Register of Vendor Pricing · Compiled by Digital Signet · Revised 20 June 2026
Annex I · Procurement

SOC / MDR RFP template.

An RFP that returns apples-to-apples pricing. The point of this document is to keep ingest, 24x7 uplift, IR retainer hours, and the compliance overlay out of the headline number, where they ordinarily hide.

Direct answer

A defensible MDR RFP has six sections: environment, services in scope, commercial line items, SLA matrix, exit terms, and scoring. The commercial section is the only one most templates get wrong; it must force vendors to quote base service, ingest, 24x7 uplift, compliance uplift, IR retainer, onboarding amortised, and off-boarding as separate lines.

Section 1. Environment

State, in vendor-neutral units: endpoints, log sources, log volume in GB/day, identity provider (Entra ID, Okta, Ping), cloud accounts and regions, compliance overlay (SOC 2, HIPAA, PCI, CMMC L2, FedRAMP, NIS2, DORA), and any BYO-SIEM constraint.

Section 2. Services in scope

Tier (Tier-1, Tier-1+2, Tier-1+2+3), coverage hours (business hours, 24x7), response authority delegated (notify-only, recommend, isolate, evict), threat hunting (none, scheduled, continuous), IR retainer hours per year, reporting cadence.

Section 3. Commercial line items (the pricing-forcing section)

Require the vendor to quote, as separate lines:

  • Base service ($ / endpoint / month or $ / unit / month).
  • Ingest charges (per GB / day; specify cap and overage rate).
  • 24x7 coverage uplift (state as a multiplier over business hours).
  • Compliance overlay uplift (per framework; state what changes operationally).
  • IR retainer (hourly rate, hours included, hours overage rate).
  • Onboarding (one-time fee, amortised /mo for the sake of comparison).
  • Contract off-boarding (data-export fee, transition support, retention).
  • Annual price escalation cap (state as % CPI or absolute).

Section 4. SLA matrix

Cross-reference /annex/sla-matrix. Require MTTD, MTTA, MTTR targets with service-credit triggers and a breach warranty trigger if the vendor offers one.

Section 5. Exit terms

Data export format, retention window after termination, off-boarding fee cap, contract assignability on merger or acquisition, and right to audit.

Section 6. Scoring

Weight commercial 40, technical 40, references 10, contractual 10. Score commercial on the normalised $/endpoint/mo (run the response through the RFP normaliser), not on the headline number.

Sources: NIST SP 800-161r1 (Cybersecurity Supply Chain Risk Management); CISA Cybersecurity Procurement Language; SANS SOC Survey.

Annex cross-references

AnnexSLA matrixMTTD, MTTA, MTTR, service credits, breach warranty triggers.AnnexQuote decoderQuestion ladder for the negotiation phase.AnnexHidden costsLine items that show up post-signature.AnnexCompliance uplift% uplift per HIPAA / PCI / CMMC L2 / FedRAMP / DORA.