This guide lists questions, not answers. Which option is better depends on your obligations, your team, and the specific product. It is general information and not legal or procurement advice.
Who is responsible for what?
- Who patches, monitors, and responds to incidents?
- Who runs capacity, and who pays when usage spikes?
- What happens to your service if the vendor changes terms or retires a feature?
Where does your data go?
- What data is sent to the vendor, and is any retained?
- Is your data used to improve the vendor's models, and can you opt out in writing?
- Which regions and subprocessors are involved?
What evidence can you actually obtain?
- Which audit reports or authorizations exist for this exact product and deployment?
- Do they cover the features you intend to use?
- Can you obtain the evidence from the issuing body, not just the vendor?
What is the real cost?
Self-managed options move cost from licence fees to staff time, infrastructure, and risk. Hosted options move cost to usage fees and dependence. Compare both over the full period you expect to run the system.
For the evidence side of these questions, see procurement guidance and security and authorization evidence. The comparison topic tracks our plan to examine this further.
Frequently asked questions
Is hosted or self-managed deployment better?
Neither is better in general. It depends on your obligations, your team's capacity, and the evidence available for the specific product and deployment.
Does a vendor's security certification cover every deployment option?
Not necessarily. A status can apply to one product, region, or deployment and not another, so check the exact scope in the authoritative record.
What hidden costs does self-managing involve?
Staff time, infrastructure, monitoring, patching, and incident response, which replace or add to licence fees.
Sources
This article is editorial analysis. It cites no external sources and contains no product performance claims, benchmark figures, or policy facts.