West Virginia buyer guide
Outsourcing software development from West Virginia
A West Virginia guide to international software and AI outsourcing: cyber-evidence classification, state-system controls, incidents, critical operations, cost, and exit.

West Virginia outsourcing at a glance
| Proposed work | First buyer decision | Evidence required before access |
|---|---|---|
| Ordinary private software, automation, analytics, support, or AI work | Prove that the work is outside every activated State, public-entity, sensitive-access, regulated-data, operational, and customer-contract lane | Work package, identities and locations, data and system boundary, synthetic-data plan, accounts, dependencies, acceptance, release owner, recovery, and exit |
| System, device, account, network, data asset, or user relationship connected to the current State cyber program | Determine the actual information custodian, article scope, current Office of Technology standards, assessment, exception, review, classification, and evidence-handling path | Contract, custodian owner, data classification, user register, controls, assessment inputs, findings, plan of action and milestones, exception approval, annual-review packet, protected repository, and buyer acceptance |
| Possible cybersecurity incident involving an entity listed in Article 5A-6C | Determine whether the entity and event enter the current public-entity reporting path without treating the supplier as the statutory decision-maker | Discovery and determination times, entity, systems, business effect, data facts, severity evidence, regulators, citizen-notice dependency, Cybersecurity Office owner, preservation, updates, and decision log |
| Supplier maintenance of West Virginia consumer information for a private owner or licensee | Preserve the separate non-owner-to-owner event path and the buyer’s breach analysis | Owner or licensee, maintainer, data elements, encryption and key facts, access-and-acquisition evidence, fraud analysis inputs, discovery time, immediate escalation, notice owner, restoration, and retained decision record |
| Service-provider personnel may work at the Capitol Complex or access sensitive or critical State information | Determine whether the exact access enters the current Division of Protective Services provision and whether each proposed person can satisfy the buyer’s approved eligibility process | Named-person list, employer, work and access location, identity proof, background-inquiry workflow, contract reservation, access decision, approval, denial, revocation, and alternative non-sensitive work package |
| Critical energy infrastructure, industrial control, or operational technology | Identify the actual asset and consequence; do not turn the statutory definition into a universal technical rule | Asset and connection inventory, operating owner, safety state, staging or digital twin, allowed commands, supervised session, monitoring, stop authority, rollback, recovery, incident route, release, and exit |
These are classification prompts, not conclusions about a particular buyer, supplier, event, system, or contract. The State cyber-program and public-entity incident articles have different stated scopes. The private breach article uses its own definitions. The sensitive-access provision is bounded by the people, place, information, and contract facts described in the current code. The critical-energy article supplies a current classification context, not a complete technical-control standard. Federal, sector, customer, grant, insurance, export, sanctions, collective-bargaining, professional, destination-country, and other-state requirements can still change the design.
The distinct West Virginia model: cyber-evidence classification relay
The West Virginia-specific operating problem is not merely whether a supplier follows a security checklist. It is whether the buyer can route each artifact to the right owner and repository without losing the facts needed for action or spreading material that itself exposes a weakness.
Article 5A-6B gives the State cyber program functions involving information custody, classification, assessment, remediation, privacy impact, training, exception approval, and annual review. It also protects specified risk assessments, reviews, plans of action and milestones, remediation plans, and threat or vulnerability information from disclosure under the State Freedom of Information Act. Article 5A-6C creates a different incident path for its listed public entities. The private consumer-information breach article creates another owner, licensee, and maintainer path. A supplier cannot safely collapse all three into a generic ticket marked “security.”
Build a buyer-controlled relay with five evidence classes:
- Public-safe delivery evidence: scope, milestones, accepted outcomes, non-sensitive architecture summaries, accessibility results, performance evidence, public notices, and other artifacts approved for broad circulation.
- Controlled contract evidence: identities, locations, subproviders, work orders, permissions, training, data-processing terms, invoices, acceptance, and transition records shared only with authorized commercial and operational owners.
- Protected cyber evidence: vulnerability details, assessment results, risk registers, exploit paths, security configurations, exception reasoning, plans of action and milestones, remediation evidence, and recovery secrets held inside the approved environment.
- Incident decision evidence: time-stamped facts, preservation, containment, business effect, affected systems and information, investigation confidence, reporting analysis inputs, communications, decisions, and updates.
- Operational safety evidence: asset state, authorized commands, observed session, interlocks, limits, stop actions, rollback, restoration, operating acceptance, and residual risk.
