An IT Support RFP Template for UAE SMEs

May 06, 2026

An IT Support RFP Template for UAE SMEs

An IT support request for proposal should do more than ask providers for a company profile and monthly price. If the requirements are vague, every bidder will make different assumptions. One provider may include onsite visits, another may price them separately. One may supply monitoring and backup tools, while another assumes the customer already owns them. The proposals will look complete but remain impossible to compare.

A good RFP creates one common description of the business, one service baseline and one response structure. It does not need to be a hundred pages. It needs to be specific enough for providers to price responsibly and for management to compare the same obligations.

The sections below can be adapted by UAE SMEs, branch networks and growing companies procuring IT support, IT AMC or managed services.

1. Introduce the organisation and procurement objective

Provide a short description of:

  • business activity;
  • legal entities;
  • office, branch, warehouse or retail locations;
  • approximate number of users;
  • working hours and critical periods;
  • current support arrangement;
  • reason for the RFP;
  • expected contract start;
  • desired contract term.

Example objective:

The organisation seeks one accountable IT support provider to operate the service desk, coordinate onsite support, administer Microsoft 365, support network and endpoint infrastructure, monitor agreed systems, manage vendors and provide service reporting across UAE locations.

2. Provide an environment baseline

Include the best available inventory. Providers can validate it during discovery, but they need enough information to estimate service.

AreaInformation to provide
UsersTotal, locations, remote users, executives and contractors.
DevicesLaptops, desktops, mobiles, printers, meeting rooms and shared devices.
CloudMicrosoft 365, Google Workspace, Azure, AWS and SaaS applications.
InfrastructureServers, storage, virtualization, firewalls, switches and Wi-Fi.
ConnectivityInternet providers, links, VPNs and backup connections.
ApplicationsERP, CRM, finance, HR, industry and customer-facing systems.
BackupPlatforms, protected workloads, retention and known gaps.
VendorsTelecom, hardware, software, cloud and specialist support partners.

State whether the information is verified or estimated.

3. Define the required service desk

Ask providers to describe:

  • service hours and days;
  • ticket channels;
  • telephone support;
  • remote-support method;
  • priority model;
  • response and update targets;
  • technical and management escalation;
  • major-incident communication;
  • customer satisfaction and closure process;
  • after-hours options.

Request sample SLA reports and an explanation of how clocks pause for customer or vendor dependencies.

4. Specify user and endpoint support

Required scope may include:

  • operating-system and standard application support;
  • email, Teams, OneDrive and SharePoint assistance;
  • password and access issues;
  • printer and office-device support;
  • device build and replacement;
  • endpoint protection and patch oversight;
  • new-user onboarding;
  • employee offboarding;
  • asset and warranty records;
  • remote-user support.

Ask bidders to identify unsupported software, personal devices and excluded activities.

5. Define onsite support requirements

State:

  • locations requiring onsite attendance;
  • scheduled visit expectations;
  • incident-based attendance;
  • target response for critical onsite needs;
  • site access, parking or security requirements;
  • after-hours or weekend work;
  • warehouse, retail or industrial conditions;
  • travel charges and included allowance.

Ask whether onsite resources are employees or subcontractors.

6. Include Microsoft 365 and identity administration

Possible requirements include:

  • user, group and license administration;
  • mailboxes and shared mailboxes;
  • Teams, SharePoint and OneDrive support;
  • MFA registration;
  • administrator-role control;
  • joiner, mover and leaver activities;
  • external sharing and guest support;
  • mail flow and security coordination;
  • service health and vendor escalation;
  • basic usage and risk reporting.

Ask the provider to explain how privileged access is secured and reviewed.

7. Define network and infrastructure support

List the expected responsibilities for:

  • firewalls, switches and Wi-Fi;
  • internet and VPN troubleshooting;
  • server and storage monitoring;
  • virtualization;
  • capacity and lifecycle review;
  • configuration backup;
  • patch and firmware coordination;
  • vendor and warranty escalation;
  • branch setup and change support.

Separate daily support from major upgrade, relocation or implementation projects.

8. State cybersecurity expectations

The RFP should distinguish routine security operations from specialist services.

Ask providers to respond to:

  • technician MFA and named accounts;
  • remote-support controls;
  • endpoint-security monitoring;
  • patch and vulnerability coordination;
  • email and identity-security support;
  • security-alert triage;
  • incident escalation;
  • customer-data handling;
  • subcontractor access;
  • breach notification;
  • security reporting.

CISA’s managed-service-provider advisory recommends transparent security discussions between providers and customers, particularly around privileged access and responsibilities. Its MSP security guidance can be referenced in the RFP.

9. Define backup and recovery scope

Ask bidders to identify:

  • protected workloads;
  • backup frequency and retention;
  • storage and copy design;
  • monitoring and failed-job response;
  • restore testing;
  • RPO and RTO responsibilities;
  • recovery documentation;
  • cyber-recovery or isolated recovery options;
  • license and storage charges;
  • customer validation required.

Require sample restore-test evidence, not only backup success reporting.

10. Include vendor management

State which third parties the provider must coordinate:

  • internet and telecom providers;
  • Microsoft or cloud vendors;
  • ERP and application vendors;
  • hardware warranties;
  • security and backup vendors;
  • building or cabling contractors.

