Managed SOC procurement: your guide to RFIs, RFPs & RFQs
Outsourcing your Security Operations Centre (SOC) is a strategic move that can strengthen cyber resilience, free your internal teams to focus on the core business, and deliver better security outcomes. This guide walks you through the procurement process in plain language — from defining requirements to signing the right partner.
Part of the complete guide to SOC outsourcing.
The complete guide to SOC outsourcingGet the editable SOC RFP template
Looking for a ready-made RFP template to streamline your SOC procurement? Download our editable template and customise it to match your needs.
Download the templateMany organisations follow a formal Request for Information (RFI) or Request for Proposal (RFP) process when selecting a managed SOC provider. You’re not required to take this route, but it’s worth considering — especially if outsourcing your SOC is a new move for the business. The aim is to find an approach that fits your operation and helps you choose the right partner.
This guide lays out simple, practical steps to navigate SOC procurement with confidence, whether or not you issue an RFI or RFP. Built on proven best practice, it will help you define your requirements, assess potential partners and structure a strong, lasting relationship with your chosen provider. It suits organisations of all sizes — from fast-growing scaleups to large enterprises modernising their security operations.
If you’re still weighing up whether to build in-house or outsource, it’s worth reading the benefits of outsourcing your SOC before starting the procurement process.
What is SOC procurement, and why does it matter?
A SOC procurement process is a structured approach to selecting and onboarding a third-party provider for managed Security Operations Centre services. It typically involves issuing an RFI, RFP or RFQ to evaluate potential partners against your specific security requirements.
Many organisations rely on managed service providers (MSPs), managed security services (MSS) or managed security service providers (MSSPs) for continuous protection without overloading internal teams. Don’t get too caught up in the acronyms — all of them essentially provide a Security Operations Centre (SOC), and partnering with any should give your business access to advanced security expertise.
Given the SOC’s critical role in threat detection, incident response and regulatory compliance, it’s essential to align your procurement process with your business goals, risk appetite and operational needs.
What’s the difference between an RFI, RFP and RFQ?
- RFI (Request for Information) — market research to understand vendor capabilities.
- RFP (Request for Proposal) — invites detailed solutions for defined needs.
- RFQ (Request for Quotation) — focuses on pricing for clearly defined services.
Understanding the SOC procurement process
Partnering with a SOC provider can simplify procurement and give your business access to advanced security expertise. There are typically five main stages:
- Define requirements. Work out what you need based on your current environment, risk profile and business goals.
- Issue an RFI. Gather basic market intelligence and narrow down potential vendors.
- Issue an RFP. Send detailed specifications to your shortlisted providers.
- Evaluate and select. Score proposals, shortlist, check references, meet finalists and choose a provider.
- Contract, onboard and orient. Finalise the contract, prepare your internal team and orient the SOC provider.
Step 1: Define your SOC requirements
The first and most critical step is defining your security objectives and success metrics. Involve key stakeholders — IT, risk, compliance and leadership — to align on goals. A cost-effective MSSP can help optimise your cybersecurity budget while protecting sensitive data.
Key questions to ask
- What are our top cybersecurity risks and compliance requirements?
- What incident response, escalation and remediation capabilities do we expect from the provider?
- Do we need 24/7 coverage, and how will that affect our internal teams?
- Should the SOC use our SIEM platform, or provide their own?
- Can the service scale with our business as we grow?
- Do we require UK-based SOC services, or are offshore options acceptable?
- What SLAs, KPIs and reporting do we need to measure performance and value?
You can engage a professional CISO on a fractional basis — a virtual CISO, or vCISO — who has experience defining SOC requirements and evaluating vendors. They may even have their own black book of providers they know can deliver, whom you can evaluate as part of the process.
Step 2: Issue a SOC RFI
An RFI helps you understand the managed SOC market before committing to a full RFP. Include details such as:
- Current security setup and objectives.
- SOC capabilities — threat detection, incident response, vulnerability management, and optional services (e.g. dark web monitoring, patch management, third-party risk management).
