In this article
Buying registry software is not like buying office supplies. The system you choose will shape how your officers schedule verifications, how your agency meets federal and state requirements, and how the public sees registry information for years to come. A rushed or vague procurement often ends with a tool that looks good in a demo and struggles in daily use.
This checklist walks through what to put in a request for proposals (RFP) and how to evaluate the responses. It is written for registry coordinators, procurement staff, and command staff who need a fair, defensible process. Adapt it to your purchasing rules and check your state statute and agency policy for procurement requirements.
Build the evaluation team first
Before you write a single requirement, assemble a small team that represents everyone who will use or support the system:
- A registry coordinator or records supervisor who knows the daily workflow
- A field deputy or officer who conducts address verifications
- An IT or security representative
- A procurement or finance representative
- A command staff sponsor who can make final decisions
Agree on the scoring method and weights before any vendor presents. Doing this up front keeps the process objective and protects the agency if a decision is challenged.
Functional requirements
Describe what the system must do in terms of your real work. "Must support verification scheduling" is weak. "Must calculate each registrant's next in-person verification date based on tier and state rules, and alert assigned staff before it is due" is strong.
SORNA workflows
Federal SORNA minimums (34 U.S.C. § 20901 et seq.) set verification frequency by tier: Tier I every year, Tier II every 6 months, and Tier III every 3 months. Your state law may be stricter or different. Requirements should cover:
- Initial registration capturing the information your state requires
- Tier assignment and registration period tracking
- Change reporting for name, residence, employment, and student status
- International travel notices
- Records for registrants who reside, work, or attend school in your jurisdiction
- Interstate and intrastate transfers
Verification scheduling and field work
- Automatic calculation of verification due dates
- Daily or weekly work queues for staff
- Mobile access for officers in the field
- Tracking of missed verifications and follow-up actions
Public website and notifications
- A public search page that displays only the fields your state allows
- Community notification options such as email alerts
- Controls for what information is public versus internal
Exports and reporting
- File exports that support your NSOPW and NCIC submission process
- Standard reports for supervisors and command staff
- Ad hoc reporting and data export in common formats
Security, migration, training, and support
Security
Require written answers on authentication, encryption, audit logging, personnel screening, data location, and incident response. Ask vendors to describe how their system is built to CJIS Security Policy requirements and whether they will sign the CJIS Security Addendum. Our article on CJIS security questions for registry software has a full question list you can paste into your RFP.
Data migration
- Which data sources will the vendor migrate (legacy system, spreadsheets, scanned files)?
- Who does field mapping and data cleanup, and who validates the results?
- Will historical records, photos, and documents be migrated?
- Is a parallel run or test migration included?
Training
- What training is included for administrators, office staff, and field officers?
- Is training on-site, remote, or recorded?
- Are user guides provided and kept current?
Support and service levels
- What are support hours and contact methods?
- How are issues prioritized, and what are the response time commitments for each priority?
- How are outages communicated?
- What remedies apply if service level commitments are missed?
Total cost of ownership questions
The lowest initial quote is not always the lowest cost. Ask every vendor to answer the same questions so you can compare the full contract term:
- What is included in the base subscription or license?
- Are there separate fees for implementation, migration, or training?
- How is pricing calculated (per user, per registrant, per agency, flat)?
- What happens to pricing if your registrant count or user count grows?
- Are upgrades and new features included?
- Are there charges for data exports, extra storage, or integrations?
- What are the renewal terms and any limits on annual increases?
- What does it cost to get your data back at contract end?
Scripted demos and reference checks
Scripted demos
Do not let each vendor show only its favorite features. Send every vendor the same scenarios in advance and require them to walk through each one live. Example scenarios:
- Register a new Tier II registrant and show when the next verification is due.
- Record a change of residence and show how staff are notified.
- Show a field officer's daily list and complete a verification on a mobile device.
- Process an international travel notice.
- Find who edited a registrant record and when, using the audit trail.
- Generate an export for your state or federal submission process.
- Show what the public sees on the registry website.
Have each team member score each scenario independently during the demo.
Reference checks
Ask for references from agencies of similar size and structure. Useful questions:
- How long did implementation take compared with the plan?
- How did the data migration go?
- How responsive is support when something breaks?
- What do your officers like and dislike about the system?
- Would you choose this vendor again?
Scoring matrix
Agree on categories and weights before demos. Score each vendor 1 to 5 in each category, multiply by the weight, and total the results. The weights below are an example; set your own based on agency priorities.
| Category | Weight (1-5) | Vendor A score | Vendor B score | Notes |
|---|---|---|---|---|
| SORNA workflows and verification scheduling | 5 | |||
| Security and CJIS Security Policy alignment | 5 | |||
| Mobile and field functionality | 4 | |||
| Public website and notifications | 3 | |||
| Exports and reporting | 4 | |||
| Data migration approach | 4 | |||
| Training and support | 3 | |||
| Total cost of ownership | 4 | |||
| References | 3 |
Next steps
A clear RFP saves time for your agency and for vendors, and it leads to a system that fits how your registry actually works. Start by documenting your current workflow, then turn each step into a requirement.
If you need to make the case for funding first, our budget justification guide and grant funding page can help. To see how Justice Compliance handles these scenarios, including its Compliance Work Engine for verification scheduling, request a demo and send us your script in advance.
Key takeaways
- Write requirements around your actual registry workflows, not feature lists
- Use scripted demos so every vendor is tested on the same scenarios
- Ask total cost of ownership questions that cover the full contract term
- Score vendors with a weighted matrix agreed on before demos begin
This article is general guidance based on federal SORNA minimums and common registry practice. It is not legal advice. Always check your state statute and agency policy.
Free PDF guide
Budget Justification Guide for Sex Offender Registry Systems
Build a defensible business case, with a workload worksheet and grant options.
Download free