collectquotes
Guide

A managed IT scope skeleton, in twelve line items

Twelve line items, a fixed response format, and published evaluation factors. Copy it and send it.

Filed 2026-07-29Updated 2026-07-297 min read

What follows is a scope of work you can retype into a document and send to three providers this afternoon. It is short on purpose. A forty-page request for proposal from a 60-person firm gets skimmed, and the sections that get skimmed are the ones that were padded, so the useful version fits on two pages and consists almost entirely of numbers you already know.

What this skeleton is

The structure is borrowed from public procurement, which faced the comparability problem earlier and answered it by dictating the shape of the response rather than hoping for one. The uniform contract format fixes sections A through M so that every offer arrives assembled the same way, with Section L holding instructions to offerors and Section M holding the evaluation factors. Two of those ideas are worth stealing wholesale: tell bidders exactly how to lay out a price, and tell them in advance how you will decide.

The second borrowing is the performance work statement, which is required to describe the work in terms of the required results rather than either how the work is to be accomplished or the number of hours to be provided, and to enable assessment against measurable standards. Applied here, that means you specify the outcome and the count, and you leave the method to the bidder. Do not tell a provider which remote monitoring platform to run. Do tell it that 157 devices must be patched on a stated cycle and that you expect a monthly report proving it.

Line items one through four are facts about you. Five through nine are the service. Ten through twelve are the commercial terms that decide what the price actually means. Every bidder prices all twelve or the bid is non-responsive, which is a phrase worth using because it saves the awkward conversation later.

The twelve line items

01

Environment of record

State the count yourself and attach it as a schedule. Total employees, total named accounts, sites with addresses, and the date the count was taken. Instruct bidders that this schedule, not their own discovery scan, is the basis of the bid, and that any discrepancy is to be raised as a written question before the due date rather than resolved silently inside a price.

02

Sites, hours and coverage window

Business hours per site, in local time, including the sites that run a second shift. Name the window inside which the recurring fee applies and state that everything outside it is priced separately on line 06. Multi-site firms should say whether on-site attendance is expected at each address and how often.

03

Devices in scope, by class

Workstations, laptops, physical servers, hypervisor hosts, network appliances, printers, tablets, mobile devices — each as its own count. Require a rate per class rather than a blended figure. This single instruction removes most of the arithmetic in the comparison guide, because a bidder who must publish a server rate cannot bury servers in an optional schedule.

04

Users, accounts and shared logins

Named accounts, shared or kiosk logins, service accounts, licensed mailboxes belonging to leavers, and contractors. Give each a number. Then state which of them you consider billable users and require bidders to price against your definition. If a bidder disagrees, it will say so, and that is a productive argument to have before signature.

05

Helpdesk scope and response targets

Say what a ticket is entitled to: unlimited remote support, a stated number of on-site visits, or an hours bank. Ask for response and resolution targets by severity, with severity defined by business impact rather than by the provider's internal queue. Ask what percentage of tickets the target must be met on and over what measurement period.

06

After-hours, weekend and holiday work

The most common source of a surprise invoice. Require three numbers: the hourly rate outside the window, the minimum billing increment, and the list of dates treated as holidays. Ask whether an incident that begins at 16:30 and runs to 19:00 bills the whole call at the after-hours rate. Providers who include after-hours in the recurring fee should say so on this line rather than leaving it implied.

07

Security tooling, named by vendor and tier

Endpoint detection, email filtering, multi-factor authentication, vulnerability scanning, log retention. For each, require the product name, the licence tier, and whether a human is watching it or it is licensed only. If you hold federal contract information, the fifteen basic safeguarding requirements are a defensible floor to write into this line, and they are short enough to attach in full.

08

Backup, retention and restore testing

Recovery time objective and recovery point objective per system class, retention period, where copies live, and who runs the annual restore test. Ask for the restore test report as a named deliverable with a date. Backup that has never been restored is a line item rather than a capability, and the difference only surfaces on the worst day of the year.

