What Should a Small Municipality Include in an IT Services RFP?
Blog/managed it

What Should a Small Municipality Include in an IT Services RFP?

A small municipality replacing its MSP should build its IT services RFP around seven areas: current environment, required services, cybersecurity and CJIS, support expectations, transition planning, pricing, and vendor qualifications. Use this framework to compare providers more effectively.

11 min read
managed it
What Should a Small Municipality Include in an IT Services RFP?

A small municipality replacing its managed IT provider can seem like a daunting task. But with the right checklist, municipalities can find a situation that is a much better fit for their changing needs. A good rule of thumb is to build its RFP around 7 areas: current environment, required services, cybersecurity and CJIS requirements, support expectations, transition planning, pricing, and vendor qualifications.

For a city with 10–50 employees, the goal should not be to create a 50-page technical document. The RFP should give qualified providers enough information to understand the environment, explain exactly what services are required, and make proposals easier to compare.

The most important thing is specificity.

Instead of asking, “Do you provide good support?” ask what the provider's response process looks like.

Instead of asking, “Are you experienced with cybersecurity?” ask how they assess risk, manage patching, protect backups, and address applicable CJIS requirements.

Here is a practical framework small municipalities can use.

1. Describe Your Current Technology Environment

A good RFP starts by helping prospective providers understand what they may be taking over.

You do not need to list every technical detail, but you should provide enough information for providers to estimate the scope of work.

Include information such as:

  • Approximate number of employees
  • Number of computers and laptops
  • Number of locations
  • Police department or public safety operations
  • Servers and cloud systems
  • Microsoft 365 environment
  • Network equipment and internet connections
  • Major software applications
  • Backup systems
  • Current cybersecurity tools
  • Existing IT staff, if any

For example, a municipality might state:

The city has approximately 35 employees across City Hall, Public Works, and the Police Department, with approximately 40 computers, two locations, Microsoft 365, cloud-based applications, and systems that support law-enforcement operations.

That gives providers a much clearer picture than simply saying, “We need managed IT support.”

Be Honest About Known Problems

If you already know about recurring issues, include them.

Examples might include:

  • Frequent internet outages
  • Aging computers
  • Slow response from the current provider
  • Poor documentation
  • Cybersecurity concerns
  • Failed backups
  • Inconsistent patching
  • Lack of technology planning
  • Concerns about CJIS compliance

The more a provider understands before submitting a proposal, the more useful that proposal is likely to be.

2. Clearly Define the Managed IT Services You Expect

One of the biggest problems with IT proposals is comparing providers that are offering completely different services.

Your RFP should clearly state what you expect the MSP to provide.

For a small municipality, that may include:

Help Desk Support

Specify whether you expect support for all city employees and how users should be able to request help.

Ask providers to explain:

  • Help desk hours
  • Support methods
  • Ticket escalation procedures
  • After-hours support
  • Emergency support
  • Average response expectations

Proactive Monitoring and Maintenance

Ask what the provider monitors and maintains.

That could include:

  • Computers
  • Servers
  • Network equipment
  • Software updates
  • Security patches
  • Backup systems
  • Antivirus or endpoint protection
  • Microsoft 365

A useful RFP question is:

“What services will you perform proactively every month even if no employee submits a support ticket?”

The answer can help separate truly proactive providers from companies that primarily operate on a break-fix model.

Strategic IT Planning

The MSP should not only fix problems.

Ask whether the provider will help the city plan for:

  • Equipment replacement
  • Technology budgeting
  • Cybersecurity improvements
  • Cloud migrations
  • Software changes
  • Long-term infrastructure needs

For small municipalities with limited internal IT staff, this strategic guidance can be especially valuable.

3. Include Specific Cybersecurity and CJIS Requirements

Cybersecurity should have its own section in the RFP.

Don't settle for a checkbox asking whether the provider offers cybersecurity.

Ask prospective MSPs to explain their approach to areas such as:

  • Multi-factor authentication
  • Endpoint protection
  • Email security
  • Patch management
  • Backup protection
  • Threat monitoring
  • Security awareness training
  • Incident response
  • Vulnerability management
  • Account security

If your municipality has a police department or systems that handle criminal justice information, also address CJIS requirements.

