Managed IT Services RFP Template: 35 Questions + Vendor Scorecard for 100–500 Employee Companies

managed it services rfp

You are trying to pick an IT partner that can support 100–500 employees, not become an expert in help desk staffing, cybersecurity, Microsoft 365, backups, and service-level agreements. A managed IT services RFP turns those technical details into business questions your leadership team can actually score.

If you are the operations leader or CFO running this decision, you have probably had the same quiet thought: “All three providers sound the same, and I cannot tell which one will actually own the problem when something breaks.” That is a fair concern, and it is the reason this process exists.

The villain here is unclear accountability. Two providers can both promise managed IT while including very different services, and the gap usually shows up after the contract is signed, not during the sales call.

CIO Technology Solutions runs this the same way with growing Tampa Bay companies: define what you need, ask every provider the same questions, and score the answers against evidence.

The Short Answer

A managed IT services RFP is a structured document that tells prospective MSPs what your business needs and asks each provider to respond to the same requirements. For a 100–500 employee company, it should cover support, cybersecurity, Microsoft 365, infrastructure, backups, SLAs, transition, pricing, reporting, and strategic planning.

The point of every section is the same: identify who is accountable, not just what is offered.

Table of Contents

Why a Managed IT Services RFP Matters More at 100–500 Employees

At 30 employees, leadership may compare two providers over a few calls. At 100–500 employees, the environment can include multiple locations, hundreds of devices, Microsoft 365, business applications, cybersecurity requirements, internal IT staff, outside vendors, and active projects.

Informal comparisons become risky because two providers can both say they offer “managed IT” while including very different services.

The goal of an MSP RFP is not to find the provider with the longest feature list. It is to identify which provider can take clear responsibility for the IT outcomes your business depends on.

A current example shows why this matters. The 2026 City of Canton Managed IT Services RFP describes roughly 150 staff and two full-time internal IT employees, with the city seeking a co-managed provider for higher-level infrastructure management, cybersecurity, and strategic procurement.

Public procurement differs from private buying, but the operating problem is familiar.

Managed IT Services RFP: A Clear Definition and Purpose

Unfortunately, the term gets used loosely. A managed IT services RFP, or request for proposal, describes your IT environment, required services, expectations, and evaluation criteria so competing MSPs answer the same questions.

In simple terms: instead of asking three providers, “What do you offer?”, you tell all three what your business needs and ask exactly how they would deliver it.

Businesses typically use an MSP RFP when the decision affects many employees, several locations, regulated data, internal IT staff, or a meaningful technology budget.

An informal quote works for a simple environment but is hard to compare consistently. A full MSP RFP fits a larger or more complex environment and takes preparation. A co-managed IT RFP works when internal IT needs added coverage, as long as responsibilities are spelled out. A project RFP covers one migration and does not define ongoing IT ownership.

Question Answer
Is an RFP only for enterprise companies? No. It helps whenever inconsistent proposals make a major IT decision difficult to compare.
Must we choose the lowest bidder? No. A scorecard can evaluate service, security, fit, risk, and price together.

What to Include in Your RFP Document

Give providers enough information to understand the business without creating a 100-page technical document.

Include:

  • Company size, locations, and support hours
  • Current IT team and responsibilities
  • Approximate devices, servers, networks, and Microsoft 365 users
  • Business-critical applications and vendors
  • Help desk and escalation expectations
  • Cybersecurity and compliance requirements
  • Backup and disaster recovery expectations
  • Reporting and technology planning
  • Transition requirements
  • Pricing format and contract expectations

Security belongs in the RFP as a business requirement, and the NIST Cybersecurity Framework 2.0 gives you a structure worth borrowing: Govern, Identify, Protect, Detect, Respond, and Recover.

The CISA small and medium-sized business resources recommend practical protections including multifactor authentication, software updates, logging, backups, encryption, and phishing awareness.

35 Questions to Ask Every Managed Service Provider

Ask every finalist the same 35 questions. When an answer sounds broad, request examples, reports, sample processes, or contract language.

Support and Service Levels

  1. What help desk hours are included?
  2. What are your response targets by issue severity?
  3. Can users reach a live technician?
  4. How are critical after-hours incidents handled?
  5. What support reports will leadership receive?

Cybersecurity and Risk

  1. Which cybersecurity services are included in the monthly fee?
  2. Who monitors security alerts, and who responds?
  3. How do you protect administrator and privileged accounts?
  4. How do you manage operating system and third-party patching?
  5. How do you support compliance or cyber insurance requirements?

Microsoft 365, Identity, and Cloud

  1. Who owns our Microsoft 365 tenant, domains, and administrator credentials?
  2. What Microsoft 365 administration is included?
  3. How do you manage onboarding and offboarding?
  4. How do you review risky sign-ins and account security?
  5. What backup options do you provide for Microsoft 365?

