OutsourcingVN is operated by Netbase JSC, and Netbase is itself a software vendor you might evaluate. This page is therefore not neutral: it names no competitor, ranks no vendor and asks you to score Netbase by the same rules. OutsourcingVN records material claims with source, owner and review date, publishes the lower figure on conflict and does not rank competitors. The criteria below are the site's provider comparison framework, criteria version 1.0, reviewed 2026-09-22, next scheduled review March 2027.
Contents
- Does the vendor type change the criteria?
- Which criteria belong on the scorecard?
- How should the criteria be weighted for your project?
- How do you run the evaluation?
- How do you check that a vendor's evidence is real?
- What does a worked evaluation look like?
- What goes wrong in vendor evaluations?
- How does Netbase answer its own scorecard?
- Common questions
- How this guide is sourced and where it stops
- Put Netbase through the same scorecard
Does the vendor type change the criteria?
The criteria stay the same; their weights move. A project vendor that takes responsibility for an outcome should be judged hardest on delivery ownership and acceptance. A staff augmentation provider that supplies people under your management should be judged hardest on team quality, continuity and replacement terms, because you own the delivery. A product company offering implementation services should be judged on how much of the work is configuration of its own licensed product, and what you can take with you if you leave. The comparison of project outsourcing and staff augmentation helps you decide which type you are buying before you score anyone, and engagement models describes the shapes Netbase contracts under.
Which criteria belong on the scorecard?
Each criterion has evidence that counts and evidence that looks persuasive but proves little.
| Criterion | What it tests | Evidence that counts | Evidence that proves little |
|---|---|---|---|
| Relevant delivered work | Has this vendor done work like yours, in the role it now proposes? | A described project with scope, the vendor's role and a contactable reference | Logo walls, award badges, "similar projects" without scope |
| Delivery ownership | Who is accountable on the vendor side once the contract is signed? | Named project lead, architect and QA owner who join the pre-contract calls | A sales lead who promises to assign a team later |
| Governance | Will you know about problems early? | A sample weekly report, risk log and escalation route from a real project, anonymised | "Agile" as a word with no artefact behind it |
| Acceptance and change control | How is "done" decided, and how are changes priced and approved? | Written milestone acceptance criteria and a change-request template | Acceptance defined as delivery of code |
| Security and secure development | How does the vendor protect your code, data and access? | Named practices, company-level certifications or attestations with their scope explained, and willingness to sign a DPA | A certificate presented as covering your product |
| Team and subcontracting | Who actually writes the code, and what happens when someone leaves? | Roles, employment status, disclosed partners and a replacement rule | Refusal to say where or by whom the work is done |
| IP and exit | What do you own, and can you leave cleanly? | Contract wording on IP, a list of licensed components and a handover package | Source code held back until an unrelated condition is met |
| Commercial clarity | Can you compare the offer with others on equal terms? | Assumptions, exclusions and what is not included, itemised by phase | A single figure with no stated assumptions |
The IP ownership guide and the handover and exit guide go deeper on the last two rows, and the total software delivery cost guide shows how to normalise commercial offers.
How should the criteria be weighted for your project?
Set weights before reading any proposal, or they drift toward the favourite. A three-level scale is enough: 3 for decisive, 2 for important, 1 for hygiene.
| Criterion | New product build | Legacy modernisation | Regulated or personal data | Staff augmentation |
|---|---|---|---|---|
| Relevant delivered work | 3 | 3 | 2 | 2 |
| Delivery ownership | 3 | 3 | 2 | 1 |
| Governance | 2 | 3 | 3 | 2 |
| Acceptance and change control | 3 | 2 | 2 | 1 |
| Security and secure development | 2 | 2 | 3 | 2 |
| Team and subcontracting | 2 | 2 | 3 | 3 |
| IP and exit | 2 | 3 | 3 | 2 |
| Commercial clarity | 2 | 2 | 2 | 2 |
Some criteria are gates rather than weights. If a vendor will not name who holds access to your data, or will not put IP ownership in writing, no score elsewhere compensates.
How do you run the evaluation?
-
Write one brief
Every vendor answers the same page, built from the software project brief template.
-
Apply the gates
Remove vendors that fail a must-pass condition before scoring anyone.
-
Send one evidence request
The same list, from the "evidence that counts" column, with the same deadline.
-
Score independently
Two evaluators score each criterion 0 to 3 without conferring, then reconcile differences in writing.
-
Call the references yourself
Use contacts you arranged directly, and ask the questions in the next section.
-
Buy a small first milestone
A paid discovery or first delivery milestone with written acceptance tests the vendor's behaviour better than any proposal.
-
Record the decision
Keep the scores, the evidence and the reason for the choice, so the decision survives a change of people.
For the security criterion, NIST SP 800-161 Rev. 1 Update 1 gives a basis for assessing suppliers, and NIST SP 800-218 lists secure development practices to ask about. The attestation form that the US Cybersecurity and Infrastructure Security Agency released on 11 March 2024 for federal software producers is a useful model of what a vendor should be able to attest to, even outside that market.
