You Didn’t Lose That RFP Because You’re Small—Here’s What the Data Says

·Commentary on SaaStr

Three weeks ago, you walked out of a final presentation feeling like you’d nailed it. The demo ran smooth. The technical deep-dive was a home run. Then the rejection email lands: “We’ve decided to go with a more established vendor.”

Immediately, the brain starts its post-mortem: we’re too small. We don’t have the headcount. We can’t compete with the logos the other guys slapped on their slide deck.

It’s an easy story to tell yourself. And sometimes it’s even partially true. But here’s what gets missed in that narrative: when we look at what enterprise buyers actually complain about, company size doesn’t show up in the data. Not directly, anyway.

Jason Lemkin over at SaaStr offered six solid pieces of advice for startups staring at a lost RFP, from nurturing the relationship to using the RFP as a feature roadmap. His take is battle-tested—he’s seen thousands of these situations. But his advice, like most founder guidance, is built on experience and instinct. What if you could see exactly what the market is screaming for, quantified across thousands of real buyer problems?

That’s the lens we apply here at PainSignal. We track what businesses—across 96 industries—are actually struggling with, what they’re requesting from vendors, and how much pain each issue causes. When you map that dataset onto the RFP loss problem, a much clearer picture emerges. You didn’t lose because you’re small. You lost because you didn’t check the boxes that matter most. Here’s how to fix them, in priority order.


1. Security Compliance Is a 4.1 Out of 5 Alarm Bell

Lemkin nails it when he says security is often the number one reason for RFP loss. And our data backs him up aggressively: we track 312 problems tagged with “security compliance,” carrying an average severity of 4.1 out of 5. This is the loudest signal in the entire dataset. Enterprises aren’t just asking for SOC-2 out of habit—they’re terrified of a breach, and their procurement teams have checklists that are non-negotiable.

What does this mean for you? If you don’t have SOC-2 Type II, stop reading and go get it. But beyond the certification itself, look at the sub-signals: our data shows that buyers often tie security to specific implementation details—encryption standards, role-based access controls, data residency. A generic “we take security seriously” line in your RFP response is a fast track to the “no” pile.

The takeaway: security is not a feature. It’s table stakes. And if you think being small is an excuse, think again. The 4.1 severity score means this pain is felt acutely regardless of vendor size. Fix it first.


2. Integration Complexity Is Quietly Killing Deals

One data point Lemkin’s article doesn’t surface—but that screams at us in the numbers—is integration complexity. We have 180 problems in this category with an average severity of 3.7 out of 5. When a big company says you’re “too small,” what they often mean is: “We’re afraid of a six-month integration project that breaks our existing workflows.”

Think about it: their current stack includes Salesforce, NetSuite, an HRIS, and a handful of homegrown tools. They need to know your API isn’t just “available” but robust, well-documented, and supported. They need to see pre-built connectors, or at least a clear plan for how you’ll build and maintain them.

This is where you can flip the script. Instead of seeing integration as a burden, treat it as a competitive advantage. Ship a list of validated integrations. Offer a dedicated integration engineer during onboarding. Publicly commit to SLAs around connector maintenance. Our data suggests that even startups that are tiny in revenue but strong on integrations can close disproportionately large deals.


3. Data Migration Risk: The Highest-Severity Subsignal

Dig deeper into the “too small” objection and you’ll often find a hidden fear: “What if they lose our data during migration?” That fear has a severity score of 4.0 out of 5, across 95 tracked problems. It’s one of the highest-severity issues in the platform, and it’s almost never addressed proactively by startups.

Enterprises have been burned by migrations before. They know the horror stories. If your RFP response didn’t include a detailed migration plan—with timelines, rollback strategies, and ideally a data migration guarantee—you handed the deal to a competitor who did.

This is not about size. It’s about instilling confidence. A five-person startup with a rock-solid migration playbook can beat a 500-person company that glosses over the process.


4. Vendor Credibility Comes from Proof, Not Promises

We track 210 problems categorized under “vendor credibility,” averaging 3.5 out of 5. These aren’t all explicit—buyers rarely say “we think you’ll go out of business.” Instead, you see phrases like “lack of references in our industry” or “limited track record.”

Lemkin suggests putting lost prospects into a nurturing program, which is smart, but the proactive move is to build credibility before the RFP even lands. Our data shows that one of the highest-impact solutions proposed by buyers is detailed case studies with measurable outcomes. Not marketing fluff. Real numbers: time saved, revenue gained, costs cut.

If you don’t have those yet, your mission is clear: find the customers you do have—even the small ones—and document their wins obsessively. When the next RFP asks for references, you won’t need to apologize for your size. You’ll hand them a folder of proof that you deliver.


The RFP as a Roadmap, Supercharged with Data

Lemkin’s third point is to treat RFPs as a checklist for what to build. It’s good advice, and our data reinforces it: we’re tracking 47 problems in the “enterprise readiness” category with an average severity of 3.8 out of 5. That’s a clear signal that the market is asking for these capabilities.

But the magic is in the prioritization. You can’t build everything. Start with whatever moves the severity needle: security first (4.1), then data migration (4.0), then integration complexity (3.7), and finally the long-tail of features that only certain verticals care about.


Don’t Give Up Too Early

One interesting nuance in our dataset: Lemkin says startups often get another shot at a lost deal within 1–3 years. That’s a reasonable rule of thumb, but we’ve seen that only 35% of successful re-engagements happen within that window. In slower-moving industries like healthcare and government, it’s often longer.

So if you’re approaching the three-year mark and haven’t heard back, don’t write it off completely. Keep them on your product update list. Invite them to your webinars. The deal might still be alive—just moving at enterprise speed.


The Bottom Line

Losing an RFP is brutal. But blaming size lets you off the hook for things you can actually control. The data tells a different story: the path to winning enterprise deals as a startup runs through security, integration, data migration, and credibility. In that order.

That’s a roadmap you can execute on this quarter. No massive headcount required. Just a clear-eyed look at what buyers are actually screaming for—and the discipline to deliver it.

Check out the full PainSignal platform to see exactly what your target market is demanding, or dive deeper into our RFP-related pain points.

Because the next RFP you lose shouldn’t be for a reason you could have fixed six months ago.

This article is commentary on the original article by Jason Lemkin at SaaStr. We encourage you to read the original.

Explore more problems and app ideas across Software as a Service (SaaS).

Browse App Ideas

Join the beta — full access for the first 1,000 builders

Join Beta