Classification belongs to an accountable buyer owner. A supplier may create or return an artifact, but it should not self-declare that an assessment can be public, that an event is not reportable, that a person is eligible for sensitive access, that an operational command is safe, or that evidence may be destroyed. Every artifact needs an owner, class, approved repository, access group, retention trigger, legal or operational hold path, production use, and exit disposition.
Classify the buyer and work package before selecting a country
Do not start with “nearshore or offshore?” Start with the actual entity, contract, system, data, user, access, and consequence. One West Virginia organization can operate several lanes at once: a public marketing site, a private employee tool, a State-supported system, a municipal service, a customer-owned platform, an industrial data historian, and a public-facing incident portal. The company name and postal address do not decide the perimeter.
For each work package, record:
- Buyer entity and role: legal entity, business unit, public or private status, information custodian if any, contract owner, system owner, data owner, operating owner, and decision owner.
- System relationship: standalone private application, State-owned or monitored system, local-government service, customer system, hosted service, device, account, network, operational technology, or mixed environment.
- Information: fields, records, logs, credentials, secrets, personal information, protected assessment material, vulnerability data, source code, model inputs and outputs, operational signals, and derived data.
- People and locations: every contributor, employer, subprovider, work city, system region, support location, physical presence, and access to sensitive or critical information.
- Authority: view, create, change, test, approve, deploy, notify, stop, operate, restore, retain, delete, and disclose permissions.
- Activated source: statute, current policy or standard, solicitation, executed contract, grant, customer requirement, sector rule, insurance obligation, destination-country requirement, or internal risk decision.
- Evidence class: public-safe, controlled contract, protected cyber, incident decision, operational safety, or another buyer-approved class.
- Exit: repository, export, return, deletion, hold, credential rotation, replacement-team test, and unresolved obligation.
If facts are missing, keep the supplier in a synthetic-data, public-information, isolated prototype, or other approved low-consequence lane. A provider’s general security presentation is not permission to touch the actual system.
Keep ordinary private delivery ordinary—but evidenced
The State cyber-program article does not turn every private West Virginia software engagement into a State system. The public-entity incident article identifies its own entity scope. The critical-energy definition does not make every business application operational technology. Preserve those boundaries.
An ordinary private lane can still use strong controls:
- buyer-held repositories, domains, cloud organizations, signing keys, billing, and production accounts;
- named contributors and disclosed work locations rather than a provider brand alone;
- least-privilege access with expiration, separate administration, review, and prompt revocation;
- synthetic, masked, minimized, or buyer-approved data for development and support;
- small work packages with acceptance criteria, code review, tests, dependency and provenance records, and rollback;
- immediate operational escalation under contract instead of waiting for a statutory notice analysis; and
- exportable code, infrastructure definitions, documentation, logs, decisions, and transition assistance.
The buyer should be able to prove why the work stayed in the ordinary lane and which change would force reclassification. A new customer, State connection, data field, log source, physical site, support permission, industrial interface, model, subprovider, or incident can activate a different path.
Translate the current State cyber program into supplier operations
Article 5A-6B currently applies to the State-agency scope stated in section 5A-6B-1, with named exclusions. It defines a user broadly enough to include contractors, vendors, automated systems, service accounts, and volunteers with access to a State system, device, account, or network. It defines an information custodian around custody or responsibility for data assets on systems, devices, accounts, or networks owned, monitored, or maintained by the West Virginia Office of Technology.
Those definitions should become operational fields, not decorative contract language. For a potentially covered work package, capture:
| Control question | Supplier implementation | Buyer evidence and authority |
|---|---|---|
| Who is the information custodian? | Route work and findings to the named custodian workflow | Named custodian, system/data ownership, applicable standard, approvals, current contacts |
| Who or what is a user? | Register people, vendors, service accounts, agents, automations, and integration identities | User inventory, sponsor, purpose, role, environment, authentication, expiry, review, revocation |
| Which data classification applies? | Enforce repository, transmission, logging, masking, regional, and disclosure boundaries | Classification decision, approved systems, access group, exception path, evidence location |
| Which controls and assessment apply? | Implement only against the current buyer-issued standard and work order | Standard version, assessment scope, evidence request, finding owner, remediation, acceptance |
| Is an exception required? | Stop the affected action until the buyer’s approval is recorded | Exception request, compensating control, approver, duration, review, closure |
| What is needed for the annual review? | Return a maintained evidence index instead of rebuilding proof at year end | Readiness summary, classifications, findings, plans, modernization work, dates, unresolved risk |
Section 5A-6B-4 currently requires covered information custodians to undergo the appropriate risk assessment, follow the State cybersecurity standard and enterprise policies, route exception requests for approval, and participate in at least one annual cybersecurity program review before November 30. That calendar is a buyer obligation, not permission for a provider to declare compliance. Put evidence delivery, remediation decisions, and review preparation into the work plan early enough for the accountable custodian to validate them.