How do you check that a vendor's evidence is real?
Grade each piece of evidence before you score it:
- Tier 1: verifiable. A named client that consented to be named, a reference you can contact, and scope that matches the published record.
- Tier 2: described. An anonymised project with scope and the vendor's role stated, and a reason for the anonymity, such as a confidentiality obligation.
- Tier 3: asserted. Logos, counts, awards and testimonials without a traceable source.
Score delivered work mostly on tier 1 and 2 evidence. On a reference call, ask what the vendor was responsible for and what it was not, what went wrong and how it was reported, whether the named team was the team that delivered, and whether the client would hire the vendor again for the same kind of work.
What does a worked evaluation look like?
A hypothetical logistics company wants a customer portal built over two quarters, with personal data involved. It weights the scorecard using the "regulated or personal data" column, and three vendors pass the gates.
- Vendor A has the strongest sales presentation and a long logo list, but offers one tier 1 reference and cannot name its architect before signature. It scores poorly on ownership.
- Vendor B supplies two described projects, a sample weekly report and a named team, but its contract keeps a reusable framework licensed with no exit terms. The IP gate forces a contract change.
- Vendor C is the smallest and scores highest on governance and security evidence, but its only similar project is anonymised with no reference available.
The company buys a paid discovery milestone from B and C with the same acceptance criteria, and chooses on how each handled the first change request.
What goes wrong in vendor evaluations?
- Scoring the pitch. Signal: scores follow the best presenter. Fix: score only evidence received in writing.
- Weights set after reading proposals. Signal: the favourite wins every weighting debate. Fix: freeze weights before the evidence request.
- One evaluator. Signal: no disagreements are recorded. Fix: two independent scorers and a written reconciliation.
- Certificates read as project controls. Signal: "they have ISO 27001, so our data is safe". Fix: ask how the company's certification maps to the practices your project will actually use.
- No exit question. Signal: nobody asked what happens if the relationship ends. Fix: make exit a gate.
- Home-country bias. Signal: vendors abroad are scored on nationality rather than evidence. Fix: the same criteria everywhere. The Vietnam provider comparison and the pre-contract due diligence guide apply the same logic to one country.
How does Netbase answer its own scorecard?
Score Netbase with the same evidence rules. For relevant delivered work, the 4over4 print commerce record is a tier 1 example: Netbase delivered e-commerce conversion work on the 4over4 print store, including a product recommendation engine, and the published case study reports revenue up 82% within six months and conversion up 48%. Those are one client's results on one store, not a benchmark. Every other record under Work states its evidence level.
On the other criteria: Netbase has served more than 500 clients, in the United States, Europe and Asia-Pacific, with most projects coming from clients outside Vietnam. Delivery runs with weekly reviews and a named project manager, in English. Security practices include secure code review and version control, role-based access control, MFA for admin dashboards, contributors under NDA, and NDAs and DPAs on request; Netbase JSC holds ISO 27001 certification for information security management and a SOC 2 Type II attestation, neither of which extends to a client's product or hosting. For custom development the client owns the IP created for it; Netbase productized modules and products are licensed, not transferred. The data security and compliance guide lists the contract questions to put to Netbase or anyone else.
Plan the next step for your project
Common questions
Because the operator, Netbase, is a vendor. A ranking published by a competitor cannot be neutral, so the page publishes criteria and names no other company.
Three to five after the gates is workable. More than that spreads evaluator attention thin and rewards vendors with large sales teams.
Commercial clarity is. The amount matters only once offers are normalised to the same scope, assumptions and exclusions; before that, a lower figure usually means less included.
Yes. The criteria test ownership, evidence, security, IP and exit, which do not depend on location. Time-zone overlap and working language belong under governance, weighted for your team.
The framework is criteria version 1.0, reviewed 2026-09-22, with the next scheduled review in March 2027.
How this guide is sourced and where it stops
The criteria, weights and evidence tiers are editorial method: no vendor was included, excluded or scored to produce this page, and no external company is named. External references are the NIST and CISA publications listed under Sources. Statements about Netbase map to approved claims in the OutsourcingVN claim register, and the methodology explains how evidence levels are labelled. The delivery record behind this page is Netbase's own as a vendor, not a record of running evaluations for buyers: Netbase has no published engagement as an independent evaluator, and this guide is not a legal, financial or security assessment. The worked evaluation is hypothetical.
Put Netbase through the same scorecard
Send your brief and your evidence request, and ask for written answers to every criterion. The build route is custom product engineering, and the wider operating model is described under global delivery. OutsourcingVN is Netbase's own outsourcing-services platform; submit a project and score the reply like any other vendor's.
Related services and solutions
Custom product engineering for a bounded release outcome
One defined release of your product, built to named outcomes and handed over with acceptance evidence.
Learn More