Most advice about hiring an MSP tells you what to look for. This is about the document you send. An RFP for managed IT services is not a shopping list, it is the first draft of your contract. Texas changes what belongs in it, because since September 2025 your provider’s framework choice decides whether you can claim the state safe harbor. Write it badly and the good providers quietly walk away.
An MSP RFP process is a structured request that asks managed IT providers to bid against one scope, one set of service levels, and one scoring model. It works when the scope describes outcomes instead of a preferred solution.
Every MSP in Texas has a pile of RFPs it never answered. Ours included. The pattern gets easy to spot after a few dozen. Same root cause. Almost every time. The document was written by somebody describing a solution they had already half-decided on, rather than a problem they wanted somebody smarter to solve.
Fair warning about my own industry here. Karl Palachuk, who has spent decades inside it, published a piece in April 2026 arguing that RFPs are a procurement mechanism built for large regulated organizations and that most providers should decline them outright. About the RFPs he receives? He is right.
But there is a version that works. It looks different. It asks for outcomes and obligations instead of products, it names the compliance language it needs back, and it tells bidders exactly how the decision gets made. That version gets answered. Usually by the firm you were hoping would answer. Here is how to write it, weight it, and run it on a calendar a 40-person company can survive.
What is an MSP RFP process?
An MSP RFP process is the sequence a business runs to pick a managed IT provider through written competition. You define scope, invite a shortlist, issue one document, collect comparable proposals, score them against fixed weights, check references, and negotiate with the winner.
One word there carries all the weight. Comparable. Two proposals describing different scopes are not comparable, however neatly you line up the monthly numbers. Most of the real work happens before anything goes out, in deciding what every bidder has to price.
So treat it less as a purchase and more as a first draft of the agreement. Whatever you ask for in section 4 is what lands in the contract. Whatever you leave out becomes a change order in month 7. Every time. If you want the criteria themselves rather than the mechanics, our managed IT services checklist covers what to look for before you sign anything.
Should a Texas SMB run an MSP RFP at all?
Usually not. An RFP earns its overhead when you have roughly 25 or more users, more than 1 site or a compliance obligation you have to evidence, and a decision more than 1 person has to sign.
Below that line the math turns against you fast. Really fast. A 12-person firm running a formal RFP spends 3 weeks producing a document that 4 providers spend 30 hours each answering, and the winner is the same firm the owner would have picked after 3 discovery calls. Everybody burned a month to arrive somewhere they could have walked to.
Bias disclosed. We win more work through referrals and discovery conversations than through competitive bids, so the industry line here happens to suit us nicely. It is still the correct read of most RFPs that reach our inbox.
Headcount is not really the threshold though. It is about who has to be convinced. That is the whole test.
| Your situation | Formal RFP? | What to do instead |
|---|---|---|
| Under 20 users, 1 site, no regulated data | No | Take 3 discovery calls and compare the written scopes side by side |
| 20 to 99 users, first real IT contract | Sometimes | A short RFP. 6 pages, not 40 |
| 100 to 249 users, or multiple sites | Yes | Full RFP with published weights and reference checks |
| Regulated data of any volume (HIPAA, GLBA, CJIS, DoD) | Yes | RFP plus a security questionnaire your auditor will accept |
| A board, PE sponsor or insurer requires competitive bidding | Yes | Document everything. The paper trail is the deliverable |
| You already know who you want | No | Skip it. A bid run to justify a settled decision wastes 4 firms’ time and yours |
That last row deserves more space than it is getting. Wired bids, where the outcome is decided and the process is theater, are the single fastest way to lose access to the providers you will want in 3 years. They can tell. They talk to each other.
RFI, RFP or RFQ. Which one do you actually need?