Section 5A-6B-3 also addresses State contracts for licensing certain software applications and the State’s ability to install or run the software on hardware of its choosing. For an applicable procurement, identify the exact license, deployment model, hardware or infrastructure dependency, support boundary, portability, and exit path. Do not generalize that provision to every cloud service or private buyer; do not let a supplier’s preferred hosting model silently become the only recoverable deployment.
Separate public-safe delivery proof from protected cyber evidence
A mature outsourcing program needs useful evidence, but not every reviewer should receive the same evidence. Article 5A-6B protects specified cybersecurity assessment, remediation, vulnerability, risk, and related material from broad disclosure under the conditions stated in the current law. That should change the repository design before the first assessment begins.
Use two linked records:
- a public-safe delivery index that can show the work package, accountable owners, milestone state, accepted outcome, non-sensitive control status, accessibility and performance result, release decision, and open commercial action; and
- a protected cyber annex that holds the detailed topology, vulnerability, exploit, credential, configuration, assessment, exception, remediation, and recovery evidence in the approved restricted system.
The index should reference protected items by stable identifier, class, owner, current state, and access path without copying their sensitive substance. A procurement leader can then confirm that a finding exists and has an assigned remediation decision without receiving the exploit path. A security owner can open the restricted record. A public-information or records owner can apply the current legal analysis to an actual artifact rather than to a mixed project folder.
Require the supplier to classify artifacts at creation. Email attachments, chat transcripts, ticket comments, exported dashboards, screen recordings, and AI prompts can reproduce protected substance even when the original report is locked down. The delivery workflow should prevent a detailed finding from being pasted into a public milestone update. It should also stop an AI assistant, analytics service, transcription tool, or observability vendor from becoming an unreviewed second repository.
For every protected item, record:
- the assessment, event, system, and work order that produced it;
- the buyer owner and approved supplier recipients;
- the authority and purpose for each access;
- the approved system, encryption, logging, export, and retention rules;
- whether a summary may enter the public-safe index;
- the finding, remediation, exception, acceptance, or recovery decision it supports; and
- the return, preservation, deletion, and access-removal outcome at exit.
Protection is not a reason to hide operational status from accountable owners. It is a reason to design a precise evidence interface.
Build a distinct public-entity cyber-incident lane
Article 5A-6C states its own public-entity scope and reporting process. Do not assume it is identical to Article 5A-6B, and do not make an international developer decide whether an event satisfies the statutory trigger. The supplier’s job is to surface reliable facts immediately; the named West Virginia owner determines applicability, coordinates with the Cybersecurity Office and counsel, and controls external reporting and citizen communication.
The operational playbook should define two times:
- supplier discovery time, when a person, service, monitor, customer, or subprovider first saw a relevant signal; and
- buyer determination time, when the accountable entity reached the decision that starts an applicable external deadline.
Preserve both. Do not rewrite discovery time after investigation. The current article includes an outside path no later than ten days after determination and sequencing tied to citizen notification for an applicable event. That outer rule is not an acceptable supplier service level. A contract can require immediate escalation in minutes or hours so the buyer has time to investigate, preserve evidence, coordinate, and decide.
An initial incident capsule should contain what is known, unknown, and changing:
| Field | Minimum useful evidence |
|---|---|
| Origin | Discovering person or system, timestamp with offset, location, alert or report, affected supplier or subprovider |
| Entity and service | Buyer entity, system owner, information custodian if applicable, service, environment, business function, public dependency |
| Technical facts | Accounts, systems, indicators, access, availability, integrity, confidentiality, suspected cause, containment already taken |
| Information facts | Data categories, approximate population or record scope, encryption and key facts, acquisition or access evidence, confidence |
| Consequence | Service degradation, safety concern, financial effect, public effect, dependent entities, restoration state |
| Decision support | Possible reporting lanes, named buyer owners, legal or regulatory dependencies, citizen-notice dependency, next decision time |
| Preservation | Logs, images, tickets, communications, chain of custody, retention hold, unavailable evidence, subprovider request |
The capsule should be progressive. Version one can be incomplete but must be time-stamped. Later versions should preserve corrections and their reasons. Suppliers should not wait for root cause, full record counts, or a polished narrative before escalating.
