En bref : Product-market fit proves users want the product; procurement fit proves the organisation can buy the company, and in regulated European markets that second fit is now an engineered, investable asset.
Two different buyers sign two different cheques
An enterprise deal carries two verdicts. The first comes from the people who use the product: an analyst who saves a day a week, an energy manager who finally sees meter data in one place, a sustainability lead who closes the reporting cycle in a single pass. Their enthusiasm proves the product solves a real problem. The second verdict comes from the organisation around them, and it answers a different question: can this company, with this balance sheet, this security posture and this contract, safely become part of how we operate?
Product-market fit measures the first verdict and procurement fit the second. A start-up reaches procurement fit when its company, as distinct from its product, consistently clears the security review, the privacy assessment, the legal negotiation, the vendor-risk file and the budget cycle of the customers it targets. The two fits run on separate clocks, and founders who treat them as one discover the gap after the pilot succeeds and before the rollout is signed.
Research by the International Data Corporation (IDC) with Lenovo found that for every 33 artificial intelligence (AI) proofs of concept a company launched, four reached production. IDC attributed the attrition to low organisational readiness in data, processes and information technology (IT) infrastructure, and noted that many pilots run with thin funding or none and a weak business case. Read from the vendor’s side, the pattern describes pilots that won the user and stalled at the edge of the organisation’s buying machinery. A signed pilot is a milestone on the path to revenue, and the distance between the two equals the number of institutional approvals still outstanding.
Each approval has an owner with a specific question and a specific standard of evidence. Mapping them turns a vague sense of “enterprise friction” into a list a founder can work through and an investor can diligence. Four instruments set most of that evidence in Europe: the General Data Protection Regulation (GDPR), the Swiss Federal Act on Data Protection (FADP), the second Network and Information Security Directive (NIS2) and the Digital Operational Resilience Act (DORA).
| Gatekeeper | Question asked | Evidence that answers it |
|---|---|---|
| End users | Does it make my work better? | Usage, retention, pilot outcomes |
| Budget holder | Which line pays, and what returns? | Business case in the buyer’s own metrics |
| IT and architecture | Does it fit our stack and identity model? | Single sign-on, integration plan, data residency |
| Security | Can we trust its controls over time? | Attested control report, penetration test, secure development process |
| Privacy and legal | Does it qualify as our processor? | GDPR Art. 28 contract, audit rights, Swiss FADP security terms |
| Vendor risk and procurement | Can we document, audit and exit this supplier? | DORA Art. 30 clauses, NIS2 supply-chain file, exit plan |
| Finances | Will the vendor still exist in three years? | Runway, funding, reference customers, continuity terms |
Regulation has written the vendor into the buyer’s compliance file
Enterprise procurement friction used to be largely cultural; in Europe today it is statutory. Successive regulations have moved responsibility for a supplier’s conduct onto the customer, which means a large buyer now carries legal exposure for every vendor it onboards. Procurement teams respond rationally, by demanding evidence before signature and contractual rights after it.
Data protection makes every software vendor a processor to be vetted
The GDPR obliges a controller to use only processors providing sufficient guarantees of appropriate technical and organisational measures, and Article 28(3)(h) requires the processor to make available all information needed to demonstrate compliance and to allow audits, including inspections. Article 28(2) adds that a processor engages a sub-processor only with the controller’s prior specific or general written authorisation, so every downstream cloud or AI service a start-up relies on enters the same review. Switzerland’s revised FADP, in force and enforceable since 1 September 2023, sets the parallel duty that controller and processor guarantee data security appropriate to the risk. A start-up handling customer personal data enters the buyer’s legal file the day it goes live, and the buyer’s privacy team vets it accordingly.
Financial and energy buyers now audit their suppliers by statute
DORA, applicable since 17 January 2025, goes furthest. Article 30 requires every contract for information and communication technology (ICT) services to carry termination rights with minimum notice periods. Where the service supports a critical or important function, it adds unrestricted rights of access, inspection and audit for the entity and its competent authority, a mandatory transition period so the customer can migrate away, and the provider’s full cooperation in threat-led penetration testing. A fintech or insurtech vendor needs those clauses ready before a regulated bank is permitted to sign, whatever its users think of it.
