Group 1 Contact Us

The RFP Checklist for Outsourced IT Services: 40 Questions to Ask Before You Shortlist

Written by David Brock

A strong outsourced IT RFP does two things: it gives providers enough context to quote accurately, and it asks questions specific enough that weak vendors cannot hide behind marketing language.

At minimum, your RFP should cover coverage and capability, technician vetting standards, security and compliance posture, SLA and escalation structure, pricing model, and transition plan. Send a vague document and you will get six vague responses that all sound identical, which leaves you choosing on price and gut feeling.

That is how most bad IT partnerships start. Not with a dramatic failure, but with a comparison spreadsheet where every vendor scored a 4 out of 5 on everything because nobody asked a question hard enough to produce a real answer.

Below is a working checklist you can lift directly into your RFP document, organized by evaluation category, along with the red flags worth watching for when responses come back.

What should an outsourced IT RFP include before you ask a single question?

Providers cannot quote accurately on incomplete information, and every gap in your RFP becomes a change order later. Before the question sections, give vendors the following.

Your organizational profile: total headcount, number of locations with general markets, device inventory by type, current help desk platform, average monthly ticket volume, and any compliance obligations that apply.

Your scope: which support tiers you need covered, how often you expect on-site presence, what hardware support looks like, whether project work is included, and which functions your internal team is keeping. If you are unclear on where that line should fall, thinking through how support tiers are structured first will save you a round of clarifying calls.

Your timeline: RFP due date, evaluation window, target start date, and whether an existing contract needs to unwind first.

Your response format requirements. This one matters more than it sounds. If one provider quotes per-user and another quotes per-location with no common denominator, you are doing arithmetic instead of evaluation, and arithmetic is where errors live. The difference between per-user and per-device pricing models is worth understanding before you specify a format, because the model you pick shapes what you pay for three years.

Coverage and capability: 8 questions

  1. In which cities and metro areas can you dispatch a technician, and how quickly in each of our specific locations?
  2. What is your average time to on-site arrival, by market, for the past 12 months?
  3. Are your technicians employees, subcontractors, or a mixed network, and how does that vary by market?
  4. Can you support all of our current locations, and what happens when we open a location in a market you do not currently cover?
  5. Which service categories do you cover directly versus subcontract out?
  6. Do you support international locations, and under what terms?
  7. What is your capacity for project work such as office buildouts, refreshes, and reimaging, running alongside day-to-day support?
  8. Can you provide surge capacity for acquisitions, office moves, or seasonal spikes, and with how much notice?

Question 4 is the one that separates national providers from regional ones wearing a national logo. Ask for a coverage map, not an adjective.

Technician quality and vetting: 6 questions

  1. What is your technician vetting process, step by step?
  2. What percentage of applicants do you accept?
  3. What certifications do you require, and how do you verify them?
  4. What background check standard applies, and does it vary by client or market?
  5. What is the average years of experience across your technician network?
  6. How do you handle escalation when a technician encounters something outside their scope?

For field and on-site roles, the A+ credential is the common baseline, and CompTIA notes it appears in more tech support job listings than any other IT credential. Network+ is a reasonable additional requirement for anyone touching switches or cabling. A provider who cannot describe their vetting standards in specifics is telling you the standards do not exist. Techmate’s breakdown of building field IT capability in-house versus outsourcing it covers what good vetting actually looks like. CompTIA

Security and compliance: 8 questions

  1. What security certifications do you hold, and can you provide current documentation?
  2. Will you sign a Business Associate Agreement or equivalent for our regulatory environment?
  3. How do you provision, manage, and revoke technician access to client systems?
  4. What is your process for offboarding a technician who leaves your network mid-engagement?
  5. Do technicians use their own devices on client sites, and how are those devices secured?
  6. What is your incident response process if a technician is involved in a security event?
  7. Do you subcontract, and if so, what security standards apply to subcontractors?
  8. Can you provide your most recent penetration test summary?

This is not paranoia, it is arithmetic. Verizon’s 2026 Data Breach Investigations Report found that third-party supply chain breaches jumped 60% and now account for 48% of total breaches. Your IT provider will hold privileged access to your environment across every location you operate, which makes vendor security assessment part of your own security posture rather than a procurement formality. NIST’s cyber supply chain risk management guidance includes a due diligence framework worth borrowing wholesale if your organization does not already have one. Question 21 is the sleeper: outsourcing that gets outsourced again is where accountability quietly evaporates. Verizon

SLA and escalation: 7 questions

  1. What response and resolution commitments do you offer by priority level?
  2. Are those commitments contractual, and what financial consequences attach to a miss?
  3. How do you measure and report SLA performance, and at what frequency?
  4. Can SLAs be tiered differently by location?
  5. What does your escalation path look like, with named roles and time thresholds?
  6. Who is our day-to-day contact, and who is the executive sponsor?
  7. What reporting do we receive, and can it be broken out by location?

Insist on location-level reporting. A global average will look perfectly acceptable while one office quietly suffers for eight months. If you want a template for what enforceable service levels look like, the deeper dive on designing and enforcing SLA governance covers priority tiers, penalty structures, and gain-sharing.

