IT Managed Service Provider RFP June 2025.pdf
PDF 233 KB Posted
- Attached to
- RFP for Managed Service Provider for Information Technology Services State and local contract opportunity
- Solicitation number
- 2025-03
- Issued by
- Oakland County, Michigan
About this file
This is a Request for Proposal (RFP) issued by the City of Bloomfield Hills, Michigan, seeking a Managed Service Provider (MSP) for Information Technology Services. The RFP was released in June 2025 with proposals due on Wednesday, July 30, 2025, at 2:00 p.m., and covers a contract period from award through June 30, 2030 (five fiscal years). The city is seeking an IT service provider to support its municipal network infrastructure across three buildings, which currently includes 90 internal IP addresses, 45 active users, 42 workstations, and 8 servers. The selected vendor will be responsible for comprehensive IT support services, including service desk support, network monitoring and administration, server administration, backup services, desktop management, security and compliance, and professional services.
The RFP outlines detailed service level agreement (SLA) requirements, including 99.9% monthly uptime for critical systems, specific incident response times ranging from 15-30 minutes for critical issues to 1 business day for low-priority inquiries, and comprehensive security compliance aligned with CISA guidelines. The city requires the MSP to conduct annual penetration testing, maintain continuous 24x7x365 monitoring, and provide monthly reports on SLA adherence, incident trends, and end-user satisfaction. The cost proposal form indicates that pricing will be structured across multiple service categories for each of the five contract years, including service desk support, network administration, server administration, backup services, desktop services, security and compliance, professional services, and Microsoft Office licensing. The city emphasizes that while cost is important, the selection will prioritize quality, experience, and references, with the goal of selecting the most qualified and competent vendor.
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
City of Bloomfield Hills
Request for Proposal (RFP)
Information Technology Managed Services
City of Bloomfield Hills
45 E Long Lake Rd
Bloomfield Hills, MI 48304
Issue Date: June 2025
Due Date: Wednesday, July 30, 2025, at 2:00 p.m.
Contract Period: Upon Award – June 30, 2030 (Five Fiscal Years)
1. General Intent
1.1 Purpose of the RFP:
• The City of Bloomfield Hills is seeking proposals for IT Managed Services.
• This RFP explains the services that the City requires from potential vendors.
1.2 Eligibility Restriction:
• Any vendor, vendor principal, or stakeholder who is currently employed by the City is not eligible to submit a proposal.
• This is to prevent conflicts of interest and ensure fair competition.
2. Project Background
2.1 Introduction - The City of Bloomfield Hills seeks a managed service provider (MSP) to support its IT infrastructure with agile, secure, and forward-looking IT operations.
2.2 IT Environment Overview - The City of Bloomfield Hills operates fully featured municipal network supporting operations across three buildings. The IT infrastructure includes a core network, two intermediate distribution frames (IDFs), managed network switching, and enterprise-grade firewall systems. The City supports approximately 90 internal IP addresses and
45 active users, with 42 workstations and 8 servers currently monitored via Kaseya RMM.
The City has recently migrated to Microsoft 365 for email, productivity, and collaboration services. With this transition, the City is focusing on enhancing cloud-based services, endpoint security, and overall network reliability.
The City is seeking a qualified vendor to provide ongoing IT support and infrastructure services, with clearly defined Service Level Agreement (SLA) targets. These targets must address both remote support and on-site response times to ensure consistent performance, availability, and rapid incident resolution.
The Public Safety Department operates 24/7/365 to ensure continuous service delivery. While many systems utilized by Public Safety are third-party applications with their own dedicated support channels, the Managed Service Provider (MSP) is expected to serve as a liaison to facilitate issue resolution between end users and these third-party organizations. These organizations may include, but are not limited to: the CLEMIS Authority, the State of Michigan –
Michigan State Police (MSP), the Department of Technology, Management, and Budget (DTMB), Motorola (for 911 systems), internet service providers (ISPs), and telecommunications providers.
