A Scorecard for Comparing Commercial Security Bids

Compare commercial security bids using a practical scorecard for scope, performance, lifecycle cost, service, cybersecurity and acceptance evidence.

Illustrative procurement and facilities team comparing security proposals during a commercial site walk

Three commercial security proposals can show similar totals while describing different systems, responsibilities and risks. Procurement and facilities leaders should first normalize each bid to a common scope, then apply mandatory gates and a weighted scorecard covering performance, implementation, lifecycle, service and commercial terms. Price should be evaluated only after hidden differences are exposed.

The most useful scorecard answers a practical question: which proposal gives the organization the strongest evidence that the required security outcome will be delivered, supported and maintainable at an understood lifecycle cost? It should reward verifiable commitments and reduce points for assumptions that transfer cost or responsibility back to the customer.

This guide begins after bids have arrived. Teams still preparing the solicitation can use the commercial security RFP checklist to create a common response structure before proposals are requested.

Start by separating compliance, clarification and scoring

Use three distinct passes. Combining them in one discussion makes a polished proposal or low total more likely to influence decisions that should be objective.

Pass 1: mandatory compliance

Check each mandatory requirement using the evidence defined in the solicitation. A response of “complies” carries little value without a model number, drawing, method statement, certificate, licence description or other requested proof.

Mandatory gates may cover:

  • required insurance, licensing or contractual declarations;
  • compatibility with an existing platform that must remain in service;
  • essential privacy, cybersecurity or data-location conditions;
  • required service coverage or response capability;
  • minimum functional performance; and
  • submission of a complete pricing schedule and exceptions register.

Keep the gates limited to requirements that are genuinely essential. The Ontario Broader Public Sector Procurement Directive requires covered organizations to disclose mandatory and rated criteria and their weightings in the competitive documents. It also says mandatory criteria should be kept to a minimum so bids are not unnecessarily disqualified. Private-sector buyers can use the same discipline even when the directive does not apply to them. See Ontario’s Broader Public Sector Procurement Directive.

Pass 2: clarification and normalization

Create one clarification log controlled by procurement. Ask bidders the same question when the same ambiguity appears, set a deadline and preserve the written answer. Clarification should explain the submitted offer according to the procurement rules. It should not become an informal opportunity to rebuild one bid after closing.

Pass 3: rated evaluation

Score only the compliant, normalized proposal. Evaluators should record evidence and a short reason for each score before a consensus meeting. CanadaBuys explains that rated criteria distinguish the relative merits of technical bids and that the stated selection method governs the final choice. Its overview also describes separating technical assessment from financial assessment to support fairness. See How bids are evaluated and selected.

Normalize the scope before comparing totals

The first comparison sheet should show what each total contains. Create a bid-normalization table with one row for every required deliverable, dependency and recurring charge.

Comparison fieldWhat to recordWarning signal
EquipmentManufacturer, model, quantity, licence and approved equivalentGeneric descriptions such as “4K camera”
Coverage or door outcomeRequired view, event, workflow or controlled openingDevice count with no operational purpose
InfrastructureCabling, pathway, switches, power, UPS, racks and network work“By others” with no owner or allowance
InstallationHours, lifts, permits, patching, fire stopping, disposal and restorationAssumed daytime access at a 24-hour site
Software and servicesHosting, licences, monitoring, cellular, integrations and renewal termsFirst-year price with later charges omitted
CommissioningTest scripts, deficiency process, retest and customer witness“System operational” as the only test
HandoverAs-builts, asset list, configuration backup, credentials and trainingDocumentation available only on request
Warranty and supportCoverage, response, exclusions, escalation and replacement processManufacturer warranty presented as on-site labour
ExitData export, configuration transfer, credential ownership and decommissioningCustomer access depends on the outgoing provider

For each row, label the response included, excluded, allowance, optional, customer supplied, or unclear. Add the bidder’s exact assumption and the person who would own the work. This makes two proposals comparable without pretending their original totals represented the same scope.

