Start with proven experience, not the number of logos on the website. Ask to see a couple of case studies that match your stack, and then find out which engineers actually built it. A serious vendor will put you on a call with the tech lead. Vague answers at this stage usually mean the demo work came from somewhere else.
The paperwork needs a slower read than the pitch. A few clauses carry most of the weight: ownership of the code, the NDA, and custom software vs saas termination and handover. Everything produced must transfer to you as it is paid for, along with designs, scripts and infrastructure configuration. Be careful with language that keeps reusable components with the vendor, .net development agency because it is usually exactly the piece that locks you in.
Find out how the estimate was built. A serious estimate arrives with a list of assumptions, a task-level breakdown and an explicit range. A fixed price is only reasonable when the requirements are stable and documented; otherwise the provider prices the risk in and you pay for it anyway. Time and materials puts the risk on your side, so it demands a cap, regular demos and transparent reporting.
software development process matters more than headcount. Establish how a new requirement enters the plan, who defines done and how quality assurance works. A well-run team will be able to show you a live build at the end of each sprint. Clear, written acceptance criteria are the practical protection against the it-was-never-in-scope conversation.
Finally, think about the end of the engagement at the start rather than at the end. Require that the source repository lives in your organisation from day one, and that a readme and architecture notes are kept current as the code changes. A partner who is comfortable with this accepts it without argument; hesitation here tells you a great deal.
