1. Baseline your environment before you write anything
Most weak MSP proposals come from weak inputs. Vendors cannot price what they cannot see, so they pad their bids or quietly exclude things. Spend the first two to three weeks building a factual baseline.
Collect:
- Users and sites: headcount by location, remote vs. office staff, expected growth over the contract term.
- Endpoints: laptops, desktops, mobile devices, printers, with operating systems and age.
- Infrastructure: servers (physical and virtual), cloud tenants (Microsoft 365, Google Workspace, AWS, Azure), network gear, firewalls.
- Applications: line-of-business systems and who supports them today.
- Ticket history: 6 to 12 months of volume by category, priority and time of day. This is the single most useful dataset you can give bidders.
- Current contracts: incumbent MSP terms, notice periods, licensing agreements and renewal dates.
- Pain points: what fails today, in specific terms. "Password resets take two days" is useful. "Support is slow" is not.
Also decide what stays in-house. Common splits include keeping strategy and vendor management internal while outsourcing the service desk, monitoring and patching.
2. Write the RFP around outcomes, not tasks
Describe what you need achieved and how you will measure it. Leave the method to the vendor, then judge the method in scoring.
A solid RFP document usually includes:
- Background: company overview, the baseline data from step 1, and why you are going to market.
- Scope of services: service desk, endpoint management, network and server monitoring, patching, backup and recovery, security operations, onboarding and offboarding, vendor management, strategic planning.
- Service levels: your target response and resolution times by priority.
- Security and compliance requirements: certifications you expect (for example SOC 2 Type II or ISO 27001), data residency, and any regulatory frameworks you fall under.
- Commercial requirements: a mandatory pricing template, contract length, payment terms.
- Response format and deadlines.
- Evaluation criteria and weights.
Example requirement wording:
The provider will acknowledge Priority 1 incidents within 15 minutes, 24x7x365, and provide status updates every 30 minutes until resolution. Describe your escalation path, staffing model outside business hours, and how you report performance against this target monthly.
That format states the target, the scope and what you want explained, which makes responses easier to compare.
3. Shortlist and set a realistic timeline
Send the RFP to four to six vendors. Fewer limits competition. More creates evaluation work without improving the outcome. Build the list from peer recommendations, analyst directories and a quick screen of vendors who serve companies your size and in your industry.
A typical timeline, which varies with complexity:
- Week 0: issue RFP, with NDA if you are sharing network details
- Week 1: vendor questions due
- Week 2: publish all answers to all bidders
- Week 4: proposals due
- Weeks 5 to 6: scoring and shortlist to two or three
- Weeks 6 to 7: demos, references, site visits
- Weeks 8 to 10: negotiation and contract
Then add transition time, which often runs 60 to 90 days. Work backward from your incumbent's notice period so you do not end up auto-renewed or without support.
One rule: route all vendor contact through a single point of contact, and share every answer with every bidder. It keeps the process fair and defensible.
4. Score responses with weights set in advance
Agree on criteria and weights with stakeholders before proposals arrive. If you set them afterward, people tend to tune the weights toward the vendor they already like.
An example weighting to adapt:
| Criterion | Weight |
|---|---|
| Service delivery approach and staffing | 25% |
| Security and compliance | 20% |
| Pricing and commercial terms | 20% |
| Transition plan | 15% |
| Relevant experience and references | 10% |
| Reporting and account management | 10% |
Use a 1 to 5 scale with written definitions for each score. For example, 5 means the requirement is fully met with evidence, 3 means met with gaps or no evidence, and 1 means not addressed.
Have three to five evaluators, including IT, finance and one end-user representative, score independently first. Then meet to discuss large gaps. Keep the scoring sheets. They support your decision and give you material for vendor debriefs.
5. Verify claims through demos, references and security review
Proposals are marketing documents. The shortlist stage is where you test them.
Scenario demos. Skip the standard slide deck. Give each finalist the same two or three scenarios drawn from your ticket history, for example: "A finance user's laptop is stolen at 9 p.m. on a Friday. Walk us through the next 24 hours." Ask to meet the service desk lead and the technical account manager who would actually be assigned to you.
References. Ask for clients of similar size who have been with the vendor for at least two years, plus one who left. Useful questions:
- How did the transition go compared with the plan?
- How are out-of-scope requests handled and priced?
- How has staff turnover on your account affected service?
- What would you negotiate differently?
Security due diligence. An MSP usually holds privileged access to your whole environment, so review it like a critical supplier. Request audit reports, penetration test summaries, their incident response process, how they manage their own remote access tools, and their cyber insurance coverage.
6. Normalize pricing so bids are comparable
MSPs price per user, per device, in tiers, or as a fixed monthly fee with add-ons. If you let each vendor use its own format, you will end up comparing things that do not match.
Require a mandatory pricing template that separates:
- Monthly recurring fees, with the unit (user, device, site)
- One-time onboarding and transition costs
- Hourly or project rates for out-of-scope work
- Third-party licensing, and whether it is resold with markup
- After-hours and on-site visit charges
- Annual price escalation mechanism
Model the total cost over the full contract term at your current headcount and at your projected growth. Check what counts as "in scope" carefully. A low monthly fee paired with narrow scope often costs more once project work and exceptions are billed.
7. Negotiate the terms that matter after go-live
Price gets most of the attention in negotiation, but most post-signature disputes come from service terms, scope and exit. Focus on:
- SLAs with remedies: service credits tied to measured performance, plus a right to terminate for repeated misses.
- Scope definitions: a clear list of in-scope and out-of-scope services in a schedule, not scattered through the proposal.
- Exit and transition assistance: documentation, credentials and data handover at contract end.
- Key personnel: approval rights over changes to your account lead.
- Flexibility: the ability to add or remove users within agreed bands without renegotiating.
- Term and renewal: a clear notice window and no silent multi-year auto-renewal.
Example exit clause:
Upon termination for any reason, the Provider will provide up to 90 days of transition assistance at the rates in Schedule C, including delivery of all administrative credentials, configuration documentation and customer data within 10 business days of request.
Let pingpong run it for you
pingpong drafts the RFP, finds and invites vendors, collects proposals through a private portal, scores them with five AI models and flags the gotchas above. It drafts every negotiation message for your approval, then keeps watching the market so you renegotiate before renewal. $100 for the first month, then $799 a month.
Common questions
How long does a managed IT services RFP usually take?
Plan for roughly 8 to 12 weeks from issuing the RFP to signing, depending on scope and approval layers. Add 60 to 90 days for transition. Starting the baseline work a few weeks earlier usually shortens everything that follows.
Should the incumbent MSP be invited to bid?
Usually yes, if the relationship is not beyond repair. The incumbent gives you a useful benchmark and may improve its terms under competition. Hold it to the same template and scoring as everyone else, and do not share its pricing with other bidders.
What is a reasonable contract length for managed IT services?
Terms of three years are common, with one to five years seen in practice. Longer terms can lower monthly pricing, but they raise the cost of a poor choice. If you commit to a longer term, protect yourself with SLA-based termination rights and clear annual escalation caps.