Each document does a different job. An RFI gathers market information and builds your shortlist. An RFP asks for a proposed approach with pricing and terms attached. An RFQ prices a scope you have already specified line by line. Most Texas SMBs need the first two. Never the third.
| Document | What you are asking for | When it fits | Response window |
|---|---|---|---|
| RFI | Coverage, client profile, capacity, and whether they would even bid | You do not yet know who serves your size and area | 1 week |
| RFP | Approach, scope response, service levels, security posture, pricing | You understand the problem but not the solution | 3 weeks |
| RFQ | A price against a scope you wrote yourself | Hardware, license counts, a defined one-off project | 1 week |
Skip the RFI when you already have 4 or 5 credible local names from peers, your insurer, or your industry association. Do not skip it when your list came from a search engine. Half those firms will be the wrong size for you. Finding that out in week 5 rather than week 2 is an expensive way to learn it. Ask early.
The 6 sections an MSP RFP has to contain
Six sections carry the whole document. Environment, scope, service levels, security and compliance, commercial terms, and your decision method. That is the list. Anything else is padding that lengthens the response window without improving the answers.
- Your environment, described honestly. User count, sites, servers, cloud tenants, line-of-business applications, and the 3 things that break most often. Vague environment sections are the number one reason providers no-bid.
- Scope written as outcomes. What must be true at the end, not which vendor tool gets you there. “Endpoint threats are detected and contained within 15 minutes” beats naming a product you read about.
- Service levels you will genuinely enforce, each with its remedy attached. A response target with no service credit behind it is a wish, not a term.
- Security and compliance requirements, named. The section below is entirely about this one, because it is the section almost every downloadable template fumbles.
- Commercial terms. Term length, renewal mechanics, price protection, onboarding cost, and what happens to your documentation and credentials the day you leave.
- How you will decide. Publish the weights.
That second bullet is the entire argument with the anti-RFP camp. Palachuk is right that RFPs freeze requirements too early and reward whoever writes proposals well. But that describes solution-first RFPs, where a buyer with partial knowledge specifies the answer and then grades vendors on obedience. Which is a real problem. An outcomes-first RFP inverts it. You state the result and the constraint, and you let 5 firms show you 5 routes.
One of those routes is usually better than the one you had in mind. That is the whole point of asking.
On the commercial section, be specific about exit long before you care about exit. Especially exit. Ownership of documentation, admin credentials, and backup data are the 3 clauses that decide how painful your next transition is, and our breakdown of MSP contract terms Texas buyers should negotiate covers the language worth borrowing.
The Texas clauses most RFP templates leave out
Three requirements change what belongs in a Texas MSP RFP. Chapter 542 of the Business and Commerce Code, the FTC Safeguards Rule if you touch consumer financial data, and the supply chain section of the NIST Cybersecurity Framework. Most templates miss all three.
Start with the state one, because it is the newest and the least understood. Senate Bill 2610 added Chapter 542 to the Business and Commerce Code effective September 1, 2025. It bars a plaintiff from recovering exemplary damages after a breach, but only from a business with fewer than 250 employees that can demonstrate it implemented and maintained a conforming cybersecurity program at the time the breach happened. No grace period. No phase-in. Our guide to the Texas data storage compliance deadline walks the wider obligations.
What almost nobody puts in an RFP is the part that decides eligibility. Section 542.004 scales the requirement by headcount. The tier you land in changes what you should be asking bidders to commit to. Find your row.
| Your employee count | What Chapter 542 requires | What the RFP should make bidders commit to |
|---|---|---|
| Fewer than 20 | Simplified requirements, including password policies and appropriate employee cybersecurity training | The policy set they deploy, and how training completion gets evidenced |
| 20 to 99 | The CIS Controls Implementation Group 1 | A control-by-control IG1 mapping, with anything they will not cover named in writing |
| 100 to 249 | Full conformance to a named framework such as NIST CSF, NIST 800-171, CIS Controls, ISO 27001 or SOC 2 | The framework by name, the assessment cadence, and who signs the attestation |
| 250 or more | Chapter 542 does not apply to you | Whatever your insurer and your largest customers require instead |
Here is the part that trips people up, and we got it wrong ourselves in the first year the law was live. An MSP holding a SOC 2 Type 2 report has evidence about the MSP. About them. Not about you. It says they run a tidy shop, which is worth knowing, but it is not evidence that your environment conforms to anything at all, and Chapter 542 asks what you implemented and maintained. So ask for both. Their attestation, and their written plan for your program.
