RFP technology: the UK rules a technology bid is scored against
RFP technology means two different things, and almost every page on the subject silently picks one. It is either software for running RFPs, or an RFP for technology — an IT buyer asking suppliers to bid.
This page is the second one, for UK public sector work, because that is the half with law behind it: two sections of the Procurement Act 2023, two mandatory Cabinet Office notices, two GDS standards and six named buying agreements. The first meaning gets an honest section of its own further down, including the figures we will not repeat.
RFP technology: the two things the phrase means
Read it one way and it is a product category. Read it the other and it is a procurement. They share three words and almost nothing else.
Reading one — technology for running RFPs. Proposal software: a content library of your past answers, a workflow for assigning questions to subject-matter experts, and increasingly a model that drafts a first pass. The buyer is a proposal or bid team. The question is which product to buy.
Reading two — an RFP for technology. A public body wants a system, a service or a team of specialists, and publishes a requirement. The reader is a supplier deciding whether to bid and how. The question is what the rules are.
This page is reading two, and specifically the UK public sector version of it, for a reason worth stating rather than hiding: reading two has primary sources and reading one does not. A statute defines how a technology bid must be evaluated. Nothing defines the software category — no regulator scopes it, no department publishes statistics on it, and every quantified claim about it that we could find traces back to a company selling into it.
So the split below is deliberate. Everything from here to what government spends is reading two, sourced to legislation, Cabinet Office notices, the Government Commercial Agency, GDS and the National Audit Office. Then one section handles reading one properly — what the category is, who defines it, and which of its widely-repeated numbers we will not put on this page.
Technology for running RFPs
A software category. Buyer: a bid or proposal team. Governed by nothing. Assessed by feature comparison. Covered on RFP tools and best RFP software.
An RFP for technology
A procurement. Reader: a supplier. Governed by the Procurement Act 2023, PPN 002, PPN 014, the Technology Code of Practice and the framework you are on. Assessed against published criteria you can read in advance.
What a technology bid is actually scored on
Not the pack's tone, not your logo, not how many case studies you can fit. Section 23 of the Procurement Act 2023 tells the buyer what its award criteria may be and what it has to publish about them — and it is short enough to read before your next bid.
Four tests, all four of which must hold. Award criteria must relate to the subject-matter of the contract, be sufficiently clear, measurable and specific, not break the technical-specification rules in section 56, and be a proportionate means of assessing tenders, having regard to the nature, complexity and cost of the contract. [3]
Then a publication duty that most suppliers do not use. The authority must describe how tenders will be assessed, specify whether failure to meet a criterion would disqualify a tender, and — where there is more than one criterion — indicate their relative importance by weighting each as a percentage, ranking them in order, or describing it another way. [3] That is a published document. Read it before you write anything.
Two more things sit in section 19 and are worth knowing before you price. The award goes to the most advantageous tender — the statute's own words, quoted in full below. And an authority may disregard any tender that offers a price that the contracting authority considers to be abnormally low, but not silently: before it does, it must notify the supplier and give the supplier reasonable opportunity to demonstrate that it will be able to perform the contract for the price offered. [2] If you are undercut by a number that cannot be delivered, that duty exists. If you are the one being questioned, that notification is your right of reply, not a rejection.
Nothing here is a recommendation and nothing is computed from our data. The three sliders are your own assumption about a split; the output states which duties in section 23 and which floor in PPN 002 that split engages, quoting them. A lawful split is a very wide range — this tool cannot tell you a bid will win, only which published rules your reading of the pack has to satisfy. Sources: Procurement Act 2023 s.23 [3], PPN 002 [9].
Five things most RFP technology guidance still gets wrong
Each of these is load-bearing — get it wrong in a bid and you are quoting a rule that no longer exists, to an evaluator who knows it. Each correction resolves to a named source you can open in one click.
How UK government actually buys technology
Six named agreements and one open procedure. Which one your requirement runs through decides who you compete against, how long you get, and in several cases whether you are eligible at all.