NIS2 extends the same logic beyond finance. Article 21(2)(d) lists supply chain security, including relationships with direct suppliers among the measures essential and important entities must take, and Article 21(3) tells them to weigh each supplier’s cybersecurity practices, explicitly including its secure development procedures. Annex I places the whole energy system in scope: distribution and transmission system operators, producers, aggregators, energy storage, recharging point operators, district heating and hydrogen infrastructure. Those are precisely the customers climate-tech software sells to.
Supervisors now read the vendor list line by line
DORA turned the supplier file into a supervisory dataset. Every financial entity keeps a register of information covering each contractual arrangement with an ICT provider, and the European Supervisory Authorities (ESAs) set 30 April 2025 as the deadline for the first submission of those registers, collected by national competent authorities ahead of that date. A start-up selling to a bank or an insurer therefore appears as a line in a file its customer’s supervisor reads, with the contract and the function it supports recorded beside its name.
The registers also feed oversight of the largest suppliers. On 18 November 2025 the ESAs published the list of designated critical ICT third-party providers, and the list names 19 firms, among them Amazon Web Services, Google Cloud, Microsoft, SAP, Orange and Deutsche Telekom. Those providers now face direct examination by European supervisors. The procurement team that negotiates with a young vendor has just documented its largest ICT contracts to that supervisory standard, and it sends the same questionnaire to every newcomer.
NIS2 adds a timing problem. In May 2025 the European Commission sent reasoned opinions to 19 member states for failing to notify full transposition of the directive, Germany, France, Spain and the Netherlands among them. A vendor selling to energy operators across several countries meets national rules at different stages of adoption. Allegory Capital expects buyers to apply the strictest reading they know to every supplier, which raises the evidence bar for every start-up in the pool.
The evidence has a lead time longer than a pilot
A widely requested security attestation, a System and Organization Controls (SOC) 2 Type II report, requires an observation window of three to twelve months, preceded by one to three months of preparation and followed by several weeks of audit and reporting. That window outlasts the interval between a successful pilot and the steering-committee decision, so founders start the procurement work before product-market fit is proven. A start-up that opens its observation window at the first pilot reaches its first large contract with the report in hand.
| Instrument | Applies from | What the buyer must obtain from the vendor |
|---|---|---|
| Swiss FADP | 1 Sep 2023 | Data security appropriate to the risk |
| GDPR Art. 28 | 25 May 2018 | Sufficient guarantees, processing contract, audit and inspection rights |
| NIS2 Art. 21 | Transposed nationally | Supply-chain risk assessment, including secure development |
| DORA Art. 30 | 17 Jan 2025 | Termination rights for all ICT contracts; audit access, exit transition and testing cooperation for critical functions |
| SOC 2 Type II | Market standard | Roughly five to eighteen months to a first attested report (Vanta phase estimates) |
Climate-tech meets the steepest version of the gap
Climate and energy software meets eager users inside heavily gated organisations. Sustainability and grid teams adopt tools quickly because their pain is measurable in tonnes and megawatts. Their employers are utilities and grid operators that sit inside NIS2’s energy perimeter, run operational technology under its own security regime, and buy through formal tenders.
The Omnibus directive amending the Corporate Sustainability Reporting Directive (CSRD), in force since 18 March 2026, limits mandatory reporting to companies with more than 1,000 employees and net turnover above €450 million, with the revised scope applying to financial years starting on or after 1 January 2027. Allegory Capital reads the cut as a concentration of demand for reporting and carbon-accounting software among the largest companies, which also run the deepest procurement machinery. The mid-market buyers who once signed on a sustainability lead’s recommendation have largely left the mandatory pool; the remaining buyers ask for every row of Exhibit 1.
A climate-tech product built for a European sustainability team in 2026 therefore needs procurement fit for a large regulated enterprise from its first serious customer. A distribution system operator, one of the energy entities NIS2 Annex I names, weighs each supplier’s secure development procedures under Article 21(3) before that supplier touches grid data. Teams that arrive with processing terms, an attestation and an exit plan already drafted convert the pilots that equally good software leaves stranded.