Run at least one exercise in which a contributor notices an ambiguous signal during the buyer’s night. Test who answers, who can preserve volatile evidence, who can revoke access, who can authorize containment, who evaluates the public-entity path, and who prepares the required facts. The exercise succeeds when the buyer can make and document the decision—not when the supplier merely opens a ticket.
Preserve the separate private consumer-information breach path
Article 46A-2A has its own definitions and responsibilities for an owner or licensee of personal information and for a person that maintains computerized data it does not own or license. A private West Virginia buyer should map the actual relationship instead of copying the public-entity playbook.
If an outsourcing provider maintains relevant information for the buyer, the agreement should require notice to the owner or licensee as soon as practicable after discovery of an applicable security breach, while also imposing a faster operational escalation for suspicious events. The provider supplies facts; the buyer retains the legal determination, regulator coordination, consumer-notice decision, delay analysis, content approval, and record of reasoning unless a different accountable allocation is validly established and documented.
Build a data-owner/maintainer register with:
- each data set and field group;
- the owner or licensee and every maintainer;
- storage, backup, logging, analytics, support, and AI-service locations;
- encryption state and who can access keys;
- deletion, restoration, and legal-hold capability;
- the owner contact the maintainer must reach at any hour;
- subprovider escalation and evidence obligations; and
- the tested path for returning an export and proving deletion.
Do not collapse the public-entity and private lanes into a universal “West Virginia ten-day rule.” Entity, data, event, role, and current source decide the path. A single event may require coordinated analysis under several lanes, but the decision log should record each separately.
Gate sensitive State access by the exact person and work package
Article 15-2D includes provisions concerning certain service-provider personnel working at the Capitol Complex or accessing sensitive or critical State information. Its identity, background-inquiry, access-list, approval, contract, and electronic-security elements are fact-dependent. It is not a blanket statement that every offshore contributor needs a particular screening, nor is a provider’s corporate certification a substitute for an individual eligibility decision.
Before proposing international contributors, the buyer should answer:
- What exact place, system, device, document, information, or electronic-security function would the person access?
- Does the executed contract or current buyer instruction activate the provision?
- Which organization owns the eligibility workflow and can approve, deny, restrict, or revoke access?
- Can the work be split so an eligible owner performs the sensitive operation while an international contributor receives only a sanitized interface, synthetic fixture, or accepted artifact?
- What happens if a proposed contributor cannot participate in the required process?
Create a person-level access manifest. Record legal identity through the approved process, employer, country and city, role, work package, systems and information, physical presence if any, requested privileges, screening state, approval owner, decision, start, expiration, review, and revocation. Keep sensitive screening results out of ordinary project tools; expose only the eligibility status necessary for access enforcement.
A denied or unavailable path needs a predesigned alternative. The supplier can create tests against synthetic data, document a public interface, implement an isolated component, or return a signed artifact for an authorized buyer owner to integrate. That is more resilient than discovering after award that the named team cannot lawfully or operationally reach the required environment.
Isolate critical-energy and operational-technology work
Article 5B-2N supplies current West Virginia policy and definitions around critical energy infrastructure, including communication, cybersecurity, electric-grid, hazardous-waste-treatment, and water-treatment systems associated with named energy activities. Use it as a classification prompt. It does not replace the asset owner’s engineering, safety, sector, environmental, reliability, contractual, and cybersecurity controls.
For any connection to operational technology or an industrial control system, split the work into zones:
- public and synthetic design: requirements, diagrams stripped of sensitive topology, mock interfaces, training, documentation, and synthetic fixtures;
- isolated engineering: versioned code, simulated devices, digital twins, replayed signals, test harnesses, and security scans in a separated environment;
- staged integration: approved hardware or lab assets, observed sessions, allowlisted protocols and commands, recorded results, and rollback rehearsal;
- production observation: time-bound, monitored, usually read-only access with an operating owner present; and
- production change: a separately approved change window with safety state, command list, interlocks, stop authority, rollback, restoration, and acceptance.
The buyer’s operating owner—not the overseas developer—owns the safe-state definition and final production command authority. No supplier should gain standing remote administration merely because it built the integration. Break-glass authority should be narrow, separately held, monitored, and tested.
