Adapted for use by Green Desert IT — greendesertit.com
MSP RFP template
Send this to 3–5 managed IT providers you're evaluating. Their answers will surface the differences your sales calls won't.
Section 1: Company & scope
- How long has your company been in business? How many full-time employees?
- What is your average client size in seats and monthly revenue?
- How many active managed IT clients do you currently serve?
- What is your client retention rate over the last 3 years?
- Which industries do you specialize in, if any?
- Do you have current clients we can contact as references (at least 2 of similar size)?
Section 2: Service scope
- What is included in your baseline managed IT plan? Please provide a detailed feature list.
- Is EDR (endpoint detection and response) included on every endpoint at no additional charge?
- Is MDR (24/7 managed detection and response) included, or is it an add-on?
- Is managed backup with restore testing included? How often are restores tested?
- Is phishing awareness training included, and does it include simulated phishing campaigns?
- Is on-site support included in the monthly fee, or billed separately? What is the coverage area?
- Is licensing (Microsoft 365, security tools) included, or billed at cost / with markup?
Section 3: SLAs and response
- What is your response time SLA during business hours? What are your defined business hours?
- What is your response time SLA for after-hours P1 (critical) incidents?
- Can you provide response-time and resolution-time data from your ticketing system for the last quarter?
- What is your escalation process for tickets that exceed the SLA?
- What is your uptime target for managed infrastructure, and how is it measured?
Section 4: Security posture
- Which specific EDR product do you deploy, and why?
- Is your MDR SOC staffed 24/7 with human analysts (not just automated triage)?
- Do you have a documented incident response runbook you can share (redacted for confidentiality)?
- Do you have a documented restore test log you can share (redacted)?
- How do you handle patching cadence? Do you separate test and production environments?
- Do you support HIPAA, PCI DSS, CMMC, or SOC 2 environments? Can you produce evidence of controls?
- Do you carry cyber liability insurance, and can you name the carrier and policy limit?
Section 5: Team & operations
- Who will be our primary account contact, and what is their tenure at your firm?
- What certifications does your team hold (Microsoft, CompTIA, Cisco, etc.)?
- What is your team's average tenure? What is your annual staff turnover?
- Do you offshore any part of the help desk or NOC? If so, which functions?
- How do you handle handoffs when a technician is on vacation or leaves?
Section 6: Pricing
- What is your pricing structure — per user, per endpoint, or per site? Please provide indicative pricing for our environment.
- Are there any per-ticket, per-incident, or after-hours surcharges we should be aware of?
- What is your policy on price increases at renewal?
- How are projects (migrations, hardware refreshes, office moves) priced — hourly or fixed-fee?
Section 7: Contract terms
- What is your minimum contract length?
- What is the notice period to cancel, and are there early termination fees?
- Who owns the tenant, admin credentials, and documentation if we terminate the relationship?
- What is your data return / migration assistance policy at end of contract?
- Is there an auto-renewal clause? If so, what is the opt-out window?
Section 8: Business continuity
- What is your own business continuity plan? What happens to us if your firm is disrupted?
- Do you maintain a documented offboarding runbook if we terminate?
How to use this template: Send to 3–5 MSPs, give them 2 weeks to respond. Score answers on a 1–5 scale per question. The revealing question is often #22 — providers who can't produce restore test logs don't have real backup practices.
Written by Green Desert IT. Feel free to redistribute or modify. We'd appreciate a link back to greendesertit.com if you republish.