SaaS & B2B Sales
Navigating Procurement and Security Reviews
Procurement and security arrive late in most software deals. Not because the buyer hid them, but because nobody asked early enough to find out they existed. Then a deal that was going to close this month meets a questionnaire nobody has seen before.
By Shane McGrath · Published 24 August 2026
Every software seller has had the call. The champion is enthusiastic, the business case is agreed, and then: "it just needs to go through security and procurement." The word "just" is doing a lot of work in that sentence.
They aren't obstacles. They're a different job
Procurement is measured on what they save and on risk avoided. Security is measured on what doesn't happen. Neither is measured on whether your buyer's problem gets solved. Treating them as blockers to get past misreads what they're for, and it shows.
The real cost is the timeline, not the terms
Most deals that slip here don't lose on price or fail a control. They lose weeks, because a questionnaire sat with an engineer for ten days, then came back with follow-ups, then the legal reviewer went on leave. Quarter-end forecasts die in that queue, quietly.
What to ask, and when
- Early, as part of understanding the problem: what has to happen internally before you can sign something like this?
- Who was involved the last time you bought software of this size, and how long did it take?
- Is there a security review, and what triggered one last time?
- Who owns the contract template, and has anything unusual come up in past negotiations?
- What would make this go faster, and what has slowed it down before?
None of these are clever. They're just asked months earlier than most sellers ask them, usually because asking feels like inviting the problem in. It's already in.
Help your champion, because they've never done this either
Your champion is not a procurement expert. They're an operations lead who now has to chase two colleagues for something they don't fully understand. A completed questionnaire, a named contact on your side and a plain summary they can forward does more for the deal than another follow-up email, and it's the same principle as not expecting them to sell internally alone.
Where the leverage actually is
In your own house. Standard security documentation ready before it's asked for. Known contract positions your team can concede without escalation. A named person who answers questionnaires in days rather than weeks. That's not selling skill, it's preparation, and it wins more software deals at the end of a quarter than negotiation training does.
FAQs
Common questions
- When should we ask about procurement and security?
- During discovery, alongside everything else about how the decision gets made. Sellers avoid it because it feels like slowing things down. Finding out in week two costs a conversation. Finding out in week ten costs the quarter.
- Should sellers negotiate directly with procurement?
- They should have the conversation, but not as if it's the same one they've been having with the champion. Procurement wants predictability and a defensible outcome. Keep the problem conversation alive with the people who own the problem.
- How do we speed up security reviews?
- Mostly on your side, not theirs. Documentation prepared in advance, a named responder, and honest answers about what you don't do. Buyers rarely punish a clear "no, we don't support that." They punish a week of silence.
More on saas & b2b sales
Want this working inside your team?
Book a free sales review and we'll find the simplest change that moves your numbers.