CISA operational-technology resources can inform the method: asset visibility, segmentation, controlled remote access, monitoring, incident preparation, recovery, and vendor-risk management. Apply the current asset-owner and sector requirements to the actual environment. A generic “SOC 2 compliant” assertion does not prove that an update can be stopped, rolled back, or recovered without unsafe consequences.
Before production, run three proofs:
- Loss of connection: the asset remains or returns to the approved state when the supplier link fails.
- Bad artifact: the buyer detects a corrupted, unauthorized, or incompatible release and restores the last accepted version.
- Supplier loss: buyer personnel or a replacement team can operate, diagnose, and recover using buyer-held credentials, code, configurations, documentation, and evidence.
Register AI systems, software services, and subproviders
International delivery now includes more than named humans. Code assistants, hosted models, transcription tools, ticket enrichers, observability platforms, dependency scanners, browser agents, data-labeling services, and automated service accounts can receive buyer information or act on buyer systems.
Maintain one service register containing:
| Field | Buyer question |
|---|---|
| Service and operator | What product, model, API, extension, agent, or platform is used, and which legal entity operates it? |
| Purpose | Which work package and approved outcome require it? |
| Inputs and outputs | Can source code, logs, personal information, protected cyber evidence, operational signals, credentials, prompts, or derived content enter or leave? |
| Location and recipients | Where is processing or support performed, and which subproviders or reviewers can receive the material? |
| Retention and reuse | What is retained, for how long, for abuse monitoring or training, and under which controllable setting or contract? |
| Authority | Can it read, write, execute, deploy, notify, delete, or call another service? Who approves and can revoke that authority? |
| Evidence | Which version, output, evaluation, provenance, review, exception, and incident records return to the buyer? |
| Exit | How are accounts disabled, tokens rotated, data exported or deleted, integrations removed, and dependent workflows replaced? |
Prohibit undisclosed tools for protected cyber or operational evidence. For ordinary development, use approved tools with minimum inputs and human review. Record material model or service changes because a different provider, region, retention setting, or agent permission can change the work package even when the user interface looks the same.
Schedule international delivery from the actual West Virginia buyer city
West Virginia uses Eastern Time, but overlap should be calculated with dated IANA time-zone identifiers for every participant city. “Five hours ahead” becomes wrong when daylight-saving transitions occur on different dates or when a country does not change clocks.
A practical operating day has four modes:
- live overlap: decisions, pairing, demonstrations, sensitive access, incident coordination, and handoffs requiring both parties;
- buyer day: prioritization, acceptance, stakeholder input, environment approvals, and release decisions;
- supplier day: bounded implementation, tests, documentation, evidence assembly, and questions that do not exceed granted authority; and
- urgent bypass: an always-on path for security, privacy, safety, availability, integrity, or irreversible-cost concerns.
Publish the next 60 to 90 days of overlap in both local times with UTC offsets. Name the buyer decision owner and supplier delivery owner. A handoff should state completed work, evidence links, blocked questions, assumptions, next authorized action, prohibited action, and the time a decision is needed. This turns time difference into a controlled relay instead of an unattended authority gap.
Country selection follows the work package. Nearshore locations such as Colombia or Mexico may offer more West Virginia daytime overlap; India or the Philippines may extend asynchronous coverage; Poland can provide a useful European engineering window. These are operating hypotheses, not country rankings. Compare the named people, work city, employment or contracting structure, language, relevant experience, security design, data and service locations, subproviders, intellectual-property path, holidays, resilience, complete cost, and tested exit.
Protect intellectual property across every contributor country
A West Virginia agreement does not by itself answer every contributor-country employment, contractor, moral-rights, invention, tax, export, sanctions, or enforcement question. Build a contributor-to-artifact chain and investigate the actual destination country through qualified counsel and official sources such as WIPO’s directory of national intellectual-property offices.
For each contributor, preserve:
- legal identity, employer or contracting entity, country and city;
- executed confidentiality and invention or copyright assignment relevant to the engagement;
- subcontractor approval and equivalent flow-downs;
- prior materials and open-source or commercial dependencies;
- repository identity, commits, reviews, tests, build provenance, model or data contribution, and accepted artifact;
- permitted portfolio, reuse, publication, and residual-knowledge boundaries; and
- termination, return, deletion, transition, and continuing obligations.
Keep source repositories, package registries, domains, infrastructure accounts, signing keys, model registries, production credentials, and billing under buyer-controlled organizations. A provider can administer a bounded role; it should not be the only party able to build, deploy, restore, or transfer the product.
