Local Government IT Procurement Checklist and Scoring Worksheet

A requirements, evaluation, implementation, and exit checklist for public-sector technology purchases.

Updated

A local government IT solicitation should let evaluators compare complete, supportable outcomes - not reward the proposal with the longest feature list or the lowest unexplained price. The work begins before an RFP is published: define the public service that must keep working, the evidence a vendor must provide, the assumptions included in its price, and the conditions for a controlled exit.

This is an operating checklist, not legal advice or a substitute for an agency's purchasing policy. North Carolina political subdivisions have an IT request-for-proposals option under G.S. 143-129.8, including identifying award factors in the RFP. That does not make every method, threshold, or contract term appropriate for every purchase. A purchasing officer and local counsel should confirm the authority, notice rules, approval path, records treatment, funding restrictions, and required clauses for the specific jurisdiction. South Carolina and federally funded procurements require their own review.

1. Start with outcomes and operating boundaries

Describe the result in terms a department head and an evaluator can test. Instead of asking for a named tool, state which users, locations, hours, workflows, recovery needs, and reporting obligations the service must support. North Carolina's statutory description of best-value procurement emphasizes business objectives and outcome-focused requirements, but its applicability must be confirmed for the procurement at hand; see G.S. 143-135.9.

  • Name the resident-facing or internal service, its business owner, and the consequence of an outage.
  • Define the locations, user groups, current systems, integrations, accessibility needs, and support window in scope.
  • List what is explicitly out of scope so vendors do not hide incompatible assumptions in narrative text.
  • State the evidence for acceptance: a completed migration test, approved configuration record, usable export, restored sample, training record, or service report.
  • Separate mandatory requirements from scored preferences. A preference presented as mandatory can unnecessarily narrow competition; a real requirement presented as optional creates delivery disputes.

2. Establish the procurement file before release

Record the business need, market research, chosen procurement method, approving authority, evaluation team, conflicts review, funding source, schedule, and communications channel. Keep vendor questions and issued answers in the official process so no proposer receives a private change to the requirement. If the team is also tracking changing grant or regulatory conditions, use a separate requirements register rather than embedding uncertain legal conclusions in the scoring notes.

Records obligations continue when a contractor hosts information. The State Archives says North Carolina local agencies, including entities contracted to perform public business, are subject to public-records requirements, while its schedules determine retention by record content rather than file format. Review the agency guidance for local government records and the statutory rules for public records in computer databases with the records officer and counsel. Do not assume a vendor's default deletion, archive, discovery, or export process satisfies the agency's obligations.

3. Require comparable assumptions and total responsibility

Give every proposer the same assumptions worksheet. Ask it to identify quantities, dependencies, customer responsibilities, third parties, one-time work, recurring work, optional work, taxes or fees, renewal rules, and any condition that could change price or schedule. Require a clear responsibility matrix for licensing, circuits, devices, identity, backup, security monitoring, project management, training, and after-hours response.

For managed services, the proposal should state the boundary between included support, separately authorized projects, and third-party escalation. The related MSP selection and governance guide provides a deeper operating model for finance and service owners.

4. Score evidence, not sales language

Publish mandatory gates, criteria, maximum points, weights, formulas, and tie or clarification procedures before proposals are opened, using the process required by local policy. Define what each point on the agency's chosen scale means. Evaluators should first record an independent score against cited proposal evidence, then preserve both that score and the moderated consensus result. Price must use the disclosed method and common cost assumptions, not an improvised formula created after reviewers see the proposals.

A defensible evaluation record identifies exactly which solicitation, proposer, evaluator, addenda, and proposal version were reviewed. Complete the header before scoring and keep the original independent record even if the consensus panel reaches a different result.

Evaluation headerRecorded value
Solicitation number and title____________________
Proposer legal name and proposal identifier____________________
Evaluator name, role, and department____________________
Independent evaluation date____________________
Proposal version, receipt record, and addenda confirmed____________________

Mandatory pass-fail gates

Copy every mandatory gate from the solicitation verbatim. Do not quietly convert a failed mandatory requirement into a scored weakness. If waiver, clarification, responsiveness, or legal interpretation is disputed, stop scoring that issue and route it through the procurement authority and counsel under the published process.

