MSP RFP template: the questions that matter
A structured RFP framework for mid-market buyers evaluating managed service providers.
A structured RFP framework for mid-market buyers evaluating managed service providers.
Most MSP RFP templates available online were built for enterprise procurement teams. They run to 200 questions, require formal response formatting, and take weeks on both sides. Mid-market companies with 100 to 500 employees don’t have procurement teams. They have a CEO, a CFO, and possibly one technology leader who is also keeping the environment running. What follows is a structure that works at that scale: five sections, the questions that actually discriminate between vendors, and a scoring rubric.
Here is what belongs in the document.
An MSP RFP is a formal document a buyer sends to managed service providers to solicit comparable, scored proposals for an outsourced technology support relationship. It defines the scope of services being evaluated, the service level expectations the buyer holds, and the questions whose answers will distinguish one vendor from another.
For mid-market buyers, the most important design decision is scope discipline. Enterprise RFPs run long because their procurement process demands comprehensiveness. At the mid-market level, an RFP that takes a vendor 40 hours to complete filters out responsive vendors, not bad ones. The goal is not exhaustiveness. It is signal: does this vendor understand your environment, and can they operate at your pace and scale?
A workable mid-market MSP RFP has five to seven sections and fits in 10 to 15 pages. It asks the questions that actually produce useful answers. Specifically: How do they define service boundaries? What happens when your most pressing problem does not fit their ticketing categories? Who manages your account day to day, and what does escalation look like? What do their security certifications actually require them to do in practice? And how does pricing change when your environment grows or changes?
The sections below address each of those questions in turn. They are not meant as a word-for-word template. They are the structure your RFP needs and the specific questions that produce answers worth comparing.
The scope section establishes what the MSP is responsible for and what stays in-house or with other vendors. It is the most underspecified section in most mid-market RFPs, and the most consequential. Vendors interpret ambiguity in their favor. Buyers who don’t define scope precisely end up with contracts that exclude the things they needed most.
Questions to include in this section:
What is included in the base managed services scope? List specific service categories you expect covered: end-user support, server management, network monitoring, patch management, backup verification.
What is explicitly excluded? This forces vendors to be specific rather than leave gray areas that become disputes later.
How do you handle requests that fall outside the defined scope? What is the process and what triggers an additional charge?
What on-site coverage is available in our geography, and what is the typical response time for on-site visits?
How do you manage support for non-standard devices or applications in our environment?
Scope definition is where most mid-market technology procurement goes wrong. If you want a vendor-neutral view of what your scope should include before you go to market, Seven Roots’ services include MSP evaluation and selection support built for exactly that starting point.
Service level agreements are the contractual backbone of an MSP relationship, and they are frequently misread. The response time in an SLA is the time until someone acknowledges the ticket, not the time to resolution. For a critical outage, those are very different things.
Questions to include in this section:
What are your defined priority tiers? What qualifies a request for each tier, and who makes that call?
What is your guaranteed response time at each priority level? What is your typical resolution time? Ask for both, and for the difference between them.
What happens when an SLA is breached? What are the financial remedies, and how are they calculated?
What is your after-hours support model? Is it included in base pricing or billed separately?
What has your SLA performance been across your client base over the last 12 months? Ask for actual data, not a summary.
Who is accountable for SLA compliance internally, and how do they report it to clients?
Vendors who can answer specifically about escalation paths and provide real performance data are worth a longer conversation. Vendors who redirect to general assurances are telling you something.
Security is the section most buyers treat as a checkbox exercise. It should not be. An MSP with administrative access to your environment is a high-value target for attackers. Their security posture is effectively your security posture.
Questions to include in this section:
What security certifications do you hold? What specifically do those certifications require you to do? A current SOC 2 Type II report, an independent AICPA audit of controls over a defined period, is different from a self-attestation of compliance.
How is privileged access to client environments managed? What controls govern who can access which systems?
What is your incident response protocol? How and on what timeline do you notify clients of a breach or suspected incident?
How is client data handled, where is it stored, and what happens to it at contract termination?
Have you experienced a security incident involving client data in the last 36 months? What happened and what changed?
Do you carry cyber liability insurance, and what are the limits?
This section is also where you communicate your own compliance requirements. If you operate in healthcare, financial services, or defense contracting, state what those requirements are and ask vendors directly how they support them. Vendors who have not worked in your sector before will surface that gap here.
References are the section most buyers treat as a formality. Vendors know which clients will give them strong reviews. The way to make references useful is to control what they reveal.
Questions to include in this section:
Provide three references at companies similar to ours in size and industry. We will contact them directly. Not available on request after selection: provided as part of the RFP response.
Who would be our named account manager? What is their tenure at your company, and how many accounts do they currently manage?
What does onboarding look like? What is the standard transition timeline and what is required from our side?
How do we escalate above the account manager level, and who would we reach?
What is your client retention rate over the last three years?
When you call references, skip the open-ended praise questions. Ask specifically: Did they deliver what the contract said? What was the worst problem you had with them and how did they handle it? Would you re-sign today?
The account manager question matters more than most buyers realize. The person selling the engagement is rarely the person managing it. Ask to meet the account manager before you sign.
MSP pricing structures vary more than most buyers realize, and the differences matter when your environment changes, grows, or runs into a problem the base contract doesn’t cover.