Compare complete cost, not the advertised hourly rate
The lowest rate can produce the highest total cost when the buyer must repair unclear scope, missing evidence, fragile access, unsafe releases, incompatible infrastructure, or an unplanned transition. Price the operating system around the team.
Use a 12-month scenario with at least these components:
| Cost component | Include |
|---|---|
| Delivery labor | Named roles, realistic utilization, leave, holidays, onboarding, replacement time, overtime, and rate changes |
| Buyer coordination | Product ownership, architecture, security, privacy, procurement, legal review, operating supervision, acceptance, and executive decisions |
| Platforms and access | Repositories, cloud environments, test data, devices, remote access, identity, logging, monitoring, evidence storage, AI tools, and license portability |
| Assurance | Assessments, remediation, testing, dependency review, accessibility, incident exercises, operational staging, and annual-review readiness |
| Communication | Overlap, travel if approved, translation, documentation, demonstrations, handoffs, and urgent response coverage |
| Failure and change | Rework, delay, incident handling, unavailable contributor, service-price change, exchange rate, taxes or fees, and contingency |
| Exit | Export, documentation repair, knowledge transfer, credential and key rotation, account transfer, data return or deletion, and replacement-team validation |
Compare three cases: expected delivery, a stressed case with material rework or one contributor replacement, and an exit case after an early termination. State every assumption. A provider should be able to explain which buyer activities remain outside its proposal and which third-party services can change price.
Rate comparisons are still useful when normalized. Compare the same role definition, seniority evidence, working location, overlap, included management, quality practices, security obligations, tooling, taxes and fees, and exit assistance. A blended team price with no named composition is not comparable to a proposal that identifies each role and responsibility.
Run a paid six-to-eight-week evidence pilot
The pilot should test the most uncertain operating claim with a reversible work package. It is not unpaid speculative work and should not begin with production-critical access.
Week 1: classify and establish authority
- Name buyer and supplier owners.
- Record entity, system, data, user, access, evidence, incident, and exit classifications.
- Approve contributors, locations, services, repositories, communication channels, and time-zone schedule.
- Write acceptance criteria and prohibited actions.
- Test urgent escalation and access revocation before substantive work.
Weeks 2–3: deliver a narrow vertical slice
- Implement one useful end-to-end outcome in synthetic, masked, isolated, or otherwise approved conditions.
- Return code, tests, dependency and provenance evidence, decisions, unresolved risks, and an operational handoff.
- Demonstrate that detailed cyber evidence stays in the protected annex while the public-safe index remains useful.
- Measure decision latency, first-pass acceptance, escaped defect count, evidence completeness, and unplanned access requests.
Weeks 4–5: exercise a change and an incident
- Introduce a realistic requirement, dependency, contributor, service, or data-boundary change and require reclassification before work continues.
- Run an ambiguous incident signal through the applicable public-entity, private-owner/maintainer, contract, and operational analysis lanes without asking the supplier to make the buyer’s legal decision.
- Verify time-stamped preservation, immediate escalation, progressive updates, access control, and recovery.
Weeks 6–8: release, recover, and exit
- Complete the approved release or handoff through the buyer-controlled gate.
- Restore the prior accepted state from buyer-held artifacts.
- Remove one contributor and prove prompt revocation.
- Export code, infrastructure definitions, documentation, evidence indexes, decision history, accounts, data, and open obligations.
- Ask a replacement engineer or team to build, test, explain, and operate the result without private help from the original provider.
Score the pilot against pre-agreed thresholds. Useful measures include accepted outcomes per cycle, buyer decision wait, reopened work, escaped defects, traceable requirements, access exceptions, protected-evidence leakage, incident escalation latency, recovery time, repository completeness, and replacement-team success. Continue, redesign, or stop from evidence—not from the quality of the sales presentation.
Put the operating model into the contract and work order
The master agreement can set reusable rights and responsibilities, but the work order should activate the exact lane. Include:
- Parties, roles, and precedence: legal entities, owner or maintainer roles where relevant, buyer authority, supplier responsibility, and which document controls a conflict.
- Work package: outcome, environments, data, systems, users, locations, dependencies, exclusions, prohibited actions, milestones, acceptance, release, and recovery.
- People and services: named contributors, employer, city and country, subprovider and AI/service register, change approval, screening or eligibility requirements, and replacement rules.
- Access: buyer-held identity, least privilege, separate administrative roles, session controls, expiration, review, revocation, physical access if any, and no shared credentials.
