Public Sector & Local Government
Updated
A local government IT solicitation should let evaluators compare complete, supportable outcomes - not reward the proposal with the longest feature list or the lowest unexplained price. The work begins before an RFP is published: define the public service that must keep working, the evidence a vendor must provide, the assumptions included in its price, and the conditions for a controlled exit.
This is an operating checklist, not legal advice or a substitute for an agency's purchasing policy. North Carolina political subdivisions have an IT request-for-proposals option under G.S. 143-129.8, including identifying award factors in the RFP. That does not make every method, threshold, or contract term appropriate for every purchase. A purchasing officer and local counsel should confirm the authority, notice rules, approval path, records treatment, funding restrictions, and required clauses for the specific jurisdiction. South Carolina and federally funded procurements require their own review.
1. Start with outcomes and operating boundaries
Describe the result in terms a department head and an evaluator can test. Instead of asking for a named tool, state which users, locations, hours, workflows, recovery needs, and reporting obligations the service must support. North Carolina's statutory description of best-value procurement emphasizes business objectives and outcome-focused requirements, but its applicability must be confirmed for the procurement at hand; see G.S. 143-135.9.
- Name the resident-facing or internal service, its business owner, and the consequence of an outage.
- Define the locations, user groups, current systems, integrations, accessibility needs, and support window in scope.
- List what is explicitly out of scope so vendors do not hide incompatible assumptions in narrative text.
- State the evidence for acceptance: a completed migration test, approved configuration record, usable export, restored sample, training record, or service report.
- Separate mandatory requirements from scored preferences. A preference presented as mandatory can unnecessarily narrow competition; a real requirement presented as optional creates delivery disputes.
2. Establish the procurement file before release
Record the business need, market research, chosen procurement method, approving authority, evaluation team, conflicts review, funding source, schedule, and communications channel. Keep vendor questions and issued answers in the official process so no proposer receives a private change to the requirement. If the team is also tracking changing grant or regulatory conditions, use a separate requirements register rather than embedding uncertain legal conclusions in the scoring notes.
Records obligations continue when a contractor hosts information. The State Archives says North Carolina local agencies, including entities contracted to perform public business, are subject to public-records requirements, while its schedules determine retention by record content rather than file format. Review the agency guidance for local government records and the statutory rules for public records in computer databases with the records officer and counsel. Do not assume a vendor's default deletion, archive, discovery, or export process satisfies the agency's obligations.
3. Require comparable assumptions and total responsibility
Give every proposer the same assumptions worksheet. Ask it to identify quantities, dependencies, customer responsibilities, third parties, one-time work, recurring work, optional work, taxes or fees, renewal rules, and any condition that could change price or schedule. Require a clear responsibility matrix for licensing, circuits, devices, identity, backup, security monitoring, project management, training, and after-hours response.
For managed services, the proposal should state the boundary between included support, separately authorized projects, and third-party escalation. The related MSP selection and governance guide provides a deeper operating model for finance and service owners.
4. Score evidence, not sales language
Publish mandatory gates, criteria, maximum points, weights, formulas, and tie or clarification procedures before proposals are opened, using the process required by local policy. Define what each point on the agency's chosen scale means. Evaluators should first record an independent score against cited proposal evidence, then preserve both that score and the moderated consensus result. Price must use the disclosed method and common cost assumptions, not an improvised formula created after reviewers see the proposals.
A defensible evaluation record identifies exactly which solicitation, proposer, evaluator, addenda, and proposal version were reviewed. Complete the header before scoring and keep the original independent record even if the consensus panel reaches a different result.
| Evaluation header | Recorded value |
|---|---|
| Solicitation number and title | ____________________ |
| Proposer legal name and proposal identifier | ____________________ |
| Evaluator name, role, and department | ____________________ |
| Independent evaluation date | ____________________ |
| Proposal version, receipt record, and addenda confirmed | ____________________ |
Mandatory pass-fail gates
Copy every mandatory gate from the solicitation verbatim. Do not quietly convert a failed mandatory requirement into a scored weakness. If waiver, clarification, responsiveness, or legal interpretation is disputed, stop scoring that issue and route it through the procurement authority and counsel under the published process.