Not sure what to put in the scope section yet? Techmate runs a free 30-minute IT support audit that maps your current coverage and identifies the gaps worth writing into your RFP. Book one here.

Pricing and contract: 6 questions

  1. What pricing models do you offer, and which do you recommend for our profile and why?
  2. Are travel, mileage, after-hours, and surge charges included or billed separately?
  3. What triggers a change order, and how is change order pricing calculated?
  4. What are the contract term, renewal terms, and price escalation provisions?
  5. What are the exit provisions, notice periods, and data or documentation handover terms?
  6. What is not included that we should expect to pay for separately?

Question 31 quietly determines whether your budget survives the year. Travel and surge charges can add a meaningful percentage to a multi-site contract, and they never appear in the headline number. Question 35 is the most useful question in the entire RFP, because it invites vendors to disclose exclusions they would otherwise let you discover in month four. Before finalizing your cost comparison, running the numbers against the full in-house versus outsourced cost breakdown will give you a defensible baseline for the board conversation.

Transition and onboarding: 5 questions

  1. What does your onboarding process look like, week by week?
  2. How do you capture our environment documentation, and what do you need from us?
  3. What happens during the overlap period if we are transitioning from another provider?
  4. What does the first 90 days look like, with defined milestones?
  5. What has gone wrong in past transitions, and what changed as a result?

Question 40 is the best question on this list. Every provider has had a transition go sideways. The ones worth hiring will tell you about it. The ones who claim a spotless record are either new or not being straight with you.

Transition risk is also the reason documentation requirements belong in the contract rather than the kickoff meeting. As the case for treating IT documentation as a core deliverable lays out, runbooks and asset records are what let a partnership survive turnover on either side. And if you are unwinding an existing agreement, the mechanics of switching providers without downtime should shape your timeline before you commit to a start date.

What are the red flags in an RFP response?

Vague geography. Phrases like “nationwide coverage” with no city list, no dispatch times, and no named markets.

SLA language stuffed with exceptions. If the carve-outs consume more space than the commitments, there is no commitment.

Pricing dramatically below everyone else with no explanation. Someone is either misreading your scope or planning to make it back on change orders.

No references at comparable scale. Ask for at least three from organizations similar in size and location count. An inability to produce them answers your question for you.

Evasion on subcontracting. Not a disqualifier by itself, but non-disclosure is.

Boilerplate answers. If the response could have been sent to any company in any industry, it was.

How should you score the responses?

Weight the categories before you read a single submission, ideally before the RFP goes out. Assigning weights afterward is how a shortlist gets reverse-engineered to match whoever gave the best presentation.

A reasonable starting split for multi-location organizations: coverage and capability 30%, security and compliance 20%, SLA structure 20%, pricing 20%, transition approach 10%. Adjust for your regulatory environment. Organizations in regulated industries typically shift more weight toward compliance, and for good reason.

Score independently before the group discussion. Group scoring converges on whoever speaks first.

How does Techmate respond to outsourced IT RFPs?

Techmate provides on-site IT support across 450+ cities, drawing from a network of 7,000+ vetted specialists across the United States, Canada, England, and parts of the EU. Every technician moves through a four-step vetting process with only the top 5% of applicants accepted, and technicians bring 5 to 10 years of business and corporate IT experience. Across completed work, technicians maintain a 97% resolution rate and a customer satisfaction score of at least 4.7 out of 5.

On the pricing question, Techmate uses unified nationwide pricing without surge or travel costs, which removes the single most common source of budget variance in multi-site agreements. Clients get a dedicated account manager, a dashboard tracking spend and work history by location, and the option to white label technicians so employees experience one consistent IT team regardless of which office they walk into.

Coverage spans desktop support, hardware, network and rack work, audio visual, projects and recurring work, and staff augmentation, with support for co-managed arrangements where your internal team keeps strategy and ownership.

Building your shortlist now? See how the engagement model works, or start a conversation about coverage for your specific locations.

Frequently Asked Questions

What should an outsourced IT services RFP include?
Your organizational profile, scope of services needed, timeline, required response format, and structured questions across six categories: coverage and capability, technician vetting, security and compliance, SLA and escalation, pricing and contract terms, and transition planning.

How many vendors should you include in an IT RFP?
Four to six is a practical range. Fewer than three limits comparison. More than six creates evaluation fatigue, and fatigue is when scoring gets sloppy.

What questions should you ask an outsourced IT provider about security?
Certifications held, access provisioning and revocation process, technician offboarding procedure, device security standards, incident response process, subcontracting practices, and recent penetration test results.

How long should an outsourced IT RFP process take?
Most organizations run four to eight weeks from RFP release to selection, plus a transition period before go-live. Compress it further and you will skip reference checks, which is the step people most regret skipping.

What is the biggest mistake companies make in IT vendor selection?
Choosing on headline price without accounting for excluded costs like travel, surge rates, after-hours premiums, and change orders. The cheapest proposal frequently is not the cheapest contract.