Procurement fit accumulates into a moat that investors can price
Procurement work accumulates. A completed security review becomes a reusable questionnaire answer, a negotiated processing agreement becomes the template the next legal team accepts faster, and each reference customer in a regulated sector shortens the next vendor-risk file. Under DORA the effect is visible in the paperwork itself: a vendor already mapped correctly in one bank’s register of information arrives at the next bank with its function classification, subcontracting chain and exit terms tested by a regulated counterparty. Once a company clears procurement repeatably, its reference customers and accepted contract templates raise the cost of entry for every newcomer, however elegant the newcomer’s product. It is the operational face of the regulatory moat that draws Series B capital to regulated-industry start-ups.
For fondateurs, the work starts with a map of every approval the target customer requires, its owner and the evidence that satisfies it. Each pilot then runs on expansion criteria agreed in writing at the outset, naming the budget line that funds rollout, the security and privacy reviews completed during the pilot, and the contract template both legal teams accept. The attestation clock starts early enough for the report to exist when the first large customer asks for it.
For investors, procurement fit belongs in diligence alongside retention and net revenue retention. Diligence asks what share of pilots converted to paid rollout, how many months separated pilot success from signed master agreement, which security attestations exist today, how many vendor-risk files the company has already passed, whether its standard contract already carries the audit, exit and termination clauses its regulated customers must obtain, and which of its own critical services run on one of the 19 designated providers, a dependency its customers’ registers will record anyway. Those answers show whether the organisation, as well as the user, has said yes.
For enterprise buyers, the same map runs in reverse. A bank that hands a start-up its DORA Article 30 clause set and its GDPR Article 28 processing terms at pilot kick-off gives the vendor the whole pilot period to prepare them. That shortens procurement for both parties and lets internal champions carry promising start-ups through the queue.
The start-ups that scale in regulated Europe earn the user’s choice and the organisation’s, and the organisation’s choice, recorded in a passed vendor-risk file and an accepted contract template, is the one a newcomer finds hardest to displace.
This article has been reviewed by Haider Alleg, General Partner at Allegory Capital.
Références
- CIO. 88% of AI pilots fail to reach production: but that’s not all on IT. https://www.cio.com/article/3850763/88-of-ai-pilots-fail-to-reach-production-but-thats-not-all-on-it.html
- Regulation (EU) 2016/679 (GDPR), Article 28. https://eur-lex.europa.eu/eli/reg/2016/679/oj
- DLA Piper. Data Protection Laws of the World: Switzerland. https://www.dlapiperdataprotection.com/index.html?c=CH&t=law
- Regulation (EU) 2022/2554 (DORA), Article 30. https://eur-lex.europa.eu/eli/reg/2022/2554/oj
- Directive (EU) 2022/2555 (NIS2), Article 21. https://eur-lex.europa.eu/eli/dir/2022/2555/oj
- Directive (EU) 2022/2555 (NIS2), Annex I. https://eur-lex.europa.eu/eli/dir/2022/2555/oj
- Vanta. How long does a SOC 2 audit take? https://www.vanta.com/resources/how-long-does-a-soc-2-audit-take
- AKD. Changes to the CSRD: Omnibus Directive enters into force on 18 March 2026. https://www.akd.eu/insights/provisional-agreement-on-omnibus-i-changes-to-the-scope-and-reporting-obligations-under-the-csrd
- PwC Luxembourg. EU finalises agreement on Omnibus. https://www.pwc.lu/en/sustainable-finance/eu-finalises-agreement-on-omnibus.html
- ESMA. The ESAs announce timeline to collect information for the designation of critical ICT third-party service providers under DORA (15 November 2024). https://www.esma.europa.eu/press-news/esma-news/esas-announce-timeline-collect-information-designation-critical-ict-third
- ESMA. The European Supervisory Authorities designate critical ICT third-party providers under DORA (18 November 2025). https://www.esma.europa.eu/press-news/esma-news/european-supervisory-authorities-designate-critical-ict-third-party-providers
- EIOPA. List of designated CTPPs (18 November 2025). https://www.eiopa.europa.eu/document/download/56b1ca78-5dd2-4d36-8377-47a538eb7558_en?filename=List%20of%20designated%20CTPPs.pdf
- European Commission. Commission calls on 19 Member States to fully transpose the NIS2 Directive (7 May 2025). https://digital-strategy.ec.europa.eu/en/news/commission-calls-19-member-states-fully-transpose-nis2-directive