Three simple questions generally decide the matter. First: is the system a core competitive asset, or a cost centre? Second: how long will the work last — months or years? Third: who owns it once the vendor leaves?
Non-functional requirements can easily double the number. A tool used by twenty people costs far less than the same feature set serving a hundred thousand users.
Find out how the estimate was built. A credible estimate arrives with a list of assumptions, a breakdown by feature or module and a best case and a worst case.
Ask for the source repository from the first week. A provider that hands over code only at milestones is inviting you to trust a black box. Visible commits tell you the actual pace far better than a weekly report.
Loose phrasing around IP is not an oversight. The agreement should state in plain terms that all deliverables become the property of the client on payment.
Handing a project to a vendor means an external team owns the outcome: they staff the project, the provider manages the day-to-day work, and they carry the staffing risk.
A quote that comes back within a day is a red flag rather than good service. A competent team returns clarifying questions before any number: about integrations.