# MSP outsourcing RFP template

Version 1.0 - 2026-09-20

This vendor-neutral template helps an MSP request comparable NOC, help desk, white-label, and after-hours proposals. Replace bracketed fields. Remove sections outside the intended scope. Do not include client credentials or confidential ticket data.

## 1. Buyer and process

- MSP legal name - [NAME]
- Operating regions - [REGIONS]
- Proposal contact - [CONTACT]
- Questions due - [DATE]
- Proposal due - [DATE]
- Target pilot start - [DATE]
- Target production start - [DATE]
- Proposal validity period - [DAYS]
- Required response format - complete the matched response table and attach evidence

## 2. Environment profile

| Field | Buyer input |
| --- | --- |
| Managed clients | [COUNT OR BAND] |
| End users | [COUNT OR BAND] |
| Endpoints | [COUNT OR BAND] |
| Servers | [COUNT OR BAND] |
| Network devices | [COUNT OR BAND] |
| Supported timezones | [TIMEZONES] |
| Required languages | [LANGUAGES] |
| PSA | [PLATFORM AND VERSION] |
| RMM | [PLATFORM AND VERSION] |
| Documentation platform | [PLATFORM] |
| Identity platform | [PLATFORM] |
| Remote access method | [METHOD] |

## 3. Required service scope

For each row mark `required`, `optional`, or `excluded`. The provider must state the exact boundary and escalation point.

| Function | Buyer requirement | Provider response | Evidence |
| --- | --- | --- | --- |
| Alert intake and deduplication | [STATE] | | |
| Alert triage | [STATE] | | |
| Automated remediation | [STATE] | | |
| Technician remediation | [STATE] | | |
| Patch management | [STATE] | | |
| Backup monitoring | [STATE] | | |
| L1 help desk | [STATE] | | |
| L2 help desk | [STATE] | | |
| L3 escalation | [STATE] | | |
| Phone support | [STATE] | | |
| Email support | [STATE] | | |
| Portal support | [STATE] | | |
| Chat support | [STATE] | | |
| After-hours coverage | [STATE] | | |
| Weekend and holiday coverage | [STATE] | | |
| Vendor coordination | [STATE] | | |
| On-site dispatch coordination | [STATE] | | |

## 4. Delivery and branding

The provider must describe:

- shared, dedicated, overflow, or hybrid staffing
- service-delivery locations and timezone coverage
- direct end-user contact policy
- phone greeting, email domain, portal, and caller ID branding
- ownership of tickets, documentation, scripts, and recordings
- use of subcontractors
- background-check and training practices
- client-specific runbook handling
- conflict escalation and executive escalation

## 5. SLA response table

| Severity | Operational definition | Service window | Response | Mitigation | Resolution basis | Escalation | Exclusions |
| --- | --- | --- | --- | --- | --- | --- | --- |
| P1 | [DEFINE IMPACT] | [WINDOW] | | | | | |
| P2 | [DEFINE IMPACT] | [WINDOW] | | | | | |
| P3 | [DEFINE IMPACT] | [WINDOW] | | | | | |
| P4 | [DEFINE IMPACT] | [WINDOW] | | | | | |

The provider must define clock start, pause conditions, business-hour treatment, holiday treatment, reporting period, breach review, and remedies.

## 6. Integrations and access

For each required platform provide:

- supported workflow and direction
- objects created or updated
- tenant mapping
- authentication method
- least-privilege permissions
- credential owner
- audit log
- failure and retry behavior
- sandbox or pilot test
- offboarding and credential revocation

Logo presence does not count as implementation evidence.

## 7. Security questionnaire

The provider must provide evidence or mark the item unavailable:

- security program owner
- current certifications and audit scope
- workforce access controls
- MFA enforcement
- privileged access management
- endpoint security
- logging and monitoring
- vulnerability management
- incident notification window
- subcontractor controls
- data locations and transfers
- retention and deletion
- business continuity and recovery testing
- cyber insurance status
- most recent independent assessment date

## 8. Onboarding and transition

Provide the owner, duration, dependency, and acceptance evidence for:

1. Discovery and inventory.
2. Tool access and tenant mapping.
3. Runbook and knowledge transfer.
4. Ticket taxonomy and severity mapping.
5. Branding configuration.
6. Pilot client selection.
7. Test cases and shadow period.
8. Production cutover.
9. First-week review.
10. Thirty-day review.

Also provide exit assistance, data export, credential removal, knowledge return, and transition charges.

## 9. Pricing response sheet

| Charge | Currency | Unit | Quantity tier | Included scope | Exclusions | Minimum | Overage | One-time or recurring | Contract condition |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Core service | | | | | | | | | |
| Onboarding | | | | | | | | | |
| After-hours premium | | | | | | | | | |
| Dedicated resource | | | | | | | | | |
| Tool or license | | | | | | | | | |
| Project work | | | | | | | | | |
| Exit assistance | | | | | | | | | |

State taxes, annual increases, renewal, cancellation, payment terms, credits, and any charge omitted from the table.

## 10. Evidence attachments

- sample monthly report
- sample escalation record
- sample anonymized ticket trail
- certificate or audit evidence
- continuity test summary
- integration documentation
- standard agreement and SLA
- data processing terms
- reference eligibility and permission

## 11. Evaluation rubric

Set weights before proposals are opened.

| Criterion | Weight | Gate or score | Evidence required |
| --- | --- | --- | --- |
| Scope fit | [WEIGHT] | | Matched scope table |
| Coverage and SLA | [WEIGHT] | | Completed SLA table |
| Workflow and integrations | [WEIGHT] | | Demonstration and test plan |
| Security | [WEIGHT] | | Current evidence |
| Onboarding and exit | [WEIGHT] | | Project plan |
| Commercial fit | [WEIGHT] | | Completed pricing sheet |
| Evidence completeness | [WEIGHT] | | Source package |

Unknown fields receive no assumed value. A mandatory gate failure disqualifies the proposal regardless of total score.

