A Scorecard for Comparing Commercial Security Bids
Compare commercial security bids using a practical scorecard for scope, performance, lifecycle cost, service, cybersecurity and acceptance evidence.
Three commercial security proposals can show similar totals while describing different systems, responsibilities and risks. Procurement and facilities leaders should first normalize each bid to a common scope, then apply mandatory gates and a weighted scorecard covering performance, implementation, lifecycle, service and commercial terms. Price should be evaluated only after hidden differences are exposed.
The most useful scorecard answers a practical question: which proposal gives the organization the strongest evidence that the required security outcome will be delivered, supported and maintainable at an understood lifecycle cost? It should reward verifiable commitments and reduce points for assumptions that transfer cost or responsibility back to the customer.
This guide begins after bids have arrived. Teams still preparing the solicitation can use the commercial security RFP checklist to create a common response structure before proposals are requested.
Start by separating compliance, clarification and scoring
Use three distinct passes. Combining them in one discussion makes a polished proposal or low total more likely to influence decisions that should be objective.
Pass 1: mandatory compliance
Check each mandatory requirement using the evidence defined in the solicitation. A response of “complies” carries little value without a model number, drawing, method statement, certificate, licence description or other requested proof.
Mandatory gates may cover:
- required insurance, licensing or contractual declarations;
- compatibility with an existing platform that must remain in service;
- essential privacy, cybersecurity or data-location conditions;
- required service coverage or response capability;
- minimum functional performance; and
- submission of a complete pricing schedule and exceptions register.
Keep the gates limited to requirements that are genuinely essential. The Ontario Broader Public Sector Procurement Directive requires covered organizations to disclose mandatory and rated criteria and their weightings in the competitive documents. It also says mandatory criteria should be kept to a minimum so bids are not unnecessarily disqualified. Private-sector buyers can use the same discipline even when the directive does not apply to them. See Ontario’s Broader Public Sector Procurement Directive.
Pass 2: clarification and normalization
Create one clarification log controlled by procurement. Ask bidders the same question when the same ambiguity appears, set a deadline and preserve the written answer. Clarification should explain the submitted offer according to the procurement rules. It should not become an informal opportunity to rebuild one bid after closing.
Pass 3: rated evaluation
Score only the compliant, normalized proposal. Evaluators should record evidence and a short reason for each score before a consensus meeting. CanadaBuys explains that rated criteria distinguish the relative merits of technical bids and that the stated selection method governs the final choice. Its overview also describes separating technical assessment from financial assessment to support fairness. See How bids are evaluated and selected.
Normalize the scope before comparing totals
The first comparison sheet should show what each total contains. Create a bid-normalization table with one row for every required deliverable, dependency and recurring charge.
| Comparison field | What to record | Warning signal |
|---|---|---|
| Equipment | Manufacturer, model, quantity, licence and approved equivalent | Generic descriptions such as “4K camera” |
| Coverage or door outcome | Required view, event, workflow or controlled opening | Device count with no operational purpose |
| Infrastructure | Cabling, pathway, switches, power, UPS, racks and network work | “By others” with no owner or allowance |
| Installation | Hours, lifts, permits, patching, fire stopping, disposal and restoration | Assumed daytime access at a 24-hour site |
| Software and services | Hosting, licences, monitoring, cellular, integrations and renewal terms | First-year price with later charges omitted |
| Commissioning | Test scripts, deficiency process, retest and customer witness | “System operational” as the only test |
| Handover | As-builts, asset list, configuration backup, credentials and training | Documentation available only on request |
| Warranty and support | Coverage, response, exclusions, escalation and replacement process | Manufacturer warranty presented as on-site labour |
| Exit | Data export, configuration transfer, credential ownership and decommissioning | Customer access depends on the outgoing provider |
For each row, label the response included, excluded, allowance, optional, customer supplied, or unclear. Add the bidder’s exact assumption and the person who would own the work. This makes two proposals comparable without pretending their original totals represented the same scope.