The agreements are not interchangeable and the differences are not subtle. G-Cloud is a catalogue: buyers search published services and award without a competition in the usual sense, and it is by far the largest — G-Cloud 14 gives access to over 46,000 services and over 4,000 suppliers. [13] DOS7 buys outcomes and people, in four lots, and Lot 3 buys named individuals. [15] Technology Services 4 buys managed services and transformation programmes, and has been updated to include artificial intelligence (AI) and automation as ancillary services. [17] Technology Products and Associated Services 2 buys hardware and software, and its Lot 4 is closed to anyone without Facility Security Clearance. [18]
And an honest caveat before the instrument: a framework is not a guarantee of anything. It is permission to be asked. Being on G-Cloud 14 alongside four thousand other suppliers is not a pipeline; it is a prerequisite for one.
Every output is one named agreement with its RM number and its own stated dates, read off the Government Commercial Agency's agreement pages on 15 August 2026 and quoted beneath the name. This is a signpost, not advice: a real requirement can be run through more than one route, and the buyer chooses, not the supplier. Sources [13] to [18].
The chain that turns a standard into a scored question
Three documents nobody sends you, which between them decide what is in the pack you eventually get. Following the chain is how you know what a buyer will ask before it asks.
Technology RFP template UK: the requirements that actually decide it
Functional requirements are where a pack spends most of its words and almost none of its marks. The non-functional half — security, resilience, data protection, exit — is where a technically capable supplier gets scored down, because it answered the feature question well and the assurance question generically.
A UK public sector technology pack tends to separate into four blocks, and only the first is about what the software does. The other three are regulated-domain questions with their own evidence expectations, and three of them show up in this cluster's own search data as separate template searches. They are treated separately below for that reason.
Compliance software RFP template
A compliance pack is asking one question in several forms: what happens when you are wrong. Expect requirements on audit trails that cannot be edited, on retention and legal hold, on who can approve a change and how that approval is evidenced, and on how a regulator's request for records is answered. The scoring weight tends to sit on evidence rather than capability — you are asked to show a completed audit, not to assert you support auditing.
The buyer-side driver is worth naming: under section 23 the criteria must be sufficiently clear, measurable and specific [3], and "supports compliance" is none of those. So a well-drafted compliance pack turns each claim into something measurable, and your answer has to be measurable back.
Risk management software RFP template
Risk packs are the ones most likely to carry a resilience and exit section with real weight. Expect questions on recovery point and recovery time objectives, on where the service degrades gracefully and where it fails hard, on concentration risk in your own supply chain, and on what happens at the end of the contract — data extraction format, transition assistance, and how long it takes.
The NAO's own framing of the problem is the buyer's: government has repeatedly found that moving from one cloud infrastructure provider to another can be challenging and disruptive, and that it is overly simplistic to treat large providers as if they are offering generic services that departments can easily switch between at will. [23] A supplier who answers the exit question concretely is answering a fear the buyer has been told to have.
Data privacy software RFP template
Data privacy is where the pack stops being about your product and starts being about your organisation. Expect data flow mapping, processing locations, sub-processor lists, the lawful basis you rely on, retention schedules, and the specific mechanics of a data subject access request against your system rather than in general.
This is also the block where PPN 014 bites hardest, because the trigger is the data itself rather than the contract value — see the gates section, which computes which certificates your case engages. And it is where a supplier can genuinely differentiate: most answers describe a policy, and the higher-scoring ones describe a mechanism.
Which certificates a technology bid actually needs
Cyber Essentials is not a general requirement and it is not optional either. PPN 014 makes it conditional, and the conditions are about the data, not the contract.
PPN 014 was published on 17 February 2025 and took effect on 24 February 2025, replacing PPN 09/14 and PPN 09/23. It applies to all central government departments, their executive agencies and non-departmental public bodies, and NHS bodies, and its operative sentence is a timing rule as much as a requirement: Evidence of holding a Cyber Essentials certificate (or equivalent) is essential at the point when data is to be passed to the supplier. [10]
That "at the point when data is to be passed" is the part suppliers get wrong in both directions. It is not a condition of bidding in every case, so an uncertified supplier is not automatically excluded from tendering. But it is a hard gate before delivery, and certification takes real time, so discovering it at contract award is discovering it too late.
Every row that lights carries the sentence from the notice that put it there. This reads PPN 014's own stated triggers and PPN 002's own stated scope; it does not model any buyer's actual policy, and a buyer may ask for more than the minimum. Where a row says a requirement is not engaged, that means the published notice does not engage it — not that the pack in front of you will not ask. Sources: PPN 014 [10], PPN 002 [9], TCoP [21].