The federal layer is older and catches more Texas businesses than owners expect. Under 16 CFR 314.4(f), a covered financial institution has to take reasonable steps to select service providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess the provider based on the risk it presents. The FTC reads “financial institution” broadly, and its own guidance for automobile dealers is the clearest proof of how far past banks that definition reaches. Mortgage brokers, tax preparers, collection agencies and dealerships all sit inside it. Check before you assume otherwise.
Read that middle obligation again. Require those safeguards by contract. If you are covered, you are already required to have contract language you probably do not have, and an RFP is the cheapest place in the world to generate it.
The framework layer says the same thing in different words. NIST rebuilt supply chain risk into a governance function in CSF 2.0, and its quick-start guide for cybersecurity supply chain risk management puts subcategory GV.SC-05 plainly, which is that supply chain requirements are established, prioritized and integrated into contracts with suppliers. Your MSP is your most privileged supplier. They hold domain admin.
Same instruction, from 3 different authorities. Put it in the contract. The RFP is where contract language is born.
How to weight the scorecard so price does not run the decision
Weight price somewhere between 20% and 25%. Common practice puts it near 40%, which reliably selects the cheapest bidder and calls the result a process.
Publish the weights inside the RFP itself. All of them. Bidders write better proposals when they know what you care about, and you lose the ability to move the goalposts after the numbers land, which is a discipline worth imposing on yourself.
| Category | Weight | What a 5 out of 5 looks like |
|---|---|---|
| Scope fit and coverage | 25% | Every item in your environment section is priced, and the out-of-scope list is specific rather than boilerplate |
| Security and compliance | 25% | Framework named, evidence offered unprompted, gaps disclosed before you ask |
| Service levels and remedies | 15% | Response and resolution both defined, with service credits that actually cost them something |
| Price and cost transparency | 20% | All-in annual cost is visible, not just a per-user headline |
| Team, references and fit | 15% | Named engineers, 3 reachable clients your size, and 1 former client |
Score independently before anyone talks. The Harvard Kennedy School Government Performance Lab is blunt about this in its RFP guidebook, and the reasoning holds at 40 seats just as well as at 40,000. The moment your loudest evaluator speaks first, the other scores drift toward theirs. Every panel does this. Watch for it.
On that price row, compare the right number. Not the headline. The quoted per-user rate is not what leaves your account. Across the Texas engagements we have priced, all-in first-year cost lands around 1.4 to 1.6 times the headline rate once onboarding, project work, license pass-through and after-hours are counted. Our Texas MSP Pricing Index publishes the current ranges, and if two bids come back far apart, the reasons MSP quotes differ on identical scope will usually explain the gap before you have to ask anyone.
A 6-week timeline a 40-seat company can survive
Six weeks from kickoff to a signed letter of intent is realistic for a 40-seat Texas business. Public sector RFPs commonly run 8 weeks or longer. Compress below 4 and you will collect thin proposals from whoever happened to be free. Do not compress it.
| Week | What happens | Who owns it |
|---|---|---|
| 1 | Write the environment section and pull a real asset list | You, with your current provider or internal IT |
| 2 | Shortlist 4 to 5 providers, send the RFI, confirm intent to bid | Whoever owns the decision |
| 3 | Issue the RFP and open a written question window | Same person |
| 4 and 5 | Bidders write. You answer every question to all bidders at once | You |
| 6 | Score independently, then meet. Shortlist 2, call references, see the portal | The scoring panel |
Answering questions to everyone at once is not politeness. It is what keeps the bids comparable. It is also the single rule most first-time buyers break. Publish every answer.
Award, negotiation and transition planning sit outside those 6 weeks. Budget another 2 to 4 weeks before anyone touches a system, and read how to switch MSPs without downtime before you send a termination letter to the incumbent. Order matters here. More than most people realize.