Do not silently estimate an unclear item. Request a written clarification where the rules permit it. If the issue remains unresolved, score the uncertainty according to the published method and document the reason.
Use a scorecard tied to evidence
A practical scorecard separates the factors that determine whether the system will work and remain supportable. The example below totals 100 points. Adapt the criteria and weights before bids are opened. Public-sector and regulated procurements need review against their governing policies and legal obligations.
| Rated category | Example weight | Strong evidence |
|---|---|---|
| Scope completeness and traceability | 20 | Requirement-by-requirement response, drawings, quantities, dependencies and exceptions |
| Operational performance and design | 20 | Coverage objectives, door workflows, alarm logic, storage calculations and demonstrated results |
| Delivery and commissioning | 15 | Site method, schedule, outage controls, test scripts, deficiency closure and accountable owners |
| Lifecycle and cybersecurity | 15 | Support horizon, updates, secure configuration, identity controls, backups and migration path |
| Service and operating support | 10 | Measurable response levels, escalation, preventive maintenance, spares and reporting |
| Evaluated lifecycle cost | 20 | Normalized capital, recurring, support, growth and exit costs over the chosen period |
Define scoring anchors for every category. A five-point scale could mean:
- 0, absent: no usable response or evidence.
- 1, weak: major gaps, unsupported statements or high customer dependency.
- 2, partial: some relevant detail with material uncertainty.
- 3, acceptable: complete response that meets the stated expectation.
- 4, strong: clear evidence, low ambiguity and useful added value.
- 5, exceptional: verified benefit beyond the requirement with no material new dependency.
Write a category-specific description for each anchor. “Excellent solution” gives evaluators no repeatable standard. “Every required camera view is tied to a drawing reference, lens, lighting assumption, retention calculation and witnessed test” can be assessed.
The Competition Bureau’s 2026 public procurement guide recommends balancing price with relevant non-price factors, assigning weights, explaining criteria clearly and using transparent evaluation grids. It also identifies after-sales support and supplier reliability as factors that may affect value. See Unlocking competition in public procurement. The guide addresses public procurement, so private organizations should adapt the process to their governance and contracting context.
Test performance claims using the same scenarios
A brochure comparison rarely establishes whether the proposed system will support the actual workflow. Require finalists to demonstrate the difficult use cases under the same script.
For video, the script might require the bidder to:
- retrieve a known incident window using an operator role;
- export footage and verify the receiving party can open it;
- show moving subjects in representative low light;
- demonstrate the proposed retention calculation and recording settings;
- show health alerts for camera, storage and time-synchronization failures; and
- apply privacy masks and restricted export permissions.
For access control and intrusion, test:
- valid, invalid, expired and lost credentials;
- forced and held-open doors;
- schedules, holidays and temporary contractor access;
- alarm acknowledgement and escalation;
- network and power interruptions;
- backup restoration; and
- removal of vendor or installer access after handover.
Record the hardware, firmware, licences, cloud services, network conditions and configuration used. A demonstration earns points only for a result included in the proposed scope. If the bidder uses an optional analytics licence, extra server or different camera during the demonstration, add that dependency to the normalized cost before scoring.
NIST SP 800-213 advises organizations acquiring connected devices to define the cybersecurity capabilities they expect from the device and the manufacturer or supporting parties. Its scope is United States federal IoT procurement, while its requirement-setting approach is useful for networked cameras, controllers, intercoms and recorders. See NIST SP 800-213.
Compare lifecycle cost and responsibility
Choose an evaluation period that matches the organization’s planning horizon and apply it consistently. Record every assumption for inflation, quantity growth, storage, site additions and support. Keep uncertain costs visible instead of forcing a false level of precision.
At minimum, compare:
- equipment, installation and project management;
- software, cloud, cellular and monitoring charges;
- warranty extensions and on-site labour;
- preventive maintenance and service call assumptions;
- firmware, software and major-version entitlements;
- storage growth and replacement drives;
- training for operators and new administrators;
- customer IT, network and identity-management work;
- expected equipment replacement or support-end exposure; and
- export, migration and decommissioning costs.