| Gate ID and verbatim requirement | Proposal evidence citation | Pass, fail, or review required | Evaluator rationale | Consensus disposition and authority |
|---|---|---|---|---|
| M-01: ____________________ | Page, section, attachment | ____________________ | Facts supporting result | Decision, name, and date |
| M-02: ____________________ | Page, section, attachment | ____________________ | Facts supporting result | Decision, name, and date |
| M-03: ____________________ | Page, section, attachment | ____________________ | Facts supporting result | Decision, name, and date |
Scored evaluation record
Populate criterion names, maximum points, and the weighting formula directly from the released solicitation. If the published method uses a separate criterion weight, one possible recorded formula is (consensus score / maximum points) x published criterion weight; use it only when that is the adopted method. If maximum points already include weighting, do not weight the result again.
| Criterion ID and name | Evidence and proposal citation | Maximum points | Published weighting formula | Independent score | Consensus score | Weighted total | Exceptions and rationale |
|---|---|---|---|---|---|---|---|
| ____________________ | Claim, page, section, and artifact | _____ | ____________________ | _____ | _____ | _____ | Strength, weakness, assumption, or condition |
| ____________________ | Claim, page, section, and artifact | _____ | ____________________ | _____ | _____ | _____ | Strength, weakness, assumption, or condition |
| ____________________ | Claim, page, section, and artifact | _____ | ____________________ | _____ | _____ | _____ | Strength, weakness, assumption, or condition |
| Total | Confirm all criteria and calculations | _____ | Per solicitation | _____ | _____ | _____ | Document unresolved exceptions |
Evaluation certification and signoff
| Signoff field | Name or value | Signature or approved electronic attestation | Date |
|---|---|---|---|
| Evaluator; conflict disclosure and confidentiality status confirmed under agency policy | ____________________ | ____________________ | __________ |
| Consensus chair; independent scores preserved and consensus rationale recorded | ____________________ | ____________________ | __________ |
| Procurement official; process, arithmetic, clarifications, and exceptions reviewed | ____________________ | ____________________ | __________ |
| Final disposition or approval reference | ____________________ | ____________________ | __________ |
Retain the independent sheets, consensus record, calculation workbook, clarification history, conflict documentation, and approval record according to the agency's records schedule. Correct errors transparently with the original value, reason, approving authority, and date rather than overwriting the evaluation history.
5. Put security and supply-chain questions in the requirement
Ask how the product is secured by default, how privileged access is controlled, how vulnerabilities are disclosed and remediated, how security updates are delivered, which subcontractors or hosted services are material, and what evidence supports the answers. CISA's Secure by Demand guide recommends addressing product security before, during, and after procurement. NIST's cybersecurity supply-chain risk guidance addresses supplier risk throughout acquisition and operations. These are risk-management resources, not automatic contract clauses or certifications.
Require incident notification duties, preservation of relevant evidence, cooperation responsibilities, access revocation, and a process for material product or supplier changes. CISA's Software Acquisition Guide supplier-response tool can help structure consistent questions. Tailor them to the service and avoid collecting sensitive architecture detail that the evaluation team does not need.
6. Make implementation, acceptance, and exit part of the award
The apparent winner is not ready for award until the agency can reconcile the proposal, solicitation, clarifications, pricing, and contract into one enforceable scope. Attach an implementation plan with owners, dependencies, change control, validation, training, status reporting, and acceptance authority. Do not let a kickoff presentation replace contractual deliverables.
Define agency ownership and usable custody of its data, configurations, documentation, domains, accounts, logs, and records. State export format, timing, cost treatment, encryption, secure transfer, deletion confirmation, transition assistance, and survival of records or confidentiality terms. Test a representative export before renewal or termination pressure exists. For a structured transition, pair the contract with a service continuity and vendor migration framework.
Acceptance should be affirmative: the authorized owner confirms objective tests passed, exceptions are documented, required records were delivered, and any retained payment or remediation duty follows the contract. Renewal should require performance, risk, cost, and exit-readiness review rather than occur only because notice was missed.
Sources and scope
- North Carolina General Assembly: G.S. 143-129.8, purchase of IT goods and services
- North Carolina General Assembly: G.S. 143-135.9, best-value procurement
- North Carolina General Assembly: G.S. 132-6.1, databases as public records
- State Archives of North Carolina: local government records schedules and guidance
- CISA: Secure by Demand Guide
- NIST SP 800-161 Rev. 1 Update 1: Cybersecurity Supply Chain Risk Management
The federal security publications are voluntary guidance unless a law, grant, policy, or contract makes particular provisions applicable. North Carolina citations are included for local context, but authority and procedure vary by entity, transaction, funding source, and current law. Confirm the final solicitation and contract with the responsible purchasing, records, security, finance, and legal officials.
Suggested next step
Book a discovery call if your team needs help translating service outcomes and operating risks into a procurement-ready technical scope.