Do not silently estimate an unclear item. Request a written clarification where the rules permit it. If the issue remains unresolved, score the uncertainty according to the published method and document the reason.

Use a scorecard tied to evidence

A practical scorecard separates the factors that determine whether the system will work and remain supportable. The example below totals 100 points. Adapt the criteria and weights before bids are opened. Public-sector and regulated procurements need review against their governing policies and legal obligations.

Rated categoryExample weightStrong evidence
Scope completeness and traceability20Requirement-by-requirement response, drawings, quantities, dependencies and exceptions
Operational performance and design20Coverage objectives, door workflows, alarm logic, storage calculations and demonstrated results
Delivery and commissioning15Site method, schedule, outage controls, test scripts, deficiency closure and accountable owners
Lifecycle and cybersecurity15Support horizon, updates, secure configuration, identity controls, backups and migration path
Service and operating support10Measurable response levels, escalation, preventive maintenance, spares and reporting
Evaluated lifecycle cost20Normalized capital, recurring, support, growth and exit costs over the chosen period

Define scoring anchors for every category. A five-point scale could mean:

  1. 0, absent: no usable response or evidence.
  2. 1, weak: major gaps, unsupported statements or high customer dependency.
  3. 2, partial: some relevant detail with material uncertainty.
  4. 3, acceptable: complete response that meets the stated expectation.
  5. 4, strong: clear evidence, low ambiguity and useful added value.
  6. 5, exceptional: verified benefit beyond the requirement with no material new dependency.

Write a category-specific description for each anchor. “Excellent solution” gives evaluators no repeatable standard. “Every required camera view is tied to a drawing reference, lens, lighting assumption, retention calculation and witnessed test” can be assessed.

The Competition Bureau’s 2026 public procurement guide recommends balancing price with relevant non-price factors, assigning weights, explaining criteria clearly and using transparent evaluation grids. It also identifies after-sales support and supplier reliability as factors that may affect value. See Unlocking competition in public procurement. The guide addresses public procurement, so private organizations should adapt the process to their governance and contracting context.

Test performance claims using the same scenarios

A brochure comparison rarely establishes whether the proposed system will support the actual workflow. Require finalists to demonstrate the difficult use cases under the same script.

For video, the script might require the bidder to:

  • retrieve a known incident window using an operator role;
  • export footage and verify the receiving party can open it;
  • show moving subjects in representative low light;
  • demonstrate the proposed retention calculation and recording settings;
  • show health alerts for camera, storage and time-synchronization failures; and
  • apply privacy masks and restricted export permissions.

For access control and intrusion, test:

  • valid, invalid, expired and lost credentials;
  • forced and held-open doors;
  • schedules, holidays and temporary contractor access;
  • alarm acknowledgement and escalation;
  • network and power interruptions;
  • backup restoration; and
  • removal of vendor or installer access after handover.

Record the hardware, firmware, licences, cloud services, network conditions and configuration used. A demonstration earns points only for a result included in the proposed scope. If the bidder uses an optional analytics licence, extra server or different camera during the demonstration, add that dependency to the normalized cost before scoring.

NIST SP 800-213 advises organizations acquiring connected devices to define the cybersecurity capabilities they expect from the device and the manufacturer or supporting parties. Its scope is United States federal IoT procurement, while its requirement-setting approach is useful for networked cameras, controllers, intercoms and recorders. See NIST SP 800-213.

Compare lifecycle cost and responsibility

Choose an evaluation period that matches the organization’s planning horizon and apply it consistently. Record every assumption for inflation, quantity growth, storage, site additions and support. Keep uncertain costs visible instead of forcing a false level of precision.

At minimum, compare:

  • equipment, installation and project management;
  • software, cloud, cellular and monitoring charges;
  • warranty extensions and on-site labour;
  • preventive maintenance and service call assumptions;
  • firmware, software and major-version entitlements;
  • storage growth and replacement drives;
  • training for operators and new administrators;
  • customer IT, network and identity-management work;
  • expected equipment replacement or support-end exposure; and
  • export, migration and decommissioning costs.

