BI add-ons, advanced reporting, AI features, mobile access, dedicated sandbox environments.
Data egress/exit costs: fees for migrating data out of the system if you switch vendors.
Training: optional training packages, on-site or virtual, sometimes priced per user or per day.
Training
New-user onboarding
Structured onboarding program with a defined curriculum
Role-based training (end users, power users, administrators)
Hands-on labs or sandbox environments
Training formats
Self-paced e-learning modules with progress tracking
Live virtual or in-person training sessions
Instructor-led workshops for admins and developers
Short how-to videos and quick-start guides
Curriculum scope
Product basics, navigation, and core workflows
Data model and data entry best practices
Security and access control configuration
Integrations and API usage
Reporting, dashboards, and analytics
Administration tasks: user provisioning, backups, maintenance
Certification and enablement
Optional certification programs for admins or power users
Documentation and knowledge bas
Access to product docs, release notes, troubleshooting guides
Community forum or support portal with searchable knowledge base
Security Measures
Data classification and encryption
Encryption at rest (AES-256, for example)
Encryption in transit (TLS 1.2+ with modern ciphers)
Access control and identity management
Role-based access control (RBAC) and attribute-based access control (ABAC)
Single sign-on (SSO) support (SAML 2.0, OpenID Connect)
MFA requirements for users with access to sensitive data
Data residency and sovereignty
Data center locations, ability to choose region, and data residency commitment
Data protection and privacy
Data minimization, encryption of backups, and secure data deletion
Pseudonymization or tokenization options if handling sensitive data
Compliance
Certifications and frameworks supported (ISO 27001, SOC 2, HIPAA, GDPR, CCPA, etc.)
Updates
Release cadence
How often updates are released (monthly, quarterly, semi-annual)
Major vs. minor releases and what constitutes a “major” change
Update types
Feature updates, security patches, bug fixes, and regulatory updates
Deployment model
Cloud: automatic vs. opt-in updates; maintenance windows; can you pause updates
On-prem: managed upgrades by Pxier or customer-driven upgrades; upgrade windows and prerequisites
Change management
How customers are notified (release notes, a change log)
Compatibility considerations, deprecation timelines, and upgrade guides
Sandbox/testing availability to validate updates before production
Rollback and safety nets
Ability to rollback updates in case of issues; data/schema migration handling
Impact on customization
How updates affect customizations, APIs, and integrations; upgrade assistance and testing suppor
Data Ownership and Portability
Ownership of data
Who owns the data stored in Pxier during and after the contract term (you vs. Pxier)
Rights to extract and retrieve data at any time.
Data formats and exportabilit
Available data export formats (CSV, JSON, XML, SQL dumps, etc.).
Frequency and any limits on bulk exports (one-time vs. scheduled exports)
Preservation of data schema, metadata, and history in exports.
Data retention and deletion
How long data remains accessible after contract termination.
Procedures for data deletion and certification of deletion (DLA, data wipe standards).
Handling of backups containing customer data after termination.
Data portability assistance
Availability of data migration services or tooling to migrate to another system.
Any fees or SLAs associated with data export/migration.
Scaling Up / Down
Elasticity model
How scaling works (automatic vs. manual), and any required approval steps.
Pricing impact
How licensing, seats, or module usage scales with usage.
Any minimum commitments, tier thresholds, and price protections for scaling.
Availability and performance during scaling
SLA implications when scaling (uptime, latency, throughput).
Operational process
Lead times to provision additional users, modules, or environments.
Impact on data migrations, integrations, or customizations when scaling up/down.
Downscaling constraints
Any penalties, minimum terms, or data handling considerations when reducing scope.
Data and security implications
How access controls, SLAs, and security configurations adapt during scale changes.
The terms & conditions for contract renewal and cancellation
Renewal structure
Auto-renewal vs. opt-in renewal; renewal notice periods.
Pricing at renewal
How pricing changes at renewal (annual inflation, market adjustments).
Any caps, discounts, or renegotiation windows.
Term lengths and termination rights
Length of contract terms (1 year, 3 years, etc.).
Early termination rights, penalties, and exit clauses.
Data and ownership on termination
Data return/export obligations at end of term and post-termination data deletion timelines.
Service continuation after termination
Access to data post-termination and any transitional support.
Renewal/termination notification requirements
Required notice period to avoid auto-renewal; format and delivery channel.
SLA and support continuity
How support and SLAs are maintained during the renewal negotiation period.
Compliance
ISO 27001, SOC 2 Type II, SOC 3, PCI DSS, HIPAA, GDPR, CCPA, FedRAMP, etc.
Compliance scope
Which parts of the product and data processing activities are covered by each certification.
Independent attestations
Availability of latest audit reports (SOC 2 Type II, ISO certificates) and their scope.
Data protection and privacy
Data processing agreements (DPAs), data processing location, subprocessors, and consent mechanisms.