Building a custom edtech platform touches more regulatory ground than almost any other software category — student data privacy, accessibility law, and interoperability standards all apply before you've written a line of code. This RFP template helps you evaluate development partners on the things that actually determine whether the project survives a district or institutional review, not just whether the demo looks good.
Who this is for: edtech founders, school district IT leads, and L&D or training platform owners about to commission a custom LMS, assessment tool, or learning platform build.
Before You Send the RFP
- [ ] Define your learner population (K-12, higher ed, corporate L&D) — compliance obligations differ sharply between them
- [ ] Document any existing SIS, LMS, or LRS systems the new platform must integrate with
- [ ] Confirm whether any users will be under 13 (triggers COPPA) or are protected under FERPA
- [ ] Set your accessibility bar explicitly (WCAG 2.1 AA is the current baseline, not a future target)
- [ ] Identify internal stakeholders — IT, legal/compliance, curriculum, and procurement all typically need a say
Compliance & Data Privacy Questions
- How do you architect for FERPA's "School Official Exception," and what does that mean for our contract terms?
- If any users are under 13, how do you handle COPPA's opt-in consent requirements?
- Can you comply with state-specific student data laws (e.g., CA's AB 1584, NY's Ed Law 2-d) if we operate in those states?
- What data fields will the platform collect or store, and how is disability-related or accommodation data protected?
- Do you hold or can you produce a SOC 2 Type II report, and how do you handle deletion rights and breach notification?
- Are your contracts explicit about data ownership and a no-advertising-with-student-data clause?
Standards & Interoperability Questions
| Standard | What to ask |
|---|---|
| SCORM / xAPI | Which versions do you support (SCORM 1.2, 2004, or xAPI via an LRS), and where does the system of record for learner progress live? |
| LTI | Do you support LTI 1.3 with Advantage for LMS embedding? |
| SIS integration | Which student information systems have you integrated with directly, and how do you handle identity matching across systems? |
| Reporting | What do we actually get in reports — a single score, per-question event data, or full time-series analytics? |
| Data export | Can we export raw learning records via API if we ever need to migrate or build our own analytics layer? |
Accessibility Questions
- [ ] Do you build to WCAG 2.1 AA by default, or is it a paid add-on?
- [ ] Can you show an accessibility audit or VPAT from a past project?
- [ ] How do you test with assistive technology (screen readers, keyboard-only navigation)?
- [ ] Does your team include anyone with dedicated accessibility expertise, or is it handled ad hoc?
Process & Delivery Questions
- What's your typical timeline from kickoff to a pilot-ready release?
- How do you sequence standards support — for example, shipping SCORM first for early sales while building xAPI into the data layer for later analytics needs?
- What does your QA process look like, particularly for cross-browser and cross-device testing?
- What post-launch support do you offer during the critical first semester or quarter of use?
- How do you handle mid-project scope changes if curriculum or compliance requirements shift?
Vendor Scorecard
| Criteria | Weight | Vendor A | Vendor B | Vendor C |
|---|---|---|---|---|
| FERPA / COPPA / state law readiness | ||||
| Accessibility (WCAG 2.1 AA) track record | ||||
| Standards support (SCORM/xAPI/LTI) | ||||
| SIS/LMS integration experience | ||||
| Cost clarity & contract terms | ||||
| References from similar institutions |
Red Flags to Watch For
- Treats WCAG accessibility as an optional add-on rather than a default
- Can't explain how their architecture separates the LMS system of record from analytics/reporting
- Vague or evasive answers on data ownership and deletion rights
- No experience with SIS integration relevant to your institution type
- No mention of a SOC 2 report or equivalent security documentation
How to Use This
Send the RFP to every vendor under consideration and require written responses before any live demos — compliance answers in particular are easy to overstate verbally but hard to fudge in writing. Loop in your legal or compliance lead on the FERPA/COPPA section specifically, since gaps there can block a district or institutional contract entirely regardless of how good the platform is technically.