- Evidence: public-safe index, protected cyber annex, incident capsule, operational safety record, source and build provenance, repository, access group, retention, hold, export, and deletion.
- Security and development: current buyer-issued standards, NIST SSDF-aligned practices where selected, vulnerability handling, dependency policy, secrets, logging, assessment, remediation, exception, and annual-review support.
- Incidents: immediate operational escalation, minimum facts, preservation, progressive updates, subprovider flow-down, cooperation, buyer decision authority, external communications, recovery, and post-incident evidence.
- Operational technology: asset boundary, staging, allowed protocols and commands, observation, safe state, stop authority, rollback, restoration, operating acceptance, and emergency path.
- Data and intellectual property: instructions, purpose, minimization, locations, recipients, transfers, return or deletion, background materials, assignments, dependencies, publication, and audit trail.
- Commercials and exit: complete fees, service changes, transition assistance, repository and account transfer, key rotation, data disposition, open findings, continuity period, and replacement-team test.
Avoid a contract that says only “comply with all applicable laws.” The operating team needs the buyer’s current classification and instructions. Also avoid promising that a provider complies with a provision that has not been mapped to the actual entity, system, person, and contract.
Reject these proposal and delivery red flags
- The provider claims a West Virginia presence, State relationship, clearance, certification, customer, or critical-infrastructure experience without verifiable evidence.
- The proposal treats all West Virginia work as regulated—or none of it as potentially regulated.
- A provider proposes a country and team before it can describe the work package, data, system, access, incident, and exit boundaries.
- Contributors, cities, subproviders, AI services, or support locations are undisclosed or change without approval.
- Protected vulnerabilities or assessment material are routinely copied into email, public tickets, sales tools, or unapproved AI services.
- The supplier wants shared production credentials, unrestricted remote access, permanent administration, or self-approval of releases.
- Incident notice waits for root cause, a complete investigation, a provider committee, or a statutory outer deadline.
- The public-entity and private breach lanes are described as one universal clock.
- A company-wide background statement is offered instead of the required person-and-access eligibility process.
- Operational-technology work has no isolated test, safe state, monitored session, stop owner, rollback, or buyer-held recovery path.
- The buyer does not own repositories, domains, cloud accounts, signing material, billing, and exportable evidence.
- The cheapest-rate claim excludes buyer coordination, tooling, assurance, rework, or exit.
- The contract claims automatic intellectual-property ownership without tracing every contributor and preexisting component.
Frequently asked questions
Can a West Virginia company hire software developers outside the United States?
Yes, international delivery can be workable. The buyer should classify the entity, contract, system, information, access, people, services, operational consequence, and destination-country issues before granting access. Some work can remain ordinary private delivery; other work may enter State, public-entity, sensitive-access, consumer-information, customer, sector, export, or operational controls.
Does West Virginia law require all software or data to stay in the United States?
This guide found no universal rule in the cited sources that makes every West Virginia software engagement domestic-only. That is not a conclusion that a particular work package may go anywhere. The exact law, solicitation, executed contract, customer promise, funding term, sector rule, data class, export or sanctions analysis, and destination-country facts control.
Does every State contractor fall under the same cyber requirements?
No. Start with the current source’s definitions, stated agency or entity scope, exclusions, contract, system relationship, user role, information custodian, data class, and buyer-issued standard. Articles 5A-6B and 5A-6C should not be assumed to have identical perimeters.
Should the outsourcing provider decide whether an incident is reportable?
The provider should immediately deliver accurate, preserved, progressively updated facts. The named buyer owners should control applicability, statutory determination, regulator coordination, citizen or consumer notice, public statements, safety, and other external decisions with appropriate counsel and specialists.
Are vulnerability reports public project records?
Do not assume either universal public availability or universal secrecy. The current State cyber-program article protects specified material under its terms. Classify each artifact, keep a useful public-safe index, store detailed protected evidence in the approved restricted repository, and let the accountable records, security, and legal owners decide access.
Can international developers work on critical energy or industrial systems?
Possibly, but only after the asset owner classifies the exact system, contract, access, data, sector, safety, export, and operational requirements. Prefer synthetic design and isolated engineering first. Production observation or change needs separate approval, monitoring, safe-state controls, stop authority, rollback, restoration, and buyer-held recovery.
Is nearshore automatically better for a West Virginia team?
No. More live Eastern-time overlap can help decisions and pairing, while a more distant team can extend asynchronous progress. The best choice depends on the named people, work city, work package, evidence quality, language, resilience, security, legal structure, complete cost, and exit—not the label alone.
