RFP scoring,
make security posture comparable.
Attach a current, externally-observed security score to every bid so proposals are comparable on posture as well as price. Same scale, same method, same date for every bidder.
RFP Scoring, step by step
Every bidder answers differently
Security sections that cannot be compared, scored by whoever has time that week.
One score per bidder
Rate every shortlisted supplier on the same scale, on the same day, from public evidence.
A defensible shortlist
Procurement decisions you can justify to audit, because the method was identical for everyone.

Every vendor discovered and rated, grouped by risk tier so the ones that need attention stand out
Security sections in tenders measure writing ability
Nearly every substantial tender contains a security section, and nearly every one scores the quality of the response rather than the security of the respondent. A supplier with a capable bid team writes a strong answer. A supplier with strong security and no bid team writes a weak one. The scoring cannot tell them apart, because both are prose.
This is well understood by everyone involved and rarely fixed, because the alternative appears to require technical assessment of every bidder, which no procurement team has capacity for.
It has a second cost that gets less attention: the effort is enormous and symmetrical. Every bidder spends days on a document, the evaluation team spends days reading them, and the resulting scores discriminate weakly on the thing they were meant to measure.
An objective, comparable criterion that costs nobody anything
Rating every bidder from their public attack surface produces a number derived from the same method for each of them. Nobody writes anything, nobody is advantaged by bid-writing capacity, and the criterion is comparable by construction.
It also scales in a way document review does not. Rating twelve bidders costs the same as rating three, which means posture can be applied at the longlist stage as a filter rather than only to the finalists, where, in practice, it rarely changes anything.
Bidders tend to prefer it once it is explained. A supplier with genuinely good security is usually pleased to be measured rather than asked to describe, and the ones who object are frequently telling you something useful.
How to use it without making it arbitrary
State it in the tender documents. Bidders should know that external posture will be assessed, how it will be weighted, and that findings will be shared with them, an undisclosed criterion is a procurement problem regardless of how good the criterion is.
Share the findings and allow a response. Every finding carries the evidence it came from, so a bidder can correct a misattribution or demonstrate that something has been remediated. Some genuinely will have fixed it, and a supplier who fixes findings inside the tender window has told you something useful about how they operate.
Weight it proportionately. Posture should be one scored criterion among several, sized to what the contract actually exposes. A supplier processing customer payments warrants heavy weighting; a supplier delivering furniture does not, and applying the same weight to both discredits the criterion.
The criterion should not stop at signature
A posture assessed during a tender describes the bidder during the tender, which is precisely when they are most motivated. What matters over a five-year contract is whether it holds.
Carrying the awarded supplier into continuous monitoring makes the security section of the contract enforceable. A clause requiring a supplier to maintain a standard is unenforceable if nobody measures it, and nobody measures it manually across a supplier base of any size.
This also closes the most common failure in public and regulated procurement, where a supplier is assessed thoroughly once and then not examined again for the contract's duration, during which acquisitions, provider changes and staff turnover reshape their posture entirely.
Written security section vs external rating
| Written response | External rating | |
|---|---|---|
| Measures | Bid-writing capability | Observable security posture |
| Bidder effort | Days per bidder | None |
| Evaluator effort | Days of reading | Minutes of comparison |
| Comparable across bidders | Poorly | Yes, same method for each |
| Scales to a longlist | No | Yes |
| Verifiable | No | Yes, evidence attached |
| Still true after award | No | Yes, if monitoring continues |
“Security stopped being the section nobody could score.”
RFP Scoring | common questions
Is it fair to rate bidders without asking them?
It is fair if it is disclosed. State in the tender documents that external posture will be assessed, how it is weighted, and that findings will be shared with a right of response. The criterion is objective; the process needs to be transparent.
Can bidders challenge a finding?
Yes, and they should be able to. Every finding carries its evidence, so a bidder can correct a misattribution or show remediation. A supplier who fixes findings inside the tender window has told you something useful.
How heavily should we weight it?
Proportionately to what the contract exposes. Heavy for a supplier processing customer payments, light for one delivering furniture. Applying the same weight to both discredits the criterion.
Can we rate a longlist rather than just finalists?
Yes, rating twelve bidders costs the same as three, which is what lets posture act as an early filter rather than a late-stage formality.
What happens after award?
The awarded supplier should enter continuous monitoring. A posture assessed during a tender describes the bidder when they were most motivated; what matters is whether it holds across the contract term.
Do bidders object?
Suppliers with genuinely good security usually prefer being measured to being asked to describe. The ones who object are often telling you something worth knowing.
Where this connects
Vendor onboarding →
Rating suppliers before the contract is signed.
Third-party risk →
Continuous monitoring once the contract is live.
Reports →
Evidence packs suitable for a procurement file.
Put your vendors on the board
Start with ten vendors. Expand when the first alert pays for the year.