Ask how cases, escalations and dependencies are tracked.

11. Define monitoring and proactive maintenance

Request details of:

  • systems monitored;
  • tools used;
  • alert ownership;
  • threshold and maintenance handling;
  • preventive checks;
  • capacity and lifecycle reporting;
  • certificate and license expiry monitoring;
  • service-health monitoring;
  • reporting and improvement actions.

Clarify whether tool costs are included and who owns the data and configuration.

12. Separate standard changes and projects

Ask providers to list included standard changes, such as:

  • new user and access changes;
  • mailbox and group administration;
  • standard software deployment;
  • minor firewall or network changes;
  • device setup;
  • approved policy changes.

Request rates and estimation method for projects such as office moves, migrations, new branches, server replacement and major security improvements.

13. Require documentation and reporting

Expected deliverables may include:

  • asset and user register;
  • network and system documentation;
  • administrator and service-account records;
  • vendor and contract register;
  • backup and recovery documentation;
  • monthly SLA report;
  • critical-incident reports;
  • risk and improvement register;
  • lifecycle and budget recommendations;
  • service-review minutes.

State that customer documentation must be exportable and returned at contract end.

14. Request a transition-in plan

Ask bidders to propose:

  • discovery schedule;
  • credential and documentation handover;
  • asset and user validation;
  • monitoring deployment;
  • open-ticket migration;
  • initial backup and security review;
  • vendor contact collection;
  • user communication;
  • service acceptance criteria;
  • first ninety-day improvement plan.

Require named customer and provider owners.

15. Include exit and continuity obligations

The provider should describe:

  • notice and transition support;
  • return of data, credentials and documentation;
  • removal of accounts and tools;
  • transfer of licenses and vendor portals;
  • export of ticket history;
  • support to the incoming provider;
  • data deletion confirmation;
  • business continuity if the provider experiences disruption.

The customer should retain ownership of its tenants, domains and primary accounts.

16. Ask for a structured commercial response

Require bidders to separate:

  • monthly managed-service fee;
  • included users, devices, locations or hours;
  • onsite allowance;
  • monitoring and security tools;
  • backup license and storage;
  • after-hours rates;
  • project rates;
  • transition charges;
  • annual increases;
  • contract term and termination;
  • assumptions and exclusions.

This prevents low base pricing from hiding required extras.

17. Request company and delivery information

Ask for:

  • company history and ownership;
  • UAE presence and service locations;
  • delivery-team structure;
  • employee and subcontractor model;
  • relevant skills and certifications;
  • insurance;
  • customer references;
  • business-continuity arrangements;
  • security and privacy controls;
  • escalation leadership.

References should match the required service rather than only industry name.

18. Provide an evaluation method

Tell bidders how responses will be evaluated. A sample weighting is:

CategoryWeight
Service scope and operating fit25%
SLA, onsite delivery and escalation15%
Technical capability15%
Security, backup and continuity20%
Transition, documentation and reporting10%
Commercial value and clarity15%

State any mandatory pass conditions.

19. Use a fair clarification process

Set one deadline for bidder questions. Share material answers with all participants so every provider prices from the same information.

After submission, request clarification rather than allowing providers to rewrite the entire proposal. Keep an audit trail of assumptions and negotiated changes.

20. Include scenario questions

Ask bidders to explain how they would handle:

  1. company-wide email access failure;
  2. internet outage at the main office;
  3. suspected executive-account compromise;
  4. urgent onboarding without available hardware;
  5. backup failure affecting a critical server;
  6. recurring Wi-Fi complaints;
  7. an application vendor blaming infrastructure;
  8. office relocation within sixty days;
  9. contract termination and provider handover.

Scenario responses reveal operating maturity better than generic service descriptions.

RFP response checklist

  1. Company and delivery profile.
  2. Understanding of the environment.
  3. Detailed service scope.
  4. SLA and support model.
  5. Onsite coverage.
  6. Microsoft 365 and infrastructure support.
  7. Security and privileged-access controls.
  8. Backup and recovery.
  9. Monitoring and maintenance.
  10. Vendor management.
  11. Transition and documentation.
  12. Exit and continuity.
  13. Commercial response.
  14. Assumptions and exclusions.
  15. References and scenario responses.

Frequently asked questions

How long should an IT support RFP be?

It should be long enough to define the environment and responsibilities, but structured enough for providers to answer consistently. Clarity matters more than page count.

Should pricing be requested per user or as a fixed monthly fee?

Request the provider’s recommended model and require all assumptions, included volumes and additional rates to be clear.

Should cybersecurity be a separate RFP?

Specialist security services may need separate scope, but the IT support RFP must still define provider access, routine controls and incident escalation.

How many providers should receive the RFP?

A focused shortlist of capable providers usually produces better evaluation than sending the RFP widely without qualification.

Should the current provider participate?

It can, provided every bidder receives the same information and the evaluation is evidence-based.

A strong RFP creates comparable proposals and reduces contract disputes because responsibilities are clear before the service starts. Organisations seeking a regional managed model across UAE and India can review managed IT services for multi-location businesses.