Gate ID and verbatim requirementProposal evidence citationPass, fail, or review requiredEvaluator rationaleConsensus disposition and authority
M-01: ____________________Page, section, attachment____________________Facts supporting resultDecision, name, and date
M-02: ____________________Page, section, attachment____________________Facts supporting resultDecision, name, and date
M-03: ____________________Page, section, attachment____________________Facts supporting resultDecision, name, and date

Scored evaluation record

Populate criterion names, maximum points, and the weighting formula directly from the released solicitation. If the published method uses a separate criterion weight, one possible recorded formula is (consensus score / maximum points) x published criterion weight; use it only when that is the adopted method. If maximum points already include weighting, do not weight the result again.

Criterion ID and nameEvidence and proposal citationMaximum pointsPublished weighting formulaIndependent scoreConsensus scoreWeighted totalExceptions and rationale
____________________Claim, page, section, and artifact________________________________________Strength, weakness, assumption, or condition
____________________Claim, page, section, and artifact________________________________________Strength, weakness, assumption, or condition
____________________Claim, page, section, and artifact________________________________________Strength, weakness, assumption, or condition
TotalConfirm all criteria and calculations_____Per solicitation_______________Document unresolved exceptions

Evaluation certification and signoff

Signoff fieldName or valueSignature or approved electronic attestationDate
Evaluator; conflict disclosure and confidentiality status confirmed under agency policy__________________________________________________
Consensus chair; independent scores preserved and consensus rationale recorded__________________________________________________
Procurement official; process, arithmetic, clarifications, and exceptions reviewed__________________________________________________
Final disposition or approval reference__________________________________________________

Retain the independent sheets, consensus record, calculation workbook, clarification history, conflict documentation, and approval record according to the agency's records schedule. Correct errors transparently with the original value, reason, approving authority, and date rather than overwriting the evaluation history.

5. Put security and supply-chain questions in the requirement

Ask how the product is secured by default, how privileged access is controlled, how vulnerabilities are disclosed and remediated, how security updates are delivered, which subcontractors or hosted services are material, and what evidence supports the answers. CISA's Secure by Demand guide recommends addressing product security before, during, and after procurement. NIST's cybersecurity supply-chain risk guidance addresses supplier risk throughout acquisition and operations. These are risk-management resources, not automatic contract clauses or certifications.

Require incident notification duties, preservation of relevant evidence, cooperation responsibilities, access revocation, and a process for material product or supplier changes. CISA's Software Acquisition Guide supplier-response tool can help structure consistent questions. Tailor them to the service and avoid collecting sensitive architecture detail that the evaluation team does not need.

6. Make implementation, acceptance, and exit part of the award

The apparent winner is not ready for award until the agency can reconcile the proposal, solicitation, clarifications, pricing, and contract into one enforceable scope. Attach an implementation plan with owners, dependencies, change control, validation, training, status reporting, and acceptance authority. Do not let a kickoff presentation replace contractual deliverables.

Define agency ownership and usable custody of its data, configurations, documentation, domains, accounts, logs, and records. State export format, timing, cost treatment, encryption, secure transfer, deletion confirmation, transition assistance, and survival of records or confidentiality terms. Test a representative export before renewal or termination pressure exists. For a structured transition, pair the contract with a service continuity and vendor migration framework.

Acceptance should be affirmative: the authorized owner confirms objective tests passed, exceptions are documented, required records were delivered, and any retained payment or remediation duty follows the contract. Renewal should require performance, risk, cost, and exit-readiness review rather than occur only because notice was missed.

Sources and scope

The federal security publications are voluntary guidance unless a law, grant, policy, or contract makes particular provisions applicable. North Carolina citations are included for local context, but authority and procedure vary by entity, transaction, funding source, and current law. Confirm the final solicitation and contract with the responsible purchasing, records, security, finance, and legal officials.

Suggested next step

Book a discovery call if your team needs help translating service outcomes and operating risks into a procurement-ready technical scope.

Want help applying this to your environment?

Start with a short discovery call and we will help you sort the practical next step without overcomplicating it.