IT support proposals are difficult to compare because providers rarely describe their services in the same way. One quotation emphasises unlimited tickets. Another focuses on engineer visits. A third includes monitoring, Microsoft 365 administration, backup and cybersecurity tools. The monthly prices may look comparable even though the responsibilities are completely different.
A useful comparison should convert every proposal into the same operating questions: what is covered, who responds, how risk is controlled, what evidence management receives and what happens when the environment changes.
This 100-point scorecard helps Dubai SMEs compare providers without allowing price or presentation quality to dominate the decision.
Step one: create one common service baseline
Before scoring providers, give each one the same environment information.
The baseline should include:
- number of users and support locations;
- laptops, desktops and mobile devices;
- Microsoft 365 or other cloud services;
- servers, storage and business applications;
- firewalls, switches, Wi-Fi and internet links;
- backup systems;
- working hours and peak periods;
- onsite-support expectations;
- known risks and recurring incidents;
- planned growth, relocation or projects.
If providers make different assumptions, their proposals cannot be compared fairly.
Category 1: service-scope fit — 20 points
Score how clearly the provider covers the environment and daily operating needs.
| Evidence | Points |
|---|---|
| Supported users, devices, locations and systems are explicitly listed. | 4 |
| Incidents, service requests, changes and projects are distinguished. | 4 |
| Microsoft 365, network, server, endpoint and vendor responsibilities are clear. | 4 |
| Remote, onsite and after-hours coverage is defined. | 4 |
| Exclusions and additional charges are understandable. | 4 |
Do not award full marks for broad phrases such as “complete IT support.” The scope must be testable.
Category 2: service desk and SLA — 15 points
Evaluate how users receive support and how priorities are controlled.
- approved ticket channels and call process — 3 points;
- P1–P4 or equivalent business-impact model — 3 points;
- response, update, restoration and resolution definitions — 3 points;
- technical and management escalation — 3 points;
- major-incident communication process — 3 points.
A fifteen-minute response promise is not valuable if the provider cannot explain what happens next.
Category 3: onsite and local delivery — 10 points
Dubai businesses may need physical support for networks, meeting rooms, devices, branches and office changes.
Score:
- location and availability of onsite engineers — 2 points;
- scheduled versus incident-based visits — 2 points;
- coverage across all business locations — 2 points;
- site-access and emergency arrangements — 2 points;
- backup staffing when the usual engineer is unavailable — 2 points.
Ask whether onsite delivery is internal or subcontracted and how the provider maintains service quality.
Category 4: technical breadth and escalation — 10 points
A service desk can solve user issues but may need specialists for cloud, networking, security, backup or servers.
Request examples of escalation capability for:
- Microsoft 365 and identity;
- firewalls and networking;
- servers and virtualization;
- backup and recovery;
- security incidents;
- business applications and vendor coordination.
Score based on named capability, ownership and response—not a long list of vendor logos.
Category 5: security of the service — 15 points
The provider may receive privileged access. Security should therefore carry significant weight.
| Control | Points |
|---|---|
| Named accounts, MFA and role-based access for technicians. | 3 |
| Secure remote-support and monitoring controls. | 3 |
| Staff access removal and periodic review. | 3 |
| Incident escalation and breach notification. | 3 |
| Customer data handling, confidentiality and subcontractor controls. | 3 |
CISA’s guidance for managed service providers and customers highlights the risk created by trusted provider access and recommends transparent security responsibilities. The joint advisory is a useful reference when scoring this category.
Category 6: backup and continuity — 10 points
Score the provider’s ability to explain:
- which systems and data are protected — 2 points;
- monitoring and failed-job response — 2 points;
- restore testing — 2 points;
- recovery priorities and responsibilities — 2 points;
- continuity of its own service — 2 points.
Do not award points merely because backup software is included. Recovery evidence matters.
Category 7: documentation and reporting — 10 points
A provider should leave the business better documented.
Score:
- asset, user and vendor registers — 2 points;
- network, cloud and backup documentation — 2 points;
- ticket and SLA reporting — 2 points;
- risk, lifecycle and improvement reporting — 2 points;
- customer ownership and export of documentation — 2 points.
Ask to see an anonymised sample monthly report. A list of ticket numbers is not enough.
Category 8: transition and exit — 5 points
Score whether the proposal includes:
- discovery and onboarding plan;
- credential and documentation handover;
- monitoring and tool deployment;
- initial risk review;
- exit support and removal of provider access.
A strong provider should not avoid discussing the end of the relationship.