3. Scope of Work
3.1 Service Desk Support -The service desk will provide SLA-governed support in alignment with industry standards such as ITIL (Information Technology Infrastructure Library) and HDI (Help Desk Institute) best practices. Defined response and resolution times will be based on issue priority levels, adhering to common benchmarks (e.g., initial response within 30 minutes for critical issues, resolution within 4 hours). Support processes will include comprehensive issue triaging, categorization, and escalation workflows to optimize incident management efficiency.
Monthly reporting will deliver detailed analytics on ticket volume, resolution metrics, SLA compliance, and root cause analysis, enabling continuous operational improvement and alignment with service management frameworks.
3.2 Network Monitoring & Administration - The provider shall deliver 24/7 network monitoring and administration services through a dedicated Network Operations Center (NOC), staffed by certified network engineers. Services must include real-time monitoring, alerting, and support for core network infrastructure such as firewalls, switches, VPNs, and wireless access points. The NOC will ensure continuous oversight, rapid incident response, and proactive management to maintain network performance, security, and high availability.
3.3 Server, Hyper-V & SQL Administration - The provider shall administer both on-premises and cloud-hosted server environments, including Hyper-V virtualization and Microsoft SQL Server instances. Services must cover routine maintenance, performance optimization, patch management, and disaster recovery planning and execution. Labor for upgrading existing server hardware and software must be included as part of the service offering. The provider is expected to ensure system reliability, data integrity, and high availability across all managed environments.
3.4 Backup-as-a-Service -The provider shall deliver Backup-as-a-Service (BaaS) for approximately 5–10 TB of data, supporting both full and incremental backup schedules. The solution must include quarterly test restorations to verify data integrity and recovery capabilities. A triple-location backup policy is required, maintaining copies on-premises, in the provider's cloud infrastructure, and at an offsite/secondary location to ensure redundancy and disaster recovery.
Recovery objectives should align with industry best practices:
• Recovery Point Objective (RPO): Maximum data loss of no more than 24 hours (daily backups)
• Recovery Time Objective (RTO): Data recovery within 24 hours of a disruption
The current environment utilizes VEEAM running on a Synology DiskStation for on-premises backups, with replication to the existing Managed Service Provider's (MSP) cloud infrastructure.
The proposed solution should ensure continuity with, or a seamless migration from, this setup.
3.5 Desktop-as-a-Service - The provider shall deliver end-to-end Desktop-as-a-Service (DaaS) solutions to support a secure, standardized, and efficient end-user computing environment.
Services must include workstation imaging, operating system and application patching, antivirus deployment and management, and full provisioning of desktops and laptops. Support for Mobile Data Computer (MDC) deployments is required.
Labor for upgrading existing workstation and laptop hardware and software shall be included as part of the base service offering. All activities must be performed with minimal disruption to end users to ensure continuity and consistent performance.
Remote management of endpoints shall be conducted using tools that are fully compliant with Criminal Justice Information Services (CJIS) security standards, ensuring the protection of sensitive law enforcement and public safety data.
3.6 Security & Compliance - The organization maintains a robust security and compliance posture through continuous assessments aligned with CISA (Cybersecurity and Infrastructure Security Agency) controls. Annual third-party audits are conducted to ensure compliance with applicable regulatory and industry standards, including PCI-DSS, HIPAA, and CJIS. Regular security awareness training is mandatory for all personnel to maintain readiness against evolving cyber threats and ensure organizational alignment with security obligations.
The selected bidder must include the performance and coordination of required annual audits within their scope of work, as well as demonstrate their ability to meet or exceed all applicable security and compliance standards.
All MSP employees with physical or remote access must pass a CJIS background check and complete the required training.
3.7 Professional Services - The MSP shall provide comprehensive professional services to support the operational and strategic needs of the City of Bloomfield Hills. These services include, but are not limited to:
• Management and Budgeting: Oversight of IT-related projects, resources, and expenditures to ensure alignment with departmental goals and fiscal responsibility.
• Project-Based Engineering: Design, implementation, and documentation of infrastructure and technology projects, including hardware/software deployments, system integrations, and network enhancements.
• Audit Support: Assistance in preparing for and responding to internal and external audits, ensuring compliance with applicable standards and regulations.
