A strong municipal IT Request for Proposal should give providers enough information to understand the municipality’s environment while giving leadership an objective way to compare proposals.
Before releasing an IT RFP, a North Carolina municipality should define at least 10 areas: objectives, current environment, scope of services, cybersecurity, support expectations, transition requirements, vendor qualifications, pricing, evaluation criteria, and contract expectations.
North Carolina law allows contracts for information technology to be entered into using an RFP procedure under G.S. 143-129.8. Under that procedure, the contract is awarded to the entity submitting the best overall proposal, with the factors used in the award identified in the RFP. citeturn693286search2
The appropriate procurement process can still depend on the specific purchase, local policies, funding source, and other requirements.
Municipal officials should involve their purchasing professionals and legal counsel when determining the appropriate procurement procedure.
This article is an IT planning resource and is not legal advice.
Municipal IT RFP Quick Checklist
Before issuing an IT RFP, make sure you have addressed:
- Business objectives
- Current technology environment
- Required scope of services
- Cybersecurity requirements
- Service levels and response expectations
- On-site and after-hours support
- Transition and onboarding
- Vendor qualifications and municipal experience
- Pricing format
- Evaluation criteria and contract expectations
Step 1: Start With the Problem You’re Trying to Solve
Do not begin with a giant list of products.
Begin with the result the municipality wants.
Examples:
- Reduce recurring downtime
- Improve cybersecurity
- Prepare for CJIS requirements
- Supplement an understaffed IT department
- Replace an outsourced provider
- Improve help desk response
- Modernize aging infrastructure
- Improve backup and disaster recovery
- Build a predictable IT budget
Providers should understand why the municipality is requesting proposals.
That produces more meaningful responses.
Step 2: Describe Your Current Environment
Give providers enough information to understand the approximate size and complexity of the environment.
Include numbers such as:
- Employees
- Users
- Computers
- Servers
- Municipal facilities
- Firewalls
- Switches
- Wireless access points
- Microsoft 365 users
- Mobile devices
- Police department users
- Existing IT staff
Also identify major departments such as:
- Administration
- Finance
- Police
- Fire
- Public Works
- Utilities
- Parks and Recreation
Specific numbers help providers produce more accurate and comparable proposals.
Step 3: Define the Scope of Services
Avoid simply writing:
“Provide IT support.”
That leaves too much open to interpretation.
Instead, define responsibilities.
User Support
- Help desk
- Remote support
- On-site support
- User onboarding
- Employee termination
Infrastructure
- Servers
- Networks
- Firewalls
- Wireless
- Internet vendor management
Microsoft 365
- Administration
- Licensing support
- User management
- Security configuration
Cybersecurity
- Endpoint protection
- MFA
- Security monitoring
- Vulnerability management
- Security awareness training
Data Protection
- Backup monitoring
- Restore testing
- Disaster recovery planning
Strategic Planning
- Budget planning
- Technology roadmap
- Hardware lifecycle
- vCIO meetings
A clear scope prevents the municipality from receiving several proposals that look similar in price but contain very different levels of service.
Step 4: Define Cybersecurity Requirements
Cybersecurity deserves its own section in the RFP.
Ask providers to explain how they address:
- Multi-factor authentication
- Endpoint Detection and Response
- Security monitoring
- Vulnerability management
- Patch management
- Email security
- Administrative privileges
- Network security
- Backup protection
- Incident response
If the municipality operates a police department or accesses Criminal Justice Information, include applicable CJIS considerations.
Do not assume every provider interprets “cybersecurity included” the same way.
Step 5: Define Support Expectations With Numbers
Do not ask:
“Do you provide fast support?”
Nearly every provider will say yes.
Ask:
- What are your support hours?
- What qualifies as an emergency?
- What is your response target for critical issues?
- What percentage of calls are answered live?
- How are after-hours incidents handled?
- How are tickets escalated?
- Is on-site support included?
- Where are technicians located?
- Are response commitments documented in the agreement?
Specific numbers make providers easier to compare.
Step 6: Include Transition Requirements
Ask each provider to explain what happens after the contract is awarded.
Questions should include:
- Who leads onboarding?
- How is information collected from the incumbent provider?
- How are credentials transferred?
- How are systems documented?
- When are security tools deployed?
- How are backups verified?
- How are employees told where to request support?
- How long does onboarding typically take?
- How is disruption minimized?
A strong proposal should explain both ongoing service and the transition into that service.
Step 7: Evaluate Municipal Experience
Municipal IT environments can differ significantly from ordinary small-business environments.
Ask about experience supporting:
- Municipal governments
- Police departments
- Public works
- Utilities
- Multi-location government environments
- CJIS-connected systems
Request relevant references or case studies where appropriate.
The objective is not simply to find a company that understands computers.
It is to find a provider that understands the municipal operating environment.
Step 8: Require a Comparable Pricing Format
Do not make an evaluation committee reverse-engineer five different pricing models.
Give every provider the same pricing template.
Request separate pricing for:
- Per-user recurring services
- Per-device services, if applicable
- Microsoft licensing
- Cybersecurity
- Backup
- On-site support
- After-hours support
- Onboarding
- Projects
- Hardware
- Optional services
Also ask vendors to identify what is excluded.
A lower initial proposal can become more expensive if important services later appear as additional charges.
Step 9: Define Evaluation Criteria Before Proposals Arrive
Under North Carolina’s IT RFP procedure in G.S. 143-129.8, contracts are awarded to the entity submitting the best overall proposal, and the factors used in the award must be identified in the RFP.