Two adjacent points, both from this page's own sources. ISO 27001 is not mandated by any PPN — it appears because buyers ask for it, which is a different kind of requirement and one you can sometimes meet with an equivalent. And the phrase or equivalent in PPN 014 is load-bearing: it is what lets an ISO 27001-certified supplier make a case, and it is why the answer to "do we need Cyber Essentials" is sometimes "no, but you need to show why not, in writing, early". Cyber Essentials in a tender has the certification route itself.
IT support RFP template UK: what an IT support pack asks for
A managed IT support requirement is the most common technology procurement a UK public body runs, and it is scored on things that are not in the product description at all.
Three blocks do most of the work. Service levels: response and resolution targets by priority, how priority is agreed, what happens when a target is missed, and whether service credits are a remedy or a cap on remedies. Transition: how the incumbent's estate becomes yours without an outage, who owns the risk during the overlap, and what the buyer has to do. The estate itself: how many endpoints, how many sites, what is out of support, what is on premises and what is not.
The commercial mechanics matter more here than in most technology buys, because the contract runs for years and the estate changes underneath it. If it is bought through a framework the ceiling is already set — G-Cloud 14 call-offs, for instance, initially last for up to 36 months (3 years) with one extension of a maximum of 12 months, giving a maximum of 48 months (4 years). [13] Price a four-year estate, not a snapshot.
And expect the assurance blocks from the section above in full, because an IT support supplier holds administrative access to everything. That is precisely the circumstance PPN 014 describes when it names ICT systems/services designed to store or process data at OFFICIAL level as a trigger. [10]
Software RFP template: what belongs in it, and where to get one
A software RFP template is a structure, not a document you can send unedited. What makes one good is that every section maps to something the buyer will actually score.
The structure that survives contact with a UK public sector evaluation has six parts: the outcome the buyer wants stated as an outcome rather than a feature list; functional requirements separated from non-functional ones; the assurance block covering security, data protection and resilience; commercial terms including the exit; the evaluation model with published weightings, because section 23 requires the buyer to indicate relative importance [3]; and the timetable, which under an open procedure is not the buyer's free choice — section 54 sets minimum tendering periods. [6]
If you are on the supplier side, the useful move is to read the template backwards: find the weightings first, then read only the questions that carry them, then decide whether you can win before you write a word. The tender process has the sequence in full.
Software RFP template
The template itself, section by section, with examples of how each part is worded.
RFP software template
The structure for an RFP aimed at buying software, with the requirements blocks laid out.
RFP for software development template
The build case: statements of work, acceptance, IP and the phases a development RFP has to name.
Sample RFP for software
A worked example rather than a blank structure, for checking your own draft against.
RFP for software development
The wider subject — scoping, estimating and evaluating a development procurement.
Procurement Act 2023
The statute behind every rule on this page: what changed on 24 February 2025 and what it means for suppliers.
Those five template pages are the spokes of this cluster and each one owns its own long-tail question. This page owns the head term and the rules; it deliberately does not reproduce their content, because two pages competing for one query is how a cluster loses both.
What government spends on technology, and who counts it
Every figure below is from one National Audit Office report, published 16 January 2025, and each one is quoted with what it actually measures — because these numbers get repeated without their scope and then mean something different.
One more, and it is the one most often quoted without its scope: three very large multinational providers now have a combined global market share of over 60% of cloud services provision. [23] That is a global cloud market share in 2024, not a share of UK government spend. It is quoted here because it explains the concentration questions that now appear in packs, not because it measures anything about the UK public sector.
The other meaning: RFP technology as a software category
If you came here looking for software to run your RFP responses, this section is for you — and it is deliberately shorter and deliberately number-free. Here is the category, who defines it, and which of its widely-repeated figures this page will not repeat.
What the category is. Proposal and RFP response software does four separable jobs: keeping a searchable library of your past answers, routing questions to the people who can answer them, drafting a first pass from that library, and tracking what was submitted and what happened. Most products are strong at one or two. Very few are strong at all four, and the honest first question is which of the four is currently failing for you.
Who defines it. Nobody neutral. There is no statute, no regulator, no standards body and no government statistical series for this category. The four most substantial pages we found on this exact term are all published by vendors selling into it: Flowcase ("12 Features To Look For When Evaluating RFP Technology", 23 July 2025), SparrowGenie ("RFP Technology in 2026: AI, Automation, Features", 18 March 2026), Arphie ("RFP in IT: 2026 Data on What Wins Technology Proposals", 5 March 2026) and DeepStream ("RFP Templates for Writing and Automating Technology RFPs", undated). They are legitimate reading; they are not neutral evidence, and neither are we.
That is not a criticism we get to make cheaply, because we sell in this category too. So the rule is applied to ourselves first: this page publishes no market size, no win-rate uplift, no time-saving multiple and no adoption percentage for our own product either. Where an independent measurement exists we will cite it and say whose it is. Where one does not, the sentence gets written without the number.
For the product comparison itself, RFP tools is the page that does that job — what each of the four capabilities actually is, and how to tell which one you need. AI tool for bids and tenders weighs eleven UK products against eleven criteria you set yourself, including the criteria on which we lose.
Read the weightings before you read the requirements, and check the framework is still alive before you cite it.
What to take away
See which UK technology tenders you are actually eligible for.
Search live technology notices freeWe ingest both UK registers — Find a Tender and Contracts Finder — so below-threshold notices are searchable alongside above-threshold ones, and we extract the requirements out of a pack with the sentence each one was read from. No card to start. Or search live tenders first without an account, and see what buyers are actually demanding across the corpus.
The framework register
Six agreements, with RM numbers and the dates each one publishes for itself. All read off the Government Commercial Agency's own agreement pages on 15 August 2026 — the same day this page was written, because these dates move.
Framework dates are the single most perishable fact on this page. Every one above was read on 15 August 2026 from the agreement's own page, and each entry links to the page it came from so you can check it rather than trust us. If you find one out of date, the source link is the correction.
Questions people actually ask about RFP technology
These are real search strings from this cluster's own query data, reproduced as typed.
what is the best rfp template for it software procurement?
There is no single best one, and any page telling you otherwise is selling a download. What a good template does is force six things into the document: the outcome stated as an outcome, functional requirements kept separate from non-functional ones, an assurance block covering security and data protection, commercial terms including exit, an evaluation model with published weightings, and a timetable. For UK public sector work the last two are not stylistic choices — section 23 of the Procurement Act 2023 requires the buyer to indicate the relative importance of its criteria, and section 54 sets minimum tendering periods. Our structure pages are software RFP template and RFP software template, and sample RFP for software is a worked example rather than a blank.
rfp for software implementation
An implementation RFP differs from a software purchase RFP in one important way: most of the risk and most of the marks sit in transition rather than in the product. Expect the pack to weight migration approach, data cleansing, cutover and rollback, training, and the definition of "done" more heavily than feature coverage. Price the implementation as a phase with its own acceptance criteria, not as a percentage of licence value. RFP for software development covers the build-and-implement case in full.
sample rfp for software development
A worked example is more useful than a blank template because the hard part is not the headings, it is the level of specificity each section needs. A development RFP has to name the phases, the acceptance mechanism, who owns the intellectual property in what is built, and what happens to source code at the end — and for central government work, TCoP point 13 pulls in the Service Standard, whose point 12 is make new source code open. That single line changes the IP conversation before it starts. Sample RFP for software has the example; RFP for software development template has the structure.
rfp for software development pdf
Most published software development RFPs arrive as a PDF pack rather than a form, and that is worth planning for rather than complaining about. Extract the requirements into a working list before you write anything — one row per requirement, with the page and sentence it came from — because a PDF hides the structure that a scoring matrix depends on, and because you will need the traceability when a clarification answer changes one of them. That extraction is one of the four jobs proposal software does, and it is the job most teams still do by hand. The template page has the structure a good pack follows.
software rfps
In UK public sector work the label on the front matters far less than the procedure underneath it. "RFP" has no definition in the Procurement Act 2023 — the Act's vocabulary is tender notice, tender, open procedure and competitive flexible procedure — so what determines your deadlines, your right to an assessment summary and your right to challenge is the procedure the buyer is running, not the word on the cover. RFP tender works that distinction through in full.
it support rfp
Scored on three things the product description does not cover: service levels and what happens when they are missed, transition from the incumbent without an outage, and the assurance block — because an IT support supplier holds administrative access to everything. PPN 014 names ICT systems/services designed to store or process data at OFFICIAL level as a Cyber Essentials trigger, which most IT support contracts meet. If it is bought through G-Cloud 14 the commercial ceiling is already set: call-offs up to 36 months plus one extension of up to 12, so price a four-year estate.
data privacy software rfp
The block where the pack stops asking about your product and starts asking about your organisation: data flow mapping, processing locations, sub-processor lists, lawful basis, retention schedules, and how a subject access request is actually answered against your system. It is also where PPN 014 bites hardest, because its triggers are about the data rather than the contract value — personal information of citizens, personal information of government staff, and ICT systems processing data at OFFICIAL level. Most answers in this block describe a policy; the higher-scoring ones describe a mechanism.
does "rfp technology" mean software, or a procurement?
Both, and the ambiguity is real rather than a quirk of phrasing. It means proposal software (technology for running RFPs) and it means IT procurement (an RFP for technology). This page leads with the second because that is the reading with primary sources behind it — a statute, two mandatory Cabinet Office notices, two GDS standards and six named framework agreements. The first reading has none: no regulator scopes the category and no government publishes statistics on it. The section on the software category covers it honestly, including the market figures we decline to repeat and why.
is cyber essentials mandatory for a technology tender?
Conditionally, and the condition is about the data. PPN 014, effective 24 February 2025, applies to all central government departments, their executive agencies and non-departmental public bodies, and NHS bodies, and says evidence of holding a Cyber Essentials certificate (or equivalent) is essential at the point when data is to be passed to the supplier. So it is not always a condition of bidding, but where it is triggered it is a hard gate before delivery — and certification takes weeks, so contract award is too late to begin. The words "or equivalent" are what allow an ISO 27001-certified supplier to make a case, in writing, early.
which framework should a technology supplier be on?
It follows from what you sell, not from which is biggest. Cloud hosting, cloud software or cloud support goes on G-Cloud 14 (RM1557.14, to 28 October 2026). Outcomes, delivery partners, named specialists or user research goes on DOS7 (RM1043.9, to 29 July 2027). Managed services, service integration or a transformation programme goes on Technology Services 4 (RM6190, to 11 June 2028). Hardware and software products go on Technology Products and Associated Services 2 (RM6098, to 9 October 2027), whose Lot 4 requires Facility Security Clearance. And a framework is permission to be asked, not a pipeline — G-Cloud 14 alone carries over 4,000 suppliers.
The glossary
Sources
Every numbered mark on this page resolves here. Nothing below is a secondary summary of a primary source — each entry is the source itself.
- Procurement Act 2023 (c. 54), legislation.gov.uk. Individual sections cited below are each at
/ukpga/2023/54/section/<n>. Accessed 15 August 2026. - Procurement Act 2023, s.19 — Award of public contracts following a competitive tendering procedure. s.19(1): "A contracting authority may award a public contract to the supplier that submits the most advantageous tender in a competitive tendering procedure." s.19(3)(c) permits an authority to disregard an abnormally low tender; s.19(4) requires prior notification and a reasonable opportunity to demonstrate performance at that price.
- Procurement Act 2023, s.23 — Award criteria. s.23(2) the four tests; s.23(3) the assessment methodology and the three permitted ways of indicating relative importance; s.23(5)(c) the qualifications, experience, ability, management or organisation of staff.
- Procurement Act 2023, s.20 — Competitive tendering procedures. s.20(2) defines the open procedure and the competitive flexible procedure — the only two under the Act.
- Procurement Act 2023, s.56 — Technical specifications, referred to by s.23(2)(c).
- Procurement Act 2023, s.54 — Time limits. The tendering-period table at s.54(4).
- Procurement Act 2023, s.51 — Standstill periods on the award of contracts.
- Procurement Act 2023, s.50 — Contract award notices and assessment summaries.
- Cabinet Office, PPN 002: Taking account of social value in the award of central government contracts. Updated 5 March 2025; applies to all central government departments, executive agencies and non-departmental public bodies, for procurements commenced under the Procurement Act 2023 on or after 1 October 2025. "A minimum 10% weighting (or an equivalent measurement) of the total score, for social value." Supersedes PPN 06/20 for in-scope procurements.
- Cabinet Office, PPN 014: Cyber Essentials scheme. Published 17 February 2025, effective 24 February 2025, replacing PPN 09/14 and PPN 09/23. "Evidence of holding a Cyber Essentials certificate (or equivalent) is essential at the point when data is to be passed to the supplier."
- Cabinet Office, PPN 019: Requirements to publish on Contracts Finder — "any new below threshold opportunities must be advertised on Find a Tender in accordance with the Procurement Act."
- Government Commercial Agency, Crown Commercial Service (CCS). "On 1 April 2026, CCS was combined with several Cabinet Office Central Commercial Teams to form Government Commercial Agency (GCA), an enhanced executive agency." Also: "the legality of any CCS framework or agreement will not change" and "existing contracts and call-offs remain valid". Accessed 15 August 2026.
- Government Commercial Agency, G-Cloud 14 (RM1557.14). Start 29/10/2024, end 28/10/2026. Lots 1–3 cloud hosting, cloud software, cloud support. "over 46,000 services and over 4,000 suppliers". Call-off up to 36 months plus one extension of up to 12 months. Accessed 15 August 2026.
- Government Commercial Agency, G-Cloud 15 (RM1557.15). Find a Tender notice published 23 October 2025; Framework Award given as estimated 6 August 2026; no framework start or end date published. Checked 15 August 2026.
- Government Commercial Agency, Digital Outcomes and Specialists 7 (RM1043.9). Start 30/01/2026, end 29/07/2027. Four lots. Buyer eligibility as quoted. Accessed 15 August 2026.
- Government Commercial Agency, Digital Specialists and Programmes (RM6263). Start 08/03/2022, end 30/05/2026; marked expired, reference only. "The Digital Outcomes and Specialists 7 agreement is now live which has replaced this agreement. For any new tenders please use DOS7."
- Government Commercial Agency, Technology Services 4 (RM6190). Start 12/12/2025, end 11/06/2028. "has been updated to include artificial intelligence (AI) and automation as ancillary services". Accessed 15 August 2026.
- Government Commercial Agency, Technology Products & Associated Services 2 (RM6098). Start 10/10/2023, end 09/10/2027. Eight lots; Lot 4 Information Assured Technology restricted to suppliers with Facility Security Clearance and Developed Vetting cleared resources; Lot 7 Sustainability and Circular IT. Accessed 15 August 2026.
- GOV.UK, Buying and selling on the Digital Marketplace. "This guidance was withdrawn on 20 November 2025." The withdrawal notice directs readers to the G-Cloud agreement page. Originally published 27 June 2019.
- Digital, Data and Technology Profession and Cabinet Office, The Digital, Data and Technology Playbook. Published 28 March 2022, last updated 20 June 2023. "11 key policy reforms for how the government should assess, procure and deliver digital projects and programmes which all central government departments and their arms length bodies are expected to follow on a 'comply or explain' basis." No withdrawal or supersession notice as at 15 August 2026.
- Government Digital Service and Central Digital and Data Office, The Technology Code of Practice. Published 14 July 2021, last updated 7 July 2025. Thirteen points. "You must consider all points of the TCoP as part of the Cabinet Office spend control process."
- Government Digital Service, Service Standard. Fourteen points, quoted in full on the page. Point 6 have a multidisciplinary team; point 7 use agile ways of working; point 12 make new source code open; point 13 use and contribute to open standards, common components and patterns.
- National Audit Office, Government's approach to technology suppliers: addressing the challenges (PDF), Session 2024-25, HC 543, 16 January 2025. Key facts panel and paragraphs 1, 2, 10, 1.14, 2.21 and 3.18. Every figure quoted on this page is taken with its own scope wording.
- Cabinet Office, Transforming public procurement. "The Procurement Act 2023 came into force on 24 February 2025", following a written ministerial statement of 12 September 2024 moving go-live from 28 October 2024.
- Cabinet Office, Central Digital Platform factsheet, and Find a Tender: notice types.
Four vendor pages are named in the software category section — Flowcase, SparrowGenie, Arphie and DeepStream — and are deliberately not listed here or linked. They are competitors' marketing pages, they are correct sources for what the category says about itself, and they are not evidence. The figures they publish are quoted in that section only to say which ones this page will not repeat.
Corrections policy: where a figure on this page turns out to be wrong we append the correction and say what was believed before, rather than editing the mistake away. Framework dates are the most perishable facts here; each carries the page it was read from and the date it was read.