SOC / MDR RFP template.
An RFP that returns apples-to-apples pricing. The point of this document is to keep ingest, 24x7 uplift, IR retainer hours, and the compliance overlay out of the headline number, where they ordinarily hide.
A defensible MDR RFP has six sections: environment, services in scope, commercial line items, SLA matrix, exit terms, and scoring. The commercial section is the only one most templates get wrong; it must force vendors to quote base service, ingest, 24x7 uplift, compliance uplift, IR retainer, onboarding amortised, and off-boarding as separate lines.
Section 1. Environment
State, in vendor-neutral units: endpoints, log sources, log volume in GB/day, identity provider (Entra ID, Okta, Ping), cloud accounts and regions, compliance overlay (SOC 2, HIPAA, PCI, CMMC L2, FedRAMP, NIS2, DORA), and any BYO-SIEM constraint.
Section 2. Services in scope
Tier (Tier-1, Tier-1+2, Tier-1+2+3), coverage hours (business hours, 24x7), response authority delegated (notify-only, recommend, isolate, evict), threat hunting (none, scheduled, continuous), IR retainer hours per year, reporting cadence.
Section 3. Commercial line items (the pricing-forcing section)
Require the vendor to quote, as separate lines:
- Base service ($ / endpoint / month or $ / unit / month).
- Ingest charges (per GB / day; specify cap and overage rate).
- 24x7 coverage uplift (state as a multiplier over business hours).
- Compliance overlay uplift (per framework; state what changes operationally).
- IR retainer (hourly rate, hours included, hours overage rate).
- Onboarding (one-time fee, amortised /mo for the sake of comparison).
- Contract off-boarding (data-export fee, transition support, retention).
- Annual price escalation cap (state as % CPI or absolute).
Section 4. SLA matrix
Cross-reference /annex/sla-matrix. Require MTTD, MTTA, MTTR targets with service-credit triggers and a breach warranty trigger if the vendor offers one.
Section 5. Exit terms
Data export format, retention window after termination, off-boarding fee cap, contract assignability on merger or acquisition, and right to audit.
Section 6. Scoring
Weight commercial 40, technical 40, references 10, contractual 10. Score commercial on the normalised $/endpoint/mo (run the response through the RFP normaliser), not on the headline number.
Sources: NIST SP 800-161r1 (Cybersecurity Supply Chain Risk Management); CISA Cybersecurity Procurement Language; SANS SOC Survey.