- Technology stack and integration — SIEM platforms, security tools, and the ability to connect to all data sources to minimise blind spots.
- Team structure, expertise and 24/7 coverage model.
- Credentials and compliance — certifications (e.g. CREST SOC, ISO 27001, ISO 9001, SOC 2, GDPR, DORA), case studies and references.
- Delivery model, escalation process and account management approach.
Research external benchmarks
As part of your vendor identification strategy, research potential SOC providers through multiple channels to build a strong shortlist. Using several sources helps validate your shortlist, provides benchmarks for negotiation, and ensures your approach aligns with cybersecurity procurement best practice:
- Analyst reports and peer reviews (Gartner Peer Insights, Forrester, IDC).
- Cybersecurity network groups.
- Industry frameworks (ISO 27001, NIST CSF v2, CIS Controls).
- Reputation and word-of-mouth from trusted partners, such as a vCISO.
Step 3: Build a strong RFP
A strong RFP is critical to the success of your procurement. It should evaluate total value, not just price, including:
- Technical and engineering capabilities.
- Service delivery approach.
- Compliance experience.
- Innovation and cultural fit.
- Contractual flexibility and exit terms.
Before issuing an RFP, it’s worth understanding how SOC pricing works — from subscription models to hidden costs. Our guide to SOC outsourcing costs breaks down what to expect and how to avoid budget surprises.
Invest time in a comprehensive but focused document. Clear requirements, submission guidelines, evaluation criteria and response timelines make it easier for vendors to respond consistently, and for you to compare proposals objectively.
What to include in your SOC RFP
- Service scope: monitoring, response, escalation and coverage.
- Technical integration: SIEM/EDR platforms, service-desk integration, multi-cloud, on-premise and scalability needs.
- Compliance requirements: e.g. CREST SOC, GDPR, NIST CSF v2, ISO 27001, DORA, regulatory reporting.
- SLAs & KPIs: response times, resolution targets, reporting frequency.
- Data governance: data residency and privacy policies.
- Commercial terms: pricing model, contract duration, exit terms and transition assistance.
Include both quantitative questions (easier to score) and qualitative ones that reveal the vendor’s expertise and approach.
Step 4: Evaluate and select your SOC provider
Assemble a cross-functional evaluation team — IT, procurement, finance and operations — for an objective assessment. Score proposals against predefined criteria:
- Technical capability: ability to support your technology stack, accommodate change, and automate for fast containment.
- Cost awareness: a focus on optimising costs and maximising ROI from your existing security tools and processes.
- Industry expertise: proven experience with similar organisations, strong references, and use of actionable threat intelligence.
- Service delivery & SLAs: quality of SLAs, reporting, integration with your team, and validation of SOC effectiveness.
- Project delivery: a clear rollout plan, realistic timelines, and understanding of customer dependencies.
- Financial stability: transparent, scalable pricing and a sound financial footing.
- Cultural fit: the ability to work effectively with your team and organisational culture.
- Innovation potential: use of advanced technologies and a commitment to continuous improvement in resilience.
Evaluating proposals: a scoring-matrix approach
Use a weighted scoring matrix to compare vendors across these critical areas, like this:
| Evaluation criteria | Weight (%) | Vendor A | Vendor B |
|---|---|---|---|
| Technical capability | 20 | 8/10 | 8/10 |
| Compliance & governance | 15 | 7/10 | 9/10 |
| Service delivery & SLAs | 15 | 9/10 | 5/10 |
| Experience & sector fit | 10 | 5/10 | 5/10 |
| Cultural fit & communication | 10 | 7/10 | 6/10 |
| Commercial model | 15 | 7/10 | 6/10 |
| Innovation & value-add | 10 | 7/10 | 5/10 |
| Project plan & dependencies | 5 | 7/10 | 6/10 |
| Weighted average | 7/10 | 6/10 |
For a deeper look at vetting providers beyond the RFP — cultural fit, transparency and SLAs — read our guide to choosing the right SOC outsourcing partner.