What it means when good MSPs do not bid
A no-bid is data. If 3 of your 5 shortlisted providers decline, the problem is almost certainly the document rather than the market.
Providers triage. A serious MSP fielding 4 bid invitations a month answers the 1 it can price accurately and win, and the deciding factor is rarely deal size. It is whether the RFP gave them enough to be right.
- The environment section was thin, so any number they quote is a guess they will have to defend later
- The deadline was 8 days. Nobody good has 30 spare hours next week
- Contract terms nobody in the industry accepts, usually unlimited liability or a 5-year term with no exit
- It read like a wired bid. An incumbent named 3 times, or requirements only 1 firm could meet
- They are not the right size for you, which is genuinely useful information and costs you nothing to receive
Ask the ones who declined why they declined. Most will tell you in a paragraph. Free consulting. The fix is often 2 sentences in your environment section and 5 extra days on the clock.
If your favorite local firm passes twice, that is not a coincidence. That is feedback.
What to do with all of this
Three things carry most of the value here. Write scope as outcomes, so bidders can show you a better route than the one you had in mind. Put your compliance requirements in the document, because Chapter 542, the Safeguards Rule and NIST CSF 2.0 all point at contract language and the RFP is where that language gets written. Then publish your weights. Price stays under a quarter.
Do that and you get comparable proposals from firms that wanted the work. Skip it and you get 4 documents that cannot be graded against each other, which is how a 6-week process turns into a coin flip with paperwork. Nobody wants that.
Have the scope reviewed before you send it
If you are drafting an MSP RFP for a Texas business, the cheapest hour you can spend is having somebody who answers these documents read your scope and compliance sections first. We will mark the parts that will trigger a no-bid and the clauses your Chapter 542 tier needs. You are welcome to use it with our competitors.
Send us your draft scope and we will mark it up. We support businesses across Houston, Dallas-Fort Worth and San Antonio.
What Texas buyers ask before they send an RFP
How long should an MSP RFP actually be?
6 to 12 pages for a business under 250 users. The environment section should be the longest part of it.
Length is a poor proxy for rigor. A weak one. We have seen 45-page documents that never stated how many servers the company ran, and 7-page documents that produced 4 tightly comparable bids. If a section does not change how somebody prices the work, cut it.
Do we have to tell bidders our budget?
Usually yes, and withholding it costs you more than it saves. A range is enough.
Buyers hide the budget because they are worried every bid will arrive exactly at the ceiling. What actually happens is that providers guess, and half of them guess wrong in a direction that makes their proposal useless to you. Give a range and ask what falls out of scope at the bottom of it. Just ask.
Can we run an RFP if we already like our current provider?
You can, and there is one honest reason to. If a board, an insurer or a lender requires competitive bidding, the process is the deliverable and everyone understands that.
What you should not do is run a bid purely to pressure the incumbent on price. They notice. Your good options stop answering, and you have spent political capital inside your own company to save a few dollars per user. If price is the issue, renegotiate directly. Bring our pricing benchmarks to that conversation instead.
Who should sit on the scoring panel?
Keep it to 3 people for a company under 100 users. The budget owner, whoever lives with the tickets, and 1 person from the part of the business that suffers most during an outage.
Keep it odd-numbered and keep it small. Panels of 7 do not produce better decisions, they produce averaged ones, and averaging is how the safest bland proposal wins.
What if every proposal comes back over budget?
Then the budget was wrong, or the scope was. Nearly always the scope.
Four independent firms pricing the same document and all landing high is a market signal, not a negotiating position. Go back to the environment section and look for what you asked to be covered without realising the cost, which is usually 24/7 coverage, a compliance framework, or a site everyone forgot was in the estimate. Then reissue with 2 clearly priced tiers.
Does the RFP become part of the contract?
Only if you say so, and you should say so. Add a clause stating the RFP and the winning response are incorporated into the final agreement.
Without that line, everything a provider promised in their proposal evaporates the moment a standard MSA gets signed on top of it. This is the single highest-value sentence in the whole document and it costs nothing to include. Add it.