What is the most important pilot result?
The strongest result is replacement-team control: the buyer can revoke the original provider, build and test the product, explain the important decisions, operate or recover the accepted service, retrieve the required evidence, and continue with buyer-held accounts and authority.
The exit test
Before expanding the engagement, ask a team that did not create the work to perform the following from buyer-controlled systems:
- identify the applicable ordinary, State cyber-program, public-entity incident, sensitive-access, private breach, and operational lanes;
- find the named owners, contributor and service registers, instructions, exceptions, decisions, and current access state;
- build and test the accepted artifact from a clean environment using recorded dependencies and provenance;
- locate the public-safe delivery index and retrieve protected cyber evidence only through the approved restricted path;
- reconstruct a simulated incident timeline and route it through each potentially applicable decision lane;
- deploy or hand off through the authorized gate, detect a bad artifact, roll back, restore, and confirm the approved state;
- export code, infrastructure, data, documentation, logs, evidence, licenses, accounts, and unresolved obligations;
- revoke identities, tokens, sessions, keys, subproviders, agents, and integrations; and
- prove required return, preservation, deletion, transition assistance, and continuing obligations.
If the replacement team cannot do this, the buyer has purchased dependency rather than controlled delivery. The practical West Virginia advantage is not a claim that every supplier satisfies every regime. It is a visible classification relay: ordinary work stays efficient, activated State and private duties remain distinct, protected evidence stays protected but usable, operational authority stays with the asset owner, and every accepted outcome can survive a supplier change.
Use the project brief generator to define the first bounded work package, then compare providers with the provider scorecard. Recheck the current primary sources, executed contract, buyer policies, and qualified professional advice before relying on any legal, security, privacy, public-records, procurement, energy, safety, tax, export, sanctions, employment, or intellectual-property conclusion.
Evidence ledger
Sources used on this page
- West Virginia Code, Article 5A-6B — Cyber Security Program — West Virginia Legislature. Supports: Current 2026 State cybersecurity-program scope, definitions, assessment and annual-review duties, information-custody and classification functions, contractor and vendor user coverage, exception approval, protected cybersecurity evidence, and software-license hardware-choice provision. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- West Virginia Code, Article 5A-6C — West Virginia Cyber Incident Reporting — West Virginia Legislature. Supports: Current public-entity incident-reporting scope, qualifying-event triggers, sequencing before citizen notification, ten-day outside reporting path, minimum report facts, and annual reporting structure. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- 2026 Enrolled House Bill 5638 — State cyber security program — West Virginia Legislature. Supports: Enrolled 2026 amendments to the State cybersecurity program and the stated June 12, 2026 effective date. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- West Virginia Code, Article 15-2D — Division of Protective Services — West Virginia Legislature. Supports: Current scoped service-provider identity, fingerprint-based background inquiry, access-list, contract-reservation, sensitive-information, Capitol Complex, and electronic-security approval provisions. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- West Virginia Code, Article 46A-2A — Breach of Security of Consumer Information — West Virginia Legislature. Supports: Current private owner-or-licensee and non-owner data-maintainer breach definitions, notice paths, as-soon-as-practicable owner notification, delay, and regulator-procedure provisions. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- West Virginia Code, Article 5B-2N — Comprehensive Grid Stabilization and Energy Security Act of 2026 — West Virginia Legislature. Supports: Current definition and policy context for critical energy infrastructure, including communication, cybersecurity, electric-grid, hazardous-waste-treatment, and water-treatment systems affecting named energy activities. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Operational Technology Cybersecurity — Cybersecurity and Infrastructure Security Agency. Supports: Maintained federal operational-technology and industrial-control-system resources used as methodology for segmentation, asset visibility, monitored access, incident response, and recovery planning. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- IANA Time Zone Database — Internet Assigned Numbers Authority. Supports: Maintained identifiers and transition rules for calculating dated overlap between a West Virginia buyer and every proposed contributor city. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Secure Software Development Framework — National Institute of Standards and Technology. Supports: Maintained methodology for secure-development requirements, protected environments, provenance, release integrity, vulnerability response, and buyer-supplier evidence. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Directory of Intellectual Property Offices — World Intellectual Property Organization. Supports: Official destination-country intellectual-property office links for investigating contributor and assignment questions rather than assuming a West Virginia contract resolves every jurisdiction. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
Next scheduled review: September 30, 2026. Corrections: hello@outsourcing.ai.