Getting beyond the RFP: steps after proposal submission
The RFP is a crucial stage, but the journey doesn’t end there. After receiving and evaluating proposals, a few more steps help refine your selection and ensure a strong partnership: finalist interviews, cultural alignment, scenario discussions, team introductions and onboarding conversations.
When to use an RFQ
While RFIs and RFPs are the common tools in managed SOC procurement, a Request for Quotation (RFQ) can be useful when you already know your exact requirements, you’re comparing pricing across a small, pre-qualified shortlist, or you’re at the final decision stage and need to clarify commercial terms. An RFQ is typically shorter and more transactional than an RFP, focusing on cost, licensing models, billing schedules and setup fees rather than detailed technical solutions or service delivery.
Be wary of vendors who respond to an RFQ without asking detailed questions. They often offer a low-cost, commoditised service that ticks the “outsourced SOC” box but struggles to integrate with your specific technologies and processes — frequently relying on your own IT staff to contain incidents off the back of tickets the SOC raises.
Interview or meet potential SOC partners
Once you’ve narrowed the field based on RFP submissions, interview and meet your shortlist. This lets you assess cultural fit, clarify proposal details and test their understanding of your cybersecurity and business goals. Use finalist interviews to:
- Ask how they’d handle specific security scenarios or incidents.
- Meet the actual SOC team who would deliver your service.
- Explore their approach to onboarding and continuous improvement.
- Discuss their measurement and reporting methodologies.
This ensures alignment not just on paper, but in real-world collaboration with the partner you’ll trust to keep your business safe.
Step 5: Contract, onboard and orient
Once you’ve selected your preferred provider, negotiate contractual terms that protect the business — total costs, SLA penalties and a RASCI agreement. With terms agreed, the provider will typically present a project plan covering onboarding their SOC staff, gaining access to IT resources, and running workshops to orient both teams on the business goals and technical requirements of the SOC.
Contract checklist
- Total cost, including setup, integration and ongoing maintenance. The IT environment changes constantly, and the provider should work as a partner to accommodate that without introducing surprise fees.
- SLA terms, penalties and remediation.
- A shared RASCI matrix (Responsible, Accountable, Support, Consulted, Informed) across the incident-response process — ideally with a partner who contains incidents on your behalf, to maximise value.
- Exit strategy, including notice periods, termination conditions and data return.
- Scope boundaries (inclusions and exclusions) and change-management processes.
Have your legal team review all terms before signing, confirming compliance with your organisational policies and regulatory requirements. DORA sets specific contractual recommendations for ICT suppliers that support critical functions of EU financial-services organisations (such as an outsourced SOC). Even if DORA doesn’t apply to you, we recommend incorporating these clauses into your SOC contracts as good practice for building resilience.
Onboarding and orientation
The provider should supply a structured transition plan covering:
- A customer document and architecture review to orient the SOC team.
- A technical integration schedule and testing.
- Risk-management and business-context workshops.
- Service-management and disaster-recovery design.
- Knowledge-transfer sessions and shared incident-response workshops.
- Performance monitoring and review checkpoints, in the form of regular service reviews.
SOC procurement checklist
Use this checklist for your internal planning and to keep to procurement best practice:
- Define requirements
- Align stakeholders
- Issue RFI
- Build and send RFP
- Score proposals
- Interview finalists
- Finalise contract
- Plan onboarding
Your SOC strategy starts here
SOC procurement is the start of a strategic partnership. A trusted MSSP helps optimise costs, strengthen your security and improve resilience. Invest the time in defining clear requirements, validating vendors, using structured evaluations, and understanding dependencies — and you’ll choose a partner that fits.
Run your process with our RFP template
Everything above, in a document you can edit and send. Free, no form to fill in.
Download the SOC RFP templateProcuring a managed SOC?
Talk to us about your requirements and the level of cover your risk calls for — a straight conversation, not a sales pitch.
Book a 30-minute consultation