• Network, Server, and Database Administration: Routine monitoring, maintenance, and performance optimization of network infrastructure, physical and virtual servers, and databases.
• Patching and Software Upgrades: Scheduled and emergency application of patches, firmware updates, and version upgrades to maintain security, stability, and compliance.
• Technical Liaison Services: Acting as an intermediary between the end users and third-party vendors, service providers, and regulatory agencies to ensure effective communication and resolution of technical matters.
4. Proposal Organization
To ensure consistency and facilitate an efficient review process, all proposals must be organized in the following format and include the specified sections:
1. General Information - Provide the name of the company, primary point of contact, mailing address, phone number, email, and relevant business identifiers (e.g., DUNS, EIN, SAM registration, certifications).
2. Statement of Interest - A brief summary outlining the bidder’s interest in the engagement, understanding of the scope, and overall value proposition.
3. Service Approach - A detailed description of the bidder’s approach to delivering the requested services, including methodologies, tools, technologies, and compliance considerations.
4. Personnel - Identify key personnel who will be assigned to this project, including roles, qualifications, relevant experience, and any applicable certifications (e.g., CJIS, HIPAA, Microsoft, Cisco).
5. References - Provide at least three (3) references from similar clients or engagements.
Include organization names, contact information, scope of work performed, and duration of the relationship.
6. Contract Terms - Include proposed contract terms and conditions, any exceptions to the standard terms (if applicable), and sample service level agreements (SLAs).
7. Cost Model - Present a clear and itemized cost structure, including fixed fees, recurring charges, hourly labor rates (if applicable), and any additional or optional service pricing.
All costs must be clearly identified and justified.
5. Proposal Submission Requirements
5.1 Format: PDF, 8.5"x11", signed cost form included.
5.2 Questions due by July 15th, 2025 to Capt. Dustin Lockard
(dlockard@bloomfieldhillspolice.com).
5.3 Deadline: July 30, 2025 by 2:00 p.m.
5.4 Proposals become City property upon submission.
6. Evaluation Criteria
6.1 Method of Award
• The CITY treats this as a professional services contract.
• Cost is important, but quality, experience, and references carry significant weight.
• The most qualified and competent Vendor will be selected, not necessarily the lowest bidder.
6.2 Cancellation of Award
• The CITY can cancel the award at any time before signing a final agreement, with no liability to any proposer.
6.3 Evaluation Procedures
• The CITY will review all proposals, judge their merit, and choose a Vendor to start negotiations.
• The CITY might invite finalists to give presentations or demonstrations.
• If a Vendor leaves out required information, their proposal may be disqualified.
6.4 Evaluation Criteria
The CITY will assess proposals using four main categories:
1. Service Experience o Vendor’s history and performance o Size, scope, and stability of vendor o Similar services previously provided o Quality of references
2. Understanding / Compatibility o Vendor’s grasp of CITY’s needs o Level of interest and commitment o Awareness of different CITY customer needs
3. Approach mailto:dlockard@bloomfieldhillspolice.com o Quality of proposed plan and timelines o Schedule management o How well the RFP specs are addressed o Quality control processes o Ability to provide multiple integrated services
4. Cost o Financial competitiveness and value
6.5 Oral Presentation
• Vendors may be asked to present their proposal in person.
• This is a chance to clarify or expand on their submission.
• Vendors bear the full cost of participation in this phase.
6.6 Negotiation Procedures
• The CITY’s Evaluation Team will review all submissions and make a final recommendation.
• Vendors should address all evaluation criteria (as outlined in Section 4.0 - Required Information) in clear, detailed terms and in the specified order.
6.7 Rejection of Proposals
• The CITY can reject any or all proposals.
• The CITY can also cancel or revise the RFP at any time.
• Any changes will be communicated to all participants who received the RFP.
7. Miscellaneous Provisions
7.1 Contract Provisions - Proposals submitted in response to this RFP may become part of any resulting contract. If the selected Vendor deviates in any material way from the services proposed in their submission, the CITY reserves the right to reject the proposal and initiate negotiations with an alternative Vendor.
