Public Sector & Local Government
Updated
A local managed service provider is not automatically more responsive, and a national provider is not automatically more capable. Either model can win a fair municipal evaluation. The useful question is whether a specific provider can produce the required public-service outcomes, under the municipality's operating constraints, with evidence that survives procurement review and contract management.
Replace the local-versus-national debate with requirements
Geography and scale affect delivery, but they are not outcomes. A nearby team may offer useful onsite context yet lack sufficient coverage, specialization, or process discipline. A national team may offer broad staffing and standardized platforms yet rely on remote queues or subcontractors that do not fit the municipality's needs. Those are possibilities to test, not conclusions to assume.
Begin with a statement of objectives: which services must remain available, which systems and sites are in scope, what response and restoration behavior is required, what the municipality will retain, and how performance will be measured. The federal performance-based acquisition principles in FAR Subpart 37.6 are written for federal acquisition, not as local-government requirements, but their focus on results and measurable standards is a useful design reference. Apply the municipality's own law, policy, and counsel's advice.
Build a neutral weighted evaluation
The municipality, not a bidder or this article, should set the weights before proposals are scored. Publish the criteria and scoring method when procurement rules require it. Define a consistent evidence scale, such as not demonstrated, partially demonstrated, and fully demonstrated, then have evaluators cite proposal pages or reference findings. Do not change weights after seeing vendor names.
| Criterion | Required evidence | Municipality-set weight | Score | Weighted result |
|---|---|---|---|---|
| Service continuity | Coverage model, escalation path, recovery roles, exercise method, and dependency handling | Set before review | Evidence-based | Weight × normalized score |
| Response and onsite delivery | Defined service levels, dispatch boundary, after-hours process, travel assumptions, and examples | Set before review | Evidence-based | Calculate consistently |
| Security and privileged access | MFA, least privilege, logging, personnel controls, incident notification, and customer separation | Set before review | Evidence-based | Calculate consistently |
| Staffing resilience | Named roles, backup coverage, relevant skills, turnover handoff, and subcontractor disclosure | Set before review | Evidence-based | Calculate consistently |
| Public-sector operations | Records support, accessibility, purchasing coordination, evidence delivery, and meeting cadence | Set before review | Evidence-based | Calculate consistently |
| Data and tool portability | Ownership, export formats, documentation, credential return, transition assistance, and deletion confirmation | Set before review | Evidence-based | Calculate consistently |
| Supply-chain transparency | Critical platforms, hosting, fourth parties, remote administration, updates, and material-change notice | Set before review | Evidence-based | Calculate consistently |
| Total evaluated cost | Recurring, project, after-hours, travel, licensing, transition, increase, and termination terms | Set before review | Evidence-based | Calculate consistently |
Require evaluators to record a rationale, not just a number. Handle mandatory conditions separately from weighted preferences: if a provider cannot meet a legally or operationally required condition, averaging that failure against attractive features can hide a disqualifying gap.
Evaluate security as a customer-control problem
An MSP may hold privileged access across endpoints, identities, cloud platforms, networks, or backups. CISA's joint advisory on protecting MSPs and customers recommends clarity about responsibilities, logging, authentication, incident information, and account management. The CISA #StopRansomware Guide also tells customers to consider MSP cyber hygiene and formalize security requirements in contracts.
Ask each bidder to show how customer environments are separated, how technician privileges are approved and revoked, which logs the municipality can obtain, how suspicious provider access is investigated, and what notification occurs when the provider or a critical subcontractor is affected. The municipality should retain independent access to essential identities, domains, backups, configurations, and records so a provider incident or dispute does not become a service lockout.
Make supply-chain claims traceable
The NIST Cybersecurity Supply Chain Risk Management program frames supplier risk across acquisition, operation, maintenance, and disposal. NIST's SP 1305 quick-start guide suggests grouping suppliers by criticality and expressing requirements through target profiles. For an MSP evaluation, identify which provider failure could interrupt payroll, public safety support, utilities, communications, records, or citizen services, then scale due diligence and contract requirements accordingly.
Do not award points for an unsupported statement such as “enterprise-grade security.” Request the policy excerpt, report, architecture explanation, sample deliverable, contract commitment, or reference evidence that demonstrates the claim. Decide in advance which sensitive evidence may be reviewed under controlled conditions rather than attached to a public procurement file.
Reference questions that expose delivery behavior
Choose references with similar service criticality and complexity, not merely the provider's happiest or closest customer. Ask the same questions for every finalist:
- Which services, sites, users, and after-hours periods were actually in scope?
- Describe a significant outage or security event. Who communicated, how often, and what changed afterward?
- Were response, restoration, and onsite commitments measured as the contract described?
- How often did staffing, subcontractors, or escalation contacts change, and how was continuity maintained?
- Were invoices predictable? Which project, travel, licensing, or after-hours charges were outside the base fee?
- Did the provider deliver current asset, configuration, credential, backup, and procedure documentation?
- How did the provider coordinate with software, telecom, public-safety, utility, or facilities vendors?
- What recurring report caused the customer to make a budget, risk, or service decision?
- Which obligation was hardest for the provider to meet, and how was the problem resolved?
- Would you select the provider again for the same scope? What would you change in the contract?
Relevant past performance is more useful than logo count. GSA's federal selection and award guidance emphasizes evaluating past performance during source selection. Local governments should use the reference and evaluation procedures permitted by their own procurement framework.
Convert the winning proposal into an enforceable operating model
Before award, reconcile proposal claims, clarifications, pricing, and exceptions into the contract. Define scope boundaries, severity rules, response and restoration measures, onsite conditions, communication frequency, security responsibilities, evidence delivery, subcontractor controls, transition assistance, data return, termination, and change control. The FAR Part 46 quality-assurance model is another federal reference point: it connects contract requirements to a documented surveillance method. A municipality needs its own named contract owner, evidence cadence, and escalation path.
A larger service desk is not proof of better outcomes. Proximity is not proof of faster response. Certifications are not proof that the proposed team will perform. Lowest price is not necessarily lowest evaluated cost. The defensible selection is the provider—local, regional, or national—that best meets the predeclared requirements and produces the strongest verified evidence.
Related evaluation guides
- Local government IT procurement checklist
- How to choose a managed service provider
- Service escalation and support expectations playbook
Official sources
- Acquisition.gov: FAR Subpart 37.6, Performance-Based Acquisition
- CISA: Protecting Against Cyber Threats to Managed Service Providers and Their Customers
- CISA: #StopRansomware Guide
- NIST: Cybersecurity Supply Chain Risk Management
- NIST SP 1305: Cybersecurity Supply Chain Risk Management Quick-Start Guide
- GSA: Selection and Award
- Acquisition.gov: FAR Part 46, Quality Assurance