Ask questions such as:

  1. Do you have experience supporting law-enforcement environments?
  2. Are the engineers who will work with our environment CJIS trained or certified?
  3. How do you assess an environment for CJIS-related security gaps?
  4. How do you document deficiencies?
  5. How do you prioritize remediation recommendations?
  6. How do you separate law-enforcement systems from general municipal networks where appropriate?

Why Verification Matters

Dazzee IT once began working with a municipality of approximately 50 employees, including 15 employees in the police department.

The city had been told by its previous provider that the environment was CJIS compliant.

After Dazzee IT performed a comprehensive assessment, we identified dozens of CJIS compliance issues.

One of the most serious concerns was that the city's general office and law-enforcement networks were co-mingled, creating a potential path where a compromised general office workstation could have exposed sensitive criminal justice systems.

Using Dazzee IT's Assured Ops framework, the environment was assessed, risks were identified, and all remediation recommendations were presented within the first 30 days.

That experience illustrates why an RFP should not ask only:

“Are we CJIS compliant?”

A better question is:

“How will you verify our compliance posture and document any gaps you discover?”

4. Define Your Support and Response Expectations

“Good customer service” is too vague for an RFP.

Be specific about what you expect.

You might ask providers to describe:

  • Average response times
  • How urgent tickets are prioritized
  • Escalation procedures
  • How employees communicate with the help desk
  • Whether support is provided by employees or outsourced staff
  • How after-hours emergencies are handled
  • How recurring problems are identified

You can also ask:

“What percentage of issues are typically resolved the same day?”

And:

“How will you communicate ticket status to city employees and leadership?”

This gives you something more concrete to compare than marketing language.

At Dazzee IT, we believe the help desk should become part of the client's team, not feel like an outside company that employees hesitate to contact.

5. Require a Detailed Transition and Onboarding Plan

This is one of the most important sections of an RFP when replacing an existing MSP.

Changing IT providers can involve access credentials, documentation, backups, licensing, security tools, vendor accounts, and institutional knowledge.

Ask each provider to explain exactly how they would manage the transition.

The plan should address:

  • Coordination with the outgoing MSP
  • Collection of documentation
  • Administrative credentials
  • Microsoft 365 access
  • Domain and DNS access
  • Network documentation
  • Backup access
  • Software licensing
  • Security tools
  • Vendor contacts
  • Equipment inventory
  • User onboarding
  • Cybersecurity assessment

A strong question is:

“What will happen during our first 30, 60, and 90 days as your client?”

The provider should be able to give you a structured answer.

The First 30 Days Matter

The transition period is often when hidden problems are discovered.

That's why Dazzee IT's Assured Ops approach includes assessing the environment, identifying risks, and developing actionable recommendations early in the relationship.

For a municipality replacing an MSP, the first month should not simply be about transferring passwords.

It should also be about understanding the actual condition of the technology environment.

6. Ask for Transparent Pricing

Municipal leaders need to understand what they are paying for.

The RFP should require providers to explain:

  • Monthly recurring price
  • Per-user or per-device costs
  • One-time onboarding fees
  • Project costs
  • After-hours charges
  • Hardware costs
  • Software licensing
  • Cybersecurity costs
  • Backup costs
  • Any services excluded from the agreement

For the types of organizations Dazzee IT serves, managed IT typically ranges from approximately $130–$180 per seat, per month, depending on the environment and services required.

For example:

Seats Approximate Monthly Range

10 $1,300–$1,800

25 $3,250–$4,500

50 $6,500–$9,000

These are example ranges, not quotes for a specific municipality.

The important point is that cities should compare what is included, not just the monthly number.

A proposal that appears less expensive may exclude cybersecurity tools, backups, after-hours support, strategic planning, or other services another provider includes.

7. Evaluate Vendor Qualifications, Not Just Price

The RFP should require providers to explain why they are qualified to support a municipality.