Questions to include in this section:
What pricing model do you use: per-device, per-user, tiered flat-rate, or a combination? What is included in the base rate?
How does pricing change when we add users, devices, or locations? Is there a minimum seat count?
What triggers an out-of-scope charge? How are those billed: time-and-materials, a project rate, or something else?
What are the contract terms? What conditions allow for early termination?
What have your average annual price increases been over the last three years, and what drives them?
Do you earn referral fees, reseller margin, or other compensation on technology you recommend to clients?
The last question matters. An MSP that earns margin on hardware and software recommendations has an incentive structure that may not align with yours. A clear, direct answer is more trustworthy than a general assurance of objectivity. For a deeper look at how MSP pricing structures differ, see our guide to MSP pricing models.
Scoring RFP responses consistently is harder than writing the RFP. Vendors structure their answers differently. Some are thorough and dense; others are polished and thin. Without a shared scoring framework, the vendor who gives the longest answer tends to score highest, which is not the same as the one who gives the best one.
A weighted rubric forces the evaluation back to what actually matters. The weights below reflect typical mid-market priorities. Adjust them to your situation before you start scoring.
| Evaluation dimension | Weight | What a “5” looks like | Red flags |
|---|---|---|---|
| Scope definition and fit | 25% | All expected service categories explicitly enumerated; exclusions clearly stated; geography and environment covered | Vague “comprehensive support” language; no explicit exclusions listed |
| Security posture | 25% | Current SOC 2 Type II or equivalent certification; documented access controls; written incident response protocol | Self-attestation only; no cyber liability insurance; evasive on prior incidents |
| Service level commitment | 20% | Tiered SLAs with defined response and resolution times; financial remedies for breach; 12-month performance data provided | Response-time-only SLAs; no resolution data; no breach remedies; refuses to share performance history |
| References and account management | 15% | Three comparable references provided with the RFP response; named account manager identified; client retention rate disclosed | References “available upon request” only; no named account manager; retention rate unavailable |
| Pricing transparency | 15% | Clear base rate; explicit out-of-scope triggers; referral and reseller relationships disclosed | Per-incident carve-outs; undisclosed reseller margins; early termination conditions buried in contract language |
Score each vendor on each dimension using a 1 to 5 scale, then multiply by the weight. Sum the weighted scores to get a comparable total across all respondents.
Use the rubric before reference calls, not after. It surfaces the gaps and trade-offs you want to probe in those conversations and clarify before you negotiate contract terms.
If you are running a first-time MSP selection, or want a read on which vendors deserve a shortlist spot before you commit to full evaluation, Heartwood can help you think through your requirements and what the proposals actually mean.
Seven Roots Consulting provides fractional CIO and senior technology leadership to mid-market companies with $25M to $300M in revenue. The firm brings more than 20 years of technology leadership experience and works with growing companies across Wisconsin, the Midwest, and nationally on technology strategy, AI readiness, vendor-neutral evaluation, and M&A due diligence.
A mid-market MSP RFP should run 10 to 15 pages. Long enough to give vendors the context they need to respond accurately, short enough that a capable vendor can complete it in under 20 hours. Enterprise RFPs that run to 50 or 100 pages are designed for procurement teams with dedicated staff. When your RFP takes vendors 40 hours to complete, you filter for vendors with large RFP response operations, not for ones who would be good at managing your environment.
Three to five vendors is the right number for a mid-market selection. Fewer than three and you may not see meaningful price or approach variation. More than five and the evaluation becomes unmanageable for a team without dedicated procurement support. Start by identifying five to eight candidates through referrals, your industry network, or existing relationships. Eliminate any who clearly don’t serve your geography, size, or sector before sending. You will typically end up with three to four usable responses.
Give vendors two to three weeks to respond. Less than two weeks produces rushed, template responses. More than three weeks lets vendors deprioritize your process. Set a firm deadline with a specific time stamp, not just a date. After sending the RFP, hold a written Q&A window of three to five business days where all vendor questions and your responses are shared simultaneously. This prevents individual side conversations and ensures every vendor is pricing to the same information.
No. Sharing your current MSP pricing gives vendors a number to price just below, not an incentive to sharpen their pricing. What you should share is your environment: number of users, devices, locations, key applications, and any growth or changes you anticipate. That gives vendors what they need to respond accurately without anchoring to your existing contract. If you are testing the market at renewal time, this discipline is especially important. The benchmark only works if vendors are pricing to your requirements.
Use the weighted rubric and score on the substance of the answer, not its format. Before scoring begins, align your evaluation team on what a 5 looks like for each dimension. A 5 on security means providing a current SOC 2 Type II report, not describing a security program. When a vendor restructures an answer differently than you asked, assess whether they addressed the underlying question. A vendor who reframes the question and still answers it is different from one who redirects to avoid it.
The decision brief: one technology decision a month, taken apart. No spam, unsubscribe anytime.
A 20-minute diagnostic call, then a written read-back of what we heard. No pitch, no pressure, just a straight read on whether we can help.
Start a diagnostic conversationHeartwood is an AI advisory panel for mid-market executives who need on-demand technology strategy guidance. Start with your toughest question.
Try Heartwood free