Data engineering partner evaluation should end with a number you can defend to your board. In the 2026 Verizon Data Breach Investigations Report, third parties were involved in 48% of breaches in a dataset of more than 22,000 confirmed breaches, a share 60% higher than in the previous year's dataset. A data engineering firm gets production data, credentials and pipeline access, so picking one is a risk decision as much as a skills decision.
Most companies compare firms on slides and a day rate, then discover that the delivery team is not the team from the pitch. When you evaluate a data engineering partner, score evidence: what a firm shows in your repository, on your data, and in a call with a client who has since left it. Gates come first, the contract last.
What Data Engineering Partner Evaluation Should Decide
Data engineering partner evaluation is a scored comparison of shortlisted firms against published criteria and weights, using evidence the firms must produce (code, a paid pilot, references) rather than answers they write.
In our practice the score has to settle three questions. Can they build this? Will the people you met be the people who build it? Can you leave later without losing the platform?
This article assumes you have already decided to bring in a partner and have a shortlist, and covers how to score it: gates, weights, evidence, a paid pilot and the contract. What a data engineering engagement includes, and when outsourcing makes sense at all, is covered in our guide to what a data engineering engagement covers.
An RFI narrows the market to a shortlist; the RFP compares that shortlist. Data engineering vendor selection is decided at the RFP stage.
Set Knockout Gates Before You Score Anything
In our process a gate failure ends the evaluation; it is not a low score. We use four gates:
- A data processing agreement, if the partner will touch personal data on your behalf (Article 28 GDPR). The EDPB Guidelines 07/2020 allow only processors "providing sufficient guarantees" and call the duty to check them "a continuous obligation".
- Security evidence: a SOC 2 report, issued against the AICPA Trust Services Criteria, or an ISO/IEC 27001:2022 certificate. The AICPA publishes a mapping between the two.
- Ownership of code, infrastructure as code and credentials from the first commit.
- A named technical lead before signature, with a stated time allocation.
Check the scope of the security document: it has to cover the entity and location doing your work, and a SOC 2 report should cover a recent period. It proves a control system within that scope, not the security of your project.
Gating comes from supply chain risk practice. Control GV.SC-06 in NIST CSF 2.0 reads: "Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships." The CSA STAR registry helps tell a self-assessment from a third-party attestation.
The Weighted RFP Scorecard: Seven Criteria and Their Weights
Two public sector rulebooks are worth borrowing from here, even though neither binds a private company. Section 15.304 of the US Federal Acquisition Regulation requires that "All factors and significant subfactors that will affect contract award and their relative importance shall be stated clearly in the solicitation." Section 15.305 leaves the method open, "including color or adjectival ratings, numerical weights, and ordinal rankings." The UK Sourcing Playbook asks for "a scoring approach that promotes effective differentiation."
| Criterion | Weight | What a 4 looks like | Evidence to request |
|---|---|---|---|
| Production evidence | 20 | Two comparable platforms still running, confirmed by the client | Named references with a technical contact |
| Paid pilot | 20 | Acceptance criteria met in your environment by the proposed team | Pilot report against the written criteria |
| Named team | 15 | The people you met are the people who deliver | Delivery-team CVs and the lead's allocation |
| Commercial terms and total cost | 15 | Pricing broken down by role and assumption, close to your should-cost | Cost breakdown and change-control terms |
| Engineering practice | 10 | Delivery metrics and data tests shown on a live service | The five DORA metrics, a data test, a post-incident review |
| Security and data protection | 10 | Report or certificate scoped to the delivery team, subprocessors listed | SOC 2 report or ISO/IEC 27001 certificate, subprocessor list, draft DPA |
| Operating model and handover | 10 | Runbooks and handover plan agreed before signature | Sample runbook and exit plan |
Our weights, a starting point: adjust them, then publish them in the RFP before proposals arrive. Gates (DPA, security evidence, code ownership, named lead) sit outside the table: failing one ends the evaluation.
Score each criterion from 0 to 4: 0 for no evidence, 1 for an unsupported claim, 2 for a claim backed by a document, 3 for something shown live, 4 for evidence verified in your environment or by a reference client. The total is the sum of (score / 4 × weight), with 100 as the maximum.
Evaluators score alone, before any discussion, or the most senior person in the room sets everyone's numbers. Pilots and reference calls go only to the top two or three firms on paper. And publish the weights before the proposals arrive, or the weights will drift toward the proposal you already like. That rule does more for a fair evaluation of a data engineering partner than any extra criterion.
RFP Questions That Force Firms to Show Artifacts
A written answer costs a vendor nothing. Our rule for a data engineering RFP: every answer must point to an artifact you can open, run or call. For example:
- Production evidence: "Name two platforms comparable to ours that you run today or ran for 12 months or more, with a technical contact at each client."