Ask about:

  • Municipal clients
  • Law-enforcement experience
  • CJIS credentials
  • Cybersecurity expertise
  • Engineering certifications
  • Help desk structure
  • Years in business
  • References
  • Insurance coverage
  • Strategic planning process

References are particularly useful.

Instead of only asking for three references, consider requesting at least one reference from another municipality or public-sector organization when possible.

A Simple RFP Scoring Framework

Municipalities can make proposals easier to compare by using a weighted scoring model.

For example:

Evaluation Area

Example Weight

Municipal and law-enforcement experience

20%

Cybersecurity and CJIS capabilities

20%

Support and response process

20%

Transition and proactive management approach

15%

Technical qualifications

10%

Pricing and value

15%

The exact weighting should reflect your municipality's priorities.

The important thing is to avoid evaluating proposals only on price.

A provider responsible for cybersecurity, backups, employee support, law-enforcement systems, and critical city technology should be evaluated on its ability to actually perform those responsibilities.

10 Questions Every Municipality Should Put in an IT RFP

If you want a shorter starting point, include these ten questions:

  1. How many municipalities or government organizations do you currently support?
  2. What experience do you have supporting police departments or CJIS environments?
  3. What happens during the first 30, 60, and 90 days after we change providers?
  4. How do you assess cybersecurity risk?
  5. How do you verify and document CJIS-related security requirements?
  6. What are your help desk response and escalation procedures?
  7. What do you proactively monitor and maintain each month?
  8. How do you manage backups and test recovery?
  9. What services are included in your monthly fee, and what costs extra?
  10. How will you help city leadership plan technology and cybersecurity spending over the next three years?

The quality of the answers can tell you a great deal about the provider.

Red Flags to Watch for in a MSP Proposal

Be cautious if a provider:

  • Gives vague answers about cybersecurity
  • Cannot explain its onboarding process
  • Has no government or law-enforcement experience
  • Says you're “CJIS compliant” without explaining how it verifies that
  • Won't explain what is included in its monthly fee
  • Has no documented escalation process
  • Focuses almost entirely on fixing problems instead of preventing them
  • Cannot explain how it will document your environment
  • Has no clear plan for communicating technology risks to leadership

Specificity matters here too.

If the proposal is vague before the contract is signed, it probably will not become clearer afterward.

Why Small Municipalities Work With Dazzee IT

Dazzee IT works with organizations throughout Missouri and Kansas, including municipalities and law-enforcement environments.

Our approach includes:

  • CJIS-certified engineers
  • Experience with city governments and law enforcement
  • Cybersecurity expertise
  • A responsive help desk designed to become part of your team
  • Proactive monitoring
  • The Assured Ops framework for assessing environments and developing remediation recommendations
  • Managed IT pricing typically ranging from approximately $130–$180 per seat, per month

For municipalities replacing an existing MSP, we believe the transition should provide more than a new help desk phone number.

It should give leadership a clearer understanding of the city's technology environment, cybersecurity risks, priorities, and long-term technology needs.

The Bottom Line

A good municipal IT RFP should help you answer one question:

Which provider is best prepared to protect, support, and improve our technology environment over the long term?

For a small municipality, focus on seven areas:

Current environment. Services. Cybersecurity and CJIS. Support. Transition. Pricing. Qualifications.

Then require providers to give specific answers.

Don't ask only whether they provide cybersecurity. Ask what they do.

Don't ask only whether they understand CJIS. Ask how they verify it.

Don't ask only whether they provide good support. Ask how quickly they respond and how issues are escalated.

And don't ask only what it costs. Ask exactly what you're getting for that investment.

A well-written RFP makes it easier to compare providers—and makes it much more likely that your next MSP becomes a true technology partner instead of simply replacing the company you're leaving.

Is your Missouri or Kansas municipality preparing to replace its current IT provider? We would love the opportunity to talk with you. Contact Dazzee IT to discuss what your city should include in its RFP and what to expect during an MSP transition.

Ready to Stop Worrying About IT?

Join hundreds of organizations who trust Dazzee IT as their technology partner.

60-day trial
100% satisfaction guarantee
No setup fees