Connected security devices also create support-lifecycle obligations. Ask each bidder to identify the expected manufacturer support period, security-update process, vulnerability notifications, supported dependencies and end-of-support plan for the exact proposed models. NIST’s requirement catalogue explains that manufacturer documentation about lifespan, support term, maintenance, operations, security and disposal costs can help customers make informed acquisition decisions. See NIST guidance on manufacturer documentation.

Assign every dependency to an owner. “Customer network required” should identify switch ports, power budget, network segmentation, addressing, DNS, certificates, time synchronization, firewall rules, remote access, monitoring and support responsibility. A low bid can become expensive when those tasks surface during installation.

Score privacy, ownership and exit conditions

Video and access systems handle information that requires operational ownership. The proposal should identify who can view, administer, export, disclose and delete data, along with the technical controls that enforce those decisions.

For video proposals, check whether the offered design can implement the organization’s approved purpose, field-of-view limits, retention, access restrictions, exports, audit evidence and secure destruction. The Office of the Privacy Commissioner of Canada advises private-sector organizations to establish a business reason for surveillance, limit camera range, restrict access, secure recordings and destroy them when they are no longer required. See the OPC’s Guidelines for Overt Video Surveillance in the Private Sector.

The buyer still owns the policy decisions. A bidder can explain platform capabilities and implement approved settings. Procurement, privacy, security and operations leaders should approve the purpose, authority, retention and disclosure rules that the system must support.

Exit conditions deserve a scored line when the system depends on a hosted service, proprietary credential, integrator-managed account or recurring licence. Require bidders to state:

  • who owns the equipment, licences, tenant and data;
  • which administrator and recovery credentials transfer at handover;
  • available export formats and practical export limits;
  • configuration and database backup rights;
  • integration and migration options;
  • contract renewal, price-change and termination rules; and
  • responsibilities when a manufacturer, platform or service provider reaches end of support.

Run a defensible consensus and decision gate

Each evaluator should score independently before the consensus meeting. The meeting should resolve differences using proposal evidence and the published anchors. Preserve the original score, consensus score and reason for every material change according to the organization’s recordkeeping rules.

Before recommending an award, confirm:

  1. every mandatory gate has objective evidence;
  2. material scope gaps have been clarified or priced;
  3. the same criteria and scenarios were applied to every bid;
  4. technical and commercial assumptions are recorded;
  5. lifecycle costs use the same period and quantities;
  6. privacy, cybersecurity and operating owners have reviewed their areas;
  7. the proposed acceptance test appears in the contract documents;
  8. exceptions and dependencies have named owners; and
  9. the decision record explains the selected offer in terms of the approved criteria.

The result should be understandable to someone who did not attend the presentations. If the recommendation depends on undocumented confidence in a salesperson, an unpriced promise or an evaluator’s preferred brand, the comparison is incomplete.

Securitron Canada can help GTA property, facilities and procurement teams translate operating requirements into a normalized comparison and testable commercial security system scope before a final award.

Frequently Asked Questions

Normalize every proposal against the same requirements, quantities, assumptions, exclusions, recurring charges and acceptance tests. Resolve material gaps in writing, then score the compliant offers using criteria and weights approved before evaluators review pricing.

Use the selection method approved for the procurement. A lowest-price method can work when requirements are complete and every responsive bid delivers the same verified outcome. Complex projects usually need a transparent assessment of technical merit, lifecycle cost, delivery risk and service.

Reserve pass or fail treatment for requirements essential to legality, safety, interoperability, cybersecurity, insurability or the operating outcome. Define objective evidence for each gate and keep desirable features in the rated criteria.

Use the same scripted scenarios, data and operating conditions for every shortlisted bidder. Score recorded evidence against predetermined acceptance measures, including failure and recovery cases, and document any configuration or licence required to reproduce the result.

Include software, cloud storage, monitoring, cellular service, support, preventive maintenance, firmware or version entitlements, warranty extensions, training, storage growth, administrator turnover and exit or data-export costs over the chosen evaluation period.