- Engineering practice: "Show the five DORA metrics for one service you operate today, a data test that blocked a bad load, and a redacted post-incident review."
- Named team: "Send CVs for the delivery team, not the company, and the share of the lead's time allocated to us."
- Security: "Attach your SOC 2 report or ISO/IEC 27001 certificate with its scope, your subprocessor list, and where our data will be stored."
- Data management: "Which areas (governance, data quality, metadata) do you own, and which stay with us?" Use DAMA-DMBOK as the shared vocabulary.
- Commercial: "Break the price down by role, rate and assumption."
The DORA question works because the five metrics cover both throughput and instability, and DORA's research finds that "speed and stability are not tradeoffs." A capabilities deck in place of the artifact earns a 0 or 1.
Run a Paid Pilot on Your Data, Scored Against Written Criteria
The UK Sourcing Playbook recommends a pilot when a service is outsourced for the first time: "Piloting a service delivery model is the best way to understand the environment, constraints, requirements, risks and opportunities."
Our rules: pay for it, because a free pilot is run by the sales team and a paid pilot is run by the team you will actually get. Run it in your environment, on your data, with the people named in the proposal. Write the acceptance criteria before the start, such as one pipeline running end to end with data tests in CI and documentation a new engineer can follow.
Pick one real pipeline with a known hard spot, such as late-arriving data or a schema that changes without notice. The pilot should be long enough to hit one real failure mode and short enough that being wrong is cheap. The result enters the paid pilot row as a 0 to 4, judged against the written criteria only.
Reference Checks and Red Flags That Change the Score
The vendor picks its references, so apply FAR 15.305 logic: it weighs how relevant past work was, and a firm with no record "may not be evaluated favorably or unfavorably on past performance." We carry that neutrality into the scorecard: a young firm without comparable references gets a neutral 2 for production evidence, not a zero.
Our protocol: talk to an engineer at the client, not only the sponsor. Ask whether anyone from the proposed team worked on their account. Ask the vendor for one client that ended the engagement, and call it. Ask every reference the same five questions.
These red flags lower the matching row by at least one point:
- The pilot team differs from the team in the proposal.
- The subprocessor list is missing or arrives only after signature.
- The ISO or SOC 2 scope covers a different entity or location than the delivery team.
- The firm refuses to run the pilot in your environment.
- The price sits well below your should-cost with no stated assumptions.
- Every reference is a client in its first year.
Trust is what a reference check tests. In an ENISA study of 24 supply chain attacks (2021), around 62% of the attacks on customers took advantage of their trust in their supplier. Those were software cases; treat the figure as an illustration.
From Scorecard to Contract: Terms That Keep the Score Honest
A score only matters if the contract holds the firm to whatever earned it. After an evaluation of a data engineering partner, we carry five terms into the agreement:
- Key personnel: the named lead and scored roles go into the contract, and substitution needs your written consent.
- Pilot result as scope: fixed price applies only to the scope the pilot proved.
- A specific DPA: per the EDPB, it "should not, however, merely restate the provisions of the GDPR," and it should include audit and inspection rights under Article 28(3)(h). The European Commission's standard contractual clauses for controllers and processors of June 4, 2021 are a ready starting point.
- Should-cost: the Sourcing Playbook uses a should-cost model against "low cost bid bias". If the cheapest bid sits below your model, ask what it leaves out.
- Ownership and exit: follow the ownership and exit terms we set in a first agreement, in line with NIST CSF 2.0 GV.SC-10 on "activities that occur after the conclusion of a partnership or service agreement".
When DS Stream answers a data engineering RFP, we send the same artifacts we tell you to ask for and agree to a paid pilot on the client's data. See how we deliver and run data platforms, or send us your RFP and scorecard.
FAQ
What criteria should a data engineering partner evaluation use?
A data engineering partner evaluation should start with pass/fail gates (a DPA if personal data is involved, security evidence, code ownership, a named lead) and then score seven weighted criteria. In our weights, production evidence and a paid pilot carry 20 points each out of 100, because both are verified outside the proposal.
How much weight should price get in a data engineering RFP?
We suggest 15 out of 100, in a row combining total cost and commercial terms. FAR 15.304 requires price to be evaluated in every source selection, with quality scored separately. Check each bid against your should-cost model.
Should a pilot with a data engineering vendor be paid?
Yes. A paid pilot runs in your environment, with the delivery team named in the proposal and acceptance criteria written in advance. The UK Sourcing Playbook recommends a pilot whenever a service is outsourced for the first time.
What security documents should a data engineering partner provide?
A SOC 2 report or ISO/IEC 27001 certificate scoped to the delivery team's entity and location, plus a subprocessor list. If the partner will touch personal data, add a data processing agreement under Article 28 GDPR that describes how requirements are met instead of restating the regulation.