Category 9: commercial clarity — 5 points
Evaluate whether the commercial model clearly states:
- monthly recurring charge;
- included users, devices, sites or hours;
- onsite allowance;
- tool and license charges;
- after-hours and project rates;
- annual increases;
- contract term and notice;
- assumptions that can change price.
Do not give the lowest bidder five points automatically. Score clarity and total expected cost.
How to use the 100-point scorecard
| Category | Weight |
|---|---|
| Service-scope fit | 20 |
| Service desk and SLA | 15 |
| Onsite and local delivery | 10 |
| Technical breadth | 10 |
| Security of the service | 15 |
| Backup and continuity | 10 |
| Documentation and reporting | 10 |
| Transition and exit | 5 |
| Commercial clarity | 5 |
| Total | 100 |
Use at least two evaluators from different functions. Operations may notice service gaps that finance misses, while finance may identify unclear charges or control risks.
Normalise proposals before assigning scores
Before the evaluation meeting, create a comparison sheet that removes packaging differences. Record the included users, devices, sites, onsite hours, monitoring tools, security products, backup licenses, storage, after-hours coverage and project rates for every bidder. Mark each item as included, excluded, optional or assumed.
Where one provider has bundled a product and another expects the customer to retain the existing tool, compare the full annual cost and responsibility—not only the recurring service fee. Ask bidders to confirm unclear assumptions in writing. The completed clarification should become part of the evaluated proposal and, for the selected provider, part of the contract schedule.
This normalisation step prevents a comprehensive proposal from appearing expensive simply because another bidder left required services outside the base price.
Apply minimum pass conditions
A high total score should not compensate for a critical weakness. Set mandatory conditions such as:
- MFA and named technician access;
- customer ownership of tenants, domains and documentation;
- clear incident escalation;
- defined backup responsibilities;
- acceptable contract exit terms;
- evidence of local or reliable onsite coverage;
- appropriate confidentiality and data-handling commitments.
A provider that fails a mandatory control should not win merely through strong pricing or presentation.
Run a scenario-based comparison
Ask each finalist to explain how it would handle the same situations:
- Microsoft 365 access fails for many users.
- The main office internet link is down.
- A senior employee reports a suspected phishing compromise.
- A new employee starts tomorrow and hardware is not ready.
- A backup job has failed for three days.
- A branch firewall is out of warranty and stops working.
- A major application vendor blames the local network.
- The customer decides to move to another provider.
Score the clarity of ownership, communication, technical reasoning and evidence.
Check references intelligently
Ask references about operating behaviour, not whether they are “happy.”
Useful questions include:
- How does the provider behave during a serious incident?
- Does it communicate before being chased?
- Are recurring issues investigated?
- Is documentation current?
- Are project estimates and extra charges predictable?
- Has staff turnover affected service?
- How well does it coordinate other vendors?
- Would the customer renew under the same terms?
Choose references with similar size, locations and technology needs.
Avoid common scoring mistakes
Giving all providers similar marks
Scores should be evidence-based. If the proposal is unclear, award fewer points and request clarification.
Scoring features rather than outcomes
A provider may include many tools but still lack clear response and ownership.
Letting price dominate
Price matters, but low cost can hide exclusions, limited onsite support or weak security.
Ignoring transition cost
Onboarding, cleanup, replacement tools and project work may add significant first-year cost.
Failing to verify the delivery team
Meet the service manager or lead engineer, not only the salesperson.
Make the final decision defensible
Keep the completed scorecards, proposal clarifications, reference notes and decision summary. Record:
- selected provider and score;
- mandatory conditions;
- commercial assumptions;
- open risks;
- contract changes;
- transition actions;
- success measures for the first ninety days.
This creates a useful baseline for the first service review and contract renewal.
Frequently asked questions
How many providers should a Dubai SME compare?
Two or three serious providers are usually enough for detailed comparison once the service baseline is clear.
Should certifications receive points?
They can support the technical or security score, but operational evidence and actual service design should carry more weight.
What if one provider is strong technically but weak onsite?
Score the gap honestly and decide whether a reliable local partner or revised coverage can address it contractually.
Should price be more than five percent?
Management can change the weighting, but commercial cost should not overwhelm service, security and continuity requirements.
When should due diligence happen?
Use the scorecard to shortlist providers, then complete deeper due diligence on the preferred option before signing.
A scorecard cannot replace judgement, but it prevents vague promises and low prices from hiding important differences. Businesses comparing broader service desk, onsite support, Microsoft 365, infrastructure, security and recovery coverage can review managed IT services for Dubai SMEs.