09

Patching, monitoring and reporting

Patch cycle for workstations and for servers, the maintenance window, the approval process for anything that reboots production, and the contents and cadence of the report that proves it happened. Specify that the report goes to a named person at your end. Reporting nobody reads is a cost with no benefit, and reporting nobody receives is neither.

10

Onboarding and transition

Ask for a fixed price, a duration in weeks, and a written list of what the fee covers: documentation, agent deployment, credential handover, the first audit. CISA's buyer guidance asks providers for a transition plan to support a smooth integration of the IT services, with any required downtime timed to suit you rather than the provider. Ask for that plan as a document, not a paragraph.

11

Tooling ownership and exit

Who holds the tenancy for the monitoring platform, the endpoint agent, the documentation system and the Microsoft partner relationship. Whether documentation is exportable and in what format. What disengagement assistance costs, in hours and in dollars, and what happens to your data if the invoice is disputed. A provider that will not answer this line in writing has answered it.

12

Price schedule and escalation

One table: rate per device class, rate per user class, the recurring monthly total, the onboarding total, and the after-hours rate. Separately, the term, the notice period, the annual escalator with its cap, and the trigger that causes a re-tier. Require licences and hardware to be shown at cost with any margin disclosed as its own line.

The response format you dictate

Three instructions do most of the work. First: answer in the order of the twelve line items, using the same numbering, with a price on every one, and write "no charge" rather than leaving a blank. Second: any exclusion must appear against the line item it excludes, not in a general terms appendix. Third: attach the full commercial terms with the proposal rather than after selection, because a term sheet that arrives after you have chosen is not a term sheet, it is a fait accompli.

Set a question deadline a week before the response deadline, and circulate every question and answer to all bidders. It costs one email and it removes the advantage that goes to whichever provider had the best relationship with whoever answers the phone. Public procurement does this for fairness. You should do it because it keeps the three responses answering the same question.

How you will evaluate

Publish the factors in the request. Something as plain as: normalized cost per endpoint over the full term, completeness against the twelve line items, security tooling depth, references from two firms of similar size in your sector, and exit terms. Say whether price is the deciding factor or one of several. Bidders write to the stated factors, which is the point.

A caution about weightings, since we would rather not pretend. Assigning percentage weights to those five factors and computing a score is popular and produces a number that looks decisive. We do not know whether it produces better decisions than reading the five columns and arguing about them, and we have not seen a study on small-business IT procurement that would settle it. The scoring matrix does have one real virtue, which is that it forces the argument to happen before the proposals arrive rather than after.

What to leave out

Leave out your budget. A stated budget becomes the price, and the three bids arrive within a few percent of it having been built backwards from the number. Leave out the incumbent's current invoice for the same reason. Leave out any requirement that names a specific platform unless you have a real reason, because it disqualifies providers whose stack is fine and whose logo is different.

Leave out the company-background section. Nobody has ever chosen a provider on the strength of a paragraph about its founding, and asking for it guarantees four pages of it. Leave out the request for a methodology narrative, which is where boilerplate lives. If you want to know how a provider works, ask line 09 what the report contains and line 06 what happens at 16:30 on a Friday. The answers to those two are specific, checkable, and impossible to write in advance.

Finally, leave out the deadline that is too short. Two weeks is enough for a provider to price twelve line items properly and not enough for it to schedule the discovery call it wants first. Three weeks gets you better numbers from the same three firms, and the extra week costs you nothing you were going to spend anyway.

Sources
  1. FAR 15.204-1 — Uniform contract format U.S. General Services Administration, Acquisition.gov
  2. FAR 37.602 — Performance work statement U.S. General Services Administration, Acquisition.gov
  3. FAR 52.204-21 — Basic Safeguarding of Covered Contractor Information Systems U.S. General Services Administration, Acquisition.gov
  4. CISA Insights: Risk Considerations for Managed Service Provider Customers Cybersecurity and Infrastructure Security Agency
Sources checked 2026-07-29. If a link has rotted since, tell us and we will fix it.