Building a custom edtech platform touches more regulatory ground than almost any other software category — student data privacy, accessibility law, and interoperability standards all apply before you've written a line of code. This RFP template helps you evaluate development partners on the things that actually determine whether the project survives a district or institutional review, not just whether the demo looks good.

Who this is for: edtech founders, school district IT leads, and L&D or training platform owners about to commission a custom LMS, assessment tool, or learning platform build.

Before You Send the RFP

  • [ ] Define your learner population (K-12, higher ed, corporate L&D) — compliance obligations differ sharply between them
  • [ ] Document any existing SIS, LMS, or LRS systems the new platform must integrate with
  • [ ] Confirm whether any users will be under 13 (triggers COPPA) or are protected under FERPA
  • [ ] Set your accessibility bar explicitly (WCAG 2.1 AA is the current baseline, not a future target)
  • [ ] Identify internal stakeholders — IT, legal/compliance, curriculum, and procurement all typically need a say

Compliance & Data Privacy Questions

  1. How do you architect for FERPA's "School Official Exception," and what does that mean for our contract terms?
  2. If any users are under 13, how do you handle COPPA's opt-in consent requirements?
  3. Can you comply with state-specific student data laws (e.g., CA's AB 1584, NY's Ed Law 2-d) if we operate in those states?
  4. What data fields will the platform collect or store, and how is disability-related or accommodation data protected?
  5. Do you hold or can you produce a SOC 2 Type II report, and how do you handle deletion rights and breach notification?
  6. Are your contracts explicit about data ownership and a no-advertising-with-student-data clause?

Standards & Interoperability Questions

StandardWhat to ask
SCORM / xAPIWhich versions do you support (SCORM 1.2, 2004, or xAPI via an LRS), and where does the system of record for learner progress live?
LTIDo you support LTI 1.3 with Advantage for LMS embedding?
SIS integrationWhich student information systems have you integrated with directly, and how do you handle identity matching across systems?
ReportingWhat do we actually get in reports — a single score, per-question event data, or full time-series analytics?
Data exportCan we export raw learning records via API if we ever need to migrate or build our own analytics layer?

Accessibility Questions

  • [ ] Do you build to WCAG 2.1 AA by default, or is it a paid add-on?
  • [ ] Can you show an accessibility audit or VPAT from a past project?
  • [ ] How do you test with assistive technology (screen readers, keyboard-only navigation)?
  • [ ] Does your team include anyone with dedicated accessibility expertise, or is it handled ad hoc?

Process & Delivery Questions

  1. What's your typical timeline from kickoff to a pilot-ready release?
  2. How do you sequence standards support — for example, shipping SCORM first for early sales while building xAPI into the data layer for later analytics needs?
  3. What does your QA process look like, particularly for cross-browser and cross-device testing?
  4. What post-launch support do you offer during the critical first semester or quarter of use?
  5. How do you handle mid-project scope changes if curriculum or compliance requirements shift?

Vendor Scorecard

CriteriaWeightVendor AVendor BVendor C
FERPA / COPPA / state law readiness
Accessibility (WCAG 2.1 AA) track record
Standards support (SCORM/xAPI/LTI)
SIS/LMS integration experience
Cost clarity & contract terms
References from similar institutions

Red Flags to Watch For

  • Treats WCAG accessibility as an optional add-on rather than a default
  • Can't explain how their architecture separates the LMS system of record from analytics/reporting
  • Vague or evasive answers on data ownership and deletion rights
  • No experience with SIS integration relevant to your institution type
  • No mention of a SOC 2 report or equivalent security documentation

How to Use This

Send the RFP to every vendor under consideration and require written responses before any live demos — compliance answers in particular are easy to overstate verbally but hard to fudge in writing. Loop in your legal or compliance lead on the FERPA/COPPA section specifically, since gaps there can block a district or institutional contract entirely regardless of how good the platform is technically.