Skip to content

Phase 3: Commercial & Contracting

Phase goal: Align commercial, legal, and procurement so the delivery team can kick off without contract or access blockers.

  1. Proposal & pricing — fixed-fee, Time and Materials (T&M), retainer, or hybrid per phase; includes optional managed operations.
  2. Statement of Work (SOW) — scope, deliverables, milestones, acceptance criteria, assumptions, change control.
  3. Technical appendix — references assessment report, Architecture Decision Record (ADR), and artifacts catalog.
  4. Legal & procurement — Master Service Agreement (MSA), Non-Disclosure Agreement (NDA), Data Processing Agreement (DPA), insurance policy, Google Cloud Platform (GCP)/partner vendor registration if relevant.
  5. Client internal approval — budget, vendor security review, and invoice/Purchase Order (PO) contact.
SectionExample contents
ScopeLanding zone, Development, Security, and Operations (DevSecOps) pipeline, hardening, specific applications
Out of scope24×7 operations outside package, third-party licenses
DeliverablesDocument list, code, infrastructure as code, runbooks
Milestone & paymentTied to phase or sprint review
Service Level Agreement (SLA) for communicationEscalation response — see Communication
Change requestScope change process and cost/time impact
Intellectual property & licensesCode ownership, Infrastructure as Code (IaC), open source licenses
ConfidentialityData, environments, and production access
  • Client: Procurement, legal, budget sponsor, security vendor assessment
  • PT CPI: Engagement lead, delivery manager, legal/commercial support
  • Statement of Work (SOW) / Purchase Order (PO) signed or purchase order issued
  • Invoice contact and project code agreed
  • Kickoff schedule (Phase 4) confirmed

2–8 weeks — highly dependent on enterprise procurement cycles.

Next: Engagement checklist then Phase 4: Kickoff