Glossary Digital sovereignty

What is vendor lock-in?

Vendor lock-in arises when switching or exiting a software becomes expensive or practically impossible. What that means for ERP and the mid-market, and how to check it.

Vendor lock-in means dependency on a vendor that makes switching or exit uneconomical. In the ERP context that matters especially: orders, finance, warehouse, and often production hang on the system. Whoever is stuck loses room on pricing, customizations, and strategic decisions. Lock-in is not a moral category. It is an economic question that leadership and IT should answer before signing the contract.

How lock-in arises in ERP

Lock-in rarely comes from a single contract. Typical levers work together:

  • License models per user, module, or transaction with high switching costs
  • Closed extensions and proprietary customization formats
  • Data formats without a complete, machine-readable export
  • Operations only at the vendor, without switchability of hosting and support
  • Undocumented customizations known only to the introduction team

The longer the system runs, the more expensive exit becomes. That is exactly why the check must happen before go-live, not after.

Why ERP is especially affected

ERP systems bundle core data and processes for years. A CRM or a shop can often be replaced while the ERP keeps running. With the ERP itself the cut is deeper: documents, inventory, approvals, and history must be migrated or run in parallel. Switching effort is high. Vendors know that. Term changes after introduction hit companies that have no short-term alternative.

Ask early therefore:

  1. Can data be exported completely and in a machine-readable format?
  2. Can customizations be operated further by another service provider?
  3. What happens on term changes, module discontinuation, or vendor sale?
  4. Which minimum terms and exit fees are agreed?

What an exit strategy does against lock-in

An exit strategy is risk management, not distrust. Test export, check contract clauses, document customizations, verify backups independently. Whoever can do that before go-live negotiates later on equal footing. Whoever only clarifies it when they want to switch pays tuition.

Lock-in and digital sovereignty belong together: sovereignty means choosing and limiting dependencies deliberately. Resilience means staying able to act when disruption hits. Both fail when exit is practically impossible.

What role open source plays

Open platforms address lock-in through freedom of choice on operations, support, and extension. What decides is whether source code, data, and extensibility remain with the company. Whoever only buys the “open source” label but hosts and extends exclusively with the manufacturer still has lock-in. Deeper reading: open source ERP.

Nuclos is licensed under the GNU AGPL 3.0. Customers keep access to source code and data. Operations and support can be switched. That reduces structural lock-in. It does not replace checking export, contracts, and documentation in the individual case.

What you should decide before signing

Acceptable dependencies exist. No company runs everything itself. The question is: which dependencies are deliberate and reversible, and which would block the business? Put lock-in into vendor evaluation, alongside functions and price. Test export. Read exit clauses. Document customizations so that another team can take them over.

Vendor lock-in is avoidable when you take it seriously before the contract. After that it becomes expensive.