A municipality might therefore create a planning framework such as:
| Category | Example Weight |
|---|---|
| Municipal experience | 20% |
| Technical approach | 20% |
| Cybersecurity | 20% |
| Support model | 15% |
| Transition plan | 10% |
| Strategic planning | 5% |
| Price/value | 10% |
These percentages are examples only and are not statutory weighting requirements.
The municipality should establish criteria appropriate to its requirements before reviewing proposals.
Step 10: Define Contract Expectations
Clarify expectations including:
- Contract term
- Renewal provisions
- Insurance requirements
- Confidentiality
- Data ownership
- Documentation ownership
- Termination procedures
- Transition assistance at contract end
- Required reporting
- Technology review meetings
Appropriate municipal purchasing and legal professionals should review procurement documents and contract requirements.
25 Questions to Ask in a Municipal IT RFP
- How many municipalities do you currently support?
- What size municipalities do you typically support?
- How many employees are on your technical team?
- Where are your technicians located?
- What are your support hours?
- What percentage of calls are answered live?
- What is your emergency response commitment?
- Is on-site support included?
- How do you handle after-hours emergencies?
- How do you manage Microsoft 365?
- What endpoint security capabilities do you provide?
- How do you manage MFA?
- How do you monitor security alerts?
- How do you manage vulnerabilities?
- How are backups protected?
- How often are restores tested?
- How do you support CJIS environments?
- How do you manage employee onboarding and termination?
- How do you document our environment?
- What happens during onboarding?
- Who manages third-party technology vendors?
- Do you provide strategic IT planning?
- What services are excluded from the monthly price?
- Can you provide municipal references?
- What happens to our data, documentation, and administrative access if the agreement ends?
These questions turn general marketing claims into information an evaluation committee can compare.
Frequently Asked Questions About Municipal IT RFPs
Does a North Carolina municipality have to issue an RFP for managed IT services?
Not automatically.
North Carolina G.S. 143-129.8 allows information technology contracts to be entered into using an RFP procedure, but the appropriate procurement method for a specific municipality may depend on what is being purchased, local purchasing policies, funding sources, contract structure, and other requirements. citeturn693286search2
Municipalities should confirm the appropriate process with their purchasing officials and legal counsel.
Does a municipality have to choose the lowest-priced IT provider?
Not necessarily when using the North Carolina IT RFP procedure under G.S. 143-129.8.
That statute provides for the contract to be awarded to the entity submitting the best overall proposal, based on factors identified in the RFP. citeturn693286search2
That allows municipalities to consider factors such as:
- Municipal experience
- Cybersecurity
- Technical approach
- Service levels
- Transition planning
- Staffing
- Price and overall value
How can we compare MSP proposals when every provider prices services differently?
Give every provider the same pricing worksheet.
Ask them to separately identify:
- Recurring managed services
- Security
- Backup
- Microsoft licensing
- On-site support
- After-hours support
- Onboarding
- Projects
- Hardware
- Excluded services
A standardized pricing format makes differences easier to identify.
What cybersecurity requirements should we include in a municipal IT RFP?
At minimum, ask providers to explain their approach to:
- MFA
- Endpoint protection
- Patch management
- Vulnerability management
- Security monitoring
- Backup protection
- Incident response
- Employee security awareness
- Administrative access
If the municipality accesses Criminal Justice Information, include applicable CJIS requirements as well.
How do we know whether an IT provider really has municipal government experience?
Ask specific questions.
For example:
- How many municipalities do you currently support?
- What are their approximate sizes?
- Do you support police departments?
- Do you have CJIS experience?
- Do you support public works or utilities?
- Where are your technicians located?
- Can you provide relevant municipal references?
- Can you provide municipal case studies?
A provider saying “we serve government” is not the same as demonstrating municipal experience.
What should we ask about onboarding before selecting an IT provider?
Ask the provider to explain:
- Who leads the transition
- How credentials are transferred
- How the old provider’s access is removed
- How backups are verified
- How systems are documented
- When security tools are deployed
- How staff learn the new support process
- What happens when documentation is missing
- What onboarding costs are separate from monthly service
This gives the municipality visibility into what happens immediately after award.
How do we avoid getting locked into an IT provider we cannot easily leave?
Address exit planning before signing the agreement.
Clarify:
- Who owns administrative accounts
- Who owns documentation
- Who owns the municipality’s data
- How credentials are returned
- How documentation is exported
- What transition assistance is provided
- What happens to security and monitoring tools
- How much notice is required for termination
A municipality should be able to change providers without losing control of its own accounts, data, or documentation.
A Better RFP Produces Better Proposals
A municipal IT RFP should not simply collect prices.
It should help leadership answer:
Who understands our environment?
Who can protect it?
Who can support our employees?
Who can help us plan for the future?
Specific questions produce specific answers.
And specific answers make providers easier to compare.
CW IT Support works with municipalities throughout North Carolina on managed IT, co-managed IT, cybersecurity, CJIS support, backup and disaster recovery, and strategic technology planning.
Planning an upcoming municipal IT RFP? Contact CW IT Support to discuss your technology requirements and the questions your municipality should be asking.
Previously Published in Our North Carolina Municipal IT Series
- How Much Does Managed IT Cost for a North Carolina Municipality in 2026?
- CJIS Compliance Checklist for North Carolina Municipalities (2026)
- Should a North Carolina Municipality Hire an Internal IT Director or Outsource to a Managed IT Provider?
- What Happens in the First 90 Days After a North Carolina Municipality Switches IT Providers?
- What 15 Cybersecurity Controls Should Every North Carolina Municipality Have in 2026?