Microsoft frames cloud security as a shared responsibility in the cloud, which means your business still owns data, identities, configurations, and users no matter who administers the tenant.

Infrastructure, Backup, and Recovery

  1. Which servers, networks, firewalls, endpoints, and cloud systems do you monitor?
  2. What data is backed up, how often, and where?
  3. How often do you test restores?
  4. What recovery time and recovery point targets will you commit to?
  5. How do you maintain and test disaster recovery plans?

In simple terms: recovery time is how long a system can remain unavailable. Recovery point describes how much recent data the business can afford to lose.

Team, Governance, and Documentation

  1. Who will be our account manager and senior technical contact?
  2. What happens when the first technician cannot solve an issue?
  3. Who owns our IT documentation?
  4. How often will you review our roadmap, risks, and budget?
  5. How do you coordinate our other technology vendors?

Governance answers matter more than they look. The provider who cannot tell you who owns your documentation is usually the provider who will make leaving difficult.

Transition, Projects, and Co-Managed IT

  1. What does transition from our existing provider look like?
  2. How do you handle missing passwords or incomplete documentation?
  3. Can you work alongside an internal IT team?
  4. Which projects are included versus separately billed?
  5. How do you support multiple offices or remote employees?

Pricing, Contracts, and Proof

  1. How is your monthly pricing calculated?
  2. What common services are excluded or billed separately?
  3. Are onboarding or offboarding fees separate?
  4. What are the contract, renewal, termination, and data-return terms?
  5. Can you provide references from similar organizations?

These questions should reveal accountability, not just capability.

Question Answer
Should providers list every security product? Tools matter, but first ask who monitors them and what happens when something goes wrong.
Should our current MSP answer the RFP too? Yes. The same process can show whether the incumbent still fits the business.

Managed IT Vendor Scorecard: How to Compare MSPs Fairly

Here is the problem with reading proposals cold. Set your scoring weights before the proposals arrive, because a polished presentation or an unusually low price can quietly change what leadership considers important.

Evaluation Category Recommended Weight
Service desk, SLAs, and support 20%
Cybersecurity and risk 20%
Backup, recovery, and continuity 15%
Microsoft 365 and infrastructure 15%
Team depth and transition 10%
Strategy, reporting, and documentation 10%
Pricing and contract terms 10%
Total 100%

Score each category from 1 to 5 and require reviewers to document unusually high or low scores.

CIO Technology Solutions has answered these questions from the other side of the table since 2010, for healthcare, legal, financial services, construction, manufacturing, and hospitality clients across Tampa Bay. Fifteen years of RFP responses makes one pattern clear: the providers who answer specifically are the ones who deliver specifically.

Score evidence, not promises. “24/7 security” should lead to questions about who watches alerts, who can act, how incidents escalate, and what reporting proves the work happened.

Question Answer
Should the cheapest MSP win? Not automatically. A lower proposal may exclude services another provider includes.
How many finalists should we compare? Three qualified finalists usually provide enough contrast without creating unnecessary complexity.

Strategic Recommendation: Fully Managed vs Co-Managed IT

Ultimately, the model matters as much as the provider. A 100–500 employee company may need an MSP without needing to outsource everything.

Use fully managed IT services when one provider should own most daily IT operations. Consider co-managed IT services when your internal IT team needs added support, cybersecurity, engineering, project capacity, or backup coverage.

Decision Area Fully Managed Co-Managed
No internal IT team Better fit Usually unnecessary
Strong internal IT leadership Can work Better fit
Full help desk ownership Better fit Depends on scope
Specialist security or engineering Strong fit Strong fit
Internal team is overloaded Strong fit Often best fit
Keep internal control Less flexible Better fit

State your preferred model in the RFP, but let providers recommend another structure when they can explain why it better serves the business.

Common Scenarios Where an MSP RFP Works Best

Your Business Has Outgrown Its Current IT Model

Recurring issues, delayed projects, thin documentation, and one-person dependency are signs the support model may no longer scale. Review the CIO Technology Solutions guide to outgrown IT support before defining the RFP scope.

Internal IT Needs More Coverage

A capable IT manager may need help desk capacity, cybersecurity monitoring, engineering, project help, or coverage during vacations and turnover. Co-managed IT can fill those gaps without replacing the internal team. CIO Technology Solutions has run this model with Tampa Bay construction and healthcare clients where one IT manager covered several hundred users, and the answer was added coverage, not replacement.

You Are Replacing an Existing MSP

Define transition responsibilities before choosing the replacement. The guide on how to switch IT providers without downtime provides a practical transition checklist.