7.2 Provisions for Subcontracting - The Vendor shall not subcontract any portion of the work or assign the contract, in whole or in part, without prior written approval from the authorized agent of the CITY. Unauthorized subcontracting or assignment will be grounds for contract termination.
7.3 Non-Discrimination - The Vendor must certify that it does not and will not discriminate in hiring or employment practices based on race, color, creed, religion, national origin, sex, age, marital status, public assistance status, veteran status, disability, or sexual orientation.
7.4 Lobbying Restrictions - Any direct or indirect contact with members of the City Commission or department heads related to this project—outside of the established procurement process— will result in the immediate disqualification of the proposal.
7.5 Limitations of Responsibility - The CITY OF BLOOMFIELD HILLS is not responsible for any costs incurred by Vendors in the preparation, submission, or presentation of proposals in response to this RFP.
7.6 Physical Presence Requirement – The Managed Service Provider (MSP) shall maintain at least one employee permanently located within 100 miles of the City of Bloomfield Hills who is available and capable of providing onsite support. This requirement ensures that the MSP can deliver timely, effective, and responsive service to the CITY, including prompt resolution of technical issues that may necessitate physical presence.
8.0 SERVICE LEVEL AGREEMENT (SLA)
8.1 Overview
This SLA outlines minimum service expectations and metrics for the MSP. These expectations are in alignment with U.S. Cybersecurity and Infrastructure Security Agency (CISA) guidance on critical infrastructure resilience, risk management, and incident response.
8.2 Uptime and Service Availability
- Minimum 99.9% monthly uptime for critical IT services and systems
- Scheduled maintenance must be communicated 48 hours in advance
8.3 Incident Response and Resolution Times
Severity 1 – Critical (e.g., major outage, security breach):
• Response Time: 15–30 minutes
• Resolution Target: ≤ 4 hours
Severity 2 – High (significant business impact):
• Response Time: 1 hour
• Resolution Target: ≤ 8 hours
Severity 3 – Medium (individual user issues or degraded performance):
• Response Time: 4 hours
• Resolution Target: ≤ 1 business day
Severity 4 – Low (general inquiries, non-urgent support):
• Response Time: 1 business day
• Resolution Target: ≤ 3 business days
8.4 Security Compliance and CISA Alignment
- MSP must conduct a comprehensive Information Security Risk Assessment within 90 days of contract start, following CISA’s Cyber Resilience Review (CRR) and CIS Controls v8.
- MSP must support implementation of secure configurations, continuous monitoring, threat detection, and vulnerability management aligned with CISA advisories.
- Annual Penetration Testing and Vulnerability Scans must be performed in compliance with
CJIS, HIPAA, PCI-DSS, and CISA-recommended practices.
8.5 Monitoring and Metrics
- Continuous 24x7x365 monitoring of network, endpoints, firewalls, and data traffic
- Monthly reports must include: SLA adherence, incident trends, threat activity, patch compliance, and end-user satisfaction metrics
- Minimum CSAT score target: 4.5/5
8.6 Service Credits and Remedies
- If monthly SLA compliance drops below 95%, MSP must issue service credits:
• 5% of monthly invoice for the first SLA breach
• Additional 5% per additional category missed (up to 20%)
8.7 Exclusions
- SLA exclusions include natural disasters, war, user misuse, or issues caused by third-party vendor failures.
8.8 Escalation Process
Level 1 – Help Desk Manager
Level 2 – Account Manager
Level 3 – Executive Sponsor
Escalation contacts and availability must be documented and updated annually.
9.0 Cost Proposal Form
Service Year 1 Year 2 Year 3 Year 4 Year 5
Service Desk Support
Network Admin & Monitoring
Server Admin
Backup-as-a- Service
Desktop-as-a-Service
Security & Compliance
Professional Services
Microsoft Office Licensing
ANNUAL
TOTAL
The undersigned affirms full authority to execute this proposal, affirms no collusion, and agrees to all stated terms.
Firm Name: _____________________________________
Representative: ________________________________
Title: _________________________________________
Signature: _______________________ Date: _______
File details come from the government source that posted it. Updated .