Skip to content

Knowledge centre

How to run an IT RFP or tender in the UAE: a procurement team's checklist

Structured IT procurement separates organisations that build strong, accountable IT partnerships from those that sign contracts they regret. This checklist covers every stage — from establishing a current-state baseline to negotiating a contract that holds.

Why IT tenders go wrong in the UAE

Most failed IT procurements share the same pattern: the organisation issues a vague RFP, receives proposals it cannot compare, selects on price alone, and discovers within six months that the contract does not cover what the business actually needs.

The UAE market has a wide range of IT providers — from single-person resellers to regional managed service organisations with 20-plus years of enterprise experience. Without a structured evaluation process, price becomes the only differentiator, and price is rarely the most important variable when you are deciding who manages your infrastructure, your data, and your organisation's ability to operate.

A well-run IT tender takes more effort upfront. It produces a contract built on documented scope, measurable SLAs, and a shared understanding of what happens when something goes wrong — before you sign.

Step 1: establish a baseline before writing the RFP

The most common RFP mistake is scoping a solution before understanding the problem. An IT system health check gives you a documented current-state view — what is working, where the risks are, and what the incoming provider will inherit. That baseline does three things:

  • It prevents bidders from under-scoping a proposal because they were not aware of a chronic problem or an undocumented dependency.
  • It gives your evaluation panel a neutral reference point — one that every bidder sees the same way, making proposals genuinely comparable.
  • It tells you whether you need a reactive support contract, a proactive managed services agreement, or a technology transformation programme. These require very different RFPs, and issuing the wrong one wastes everyone's time.

If you are evaluating enterprise IT services, the Missan enterprise vendor information page sets out the structure, credentials, operating model and reference documentation that procurement and vendor management teams typically request at the pre-qualification stage.

Step 2: define scope before issuing the document

A well-scoped RFP specifies what is in scope and what is not. For IT, that means:

  • In scope. List each category explicitly: endpoints, servers, network infrastructure, Microsoft 365 licences and governance, cybersecurity, backup, onsite response, third-party vendor coordination, helpdesk, escalation engineering.
  • Out of scope. If the incoming provider will not manage your ERP, your CCTV system, or a specialist application, say so clearly. Ambiguity here becomes a dispute at go-live.
  • Geography. List every office, site and emirate where support is required. A Sharjah-based provider covers Dubai readily; cover for Ras Al Khaimah, Fujairah or Abu Dhabi warrants a specific question about response capability and team location.
  • Scale. User count, device count, server count, branch count. Providers price and resource based on these numbers — inaccurate figures produce inaccurate proposals.
  • Current contract status. If you are mid-AMC, state the exit date and any transition obligations. Providers need this to plan handover timing and resource commitment.

Step 3: set your evaluation criteria before reading proposals

Agree your scoring matrix before proposals arrive. Once you have read a compelling bid, it is difficult to weight criteria objectively. A typical enterprise IT evaluation covers:

  • Technical capability. Certifications (Microsoft, Sangfor, Cisco, relevant vendor partnerships), tooling, engineer headcount, NOC or SOC capability, and whether escalation is internal or outsourced.
  • UAE operational experience. Years in market, reference clients at comparable size, and sector experience where relevant — healthcare, government, oil and gas, and financial services each carry specific compliance and uptime expectations.
  • Service structure. Helpdesk tiers, escalation path, onsite response commitments, named engineers versus a shared pool, and out-of-hours coverage.
  • Reporting and governance. What leadership receives, how often, and in what format. Managed IT without executive reporting is invisible IT — issues accumulate unseen until a failure makes them visible.
  • Total cost of ownership. Not just the monthly fee. Factor in transition costs, hardware refresh advisory, licence rationalisation, and exit provisions. A lower monthly fee with no transition assistance or no data portability can cost significantly more over a three-year term.
  • References. At least two UAE reference clients at comparable scale, contactable, and willing to speak candidly about what went wrong and how the provider responded.

For a structured view of what separates a reactive break-fix vendor from a strategic managed IT partner, the how to choose an IT partner guide covers the criteria, questions and red flags in detail.

Step 4: structure the RFP document itself

A clear RFP document reduces clarification questions and produces more comparable responses. Include:

  • Executive summary of your organisation and the requirement
  • Scope table: in scope and explicitly out of scope
  • Current-state summary from your health check, redacted as appropriate for commercial sensitivity
  • Mandatory requirements — items where a "no" disqualifies the bid entirely
  • Evaluation criteria and weightings, published openly — this focuses proposals on what actually matters
  • Required response format — section headings, page limits, a standard price schedule template so bids are genuinely comparable
  • Timeline: issue date, clarification deadline, submission deadline, presentation date, award date
  • Commercial terms: payment schedule, SLA penalties, contract length and renewal terms, exit provisions and data portability obligations

Step 5: shortlisting and due diligence

Score proposals against your matrix before inviting shortlisted vendors to present. Presentations should be live demonstrations of capability, not prepared slide decks. Ask each bidder to walk through how they would handle a specific scenario: a ransomware event at 2am on a public holiday, or onboarding 60 new users across three sites in two weeks. The answers reveal whether the response is procedural knowledge or genuine operational experience.

Reference checks are non-negotiable. Contact referees directly — not names supplied by the vendor's sales team, but organisations you have independently identified from their published partnerships or case studies. Ask: what went wrong in the first six months, and how did the provider handle it? A provider who reports no difficult periods is either very new or not giving you the full picture.

Step 6: negotiate the contract, not just the price

The signed contract is the only document that matters when performance falls short of expectations. Confirm in writing:

  • Response and resolution SLAs for each priority level, with clear definitions of what constitutes each priority
  • Escalation contacts by name on both sides
  • Reporting cadence, format, and who receives it
  • What happens if your headcount or site count changes significantly mid-contract
  • Exit provisions — notice period, data portability, transition assistance obligations
  • Penalty structure for sustained SLA failure

A contract that only specifies a monthly fee is not a managed IT contract — it is a purchase order with an open end. The value of a managed IT relationship is the accountability built into the agreement, not the technology it covers. Take time on the contract.

Missan Global has supported UAE organisations through IT procurement, transition and managed services since 2004. Whether you are running a formal tender or evaluating providers informally, the managed IT services overview sets out what a structured engagement looks like in practice. Speak to the team if you want a pre-qualification briefing or a current-state assessment before your RFP goes out.

Common questions

How many vendors should we invite to an IT RFP in the UAE?

Three to five is a productive range. Fewer than three limits meaningful comparison; more than five creates evaluation overhead that rarely changes the outcome. Invite vendors who can clearly demonstrate UAE operational experience at the right scale for your organisation — a provider that works well for a 20-person company may not have the engineering bench for a 300-seat enterprise.

Should we share IT health check results with bidding vendors?

Sharing a current-state summary — without commercially sensitive details — helps vendors scope accurately and reduces the risk of under-specified proposals. A structured IT health check gives you a neutral baseline that all bidders see the same way, which makes proposals far easier to compare. Vendors who price without understanding the environment often discover surprises after contract signature.

What is a reasonable evaluation timeline for an IT tender in the UAE?

Allow four to six weeks from RFP issue to shortlist. Rushed timelines attract under-specified bids and give vendors little time to consult their engineering teams. Very long timelines lose vendor engagement. Build in time for a clarification window, reference calls, and a live technical demonstration — scored presentations are more revealing than written proposals alone.

Running an IT procurement in the UAE?

Missan can provide pre-qualification documentation, a current-state health check baseline and technical briefings — so your RFP goes out on solid ground.