You Are Growing Toward 300–500 Employees

Compare each proposal against the IT organization you are becoming, not only the company you operate today. The IT department structure guide can help identify the functions that need ownership.

Common Situations Where Another Approach May Be Better

A full RFP may be unnecessary for one small project or a simple environment. A scoped assessment, project proposal, or direct provider comparison may move faster when the decision has few variables.

How to Run the RFP Process in 3 Steps

1. Assess the Environment and Define the Scope

Document users, locations, applications, Microsoft 365, infrastructure, security, backups, vendors, and internal IT responsibilities. Clearly identify what the provider must own.

2. Score Every Provider the Same Way

Give finalists the same questions, assumptions, pricing format, and deadline. Clarify vague responses in writing so reviewers compare equivalent information.

3. Validate the Winner Before Signing

Check references, review exclusions, confirm the transition plan, and read the termination terms. Meet the people who will actually support your company, not only the sales team.

Getting this wrong is expensive in ways that never show up on the first invoice. A provider who cannot staff after-hours escalation turns a Friday night server failure into a Monday morning revenue problem. A provider with untested backups turns a ransomware event into weeks of reconstruction. Unclear accountability leaves your business exposed during a compliance audit or a cyber insurance renewal, and nobody owns the fix while your clients wait.

Once you choose a provider, the work shifts to onboarding. CIO Technology Solutions runs that through the CIO Provider Transition Roadmap:

  1. Schedule a conversation about your environment, your risks, and what the RFP surfaced.
  2. We assess the environment and build a roadmap covering support, security, Microsoft 365, and continuity.
  3. You get predictable, proactive IT, and your team gets back to work.

Frequently Asked Questions About MSP RFPs

What is a managed IT services RFP?

It defines your IT requirements and asks competing MSPs to respond in a consistent format.

How many questions should an MSP RFP include?

There is no required number. These 35 questions cover the major service, security, continuity, team, and commercial areas.

Should cybersecurity be included?

Yes. Define responsibility for monitoring, patching, identity protection, incident response, and recovery.

Should Microsoft 365 management be included?

If your business uses Microsoft 365, clarify administration, identity, email, licensing, support, and backup responsibilities.

How should we compare MSP pricing?

First normalize what each proposal includes. Then compare recurring costs, add-ons, projects, onboarding fees, and contract requirements.

Is fully managed or co-managed IT better?

Fully managed works well when the provider owns most operations. Co-managed works well when internal IT needs additional capacity or expertise.

What are common MSP RFP red flags?

Watch for vague SLAs, unclear exclusions, weak documentation ownership, poor recovery testing, thin escalation coverage, and unclear security responsibility.

Should Tampa Bay companies require onsite support?

Include it when hands-on response matters. Define locations and expected onsite availability before comparing providers.

Can CIO Technology Solutions work with an existing IT team?

Yes. CIO Technology Solutions supports both fully managed and co-managed environments.

Conclusion

A managed IT services RFP gives growing companies a common definition of good IT support. It helps leadership compare who owns support, cybersecurity, Microsoft 365, continuity, strategy, transition, and cost before signing an agreement.

For a 100–500 employee organization, the right technology partner should reduce uncertainty rather than add to it. Businesses should be able to grow with confidence, protect their reputation, and know who is accountable when technology matters most.

Picture the version where this goes well. Six months in, help desk tickets close without leadership chasing them, your monthly IT cost is a number you can forecast, your backups have been restored in a test you watched, and you know exactly who to call when something breaks. CIO Technology Solutions helps organizations in Tampa, St. Petersburg, Clearwater, and across Tampa Bay reach that point without turning the process into a technical exercise.

Call 813-649-7762 or Talk to an Expert

Bring your current RFP, vendor proposals, or even a rough list of requirements. CIO Technology Solutions can help identify gaps, ask better questions, and determine which support model fits your business.

Get Tampa Bay IT and cybersecurity insights delivered to your inbox.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

Categories

Categories
protecting your business with managed it services

ARE YOU AT RISK?

According to McAfee, malicious cyber attacks cost the US $300 billion to $1 Trillion per year. Don’t be a victim.

Protect your data with our Guide to Protecting
Your Business with Managed IT.

STOP CYBER CRIMINALS
top 10 ways to prevent being hacked ebook

ARE YOU VULNERABLE TO ONLINE ATTACKS?

PROTECT YOUR COMPANY FROM HACKERS.

Download our free Ebook:
Top 10 Ways to Prevent Your Business from Being Hacked

GET YOUR COPY

OWN A SMALL BUSINESS?

Get tips on how to minimize vulnerabilities
and maintain a healthy IT infrastructure.

small business network security risks landing page DOWNLOAD EBOOK
Remote Support