Connected security devices also create support-lifecycle obligations. Ask each bidder to identify the expected manufacturer support period, security-update process, vulnerability notifications, supported dependencies and end-of-support plan for the exact proposed models. NIST’s requirement catalogue explains that manufacturer documentation about lifespan, support term, maintenance, operations, security and disposal costs can help customers make informed acquisition decisions. See NIST guidance on manufacturer documentation.
Assign every dependency to an owner. “Customer network required” should identify switch ports, power budget, network segmentation, addressing, DNS, certificates, time synchronization, firewall rules, remote access, monitoring and support responsibility. A low bid can become expensive when those tasks surface during installation.
Score privacy, ownership and exit conditions
Video and access systems handle information that requires operational ownership. The proposal should identify who can view, administer, export, disclose and delete data, along with the technical controls that enforce those decisions.
For video proposals, check whether the offered design can implement the organization’s approved purpose, field-of-view limits, retention, access restrictions, exports, audit evidence and secure destruction. The Office of the Privacy Commissioner of Canada advises private-sector organizations to establish a business reason for surveillance, limit camera range, restrict access, secure recordings and destroy them when they are no longer required. See the OPC’s Guidelines for Overt Video Surveillance in the Private Sector.
The buyer still owns the policy decisions. A bidder can explain platform capabilities and implement approved settings. Procurement, privacy, security and operations leaders should approve the purpose, authority, retention and disclosure rules that the system must support.
Exit conditions deserve a scored line when the system depends on a hosted service, proprietary credential, integrator-managed account or recurring licence. Require bidders to state:
- who owns the equipment, licences, tenant and data;
- which administrator and recovery credentials transfer at handover;
- available export formats and practical export limits;
- configuration and database backup rights;
- integration and migration options;
- contract renewal, price-change and termination rules; and
- responsibilities when a manufacturer, platform or service provider reaches end of support.
Run a defensible consensus and decision gate
Each evaluator should score independently before the consensus meeting. The meeting should resolve differences using proposal evidence and the published anchors. Preserve the original score, consensus score and reason for every material change according to the organization’s recordkeeping rules.
Before recommending an award, confirm:
- every mandatory gate has objective evidence;
- material scope gaps have been clarified or priced;
- the same criteria and scenarios were applied to every bid;
- technical and commercial assumptions are recorded;
- lifecycle costs use the same period and quantities;
- privacy, cybersecurity and operating owners have reviewed their areas;
- the proposed acceptance test appears in the contract documents;
- exceptions and dependencies have named owners; and
- the decision record explains the selected offer in terms of the approved criteria.
The result should be understandable to someone who did not attend the presentations. If the recommendation depends on undocumented confidence in a salesperson, an unpriced promise or an evaluator’s preferred brand, the comparison is incomplete.
Securitron Canada can help GTA property, facilities and procurement teams translate operating requirements into a normalized comparison and testable commercial security system scope before a final award.
Frequently Asked Questions
Normalize every proposal against the same requirements, quantities, assumptions, exclusions, recurring charges and acceptance tests. Resolve material gaps in writing, then score the compliant offers using criteria and weights approved before evaluators review pricing.
Use the selection method approved for the procurement. A lowest-price method can work when requirements are complete and every responsive bid delivers the same verified outcome. Complex projects usually need a transparent assessment of technical merit, lifecycle cost, delivery risk and service.
Reserve pass or fail treatment for requirements essential to legality, safety, interoperability, cybersecurity, insurability or the operating outcome. Define objective evidence for each gate and keep desirable features in the rated criteria.
Use the same scripted scenarios, data and operating conditions for every shortlisted bidder. Score recorded evidence against predetermined acceptance measures, including failure and recovery cases, and document any configuration or licence required to reproduce the result.
Include software, cloud storage, monitoring, cellular service, support, preventive maintenance, firmware or version entitlements, warranty extensions, training, storage growth, administrator turnover and exit or data-export costs over the chosen evaluation period.


