Use case · Enterprise

RFP scoring,
make security posture comparable.

Attach a current, externally-observed security score to every bid so proposals are comparable on posture as well as price. Same scale, same method, same date for every bidder.

How it works

RFP Scoring, step by step

Before

Every bidder answers differently

Security sections that cannot be compared, scored by whoever has time that week.

With GuardianGaze

One score per bidder

Rate every shortlisted supplier on the same scale, on the same day, from public evidence.

Result

A defensible shortlist

Procurement decisions you can justify to audit, because the method was identical for everyone.

Third-party vendor inventory scored by security rating, tier and risk category

Every vendor discovered and rated, grouped by risk tier so the ones that need attention stand out

The problem

Security sections in tenders measure writing ability

Nearly every substantial tender contains a security section, and nearly every one scores the quality of the response rather than the security of the respondent. A supplier with a capable bid team writes a strong answer. A supplier with strong security and no bid team writes a weak one. The scoring cannot tell them apart, because both are prose.

This is well understood by everyone involved and rarely fixed, because the alternative appears to require technical assessment of every bidder, which no procurement team has capacity for.

It has a second cost that gets less attention: the effort is enormous and symmetrical. Every bidder spends days on a document, the evaluation team spends days reading them, and the resulting scores discriminate weakly on the thing they were meant to measure.

The alternative

An objective, comparable criterion that costs nobody anything

Rating every bidder from their public attack surface produces a number derived from the same method for each of them. Nobody writes anything, nobody is advantaged by bid-writing capacity, and the criterion is comparable by construction.

It also scales in a way document review does not. Rating twelve bidders costs the same as rating three, which means posture can be applied at the longlist stage as a filter rather than only to the finalists, where, in practice, it rarely changes anything.

Bidders tend to prefer it once it is explained. A supplier with genuinely good security is usually pleased to be measured rather than asked to describe, and the ones who object are frequently telling you something useful.

Fairness

How to use it without making it arbitrary

State it in the tender documents. Bidders should know that external posture will be assessed, how it will be weighted, and that findings will be shared with them, an undisclosed criterion is a procurement problem regardless of how good the criterion is.

Share the findings and allow a response. Every finding carries the evidence it came from, so a bidder can correct a misattribution or demonstrate that something has been remediated. Some genuinely will have fixed it, and a supplier who fixes findings inside the tender window has told you something useful about how they operate.

Weight it proportionately. Posture should be one scored criterion among several, sized to what the contract actually exposes. A supplier processing customer payments warrants heavy weighting; a supplier delivering furniture does not, and applying the same weight to both discredits the criterion.

After award

The criterion should not stop at signature

A posture assessed during a tender describes the bidder during the tender, which is precisely when they are most motivated. What matters over a five-year contract is whether it holds.

Carrying the awarded supplier into continuous monitoring makes the security section of the contract enforceable. A clause requiring a supplier to maintain a standard is unenforceable if nobody measures it, and nobody measures it manually across a supplier base of any size.

This also closes the most common failure in public and regulated procurement, where a supplier is assessed thoroughly once and then not examined again for the contract's duration, during which acquisitions, provider changes and staff turnover reshape their posture entirely.

Comparison

Written security section vs external rating

Written responseExternal rating
MeasuresBid-writing capabilityObservable security posture
Bidder effortDays per bidderNone
Evaluator effortDays of readingMinutes of comparison
Comparable across biddersPoorlyYes, same method for each
Scales to a longlistNoYes
VerifiableNoYes, evidence attached
Still true after awardNoYes, if monitoring continues
“Security stopped being the section nobody could score.”
CISO · Mid-market financial services group
FAQ

RFP Scoring | common questions

Is it fair to rate bidders without asking them?

It is fair if it is disclosed. State in the tender documents that external posture will be assessed, how it is weighted, and that findings will be shared with a right of response. The criterion is objective; the process needs to be transparent.

Can bidders challenge a finding?

Yes, and they should be able to. Every finding carries its evidence, so a bidder can correct a misattribution or show remediation. A supplier who fixes findings inside the tender window has told you something useful.

How heavily should we weight it?

Proportionately to what the contract exposes. Heavy for a supplier processing customer payments, light for one delivering furniture. Applying the same weight to both discredits the criterion.

Can we rate a longlist rather than just finalists?

Yes, rating twelve bidders costs the same as three, which is what lets posture act as an early filter rather than a late-stage formality.

What happens after award?

The awarded supplier should enter continuous monitoring. A posture assessed during a tender describes the bidder when they were most motivated; what matters is whether it holds across the contract term.

Do bidders object?

Suppliers with genuinely good security usually prefer being measured to being asked to describe. The ones who object are often telling you something worth knowing.

Related

Where this connects

Vendor onboarding →

Rating suppliers before the contract is signed.

Third-party risk →

Continuous monitoring once the contract is live.

Reports →

Evidence packs suitable for a procurement file.

Put your vendors on the board

Start with ten vendors. Expand when the first alert pays for the year.