Vendor lock-in almost never gets measured before a contract is signed. It gets discovered after, when leaving turns out to cost more than anyone estimated and the estimate that mattered was never actually made.
I’ve written before about vendor lock-in inside industry-specific ERP specifically. This is the general version — a measurement exercise that applies before you sign anything, in any category, because lock-in is not a property of bad vendors. It’s a property of contracts and architectures that were never tested for it, and it accumulates whether or not the vendor intended it to.
The four things that actually create lock-in
Lock-in is rarely one dramatic clause. It’s usually four smaller things, each individually reasonable, that compound.
Free · 4 minutes
Do you know what could take the business down — and have you priced it?
Fourteen questions on concentration, third-party dependence, resilience, and incident readiness — the exposures a board is accountable for whether or not it can see them. Banded finding on screen, full sheet by email.
Data export terms. Ask, before signing, exactly what format your data comes out in if you leave, how long extraction takes, and whether the export is complete or a subset. “You can export your data” and “you can export your data in a usable format, completely, within a timeframe that doesn’t hold your business hostage” are different promises, and vendors are careful to only make the first one explicitly.
Proprietary extensions. Every platform that lets you customise is, to some degree, encouraging you to build logic that only runs inside it — workflow rules, custom fields, scripting in a vendor-specific language. The more of your actual business logic lives inside those extensions, the more expensive leaving becomes, because leaving now means rebuilding logic, not just moving data. This cost is invisible at signing and grows with every customisation approved afterward, one reasonable request at a time.
Integration depth. A platform that becomes the system of record other tools write to and read from is far more entrenched than one used in isolation. Count how many other systems would need to be re-pointed if this platform disappeared tomorrow. That number, more than any contractual clause, is the real measure of how embedded a vendor has become.
Contractual switching cost. Minimum terms, auto-renewal clauses, data-migration assistance fees, and — increasingly — AI features priced or licensed in ways that make the platform harder to leave once your team has built workflows around them. Read the contract specifically for what happens in the first ninety days after a termination notice, not just what happens during the term.
How to actually measure it before signing
Before any contract is signed, price an exit as if you were doing it eighteen months from now: what would extraction cost, in time and money; what proprietary logic would need rebuilding; what other systems would need re-pointing; what the contract actually says about the transition period. If that exit price is high enough to change your appetite for the deal, that is exactly the information the vendor’s sales process is not going to volunteer, and it’s the information a pre-signature review exists to surface. If it isn’t high enough to worry about, sign with genuine confidence instead of hopeful assumption — the exercise has value either way, because the alternative is finding out the real number only when you actually need to leave, at the worst possible moment to be doing that arithmetic for the first time.
A case where the exit price changed the decision
A maritime operator evaluating a fleet-management platform found, on a pre-signature review, that the vendor’s standard contract offered data export “on request,” undefined format, no committed timeline — language that reads as reasonable in a contract review and means, in practice, whatever the vendor decides it means the day you actually need to leave. The platform also proposed absorbing several existing point solutions — crew scheduling, maintenance logging, compliance documentation — as native modules, which was the actual selling point. Priced honestly, that consolidation is also the lock-in: three systems’ worth of institutional data and workflow logic, migrating into one vendor’s proprietary structure, with no committed exit terms. That didn’t kill the deal — the platform was still the right choice — but it changed the negotiation, because “data export on request” became a specific, defined, contractually committed clause before signature rather than a hopeful assumption discovered years later.
This measurement is also, not incidentally, the practical test behind being credibly vendor-agnostic rather than just claiming to be. Agnosticism that hasn’t priced the exit cost of its own recommendation is a slogan, not a design property.
A pre-signature vendor lock-in review is a small, specific piece of work that changes the negotiating position before the contract is final rather than after. It fits naturally inside a technology control assessment scoped around an active procurement decision.
This measurement exercise works best as part of the wider build-vs-buy decision framework, run before a vendor conversation starts, not after.
The exercise takes days, not weeks, and it’s worth treating as standard practice for any platform decision above a modest threshold — not a formality reserved for the largest, most obviously risky procurements. Lock-in accumulates fastest in the platforms nobody thought to scrutinise closely, precisely because they looked too straightforward to bother measuring.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Governance is what happens when nobody is watching.
Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming