This field guide explains common content clients place in a private security request for proposals, including certificates of insurance, licensing, staffing posts, qualifications, reporting, and pricing. Requirements vary by service type and jurisdiction. Review current public-procurement guidance from the U.S. Small Business Administration and the General Services Administration, then confirm every legal, insurance, and licensing requirement locally before issuing or answering an RFP.
A security RFP is more than a request for an hourly rate. It is the client’s working description of risk, service expectations, accountability, and contract administration. A well-built document gives vendors enough information to price the work responsibly while allowing the client to compare qualified proposals.
Clients often use different terms for similar documents. A request for proposals invites a solution and price. A request for quotations may focus more narrowly on price and defined specifications. A statement of work describes required services, while post orders explain how officers should perform duties at a specific location. The terminology matters less than clarity. Vendors should be able to identify what is mandatory, what is preferred, and what must be confirmed during a site visit.
What should the RFP say about the client and the site?
Start with the contracting entity, site address, primary contact, and procurement calendar. If the work covers multiple buildings or locations, list each location and identify whether the same staffing model applies everywhere. Include the expected contract term, renewal options, transition period, and anticipated start date.
The RFP should describe the operating environment without disclosing sensitive information unnecessarily. Useful information may include building use, operating hours, visitor volume, access points, parking areas, loading zones, public-facing areas, and whether employees work overnight. If a site contains regulated, confidential, hazardous, or high-value materials, describe the security implication without publishing details that could create an avoidable vulnerability.
State whether vendors may inspect the site before submitting proposals. A mandatory site walk should include a date, attendance procedure, question process, and deadline for submitting clarification requests. If attendance is optional, say whether information from the walk will be shared with all bidders.
What services and security posts should be included?
Clients should identify each required security post by location, operating hours, and function. A post may be a lobby desk, vehicle gate, patrol route, control room, reception area, loading dock, event position, or roving assignment. The RFP should state whether a post is continuously staffed, scheduled only during certain hours, or activated when a defined condition occurs.
For each post, explain the expected duties. These may include access control, visitor processing, badge checks, alarm response, patrols, opening and closing procedures, incident notification, camera monitoring, key control, escort services, or emergency coordination. Avoid vague language such as “provide adequate protection” without describing the observable tasks that support that objective.
Include a post schedule or staffing matrix whenever possible. The matrix can show the number of officers by shift, day of week, and location. If staffing may change because of events, occupancy, construction, or seasonal activity, describe the notice period and approval process for changes.
How should post orders be handled?
Post orders should translate the RFP into practical instructions for officers. They may cover routine duties, prohibited conduct, escalation steps, radio procedures, required logs, emergency contacts, and supervisor checks. The client may attach draft post orders or require the selected contractor to prepare them for approval.
State who owns the final approval of post orders and how revisions will be controlled. A revision process should identify the approving authority, effective date, training requirement, and method for documenting that officers received the update. If the client expects the contractor to recommend changes after an incident or site review, include that expectation in the scope.
Post orders should not conflict with law, emergency instructions, collective bargaining obligations, or the authority of public responders. Clients should have counsel or qualified local professionals review language involving detention, searches, use of force, medical response, privacy, or access to restricted areas.
What licensing requirements belong in the RFP?
The RFP should require the contractor and assigned personnel to hold all licenses, registrations, permits, certifications, or approvals required for the work. The exact requirements depend on the jurisdiction, service category, armed or unarmed status, guard duties, private-investigation activity, alarm work, security technology, and other factors.
Do not assume that a license in one state, county, or municipality satisfies another jurisdiction’s rules. The RFP should identify the work location and instruct bidders to confirm applicable requirements with the relevant licensing authority. Clients can request license numbers, expiration dates, issuing jurisdictions, and a statement that the contractor will maintain good standing throughout the contract.
For assigned officers, request evidence of required training or credentials only to the extent relevant and legally permitted. The client may specify minimum experience, orientation, first-aid training, customer-service training, report-writing ability, or site-specific instruction. Requirements should be connected to the work rather than written as unnecessary barriers to competition.
What should the certificate of insurance require?
A certificate of insurance, commonly called a COI, gives the client evidence that specified coverage is in place. It is not a substitute for reviewing the policy, endorsements, exclusions, or renewal status. The RFP should identify the types of insurance and minimum limits the client reasonably expects, subject to review by the client’s broker, counsel, and risk manager.
Common categories may include commercial general liability, workers’ compensation as required by applicable law, employer’s liability, automobile liability for vehicles used in the work, and professional or errors-and-omissions coverage when the scope includes advisory, investigative, monitoring, or technology services. If firearms are involved, the client should obtain qualified advice about coverage specific to the exposure.
The RFP should state whether the client must be named as an additional insured, whether coverage must be primary and noncontributory, and whether waiver-of-subrogation language is required. These terms should be confirmed by the client’s insurance professional because availability and wording vary by carrier and risk.
Request a COI before work begins and after renewal. The client may also require notice of cancellation or material change when available under the policy and applicable practice. Vendors should not simply promise “full coverage.” They should identify the actual carrier, policy period, limits, and any requested endorsements, while protecting sensitive policy information appropriately.
What qualifications should the security company show?
Clients commonly request a company profile, years in business, relevant service experience, organizational structure, and information about the proposed contract manager. The strongest qualification requirements relate directly to the assignment. For example, a multi-site access-control program may justify experience coordinating supervisors, scheduling, reports, and client communications across several locations.
Ask for references from comparable clients when references are appropriate and legally permissible. A reference request can identify the service type, approximate contract period, number of posts, and contact role. Do not ask vendors to provide confidential client information or imply that a reference guarantees performance.
Clients may also request information about quality controls, supervisor coverage, employee screening practices, training records, complaint handling, and continuity planning. If the contractor uses subcontractors, the proposal should identify where they may be used and how the prime contractor will supervise them.
How should the RFP address conflicts of interest?
A conflict-of-interest section should require bidders to disclose actual, potential, or perceived conflicts that could affect independent performance. Examples may include ownership or management relationships with the client, a competitor, a tenant, a supplier, or a party involved in a related investigation. The definition should be practical and should explain when disclosure is required.
For public or regulated clients, the RFP may need additional ethics, procurement-integrity, gift, lobbying, confidentiality, or non-collusion certifications. Requirements should be reviewed against the client’s governing policies and applicable local rules. A general disclosure should not be presented as a substitute for any specific legal form required by the contracting authority.
Ask vendors to explain how a disclosed conflict will be managed. Possible controls include separating personnel, limiting access to information, using independent supervision, obtaining written consent, or declining a particular assignment. The client should reserve the right to determine whether a conflict is acceptable, while giving bidders a clear opportunity to raise questions before proposals are due.
What employee screening and training details belong in the proposal?
The RFP should describe minimum screening expectations without requesting information the client does not need. Depending on the assignment and local law, clients may address identity verification, legally permitted background checks, employment verification, driving records for vehicle duties, and confirmation of required credentials.
State who pays for screening and training, when screening must occur, and whether the client may reject an assigned officer for a documented, job-related reason. The process should respect privacy, fair-employment requirements, and any notice or consent obligations that apply in the location where the work is performed.
Training requirements may include site orientation, emergency procedures, customer interaction, report writing, radio use, access-control technology, fire and life-safety awareness, and de-escalation. If the client requires recurring training, specify the frequency or performance standard rather than leaving the requirement open-ended.
What reporting and documentation should the RFP require?
Security services are evaluated partly through records. The RFP should list required daily activity reports, incident reports, patrol logs, visitor records, key or badge logs, inspection checklists, staffing reports, and supervisor reviews. It should state whether reports must be electronic, the submission deadline, required fields, and who receives them.
Incident-reporting language should distinguish routine reporting from urgent notification. For urgent events, identify the expected notification sequence and required time frame, while recognizing that emergency services should be contacted when appropriate. The client should avoid requiring officers to delay emergency response in order to complete paperwork.
Address ownership, retention, access, confidentiality, and permitted use of records. If cameras, access systems, body-worn devices, or other technology are involved, clarify who owns the data, how it is protected, and how records may be produced for an investigation or legal request.
How should technology and equipment be specified?
Identify equipment the client will provide and equipment the contractor must supply. The list may include uniforms, radios, flashlights, mobile devices, vehicles, safety equipment, access-control credentials, patrol verification tools, or reporting software. State whether equipment must meet a particular technical standard or simply be suitable for the assigned duty.
For technology services, describe required functions rather than naming a brand unless compatibility makes a brand necessary. Include installation, configuration, maintenance, replacement, cybersecurity responsibilities, data access, user training, and end-of-contract transition. Vendors should disclose recurring charges separately from one-time costs.
What emergency and continuity expectations should be included?
A security RFP should explain how the contractor is expected to respond to foreseeable disruptions, such as severe weather, power loss, facility closure, labor shortages, system outages, or a sudden increase in visitors. The client may require an emergency contact list, escalation plan, relief staffing process, and business-continuity approach.
Do not promise a specific response time unless the contractor can reliably meet it and the client has defined how it will be measured. Instead, state the operational need, such as maintaining critical posts, notifying designated contacts, or providing a replacement officer when a scheduled employee is unavailable.
How should pricing and labor assumptions be requested?
Pricing forms should make proposals comparable. Ask vendors to show hourly rates by service category, regular and overtime assumptions, supervisor costs, one-time transition charges, equipment costs, technology fees, and approved reimbursable expenses. If the client expects a fixed monthly amount, require a schedule showing the staffing and assumptions behind that amount.
State how invoices will be verified, how disputed charges will be handled, and whether rates may change during renewal periods. Do not insert an arbitrary rate or fee into the RFP without a documented basis. Clients should obtain procurement, tax, labor, and legal advice where pricing rules are complex.
Small businesses may need clear instructions about required forms, representations, and submission procedures. The SBA provides general information for small businesses, while federal buyers and vendors can consult the GSA for government acquisition resources. These resources do not replace the solicitation’s specific instructions or local requirements.
How will proposals be evaluated?
Publish evaluation factors before proposals are submitted. Factors may include technical approach, relevant experience, staffing plan, licensing and compliance, quality controls, reporting, transition plan, price, and responsiveness to the scope. If the client assigns relative importance or points, the proposal instructions should explain the method clearly.
Price should not be the only consideration when service failure could create substantial operational or safety risk. At the same time, the client should avoid vague claims that quality will matter without explaining how quality will be assessed. Request enough evidence to support a fair comparison, then apply the stated criteria consistently.
What contract terms should the winning vendor expect?
The RFP should identify material contract terms, including performance standards, payment, indemnification, confidentiality, privacy, records, audits, subcontracting, termination, transition assistance, dispute procedures, and compliance obligations. If the client has a standard agreement, attach it or summarize provisions that may materially affect pricing.
Include a process for replacing personnel, changing posts, approving overtime, handling missed coverage, and correcting deficiencies. Service-level remedies should be proportionate and measurable. A vendor cannot price responsibly when the client reserves unlimited discretion to expand duties without a change-order process.
What questions should bidders ask before submitting?
Bidders should ask about unclear post coverage, site conditions, access procedures, expected report volume, equipment responsibility, training time, emergency staffing, contract assumptions, and the treatment of holidays or special events. Questions should be submitted through the stated channel and before the deadline.
The client should issue written answers to material questions and distribute them to all bidders when fairness requires. An addendum should identify changes to the scope, schedule, forms, or contract terms. Vendors should acknowledge addenda as instructed and avoid relying on informal conversations that are not part of the solicitation record.
How can the client confirm requirements locally?
Before release, confirm the licensing rules, insurance expectations, employment requirements, privacy obligations, tax treatment, procurement procedures, and any site-specific safety rules with the appropriate local authorities and advisers. Requirements can differ by state, county, municipality, facility type, and whether services are armed, unarmed, investigative, technological, or event-based.
Also confirm that the requested post duties are legally and operationally appropriate. A private security officer’s authority is not automatically the same as a law enforcement officer’s authority. The final RFP should use precise language, avoid implying powers the contractor does not have, and direct emergencies to public responders when appropriate.
A strong security RFP gives vendors a complete but controlled picture of the work. It defines posts, licensing, COI requirements, conflicts, personnel standards, reporting, pricing, evaluation, and contract administration. The result is a more useful comparison of proposals and a clearer foundation for service after award.