Skip to main content
NC State Home
Learning Finance

What Is the IT Purchase Compliance and When Should I Submit One?

IT Purchase Compliance process flow
This image was created with help from Gemini.

Written by Sharon Loosman and Mike McComas

If you are looking to purchase software or other IT products for the university, you might be wondering where to start. Following the university’s IT Procurement Guide, here is a breakdown of what you need to do to ensure your purchase is compliant, compatible and efficient.

  1. Confirm if it is an IT purchase: First, understand that an IT purchase isn’t just software. It includes any information and communication technology product that stores or transmits university data, integrates with university systems, or is used by faculty, staff or students. This covers web-based applications, cloud-hosting services, network solutions and even consulting services that access sensitive data.
  2. Determine data sensitivity: You must assess the sensitivity of the data the product will handle. The university classifies data into four levels:
  • Ultra-sensitive (Purple): Includes Social Security numbers, credit card data and biometrics.
  • Highly sensitive (Red)
  • Moderately sensitive (Yellow)
  • Normal (Green): Not sensitive
  1. Check if your product needs a review: Not every purchase requires a full review, but many do. You must submit an IT Purchase Compliance request if the product meets any of the following conditions:
  • It involves red data, Health Insurance Portability and Accountability Act (HIPAA), Payment Card Industry (PCI), or Export Control Regulations (regardless of cost)
  • It is used by students, the public or a large audience
  • Meets federal accessibility standards
  • It is a new IT purchase costing $5,000 or more
  • It is a renewal costing $5,000 or more
  1. Gather documentation: As the requester, you are responsible for collecting necessary documentation before submitting your review. This may include:
    • Security Documentation: Such as a Security Questionnaire or System and Organization Controls 2 (SOC2) report from the supplier
    • Approvals: Written approval from the Data Steward
    • Accessibility: Validation that the product meets WCAG 2.0/2.1 AA standards (e.g., a VPAT)
    • Technical Details: Integration information or email volume estimates if applicable
  2. Submit your request: Once you have the information ready, submit the IT Purchase Compliance Review form. It is best practice to have a technical contact who is familiar with the product to fill this out. Please note that, while every project is unique, most reviews on average wrap up within six weeks, depending on the level of detail involved.
  3. Wait for approval: Your request will be reviewed by the ITPC Group (IT Purchase Compliance). If approved, you will receive an approval email, which must be attached to the requisition. Without this approval, Procurement Services cannot process your order.

Need Help? If you are ever in doubt about whether a product needs review or how to proceed, contact the Software Team.